A field investigator spends three days on a workers compensation surveillance assignment and captures the footage the claims examiner has been waiting for: a claimant, supposedly unable to lift more than ten pounds, loading furniture into a truck. The footage is clear, the subject is identifiable, and the timing lines up with the claim. Six weeks later, opposing counsel moves to exclude it — not because the content is wrong, but because the files metadata shows it was exported and re-saved before it reached the claims file. The judge agrees. The footage never reaches the jury. That scenario plays out more often than most case files acknowledge, and it is becoming more common as smartphone video replaces dedicated surveillance cameras in routine investigative work. Courts have not rewritten the rules of evidence to punish investigators. They have simply started enforcing existing authentication standards more consistently against footage that was never built to survive them.
The Four Cumulative Tests
Investigative video footage recorded by a licensed investigator with litigation in mind is held to a higher bar than incidental recordings like a bystander's phone video or a store's security camera. Courts evaluating that footage generally work through four cumulative tests, and failure on any single one is enough to keep the recording out.
Legitimacy asks whether the person behind the camera had a lawful basis to record the subject, in that location,at that time. For a licensed investigator, that basis comes from three things read together: the investigators license, the written scope of the client's engagement, and the boundaries set by state law. Footage captured after a mandate has lapsed, or outside the scope the client actually authorized, invites a legitimacy challenge before anyone even looks at what the video shows.
Usability weighs the subject's privacy interest against the litigants' right to present a defense or make a claim. U.S. courts apply a version of the “reasonable expectation of privacy” doctrine that traces back to Katz v. United States a subject in a fenced backyard has a strong claim to privacy; the same subject in a parking lot or public sidewalk has very little. Where the camera was pointed, more than how it was operated, tends to decide this test.
Integrity is the one that catches the most modern surveillance work off guard. It asks a purely mechanical question: are the bytes shown to the court the same bytes recorded in the field? Raw smartphone video files are editable containers; metadata can be altered, files re-encoded, and timestamps changed using nothing more than consumer software. Defense counsel does not need to prove tampering occurred; showing that it was possible is often enough to force exclusion or, at minimum, expensive authentication litigation.
Authenticity is where the investigator (or the system that produced the recording) has to establish that the file is what it claims to be. Federal courts generally recognize three paths to authentication: pictorial testimony (a witness testifies the video accurately depicts what they saw), the “silent witness” theory (the recording system itself is shown to be reliable, independent of witness testimony), and circumstantial authentication built from surrounding facts. Investigators and firms are increasingly favoring the silent-witness route in commercial and insurance matters, because it takes the investigators' personal credibility off the stand and puts the emphasis on a verifiable, documented process instead.
Where Cases Actually Fail
Legitimacy and usability get the most attention in law school evidence courses, but integrity is what quietly kills otherwise strong investigative work. A recording with no qualified timestamp, no cryptographic verification, and no documented chain of custody puts the entire case on the investigators word. That is a fragile foundation once opposing counsel starts asking pointed questions about export history, device settings, and who else had access to the file between capture and production. The practical fix is not complicated, but it has to be built into the workflow before the camera starts rolling, not reconstructed after a motion to exclude has already been filed. It starts with confirming and documenting the engagement scope in writing before surveillance begins, recording with tools or procedures that preserve timestamp and location metadata at the point of capture, maintaining a clear, contemporaneous chain-of-custody log from the moment footage is recorded to the moment it is handed to counsel, and keeping field notes that corroborate — rather than merely repeat — what the footage shows.
Civil and Criminal Standards Diverge
The four tests apply in both civil and criminal matters, but the practical thresholds are not identical. Civil courts generally resolve privacy and authentication disputes at trial under a preponderance standard, and a reasonable jurors ability to find the footage authentic is often enough to clear the bar. Criminal courts apply heightened scrutiny, frequently through pre-trial suppression motions, and are more likely to demand expert testimony on authentication. In both settings, integrity problems are increasingly the deciding factor — and in criminal matters, they tend to be closer to fatal, given the stakes of admitting unreliable evidence against a defendant.
WHY IT MATTERS
For attorneys, SIU investigators, and corporate risk teams, this is not an abstract evidentiary debate — it determines whether months of surveillance work and investigative spend translate into usable proof or a wasted case file. Before relying on third-party surveillance in a filing, confirm that the vendors evidence-handling protocol produces a documented chain of custody, preserves capture-level metadata, and can withstand a legitimacy and integrity challenge, not just a “the video speaks for itself” argument. Firms that build this into intake now avoid learning about it for the first time in a motion to exclude.
