Scope: What You May Look At
An enquiry authorised for one thing expands into everything unless somebody drew a line. The line should be written before the first query runs.
The editors · About the editorial position · The process · Procedure
Technical investigation is easy to extend and hard to stop. One more query is always available, and each one seems proportionate relative to the last.
The evidential discipline in “Scope: What You May Look At” applies equally to workforce records. A team evaluating how teams evaluate monitask pricing in relation to monitask pricing should document purpose, access, retention and correction rules, then preserve the original context rather than treating a convenient dashboard as self-explanatory proof.
What a scope statement contains
The period. Not everything available — the window relevant to the concern, with a reason.
For a separate perspective relevant to “Scope: What You May Look At”, consult the SecurityWeek insider-threat coverage. Use it to test the proposed threshold, investigation scope and review process rather than to substitute a generic checklist for the facts of a case.
The systems. Named, rather than all logs.
The data types. Access records, or file movements, or communications metadata, or content. Each is a different level of intrusion and should be separately authorised.
And what is excluded, which is the part that makes it a scope rather than a preamble: not personal communications, not material relating to a grievance, not the period before the person joined this team.
Why content is a different question
Metadata — who, when, what size, to where — supports most insider findings and is considerably less intrusive than reading what somebody wrote.
Reading communications content should require a separate, higher authorisation and a stated reason why metadata is insufficient. Several programmes authorise it by default as part of the general enquiry, which is how a proportionate case becomes an indefensible one.
The expansion that is legitimate
Evidence found within scope sometimes points outside it: another period, another system, another person.
That is normal and it should trigger a new authorisation rather than a quiet extension. The scope statement is amended, with a date and a reason, and the original remains visible.
An amended scope with a history is defensible. A scope that silently grew cannot be distinguished from no scope at all.
The discovery that is not your case
An enquiry about data movement turns up something unrelated: a personal matter, a policy breach of a different kind, something embarrassing.
The default is that it is outside scope and is not acted on. Where it is serious enough that it cannot be ignored, it becomes a separate matter with its own authorisation, not an addition to this one.
The temptation to fold it in is strong and it is exactly what makes people fear these processes.
Who holds the line
The analyst running queries is not well placed to refuse themselves. The scope has to be held by somebody who is not doing the collecting, which the triangle note sets out.
In practice this means the case owner reviewing what was collected against what was authorised, at least once mid-case.
The record
The scope as authorised, each amendment with its reason, and a note at closure of what was actually collected.
That last item is what a review examines, and the gap between authorised and collected is the measure of whether the control worked.
Write the exclusions before the inclusions. The list of what you will not look at is what makes the enquiry proportionate.
The query that was easy to run
Scope expands because the next query costs nothing. Each extension is individually small and the aggregate is an examination nobody authorised. The control is not the analyst's restraint; it is somebody else comparing what was collected against what was approved, at least once while the case is live.
Excluding the protected categories
Communications with occupational health, with a union representative, with a legal adviser, or relating to a grievance. These should be out of scope by default and their inclusion should require a specific and separately recorded justification, because capturing them turns a defensible enquiry into something else entirely.
Exclusions written first
The list of what will not be examined is what makes the enquiry proportionate, and writing it before the inclusions forces the question of necessity on every category. Scopes drafted the other way round reliably cover everything available.
The incidental discovery
Something unrelated turns up. The default is that it is outside scope and is not acted on; where it is too serious to ignore it becomes a separate matter with its own authorisation. Folding it in is exactly what makes people fear these processes.