NIRMION FIELD GUIDES · NO PRODUCTIVITY GURU REQUIRED
A little less “where did I put that tab?”
Practical guides for real-world jobs: what to prepare, what to do next, and which Nirmion tools can help with the fiddly bits.
PICK A QUEST
Find your next “done”.
Each guide links its sources and the matching live tools. A broken map is no fun for anyone.
Create and verify a Google Takeout archive
Google Takeout creates a copy of selected data from supported Google products. This guide helps you scope the export, request it from the signed-in Google Account, download the resulting archive, compare its contents with your selection, and store it safely. Google says downloading does not delete the source data, an export may omit some changes made after the request, and managed work or school accounts can be restricted by an administrator. Use the Data Inventory Template only for generic product names, export categories and status; do not enter your Google email, personal records, filenames, account identifiers or archive contents. Keep the actual archive on storage you control and protect it as sensitive personal data.
Open the step-by-step guide Security & PrivacyMaintain a credential inventory without copying secrets
Teams cannot rotate or revoke credentials reliably if they do not know which service uses them, who owns them or how to recover safely. This workflow tracks only non-secret metadata in an approved, access-controlled system; never paste passwords, API tokens, private keys, recovery codes or secret-bearing connection strings into the register, a ticket or a Nirmion tool. OWASP, NIST, GitHub and AWS guidance below supports secure lifecycle and least-privilege practices; follow the documentation for the actual provider and your organization?s policy. Nirmion?s Access Review Checklist helps review who can access systems, but it does not manage credentials or store secrets.
Open the step-by-step guide Security & PrivacyPlan and test Microsoft Entra emergency access accounts
This platform-specific guide follows Microsoft's current emergency-access account recommendations for Microsoft Entra ID. It is for authorized tenant identity and security administrators; emergency accounts are highly privileged and reserved for genuine lockout or service-outage scenarios, not routine administration. Microsoft's current Learn guidance calls for at least two cloud-only emergency accounts, phishing-resistant authentication, protected credential custody, sign-in monitoring, and regular validation. Confirm the live documentation and your tenant's licensing, Conditional Access, authentication, logging, and governance settings before changing privileged access. Keep real account names, object IDs, credentials, security keys, recovery material, and tenant details inside approved administrator systems, never in a shareable worksheet or public Nirmion tool.
Open the step-by-step guide Security & PrivacyPrepare and erase an iPhone before sale
Follow this Apple-specific process before selling, trading in, or giving away an iPhone. Make and check a backup, transfer the information and phone service you need, then use Apple's own sign-out and erase controls. Erasing the phone does not delete the copy already stored in iCloud. Menu labels differ by iOS version, and an iPhone that is managed by an employer or organization may require its administrator to release it; use the current Apple instructions and organizational process for those cases. Never give a buyer your Apple Account password, device passcode, verification code, or backup encryption password.
Open the step-by-step guide Security & PrivacyRecord a suspicious URL or file indicator without opening it
Use this bounded process when someone reports a suspicious URL, domain, IP address, or file hash and your role is to document it safely. Do not click, paste into a browser, resolve, download, or test the indicator. A text record is not a malware verdict, and a reputation result is not proof that a destination is safe. If anyone already opened the link, entered credentials, approved a prompt, or downloaded a file, switch to your organization?s incident-response process immediately.
Open the step-by-step guide Security & PrivacyRecord and verify a downloaded file's checksum
Use this workflow when you need a reproducible integrity check for a downloaded release, backup, dataset or other file. First establish where the expected digest came from; then compute the same algorithm over the original bytes, compare the complete values and document what was actually verified. A plain checksum comparison can detect a mismatch against a trusted reference, but cannot authenticate a publisher unless the reference itself is authenticated, and it does not determine whether a matching file is safe. Nirmion's Checksum File Generator and Checksum Verifier can help with local digest calculation and comparison; review each tool's current page and limits before relying on it.
Open the step-by-step guide Security & PrivacyRespond to a suspected phishing incident
Use this guide after receiving a suspicious email, text, or message, or after someone has interacted with it. Stop further interaction, report through a trusted channel, and choose the response branch based on what was exposed. If a work account, managed device, payment, or business email compromise may be involved, notify the responsible security or finance team immediately and follow its incident plan. This guide does not investigate messages or replace provider recovery instructions. Never paste the message, live link, password, code, customer data, or private incident details into a public tool.
