Nirmion
HelpLog in Find a tool

NIRMION FIELD GUIDES · NO PRODUCTIVITY GURU REQUIRED

A little less “where did I put that tab?”

Practical guides for real-world jobs: what to prepare, what to do next, and which Nirmion tools can help with the fiddly bits.

250reviewed guides on the shelf

PICK A QUEST

Find your next “done”.

Each guide links its sources and the matching live tools. A broken map is no fun for anyone.

Security & Privacy

Create and verify a Google Takeout archive

Google Takeout creates a copy of selected data from supported Google products. This guide helps you scope the export, request it from the signed-in Google Account, download the resulting archive, compare its contents with your selection, and store it safely. Google says downloading does not delete the source data, an export may omit some changes made after the request, and managed work or school accounts can be restricted by an administrator. Use the Data Inventory Template only for generic product names, export categories and status; do not enter your Google email, personal records, filenames, account identifiers or archive contents. Keep the actual archive on storage you control and protect it as sensitive personal data.

Open the step-by-step guide
Security & Privacy

Maintain a credential inventory without copying secrets

Teams cannot rotate or revoke credentials reliably if they do not know which service uses them, who owns them or how to recover safely. This workflow tracks only non-secret metadata in an approved, access-controlled system; never paste passwords, API tokens, private keys, recovery codes or secret-bearing connection strings into the register, a ticket or a Nirmion tool. OWASP, NIST, GitHub and AWS guidance below supports secure lifecycle and least-privilege practices; follow the documentation for the actual provider and your organization?s policy. Nirmion?s Access Review Checklist helps review who can access systems, but it does not manage credentials or store secrets.

Open the step-by-step guide
Security & Privacy

Plan and test Microsoft Entra emergency access accounts

This platform-specific guide follows Microsoft's current emergency-access account recommendations for Microsoft Entra ID. It is for authorized tenant identity and security administrators; emergency accounts are highly privileged and reserved for genuine lockout or service-outage scenarios, not routine administration. Microsoft's current Learn guidance calls for at least two cloud-only emergency accounts, phishing-resistant authentication, protected credential custody, sign-in monitoring, and regular validation. Confirm the live documentation and your tenant's licensing, Conditional Access, authentication, logging, and governance settings before changing privileged access. Keep real account names, object IDs, credentials, security keys, recovery material, and tenant details inside approved administrator systems, never in a shareable worksheet or public Nirmion tool.

Open the step-by-step guide
Security & Privacy

Prepare and erase an iPhone before sale

Follow this Apple-specific process before selling, trading in, or giving away an iPhone. Make and check a backup, transfer the information and phone service you need, then use Apple's own sign-out and erase controls. Erasing the phone does not delete the copy already stored in iCloud. Menu labels differ by iOS version, and an iPhone that is managed by an employer or organization may require its administrator to release it; use the current Apple instructions and organizational process for those cases. Never give a buyer your Apple Account password, device passcode, verification code, or backup encryption password.

Open the step-by-step guide
Security & Privacy

Record a suspicious URL or file indicator without opening it

Use this bounded process when someone reports a suspicious URL, domain, IP address, or file hash and your role is to document it safely. Do not click, paste into a browser, resolve, download, or test the indicator. A text record is not a malware verdict, and a reputation result is not proof that a destination is safe. If anyone already opened the link, entered credentials, approved a prompt, or downloaded a file, switch to your organization?s incident-response process immediately.

Open the step-by-step guide
Security & Privacy

Record and verify a downloaded file's checksum

Use this workflow when you need a reproducible integrity check for a downloaded release, backup, dataset or other file. First establish where the expected digest came from; then compute the same algorithm over the original bytes, compare the complete values and document what was actually verified. A plain checksum comparison can detect a mismatch against a trusted reference, but cannot authenticate a publisher unless the reference itself is authenticated, and it does not determine whether a matching file is safe. Nirmion's Checksum File Generator and Checksum Verifier can help with local digest calculation and comparison; review each tool's current page and limits before relying on it.

Open the step-by-step guide
Security & Privacy

Respond to a suspected phishing incident

Use this guide after receiving a suspicious email, text, or message, or after someone has interacted with it. Stop further interaction, report through a trusted channel, and choose the response branch based on what was exposed. If a work account, managed device, payment, or business email compromise may be involved, notify the responsible security or finance team immediately and follow its incident plan. This guide does not investigate messages or replace provider recovery instructions. Never paste the message, live link, password, code, customer data, or private incident details into a public tool.

