A convincing fake Slack screenshot now takes about a minute to make. Not with dark-web software, but with the same AI tools already sitting in your company's stack.

That is the shift most employee relations teams are not ready for. HR has always worked with conflicting accounts and faulty memories. What is new is that the proof meant to settle them can be fabricated, and most intake processes were never built to catch it.

This recap breaks down a recent AllVoices session, Don't Trust the Screenshot, hosted by Rebecca Taylor with Laura Azzarella, Partner at Applied Potential Solutions, and Madyson Kmiec, director of customer success at AllVoices. It is written for the people who catch this first: ER specialists, HR business partners, and investigators.

How Easy It Is to Fake Digital Evidence Now

Very easy, and it no longer takes any skill. Editing a screenshot used to mean knowing Photoshop, and the edits usually gave themselves away. That barrier is gone.

A general image tool can now rewrite the text inside a screenshot from a plain-English request, often on the first try. Laura Azzarella, who has worked in HR since 2009 and calls herself a lifelong technology nerd, put it plainly:

"The curtains really pull back, and literally anyone with any background can generate an image in seconds." -Laura Azzarella

Her advice for anyone feeling behind is not to panic. The horse has left the barn. The job is to understand what the tools can do and build guardrails, because you can no longer fully trust your eyes.

What does a convincing fake look like?

Close enough that a glance will miss it, which is exactly the problem. When a screenshot comes in, compare it against a real export from your own workspace and look for the small tells:

  • A font that shifts between messages.
  • Bubble colors that are slightly wrong, or out of order.
  • A header that does not match your actual layout.
  • Spacing or alignment that feels off.

The danger is not that fakes are flawless. It is that almost no one looks. Most people react to an alarming Slack exchange instead of checking the details first.

See what a defensible record looks like

Turn a single report into a timestamped, corroborated case file your team can stand behind.

Book an AllVoices demo

Has HR seen fabricated evidence before AI?

Yes, and the instinct that catches it has not changed. If something looks too good to be true, slow down. Laura started catching manipulated images as far back as 2017, usually because a submission looked too clean or too curated.

Madyson Kmiec named the trap this creates. Bad actors submit fakes, but investigators can also grow so suspicious that they start doubting real evidence. The habits below are built to avoid both failure modes.

How to Verify Digital Evidence

A verification protocol does not need to be elaborate. It needs to be consistent, and it starts with knowing where the evidence actually lives.

Why IT is your first call

For anything on a company system, IT holds the record that settles it. Laura's point was that HR runs on relationships, and the one with IT pays off most in an investigation, because they can pull the original from Slack, Teams, or email.

Where the evidence sits decides your next move:

  • On a company system: ask IT for the source record.
  • Personal texts: ask to see each phone and check the number against your HRIS. A mismatch is a flag.
  • An outside platform like Discord: get a screenshot from each party and compare them.

What reverse image search and metadata reveal

Two free checks worked long before AI, and still do. During COVID, Laura received a photo of a positive test that looked off because it looked too good, perfectly framed and lit. A reverse image search showed it was an Adobe stock photo. A peer hit the same thing recently, when an employee's "proof" turned out to be the third result in a Google search.

Metadata is the second check. Every photo carries data about the camera, lens, and often the location it was taken. Social platforms strip it, but it usually survives an email or an iMessage, and you can read it by right-clicking the file and opening properties. For a closer look, run the image through FotoForensics, a free tool that highlights regions that look edited.

How to rate evidence with a four-level scale

Do not sort evidence into simply real or fake. Laura grades every piece on a four-level scale, then writes her findings in preponderance-of-evidence language, the standard for workplace investigations rather than criminal court:

LevelWhat it meansUse it when
AuthenticatedPulled straight from the source systemIT can retrieve the original, like a Slack thread
CorroboratedConfirmed across two independent sourcesYou have the same texts from both phones
UnverifiedProvided in good faith but unconfirmedThere is no metadata and open questions remain
Concerns notedVisible signs of manipulationSomething looks off; dig deeper before relying on it

Because the law has not caught up with the technology, the burden sits with you to show you tried, in good faith, to verify the truth from every angle. Writing a finding as more likely or less likely than not reflects that honestly.

How do you verify a suspicious doctor's note?

Call the office and confirm only that a note dated for a specific day came from them. HIPAA means they will not discuss medical details, but that narrow question is usually fine.

If they will not confirm, have the employee sign a release. And search for the practice itself, because sometimes the office on the letterhead does not exist. Rebecca shared a case that makes the point: she once received a note where the listed phone number turned out to be the employee's own cell.

One nuance worth keeping in mind. Unrealistic policies invite fabrication: a rule demanding a note after two sick days pushes honest people to fake one. The problem often starts with the policy, not the person.

Why People Fake Evidence, and How to Keep Trust

Most fabrication is desperation, not villainy. Madyson sees three recurring motives: avoiding discipline, framing someone, and the hardest one to read, when a real event happened but the person cannot prove it, so they recreate it. That last case blurs the line between misremembering and fabrication, and it is why tone matters as much as technique.

