SENTRY — IDENTITY INVESTIGATION CHECKLIST 1. What started the investigation? Capture the original signal, the identity, the environment, and the relevant time window. 2. Which evidence is available? Identify the sources you can review and the periods they cover. Keep evidence gaps visible. 3. What happened around the signal? Connect the sign-in with email, file, application, and authentication activity. Build the sequence before summarising it. 4. What changed, and what remains? Review the incident’s scope alongside the applicable response policy. Document access, persistence, and affected resources. 5. What can you explain? Separate observed findings from inference. Record the response actions, the impact you can support, and the remaining questions. An investigation aid for use alongside your organisation’s incident-response procedures.