# Installed, launched or running: read software evidence correctly

Canonical: https://stafflytracker.com/blog/software-inventory-evidence/
Updated: 2026-10-07

[Home](https://stafflytracker.com/)/Workforce Practice

WORKFORCE PRACTICE

# Installed, launched or running: read software evidence correctly

Why an installed app, a historical launch and current activity are different kinds of evidence.

By [Syed Toheed Shah](https://stafflytracker.com/authors/syed-toheed-shah/) · 2026-10-07

![Closed laptop, USB stick and blank checklist illustrating software evidence review](https://stafflytracker.com/assets/editorial/blog-software.webp)

Illustrative workplace image, not a customer or employee photograph.

**On this page**[Inventory answers a limited question](#part-0)[Launch history has a timestamp and a scope](#part-1)[Observed activity needs context too](#part-2)[Device and filename matches are not file-transfer logs](#part-3)[Use careful wording in review notes](#part-4)[Make the next step proportionate](#part-5)[Documentation home →](https://stafflytracker.com/docs/)

## Inventory answers a limited question

An installed-program entry says that Windows reported an application in one of the sources the tracker queried. It does not prove that the application was opened during today’s shift. Store packages, startup entries and ordinary desktop installers also use different registration mechanisms. Portable tools may leave no conventional installation entry, so the absence of a name is not a guarantee that the tool has never existed.

## Launch history has a timestamp and a scope

Available Windows launch history can add a last-run time or count. That is historical metadata, not a live process stream. Check the computer, reporting time and relevant date. An old entry may remain after an uninstall. Do not turn a launch from months ago into a statement about what someone is doing now.

## Observed activity needs context too

Foreground application activity indicates what the tracker observed in a window during a recorded interval. It still does not describe all background behavior or prove the purpose of an application. If a record is flagged, inspect the interval and the surrounding work. A general automation tool can have legitimate uses; the relevant question is what evidence supports a specific concern.

## Device and filename matches are not file-transfer logs

A USB device remembered by Windows is not proof that a file was copied today. A filename matching a known-tool pattern is not a malware analysis or proof of execution. StafflyTracker’s bounded metadata scan does not read every document or provide a complete transfer history. Report the match with its limitations instead of extending it into a conclusion the data cannot support.

## Use careful wording in review notes

Write “the inventory reported this application” or “launch metadata shows this timestamp” when that is what you know. Reserve statements about current use for evidence that actually supports them. Include gaps and uncertainty. This helps another administrator understand the case and prevents a suspicion from becoming a supposed fact as it is passed between people.

## Make the next step proportionate

Start with a conversation and a review of the relevant period. If a company needs forensic investigation, a time tracker is not a substitute for a properly scoped endpoint-security process. Use the available dashboard to organize observations, preserve the distinction between evidence types and avoid automatic penalties based on a name match.

## Keep exploring

[What admins can see →](https://stafflytracker.com/docs/admin-visibility/)[Collection and limits →](https://stafflytracker.com/docs/data-collection/)[Release history →](https://stafflytracker.com/changelog/)[Ask a product question →](https://stafflytracker.com/contact/)

[Read as Markdown](https://stafflytracker.com/blog/software-inventory-evidence/index.md)Updated 2026-10-07[Editorial policy](https://stafflytracker.com/trust/editorial-policy/)