Preliminary Review Without Naming It an Investigation
A short, bounded check that resolves most alerts before anybody becomes a subject. The step that distinguishes a programme from a machine for generating cases.
The editors · About the editorial position · Deciding · Procedure
Between the alert and the decision to open a case sits a step most programmes skip, and it is the one that keeps the majority of people out of a process they should never enter.
The practical lesson in “Preliminary Review Without Naming It an Investigation” is that visibility is not certainty. For teams researching employee monitoring at tech companies, the official software website can add time and project context to the operational record, provided the purpose is disclosed, access is limited and every material inference receives human review.
What it is
Twenty minutes establishing whether there is an obvious explanation.
For a separate perspective relevant to “Preliminary Review Without Naming It an Investigation”, consult the ENISA threat-landscape resources. Use it to test the proposed threshold, investigation scope and review process rather than to substitute a generic checklist for the facts of a case.
Not gathering evidence about a person. Establishing context about an event: what was the team doing, was there a deadline, is this a known pattern for this role, does the destination make sense, did somebody authorise it.
Where the answers come from
The work itself: a project schedule, a ticket, a client deadline that explains a large export on a Friday.
The system's own records: was the access granted deliberately, is this file classified as it appears.
A colleague who can say what the team was working on, without being told why you are asking.
And occasionally the subject, which is a judgement — the next note on timing covers when asking directly is right and when it is not.
Why it has to be bounded
An unbounded look is an investigation with no authorisation, which is the drift the threshold note describes.
So: a stated time limit, a stated scope, and a rule that anything beyond it requires the formal opening step. Twenty minutes and these sources, not a day and everything available.
If twenty minutes does not resolve it, that is itself a finding and the case goes to the authoriser with what was checked.
What it resolves
A large share. The process-failure note explains the commonest category: somebody working around something broken, which takes one question to establish.
Also: role changes nobody told the system about, projects with legitimate unusual patterns, test activity, and the frequent case of an alert that is simply a rule misfiring.
Programmes that measure this find that most alerts surviving automated triage are resolved here, which means the formal process is reserved for the small remainder.
The record it produces
What was checked, what was found, what was concluded, how long it took.
Short, and it matters: a case closed at preliminary review with no record is indistinguishable from one nobody looked at. If the same person is flagged again, the earlier record is what prevents the second look starting from zero.
The thing that makes it work
That it is explicitly not an investigation, and that everybody involved knows the distinction.
A preliminary review conducted like an enquiry — pulling records, building a picture, writing about the person — is an enquiry, whatever it is called. The bound is what makes the name honest.
Twenty minutes, four sources, a written outcome. Most of the programme's value sits in this step and most programmes have not defined it.
Who should do it
Somebody who understands the work, which is frequently not the security analyst. A twenty-minute check conducted by a person who knows what the team does resolves cases that an outsider would escalate, because recognising an ordinary pattern requires knowing what ordinary looks like here.
The record it leaves
Four lines: what was checked, with whom, what was found, what was concluded. Short enough to be written every time and sufficient to prevent a future alert about the same person starting from zero. A preliminary review with no record is indistinguishable from nobody having looked.
Bounded by design
Twenty minutes, four sources, written outcome. The bound is what keeps it from becoming an unauthorised enquiry, and a preliminary review that runs for a day with no limit is an investigation that nobody opened.
Most of the value sits here
Programmes that measure it find the majority of surviving alerts resolve at this step. It is twenty minutes of work standing between an ordinary explanation and somebody becoming a subject, and it is the step most commonly absent from the written process.