Open the step-by-step guide Security & PrivacyReview an organization’s account inventory without collecting secrets
This procedure reviews an organization’s account inventory; it is not a password vault or a credential-rotation service. Use the organization’s approved identity, directory, HR and application administration systems to identify accounts and verify authorization. Record only the account metadata needed for ownership and review, and never copy passwords, API keys, recovery codes, session tokens or authentication secrets into the inventory. CIS Controls v8.1 Safeguard 5.1 calls for user, administrator and service accounts to be inventoried and active accounts checked for authorization at least quarterly; it lists person, username, start/stop dates and department as minimum user-account data. Safeguard 5.5 separately calls for service-account owner, review date and purpose. Adapt the schedule to your organization’s policy and risk. Keep names and usernames in access-controlled company systems, not in Nirmion or a public page.
Open the step-by-step guide Security & PrivacyReview Google Drive access for a sensitive shared document
A document can be exposed through a direct invitation, a broad link setting, a Google Group or permissions inherited from a parent folder. Reviewing one sensitive item means checking those paths and their owners before changing anything. This workflow is for Google Drive; Workspace administrators may have additional audit-log controls that ordinary users cannot see. Follow your organization?s access policy and preserve required business access. Nirmion?s Access Review Checklist helps record reviewers and actions, but changes must be made and verified in the Google account that owns or administers the file.
Open the step-by-step guide Security & PrivacyRevoke a lost or compromised Indian Digital Signature Certificate
Treat a missing DSC token, exposed token PIN or suspected private-key compromise as a security incident. A Digital Signature Certificate is issued by a licensed Certifying Authority under India's CCA framework; the subscriber's revocation request and identity checks are handled by the issuer under its current Certificate Policy and Certification Practice Statement. There is no single universal request form or turnaround time. Do not email a private key, token PIN, one-time code or token itself to a support contact. Stop using a questionable certificate, preserve evidence, and work only through verified CA and organization channels. If the certificate was used to sign an unauthorized filing or agreement, contact the affected portal/organization and qualified legal or security advisers promptly; this workflow does not decide the legal effect of a signature.
Open the step-by-step guide Security & PrivacySafely redact and verify a PDF before sharing
For a person or organization preparing a PDF copy for a permitted disclosure. First confirm who is entitled to receive which information under the applicable law, order, contract and internal policy; this workflow is not legal advice and does not decide what should be withheld. Keep the source unchanged, work on a clearly named copy, use a genuine redaction operation that removes content rather than drawing black shapes over it, and inspect hidden information as well as the visible pages. Nirmion Redact PDF is narrowly scoped to one exact searchable phrase; it cannot safely handle every image, irregular region, hidden object or legal redaction decision. Before using any online tool with a document, confirm that its data-handling terms fit the information and your organization's rules; use an approved offline editor for restricted material.
Open the step-by-step guide Security & PrivacySet up and verify GitHub account two-factor authentication
This guide covers two-factor authentication (2FA) for a GitHub.com personal account. GitHub recommends an authenticator app such as TOTP as the primary method and a security key as a backup; passkeys and GitHub Mobile can also be available. Secure recovery before closing your existing session. Organization or enterprise-managed accounts may be controlled by an administrator, and disabling 2FA can remove access to organization resources.
Open the step-by-step guide Security & PrivacyVerify an Ubuntu ISO with its signed SHA-256 checksum
A matching checksum is meaningful only when the expected checksum comes from a trusted source. For Ubuntu installation media, Canonical publishes a SHA-256 manifest and a detached GPG signature; verify the signing key and manifest first, then compare the downloaded ISO with the signed manifest. This guide covers Ubuntu ISO images, not third-party software or every cloud image format. Nirmion's Hash Verifier can compare a local file with the expected digest in your browser, but it cannot establish that the checksum or signing key is authentic. Never skip the GPG verification step or run/flash an image after a mismatch.
Open the step-by-step guide SEO & MarketingBuild a Measurement Plan for a Social Campaign
For a campaign owner measuring one defined social campaign across organic posts, paid ads or both. Decide which channels are in scope and use each platform?s own current reporting definitions. A view, reach, impression, click and conversion can be counted differently by platform and should not be combined without a documented rule. This plan organizes measurement; it does not attribute causation or replace platform privacy, consent, analytics or advertising rules. Use aggregate campaign reporting and do not place personal data or access tokens in public Nirmion tools.
Open the step-by-step guide SEO & MarketingBuild a useful local business location page with structured data
For a business owner or site editor creating or improving one page for one real customer-facing location. The aim is to help people confirm what the location offers, where it is, when it is open, and how to contact it, then give search engines accurate structured data. This workflow is not a ranking trick: markup does not guarantee a rich result or indexing, and a thin page made only to target city keywords can violate Google's spam policies. Service-area, online-only, virtual-office, practitioner, department, and multi-location cases need their applicable guidance. The Nirmion schema generator creates a starting draft; the business owner must verify every fact and have the site's implementer review the markup.
