How should uncertainty about message authorship be reported?¶
Message authorship may be strongly indicated without being certain.
Evidential caution: that uncertainty must either be ignored or expressed so vaguely that the evidence becomes meaningless.
What this means¶
State what is established.
For example: the account sent the message, the message was present on a device, or the provider recorded activity from a session.
Then identify the evidence linking that account or device to the person: possession, access, location, witness evidence, content knowledge, login records or conduct.
Explain whether the evidence supports, weakens or leaves that alternative unresolved.
Equally, do not treat every theoretical possibility as equally plausible. The alternative should have a factual and technical basis.
A clear report allows the reader to see both the strength of the attribution and its limits.
What to check or do next¶
- Preserve the source and collection method so another investigator can test the same conclusion.
- Preserve the source and collection method so another investigator can test the same conclusion.
Evidential limits¶
Set out any realistic alternative explanation such as shared use, linked-device access, compromise, delegation or automation.
Use proportionate language. “Consistent with”, “strongly supports”, “likely” or “cannot exclude” may be appropriate depending on the evidence and reporting framework.
Do not hide a material uncertainty inside technical jargon.
Where uncertainty remains, identify what further evidence would be needed and why it would matter.
Where uncertainty remains, identify what further evidence would be needed and why it would matter.
Operational takeaway
Report authorship by separating the proven account or device event from the personal attribution, and explain the evidence, alternatives and remaining uncertainty directly.