> For the complete documentation index, see [llms.txt](https://docs.monolithforensics.com/monolith/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.monolithforensics.com/monolith/using-monolith/evidence-management/evidence-items.md).

# Evidence Items

Create, track, and manage the devices, data sources, accounts, media, and other evidence associated with Monolith cases.

Evidence Items represent the devices, data sources, accounts, media, and other items associated with forensic work in Monolith.

An Evidence Item might represent a mobile phone, computer, hard drive, email account, cloud account, removable media, or another physical or logical source of data.

Every Evidence Item belongs to a Case. Once created, the Evidence Item becomes the central record for tracking information about that source and the work performed against it.

Evidence can connect to:

* Structured item metadata
* Contacts
* Intake information
* Chain of custody
* Physical location
* Assigned users
* Progress and status
* Acquisitions
* Storage items
* Child evidence
* Photos
* Notes
* Audits
* Reporting

Keeping this information together provides a consistent historical record of the item throughout its lifecycle.

### Evidence in the Monolith Workflow

Evidence is often one of the first records created after a Case.

A common workflow looks like:

```
Case
  ↓
Evidence Item
  ↓
Intake / Chain of Custody
  ↓
Acquisition
  ↓
Analysis / Forensic Work
  ↓
Reporting
```

An individual Case may contain many Evidence Items, and each item can move through its own workflow independently.

For example, one device may be awaiting legal authority while another device in the same Case is being acquired and a third is already in analysis.

Monolith tracks those Evidence Items individually while keeping all of them associated with the same Case.

### Global Evidence Items and Case Evidence

There are two common ways to work with Evidence Items in Monolith.

<figure><img src="https://2683670198-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCD1iskOdIm8E2TpCd9iZ%2Fuploads%2FYnwsmKGONCVu1Ia2x8Eq%2Fimage.png?alt=media&amp;token=47e9112e-ee74-4502-bf73-0f32196cfaee" alt=""><figcaption></figcaption></figure>

#### Evidence Management > Evidence Items

The **Evidence Items** page provides an organization-wide view of evidence across Monolith.

Use this view to:

* Search for evidence across Cases
* Filter and sort Evidence Items
* Review evidence across the organization
* View Evidence Items associated with your Cases
* Add an Evidence Item when you already know which Case it belongs to

Because this view is not scoped to a single Case, Monolith requires you to select the appropriate Case when creating an Evidence Item here.

The **My Cases** option can be used to focus the list on Evidence Items belonging to Cases associated with the current user.

#### Case > Evidence

When you are already working inside a Case, use the Case's **Evidence** tab to work with the Evidence Items associated with that Case.

Creating evidence from within a Case keeps the workflow focused on the Case you are already working in.

Both views work with the same underlying Evidence Items. The difference is simply your frame of reference.

### Ways Evidence Can Enter Monolith

Evidence does not always need to be entered manually from scratch.

Depending on your workflow, Evidence Items can originate from several places.

#### Manual Entry

Create an Evidence Item directly from:

* **Case > Evidence**
* **Evidence Management > Evidence Items**

#### Relay Requests

Evidence information submitted through **Relay** can flow into a Monolith Inquiry.

When the Inquiry is used to create a new Case or merged into an existing Case, selected evidence information can carry forward into Evidence Items without requiring your team to re-enter the requestor's information.

See [**Managing Relay Requests in Monolith**](/monolith/relay-request-portal/relay-overview/managing-relay-requests-in-monolith.md) for more information.

#### Monolith Mobile

Monolith Mobile can be used during intake or field work to create Evidence Items, capture evidence information, and photograph items directly from a phone or tablet.

This creates the same underlying Evidence Item used throughout Monolith.

See [**Monolith Mobile**](/monolith/start-here/welcome-to-monolith/monolith-mobile.md) for additional mobile workflows.

#### Smart Paste

If evidence information already exists in text that you can copy to your clipboard, **Smart Paste** can help populate the Evidence form.

Copy the available item information, open the Evidence creation form, and use **Smart Paste** to populate supported evidence details.

Review the populated information before creating the Evidence Item.

Smart Paste focuses on Evidence details and does not populate chain of custody information or the Linked Contact.

### Create an Evidence Item

<figure><img src="https://2683670198-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCD1iskOdIm8E2TpCd9iZ%2Fuploads%2FA8ELBaS6iYyn3ABdYdDT%2Fimage.png?alt=media&amp;token=9c8e8f58-2367-4717-9ae0-ea1c5364475d" alt=""><figcaption></figcaption></figure>

To create an Evidence Item from the organization-wide Evidence Items page:

1. Navigate to [**Evidence Management**](/monolith/using-monolith/evidence-management.md) **> Evidence Items**.
2. Click **Add Evidence**.
3. Select the **Case** the Evidence Item belongs to.
4. Enter or review the Evidence Number.
5. Select an **Evidence Type**.
6. Enter the available information about the item.
7. Complete any applicable Custom Fields.
8. Enter Intake Details now, or complete intake later.
9. Click **Create Evidence**.

