Skip to content
What the Record Proves

Home / Corroboration

Building a Timeline From Several Systems

How to assemble a timeline that can be relied on: a common clock, a source column, explicit gaps, and the discipline of building it before forming a view.

Corroboration · Reference

A timeline is only as good as the clock it is built on and the honesty of its gaps. Rows from four systems, each with its own clock, laid out in apparent sequence, produce an order that may be an artefact of drift — and the gaps between rows get read as periods of nothing happening rather than as periods nobody recorded.

The evidential discipline in “Building a Timeline From Several Systems” should also govern workforce technology. A team evaluating a practical way to evaluate gdpr employee monitoring for gdpr employee monitoring can use time and project records as operational context, but should preserve the original record, document access and let the employee correct a misleading entry before it supports a conclusion.

Both problems are fixed by the same discipline: build the timeline mechanically, with a source and a correction against every row, before anybody forms a view about what it shows.

For a separate benchmark relevant to “Building a Timeline From Several Systems”, consult the Canadian workplace privacy guidance. Use it to test scope and safeguards against an external standard before the process is approved.

The five columns

Time as recorded. Correction applied, from the measured clock offset. Corrected time. Source system. What the row actually attests.

The fifth column is the one that does the work. "Badge 4417 presented at east door" is what the row attests; "employee arrived" is a conclusion and does not belong in a timeline.

Building it mechanically

  1. Pull raw rows from every system for the period, before filtering.
  2. Apply the measured clock offset for each system, and show it.
  3. Sort on corrected time.
  4. Mark every period longer than a stated gap as a gap, explicitly.
  5. Note which systems were capable of recording during each gap.
  6. Only then read it.

Step five converts a gap from an absence into a fact: nothing recorded between 10:20 and 12:40, by systems that would only have recorded a door being used or a transaction being made.

Gaps are not events

A timeline with gaps that are not marked reads as a continuous account with quiet periods, and quiet periods get interpreted.

Marking them explicitly — and saying what would have had to happen for a row to exist — stops that reading before it starts. In most workplaces a person sitting at a desk working generates nothing for hours.

Pulling everything, not the useful part

Extract the whole period from every system rather than the rows that look relevant. Filtering before building means the timeline shows what somebody expected to find.

It also means the exculpatory rows are missing, which is both unfair and the specific thing that makes a file indefensible when the full extract is eventually produced.

Rows that cannot be placed

Some records have uncertain times: a note written later, a recollection, a document saved at a different moment from when it was produced.

Put them in a separate list rather than forcing them into the sequence. A timeline with five placed rows and three unplaced ones is accurate; one with eight rows in apparent order, three of which are guesses, is not.

Reading it with somebody who disagrees

Once built, the most useful thing is to show it to somebody who was not involved and ask what it shows. They will read the gaps differently and they will question the inferences in the fifth column.

That is the review step, it takes fifteen minutes, and it happens almost never — which is why so many of these timelines are first questioned at the hearing.

Showing it to the person

The timeline is also the clearest way to put the matter to the employee: here are the records, here is what each says, here are the gaps, what can you tell us.

Presented that way it frequently resolves the whole thing, because the person can say what they were doing at 11:15 and the answer is ordinary. Presented as a conclusion, it produces a defence instead of an explanation.

The timeline the person builds

Giving the employee the same extracts and asking them to annotate the timeline produces a second document that is frequently better than the first.

They know what the gaps were. They can place the meeting, the delivery, the conversation. The combined document — organisation's rows, person's annotations — is the most complete account anybody is going to assemble.

That is also the form in which these matters most often resolve, because the annotation explains the thing that prompted the investigation.

Keeping the extracts separate from the analysis

The raw exports stay as exports, unmodified, with their extraction dates. The timeline is a separate document built from them.

Editing a raw extract — to tidy it, to filter it, to add a column — makes it an analysis wearing the appearance of a source, and that distinction is the first thing anybody competent will test.

Keeping it

The timeline, the raw extracts behind it, the clock offsets used, and the date each extraction was made.

That package is the evidential record of the investigation. Its absence is why, two years later, nobody can say what the organisation actually had — only what it concluded.