Skip to content
Skip to main content
Messaging, Social Media & Telecoms Technical Explainer

Why should investigators request raw records rather than only a provider summary?

Raw provider records preserve the fields, identifiers and sequence needed to test an interpretation. A summary can explain the return, but it may omit technical detail or combine several events into one sentence.

Detail makes conclusions reproducible

Underlying data may expose event IDs, device or session identifiers, exact statuses, failed events, timestamps and time zones. These allow records from different systems to be aligned and apparent inconsistencies to be investigated.

Provider terminology can be specialised. Seek the data dictionary, code explanations, field definitions and time basis that applied to the returned system. “Raw” does not mean complete or self-explanatory: retention, redaction and system boundaries can still limit it.

Preserve both return and explanation

Keep the original file format and covering correspondence. Work on a copy when converting data into a spreadsheet or timeline, document the transformation and retain a route back to each source row.

Distinguish the provider's narrative interpretation from conclusions reached through analysis of the records. If only a summary is available, state that limitation and do not imply that omitted technical fields were independently checked.

The point to remember

Obtain original provider data with its definitions and explanation so event-level conclusions can be checked, reproduced and distinguished from a narrative summary.

Reference: MSG-103Messaging, Social Media & Telecoms