{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/govern-evidence-locks-as-retention-exceptions/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions/",
        "slug": "govern-evidence-locks-as-retention-exceptions",
        "url": "https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/govern-evidence-locks-as-retention-exceptions/"
        },
        "title": "Govern evidence locks as retention exceptions, not permanent pins",
        "summary": "An evidence lock can preserve selected video beyond normal retention. Define who may create, extend, review, and remove each lock before storage and legal obligations collide.",
        "format": {
            "slug": "playbook",
            "name": "Playbook"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "video-surveillance",
                "name": "Video Surveillance",
                "url": "https://update.dsesecurity.com/topic/video-surveillance/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-25T21:36:11+00:00",
        "modified_at": "2026-08-25T21:36:16+00:00",
        "reviewed_on": "2026-08-25",
        "reading_minutes": 2,
        "word_count": 429,
        "potentially_affected": "XProtect Corporate deployments using evidence locks to preserve recordings for investigations, litigation, regulatory review, or internal holds.",
        "dse_recommendation": "Require a case owner, scope, reason, expiration, access restriction, periodic review, and witnessed release for every evidence lock.",
        "primary_source": {
            "name": "XProtect evidence locks",
            "url": "https://doc.milestonesys.com/2025r2/en-US/wp_storage_arch/evidence_lock.htm",
            "published_on": null,
            "authority": "doc.milestonesys.com"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<p><strong>Bottom line:</strong> an evidence lock is an exception to ordinary retention, not a substitute for case management. Without ownership and release controls, locks can accumulate indefinitely; if a lock is removed after ordinary retention has expired, the protected recording may become eligible for deletion.</p>\n<h2>Source fact: evidence locks override normal retention for selected recordings</h2>\n<p>Milestone&#8217;s <a href=\"https://doc.milestonesys.com/2025r2/en-US/wp_storage_arch/evidence_lock.htm\" target=\"_blank\" rel=\"noopener noreferrer\">XProtect evidence-lock documentation</a> explains that evidence locks in XProtect Corporate protect selected recordings from the normal retention process. The system supports permissions for evidence-lock operations, a configured lock duration, and status information. The documentation also warns that deleting a lock can result in deletion of recordings that are already older than the standard retention period.</p>\n<p>The important operational event is therefore not only creation. Extension, expiration, and removal can change whether the last retained copy continues to exist.</p>\n<h2>Source boundary and applicability</h2>\n<p>The page documents a Milestone feature; it does not determine legal-hold scope, evidence admissibility, chain of custody, or required retention. Availability and behavior depend on XProtect edition, version, permissions, storage configuration, and the recorded devices included. Counsel or the designated records authority should define binding hold requirements.</p>\n<h2>Applicability questions</h2>\n<ul>\n<li>What event, case, request, or obligation authorizes the lock?</li>\n<li>Which cameras and exact time interval are necessary, including pre-event and post-event context?</li>\n<li>Who may create, extend, export, and delete locks, and are those actions logged?</li>\n<li>What review occurs before expiration or manual removal?</li>\n<li>Is the locked database the authoritative evidence copy, or must a verified export also be preserved?</li>\n</ul>\n<h2>DSE recommendation: require a lock record and controlled release</h2>\n<p><em>The following steps are DSE recommendations based on the cited source.</em></p>\n<p>Assign each lock a unique case identifier, accountable owner, approving authority, reason, camera and time scope, creation date, review date, and expected release condition. Separate permission to view video from permission to delete a lock. Use the narrowest defensible interval, while preserving enough context to avoid misleading fragments.</p>\n<p>Review open locks on a defined cadence with records, legal, security, and storage owners. Before shortening or deleting one, confirm authorization, determine whether ordinary retention has elapsed, verify any required export and hash, and record the effect on storage. Emergency deletion to recover capacity should follow the same escalation and documentation, not an undocumented administrator shortcut.</p>\n<h2>Verification and evidence</h2>\n<p>Retain the lock register, approval, XProtect status export or screenshots, audit events, storage-capacity trend, periodic review record, and release authorization. For a controlled test case, show that locked video survives normal retention and document exactly what occurs after authorized release. Never use production evidence merely to test deletion behavior.</p>\n<h2>Official references</h2>\n<ul>\n<li><a href=\"https://doc.milestonesys.com/2025r2/en-US/wp_storage_arch/evidence_lock.htm\" target=\"_blank\" rel=\"noopener noreferrer\">XProtect evidence locks</a> &#8211; Milestone Systems</li>\n</ul>",
