Digital states move. Evidence must hold.
Evidence collection converts a transient digital observation into a stable research record. Preservation keeps that record identifiable, intact, inspectable and connected to its acquisition context across storage, transfer and later use.
Collection fixes an observation. Preservation keeps it testable.
The collection event must retain enough context to explain what was observed and under which conditions. Preservation must ensure that the same record—not a later replacement—can be inspected when the claim is reviewed.
Collect the source state and its observation context. Preserve the raw representation, integrity reference, custody history and every later version as distinct records.
EVD/03 models where a record came from. EVD/04 evaluates whether the source fits the claim. EVD/05 owns the procedure that acquires the record, fixes the observation boundary and keeps the captured state available without silent substitution.
Different evidence forms need different capture envelopes.
Select a record type and toggle controls. The console distinguishes required acquisition context from optional enrichment and refuses to call an incomplete observation preserved.
Web snapshot ready to seal.
The page state, canonical location, retrieval time, response context and preserved representation are bound into one acquisition event.
One saved file is not a preservation system.
A defensible record combines five layers. Removing any layer changes what can later be verified, reproduced or safely claimed.
Raw representation
The closest retained form of the acquired response, document, image or output before research transformation.
Acquisition envelope
Target, request, query, locale, device, access state, timestamps and collector identity.
Integrity reference
Checksum, immutable object identifier or equivalent control able to reveal content change.
Custody record
Storage, transfer, access and modification events linked to responsible actors and times.
Readable preservation
Formats, manifests and migration records that keep the evidence inspectable as systems change.
A live URL is a pointer. A snapshot is an observed state.
Switch between the source timeline states. Preservation prevents a later page, response or output from silently replacing the record that actually supported the original analysis.
Observed source state
The live representation is acquired under a declared context at T₀. It is not yet safe to assume future availability or stability.
Integrity detects change. It does not prove truth.
A checksum can show that a stored record still matches the captured bytes. It cannot prove that the source was accurate, that the collection context was representative or that the claim is valid.
sha256:91c8…4e20
time: T₀sha256:7bf1…9d42
parent: 91c8sha256:34aa…f189
object: 7bf1match: true
checked: T₁The stored bytes match the sealed capture reference.
Source identity requires its own provenance controls.
Integrity preserves an assertion; it does not validate it.
A checksum difference requires a new version or incident review.
Every handoff becomes an evidence event.
Custody records show who controlled the evidence object, what action occurred, when it occurred and whether integrity remained verified.
Acquired source state and wrote capture manifest.
HASH CREATEDAccepted immutable raw object and restricted overwrite.
HASH MATCHRead raw object and created a separate derived representation.
READ ONLYCopied object to a new storage class; original reference retained.
REVERIFIEDPreserve by volatility, risk and claim horizon.
There is no universal capture frequency. Recollection depends on how quickly the source can change, how long the claim must remain current and what consequence follows from using stale evidence.
Preserve content and visual context when relevant.
Include redirects and access state.
Bind manifest and object.
Or claim review date.
Record unloaded or personalized regions.
Do not retain only normalized fields.
Parameters, version and time.
Separate request and response IDs.
Or endpoint/version change.
Note fields not exposed by the service.
Not only target rank.
Include time and result type.
Bind raw result set.
Based on volatility and study design.
One snapshot supports only one state.
Preserve formatting and citations.
Settings and retrieval state when exposed.
Bind to run identifier.
Or repeated-run study.
Recollection creates a new run, not a replacement.
A screenshot can look convincing and still be unusable.
Collection failure occurs when a record loses the context, integrity or continuity required to inspect the original observation.
A rank, quote or number is retained without the surrounding result or document state.
The timestamp lacks zone, clock source or distinction between publication and retrieval.
Normalization or cleanup replaces the acquired representation instead of creating a derived version.
Visual appearance is preserved while text, metadata, links or machine-readable fields disappear.
Personalization, authentication, consent or geolocation influences the source but is not recorded.
A live URL is cited as if it permanently represented the state observed earlier.
A hash exists but is not bound to a manifest, object identity or verification event.
A format or storage move changes the object without a new checksum and custody event.
Six controls convert access into revisit-able evidence.