Open the step-by-step guide
Security & Privacy

Review an organization’s account inventory without collecting secrets

This procedure reviews an organization’s account inventory; it is not a password vault or a credential-rotation service. Use the organization’s approved identity, directory, HR and application administration systems to identify accounts and verify authorization. Record only the account metadata needed for ownership and review, and never copy passwords, API keys, recovery codes, session tokens or authentication secrets into the inventory. CIS Controls v8.1 Safeguard 5.1 calls for user, administrator and service accounts to be inventoried and active accounts checked for authorization at least quarterly; it lists person, username, start/stop dates and department as minimum user-account data. Safeguard 5.5 separately calls for service-account owner, review date and purpose. Adapt the schedule to your organization’s policy and risk. Keep names and usernames in access-controlled company systems, not in Nirmion or a public page.

Open the step-by-step guide
Security & Privacy

Review Google Drive access for a sensitive shared document

A document can be exposed through a direct invitation, a broad link setting, a Google Group or permissions inherited from a parent folder. Reviewing one sensitive item means checking those paths and their owners before changing anything. This workflow is for Google Drive; Workspace administrators may have additional audit-log controls that ordinary users cannot see. Follow your organization?s access policy and preserve required business access. Nirmion?s Access Review Checklist helps record reviewers and actions, but changes must be made and verified in the Google account that owns or administers the file.

Open the step-by-step guide
Security & Privacy

Revoke a lost or compromised Indian Digital Signature Certificate

Treat a missing DSC token, exposed token PIN or suspected private-key compromise as a security incident. A Digital Signature Certificate is issued by a licensed Certifying Authority under India's CCA framework; the subscriber's revocation request and identity checks are handled by the issuer under its current Certificate Policy and Certification Practice Statement. There is no single universal request form or turnaround time. Do not email a private key, token PIN, one-time code or token itself to a support contact. Stop using a questionable certificate, preserve evidence, and work only through verified CA and organization channels. If the certificate was used to sign an unauthorized filing or agreement, contact the affected portal/organization and qualified legal or security advisers promptly; this workflow does not decide the legal effect of a signature.

Open the step-by-step guide
Security & Privacy

Safely redact and verify a PDF before sharing

For a person or organization preparing a PDF copy for a permitted disclosure. First confirm who is entitled to receive which information under the applicable law, order, contract and internal policy; this workflow is not legal advice and does not decide what should be withheld. Keep the source unchanged, work on a clearly named copy, use a genuine redaction operation that removes content rather than drawing black shapes over it, and inspect hidden information as well as the visible pages. Nirmion Redact PDF is narrowly scoped to one exact searchable phrase; it cannot safely handle every image, irregular region, hidden object or legal redaction decision. Before using any online tool with a document, confirm that its data-handling terms fit the information and your organization's rules; use an approved offline editor for restricted material.

Open the step-by-step guide
Security & Privacy

Set up and verify GitHub account two-factor authentication

This guide covers two-factor authentication (2FA) for a GitHub.com personal account. GitHub recommends an authenticator app such as TOTP as the primary method and a security key as a backup; passkeys and GitHub Mobile can also be available. Secure recovery before closing your existing session. Organization or enterprise-managed accounts may be controlled by an administrator, and disabling 2FA can remove access to organization resources.

Open the step-by-step guide
Security & Privacy

Verify an Ubuntu ISO with its signed SHA-256 checksum

A matching checksum is meaningful only when the expected checksum comes from a trusted source. For Ubuntu installation media, Canonical publishes a SHA-256 manifest and a detached GPG signature; verify the signing key and manifest first, then compare the downloaded ISO with the signed manifest. This guide covers Ubuntu ISO images, not third-party software or every cloud image format. Nirmion's Hash Verifier can compare a local file with the expected digest in your browser, but it cannot establish that the checksum or signing key is authentic. Never skip the GPG verification step or run/flash an image after a mismatch.

Open the step-by-step guide
SEO & Marketing

Build a Measurement Plan for a Social Campaign

For a campaign owner measuring one defined social campaign across organic posts, paid ads or both. Decide which channels are in scope and use each platform?s own current reporting definitions. A view, reach, impression, click and conversion can be counted differently by platform and should not be combined without a documented rule. This plan organizes measurement; it does not attribute causation or replace platform privacy, consent, analytics or advertising rules. Use aggregate campaign reporting and do not place personal data or access tokens in public Nirmion tools.

Open the step-by-step guide
SEO & Marketing

Build a useful local business location page with structured data

For a business owner or site editor creating or improving one page for one real customer-facing location. The aim is to help people confirm what the location offers, where it is, when it is open, and how to contact it, then give search engines accurate structured data. This workflow is not a ranking trick: markup does not guarantee a rich result or indexing, and a thin page made only to target city keywords can violate Google's spam policies. Service-area, online-only, virtual-office, practitioner, department, and multi-location cases need their applicable guidance. The Nirmion schema generator creates a starting draft; the business owner must verify every fact and have the site's implementer review the markup.

