What should be preserved from an account-security page?¶
Capture the complete page context and visible sign-ins, sessions, devices, recovery methods and warnings before scrolling, expanding or changing anything.
Record volatile security evidence¶
Include service, URL, account, date, timezone and device. Preserve session identifiers, browsers, locations, IP addresses, activity times, authentication methods, trusted devices and password or recovery events.
Retain provider qualifiers such as approximate, failed, challenged or blocked. Generic and user-defined device labels do not identify a person by themselves.
Preserve the unaltered display first¶
Capture the initial screen before scrolling or expanding detail. Do not revoke sessions or open hidden panels merely to gather more.
If action changes the page, preserve the new state separately. Record provider references and distinguish current sessions from historical sign-ins.
Key takeaway
Preserve the full security page and its provider wording before interaction removes, reorders or changes volatile account evidence.