Evidence Basics · 10 min read

Text Message Evidence Manifest: What to Track Before Review

A manifest checklist for source files, hashes, participants, working copies, summaries, and report outputs before text message analysis starts.

The short answer

A manifest is the table of contents for a message record, and its real function is answering questions before they get asked. It lists what was preserved, where each file came from, who handled it, how participants were mapped, which working copies exist, and which output was produced from which source. The value shows up the moment someone challenges a single excerpt. Without a manifest, defending one line means reconstructing the entire handling history from memory. With one, the answer is a lookup. A workable manifest records, for each source file: its name, its size, a checksum taken at a documented point, the date and method of acquisition, and who acquired it. Then for each derived artifact — a redacted copy, a PDF, a chart — what it was made from and what changed. It does not need to be elaborate. It needs to have been written at the time. The manifest matters because summaries are not the source. Under Rule 1006-style summary workflows, and under ordinary authentication review, the reader needs a path from each summary row back to the messages and files being summarized.

Manifest fields

A practical manifest does not need to look like a forensic lab report. It needs stable fields that let a reviewer reproduce the workflow and identify missing or ambiguous material. Source ID, original filename, platform, export method, device or account context, and date range. Uploader, export creator, upload date, review date, and access notes. File hash when available, file size, row count or message count, and attachment count. Participant map entries for names, phone numbers, emails, account handles, aliases, and ambiguous senders. Working-copy filename, redaction status, cleanup steps, filters, and timezone assumptions. Generated artifacts: timelines, summaries, PDF reports, CSV exports, manifests, and exhibit indexes. Known gaps: missing dates, missing media, deleted-message claims, partial screenshots, or unsupported formats.

Why summaries need source access

Federal Rule of Evidence 1006 addresses summaries offered to prove the content of voluminous admissible materials that cannot be conveniently examined in court, and it requires the originals or duplicates to be made available. A matter manifest can help identify those records, but it does not establish that the rule applies. Federal Rule of Evidence 901 also matters because a person may need to show that a message record is what it claims to be. The manifest does not prove authenticity by itself, but it keeps the source trail visible.

Keep the manifest beside the Textimony run

Textimony records an intake checksum, parsed message fields, participant confirmation, run status, reviewer decisions, and reports. It does not replace the matter’s source inventory or generate a forensic handling record, so keep your broader manifest alongside the case. The manifest should state which source was converted into the supported working file, what date range it covers, and what remained outside the analysis. That prevents a report from one file or one date range from being described as the complete record.

Review rhythm

Start with the manifest before reading the most dramatic messages. Confirm the files, date ranges, participants, and gaps first. Then inspect issue clusters, timelines, summary charts, and highlighted evidence windows. This order keeps the workflow defensible: source first, mapping second, interpretation third, export last.

Manifest quality control

A manifest should be updated whenever the review scope changes. If a new export is added, a participant is remapped, a redacted copy is created, or a report is regenerated, the manifest should show the new artifact and the relationship to prior versions. That version trail matters because source-linked reports can otherwise become ambiguous. A timeline generated before redaction is not identical to a privacy-safe packet exported later, and both should be traceable.

Is an evidence manifest the same as chain of custody?

No, though they overlap. Chain of custody is specifically the record of who handled evidence, when, and what changed — a history of possession. A manifest is broader and more static: it inventories the source files, the working copies derived from them, participant mapping, generated reports, known gaps, and the scope of review. A manifest describes what you have; chain of custody describes what happened to it.

Do I need hashes for every file?

Hashes are strongly preferable but not always achievable. A hash establishes that a file is byte-for-byte identical to what existed at a documented moment, which is the cleanest way to answer a tampering question. Where you cannot hash — a file already in circulation, or a source you received second-hand — record what you can: filenames, dates, sizes, message counts, the export method, and how the file reached you.

Can Textimony replace attorney or forensic review?

No. Textimony organizes a supported working file and records parts of the workflow applied to it, which is a narrower job than either an attorney or a forensic examiner performs. Acquiring data from a device, deciding an authentication strategy, judging admissibility, and filing exhibits all require professional judgment and, in most cases, professional responsibility for the outcome. The software produces material those professionals then evaluate.

When should a manifest be updated?

Whenever the picture it describes changes: a new source file arrives, a participant is identified or reassessed, filters or date ranges are altered, a redaction is applied, a report is generated, or the scope of review shifts. Update it at the time rather than reconstructing later — a manifest assembled from memory at the end of a matter is exactly the document whose reliability gets questioned.

Should reports have their own manifest entries?

Yes. A report is a derived artifact, and without its own entry there is no way to establish which source files and settings produced it. Record the report version, when it was generated, which source files fed it, and the filters, date ranges, and redactions in effect at the time. Two reports generated weeks apart can differ legitimately, and only the manifest explains why.

Can a manifest include uncertainty?

Yes, and it should. Missing media, sender identity you could not confirm, unsupported formats, and incomplete date ranges belong in the manifest stated plainly. Recording uncertainty is not a weakness in the record; a manifest that presents everything as settled invites the discovery of a gap you did not disclose, which damages the whole document. Name what you do not know.

Published by

Textimony. Editorial status: Source-linked informational guide. Updated: 2026-07-12.

Sources

Federal Rule of Evidence 901; Federal Rule of Evidence 1006; NIST SP 800-101 Rev. 1: Guidelines on Mobile Device Forensics; American Bar Association: Authenticating Digital Evidence at Trial