An Evidence Log Template for Investigations (And Why a Spreadsheet Isn’t One) — Herarx Blog

An Evidence Log Template for Investigations (And Why a Spreadsheet Isn’t One)

The columns an evidence log needs, the rules that keep it trustworthy, and the reason the log should live with the case rather than in a workbook.

April 24, 2026
An Evidence Log Template for Investigations (And Why a Spreadsheet Isn’t One)
Back to blog

Every investigator keeps an evidence log. Most keep it in a spreadsheet, and the spreadsheet works right up to the moment someone asks "who added row 41, and when?". A log is only as good as the properties of the thing it is kept in. Here are the columns, the rules, and the properties.

The columns

ColumnWhat goes in it
ReferenceUnique, sequential, never reused (EV-0041). Minted by the system when the row is saved.
DescriptionWhat the item is, in plain words. "Photo of rear entrance, north side".
TypePhoto / video / document / email / message export / physical item / statement.
Collected byThe person. A named user, not initials typed in.
Collected atDate and time of collection. Typed by the collector and stamped by the system on save; the difference between the two is itself informative.
LocationWhere it was collected (address, coordinates, device).
SourceWho or what it came from.
FileThe item itself, attached to the row; unchangeable after upload.
HashA fingerprint of the file at upload, for later verification.
Current location / custodianWhere the original is now (for physical items) or that it is held in the system.
TransfersEach hand-over: to whom, when, how.
NotesAnything else, dated.

The rules

  • Rows are added, never deleted. A withdrawn item is marked withdrawn, with a reason and a date.
  • Rows are not reordered and references are not reassigned.
  • The file attached to a row is the original; a working copy is a separate item that references it.
  • The log is completed at collection, not at the end of the day.

Why a spreadsheet isn't one

A spreadsheet has none of the properties the rules require. Rows can be deleted, reordered and renumbered without trace. The "collected at" cell is whatever was typed. The file is somewhere else, linked by a path that breaks. Nobody can say who edited what. It is a fine place to draft a log and a poor place to keep one.

The log as a table on the case

Kept as a table on the investigation's record, the log gains the properties for free: sequence references minted on save, system timestamps beside the typed ones, files attached to rows and immutable, every edit in the audit trail with the person and the time, and the whole thing exportable as the evidence schedule with the chronology beside it. Photos added from a phone at the scene create their row on the spot. The wider discipline is in the chain-of-custody checklist; the field routine in working from a phone.

The report at the end

The evidence schedule in the final report is the log, printed. If the log was kept properly, that is a document generated from the case in one click, and it matches the audit trail because it is the audit trail's subject. If it was kept in a spreadsheet, the report's schedule is a retyped copy of a document nobody can vouch for — and that is the version opposing counsel will ask about.