        "content_text": "Bottom line: an evidence lock is an exception to ordinary retention, not a substitute for case management. Without ownership and release controls, locks can accumulate indefinitely; if a lock is removed after ordinary retention has expired, the protected recording may become eligible for deletion.\nSource fact: evidence locks override normal retention for selected recordings\nMilestone’s XProtect evidence-lock documentation explains that evidence locks in XProtect Corporate protect selected recordings from the normal retention process. The system supports permissions for evidence-lock operations, a configured lock duration, and status information. The documentation also warns that deleting a lock can result in deletion of recordings that are already older than the standard retention period.\nThe important operational event is therefore not only creation. Extension, expiration, and removal can change whether the last retained copy continues to exist.\nSource boundary and applicability\nThe page documents a Milestone feature; it does not determine legal-hold scope, evidence admissibility, chain of custody, or required retention. Availability and behavior depend on XProtect edition, version, permissions, storage configuration, and the recorded devices included. Counsel or the designated records authority should define binding hold requirements.\nApplicability questions\n\nWhat event, case, request, or obligation authorizes the lock?\nWhich cameras and exact time interval are necessary, including pre-event and post-event context?\nWho may create, extend, export, and delete locks, and are those actions logged?\nWhat review occurs before expiration or manual removal?\nIs the locked database the authoritative evidence copy, or must a verified export also be preserved?\n\nDSE recommendation: require a lock record and controlled release\nThe following steps are DSE recommendations based on the cited source.\nAssign each lock a unique case identifier, accountable owner, approving authority, reason, camera and time scope, creation date, review date, and expected release condition. Separate permission to view video from permission to delete a lock. Use the narrowest defensible interval, while preserving enough context to avoid misleading fragments.\nReview open locks on a defined cadence with records, legal, security, and storage owners. Before shortening or deleting one, confirm authorization, determine whether ordinary retention has elapsed, verify any required export and hash, and record the effect on storage. Emergency deletion to recover capacity should follow the same escalation and documentation, not an undocumented administrator shortcut.\nVerification and evidence\nRetain the lock register, approval, XProtect status export or screenshots, audit events, storage-capacity trend, periodic review record, and release authorization. For a controlled test case, show that locked video survives normal retention and document exactly what occurs after authorized release. Never use production evidence merely to test deletion behavior.\nOfficial references\n\nXProtect evidence locks – Milestone Systems",
        "content_markdown": "Bottom line: an evidence lock is an exception to ordinary retention, not a substitute for case management. Without ownership and release controls, locks can accumulate indefinitely; if a lock is removed after ordinary retention has expired, the protected recording may become eligible for deletion.\n\n## Source fact: evidence locks override normal retention for selected recordings\n\nMilestone’s [XProtect evidence-lock documentation](https://doc.milestonesys.com/2025r2/en-US/wp_storage_arch/evidence_lock.htm) explains that evidence locks in XProtect Corporate protect selected recordings from the normal retention process. The system supports permissions for evidence-lock operations, a configured lock duration, and status information. The documentation also warns that deleting a lock can result in deletion of recordings that are already older than the standard retention period.\n\nThe important operational event is therefore not only creation. Extension, expiration, and removal can change whether the last retained copy continues to exist.\n\n## Source boundary and applicability\n\nThe page documents a Milestone feature; it does not determine legal-hold scope, evidence admissibility, chain of custody, or required retention. Availability and behavior depend on XProtect edition, version, permissions, storage configuration, and the recorded devices included. Counsel or the designated records authority should define binding hold requirements.\n\n## Applicability questions\n\n- What event, case, request, or obligation authorizes the lock?\n\n- Which cameras and exact time interval are necessary, including pre-event and post-event context?\n\n- Who may create, extend, export, and delete locks, and are those actions logged?\n\n- What review occurs before expiration or manual removal?\n\n- Is the locked database the authoritative evidence copy, or must a verified export also be preserved?\n\n## DSE recommendation: require a lock record and controlled release\n\nThe following steps are DSE recommendations based on the cited source.\n\nAssign each lock a unique case identifier, accountable owner, approving authority, reason, camera and time scope, creation date, review date, and expected release condition. Separate permission to view video from permission to delete a lock. Use the narrowest defensible interval, while preserving enough context to avoid misleading fragments.\n\nReview open locks on a defined cadence with records, legal, security, and storage owners. Before shortening or deleting one, confirm authorization, determine whether ordinary retention has elapsed, verify any required export and hash, and record the effect on storage. Emergency deletion to recover capacity should follow the same escalation and documentation, not an undocumented administrator shortcut.\n\n## Verification and evidence\n\nRetain the lock register, approval, XProtect status export or screenshots, audit events, storage-capacity trend, periodic review record, and release authorization. For a controlled test case, show that locked video survives normal retention and document exactly what occurs after authorized release. Never use production evidence merely to test deletion behavior.\n\n## Official references\n\n- [XProtect evidence locks](https://doc.milestonesys.com/2025r2/en-US/wp_storage_arch/evidence_lock.htm) – Milestone Systems"