The protocol ends with a sealed record and an explicit recollection condition—not with a conclusion about the claim.
Declare target
Name the exact source object, expected record form and required observation boundary.
Fix context
Record time, locale, request, device, access state and collector.
Acquire raw
Retain the closest available representation before research transformation.
Seal integrity
Bind object and manifest with an immutable identifier and verification control.
Register custody
Log storage, access, transfer, migration and derived-object events.
Set recollection
Define change, age, model, endpoint or review events that require a new capture.
Define the observation before opening the source.
A collection specification limits selective capture and makes repeated observations comparable. It states what is being sought, where it may be observed, which context must travel with the record and what conditions make collection incomplete.
Name the exact evidence object
Identify the entity, claim, page, endpoint, document, interface state, query environment or generated output to be captured. Distinguish a company from its product, a live URL from a page version and a query from a broader topic. If the object can change identity through redirects, aliases, ownership or versioning, record the resolution rule in advance.
State which claim the record may support
Collection should be claim-aware without becoming conclusion-driven. Define the proposition or research question that gives the record relevance, then separate which inferences remain outside the capture. A screenshot of a ranking can support an observed position under one environment; it cannot alone establish long-term stability, traffic impact or causal effect.
Fix the collection universe
Set geography, language, device, account state, audience, market, time window, source class and inclusion rules. A bounded collection can be complete for its purpose while remaining incomplete globally. Explicit exclusions allow later reviewers to distinguish a deliberate boundary from a missed observation.
Define when collection begins and repeats
Collection may occur on a schedule, after a state change, before a decision, when a threshold is crossed or when prior evidence expires. The trigger should match source volatility and consequence. High-change evidence may need event-based capture; stable records may need only version checks and a longer review interval.
Record the acquisition procedure
Describe navigation, request parameters, authentication state, extraction method, pagination, rendering behavior and tools that materially shape the result. The method must be detailed enough to explain why a later collector may observe a different state. Sensitive credentials never belong in the preserved analytical record.
Set the minimum capture envelope
List the files, metadata and checks required before a collection event can close. A successful download is not sufficient if the timestamp, source identity, response status or environment is missing. Mark partial captures explicitly and state whether they remain useful for a narrower claim.
The representation and its context must remain separable.
The raw object preserves what was acquired. The envelope preserves the conditions needed to interpret that object. Different evidence forms require different fields, but source, time, identity, method and integrity remain recurring controls.
Capture visible state and recoverable content.
Some evidence does not exist until the observation is performed.
Personalized pages, structured responses, search results and generated answers are produced under request-specific conditions. Preserving only the visible output removes the context needed to understand why the state appeared.
Preserve the complete query environment
Record exact query string, location, language, device, search surface, time and any known personalization or session state. Capture visible features as well as organic results. A later change may reflect ranking movement, interface composition or localization; the envelope must allow those explanations to be separated.
Preserve request and response as paired records
Store the endpoint, method, parameters, pagination, status, response headers that affect interpretation and original response bytes. Record transformation separately from acquisition. Authentication secrets should be excluded, while access tier or permission state may need a non-sensitive description when it changes the returned data.
Treat each generated answer as one run
Capture the prompt, attachments or source context, answer, citations, model or interface label, visible settings, run time and position in the conversation. The preserved output proves what was generated in that run. It does not by itself prove the truth of the generated claims or guarantee reproducibility under an inaccessible internal state.
Capture state, action and resulting state
Interactive dashboards and authenticated systems may reveal data only after filters, clicks or account-specific actions. Preserve the initial state, action sequence, selected filters and final state. When a visual depends on client-side rendering, pair the screenshot with exportable data or a structured response where lawful and available.
Match preservation depth to volatility, consequence and review horizon.
Not every observation requires the same custody burden. The selected tier should be proportionate, declared and sufficient for the way the evidence will be used.
Reference
URL or identifier, source name, access date and concise note. Appropriate for discovery leads that are not yet used as material support.
Contextual capture
Screenshot or file plus source, timestamp and basic environment. Suitable for low-consequence descriptive work when the state is unlikely to be disputed.
Reproducible capture
Raw representation, complete envelope, method, transformation log and integrity value. Another reviewer can understand and repeat the acquisition.
