Skip to content
Skip to main content
First Response & Preservation Technical Explainer

What identifiers should be preserved before contacting a provider?

Preserve the provider-generated identifiers that locate the service, account, object, session and relevant time window. A display name or handwritten email address may be changeable, duplicated or insufficient.

Identify the correct account and service

Record the service name, complete URL, username, handle, email address, phone number and internal account ID where visible. For organisational platforms, include the tenant, workspace, domain, organisation, subscription or customer reference. Note whether the account is personal, managed, delegated, shared, suspended or deleted.

Preserve public-facing and internal identifiers when they differ, with enough context to show their relationship. Capture partial or masked recovery details exactly as displayed; do not guess hidden characters.

Locate the particular record or event

Content may have file, document, message, conversation, channel, folder, transaction or case identifiers. Access events may instead depend on device and session IDs, browser information, network addresses, dates, times and time zones. State time ranges unambiguously.

Capture screenshots or exports showing identifiers in their original interface before transcribing them into a request, and verify copied strings. The aim is not to collect unrelated personal information but to let the provider distinguish the intended records from similar accounts or objects.

Key takeaway

Preserve exact identifiers in their original context so the provider can resolve the correct service, account, object and time period without relying on ambiguous user-facing labels.

Reference: FRP-163First Response & Preservation