Criminology & Forensic Studies¶
← Back to Mechanisms by Origin Domain
The study of crime, criminal behavior, the institutions that respond to crime, and the scientific methods used to investigate it. Canonical traditions: classical and positivist criminology, routine activity theory, strain and labeling theories, forensic science (DNA, toxicology, digital forensics).
Reviewed origins (37)¶
These attributions have been reviewed as historical or practice origins and promoted to mechanism frontmatter.
- Audit Trail Review — Inspects logs, version histories, document histories, custody records, or system traces to identify edits, gaps, and handling anomalies.
- Background Check — Retrieves external records of a candidate's documented past — conduct, credit, sanctions, history — to reveal a track record the candidate cannot see or won't disclose.
- Before–After–Elsewhere Evaluation — Measures the target outcome before and after at the intervention site and — the defining addition — at the places the hazard could have moved to, so a local win cannot pass as reduction until 'elsewhere' clears too.
- Blind Proficiency Test — Feeds a laboratory known-origin samples disguised as ordinary casework to measure — blind — how often its whole attribution pipeline gets the source right.
- Case Management Tiers — Assigns cases to light, standard, intensive, or specialist management tracks according to need, risk, or complexity.
- Chain-of-Custody Cross-Check — Compares process-imprint attribution against explicit provenance or custody evidence without conflating them.
- Chain-of-Custody Evidence Review — Authenticates an artifact by reconstructing its unbroken, documented custody trail — proving the thing in hand is the same one collected at origin, handled intact and untampered.
- Chain-of-Custody Form — Records an unbroken, signed sequence of who held an item, when, and with what integrity check, so the transfer chain itself can be proven later.
- Chain-of-Custody Log — Maintains an unbroken, timestamped record of every hand and transfer an item passes through, so any later claim about its status can be audited back to origin.
- Chain-of-Custody or Lineage Check — Reconstructs an item's unbroken trail back to its origin — every handoff and transformation logged beside the content — so its source class is established rather than assumed when it is used.
- Chain-of-Custody Record — Holds an artifact's identity intact through every handoff by logging who held it, when, and what they did — an unbroken, tamper-evident chain of possession.
- Chemical Taggant Program — Embeds a covert, coded chemical marker into a product at manufacture so its batch and maker can be decoded after the fact — and can't be easily counterfeited.
- Custody Chain Reconciliation — Reconstructs an unbroken sequence of who held an item when, confirming each handoff refers to the same sealed object and assigning any gap to an accountable owner.
- Delayed Interview Protocol — Elicits after-the-fact accounts on a structured protocol that labels their memory-based uncertainty and cross-checks them against independent sources, so reconstruction never impersonates live observation.
- Evidence Locker — A restricted physical or digital custody artifact for preserving evidence outside ordinary access.
- Forensic Discriminator — Resolves which generator produced a shared observation by hunting for a trace that only one candidate would have left behind.
- Forensic Scenario Reconstruction — Builds and compares scenarios that could have produced observed traces while preserving uncertainty about alternatives.
- Hotspot Response Plan — Concentrates a surge of action in the spatial, temporal, or network regions where incidents cluster, with built-in guardrails against displacing the problem or over-burdening the place.
- Intervention Displacement Stress Test — A pre-deployment probe that grants the control its local success and asks the harder question — where would the blocked pressure go, who would absorb it, and how long until it surfaces — before you commit.
- Investigation-Report Chronology Appendix — Publishes the neutral event-and-evidence chronology, with its gaps and uncertainties marked, as a fixed reference the narrative-ordered report points back to.
- Layered Case or Event Dossier — Connects overview, source evidence, conflicting accounts, uncertainty, later interpretation, response, and correction as distinguishable layers.
- Likelihood-Ratio Attribution Report — Turns a signature comparison into a calibrated likelihood ratio — how much more the evidence favors one origin than a stated alternative — with scope and limits attached.
- Manufacturing Toolmark Analysis — Reads the microscopic marks a tool or machine imprints on what it makes or touches, matching an object back to the individual tool that shaped it.
- Moderation Record with Reentry — Logs rule violations and their repair while defining the conditions under which standing is restored.
- Provenance and Chain-of-Custody Log — A ledger that records who produced, held, moved, and altered each piece of evidence, so every layer's origin and handling travel with it.
- Provenance Chain-of-Custody Record — Reconstructs and records the origin-to-here custody chain of an inherited substrate, so every handoff — and every gap in the trail — is on the record before the substrate is trusted.
