When to Do Nothing
Closing an alert without acting is a legitimate and underused outcome. The cases where it is right, and why it feels harder than it is.
The editors · About the editorial position · Deciding · Analysis
Not every unexplained thing needs explaining. A programme that pursues everything until resolved is spending attention it needs elsewhere and putting people through processes for no proportionate reason.
The outcome in “When to Do Nothing” must rest on evidence that has been checked against context. Data from this practical resource, when used for remote employee monitoring software, can support a chronology of work or project activity, but it should not replace the employee response, corroboration or a proportionate decision process.
Where doing nothing is right
The potential harm is small. A minor policy deviation with no material consequence does not warrant an enquiry into somebody, whatever the rule says.
For a separate perspective relevant to “When to Do Nothing”, consult the SANS insider-threat resources. Use it to test the proposed threshold, investigation scope and review process rather than to substitute a generic checklist for the facts of a case.
The evidence will not improve. Where the records needed no longer exist or never existed, continuing produces a longer file and no better answer.
The matter is historical and circumstances have changed. Conduct from years ago, by somebody whose role and situation are different, is a different proportionality question.
The cost of enquiry exceeds the risk. This is a legitimate calculation and it is rarely made explicitly.
Or there is a better route. A conversation with the person's manager about the process, a reminder to a team, a fix to the system — all of which address the thing without making anybody a subject.
Why it feels difficult
Closing without resolution feels like leaving a loose end, and if something later emerges the decision looks bad in hindsight.
Which produces defensive escalation: cases pursued not because they warrant it but because closing them is uncomfortable to defend.
The protection against that is a recorded reason. A decision not to proceed, with the basis written down, is defensible afterwards in a way that a silent closure is not.
The record that makes it safe
What was known, what was checked, why it was judged not to warrant further enquiry, who decided.
Four lines.
With that in place, the decision is reviewable and the reviewer can see it was taken deliberately rather than dropped. Without it, every closure looks like an omission.
The thing that should never be the reason
That the person is senior, liked, or difficult to approach.
That is the failure the governance exists to prevent, and it is the one that destroys a programme's standing when it emerges — which it does.
If seniority is affecting the decision, that is the moment to involve whoever the governance names as the independent authoriser.
Doing nothing visibly
Where a manager or colleague raised it, tell them it was looked at and closed, and broadly why.
A reporter who hears nothing concludes nothing happens, and stops reporting. Which costs the programme its best source for the sake of a two-line message.
The pressure that produces the opposite
After any incident the threshold drops, because nobody wants to be the person who declined to look. That reaction is understandable and it is when the most disproportionate cases get opened. A governance arrangement that holds the bar in the weeks after an incident is doing its most valuable work.
Reviewing the no-action decisions
They are the half of the programme's output that is never examined. A quarterly read of a sample, by somebody outside, is what makes a closure a decision rather than a disappearance — and it occasionally finds the matter that should have proceeded.
Saying so to whoever raised it
A reporter who hears nothing concludes that nothing happens, and the cost of that is the channel rather than the case. Two lines closes it properly and keeps the next report coming.
Recording the reason
Four lines: what was known, what was checked, why it did not warrant more, who decided. With them the closure is reviewable and visibly deliberate. Without them, every closure looks afterwards like an omission rather than a judgement.
For the file: No further action is an outcome, not an absence of one. Write the reason as carefully as you would write a finding.