What you need to know
An evidence lock can preserve selected video beyond normal retention. Define who may create, extend, review, and remove each lock before storage and legal obligations collide.
Potentially affected
XProtect Corporate deployments using evidence locks to preserve recordings for investigations, litigation, regulatory review, or internal holds.
DSE recommendation
Require a case owner, scope, reason, expiration, access restriction, periodic review, and witnessed release for every evidence lock.
Bottom line: an evidence lock is an exception to ordinary retention, not a substitute for case management. Without ownership and release controls, locks can accumulate indefinitely; if a lock is removed after ordinary retention has expired, the protected recording may become eligible for deletion.
Source fact: evidence locks override normal retention for selected recordings
Milestone’s XProtect evidence-lock documentation explains that evidence locks in XProtect Corporate protect selected recordings from the normal retention process. The system supports permissions for evidence-lock operations, a configured lock duration, and status information. The documentation also warns that deleting a lock can result in deletion of recordings that are already older than the standard retention period.
The important operational event is therefore not only creation. Extension, expiration, and removal can change whether the last retained copy continues to exist.
Source boundary and applicability
The page documents a Milestone feature; it does not determine legal-hold scope, evidence admissibility, chain of custody, or required retention. Availability and behavior depend on XProtect edition, version, permissions, storage configuration, and the recorded devices included. Counsel or the designated records authority should define binding hold requirements.
Applicability questions
- What event, case, request, or obligation authorizes the lock?
- Which cameras and exact time interval are necessary, including pre-event and post-event context?
- Who may create, extend, export, and delete locks, and are those actions logged?
- What review occurs before expiration or manual removal?
- Is the locked database the authoritative evidence copy, or must a verified export also be preserved?
DSE recommendation: require a lock record and controlled release
The following steps are DSE recommendations based on the cited source.
Assign each lock a unique case identifier, accountable owner, approving authority, reason, camera and time scope, creation date, review date, and expected release condition. Separate permission to view video from permission to delete a lock. Use the narrowest defensible interval, while preserving enough context to avoid misleading fragments.
Review open locks on a defined cadence with records, legal, security, and storage owners. Before shortening or deleting one, confirm authorization, determine whether ordinary retention has elapsed, verify any required export and hash, and record the effect on storage. Emergency deletion to recover capacity should follow the same escalation and documentation, not an undocumented administrator shortcut.
Verification and evidence
Retain the lock register, approval, XProtect status export or screenshots, audit events, storage-capacity trend, periodic review record, and release authorization. For a controlled test case, show that locked video survives normal retention and document exactly what occurs after authorized release. Never use production evidence merely to test deletion behavior.
Official references
- XProtect evidence locks – Milestone Systems
Review the official source
XProtect evidence locks · Verified August 25, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE