Decide whether the file is necessary

Published September 9, 2026.

Before asking for a screenshot or document, define the fact the team needs to verify. Offer a lower-risk option when possible, such as an order number or a cropped image. Tell the customer what to hide and never request full payment card data, passwords, or authentication codes.

Review inside the approved workspace

Open files only in the authorized case system and follow malware scanning controls. Do not download a copy to a personal device or paste it into a side channel. If the file contains more data than expected, stop circulation and follow the incident or privacy escalation path.

Record the result, not a second copy

Write the minimum case note needed to support the decision. Apply the relevant retention schedule and restrict access by role. Supervisors should sample attachment requests to find forms and scripts that encourage unnecessary collection.

Connect this routine to support record minimization and AI review controls. The NIST Cybersecurity Framework offers a broader structure for managing information risk.