Skip to content
Skip to main content
First Response & Preservation Technical Explainer

Could another user delete cloud evidence remotely?

Yes. Owners, collaborators, administrators, attackers and automated retention can remove or restrict provider-held data independently of the local device.

Preserve object and access context

Record service, object ID, path, owner, collaborators, sharing roles, timestamps and visible content. Local isolation does not prevent action through another session.

Seek provider preservation or organisational controls quickly where loss is credible. Password and permission changes can reduce risk while alerting users and changing sessions.

Keep capability separate from action

Record disappearance, access denial, recycle-bin movement, permission and version changes. Audit evidence is needed to determine which account or process acted.

Use the least destructive protective control and document why delay was unsafe.

Key takeaway

Assume cloud evidence remains remotely controllable and preserve identifiers, roles and state before coordinated protection changes access.

Reference: FRP-123First Response & Preservation