This article is about doing it properly.
What OSINT is and is not
Open source intelligence is intelligence derived from publicly available information. The operative word is publicly. Information behind an authentication barrier, obtained through a false identity, or accessed contrary to a platform’s terms is not open source.
The distinction determines the legal basis. Observing a public post requires no special authority. Creating a persona to gain access to a closed group is covert activity requiring specific authorisation.
The collection disciplines
Attribution management — research from an official network reveals institutional interest. Collection from managed environments protects discretion.
Preservation at point of collection — online material is ephemeral. Anything of evidential relevance must be captured with sufficient technical detail: full page capture, complete URL, timestamp, collecting analyst, and hash.
Verification before reliance — before any open source finding informs a decision, establish provenance, earliest instance, corroboration, and technical metadata consistency.
Documenting the negative — record searches that returned nothing.
Legal boundaries
Purpose limitation — collection relates to a defined investigative purpose.
Proportionality — systematic and sustained monitoring of an individual is qualitatively different from a single lookup.
Third-party data minimisation — retention should be reviewed.
Terms of service and access controls — circumventing restrictions may engage computer misuse provisions.
Covert engagement requires authorisation — persona-based access to closed communities requires specific approval.
What tooling should provide
Structured capture — automatic preservation with URL, timestamp, analyst identity and hash.
Case-linked storage — findings attached to case files with provenance.
Entity integration — findings flow into the same entity model as other data.
Audit logging — every query recorded against case authority.
Authentication support — integration with media authentication analysis.
Governance that makes the capability durable
Write a policy distinguishing open source research from covert engagement. Document an approval route for anything approaching the latter. Mandate capture and provenance standards. Audit query logs against case authority.
pi-scout integrates open source findings into a governed investigative entity model with provenance grading and query-level audit.