Open the step-by-step guide SEO & MarketingCreate a content brief that serves a real audience
A useful content brief gives a writer a clear reader, task, evidence plan and quality bar. This workflow starts with a real audience question, checks search language and existing site data, then sets a distinctive angle and a practical review checklist. Google Trends shows relative interest rather than absolute search volume, and Search Console only reports performance for a verified property. Neither data source nor this process guarantees traffic or ranking. Use Content Brief Generator to organize the inputs; a person still needs to verify claims, audience fit and originality.
Open the step-by-step guide SEO & MarketingCreate a fact-checked U.S. press release
A press release is a public statement that can be republished, quoted or treated as marketing. Start with a verifiable announcement and a named approver, then draft for readers and journalists rather than filling a template with hype. Claims about products, results or endorsements need support; public-company financial or material announcements may also require securities-law review. Nirmion's Press Release Builder can organize a draft, but it cannot verify facts, obtain quote permission, assess legal compliance or distribute the release. This workflow covers general U.S. organizational announcements and flags specialist review where the release involves regulated claims, securities, health or financial results.
Open the step-by-step guide SEO & MarketingCreate a GA4 campaign URL with UTM parameters
Use this workflow to create and release a tagged URL for a website campaign whose traffic you want to review in Google Analytics 4. You need the approved final landing page, the campaign owner?s naming convention, and a decision about manual tagging versus the ad platform?s auto-tagging. The UTM Builder handles the common source, medium, campaign, term and content fields; it does not validate a GA4 property or configure campaign IDs/platform fields.
Open the step-by-step guide Social MediaCreate a verified product launch post on LinkedIn
For a U.S. business announcing one product or a material product update to a professional audience on LinkedIn. This workflow covers the content draft and checks; it does not verify the product, publish the post, guarantee reach or replace legal/compliance review for regulated products.
Open the step-by-step guide Social MediaMeasure a before-and-after social post without overstating results
For a marketer or business owner reviewing a social post that shows a before-and-after comparison. First establish what the images and accompanying words communicate to a typical viewer; measurable product, health, safety or performance claims need support before an ad runs. Then define the campaign question, compare like periods and formats, inspect native platform metrics and use tagged destination links for website visits. A change in reach, clicks or sales after a post does not by itself show that the post caused the change or substantiate the result depicted. Legal requirements and platform metrics vary; this guide gives a measurement method, not legal advice or an outcome guarantee.
Open the step-by-step guide Social MediaRepurpose a before-and-after comparison for a new post
Use this U.S.-focused editorial workflow when adapting an already approved before-and-after comparison for a new social post, format or placement. Before-and-after imagery can imply a result claim even when the caption does not say it outright. Confirm rights and evidence again for the new use; if the product, subject, context or claim has changed, pause for the appropriate owner or compliance reviewer.
Open the step-by-step guide Tax & ComplianceEstimate India freelance income tax from verified records
Freelance income can involve multiple clients, payment platforms, tax deductions at source and business expenses. This India-focused workflow organizes the evidence before an estimate and flags the tax-year transition: for AY 2026?27 the Income Tax Department says to select the Income-tax Act, 1961, while income earned from 1 April 2026 is handled as Tax Year 2026?27 under the Income-tax Act, 2025. Your residency, work type and filing route affect the result. Nirmion?s Tax Document Organizer tracks records locally; it does not decide deductibility or file a return.
Open the step-by-step guide Tax & CompliancePlan and Pay U.S. Federal Estimated Taxes for 2026
For U.S. individuals with self-employment, investment, rental or other income that may not have enough withholding. The IRS 2026 Publication 505 and Form 1040-ES are the controlling sources for the current-year worksheets, due dates and rules. Whether you must pay, how much, and whether a penalty applies depend on your income, withholding, filing history, credits, annualized income and special circumstances. This workflow helps organize a review; it is not tax advice or a calculation of your liability. Do not enter Social Security numbers, employer records, detailed income, bank data or IRS account credentials in public Nirmion tools.
Open the step-by-step guide Tax & CompliancePrepare and e-file an Indian individual income tax return
Use the Income Tax Department's own form-selection and e-filing flow to prepare an Indian individual return, reconcile the supporting statements, submit it and complete verification. The correct ITR, tax treatment and filing due date depend on the assessment year and personal facts; this guide does not calculate your liability or choose deductions for you.
Open the step-by-step guide