How should message evidence be described in an investigative report?¶
Messaging evidence should be described at the level the records actually support.
Evidential caution: that a message shown against an account can be reported as if a named person unquestionably wrote and sent it.
What this means¶
Then identify the object: account, device, session, message, attachment, call or group event.
State the relevant identifiers, timestamps and time basis.
Distinguish observed content from interpretation. Quote or summarise the message accurately, then explain the evidential significance separately.
Avoid phrases such as “proves”, “definitely” or “must have” unless the evidential basis genuinely supports that level of certainty.
A good report should allow another investigator, lawyer or specialist to understand how the conclusion was reached and what remains uncertain.
What to check or do next¶
- Start by identifying the source: device extraction, provider return, recipient device, screenshot, export, organisational record or witness production.
- Use precise language. “The account sent the message” may be justified where the service record supports that event. “The person sent the message” requires evidence linking the person to the account, device or session at the relevant time.
- Preserve the source and collection method so another investigator can test the same conclusion.
Evidential limits¶
Record edits, deletions, missing content, synchronisation differences and any uncertainty about completeness.
Where screenshots or exports are used, explain their provenance and limitations.
Set out realistic alternative explanations where they remain material: account sharing, compromise, linked devices, automation or device transfer.
Operational takeaway
Report messaging evidence by source, account, device, event and attribution step, and separate what the records show from the conclusion drawn.