What should be preserved before requesting provider records?¶
Preserve stable identifiers, their source context and the exact event period before making a provider request. A display name or screenshot alone may identify neither the correct account nor the records required.
Capture identifiers at every relevant layer¶
Depending on the enquiry, this can include service and account IDs, username, registered number or email, profile URL, conversation, group or channel ID, message, attachment or call ID, and device or session identifiers. Record historical usernames, number porting or reassignment and linked endpoints where relevant.
Retain the date range, time zone and event type. Capture identifiers in native messages, exports or device records as well as a contextual screen view; handwritten transcription can lose prefixes, punctuation or leading zeros.
Preserve account state before changing it¶
Logging in, changing credentials or removing sessions can create new events and alter what the account displays. Record the current profile, linked devices, security state and source device before avoidable interaction. Consider timely preservation where relevant records may be volatile.
The identifiers included in the request should be selected from this preserved material and tied to the investigative question. If terminology is unclear, establish provider definitions rather than guessing from a visible label.
The point to remember
Preserve stable account, conversation, event, endpoint and time identifiers in their original context before any account interaction or provider approach.