- Reconstruction Workspace or Replay Table — A workspace that replays independent evidence streams onto a shared timeline to reconstruct what happened, keeping the reconstruction visibly separate from the raw inputs.
- Reference Library Match — Looks a query signature up against a governed library of known-origin references and returns scored candidate matches — only as trustworthy as the library is current and representative.
- Repair or Reentry Reflection — After a breach or drift, a structured reflection that turns the violation into understood harm and renewed commitment — restoring standing without permanent shame.
- Restorative Conference or Repair Circle — A facilitated circle where the harmed, the responsible, and the affected clarify harm, agree on repair, and set the conditions for restored standing.
- Sealed Evidence Package — Encloses an item and its chain-of-custody record behind a tamper-evident seal, so every handler can move it and prove it arrived unaltered without opening it.
- Sensor Fingerprint Analysis — Detects device-specific noise, calibration, dead-pixel, acoustic, or timing patterns.
- Signature Likelihood Report — Documents features, exemplars, controls, confidence language, alternative sources, and limits.
- Spoofing & Counter-Forensic Challenge — Attempts to imitate, suppress, transfer, or plant signature features before accepting attribution.
- Structured Professional Judgment Tool — A structured instrument that walks one decider through a fixed set of factors and the case's own facts to reach a defensible, proportionate judgment — structured, but deliberately not reduced to a formula.
- Substitution Channel Monitoring Workflow — An ongoing routine that watches the channels suppressed behavior migrates to, confirming and chasing displacement so an intervention that looks successful locally isn't merely pushing the problem sideways.
- Toolmark Comparison Protocol — Compares striations, impressions, wear marks, or tooling defects across known and disputed artifacts.
Also Draws from This Domain (76)¶
These mechanisms have another primary origin but were reviewed as also drawing materially from this domain.
- Access Restriction or Exclusion Rule — A pre-declared rule that curtails or removes a member's access to the group's shared benefit when lesser sanctions fail — the terminal boundary of peer enforcement.
- Account/Event Reconstruction Table — Separates what the source says from the reconstructed event sequence, inferred omissions, and uncertain intervals.
- Actual Fact Ledger — Pins down the established, actually-obtaining facts of the case as the fixed anchor every counterfactual is edited away from and measured against.
- Admissibility or Relevance Gate — Prevents traces below provenance, quality, or relevance thresholds from being used in high-stakes reasoning.
- Affected Target Protection Protocol — Shields a targeted person from informal punishment — harassment, retaliation, exclusion — while responsibility is being clarified, without dismissing the underlying harm.
- After-Action Proportionality Review — Reviews whether the response produced intended safety, fairness, deterrence, repair, or learning without excessive collateral burden.
- Anonymous Reporting — Strips the reporter's identity from a disclosure so the fear of being personally targeted can no longer gate whether a concern is raised.
- Archival Provenance Metadata Template — A structured template for capturing an instance's origin, custody, and transformation history, so that a claim to be the same work rests on documented evidence rather than assertion.
- Artifact Metadata Capture — Attaches provenance and setting to a captured artifact so the object stays interpretable once it leaves the moment it documents.
- Audit and Penalty System — Combines probabilistic inspection with calibrated consequences so that the expected cost of cheating exceeds its gain, without checking everyone.
- Audit Log — Keeps an append-only, attributable record of every action on protected data — who, when, and what changed — so integrity events can be investigated and reconstructed after the fact.
- Audit Log and Trace — Records actual effect events in a durable form that can be inspected, explained, and reconciled.
- Audit Log Review — Replays an append-only event history to reconstruct how two records drifted apart, classifying the cause so the correct prior state can be restored and the leak sealed.
- Audit Trail Export — Emits the ordered, timestamped record of who did what to which record, in a portable form an outside reviewer can ingest and verify independently.
- Audit-Trail Sampling — A sampling method comparing producer assertions against trace records, transactions, logs, cases, or physical evidence.
- Backward-Chaining Reconstruction — Reasons backward from an observed output through the rules that could have produced it, yielding a bounded set of candidate sources rather than one arbitrarily chosen preimage.
- Barrier Coverage Matrix — A cross-tabulation of control layers against variant classes and contexts that marks demonstrated coverage apart from unknown, stale, correlated, or merely-inferred coverage — making uncovered cells and shared blind spots visible before escape finds them.
- Barrier Gap and Shortcut Audit — An audit that identifies unintended high-permeability paths around containment or intended routing boundaries.
- Before/After Condition Photography — Creates a dated, registered set of before, during, and after images so condition change is visible at a glance and every treatment stays traceable to what was originally there.