Controlled custody
Immutable original, versioned working copies, access log, custody events and verified backups. Appropriate when evidence influences a consequential decision.
Long-horizon archive
Redundant storage, format strategy, periodic integrity verification, migration history and documented retention authority.
The capture method changes with the evidence form. The preservation principle remains stable.
Each example separates raw representation, required context, integrity control and the limit that must remain visible in later analysis.
Preserving a ranking claim
A researcher observes a page at position four. The capture includes the exact query, result surface, location, language, device, timestamp, visible features, target URL and surrounding results. A screenshot records presentation; structured extraction supports comparison. The claim remains limited to that environment and moment. Repeated captures are required before asserting stability or trend.
Preserving a company attribute
A registry document supports legal identity, while the official site supports current positioning. Each file is captured with identifier, version, effective date, acquisition path and hash. The analytical profile maps attributes to their respective sources. Preservation prevents a later website rewrite from replacing what supported the earlier description.
Preserving a numeric estimate
The raw table is stored together with metric definition, population, period, currency, denominator, confidence information and methodological notes. A normalized value is created as a separate derivative object with its conversion equation. The original number is never overwritten. Later reviewers can test whether category or exchange-rate assumptions changed the result.
Preserving a removed statement
A claim appears on a page and disappears two weeks later. Both states are captured independently with timestamps, page exports and integrity values. A comparison identifies the changed fragment. The record supports a temporal statement—what the page displayed at each capture—not an assumption about why the publisher changed it.
Preserving a changing operational event
Status updates, customer reports and technical observations are captured as separate evidence lines. Each receives source, time, affected service, region and custody information. Later corrections are appended rather than replacing earlier notices. This supports reconstruction of the evolving state while leaving root-cause attribution to separate evidence.
Preserving a generated citation event
The prompt, complete answer, cited URLs, visible model label, time and conversation context are retained as one run. Source pages are captured separately because they can change or disappear. The run record supports that the system produced and cited the output; the source captures support later factual validation.
Preserving a discovered reference
An index reports a backlink. The index response is preserved with capture time and relevant parameters, while a direct fetch records the referring page, canonical URL, anchor, target and link attributes. These are distinct observations. The preserved state does not prove continuous historical presence or causal ranking effect.
Preserving a filtered analytical view
The collector records initial settings, filter sequence, selected period, exported values and final visual state. The underlying data export is retained when available. A screen alone may omit scale, denominator or excluded categories. Pairing presentation with data and action history keeps the result interpretable.
Integrity answers “did it change?”—not “was it true?”
Hashing, custody and version control protect the relationship between the stored record and the captured bytes. They do not validate source competence, observation representativeness or the conclusion drawn from the record.
Detect byte-level alteration
A cryptographic hash creates a compact integrity value for a file. Recomputing it can reveal whether the bytes changed. The algorithm, value and verification time should be recorded. A matching hash does not authenticate the original source unless source identity is established separately.
Bind related files into one capture
A manifest lists representations, metadata, hashes and relationships. It prevents a screenshot, response and extraction from becoming detached. Version the manifest when derivatives are added, while preserving the original capture inventory.
Record every material handoff
Custody records identify who or what controlled the evidence, what action occurred, when it occurred and whether integrity remained verified. Automated transformations should be logged as clearly as human access when they can affect the analytical object.
Verify origin separately from integrity
Signatures, authoritative identifiers, retrieval path, source comparison and contextual consistency may support authenticity. A perfectly preserved forgery remains false in origin. Authenticity and integrity are related controls, not synonyms.
Validate the claim after preserving the record
Preservation fixes what the source presented. Evidence validation then tests whether the source could know it, whether the method fits and whether independent evidence corroborates or contradicts the claim.
Preserve proportionately and lawfully
Minimize personal and sensitive data, define access controls and retention authority, and avoid collecting secrets not needed for the research purpose. Auditability does not require indiscriminate retention.
A failed capture is not repaired by hiding it. Record the failure, then recover deliberately.
Collection can fail because access changes, content is generated late, a session expires, an export truncates, a file becomes corrupted or the source disappears. Recovery begins by preserving what is known about the failed attempt. A replacement capture must remain distinguishable from the original event so that later reviewers can see what was observed, what was missing and what was reconstructed.
