How to Write an OSINT Findings Report That Holds Up to Review
A clear reporting structure for turning public-source research into a reviewable record of observations, confidence, limitations, and next steps.
An OSINT finding only becomes useful when another person can understand how it was reached, what it does and does not establish, and what action is proportionate. A good report is not a dump of links or screenshots. It is a compact, reviewable explanation that preserves evidence without overstating certainty.
Lead with scope and question
Open with the approved purpose, assets or identities in scope, observation dates, sources permitted, and the question the research was meant to answer. A reviewer should be able to tell immediately whether a finding is current, relevant, and authorized. If scope changed during the work, state who approved the change.
Use a four-part finding format
| Part | What to write |
|---|---|
| Observation | What the direct public source visibly showed, with URL and date. |
| Assessment | What the observation may mean, including confidence and alternatives. |
| Impact | Why the item matters to the approved decision, if it does. |
| Recommendation | The appropriate owner and a proportionate next action. |
For example, “A public account used the organization name and linked to an unrelated support address” is an observation. “The account may confuse customers” is an assessment. “Customer support should review and use the platform reporting process” is a recommendation. This separation makes it easier to challenge the reasoning without disputing the source itself.

Make citations actionable
Use direct links where access is appropriate, record the time observed, and describe the relevant part of the source. Avoid vague citations such as “found online” or “seen on social media.” If a source may change or disappear, preserve a policy-approved record, but do not copy more personal or sensitive content than necessary.
State confidence and limitations plainly
Explain why a conclusion is high, moderate, or low confidence. Name the unresolved facts: a username match may be unconfirmed; a page may be stale; several sources may trace to one origin. Limitations are not a weakness. They prevent a decision maker from reading more certainty into the report than the evidence can carry.
- Use “observed,” “appears,” “may,” and “could” when the evidence calls for them.
- Avoid identity, intent, or causation claims unless independently supported and necessary.
- Distinguish a missing result from proof that something does not exist.
- Do not include unrelated personal details merely because they were public.

Close with ownership and retention
Every report should name what happens next: who receives it, whether an owner must validate it, what deadline applies, and where the record will be kept. Remove duplicate local copies after handoff. If the research was inconclusive, say so and explain what additional authorized evidence would be required before action.
The best OSINT report is easy to audit. It is restrained, sourced, useful to its reader, and honest about what public information cannot tell you.
// USEFUL_INTEL?
Signal that this research note was useful.