THE DRTE FIELD GUIDE / LEARN BY DOING
Documentation: capture the context.
Documentation is the account of what you did, observed, received and changed. It lets someone retrace your work without guessing.
What it means—and why it matters
A record is an item you obtained. Documentation is the explanation that travels with it: who supplied it, when, where, how, and with what limitations. A useful image without a source or date can become an uncheckable claim.
Keep observation separate from explanation. Write “I received a message at 2:14 p.m.” if you observed that. Write “I think it was sent in response to my request” as an interpretation, not an observed fact.
For every item, answer these questions
- Who? Who created it, who supplied it, who collected it, and which people or offices are mentioned? Record roles; keep private contact details in a restricted index.
- What? Describe the item, format, page count or duration, and the exact relevant passage. Include an item ID such as REC-001.
- When? Separate the event, document creation, sending, filing and your receipt dates. Include time zone and whether the time is exact, approximate or unknown.
- Where? Record the agency, original URL, case number, email folder or physical location. Record where your preserved copy is stored.
- Why? State the research question this item may address. Do not turn the reason you collected it into a conclusion about its meaning.
- How? Describe the download, export, photograph, scan or handover; note tools, settings and any missing parts.
- What is uncertain? Record unreadable text, missing attachments, secondhand accounts, disputed dates and the next step needed.
A repeatable collection routine
- Start a dated activity entry before collection. Identify the lawful source and your purpose. If the material is outside your authorization, stop and use an appropriate records request.
- Assign the next item ID. Save the original filename in the intake sheet. Keep the received file in its own ID folder so duplicate filenames do not overwrite one another.
- Preserve the received item and create a separate working copy. Do not annotate, enhance or redact the preserved copy. For device-level evidence or deleted data, obtain specialist help before experimenting.
- Record the collection method, exact source, receipt date, collector and limitations. A screenshot is a capture, not the original document.
- Record later handling: who accessed or received the item, when, why, and which copy. Keep revisions to your notes as dated additions.
- Check the item against the intake sheet. Can another reader find the same page or timestamp? If not, add the missing reference.
Preservation reference: NIST digital evidence preservation guidance (PDF). A copy of a file is not a forensic image of a device; ordinary copying may not preserve all filesystem information.
What to capture for each format
- Web pages / social posts: full URL, displayed author/account, visible posted date, collection time with time zone, surrounding conversation and linked attachments. Save a lawful page copy or print-to-PDF plus screenshots where useful. Record collapsed replies or missing media. A handle can change.
- Email: retain the original message/export with full headers and attachments when available. A forwarded message or PDF omits information. Note sender, recipients, subject, message ID, displayed time and source mailbox.
- Messages: preserve a lawful native export when available and capture surrounding messages, account identifiers and date separators. Note edited/deleted-message indicators and export limits. Avoid collecting unrelated private conversations.
- Photos / video / audio: retain the original received file and surrounding sequence. Note camera or sender information if known, time basis, duration and any conversion. Keep transcripts separate and mark unclear words.
- Paper: note who supplied it, pages and condition. Retain envelopes and attachments together. Scan all sides that carry information; label blank backs in your notes if completeness matters.
- Witness accounts: use their words, note whether firsthand or secondhand, questions asked, date, location and consent. Do not coach an answer. Check recording laws before recording.
Metadata: clues about a file
Metadata means information stored in or around a file: camera fields, document author names, software, GPS tags and timestamps. Embedded metadata, filesystem dates and platform upload times are different things. They can be missing, altered, stripped during sharing or based on a wrong device clock. None alone proves authorship, location or authenticity.
- Use a working copy. Note the preserved item ID and the source of that copy.
- For an initial look, use Windows file Properties → Details, or Mac Finder Get Info and the relevant photo/PDF information panel. These show only some fields, not a full forensic report.
- For a fuller local report, a knowledgeable helper can use ExifTool. After installing it from its official source, this read-only command lists metadata:
exiftool -a -G1 -s "working-copy.jpg". Replace the filename with your working copy; do not use write/delete options. - Save the report with the item ID, tool version, command and review date. Keep the field name and raw value, including offset when present.
- Compare a timestamp or GPS clue with independent records. Mark a conflict or absent field as unresolved; do not “repair” the source to fit your theory.
- Keep metadata reports private if they contain location or personal details. Inspect a separate publication copy before sharing; never strip your only original.
Check before moving on
Your item should have a source, ID, collection time, stored location, intact preserved copy, working copy, limitations and a dated intake entry. If something is unknown, write “unknown” and explain the next check. Never invent a missing value.
This is a practical research workflow, not legal advice, a forensic certification or a promise that material will be accepted in court. Access and preserve material lawfully. Case-specific court rules, deadlines and preservation duties may require qualified legal or forensic help.
Build a complete case file → · Download the worksheets and folder starter (ZIP)
