THE WORKING PRINCIPLE

The recipient should be able to identify the decision, inspect the evidence, and understand the next question without reconstructing the conversation.

Write for the receiving team

Identify who will use the brief and what they need to do with it. An engineer, operations reviewer, and incident responder may each need a different level of transaction detail.

Open with the question, the scope of the review, and the next action. Put supporting material in a predictable order so the recipient can move from the summary to the evidence.

Retain the evidence boundary

Include the address, network, snapshot context, and source references behind the findings. State which activity window was reviewed and which sources were unavailable or outside scope.

Keep observed evidence separate from the analyst’s conclusions. An exported record should make both available without forcing the reader to guess which is which.

KEEP IN THE RECORD
  • Case purpose and review boundary
  • Network, address, and snapshot context
  • Relevant observations and source references
  • Assessment, gaps, and next action

Choose a useful export format

A structured JSON package supports downstream processing and detailed record inspection. A CSV worksheet is useful when the recipient needs to analyze the returned transaction rows. A Markdown brief makes the written assessment easy to review.

Inspect the exported file before sharing. Ensure it contains the intended case, retains any sample-data label, and includes only material appropriate for the recipient.

Close with ownership and follow-up

Document the next investigative question, the intended owner, and any condition that should prompt another review. Record those details in the brief using your team’s operating practice.

Share the package through an approved channel. The exported file is a separate copy, so its storage and distribution should follow the same handling requirements as the source case.

GroundTruth field notes describe an investigation method. Apply the review scope, source licensing, and information-handling requirements appropriate to your organization.