Define the record being collected
A command event can store the actor, target, timestamp and result. A terminal recording captures an output stream. A desktop recording captures a visual session. Each has different evidence and storage requirements.
Teleport documents these distinctions and the limitations of terminal capture. Establish the required evidence before describing a record as a complete audit.
Limit the data people can retrieve
Logs and recordings can contain credentials, personal information and customer records. Define retention, redaction, access and exports with the responsible owner.
An encrypted store needs an access and recovery policy. A lost key can make an intact archive unreadable.
Test verification and handover
The test should include a missing event, changed stored content, failed verification and unauthorized export. Signed or chained records should expose a failed check clearly.
The DSDillon Terminal source includes signed activity record functions. They support review within their implemented coverage. Independent certification and complete host surveillance are separate matters.
Before you begin
Can a recording prove every command executed?
Terminal capture has limits. Define the evidence required and consider additional operating system records where needed.
Can exports be linked to tickets?
Yes. A permitted export or event summary can be linked to the relevant support or change request.
DSDillon / 26 September 2026

