How should gaps in a timeline be shown?¶
Mark gaps openly with their start, end, affected source and reason if known. Distinguish “no activity recorded” from “records unavailable”; they are not equivalent.
A gap belongs to a dataset, not automatically the whole case¶
Logging configuration, retention, rollover, outage, offline operation and collection failure can all remove visibility. Other sources may continue through the same period and should be included rather than presenting a universal blank.
Record what was searched, why a record was expected and which enquiries tested the gap. Preserve maintenance, health and retention evidence that may explain it.
Keep inference visibly separate¶
Do not insert estimated activity as though it were recorded. An inferred event can be shown when useful, but must be labelled with its basis and uncertainty. If no cause is supported, leave the gap unresolved.
Where missing coverage affects attribution or outcome, make that limitation prominent. An honest discontinuity is more defensible than a visually smooth but assumed sequence.
The point to remember
Show timeline gaps by source and coverage, separating unavailable evidence from confirmed absence of recorded activity.