Evidence workflows

    Evidence workflows by harm type

    Workflow guides for preserving lawyer-ready evidence across NCII, cyberstalking, threats, and defamation matters, organized by harm type.

    Key takeaways

    • Different harm types decay and escalate in different ways, so each workflow below leads with what is specific to that pattern rather than repeating generic capture advice.
    • Every workflow shares the same underlying discipline: capture, preserve, timestamp, structure, and hand off, with observed facts kept separate from inference.
    • Start with the workflow that matches your situation, then use the pillar guide for the full capture-to-chronology method if you need the fundamentals first.

    Why does the workflow change by harm type?

    Definition

    An evidence workflow is a repeatable sequence, tailored to a specific harm pattern, for capturing online material and structuring it into a file a lawyer can actually review.

    The underlying discipline is the same everywhere: capture before content changes, preserve the original without altering it, timestamp consistently, and structure the result as a chronology rather than a folder of files. What changes by harm type is what to prioritize first, because different harms decay and escalate differently.

    A single threatening message needs a full thread and account context captured quickly. A pattern of impersonation needs related accounts tracked over weeks. A false statement causing reputational harm needs its spread and republication tracked, since a single capture of the original post rarely tells the whole story. Using a workflow built for the actual pattern, rather than a generic checklist, is what keeps the file focused on what a reviewer will actually need.

    Key point

    Every workflow below assumes the same starting habit: preserve first, and decide what matters later. Deleted or edited material is very rarely recoverable after the fact.

    If your situation does not fit neatly into one of these, or you want the underlying method before narrowing in, start with the complete guide to documenting online harassment. It covers capture, timestamps, chronology building, and handoff to a lawyer in full, and every workflow here builds on the same foundation.

    For the operational details behind every workflow, the online-harm evidence pack checklist and the chain of custody for online evidence reference cover the capture and custody mechanics common to all of them.

    Frequently asked questions

    What is an evidence workflow?

    An evidence workflow is a repeatable sequence for capturing, preserving, timestamping, and structuring online material into a file a lawyer can review, tailored to how a specific harm type typically appears and decays online.

    Which workflow should I start with?

    Match it to what is happening. Threats and repeated unwanted contact fit the cyberstalking workflow, fake or altered intimate media fits the NCII and synthetic-abuse workflow, and false statements harming reputation fit the defamation workflow.

    Do these workflows replace legal advice?

    No. Each workflow prepares a structured factual record for review. It does not decide legal questions, classify conduct as unlawful, or replace an assessment by a qualified lawyer.

    FINIUM LEGAL

    Want this structured for a real matter?

    Send one public URL or representative matter and review the kind of source-aware evidence file Finium is built to prepare.