Web-forensics use case
Acquire evidence from helpdesk and support-ticket portals
Eviquire can document authorized helpdesk and customer-support records presented through a browser, including ticket identity, customer and agent messages, internal notes, status and assignment history, attachments, linked records, SLA information, visible audit events, exports, and acquisition activity. It does not replace the service database, API, provider audit logs, or CRM backend.
What this use case means
Eviquire can document authorized helpdesk and customer-support records presented through a browser, including ticket identity, customer and agent messages, internal notes, status and assignment history, attachments, linked records, SLA information, visible audit events, exports, and acquisition activity. It does not replace the service database, API, provider audit logs, or CRM backend.
Ticket evidence is distributed across conversation, event, attachment, customer, organization, assignment, and audit panels. Views differ by agent role, private notes may be hidden, and automation can change status while the examiner is collecting. The acquisition must show how the investigator moved from a queue or customer record to the specific ticket and which panels were actually available.
Common situations
When this workflow is useful
- Customer disputes, service failures, fraud, complaints, litigation, regulatory review, or internal investigations
- Preserving agent/customer communications, private notes, assignments, escalations, and attachments
- Documenting a ticket before automation, retention, account changes, or closure alters the presentation
Recommended process
A documented acquisition workflow
- Set scope and authority
Define tenant, queues, ticket IDs, customers, agents, dates, messages, notes, attachments, and exclusions.
- Record role and route
Document the authenticated agent or reviewer role, permissions, portal URL, queue or search, customer record, and navigation to the ticket.
- Acquire the complete relevant ticket
Expand conversation, events, assignments, SLA, internal notes, attachments, linked tickets, and audit panels, recording unavailable content and automated changes.
- Export and close
Preserve authorized ticket exports and attachments, hash originals, distinguish live presentation from exports, and verify the closed case.
Technical guidance
Conditions that affect support-ticket acquisition
Confirm these points during a short pre-acquisition validation on the authorized workstation.
Role-based visibility
Customers, agents, supervisors, and administrators may see different messages, private notes, fields, and history.
- Record the account role.
- Do not infer hidden notes are absent.
- Use the least privilege consistent with scope.
Automation and mutable state
Opening, assigning, exporting, or replying to a ticket can trigger read receipts, workflows, SLA changes, notifications, or audit events.
- Avoid unnecessary actions.
- Record starting and ending status.
- Explain investigator-caused events.
Attachments and linked records
Attachments, CRM profiles, calls, chats, knowledge articles, and linked tickets may be separate artifacts or systems.
- Preserve original downloads.
- Record cross-system links.
- Acquire external records only under proper authority.
Reviewable output
What the evidence package should explain
Ticket context
Tenant, queue, ticket ID, customer, agents, status, assignment, SLA, and navigation.
Conversation and history
Messages, private notes where authorized, events, screenshots, and session recording.
Attachments and exports
Original authorized files and ticket reports with hashes.
Review record
Acquisition settings, timestamps, limitations, reports, and custody history.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- Support records can contain customer, payment, health, credential, and security data; minimize and protect collection.
- Portal acquisition preserves the displayed ticket, not the complete service database or every automation and audit event.
- Do not send replies, alter assignments, or change status unless expressly required and authorized.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
Can private notes be acquired?
Only when the authorized account and scope permit access.
Can viewing a ticket change it?
Yes. Read state, audit events, automation, or SLA behavior may change; document effects.
Should attachments be downloaded?
When relevant and authorized, preserve the original files separately with hashes.
Does a ticket export replace the web capture?
No. Preserve both because the portal context and generated export answer different reviewer questions.
Can Eviquire acquire the helpdesk database?
No. Database, API, or provider audit acquisition requires another method.
Who uses this workflow?
Relevant professional roles
This acquisition workflow is commonly relevant to these teams. The appropriate authority, scope, procedure, and review requirements still depend on the matter.
Forensic experts
Acquire online evidence with technical context, integrity verification, custody records, and reporting.
See role-specific guidance →Law enforcement
Preserve volatile online evidence for authorized criminal and intelligence investigations.
See role-specific guidance →Law firms
Preserve websites and online content for litigation, disclosure, legal holds, and expert review.
See role-specific guidance →In-house legal teams
Preserve early evidence for disputes, compliance, legal holds, and outside-counsel review.
See role-specific guidance →