What should I do when I encounter a logged-in online account?¶
Capture the account and session as found, then avoid navigation while authority, remote change and urgent protection are assessed.
Preserve the active context¶
Record service, URL, username, handle, tenant, profile, page, time, browser and device. Note whether the session appears live, cached, delegated, shared, remote or inside a virtual environment.
Capture notifications, security warnings, linked-device indicators and visible sign-in activity. Do not refresh, open messages, switch profiles, change settings or log out solely because access exists.
Access is not attribution or search authority¶
The session proves availability at that moment, not who authenticated or controls it now. Another user may remain connected.
Immediate fraud or safeguarding may justify security action, but record the original state and its evidential cost. Use approved preservation methods rather than copying account material into personal storage.
Key takeaway
Preserve the logged-in session without exploring it and separate visible access from later search, security and attribution decisions.