One-sentence brief
Investigating a leak or exploit should never authorize doxxing, off-platform surveillance, biometric profiling, harassment, or guilt by access.
JUSTICE, RIGHTS & GOVERNANCE
A server-bounded investigation model using authorized game logs, minimum necessary data, competing hypotheses, chain of custody, exculpatory evidence, independent review, and appeal.
ORIENTATION
Investigating a leak or exploit should never authorize doxxing, off-platform surveillance, biometric profiling, harassment, or guilt by access.
WORKING BRIEF
Define the incident, evidence sources, time range, reviewer authority, retention, and permitted uses before searching. Narrow requests protect both privacy and evidence quality.
Create read-only copies or immutable event references, record who accessed them, and retain source context. Chat, trade, movement, and access logs have different meanings and should not be collapsed.
Consider malicious action, accident, shared credentials, software defect, spoofed events, compromised automation, misunderstanding, and false allegation. Access identifies a pool, not a culprit.
Temporary access limits may protect the world while evidence is reviewed, but should be narrow, time-limited, explained, and reversible. Preserve essential account access where safe.
Provide the decision basis, evidence summary, conflict checks, and appeal. If overturned, restore access and assets, delete unsupported warnings where policy allows, and correct downstream reputation or faction records.
COMPLETE DOSSIER
Terms are defined for this site’s evidence method, not as universal legal or clinical definitions.
RESEARCH EDITION
This page follows the public method for provenance, confidence, source independence, alternative accounts, limitations, review state, and visible correction.
CONTINUE