All lessons Leer en español

Security in depth · Unit 30 · Lesson 5 of 11

Evidence needs enough context to review

Turn an isolated screenshot into a record another reviewer can interpret.

4 minreadyShort lesson

Helpful before thisReporting: turn evidence into useful improvements

See all lessons in this topic

After this lesson you can

  • Identify the minimum contextual fields needed to assess a supplied permission decision.

More evidence is not always more explanatory evidence.

Preserve the conditions that matter

Evidence context records the conditions and provenance needed to understand an observation. A reviewer needs to distinguish the expected behavior from the result, and know which release, environment, identity role, and time the observation concerns. An image alone often omits those facts.

Assume a fictional archive is reviewing whether a Viewer can change catalog descriptions. The task is to assess supplied records, not perform an access attempt. A report copy should minimize unrelated personal information while preserving a controlled reference to the original evidence.

Observed result → Relevant conditions → Reviewable evidenceObserved resultRelevant conditionsReviewable evidence
Relevant conditions and provenance make an observation reviewable. A larger transcript cannot replace missing role or policy context.

Supplied evidence packet

  • E1: A screenshot says “change saved,” but includes no visible environment or role. It also contains unrelated member names.
  • E2: The assessor’s accompanying record identifies staging release 4.2, Viewer role, and observation time 14:05 UTC on the recorded exercise date.
  • E3: The approved policy permits Viewer reading only. A protected before-and-after record confirms the changed description persisted under E2’s conditions and identifies the evidence custodian.

Build an interpretable card

Combine E1 with E2 and E3: expected read-only behavior, observed saved change, and the stated conditions. A redacted report copy can replace unrelated names with stable labels and point to the protected original. Keep the original separately governed; do not claim that an edited screenshot is unchanged evidence.

The card supports review of this observation, not all roles or releases. It also does not independently establish the technical cause of the policy mismatch. If the record is inconsistent, preserve the conflict and request clarification instead of filling gaps from memory.

Model card: Staging 4.2; Viewer; read-only policy; saved change observed; dated source reference; other environments and cause unverified.

Terms you met

Evidence context

Check yourself

No timer. No penalties. Read the explanation and try again whenever you like.

  1. Which revision makes the evidence most useful?

    Show the answer

    Correct answer: Add the release, staging environment, role, expected policy, timestamp, and protected source reference. These fields make the observation interpretable and traceable while supporting a limited report copy that excludes unnecessary personal data.

Try it

  • WriteDraft a compact evidence card from E1-E3 with release, environment, role, expected policy, observation, time, and limitation. Replace personal names with stable fictional labels, retaining the separate protected original reference.
References