# Govern evidence locks as retention exceptions, not permanent pins

> An evidence lock can preserve selected video beyond normal retention. Define who may create, extend, review, and remove each lock before storage and legal obligations collide.

- Canonical URL: https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-25T21:36:11+00:00
- Modified: 2026-08-25T21:36:16+00:00
- Last reviewed by DSE: 2026-08-25
- Resource type: Playbook
- DSE priority: Important
- Topics: Cybersecurity, Video Surveillance
- Reading time: 2 minutes

## What you need to know

An evidence lock can preserve selected video beyond normal retention. Define who may create, extend, review, and remove each lock before storage and legal obligations collide.

## Potentially affected

XProtect Corporate deployments using evidence locks to preserve recordings for investigations, litigation, regulatory review, or internal holds.

## DSE recommendation

Require a case owner, scope, reason, expiration, access restriction, periodic review, and witnessed release for every evidence lock.

## Article

Bottom line: an evidence lock is an exception to ordinary retention, not a substitute for case management. Without ownership and release controls, locks can accumulate indefinitely; if a lock is removed after ordinary retention has expired, the protected recording may become eligible for deletion.

## Source fact: evidence locks override normal retention for selected recordings

Milestone’s [XProtect evidence-lock documentation](https://doc.milestonesys.com/2025r2/en-US/wp_storage_arch/evidence_lock.htm) explains that evidence locks in XProtect Corporate protect selected recordings from the normal retention process. The system supports permissions for evidence-lock operations, a configured lock duration, and status information. The documentation also warns that deleting a lock can result in deletion of recordings that are already older than the standard retention period.

The important operational event is therefore not only creation. Extension, expiration, and removal can change whether the last retained copy continues to exist.

## Source boundary and applicability

The page documents a Milestone feature; it does not determine legal-hold scope, evidence admissibility, chain of custody, or required retention. Availability and behavior depend on XProtect edition, version, permissions, storage configuration, and the recorded devices included. Counsel or the designated records authority should define binding hold requirements.

## Applicability questions

- What event, case, request, or obligation authorizes the lock?

- Which cameras and exact time interval are necessary, including pre-event and post-event context?

- Who may create, extend, export, and delete locks, and are those actions logged?

- What review occurs before expiration or manual removal?

- Is the locked database the authoritative evidence copy, or must a verified export also be preserved?

## DSE recommendation: require a lock record and controlled release

The following steps are DSE recommendations based on the cited source.

Assign each lock a unique case identifier, accountable owner, approving authority, reason, camera and time scope, creation date, review date, and expected release condition. Separate permission to view video from permission to delete a lock. Use the narrowest defensible interval, while preserving enough context to avoid misleading fragments.

Review open locks on a defined cadence with records, legal, security, and storage owners. Before shortening or deleting one, confirm authorization, determine whether ordinary retention has elapsed, verify any required export and hash, and record the effect on storage. Emergency deletion to recover capacity should follow the same escalation and documentation, not an undocumented administrator shortcut.

## Verification and evidence

Retain the lock register, approval, XProtect status export or screenshots, audit events, storage-capacity trend, periodic review record, and release authorization. For a controlled test case, show that locked video survives normal retention and document exactly what occurs after authorized release. Never use production evidence merely to test deletion behavior.

## Official references

- [XProtect evidence locks](https://doc.milestonesys.com/2025r2/en-US/wp_storage_arch/evidence_lock.htm) – Milestone Systems

## Primary reference

- Name: XProtect evidence locks
- Authority: doc.milestonesys.com
- URL: https://doc.milestonesys.com/2025r2/en-US/wp_storage_arch/evidence_lock.htm
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Govern evidence locks as retention exceptions, not permanent pins,” DSE Security, https://update.dsesecurity.com/updates/govern-evidence-locks-as-retention-exceptions/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