Record the requested location, UTC time, response status, visible error and collection environment. Retry only under a declared alternative such as a different authorized account, device or network. Never present the later successful response as if it were the state observed during the failed attempt.
Preserve the initial response and document the interaction required to reveal the state: consent choice, filter, expansion, scroll, query or wait condition. Capture the final rendered state and, where available, the underlying structured response. This distinguishes absent content from content generated after an action.
Keep the incomplete export as evidence of the attempt. Record displayed totals, pagination, limits and active filters. Re-collect using bounded partitions only when the partitions are mutually interpretable and their assembly method is declared. A reconstructed dataset should never silently replace the incomplete original.
Quarantine the affected object, retain its failed integrity result and inspect other replicas. If a verified copy exists, restore from it while documenting source, time and operator. If none exists, mark the representation unavailable and recollect only as a new observation. Recollection cannot recreate the lost historical state.
Do not manufacture certainty from search snippets or secondary quotations. Preserve the unavailable response, then locate prior captures, archives, quoted fragments or derivative records and classify each by origin. These may establish that a statement circulated, but not necessarily the exact original page state.
Check time, market, language, account, device, personalization, experiment exposure and canonical identity before calling the difference a change. Preserve both states. If the cause cannot be resolved, keep the variation explicit and narrow the claim to the environments actually observed.
Preserve the restricted original only when lawful and necessary, then create a clearly labeled redacted derivative for analysis or publication. Record the redaction rule and integrity values for both objects. Never overwrite the source file in place, because that destroys the distinction between collected and released evidence.
Keep the locally recorded time but mark its uncertainty. Seek independent temporal anchors such as signed response headers, event logs or version identifiers. Do not convert an approximate time into false precision. If sequence matters, express an interval or ordering constraint instead of an exact instant.
Preserved evidence is ready for use only when another reviewer can locate, interpret and test it.
A collection release is a controlled research object, not a folder of unexplained files. Before analysis, publication or handoff, review the capture against a minimum release matrix. The review does not certify that every source claim is true. It certifies that the collected record is sufficiently identified, bounded and preserved for its intended evidential use.
Can the exact evidence object be identified?
The release names the source, canonical location or stable identifier, captured representation, version and collection event. File names alone are insufficient when they can be changed or duplicated. Each object needs a durable record identifier that remains stable across storage moves and derivative creation.
Can the observation environment be reconstructed?
Market, language, device, account state, query, filter, time and interaction history are recorded to the depth required by the source. A context field may be explicitly “not applicable” or “unknown,” but it should not disappear silently. Reviewers must know which boundaries were controlled and which remain uncertain.
Does the record preserve the claim-bearing context?
The captured fragment includes the heading, scale, denominator, footnote, surrounding qualification or interaction state needed to interpret it. Completeness is claim-specific: a full-page image can still be incomplete if an opened tooltip contains the relevant definition, while a bounded data row may be sufficient when its schema and filters are preserved.
Is the raw representation distinct from derivatives?
The release retains the acquired object before extraction, annotation, compression, translation or normalization. Every derivative points back to that object and declares the transformation that produced it. This allows a reviewer to test whether the analytical value matches the collected source rather than trusting a cleaned table or cropped image.
Can unintended change be detected?
Integrity values cover the evidence objects and their manifest. Verification is repeated after transfer or restoration. Where a platform prevents access to original bytes, the limitation is declared and complementary controls—signed export, capture log, redundant representation or independent timestamp—are used without pretending they are equivalent to direct byte verification.
Are material actions visible?
The record shows collection, transfer, transformation, review, redaction and release events. Custody detail should be proportionate to consequence: an exploratory inventory may need a compact automated log, while evidence supporting a high-impact decision may require named reviewers, access restrictions and independently verified handoffs.
Does the release state what it cannot establish?
A strong record separates observation from inference. A snapshot may establish displayed content at a capture time, not continuous availability. An index record may establish discovery by that index, not the historical existence of a link. A generated answer may establish output from one run, not stable system behavior or factual truth.
Is the future control state declared?
