Evidence workflows
Evidence workflows by harm type
Workflow guides for preserving lawyer-ready evidence across NCII, cyberstalking, threats, and defamation matters, organized by harm type.
Key takeaways
- Different harm types decay and escalate in different ways, so each workflow below leads with what is specific to that pattern rather than repeating generic capture advice.
- Every workflow shares the same underlying discipline: capture, preserve, timestamp, structure, and hand off, with observed facts kept separate from inference.
- Start with the workflow that matches your situation, then use the pillar guide for the full capture-to-chronology method if you need the fundamentals first.
Why does the workflow change by harm type?
Definition
An evidence workflow is a repeatable sequence, tailored to a specific harm pattern, for capturing online material and structuring it into a file a lawyer can actually review.
The underlying discipline is the same everywhere: capture before content changes, preserve the original without altering it, timestamp consistently, and structure the result as a chronology rather than a folder of files. What changes by harm type is what to prioritize first, because different harms decay and escalate differently.
A single threatening message needs a full thread and account context captured quickly. A pattern of impersonation needs related accounts tracked over weeks. A false statement causing reputational harm needs its spread and republication tracked, since a single capture of the original post rarely tells the whole story. Using a workflow built for the actual pattern, rather than a generic checklist, is what keeps the file focused on what a reviewer will actually need.
Key point
Every workflow below assumes the same starting habit: preserve first, and decide what matters later. Deleted or edited material is very rarely recoverable after the fact.
The workflows
NCII and synthetic-abuse evidence workflow
Covers preservation of non-consensual intimate imagery and suspected synthetic or manipulated media, including provenance signals, authorization handling, and the distribution trail across platforms.
Read the workflow→Cyberstalking and threat evidence workflow
Covers repeated unwanted contact, escalating threats, and pattern documentation across accounts and platforms, where the sequence and frequency of contact matter as much as any single message.
Read the workflow→Defamation evidence workflow
Covers false statements causing reputational harm, including how to capture the statement and its context, track publication and reach, and follow repeat publication as it spreads or resurfaces.
Read the workflow→If your situation does not fit neatly into one of these, or you want the underlying method before narrowing in, start with the complete guide to documenting online harassment. It covers capture, timestamps, chronology building, and handoff to a lawyer in full, and every workflow here builds on the same foundation.
For the operational details behind every workflow, the online-harm evidence pack checklist and the chain of custody for online evidence reference cover the capture and custody mechanics common to all of them.
Frequently asked questions
What is an evidence workflow?
An evidence workflow is a repeatable sequence for capturing, preserving, timestamping, and structuring online material into a file a lawyer can review, tailored to how a specific harm type typically appears and decays online.
Which workflow should I start with?
Match it to what is happening. Threats and repeated unwanted contact fit the cyberstalking workflow, fake or altered intimate media fits the NCII and synthetic-abuse workflow, and false statements harming reputation fit the defamation workflow.
Do these workflows replace legal advice?
No. Each workflow prepares a structured factual record for review. It does not decide legal questions, classify conduct as unlawful, or replace an assessment by a qualified lawyer.
FINIUM LEGAL
Want this structured for a real matter?
Send one public URL or representative matter and review the kind of source-aware evidence file Finium is built to prepare.