Web-forensics use case

Acquire evidence from helpdesk and support-ticket portals

Eviquire can document authorized helpdesk and customer-support records presented through a browser, including ticket identity, customer and agent messages, internal notes, status and assignment history, attachments, linked records, SLA information, visible audit events, exports, and acquisition activity. It does not replace the service database, API, provider audit logs, or CRM backend.

What this use case means

Eviquire can document authorized helpdesk and customer-support records presented through a browser, including ticket identity, customer and agent messages, internal notes, status and assignment history, attachments, linked records, SLA information, visible audit events, exports, and acquisition activity. It does not replace the service database, API, provider audit logs, or CRM backend.

Ticket evidence is distributed across conversation, event, attachment, customer, organization, assignment, and audit panels. Views differ by agent role, private notes may be hidden, and automation can change status while the examiner is collecting. The acquisition must show how the investigator moved from a queue or customer record to the specific ticket and which panels were actually available.

Common situations

When this workflow is useful

  • Customer disputes, service failures, fraud, complaints, litigation, regulatory review, or internal investigations
  • Preserving agent/customer communications, private notes, assignments, escalations, and attachments
  • Documenting a ticket before automation, retention, account changes, or closure alters the presentation

Recommended process

A documented acquisition workflow

  1. Set scope and authority

    Define tenant, queues, ticket IDs, customers, agents, dates, messages, notes, attachments, and exclusions.

  2. Record role and route

    Document the authenticated agent or reviewer role, permissions, portal URL, queue or search, customer record, and navigation to the ticket.

  3. Acquire the complete relevant ticket

    Expand conversation, events, assignments, SLA, internal notes, attachments, linked tickets, and audit panels, recording unavailable content and automated changes.

  4. Export and close

    Preserve authorized ticket exports and attachments, hash originals, distinguish live presentation from exports, and verify the closed case.

Technical guidance

Conditions that affect support-ticket acquisition

Confirm these points during a short pre-acquisition validation on the authorized workstation.

Role-based visibility

Customers, agents, supervisors, and administrators may see different messages, private notes, fields, and history.

  • Record the account role.
  • Do not infer hidden notes are absent.
  • Use the least privilege consistent with scope.

Automation and mutable state

Opening, assigning, exporting, or replying to a ticket can trigger read receipts, workflows, SLA changes, notifications, or audit events.

  • Avoid unnecessary actions.
  • Record starting and ending status.
  • Explain investigator-caused events.

Attachments and linked records

Attachments, CRM profiles, calls, chats, knowledge articles, and linked tickets may be separate artifacts or systems.

  • Preserve original downloads.
  • Record cross-system links.
  • Acquire external records only under proper authority.

Reviewable output

What the evidence package should explain

Ticket context

Tenant, queue, ticket ID, customer, agents, status, assignment, SLA, and navigation.

Conversation and history

Messages, private notes where authorized, events, screenshots, and session recording.

Attachments and exports

Original authorized files and ticket reports with hashes.

Review record

Acquisition settings, timestamps, limitations, reports, and custody history.

The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.

Professional considerations

Authority, proportionality, and limitations

  • Support records can contain customer, payment, health, credential, and security data; minimize and protect collection.
  • Portal acquisition preserves the displayed ticket, not the complete service database or every automation and audit event.
  • Do not send replies, alter assignments, or change status unless expressly required and authorized.

Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.

Standards and primary guidance

Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.

Frequently asked questions

Can private notes be acquired?

Only when the authorized account and scope permit access.

Can viewing a ticket change it?

Yes. Read state, audit events, automation, or SLA behavior may change; document effects.

Should attachments be downloaded?

When relevant and authorized, preserve the original files separately with hashes.

Does a ticket export replace the web capture?

No. Preserve both because the portal context and generated export answer different reviewer questions.

Can Eviquire acquire the helpdesk database?

No. Database, API, or provider audit acquisition requires another method.

Privacy preferences

Essential storage remembers this preference and is always active. Optional third-party services are disabled unless you allow them.