The release defines storage class, authorized access, review horizon, retention trigger and destruction or legal-hold conditions. Volatile sources may require scheduled recollection, while sensitive derivatives may require earlier deletion than public source records. Preservation is governed continuity, not indefinite accumulation.
Collection decisions become easier when the claim and volatility are explicit.
The answers below define practical boundaries for common digital evidence situations. They are methodological defaults, not universal legal instructions. Higher-consequence, regulated or disputed matters may require jurisdiction-specific retention, disclosure and forensic procedures.
Is a screenshot enough?
Sometimes, but only for a narrow claim about visible presentation. A screenshot should normally be paired with source identity, URL, capture time, viewport and relevant interaction state. If the claim depends on hidden metadata, structured values, response behavior or downloadable content, preserve those objects separately. A screenshot is a representation, not a complete acquisition by default.
Why not cite the live page and move on?
A live URL can change, redirect, personalize, disappear or display a later correction. It is essential for provenance, but it does not freeze the observed state. Preserve a time-bound representation and retain the URL as part of its envelope. Later captures should be separate versions so that change can be measured without rewriting history.
How often should evidence be recollected?
Set cadence from volatility, decision consequence and known update rhythm. Fast-moving rankings, prices or status events may need minutes or hours; policies and reference documentation may need event-triggered or monthly checks. Recollection should occur sooner when a decision threshold is near, a source signals revision or the existing record approaches its validity boundary.
Can collection be fully automated?
Automation can improve consistency, timestamps and scale, but it must expose parameters, failures, retries and transformations. Human review remains important when identity is ambiguous, consent or access rules matter, interactive states change meaning or the capture determines a high-impact conclusion. The correct boundary is controlled automation with visible exceptions.
Should every preserved object be published?
No. Preservation and disclosure have different purposes. A research archive may contain licensed, personal, confidential or security-sensitive material that cannot be distributed. Publish the minimum sufficient evidence, derived summaries or redacted representations while maintaining a controlled path for authorized verification. State when access restrictions limit external review.
What if another reviewer cannot reproduce the same result?
First compare collection envelopes rather than assuming error. Time, location, account, query, device, experiment exposure and source revision can legitimately create different states. If conditions match and the result still differs, preserve the new observation and investigate instability. Reproducibility means explainable comparison, not a promise that dynamic systems never change.
What is the minimum defensible capture?
At minimum: the exact claim-bearing representation, source identity, retrieval time, collection context, acquisition method and an explicit limitation. The minimum expands whenever interpretation depends on filters, units, versions, user state or transformations. Capture sufficiency is determined by what must later be tested, not by the smallest possible file.
When is preserved evidence ready for analysis?
When the analyst can distinguish raw observation from derivative, recover the source and context, verify integrity, understand material gaps and state the claim the record can support. Readiness does not require certainty. It requires enough controlled information to prevent an unexplained file from being mistaken for a reliable evidential object.
Collection stabilizes the record. Corroboration tests independence.
EVD/05 preserves each observation as a controlled evidence object. EVD/06 then determines whether separate sources or methods provide genuinely independent confirmation.
Digital records, observations and claim-specific support.
EVD / 02CLASSEvidence Types & ClassesOrigin, directness, form, independence and temporal state.
EVD / 03ORIGINSource ProvenanceIdentity, custody, version, authorship and transformation history.
EVD / 04QUALITYSource QualityCompetence, access, transparency, incentives and accountability.
EVD / 05CAPTUREEvidence Collection & PreservationAcquisition context, stable records, snapshots and chain of custody.
EVD / 06CONFIRMCorroboration & TriangulationIndependent agreement across sources and observation modes.
EVD / 07CONFLICTConflicting Evidence ResolutionDiagnosing disagreement through scope, timing and lineage.
EVD / 08TIMETemporal Validity & Evidence DecayFreshness windows, volatility, supersession and re-collection.
EVD / 09SUPPORTClaim–Evidence MappingConnecting observations to exact claims and inference boundaries.
EVD / 10CONFIDENCEConfidence CalibrationTransparent confidence states without false certainty.
EVD / 11UNKNOWNEvidence Gaps & UnknownsMissing observations and unresolved alternatives.
EVD / 12SYNTHESISEvidence Synthesis & Decision ReadinessCombining support, conflict and uncertainty into a decision state.