Required Operating Practices
Before deployment, assign accountable product, security, privacy, support, and governance owners. Document configuration baselines, approved modules, group structures, retention, access roles, customer separation, support procedures, and incident escalation. Test setup packages and policies with a controlled pilot. A technical success message does not prove that collection, access, or restrictions are appropriate for every employee or endpoint.
When investigating an alert, begin with the narrowest relevant period and data source. Do not search unrelated communications or personal material in the hope of discovering misconduct. Protect exported reports and screenshots from onward sharing. Record the case purpose, reviewer, evidence considered, contextual checks, conclusion, action, and deletion or retention decision. High-risk or disputed cases should involve the appropriate management, privacy, security, human-resources, legal, or customer owner.
Customers should provide a route for users and administrators to report inaccurate classifications, mistaken device assignment, excessive policy, compromised credentials, unexpected remote access, or other concerns. Correct configuration promptly and preserve only evidence needed for a legitimate investigation. Attempts to disable security controls, falsify logs, conceal administrator activity, or retaliate against a good-faith reporter are themselves unacceptable. DeskGate may update this policy to address new risks, capabilities, laws, or abuse patterns.