TRUST-IT Content reviewed
DECISION BRIEF
What you will be able to decide
For: Corporate legal teams, HR, security leaders and authorised case owners.
Determine what the evidence supports while preserving material and controlling continuing exposure.
- Document authority, purpose, sources and reporting restrictions.
- Correlate events without equating account activity with personal intent.
- Deliver referenced findings, alternative explanations and clear limitations.
Define the concern before examining the person
A departing employee, an unusually large download or an external sharing alert may justify a technical question. None establishes wrongdoing by itself. Define the data, account, system and period in question, then record what would support or weaken the concern. Routine migration, approved work, automated synchronisation and delegated access are alternative explanations to examine.
Appoint an authorised case owner and coordinate with HR, legal and privacy advisers. Agree access authority, reporting recipients, permitted sources and restrictions on personal or unrelated material. Corporate device ownership alone does not resolve every question about reviewing communications or mixed personal data. The investigation should have a documented purpose and decision boundary.
Coordinate containment with preservation
Where exposure is continuing, the authorised incident owner decides what must be restricted immediately. Where feasible, preserve relevant volatile or expiring records before a change removes access to them. Record the order of actions and their effect on available evidence. Preservation must not become a reason to leave an urgent risk uncontrolled.
Account suspension, session revocation, device collection, reassignment, mailbox changes and deletion have different effects. Before routine offboarding proceeds, establish which sources need protected retention and who will execute that instruction. Avoid improvising with personal credentials or forwarding an entire mailbox to an unrestricted shared account. Technical and procedural handling should remain traceable.
Related primary guidance: NIST SP 800-86
Map evidence across identity, cloud and endpoint systems
Build a source matrix for sign-ins, cloud audit events, file sharing, mail activity, endpoint telemetry, removable-media traces and the relevant source repositories. Record the actual event coverage, time window, retention, licensing and permission requirements. Product documentation describes possible events; it does not prove that the organisation recorded those events during the period under investigation.
Distinguish access, download, sharing, synchronisation and recipient activity. A file-access record may describe a preview or service operation. A sharing invitation may exist without evidence that the recipient opened the material. A local file and a USB connection near the same time do not alone establish a completed transfer of that file. Correlate sources and state what remains unknown.
Related primary guidance: Microsoft — Audit log activities
Collect material with reproducible boundaries
For each export or acquisition, record source identifier, custodian, authorised collector, timestamps with time zone, query or export parameters, tool version, errors and completeness checks. Use stable evidence identifiers and integrity checks appropriate to the artefact. Keep original exports distinct from working copies and analysis outputs.
Large cloud exports may be paginated, delayed, truncated or affected by permissions. Reconcile requested periods and item counts, retain error records and document retries. Preserve native metadata when it matters to the question. A PDF or screenshot may help presentation but should not silently replace the source data on which the finding depends.
Preserve evidence while testing competing explanations
Containment and preservation are coordinated decisions; analysis follows the authorised scope.
- MandateQuestion, authority and recipients
- PreserveSources and urgent risk decisions
- CorrelateCloud, identity and endpoint events
- EvaluateAlternatives and coverage gaps
- ReportFacts, inference and restrictions
A recorded account action is not automatically proof of who performed it, their intent or a later recipient’s activity.
Build a chronology with uncertainty visible
Normalise event times for analysis while preserving the original value and time zone. Different systems may record event occurrence, ingestion or processing time. Note clock drift, missing offsets and ambiguous ordering rather than creating false precision. Connect events through supported identifiers such as account, device, object and operation, not merely a similar display name.
Distinguish an action attributed to an account from an action attributable to a person. Shared devices, delegated access, compromised credentials and background processes can change the interpretation. Test plausible alternatives and record evidence that contradicts the initial hypothesis. The report should explain how strongly each source supports the conclusion.
Separate technical findings from employment or legal decisions
Use clear finding categories: observed fact, supported inference, unresolved question and material limitation. Describe affected information and demonstrable activity without claiming intent, onward disclosure or competitive harm beyond the evidence. “A download event was recorded” and “confidential information was delivered to a competitor” are substantially different conclusions.
Legal advisers and responsible management decide employment action, notification, claims and procedural steps. Technical investigators provide a referenced chronology and explain uncertainties. Sensitive findings may require a restricted annex; recipients should receive only the information necessary for their role. Agree evidence retention and disposal with the authorised owner and applicable instructions.
Request deliverables that another reviewer can follow
A useful package includes the mandate, evidence register, collection log, source-coverage matrix, timeline, findings with references, alternative explanations and limitations. Make the relationship between the executive account and technical appendices explicit. Every significant conclusion should be traceable to the reviewed material.
At the initial checkpoint, agree whether the available evidence answers the question, whether another source is needed or whether the investigation must stop with a documented uncertainty. More collection is justified by the question it can answer. Additional scope, access and cost should be agreed before broadening the review.
Turn the result into better offboarding controls
The outcome can reveal gaps in delegated access, account recovery, external sharing, retention or ownership of source code and client records. Assign remediation owners and verify their actions with controlled tests. An investigation may conclude that the alleged conduct is unsupported while still identifying a control weakness worth fixing.
Test offboarding across the full dependency chain: directory account, active sessions, service integrations, guest access, repository membership, shared credentials and recovery channels. Preserve required records through the authorised process. Confirm both that obsolete access ends and that the organisation can continue its legitimate work.
WORKED EXAMPLE
An unusually large download before a departure
Illustrative scenario, not a client case. A file-sharing platform reports a large download shortly before an employee leaves. The business suspects loss of confidential project material, but the account was also used for an approved workstation migration.
- Evidence and checks
- Within the agreed mandate, the examiner correlates audit events, the migration request, endpoint telemetry and authorised sharing records. The source matrix identifies a gap in recipient-side visibility. The chronology separates service-driven synchronisation from the events requiring further examination.
- Supported conclusion and next action
- The download volume alone does not establish unauthorised disclosure. The report identifies supported activity, tests the migration explanation and leaves onward receipt unresolved where evidence is missing. The case owner decides whether another authorised source is justified.
What to request from your provider
Use these criteria to compare the proposed work and review the result. The scope and acceptance checks should be agreed before delivery.
Swipe across the table to see all columns.
| Deliverable | What it includes | Acceptance check |
|---|---|---|
| Mandate and source map | Purpose, authority, custodians, periods and exclusions. | Collection stays within a documented, authorised scope. |
| Collection record | Methods, parameters, errors, integrity and handling history. | An independent reviewer can trace each evidence item. |
| Analytical chronology | Correlated records with original times and alternative explanations. | Time ordering and attribution limits remain visible. |
| Restricted findings | Executive account, referenced findings and controlled annexes. | Sensitive material is distributed only to agreed recipients. |
TAKE THIS INTO YOUR NEXT MEETING
Your preparation checklist
- Appoint a case owner and agree HR, legal and privacy coordination.
- Write the question, affected information and relevant period.
- Coordinate containment and preservation before routine deletion or reassignment.
- Map actual audit coverage, retention and collection permissions.
- Test legitimate explanations and separate account activity from attribution.
- Agree report recipients, next checkpoint and final retention or disposal instructions.
Use the bilingual workbook for notes or the editable CSV to assign owners and evidence references. These are preparation templates, not a completed assessment.
Further reading
- NIST SP 800-86 — Forensic techniques and incident response
- Microsoft Learn — Audit log activities and event definitions
Put the guidance to work
Confidential technical investigations into suspected insider activity, IP loss, digital fraud and misuse of corporate information.
Corporate & insider investigations