Spokes.wiki Search About
Report source ↗ source url updated Thu Aug 13 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

GLAN/Bellingcat Justice & Accountability Methodology

Methodology for Online Open Source Investigations into Incidents Taking Place in Ukraine since 24 February 2022 — 90 pages, jointly authored by Bellingcat and the Global Legal Action Network, last updated 14 December 2022. It is the working manual of Bellingcat’s Justice and Accountability Unit, published in full rather than described.

Where the Berkeley Protocol states what the field’s standards are, this states what one organisation actually does on Monday morning: which browser plugin to install, which spreadsheet a link goes in, which document the verification reasoning is written into. It is the first source here written by the institution the spoke has been arguing about.

What it is for, and what it deliberately is not

The aim is narrow and stated plainly: to ensure material the Unit finds “is gathered in accordance with rules on admissibility of evidence so as to make it suitable for use in future legal proceedings and other accountability processes.”

Two exclusions matter as much as the content. The manual “does not teach online investigation methods such as locating or verifying content; it assumes knowledge of these and instead addresses the surrounding aspects relating to legal admissibility.” And it “does not cover forensic preservation, since Bellingcat’s preservation is carried out by our partners at Mnemonic.”

So the craft half of open-source investigation, the geolocation and chronolocation this spoke’s coverage edge asks for, is assumed here rather than taught. What the document supplies instead is the apparatus around it.

The provenance it was built to survive

The reasoning behind the whole manual is a problem of court procedure. Evidence in a criminal trial “is generally ‘produced’ by a witness who can speak to its provenance and reliability” — a crime-scene photographer the defence can cross-examine, a police officer who checked the CCTV timing. A video pulled off the internet by an investigator has no such witness. The methodology is the substitute: a recorded trail detailed enough that the investigator can be cross-examined in the photographer’s place.

That framing was tested rather than asserted. In 2021 GLAN, Bellingcat and Swansea University’s OSR4Rights project “designed and convened a mock hearing challenging the admissibility of a piece of open source evidence discovered using the methodology,” staged in the context of an English court; the draft “was then revised again to address the issues raised by the exercise.” The lineage runs back to a 2018 GLAN/Swansea/Garden Court Chambers workshop on Yemen, through a 2019 hackathon in which outside investigators trialled the method, to the Unit’s launch in 2022.

The phases

The investigation is cut into numbered phases: I Systems and resources · II Briefings · III Categories of information · IV Preparation · V–VI Discovery / content gathering · VII Verification & Analysis, with annexes on data protection and closed groups, sexual and gender-based crimes, crimes against children, legal briefing, style, and an incident-assessment template.

Phase VII is where this spoke’s vocabulary appears: it “includes geolocation, chronolocation, corroboration, and describing your content,” feeding the Research Notes and then the Incident Assessment Report, the investigation’s final product. The assessment is explicitly “a living document which will contain all of your verification work and conclusions,” and the verification “must be clearly displayed” within it.

The intended reader is specified, which is unusual: reports “should be written in an accessible style, but your target audience is someone who understands the concepts of geolocation, chronolocation and cross-referencing.” A fuller, “very detailed geolocation report” is written later, only if a particular proceeding calls for it.

Two rules with teeth

The Original Online Source. For examinable content, “always try to find the earliest online source (the Original Online Source) of the full text, video, or image. This earliest user should be the person cited for the content even if their post isn’t how you first came across it.” The Hunchly capture files “should trace how you came upon the earliest version,” and a later version is preserved too when it is higher quality or longer. Attribution follows the content’s origin, not the investigator’s path to it, and the path is retained anyway.

Content is sorted before it is analysed. Examinable (or core) content is what an analyst can interrogate: audiovisual content, satellite imagery, maritime/aviation trackers, weather logs, social posts usable for chronolocation or bulk text patterns, user-entry sites like Google Maps and Wikimapia. Descriptive content, meaning an NGO’s witness statements or a news article recounting an event, “cannot be examined using OOSI techniques.” The line decides what may carry a conclusion.

The stack, named

The manual names its tooling, which makes the practice checkable: Hunchly (a Chrome plugin that “tracks your online activities, preserving essential information about the webpages”), a VPN, Slack, cloud storage, and Uwazi as the analysis database. Bookkeeping runs through named spreadsheets (Civilian Harm and Ukraine Witness seed data, a Device Log Sheet, a Mnemonic Preservation Sheet, an Incident Link Sheet) plus per-investigation Research Notes and an Incident Assessment. Anything amounting to relevant information “should be placed in the archiving sheet so that it is picked up by Mnemonic”; once an investigation closes, “all relevant material will go to them and you/Bellingcat will not be responsible for preservation of the content.”

The passive research account

Annex II’s treatment of research accounts is candid in a way vendor documentation is not. A fresh account per investigation is the ideal and “in reality this is not feasible”: platforms run bot-detection, so building a stable account takes a time-consuming process the manual withholds; and “continually generating new social media accounts appears extremely inauthentic to social media platforms.” A VPN helps only so far, because a platform “may still be able to identify the fingerprint of a user from other pieces of information, such as the version of the browser, the language, the time settings of the machine, the window size.” A separate account is still wanted, partly “to mitigate potential algorithmic selection based on the profile that a researcher has developed on their personal account.”

Portions are redacted in the published version: paid satellite imagery sources and parts of the account-generation procedure are marked withheld.

Connections

bellingcat · global-legal-action-network · geolocation-chronolocation · berkeley-protocol · mnemonic · uwazi · conflict-monitoring · ironsight