When creating Evidence from within a Case, the Evidence Item is created in the context of that Case.

### Capture Useful Evidence Information

The Evidence form is designed to capture structured information that helps identify, track, search, report on, and work with the item throughout its lifecycle.

Depending on the item, useful information may include:

* Evidence Type
* Item Brand or Provider
* Item Name
* Model Number or Service
* Unique Identifier
* Size
* Priority
* Description
* Linked Contact
* Custom Fields

Capture the information that is available and relevant to your workflow.

More complete records improve the usefulness of Monolith for searching, filtering, reporting, historical review, and operational visibility.

#### Linked Contacts

Evidence can be associated with a [Contact](/monolith/using-monolith/people/contacts.md).

This is useful when a device, account, or other item has a meaningful relationship to a person involved in the Case, such as a device owner, custodian, employee, suspect, or other relevant contact.

Linking the Contact preserves that relationship as part of the Evidence record.

### Evidence Types

Evidence Types classify the kinds of devices, data sources, and other items handled by your organization.

Examples might include:

* Mobile Phone
* Computer
* Hard Drive
* Removable Media
* Email Account
* Cloud Account

Configure [Evidence Types](/monolith/using-monolith/settings/evidence-types.md) that reflect the work your organization actually performs.

Consistent Evidence Types make it easier to understand and report on your workload over time.

For example, an organization can distinguish between the number of mobile phones, hard drives, cloud accounts, email accounts, or other sources processed during a given period.

### Evidence Numbering

Each Evidence Item has an Evidence Number.

Monolith can automatically generate Evidence Numbers using the format configured by your organization under **Settings >** [**Item Number Formats**](/monolith/using-monolith/settings/item-number-formats.md).

For most organizations, allowing Monolith to generate Evidence Numbers is recommended.

A consistent organization-wide numbering format helps:

* Keep Evidence Numbers unique
* Reduce ambiguity between Evidence Items
* Make global evidence searches easier
* Improve organization-wide reporting
* Make individual items easier to reference outside the context of a single Case

Some organizations use their own evidence numbering procedures, and Monolith supports manually entered Evidence Numbers when required.

For example, an organization may choose to restart evidence numbering within every Case. While this may match an existing procedure, repeated values such as `EVI-001` across many Cases make the organization-wide Evidence Items view less immediately identifiable.

Choose a numbering strategy that fits your organization's procedures while considering how Evidence Items will be searched and reported across Monolith over time.

### Intake and Chain of Custody

Creating an Evidence Item and formally intaking it do not have to happen at the same time.

The **Intake Details** section allows you to begin chain of custody tracking when the item is received.

Intake information can include:

* Received By
* Received From
* Signatures
* Intake Timestamp
* Location Received
* Notes

**Received By** identifies the person receiving the item or data, typically a Monolith user, and begins the associated chain of custody record.

Once chain of custody begins, Monolith can track the item's location as it moves between people and Item Locations.

{% hint style="info" %}
Chain of custody is available for every Evidence Item and is strongly recommended when your organization needs to maintain location and custody history.
{% endhint %}

Intake does not need to be completed during initial Evidence creation.

For workflows involving multiple Evidence Items, your team may choose to create the records first and then use bulk chain of custody actions to intake or move multiple items together.

See [**Item Locations**](/monolith/using-monolith/evidence-management/item-locations.md) for information about configuring the physical locations used during these workflows.

### Status, Progress, and Assignment

Monolith provides several independent ways to describe what is happening with an Evidence Item.

These fields answer different questions.

#### Status

**Status** represents the current state or condition of the Evidence Item.

Evidence Status uses a standardized set of options in Monolith rather than a customer-defined workflow.

#### Progress

**Progress** represents where the Evidence Item currently sits in your organization's workflow or pipeline.

Evidence Progress is configurable so organizations can define stages that reflect how their lab operates.

A pipeline might include stages such as:

```
Pending Authority
→ Intake
→ Acquisition
→ Analysis
→ Complete
```

The exact pipeline depends on your organization's process.

Evidence Progress is intentionally independent from Case Progress. A Case may contain several Evidence Items at completely different stages of work.

#### Assigned User

An Evidence Item can be assigned to one user associated with the Case.

Assignment answers a different question from Status or Progress:

* **Status:** What state is the item in?
* **Progress:** Where is it in the workflow?
* **Assigned User:** Who is responsible for it?

Keeping these concepts separate provides more useful operational visibility than trying to represent all three with a single field.

### Understanding the Evidence Record

Open an Evidence Item to view its complete record.

<figure><img src="https://2683670198-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FCD1iskOdIm8E2TpCd9iZ%2Fuploads%2FH0zavABDLnwzQSLzDV4H%2Fimage.png?alt=media&amp;token=01cd26ea-fdf1-4781-9452-ce5b6d397dd3" alt=""><figcaption></figcaption></figure>

The Evidence Overview brings together identifying information, workflow information, location information, and related activity.

