Open-Source Research Notes: How Investigators Should Capture What They Find Online
Online material changes or disappears overnight. How to capture open-source findings so they still stand up months later: what to save, what to note, and how to keep it together.
Open-source research is only as good as the record you keep of it. A profile you found on Tuesday may be private by Friday; a post may be edited, a page taken down, a company registry entry amended. If your note says "found on social media, subject lists employer as X", you have a lead. If it has a full capture, the address, the date and time, and how you got there, you have evidence. The short answer: capture the page, record where and when, note your route, and never change the original.
What to capture for every finding
- The full address of the page, copied, not retyped. Shortened links should be expanded and both recorded.
- Date, time and time zone of capture. Pages change; the capture time is what your finding is anchored to.
- A full-page capture, not a cropped screenshot. Include the address bar and the device clock where you can. Save a PDF or web archive copy as well as an image if the page is long or dynamic.
- The route you took: the search terms, the site you started from, the link you followed. Someone else should be able to repeat it.
- Who captured it and on which device or account, especially if you use a dedicated research profile.
- A one-line relevance note: why this matters to the question you were asked.
Keep originals untouched
Treat each capture as an exhibit. Store the original file as saved, give it a clear name (date, source, short description), and do all annotation on a copy. If you highlight a name or blur a bystander, the untouched version must still exist alongside it. Record a checksum of the original if your process calls for it; at minimum, note its file size and the time it was saved. Much of this is about metadata, which we cover in what metadata is and why it matters.
Write the note at the time, not afterwards
The temptation is to collect twenty tabs and write it all up at the end of the day. By then you will not remember which search led to which result, and the order of discovery, which often matters, is lost. Keep a running log as you work: time, action, result. It reads like a surveillance log for the screen: plain, sequential, factual.
Separate fact from inference
"Profile photo shows subject at a gym" is an observation. "Subject is fit enough to work" is an inference, and it belongs in a clearly marked analysis section, not in the capture note. Say what you saw; say what you think it means separately; say how confident you are. Mixing them is the fastest way to have your whole log discounted.
Stay inside the lines
What you may lawfully access, and how, varies by jurisdiction and by your professional rules. As a baseline: do not use deception to get behind privacy settings, do not log in as someone else, respect the terms of the platforms you use, and record any account you used so your method is transparent. If you are unsure whether an approach is permitted where you work, check before, not after.
Keep it with the matter
Captures scattered across a downloads folder, a notes app and your email are hard to defend and easy to lose. File every capture, the running log and your analysis into the one record for the matter, so the finding, its source and its context travel together. In a case-based system such as Herarx, that means the files, the log and the dates sit in the same case, with a history of who added what. However you do it, the test is simple: could a colleague pick up the file in a year and see exactly what you found, where, and when? For more on writing notes that last, see how to write a case note that still makes sense in five years.