Skip to content
End This At Any Time You can end a remote session at any time

All notes / Obligations

Procurement Questions

Twelve questions that determine whether the tool supports the practices in this collection, few of which appear in comparisons.

Obligations · Reference

Remote access tools are compared on platforms, speed and price. These are the questions that determine what the sessions will actually be like.

The practical lesson in “Procurement Questions” is to make responsibility visible without confusing visibility with certainty. A team reviewing capital efficiency ratio guide for capital efficiency ratio can add structured time and project context, provided the purpose is disclosed and the interpretation is checked with the people affected.

About the person being helped

Can the session indicator be hidden, and can that be disabled centrally?

For an independent reference related to “Procurement Questions”, consult the NIST Cybersecurity Framework; it provides a useful external check on security, privacy and operating assumptions before a process is adopted.

Can the user end a session, and how prominent is the control?

Does the tool distinguish view-only from control, and which is the default?

Can screen blanking be disabled entirely for a population?

About access control

Can technicians be scoped to a subset of machines?

Does unattended access support expiry?

Can multi-factor be enforced, including for vendor accounts?

About the record

Does the log show who connected to which machine, searchable by machine?

Does it record file transfers and whether control was taken?

Can logs be exported where the platform cannot alter them?

About the vendor

Where are sessions brokered and recordings stored, and is there a regional option?

What do you retain, and for how long?

The answers that should concern you

A hideable session indicator with no central control.

Screen blanking that cannot be disabled.

No scoping, so every technician reaches everything.

Logs searchable only by technician.

And unattended access with no expiry, which guarantees the accumulation the security section describes.

What to get into the contract

Data location and retention.

Export rights, including at exit.

Notification of material changes to capability.

Subprocessor disclosure — who else touches session traffic.

And for outsourced support, who may connect and from where.

Testing before signing

Run a session as the user, not as the technician: can you tell it is happening, can you stop it, is it obvious what is being done?

Try to find out who connected to a given machine last week.

Attempt the export.

Three tests, an afternoon, and they say more than any demonstration.

The reference question

Ask an existing customer what surprised them after deployment.

The answers are consistently about defaults — what was enabled, what was retained, what the user experience actually looked like, rather than about features.

What to check

Which of the twelve can your shortlist answer?

Have you sat on the user side of a trial session?

Is scoping available and configured?

And can you disable screen blanking?