Web-forensics use case

Acquire ERP, procurement, and accounting web evidence

Eviquire can document records presented through an authorized browser-based ERP, procurement, expense, inventory, or accounting application, including linked transactions, approvals, vendors, reports, visible audit history, attachments, and exports. It does not acquire the underlying database, accounting engine, integration logs, or endpoint files.

What this use case means

Eviquire can document records presented through an authorized browser-based ERP, procurement, expense, inventory, or accounting application, including linked transactions, approvals, vendors, reports, visible audit history, attachments, and exports. It does not acquire the underlying database, accounting engine, integration logs, or endpoint files.

Business records are relational: an invoice may connect to a purchase order, vendor, approval, receipt, payment, journal entry, and attachment. Role permissions, filters, fiscal periods, currencies, organizational units, and timezones affect the view. Capturing one screen without the linked transaction path can obscure provenance and meaning.

Common situations

When this workflow is useful

  • Fraud, bribery, invoice, expense, procurement, asset, audit, tax, compliance, or commercial investigations
  • Preserving transaction and approval histories for litigation, internal review, or expert examination
  • Documenting web-generated reports and native exports together with their filters and source context

Recommended process

A documented acquisition workflow

  1. Define entities and transactions

    Identify organization, module, fiscal period, records, users, vendors, currencies, reports, and exclusions.

  2. Record role and configuration

    Document account role, business unit, locale, timezone, currency, filters, and network or authentication conditions.

  3. Trace linked records

    Navigate systematically across transaction, approval, vendor, attachment, payment, journal, and visible audit panels while preserving identifiers and status.

  4. Export and reconcile

    Preserve authorized reports and native exports with their parameters, hash originals, note unavailable backend data, and close the case for review.

Technical guidance

Conditions that affect ERP and accounting acquisition

Confirm these points during a short pre-acquisition validation on the authorized workstation.

Relational context

A single screen may represent data assembled from many records and modules.

  • Preserve primary identifiers.
  • Record linked-record navigation.
  • Capture filters and organizational scope.

Roles and mutable workflows

Permissions and actions can change approval, posting, payment, or audit state.

  • Use read-only access when possible.
  • Avoid workflow actions.
  • Record starting and ending status.

Reports and authoritative records

A browser report or export reflects selected parameters and application logic at acquisition time.

  • Preserve parameters and generated file.
  • Distinguish displayed data from authoritative ledger or database evidence.
  • Correlate with system audit and integration logs when required.

Reviewable output

What the evidence package should explain

Business context

Tenant, entity, module, period, role, filters, currency, and locale.

Transaction chain

Orders, invoices, approvals, vendors, payments, journal or inventory links, and history.

Reports and files

Authorized exports and attachments with parameters and hashes.

Review package

Session record, timestamps, limitations, reports, and custody history.

The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.

Professional considerations

Authority, proportionality, and limitations

  • Financial and employee data requires strict scope, access, retention, and disclosure controls.
  • Portal presentation does not independently validate accounting accuracy, authorization, or database completeness.
  • Avoid posting, approving, paying, editing, or otherwise changing business records during acquisition.

Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.

Standards and primary guidance

Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.

Frequently asked questions

Can Eviquire acquire ERP records?

It can preserve selected authorized records presented through the compatible web interface.

Does it acquire the ERP database?

No. Database and backend acquisition require another method.

Why record report filters?

They determine which records, periods, entities, currencies, and statuses the report contains.

Can approvals be preserved?

Yes when visible and authorized, but authoritative workflow history may require system audit records.

Should exports be hashed?

Yes. Preserve and hash the original generated file before analysis or conversion.

Privacy preferences

Essential storage remembers this preference and is always active. Optional third-party services are disabled unless you allow them.