- Beneficial Ownership and Influence Disclosure — Requires the real people behind bidders, licence-holders, and lobbyists to be named on the record, so hidden ownership and undisclosed influence can no longer work the allocation in the dark.
- Black Box Log — Maintains tamper-resistant or failure-resistant traces for situations where ordinary records may be lost during the event itself.
- Breach Checklist — A ready-to-hand list of the must-see events, forbidden combinations, and timing markers that flag — live, in the moment — when a familiar encounter has left its script.
- Caseload Cap — Sets an enforced not-to-exceed ceiling on the number or risk-weighted load an overseer may carry, and routes anything over the line elsewhere.
- Causal-Temporal Trace — Lays the narrative's events, actors, and causal claims onto one timeline so anachronisms and causal-capacity mismatches surface — the places where the story needs something to happen before the thing that makes it possible.
- Cognitive Interview — Walks an expert back through one specific remembered episode in fine-grained detail, reinstating the original context to recover the cues, reasoning, and rule-breaks they can no longer summarize.
- Conditional Release or Off-Ramp Protocol — The defined pathway by which a target under pressure earns its way back — through verified compliance, restitution, or a negotiated transition — so coercion always has a reachable exit.
- Contemporaneous Event Log — Captures events into the record as they happen, at near-zero latency, so a timestamped primary trace exists before memory or hindsight can reshape it.
- Contradiction Timeline — Places inconsistent statements, records, and observed events on a timeline to distinguish memory, framing, drift, and strategic revision.
- Corroboration Ladder — Orders independent traces from weak consistency checks to strong external confirmation and contradiction.
- Cross-Boundary Escape Incident Review — Investigates an apparent escape event across teams or jurisdictions to establish whether it is real selection-driven circumvention or an impostor — migration, a protected refuge, an implementation failure, or measurement drift.
- Cross-Jurisdiction Incident Review — A recurring convening where separately-accountable jurisdictions pool their incident data, so a hazard that slips across the seam between them gets caught, owned, and made good instead of falling into the gap no one answers for.
- Custody Roster or Stewardship Rotation — Assigns named, rotating responsibility for the object's care, transport, display, storage, and repair, so an unbroken line of accountable custody follows it over time.
- Engagement Threshold Table — Converts severity or state tiers into a graduated ladder of proportional response, so a mild condition unlocks a light action and a severe one a stronger action.
- Equality Before Rules Test — Probes whether the same rule produces the same outcome across identity, rank, and status — including for the powerful — by comparing matched cases that differ only in who the actor is.
- Evidence Provenance Checklist — A checklist for classifying whether cited reasons are primary, secondary, independent, current, relevant, and verified.
- Fraud Risk Cutoff Review — Runs a recurring review of a fraud-score cutoff, splitting decisions into allow / review / block bands and re-tuning the band edges from monitored outcomes like caught fraud, chargebacks, and false declines.
- Fraud Risk Decay Model — Estimates how the probability of fraud or misuse for a flagged actor falls over time and events, producing a projected decay curve with a confidence band per risk class.
- Free-Recall-Then-Recognition Probe — Asks first for unaided recall, then for recognition, and reads the gap between them to tell 'never stored' apart from 'stored but not retrievable.'
- High-Risk Targeting List — Ranks cases, sites, or suppliers by predicted contribution to harm or cost so scarce scrutiny lands on the riskiest few — and holds the risk scores themselves to account.
- Incident Snapshot — Packages state, context, logs, timestamps, and human observations into a preserved record for later analysis.
- Initiator Interview Protocol — A structured interview process for recovering what early actors knew and why they acted.
- Intent Audit — Reviews records, incentives, choices, and communications for evidence that a function was deliberately pursued or knowingly maintained.
- Isotopic Fingerprint Analysis — Measures the stable-isotope ratios carried in a material to place its origin in the geography and geology those ratios record.
- Layered Case Note — A record template with separate fields for what was observed, what is inferred, and what was reconstructed later, so a single note keeps its evidentiary strata visible.
- Likelihood Ratio for Non-Detection — Quantifies how much less likely the null finding is under target presence than target absence.
- Liveness or Presence Check — Proves a real, live, present subject is producing the evidence right now — so a photo, recording, mask, or deepfake cannot stand in for a genuine presence.
- Model-Output Signature Probe — Tests whether a model, generator, or pipeline leaves recurrent statistical artifacts.
- Motive-Opportunity-Bias Analysis — Checks whether a proposed distortion pattern is plausible given the source's incentives, opportunity, and known bias profile.
