Timelines · Resource
How to Build a Cold-Case Timeline
A step-by-step method for building an accurate cold-case timeline — separating exact, approximate, and disputed dates, and keeping every entry tied to its source.
By Second Trace editorial · Published August 30, 2026 · Updated August 30, 2026 · 6 min read
In short
A cold-case timeline turns a scattered record into a dated, sourced sequence. For every event you record its date — with its certainty (exact, approximate, disputed, range, or unknown) — and the source that establishes it, and you keep conflicting accounts side by side instead of merging them. A timeline is never finished; it is versioned and re-reviewed as new material arrives.
Why a timeline matters
A cold case spans years or decades. Memories fade, records are destroyed or lost, and the people who built the original investigation move on. The timeline is the spine that holds the case together: a single, dated, sourced sequence that anyone — including someone who was not there — can follow later. When done well, it does not just list events; it exposes gaps, conflicts, and uncertainty that are themselves evidence of where to look next.
Step 1 — Define the span and the events that matter
Start by bounding the inquiry: from the earliest relevant event to the last known development. Then ask what the timeline is for. A timeline built to test a hypothesis about a specific night looks different from one built to map a person's whereabouts over years. Keep it question-driven, and resist the urge to log every detail.
Step 2 — Record the date and its certainty
Every entry carries a date and a certainty state. Use one of these, and never blur them together:
- Exact — a specific, established date.
- Approximate — a rough placement (e.g., "circa June 1998").
- Disputed — two or more sources disagree; record each account.
- Range — between two dates, when the window is known but the point is not.
- Unknown — no reliable date; state that plainly.
The rule is simple: never convert an approximate or disputed date into an exact one just to make the timeline look cleaner. False precision is a form of error.
Step 3 — Attach a source to every entry
A timeline entry without a source is a rumor. For each entry, record the source, its location within that source (page, paragraph, timestamp), when you obtained it, and your reliability assessment. This is what makes the timeline auditable: a reader can always trace a claim back to where it came from and decide for themselves how much weight to give it.
Step 4 — Keep conflicting accounts side by side
When two witnesses describe the same event differently, or two records give different dates, do not merge them into one "best guess." Keep both, with equal weight, and note the dispute. The conflict itself is a fact worth preserving — it may later resolve, or it may be the clue that breaks the case open.
Step 5 — Mark the gaps
An empty stretch of time is data, not a defect. A gap between two events often points to the next thing to find: a missing record, an unreported period, an unaccounted witness. Mark gaps explicitly rather than smoothing over them. A timeline that shows its holes is more useful — and more honest — than one that pretends completeness.
Step 6 — Review and version
Re-read the timeline periodically, especially after new material arrives. When you change an entry, record the change and keep the prior version. A cold case can run for years; the timeline must remain legible across that whole span, and its changes must themselves be traceable.
Common mistakes
- Merging conflicting accounts into a single "clean" version.
- Backdating a guess so a gap disappears.
- Omitting the source (or recording "someone said").
- Treating the absence of a record as proof the event did not happen.
- Adding entries with no clear connection to the questions at issue.
Sources & further reading
- National Institute of Justice (NIJ) — U.S. Department of Justice research on cold-case investigation practices and forensic science.
- NamUs — National Missing and Unidentified Persons System — a national clearinghouse for missing and unidentified persons, administered by NIJ.
Frequently asked questions
What is the difference between an approximate and a disputed date?
An approximate date is one you can place roughly but not precisely (for example, "early 1998" or "circa June"). A disputed date is one where two or more sources disagree, and you record both accounts rather than choosing one. Both are honest states — neither is a guess dressed up as fact.
Should I include every small event?
No. A useful timeline is question-driven: it includes events relevant to the specific questions the case is trying to answer. Logging trivia dilutes the record and makes the important sequence harder to see.
How do I handle undated records?
Mark the date as unknown and record whatever anchors the item does have (a filing stamp, a publication date, the date it was obtained, or the range the content implies). Never backdate an item to fill a gap.
Put this into practice
Second Trace is a workspace for organizing case information with full provenance. These capabilities map directly to the method above:
Related resources
Evidence
Organizing evidence →A practical framework for organizing evidence in large, long-running investigations — provenance, chain of custody, and how to keep thousands of items findable.
Method
Facts, allegations & theories →A working taxonomy for sorting confirmed facts, allegations, testimony, inference, and theory in a case record — and why the distinction must survive export.
Template
Timeline template →A reusable timeline template and pre-publication checklist for documenting events, sources, and uncertainty in any investigation.