Open the step-by-step guide
SEO & Marketing

Create a content brief that serves a real audience

A useful content brief gives a writer a clear reader, task, evidence plan and quality bar. This workflow starts with a real audience question, checks search language and existing site data, then sets a distinctive angle and a practical review checklist. Google Trends shows relative interest rather than absolute search volume, and Search Console only reports performance for a verified property. Neither data source nor this process guarantees traffic or ranking. Use Content Brief Generator to organize the inputs; a person still needs to verify claims, audience fit and originality.

Open the step-by-step guide
SEO & Marketing

Create a fact-checked U.S. press release

A press release is a public statement that can be republished, quoted or treated as marketing. Start with a verifiable announcement and a named approver, then draft for readers and journalists rather than filling a template with hype. Claims about products, results or endorsements need support; public-company financial or material announcements may also require securities-law review. Nirmion's Press Release Builder can organize a draft, but it cannot verify facts, obtain quote permission, assess legal compliance or distribute the release. This workflow covers general U.S. organizational announcements and flags specialist review where the release involves regulated claims, securities, health or financial results.

Open the step-by-step guide
SEO & Marketing

Create a GA4 campaign URL with UTM parameters

Use this workflow to create and release a tagged URL for a website campaign whose traffic you want to review in Google Analytics 4. You need the approved final landing page, the campaign owner?s naming convention, and a decision about manual tagging versus the ad platform?s auto-tagging. The UTM Builder handles the common source, medium, campaign, term and content fields; it does not validate a GA4 property or configure campaign IDs/platform fields.

Open the step-by-step guide
Social Media

Create a verified product launch post on LinkedIn

For a U.S. business announcing one product or a material product update to a professional audience on LinkedIn. This workflow covers the content draft and checks; it does not verify the product, publish the post, guarantee reach or replace legal/compliance review for regulated products.

Open the step-by-step guide
Social Media

Measure a before-and-after social post without overstating results

For a marketer or business owner reviewing a social post that shows a before-and-after comparison. First establish what the images and accompanying words communicate to a typical viewer; measurable product, health, safety or performance claims need support before an ad runs. Then define the campaign question, compare like periods and formats, inspect native platform metrics and use tagged destination links for website visits. A change in reach, clicks or sales after a post does not by itself show that the post caused the change or substantiate the result depicted. Legal requirements and platform metrics vary; this guide gives a measurement method, not legal advice or an outcome guarantee.

Open the step-by-step guide
Social Media

Repurpose a before-and-after comparison for a new post

Use this U.S.-focused editorial workflow when adapting an already approved before-and-after comparison for a new social post, format or placement. Before-and-after imagery can imply a result claim even when the caption does not say it outright. Confirm rights and evidence again for the new use; if the product, subject, context or claim has changed, pause for the appropriate owner or compliance reviewer.

Open the step-by-step guide
Tax & Compliance

Estimate India freelance income tax from verified records

Freelance income can involve multiple clients, payment platforms, tax deductions at source and business expenses. This India-focused workflow organizes the evidence before an estimate and flags the tax-year transition: for AY 2026?27 the Income Tax Department says to select the Income-tax Act, 1961, while income earned from 1 April 2026 is handled as Tax Year 2026?27 under the Income-tax Act, 2025. Your residency, work type and filing route affect the result. Nirmion?s Tax Document Organizer tracks records locally; it does not decide deductibility or file a return.

Open the step-by-step guide
Tax & Compliance

Plan and Pay U.S. Federal Estimated Taxes for 2026

For U.S. individuals with self-employment, investment, rental or other income that may not have enough withholding. The IRS 2026 Publication 505 and Form 1040-ES are the controlling sources for the current-year worksheets, due dates and rules. Whether you must pay, how much, and whether a penalty applies depend on your income, withholding, filing history, credits, annualized income and special circumstances. This workflow helps organize a review; it is not tax advice or a calculation of your liability. Do not enter Social Security numbers, employer records, detailed income, bank data or IRS account credentials in public Nirmion tools.

Open the step-by-step guide
Tax & Compliance

Prepare and e-file an Indian individual income tax return

Use the Income Tax Department's own form-selection and e-filing flow to prepare an Indian individual return, reconcile the supporting statements, submit it and complete verification. The correct ITR, tax treatment and filing due date depend on the assessment year and personal facts; this guide does not calculate your liability or choose deductions for you.

Open the step-by-step guide