Evidence Lifecycle for Open-Source Intelligence
A requirement-to-correction workflow for turning public information into a traceable assessment without treating availability as permission or inference as fact.
Publication boundary
Neutral synthesis with visible limits
Information only. The guide reports source-supported patterns, attribution limits, and open questions without endorsing an actor, institution, ideology, campaign, or geopolitical side. Operational details that could facilitate harm are omitted.
The guide describes governance and evidence handling, not methods for unauthorized access, intrusive targeting, evasion, or collection of private data without authority.
Scope
What this guide connects
This guide synthesizes the OSINT methodology reports around question definition, collection, preservation, validation, analysis, dissemination, privacy, review, and correction.
Cross-report synthesis
Accepted analytical modules
These modules paraphrase and compare the preserved reports. They remain subordinate to source evidence and may be revised when stronger records become available.
Begin with a bounded public-interest question
The reports treat collection as a response to a defined requirement rather than an invitation to gather everything available. A useful requirement names the decision or claim under review, the relevant time period, the necessary evidence classes, and the conditions that would stop collection. This improves relevance and supports proportionality because material unrelated to the question can be excluded early.
Preserve provenance before interpretation
A record should retain where it came from, when it was observed, who preserved it, what transformations occurred, and whether the source can change. Screenshots alone may omit context; links alone may disappear. The correct preservation method depends on law, authorization, source type, and risk. The public output should expose enough provenance to make a claim checkable without exposing sensitive or unnecessary personal data.
Corroborate across genuinely independent sources
Multiple reports or accounts can create an illusion of confirmation when they repeat the same press release, post, database, or anonymous source. The analysis should map source dependence, distinguish primary from secondary material, and ask what each source can actually establish. Contradiction is not a defect to conceal; it is information about uncertainty, definitions, access, or changing conditions.
Separate observation, interpretation, and confidence
An assessment should show the underlying observation, the inference drawn from it, the assumptions connecting them, and the confidence justified by the evidence. Automated tools can sort, translate, cluster, or flag material, but their output remains an intermediate product. Model confidence, popularity, or visual polish does not replace source validation or accountable human review.
Dissemination includes minimization and correction
The final product should publish only what is needed for the stated purpose, label current-through dates, identify unresolved conflicts, and provide a route for correction. Retention and access should be limited. When a source changes or an inference fails, the correction should update both the public statement and the supporting evidence record rather than leaving a misleading conclusion in circulation.
Evidence language
Five states that should not be collapsed
- Verified record
- A claim supported by a primary record or multiple independent sources whose provenance and date can be checked.
- Attributed claim
- A statement made by an identified source, institution, account, or participant; attribution does not by itself establish accuracy.
- Analytic inference
- A reasoned interpretation drawn from evidence. The assumptions and plausible alternatives should remain visible.
- Disputed or conflicting
- Material for which credible sources disagree, use incompatible definitions, or rely on different records.
- Unknown or not current
- A point the preserved corpus cannot establish, or a time-sensitive fact that requires fresh verification before present-tense use.
Source chain
Preserved reports used by this synthesis
The private full reports remain in repository-owned long-term memory. These links open their reviewed public adaptations.
Verification agenda
Questions to answer before stronger publication
- What requirement authorizes and limits the collection?
- Can each important claim be traced to a dated, preserved source with known provenance?
- How many sources are actually independent rather than repetitions of one origin?
- Which parts of the conclusion are observation, inference, or automated output?
- What correction, retention, access, and deletion rules apply after publication?
Subject index
Themes in this guide
Deeper single-report explorations
Research Briefs connected to this guide
Each brief stays close to one submitted report; this guide compares those ideas with the wider evidence corpus.
Anonymous Campaigns: A Chronology of Claims and Outcomes
A campaign-centered record that separates self-claims, independently observed events, court-established conduct, disputed scale, corrected identification, and unresolved attribution.
- Source words
- 6,684
- Modules
- 6
- Checkpoints
- 3
Anonymous in Court: What Legal Records Establish
A legal-record guide to action-specific liability, DDoS prosecutions, hyperlinking controversy, digital chain of custody, and the different ways courts have treated decentralized networks.
- Source words
- 6,606
- Modules
- 6
- Checkpoints
- 3
Anonymous Sources and Whistleblowing: Protection Is Not Verification
A framework separating anonymous sources, confidential sources, whistleblowers, leakers, legal protection, source reliability, document authenticity, corroboration, subject response, and correction.
- Source words
- 6,781
- Modules
- 6
- Checkpoints
- 3
OSINT Attribution: Claim Status, Confidence, and Source Independence
A publication-safe verification model built around origin, directness, independence, authenticity, timeliness, corroboration, custody, claim status, confidence, source reliability, and visible correction.
- Source words
- 7,282
- Modules
- 6
- Checkpoints
- 3
Metadata and Identity Inference: From Signals to Consequences
A non-operational map of collection, aggregation, inference, brokerage, consequential use, documented harm, oversight, and remedy, with special attention to the gap between probability and proof.
- Source words
- 8,773
- Modules
- 6
- Checkpoints
- 3
Continue the synthesis