Skip to content
End This At Any Time You can end a remote session at any time

All notes / Reference

Glossary and Where to Start

Terms used across these notes, defined plainly, and the routes through the collection for the common situations.

Reference · Reference

Attended access — a session somebody approves and can watch. The safer arrangement and the one that should be default.

The practical lesson in “Glossary and Where to Start” is to make responsibility visible without confusing visibility with certainty. A team reviewing explore Monitask for fte meaning can add structured time and project context, provided the purpose is disclosed and the interpretation is checked with the people affected.

Co-browsing — sharing one browser session rather than the whole screen. Narrower exposure, and worth asking for.

For an independent reference related to “Glossary and Where to Start”, consult the ENISA cybersecurity resources; it provides a useful external check on security, privacy and operating assumptions before a process is adopted.

Narration — saying what you are doing as you do it. The only verification available to the person watching.

Screen blanking — hiding the screen from the person whose machine it is. Removes their only oversight and is a standard part of fraud.

Selective scope — limiting which machines a technician can reach. The single highest-value organisational control.

Session indicator — the visible sign that a session is running. A tool where it can be hidden is a monitoring tool.

Unattended access — a connection needing no approval. Necessary, and where the unreviewed exposure accumulates.

View-only — seeing without control. Sufficient more often than it is used.

Terms used loosely elsewhere

"Remote support" covers everything from screen sharing to full unattended control. Ask which.

"Secure" in a product description usually means the connection is encrypted, which is not the risk this collection is about.

"We just need to take a quick look" is how a session with unbounded scope is requested.

And any figure about losses to remote access fraud varies by orders of magnitude depending on who counted.

Where to start

Helping a relative: helping a relative remotely, then setting up a family member safely.

Worried about a phone call somebody had: the remote access scam described, then what to do if it already happened.

Running a support desk: running a support desk that uses it, then technician conduct.

Securing the capability: exposed remote desktop, then unattended access and its risks.

Something went wrong in a session: when the session goes wrong.

If you read only three

The trust problem at the centre of it, because everything else follows from it.

The remote access scam, described, because it is the harm this capability actually causes to people.

And before you connect: what to say, because four sentences change every session you will ever run.

A closing note

No products are named here, deliberately. The tools consolidate, the names date, and naming a legitimate product in a chapter about fraud would misdirect the warning — the rule is about who asked, not about which software.

No fraud statistics, because the available figures are not comparable.

And nothing here is legal advice. Obligations differ by jurisdiction and sector.

What the collection argues

A remote session is a moment when one person trusts another completely and has no means of checking. Watching does not help, because the activity is legible only to the person performing it.

Which means the decision happens before the connection, not during it — and why pressure to connect quickly is the clearest warning there is.

The same tools serve help and harm, and that is not a coincidence: ease of granting access is the feature and the vulnerability, and no configuration separates them.

So the protection is not technical but ritual: what is said before, what is narrated during, what remains after. And the most valuable thing you can give anybody is the knowledge that they can end it at any moment.