# Lesson 7 practice: Investigate access and source withdrawal separately

[中文](README.md)

Open [events.csv](events.csv). Separate observed facts, immediate protective measures, and unanswered questions, then write a record that a responsible owner could act on. These eight synthetic rows were written specifically for this exercise. They contain no real people or system logs and do not replace the facts in Beichen’s public case.

## Fields

| Field | Meaning |
| --- | --- |
| `event_id` / `path` | Event ID / investigation path: `session_access` or `source_withdrawal` |
| `event_order` | Observation order within a path; not an elapsed-time measurement |
| `user_id` / `session_id` | Synthetic user and session IDs; a blank session means unspecified |
| `current_region` / `session_region` | Current region / region when the session was created; `south_china` and `east_china` |
| `document_id` | Synthetic document ID |
| `event_type` / `outcome` | Observed event type / recorded outcome for that event only |
| `target` | Location or destination, such as a session, index, or local download |

`retrieval/returned` records a returned document. `export/completed` records one completed export. Neither proves that the person read, used, or shared its contents. `recommendation/generated` establishes that a recommendation was generated; `no_external_action` means that row contains no external action.

## Work through the evidence

1. Make two fact tables. The session path shows two returns of documents from the users’ former region and one local export. The withdrawal path shows a withdrawal record, a later retrieval from the index, and a generated recommendation. Do not assume a shared root cause.
2. Propose immediate protection: restrict relevant old sessions, isolate the affected retrieval path, and notify people authorized to investigate. Actual actions require the responsible owner’s authority. Preserve investigation evidence under controlled access; cleanup must not erase it.
3. List at least two possible explanations for the session path, such as identity changes not propagating or missing session reauthorization. Request permission records at the time of access and session checks that could distinguish them. Region fields alone do not identify a specific software defect.
4. For withdrawal, trace the register, index updates, prompts and caches, evaluation sets, and exported copies. No synchronization times or implementation settings are provided here. A returned document does not identify which cache, if any, caused the problem.
5. Define recovery evidence covering continuing sessions after a transfer, withdrawn sources, and one normally permitted task. Denying everything does not demonstrate correct authorization. Use synthetic data; no real customer files are needed.

## Check your reasoning

You can verify two returns through old sessions, one local export, and two separate investigation paths. You cannot calculate total affected users, conclude that only three people were affected, determine where the export later went, or claim a fix. The simulated users here are not the affected population in Beichen’s public case.

Produce a one-page record with facts, unknowns, proposed protection, investigation owners and access needs, and recovery evidence. Mark proposals and unresolved questions clearly; do not fabricate approvals or completed actions. A peer can look for unsupported conclusions. When studying alone, check each claim against the CSV.

Carry revocation and withdrawal scenarios into the Lesson 8 practice to define evaluation slices and blocking conditions.