- Negative-Control Signature Panel — Challenges candidate marks against non-source exemplars and shared-process controls.
- Negative-Evidence Reliability Review — Scrutinizes a claimed absence before it is allowed to eliminate anything — asking whether the missing footprint could actually have been detected, whether the right place was searched, and whether the absence is strong enough to count.
- Pattern Drift and Exception Audit — Samples deployed instances against the intended grammar to catch unauthorized mutations, semantic collisions, and one-off exceptions before they erode the family.
- Physical Security Zoning — Arranges physical space into concentric graded zones so reaching the asset means passing successively harder, differently-guarded boundaries under lengthening exposure.
- Platform Abuse Controls — Runs distributed abuse through an end-to-end pipeline — detect the pattern, throttle or restrict, adjudicate appeals, and watch for displacement — to contain coordinated misuse.
- Probation Review Schedule — Tapers oversight through scheduled checkpoints as clean checks accumulate, while holding a floor of supervision and instant escalation triggers throughout the probation.
- Proportional Enforcement Ladder — Starts with the least coercive enforcement level likely to achieve compliance, then escalates only when defined failure or risk conditions appear.
- Provenance Chain Review — Authenticates an artifact by tracing its origin and every handoff — accepting it only when the lineage back to a trusted source is complete and unbroken.
- Randomized Patrol or Route Schedule — Generates unpredictable coverage schedules across space and time — routes, timings, checkpoints — that still satisfy coverage requirements and weight high-risk zones more heavily.
- Read-Only Raw Evidence Archive — An immutable, write-once store that preserves the earliest raw evidence read-only, so correction and synthesis can never overwrite the original trace.
- Reconstruction Note — A written record that lays a reconstructed whole out as three separate columns — what is known, what is inferred, and what is still missing — so speculation never inherits the authority of fact.
- Red-Flag Screen — Uses a short checklist of disqualifying warning signs to pull suspect candidates out of the flow early — a fast, high-sensitivity screen tuned to miss few real problems even at the cost of false alarms.
- Rolling Hotspot Recalibration — Re-scores and re-ranks the hotspot map on a fixed cadence against what actually happened, so the map tracks a moving risk landscape instead of freezing on its first version.
- Scapegoat Screening Review — Checks whether a salient, low-power, or last-in-chain actor is absorbing more blame than their actual contribution and the available evidence support.
- Situational Attribution Review — Checks whether a behavior or outcome has been attributed to a stable trait when situational causes — constraints, incentives, role, history, exposure — better explain it, and states the situational explanation the decision should use instead.
- Source Attribution Confidence Rubric — A graded scale that scores how sure you are of an item's source — separately from whether the content is true — and trips a corroboration gate when the grade is low and the stakes are high.
- Source Attribution Training Set — A curated corpus of real items whose true source class is already known, held as the gold reference that calibrates and teaches an attribution judgment — human or model.
- Source Confusion Matrix Review — A retrospective review that tabulates which source classes get mistaken for which — reading the off-diagonal cells to find systematic, directional misattributions and feed the fixes back.
- Source Criticism Protocol — Uses structured questions about authorship, purpose, audience, context, proximity, and transmission to evaluate a source before accepting its claims.
- Spatial or Network Cluster Detection — Tests where high-risk units genuinely cluster in space or on a network, screening out the concentrations that are only chance, so hardening targets real hotspots.
- Spectral Signature Matching — Measures a material's full spectrum and matches its shape against a reference spectral library to identify what it is — and thereby where or when it could have come from.
- Stochastic Challenge or Audit Timing — Randomizes whether and when a check, challenge, or audit fires on a stream of events so an evader can never find a reliably safe window — keeping perceived detection risk above the exploitability threshold.
- Stylometric Attribution Model — Estimates source likelihood from stable linguistic, formatting, rhythm, or choice-pattern features.
- Sybil, Collusion, and Brigading Detection — Detects fake accounts, coordinated rings, paid reviews, and retaliatory brigading that manufacture or attack reputation.
- Time-Anchored Evidence Record — Attaches each observation to an explicit, tamper-evident temporal anchor so that later comparison can separate true change from recall bias, narrative smoothing, or context drift.
- Trace-Element Profile Matching — Fuses the concentrations of many trace elements into one multivariate profile and matches it to a specific source deposit or batch.
- Trace-to-Claim Diagram — Visualizes trace, source, inference bridge, hypothesis, and defeaters.
- Witness / Source Comparison — Compares firsthand accounts or records by role, access, incentive, timing, memory risk, and corroboration against non-testimonial evidence.