Depending on the Evidence Item and your configuration, information may include:

* Evidence Number
* Case
* Evidence Type
* Item Name
* Brand or Provider
* Model Number
* Unique Identifier
* Assigned User
* Priority
* Status
* Progress
* Intake information
* Current Location
* Location Path
* Linked Contact
* Size
* Custom Fields
* Acquisition information
* Parent or Child relationships
* Photo information
* Audit information

The Evidence record also provides access to several related workflows.

### Chain of Custody

The **Chain of Custody** area maintains custody and location history for the Evidence Item.

As the item moves between users and physical locations, Monolith can maintain its current location and historical custody record.

This helps preserve a defensible history of where the item has been and who has handled it.

### Acquisitions

An Evidence Item represents the original source or item being examined.

An **Acquisition** represents a forensic collection, extraction, image, or other acquisition performed against that source.

One Evidence Item can have multiple Acquisitions.

For example:

```
Mobile Phone
├── Initial Logical Acquisition
├── Full File System Acquisition
└── Supplemental Acquisition
```

Keeping the source Evidence Item separate from its Acquisitions allows Monolith to preserve both the original evidence record and the individual forensic collections performed against it.

### Storage Items

Acquired forensic data often needs to be stored somewhere.

Monolith uses **Storage Items** to track the physical or digital storage used to preserve forensic acquisitions.

A common relationship is:

```
Evidence Item
  ↓
Acquisition
  ↓
Storage Item
```

These are separate records because they represent different parts of the forensic workflow.

The Evidence Item represents the source. The Acquisition represents the forensic collection. The Storage Item represents where that collected data is preserved.

See [**Storage Items**](/monolith/using-monolith/evidence-management/storage-items.md) for additional information.

### Child Items

Evidence can contain other evidence.

Use **Child Items** when something associated with or contained within the original evidence needs to become independently tracked evidence.

For example, removable media or another component removed from a source item may need its own Evidence record so its location and chain of custody can be tracked separately.

The parent and child relationship preserves the connection between those Evidence Items.

### Evidence Photos

Photos can be associated directly with an Evidence Item.

Use Evidence Photos to document the physical item, identifying information, condition, labels, packaging, or other useful visual information.

Photos can be uploaded from existing images or captured as part of a mobile workflow using Monolith Mobile.

### Audit Logs

The **Audit Logs** area shows audit activity involving the Evidence Item when the item has been included in a Monolith Audit.

This provides a record of the item's participation in inventory and verification workflows.

See [**Audits**](/monolith/using-monolith/evidence-management/audits.md) for information about conducting evidence and storage audits.

### Notes

Evidence Notes allow information to be documented directly against the Evidence Item rather than only at the Case level.

This helps keep item-specific observations, work details, and other information associated with the source they relate to.

### If Evidence Is Created in the Wrong Case

Because every Evidence Item belongs to a Case, confirm that the correct Case is selected before creating the item from the global Evidence Items page.

Monolith includes an Evidence migration workflow for situations where an Evidence Item has been created in the wrong Case.

Review the migration option before deleting and recreating an Evidence Item solely to correct its Case association.

{% hint style="warning" %}
Deleting Evidence can remove an important part of the Case and its historical record. Confirm that deletion is appropriate before removing an Evidence Item.
{% endhint %}

### Recommended Practices

For a strong and consistent Evidence workflow:

* Create Evidence Items as early as practical once the relevant sources are known.
* Use structured Evidence Types that reflect the work your organization performs.
* Capture useful identifying information rather than relying only on a description.
* Link Contacts when an Evidence Item has a meaningful relationship to a person.
* Use your organization's configured Evidence Number format when possible.
* Keep Evidence Numbers globally identifiable when your operating procedures allow it.
* Use Evidence Progress to represent the item's position in your workflow.
* Use Status, Progress, and Assignment for their separate purposes.
* Use chain of custody when location and custody history are important to the record.
* Track where forensic acquisitions are stored by associating them with the appropriate Storage Item.
* Use Child Items when something removed from or associated with Evidence needs its own independent tracking.

The goal is to create a record that remains useful not only during the current examination, but also for future searching, reporting, review, and historical reference.

### Related Documentation

* [**Evidence Management**](/monolith/using-monolith/evidence-management.md)
* [**Item Locations**](/monolith/using-monolith/evidence-management/item-locations.md)
* [**Storage Items**](/monolith/using-monolith/evidence-management/storage-items.md)
* [**Audits**](/monolith/using-monolith/evidence-management/audits.md)
* [**Monolith Mobile**](/monolith/start-here/welcome-to-monolith/monolith-mobile.md)
* [**Managing Relay Requests in Monolith**](/monolith/relay-request-portal/relay-overview/managing-relay-requests-in-monolith.md)
