Remote support is privileged access by another name. The engineer sees the screen of a machine that may hold customer data, and can usually act on it. Sooner or later — after an incident, during an audit, or because a customer asks — somebody will want to know exactly what happened in that session.
Record the session, and the context around it
- Who connected, from which account, and who approved or consented.
- Which machine, and which ticket the session belonged to.
- Start and end time, and whether files were transferred in either direction.
- The screen recording itself, stored where the ticket can find it.
A recording with no ticket attached is almost useless six months later: you have a video of a screen and no idea why anyone was there. The link back to the ticket is what turns it into evidence.
Consent is not optional
Tell the person before the session that it is being recorded, and get it in the support terms you sign with the customer. Under most data protection regimes a recording of a working screen is personal data of whoever is at that desk, and unattended access to a personal workstation is exactly the case a regulator asks about.
Keep the recordings out of reach of the people in them
An engineer should be able to make a recording and not be able to delete it. Restrict who can view and who can remove, keep an access log, and store the files with the same protection as the data they may show.
Choose a retention period and enforce it
- Short enough that you are not holding customer screens indefinitely — 90 to 180 days suits most support desks.
- Long enough to cover a dispute, a quarterly review or an audit cycle.
- Automatic deletion at the end of it, with the metadata trail kept even after the video goes.
The practical test is simple: can you answer "what did we do on that machine on the 14th?" in under five minutes, without asking the engineer? If the answer is no, the recording is a habit rather than a control.