What should I include in a cloud-evidence decision log?¶
A cloud-evidence decision log should record why the line of enquiry was opened, what action was taken and how each decision was reached.
Evidential caution: that the technical records alone will explain the investigative reasoning.
What this means¶
Document what providers, organisations or specialists were approached and the dates of each action.
Include the identifiers, date ranges and record types requested.
Where evidence was not pursued, explain why.
For example, note whether account sharing, compromise, automation or several linked devices were considered.
The log should distinguish facts, provider statements, specialist interpretation and investigator inference.
Update the decision log when new evidence changes the value or direction of the enquiry.
Where a decision depends on provider behaviour or retention, record the source of that information and when it was confirmed. Product rules may change after the investigation.
What to check or do next¶
- Record the investigative question, account or service involved, likely evidential value and immediate preservation risk.
- Record decisions about lawful process, jurisdiction, proportionality, specialist support, containment and live-system interaction.
- Do not use it as a narrative dump. It should explain the key judgement points clearly enough for a supervisor, reviewer or court to understand the process.
Evidential limits¶
Where records were unavailable, record whether the cause was retention, account uncertainty, logging limits or provider response.
Also record assumptions and alternative explanations.
Where the enquiry involves several agencies or teams, record who held responsibility at each stage. This prevents delay, duplication and uncertainty about whether preservation or acquisition was completed.
Operational takeaway
Use the decision log to show the investigative question, actions, assumptions, proportionality and reasons for continuing, changing or stopping the cloud line of enquiry.