Web-forensics use case
Acquire ERP, procurement, and accounting web evidence
Eviquire can document records presented through an authorized browser-based ERP, procurement, expense, inventory, or accounting application, including linked transactions, approvals, vendors, reports, visible audit history, attachments, and exports. It does not acquire the underlying database, accounting engine, integration logs, or endpoint files.
What this use case means
Eviquire can document records presented through an authorized browser-based ERP, procurement, expense, inventory, or accounting application, including linked transactions, approvals, vendors, reports, visible audit history, attachments, and exports. It does not acquire the underlying database, accounting engine, integration logs, or endpoint files.
Business records are relational: an invoice may connect to a purchase order, vendor, approval, receipt, payment, journal entry, and attachment. Role permissions, filters, fiscal periods, currencies, organizational units, and timezones affect the view. Capturing one screen without the linked transaction path can obscure provenance and meaning.
Common situations
When this workflow is useful
- Fraud, bribery, invoice, expense, procurement, asset, audit, tax, compliance, or commercial investigations
- Preserving transaction and approval histories for litigation, internal review, or expert examination
- Documenting web-generated reports and native exports together with their filters and source context
Recommended process
A documented acquisition workflow
- Define entities and transactions
Identify organization, module, fiscal period, records, users, vendors, currencies, reports, and exclusions.
- Record role and configuration
Document account role, business unit, locale, timezone, currency, filters, and network or authentication conditions.
- Trace linked records
Navigate systematically across transaction, approval, vendor, attachment, payment, journal, and visible audit panels while preserving identifiers and status.
- Export and reconcile
Preserve authorized reports and native exports with their parameters, hash originals, note unavailable backend data, and close the case for review.
Technical guidance
Conditions that affect ERP and accounting acquisition
Confirm these points during a short pre-acquisition validation on the authorized workstation.
Relational context
A single screen may represent data assembled from many records and modules.
- Preserve primary identifiers.
- Record linked-record navigation.
- Capture filters and organizational scope.
Roles and mutable workflows
Permissions and actions can change approval, posting, payment, or audit state.
- Use read-only access when possible.
- Avoid workflow actions.
- Record starting and ending status.
Reports and authoritative records
A browser report or export reflects selected parameters and application logic at acquisition time.
- Preserve parameters and generated file.
- Distinguish displayed data from authoritative ledger or database evidence.
- Correlate with system audit and integration logs when required.
Reviewable output
What the evidence package should explain
Business context
Tenant, entity, module, period, role, filters, currency, and locale.
Transaction chain
Orders, invoices, approvals, vendors, payments, journal or inventory links, and history.
Reports and files
Authorized exports and attachments with parameters and hashes.
Review package
Session record, timestamps, limitations, reports, and custody history.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- Financial and employee data requires strict scope, access, retention, and disclosure controls.
- Portal presentation does not independently validate accounting accuracy, authorization, or database completeness.
- Avoid posting, approving, paying, editing, or otherwise changing business records during acquisition.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
Can Eviquire acquire ERP records?
It can preserve selected authorized records presented through the compatible web interface.
Does it acquire the ERP database?
No. Database and backend acquisition require another method.
Why record report filters?
They determine which records, periods, entities, currencies, and statuses the report contains.
Can approvals be preserved?
Yes when visible and authorized, but authoritative workflow history may require system audit records.
Should exports be hashed?
Yes. Preserve and hash the original generated file before analysis or conversion.
Who uses this workflow?
Relevant professional roles
This acquisition workflow is commonly relevant to these teams. The appropriate authority, scope, procedure, and review requirements still depend on the matter.
Forensic experts
Acquire online evidence with technical context, integrity verification, custody records, and reporting.
See role-specific guidance →Law firms
Preserve websites and online content for litigation, disclosure, legal holds, and expert review.
See role-specific guidance →In-house legal teams
Preserve early evidence for disputes, compliance, legal holds, and outside-counsel review.
See role-specific guidance →