The Threshold for Opening Anything
The decision to look into a named person is the point at which a programme starts affecting somebody's life. It deserves a stated threshold and almost never has one.
The editors · About the editorial position · Deciding · Procedure
Everything before this point is handling data. From here on it is an enquiry about a person, and the step across that line is the one worth governing.
The distinction made in “The Threshold for Opening Anything” should also shape any workforce technology used near an investigation. When reviewers consult Monitask guide to remote desktop monitoring software for remote desktop monitoring software, its records can provide operational context, but a signal still needs validation, a stated threshold and a human decision before it becomes a finding.
What the threshold should require
A specific concern, stateable in a sentence: not this person looks risky but this volume of this material went to this destination and we cannot establish why.
For a separate perspective relevant to “The Threshold for Opening Anything”, consult the CERT insider-risk research. Use it to test the proposed threshold, investigation scope and review process rather than to substitute a generic checklist for the facts of a case.
That the ordinary explanations have been checked and did not resolve it, which the preliminary review note covers.
That the potential harm justifies the intrusion, which is a judgement and should be recorded as one.
And that somebody with authority has decided, by name, rather than the case drifting into existence because a reviewer kept working on it.
The drift problem
Most cases are never formally opened. A reviewer looks at an alert, then looks at a bit more, then pulls some history, and at some point an enquiry about a person is underway with nobody having decided to start one.
The cost of that is procedural: there is no moment at which proportionality was assessed, no record of who authorised it, and no scope.
A formal opening step — a short form, a named approver, two minutes — creates that moment. It is the single structural control that distinguishes a programme from a practice.
What a stated threshold prevents
Enquiries opened because somebody is disliked.
Enquiries opened because a score is high, which the previous note argues is not a reason.
Enquiries that expand without anybody noticing, because the scope was never written.
And the common situation where nobody can say afterwards why this person was looked at and that one was not.
Different thresholds for different intrusions
Checking whether a file was authorised is low intrusion and can sit below the threshold.
Reviewing somebody's communications is high intrusion and should sit well above it.
A single threshold for all activity is either too high to be useful or too low to be defensible. Two or three tiers, each with its own authoriser, is the workable arrangement.
Writing it down
The threshold, the tiers, who authorises each, and what must be recorded.
One page, agreed with legal and HR before any case uses it.
The point of writing it in advance is that it will otherwise be set case by case, under pressure, by whoever is in the room.
The two-tier version
Low-intrusion checks — whether an access was authorised, whether a file is classified as it appears — can sit below the threshold and be done routinely. Examining communications sits well above it. A single bar for both is either too high to permit ordinary work or too low to defend the serious steps, and almost every programme has only one.
What the form should ask
The concern in one sentence, the ordinary explanations already checked, the scope requested, the intrusion level, and the authoriser's name. Five fields. Its purpose is not administrative: it creates the moment at which somebody decides, which is the thing that otherwise does not exist.
The moment that otherwise never happens
Without a formal opening there is no point at which proportionality was assessed, nobody who authorised anything, and no scope. The form exists to create that moment, and two minutes is the entire cost of having one.
Different bars for different intrusions
Checking an authorisation is not the same act as reading somebody's messages, and a single threshold covering both is either useless or indefensible. Two or three tiers with separate authorisers is the arrangement that actually holds.
Scope at the moment of opening
Decided with the authorisation rather than afterwards, because a scope written once collection is underway is written around what has already been collected.
For the file: Record the moment of opening, the person who authorised it, the stated concern, and the scope. If those four are absent, there was no decision — only momentum.