- The affected feature, workspace slug, and approximate timestamp
- One safe record identifier and exact visible status or error
- Permission to disclose the minimum evidence needed for support
- A redaction method for secrets and unrelated customer data
Evidence should answer six questions
What failed? Where? For whom or what record? When? What state was visible? What safe recovery was already tried? Start with these answers before taking screenshots.
Evidence-led escalation
- 01ScopeConfirm scope
Identify the workspace, record, channel, time, and affected users.
- 02ObserveCheck visible state
Read the current status instead of repeating the action.
- 03TraceReview history
Use delivery events, audit history, or run logs to find the last good step.
- 04RecoverTry safe recovery
Retry only when duplication and customer impact are understood.
- 05EscalateEscalate with redacted evidence
Share expected versus actual results without secrets or excess customer data.
Build the support packet
- State the expected result and actual result in one sentence each.
- Record organization/workspace slug and exact route.
- Record approximate time, timezone, and first/last occurrence.
- Add safe record identifiers: conversation, contact, campaign, automation/run, quote, import, connection, or billing reference as relevant.
- Record actor role and whether the problem affects one record, one user, one channel, or the whole workspace.
- Capture visible status, published/configuration version, provider reason, and relevant timeline or audit event.
- Reproduce once with a marked test record if the action is reversible and non-consequential.
- Redact the screenshot and review it at full size.
- List recovery steps already tried and their results.
What to include by incident
| Area | Useful evidence | Exclude |
|---|---|---|
| Sign-in/security | User ID/work email, event/session ID, time, browser, safe audit state | Password, MFA seed/code, cookies, full audit for unrelated users |
| Channels/delivery | Connection or sender ID, direction, message/campaign ID, provider reason, delivery state | OAuth/Meta tokens, SMTP password, unnecessary message body |
| Automation | Workflow/run ID, published version, failed step, receipt state, retry simulation | Webhook key, unrelated customer context |
| Import/CRM | Import job ID, file headers, mapping, row number, sanitized sample | Full source file unless explicitly authorized |
| Quote/billing | Quote or organization reference, state, currency, estimate time, provider reference | Card/bank data, buyer verification secrets |
| AI | Capability, approximate time, enabled context classes, redacted incorrect claim | Prompts or customer content not needed to reproduce |
Screenshot sanitization
Crop to the affected control. Remove names, email addresses, phone numbers, message bodies, addresses, commercial terms, and IDs that are not needed. Mask browser tabs and desktop notifications. Keep the route, status label, timestamp, and error when they are material. Re-open the exported image and inspect pixels; a drawn translucent box may not actually remove data.
Reproduction boundaries
Do not resend a message, rerun an import, retry a charge, reconnect a provider, or execute a live automation merely to create evidence until side effects are understood. Prefer status refresh, safe simulation, a test workspace/record, or retained logs.
Transfer and retention
Use the approved support channel. Grant the smallest audience and retain evidence only as long as the incident and policy require. If support asks for broader data, confirm purpose and authorization before providing it.
Final check
Have a second authorized person review high-risk packets. Confirm every attachment belongs to the intended organization and workspace.
- Expected and actual result are precise
- Route, time, scope, role, and safe IDs included
- One safe reproduction or reason not to reproduce recorded
- Screenshots inspected after redaction
- Secrets and unrelated customer data excluded
- Recovery attempts and current state listed