The cartoon villain almost never shows up. Rebecca admitted she once forged her mom's signature on a school test, because the urge to manufacture proof when you feel cornered is human. The response should be process, not suspicion.

How do you verify without making someone feel accused?

Tell people what you are doing and why. Verification reads as suspicion only when you skip the explanation.

Laura made a point that rarely shows up in HR training: you need a bedside manner. Stay neutral no matter what you feel, and frame the extra step as protection for everyone involved. Rebecca distilled the balance into one line worth keeping ready for a hard conversation:

"I don’t not believe you. I just need to verify that what I’m seeing is what I’m seeing." - Rebecca Taylor

Consistency carries the rest. The same process every time builds trust and makes a decision easier to defend later. When a case comes down to one person's word against another's with no records, Laura errs toward caution, sometimes moving both parties into separate but equal roles to prevent any chance of recurrence, without treating that as a finding of guilt.

Why one screenshot is never the whole case

A single piece of evidence is a claim, not proof. Madyson's reframe takes the pressure off any one image: instead of asking whether a screenshot is real, ask what else would be true if the event actually happened, then look for it in metadata, behavioral patterns, other reports, and system logs.

The most reliable record is rarely the artifact someone hands you. It is what builds up when every case lives in one consistent investigation record: a timestamped report that something was filed, and the patterns that surface across cases over time. Not foolproof, but far stronger than a single photo.

Using AI in Investigations Without Creating New Risk

The wish list is appealing. AI that drafts an investigation plan, cleans up handwritten notes, compares accounts, and assembles a board-ready summary. The catch is doing it without feeding sensitive detail into an open tool.

That gap is what an AI copilot built specifically for employee relations is meant to close. In AllVoices, the copilot drafts the end-of-investigation summary, prepares interview notes, and can turn a photo of handwritten notes into a structured case, with a human signing off on every step.

The difference is the environment. AllVoices runs on an enterprise OpenAI agreement, so case content stays in your tenant and is never used to train a model. That is the line that lets a team get the speed of AI without handing its most sensitive records to a general chatbot.

What to Do Before the End of the Week

You do not need to rebuild anything. Start with one habit.

Talk to IT and find out exactly who can pull records, including email, when you need to corroborate an account. Then sketch a basic verification flowchart so the process is repeatable, using the same discipline you would bring to any workplace investigation. As Laura put it:

"You don’t rise to the occasion. You sink to the level of your preparation." - Laura Azzarella

A process does not have to be perfect on day one. Put one or two checks in place, write them down, and improve them as the technology and the law keep moving. You cannot stop fabricated evidence from showing up, but you can decide in advance how your team handles it.

Fabricated Evidence Is an Employee Relations Problem, Not Just a Tech One

Detection tools matter, but the real work is relational. The employee who feels accused, the investigator who starts from doubt, the manager who reacts to a screenshot before anyone checks it: these are employee relations events, and they are where trust is won or lost.

Teams that verify consistently and explain why they are doing it keep that trust intact, even as the fakes get better. The screenshot is only ever the start of the conversation, not the end of it.

AI-Generated Evidence Frequently Asked Questions

The questions HR and ER teams ask most about fabricated digital evidence.

How can HR tell if a Slack message or screenshot is fake?

Compare it against a real export from your own workspace and check the font, bubble colors, header, and spacing. Then pull the original record from IT wherever the message lives on a company system. Treat the screenshot as a claim to corroborate, not as proof on its own.

What is the four-level framework for verifying digital evidence?

Grade each piece of evidence as authenticated (pulled from the source system), corroborated (confirmed across two independent sources), unverified (provided in good faith but unconfirmed), or concerns noted (visible signs of manipulation). Findings are then written in preponderance-of-evidence language.

How do you verify a suspicious doctor's note without violating HIPAA?

Call the office and confirm only that a note dated for a specific day came from them, without asking for medical details. If they will not confirm, have the employee sign a release, and search for the practice to confirm it exists.

Why do employees fabricate evidence in workplace investigations?

Usually out of desperation rather than malice: to avoid discipline, to frame someone, or because a real event happened that they cannot prove, so they recreate it. The line between misremembering and fabrication is often blurry, which is why tone and process matter.

Is it safe to use AI tools in employee relations investigations?

Not in public, general-purpose models, where sensitive detail can be retained and resurface. Use a purpose-built system with enterprise terms and zero data retention so case content stays in your environment and is never used to train a model.

How does AllVoices help ER teams verify evidence and document investigations?

AllVoices acts as a system of record, keeping timestamped reports and patterns across cases rather than relying on a single artifact. Its AI copilot drafts summaries and interview notes and turns handwritten notes into a structured case, with a human approving every step.

What to Do About AI Evidence in ER Investigations

Frequently asked questions

Got more questions? Email us at support@allvoices.co and we'll respond ASAP.

No items found.

Stay up to date on Employee Relations news

Sign up to our newsletter

Thank you! We look forward to meeting you soon
Oops! Something went wrong while submitting the form. Please try again or use the email below to get support.
Join our newsletter for updates. Read our Terms
Frequently asked questions

Got more questions? Email us at support@allvoices.co and we'll respond ASAP.

No items found.