--- title: Create a chain of custody log for an evidence record in an investigative case description: As an investigator or supervisory agent, you can create a Chain of Custody \(CoC\) log within the workspace to keep track of evidence if or when it is transferred or moved. locale: en-US canonical_url: https://www.servicenow.com/docs/r/government-industry/psds-using-icm-create-chain-of-custody-log.html release: australia topic_type: task last_updated: "2026-03-12" reading_time_minutes: 3 breadcrumb: [Using Evidence Management, Investigative Case Management, Solutions, Use, Public Sector Digital Services \(PSDS\)] --- # Create a chain of custody log for an evidence record in an investigative case As an investigator or supervisory agent, you can create a Chain of Custody \(CoC\) log within the workspace to keep track of evidence if or when it is transferred or moved. ## Before you begin Role required: icm.investigator, supervisory\_agent, admin **Note:** The ability to create a Chain of Custody Log for an evidence record is strictly tied to write access for that evidence record. If the particular user does not have write access to the open evidence record, they will not be able to create a record. For more information on modifying the security classification for an evidence record or for a case, see . ## About this task With Investigative Case Management Evidence Management, investigators can create a chain of custody log within the workspace. The log tracks the movement, transfer, and status changes of evidence records associated with the case. Audit logging captures timestamps and responsible personnel for each action, including when and by whom evidence was opened and viewed. **Note:** A Chain of Custody Log cannot be created if the evidence record is in Draft state. The Chain of Custody Log form collects the following information about a piece of evidence:
| Fields | Description |
|---|---|
| From custodian | The custodian that the evidence was transferred from. Filled in by default. |
| Method used to transfer custody of evidence from one individual to another. If this is the first time this piece of evidence is being received or handled, select **Initial Receipt**. Otherwise, the method of transfer may be:- In-person - Secure upload - Courier - Email | |
| The date and time of the transfer. You may enter a past, present, or future date. | |
| The action taken on the evidence. The evidence may have been taken:- To laboratory for analysis - To court for trial/proceeding - To storage/vault - To case agent or investigator - For review or inspection - To case agent or investigator - For review or inspection - Collected - Return from court - Inter-agency transfer - Disposal - Return to owner - Digital transfer - Returned from laboratory - Temporary custody assignment | |
| Custodian type | Whether the receiving custodian is an internal user with a user record in the instance, or external. |
| To Custodian | The custodian’s name. If internal, a user record reference. If external, a string. |
| Location type | Indicates whether the evidence is changing physical location, digital location, or both. |
| From location | Location the evidence is being transferred from. Filled in by default. |
| To location | Location the evidence is being transferred to. Changing the location within the Chain of Custody log will change the physical/digital location in the evidence record at large. |