Core fields
- --Claim or question
- --Visible evidence
- --Source and capture date
- --What is missing
- --Confidence level
- --Safe next step
evidence log
Good OSINT work needs a record another person can inspect. The evidence log keeps observations, limits, and next checks separate.
Use plain labels such as low, medium, and high confidence. Explain why the label was chosen. Avoid writing a strong conclusion when the source is weak, old, or single-source.
A useful note does not try to sound certain. It tells the reader what was seen, what was checked, what remains open, and what should not be inferred.