Skip to content
Sections
All notes

All notes · Wipe

Wipe: the Irreversible Action

The one command in the platform that cannot be undone, and the controls that should sit around it.

Wipe · Analysis

Everything else device management does can be changed back. A wipe cannot. That asymmetry justifies treating it differently from every other capability.

What it destroys

On a selective wipe: work data and work applications.

On a full wipe: everything on the device, including photographs, messages, notes, downloaded media and anything not backed up.

For an independent baseline relevant to “Wipe: the Irreversible Action”, the NCSC mobile-device guidance is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.

And on a personal device, the second includes a great deal that does not belong to the organisation.

Why it goes wrong

Wrong device selected from a list of similar names.

Ownership model not visible at the point of action.

Full wipe chosen when selective was meant, because they sit next to each other.

A bulk action applied to a filter that matched more than intended.

And an urgent request acted on without verification, which is the loss-and-theft case and has its own note.

The controls that belong around it

Named individuals only, not a role everybody holds.

Selective as the default, with full requiring a second approval.

Ownership model displayed at the point of action.

A confirmation that requires typing the device identifier rather than clicking.

And a log that somebody reviews.

Structural beats procedural

On personal devices, remove the capability rather than controlling it.

A work profile makes full wipe unavailable, which is stronger than a rule saying do not use it.

Every procedural control depends on somebody being careful at the wrong moment, and that is exactly when they will not be.

The bulk action problem

Platforms allow actions against a filtered set.

A filter that is wrong by one condition can include hundreds of devices.

Check the count before confirming — if you expect three and it says three hundred, stop.

This is the same discipline as any wide-scope operation and it is more unforgiving here.

Testing the process

Issue a selective wipe on a test device and watch what happens.

Most administrators have never seen the user experience of the action they can issue.

Fifteen minutes, and it changes how carefully the capability is held.

Recording

Every wipe: device, type, who authorised, who issued, why, confirmation.

Retained.

Because the question "did you wipe my phone" will eventually be asked, and the answer should not depend on somebody's memory.

What to check

Who can issue a full wipe, by name?

Is the ownership model visible where the action is taken?

Is selective the default?

And has anybody seen what a wipe looks like from the user's side?