Responsible OSINT
How to run a responsible, authorized username investigation
Answer first: write down the authority, purpose, handles, public sources, retention period, and stop conditions before searching; collect only what answers that question; verify leads at original public URLs; and report observations, confidence, and gaps without asserting identity from a shared username.
This guide supports defensive, compliance, support, self-audit, and other authorized public-source work. It does not create legal authority and is not legal advice.
Maigret 3.0 is available now. App workflow examples on this site preview 3.1, which is in development. The research method and its limitations apply independently of those upcoming features.
Gate 1: authority
Write a one-page investigation charter
Authorization should be understandable to someone who did not attend the kickoff. Record who requested the work, who approved it, the specific purpose, the subject or organization in scope, the known handles to check, allowed public sources, time window, expected deliverable, retention date, and escalation owner.
“It is on the internet” is not an investigation charter. Public information can still be misused, combined into a harmful profile, taken out of context, or processed in ways restricted by law, policy, contract, or professional duty. If the authorization is unclear, pause before searching and route the question to the appropriate internal owner.
“Confirm which public profiles listed in the creator’s intake form are currently reachable so the support team can correct broken campaign links by Friday; do not search relatives, followers, or private accounts; delete working notes after the link register is approved.”
Gate 2: necessity
Design the smallest search that can answer the question
Start from identifiers supplied or validated within the authorized process. Search an exact handle before considering a documented variant. Prioritize sources connected to the purpose—for example, approved campaign channels for a brand-link review—rather than maximizing site count.
| Planning question | Bounded answer | Warning sign |
|---|---|---|
| Whose data? | The named, authorized subject or owned brand | Contacts and relatives added through curiosity |
| Which identifiers? | Known handles relevant to the purpose | Generated guesses or private identifiers |
| Which sources? | Ordinary public pages needed for the task | Login, scraping around controls, data brokers by default |
| Which facts? | Only fields needed for the deliverable | Copying entire profiles or social graphs |
| How long? | A review date and deletion date | Indefinite retention “just in case” |
Consider the consequence of a false match before choosing depth. A low-impact link-cleanup task and a decision affecting safety, access, employment, insurance, credit, housing, or legal rights do not share the same risk. A username-search result should not be used as an automated decision about a person.
Gate 3: collection
Stay on ordinary public sources
- Run the known handle. Keep each handle and search run separate so evidence does not bleed between subjects or variants.
- Review status groups. Prioritize Confirmed leads, preserve Blocked and Unknown as unresolved, and do not treat Not Found as global absence.
- Open the original public URL. Confirm that the live page supports the narrow observation relevant to the charter.
- Collect the minimum. Record the URL, date, relevant public fact, and confidence. Prefer a note over a screenshot when a note is sufficient.
- Respect controls. Do not bypass authentication, CAPTCHAs, rate limits, robots restrictions that apply to your process, or other technical barriers.
Do not send messages, follow accounts, trigger notifications, attempt password recovery, or use a pretext to elicit information under a passive public-source authorization. Those interactions change the risk and may alert or affect people; they require their own explicit approval and method.
Gate 4: verification
Move from technical match to contextual confidence
A Confirmed result establishes that a public response matched a site rule. It does not establish the account holder. Evaluate provenance: Was the profile linked from an owned domain? Does the subject’s authorized account register include it? Is the relevant claim self-published, independently documented, copied from elsewhere, or merely inferred?
Corroboration should be genuinely independent and proportionate. Two profiles that copy the same bio are not necessarily two independent sources. A circular set of aggregators does not improve confidence. When the evidence cannot distinguish same person, coincidence, parody, abandoned account, or impersonation, state those alternatives and leave attribution unresolved.
Observed
Describe what the original public page displayed and when. Keep this separate from interpretation.
Corroborated
Explain the independent public or authorized record that supports a connection and why it is relevant.
Inferred
Label analytical judgment, confidence, assumptions, and plausible alternatives instead of presenting it as source fact.
Unresolved
State the evidence gap and stop. Uncertainty is a valid finding when more collection is not authorized or proportionate.
Gate 5: evidence
Keep a compact, auditable evidence ledger
A good ledger lets a reviewer reproduce the reasoning without turning every profile into a local archive. Separate source facts from analyst notes, preserve original URLs, record observation dates, and make edits traceable. Mark stale or superseded observations rather than silently rewriting them.
- Case purpose and authorization reference.
- Handle, public source URL, observed status, and review date.
- Relevant source text summarized in your own words where possible.
- Attribution assessment, confidence, and alternative explanations.
- Access restrictions, source conflicts, and unresolved gaps.
- Retention date, action owner, and disposition.
Avoid storing cookies, credentials, private communications, complete follower lists, sensitive details unrelated to the question, or bulk page captures. If evidence must be preserved for legal or security reasons, use the organization’s approved chain-of-custody and access controls rather than an ad hoc report folder.
Gate 6: stop and escalate
Define stop rules before the interesting result appears
| Condition | Action |
|---|---|
| The charter question is answered | Stop collection, finish the deliverable, begin disposition. |
| A source requires login, circumvention, or interaction | Do not proceed under public-source authority; request a separate review if genuinely needed. |
| The search exposes imminent safety risk or suspected crime | Preserve only necessary information and use the organization’s emergency or legal escalation path; do not investigate beyond your role. |
| The result implicates an out-of-scope person | Exclude and delete their unrelated information unless an authorized owner expands scope through the proper process. |
| Identity remains ambiguous | Report the ambiguity and consequences of error; do not force attribution. |
| Authorization expires or is withdrawn | Stop and follow the agreed retention or deletion process. |
Deliverable
Report observations, limits, and actions
Lead with the answer to the charter’s question. Then describe scope, public sources used, material observations, verification method, uncertainty, excluded data, and recommended action. Separate what the source showed from what you infer. Include enough method detail for review without exposing unrelated personal information.
Before delivery, ask: Could a reasonable reader mistake a username match for identity proof? Does every sensitive detail change the decision? Are Blocked, Unknown, and Source Conflict results represented honestly? Does the recipient need this data, and do they know when to delete it?
If the work is about your own exposure, use the narrower self public-footprint audit checklist. If the assignment concerns official channels, use the creator and brand handle register workflow.
Guide FAQ
Questions to settle before you act
What counts as authorization for a username investigation?
Use a clear basis appropriate to your role and jurisdiction: the account owner’s consent, a documented organizational assignment, or another lawful mandate reviewed through your organization’s process. Record who authorized what purpose, sources, time window, and deliverable. Public accessibility alone does not make every use appropriate.
May I log in, send a follow request, or reset a password to verify a lead?
Not as part of this public-source workflow. Do not seek private access, test credentials, trigger recovery, impersonate someone, or bypass controls. If a separate authorized process permits account interaction, handle it under that process rather than mixing it into passive OSINT.
How many sources are enough to identify someone?
There is no universal number. Independence, provenance, context, freshness, and the consequence of error matter more than count. A username match is only a lead, and two sites can repeat the same incorrect or copied information. Report confidence and alternatives instead of promising certainty.
When should I stop an authorized investigation?
Stop when the defined question is answered, authorization expires, a source requires prohibited access, the work begins collecting out-of-scope people or sensitive data, expected harm outweighs the purpose, or the evidence remains too ambiguous for the intended decision. Document the stop reason.