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions/",
                "url": "https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-25"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Govern evidence locks as retention exceptions, not permanent pins",
                        "item": "https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions/#article",
                "identifier": "https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions/",
                "url": "https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions/",
                "headline": "Govern evidence locks as retention exceptions, not permanent pins",
                "description": "An evidence lock can preserve selected video beyond normal retention. Define who may create, extend, review, and remove each lock before storage and…",
                "abstract": "An evidence lock can preserve selected video beyond normal retention. Define who may create, extend, review, and remove each lock before storage and legal obligations collide.",
                "articleBody": "Bottom line: an evidence lock is an exception to ordinary retention, not a substitute for case management. Without ownership and release controls, locks can accumulate indefinitely; if a lock is removed after ordinary retention has expired, the protected recording may become eligible for deletion.\nSource fact: evidence locks override normal retention for selected recordings\nMilestone’s XProtect evidence-lock documentation explains that evidence locks in XProtect Corporate protect selected recordings from the normal retention process. The system supports permissions for evidence-lock operations, a configured lock duration, and status information. The documentation also warns that deleting a lock can result in deletion of recordings that are already older than the standard retention period.\nThe important operational event is therefore not only creation. Extension, expiration, and removal can change whether the last retained copy continues to exist.\nSource boundary and applicability\nThe page documents a Milestone feature; it does not determine legal-hold scope, evidence admissibility, chain of custody, or required retention. Availability and behavior depend on XProtect edition, version, permissions, storage configuration, and the recorded devices included. Counsel or the designated records authority should define binding hold requirements.\nApplicability questions\n\nWhat event, case, request, or obligation authorizes the lock?\nWhich cameras and exact time interval are necessary, including pre-event and post-event context?\nWho may create, extend, export, and delete locks, and are those actions logged?\nWhat review occurs before expiration or manual removal?\nIs the locked database the authoritative evidence copy, or must a verified export also be preserved?\n\nDSE recommendation: require a lock record and controlled release\nThe following steps are DSE recommendations based on the cited source.\nAssign each lock a unique case identifier, accountable owner, approving authority, reason, camera and time scope, creation date, review date, and expected release condition. Separate permission to view video from permission to delete a lock. Use the narrowest defensible interval, while preserving enough context to avoid misleading fragments.\nReview open locks on a defined cadence with records, legal, security, and storage owners. Before shortening or deleting one, confirm authorization, determine whether ordinary retention has elapsed, verify any required export and hash, and record the effect on storage. Emergency deletion to recover capacity should follow the same escalation and documentation, not an undocumented administrator shortcut.\nVerification and evidence\nRetain the lock register, approval, XProtect status export or screenshots, audit events, storage-capacity trend, periodic review record, and release authorization. For a controlled test case, show that locked video survives normal retention and document exactly what occurs after authorized release. Never use production evidence merely to test deletion behavior.\nOfficial references\n\nXProtect evidence locks – Milestone Systems",
                "datePublished": "2026-08-25T21:36:11+00:00",
                "dateModified": "2026-08-25T21:36:16+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Govern evidence locks as retention exceptions, not permanent pins"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Video Surveillance"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Video Surveillance",
                    "Playbook",
                    "Important priority"
                ],
                "genre": "Playbook",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Video Surveillance",
                        "url": "https://update.dsesecurity.com/topic/video-surveillance/"
                    }
                ],
                "wordCount": 429,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "XProtect evidence locks",
                    "url": "https://doc.milestonesys.com/2025r2/en-US/wp_storage_arch/evidence_lock.htm"
                }
            }
        ]
    }
}