She doesn’t look at me.
That, more than anything, is what keeps me calm. Guilty people look for the reaction before they build their own. Innocent people go to the data first.
She goes to the data.
She shifts closer to the desk, one hand bracing against the edge as she reads. “So the file was opened under my credentials without the system recording how the access happened?”
“Correct.”
“That shouldn’t be possible.”
“No,” I say evenly. “It shouldn’t.”
Her jaw tightens with irritation. “Show me the surrounding entries.”
I already have them pulled up. I click open the adjacent records and step half an inch to the side, giving her visual priority without ceding control of the machine.
She tracks the screen quickly. Timestamp clusters, file paths, user credentials. System recognition markers.
Her eyes move in patterns I recognize immediately, because they mirror mine. Not reading linearly, but mapping. Comparing lateral behavior across entries rather than treating each record as isolated.
She points. “This one.”
I enlarge it.
“Normal access?” she asks.
“Yes.”
She meets my eyes then. “Because it has the authentication handshake?”
“Yes.”
“And this one…” she taps the unauthorized entry with one short nail, “doesn’t.”
“No.”
“Okay.” She exhales. “Then whoever did this either bypassed the login sequence or injected the access record after the fact.”
I glance at her. “That was also my conclusion.”
“Also?” she mutters. “That’s so reassuring.”
I let that pass.
She straightens. “How many times has this happened?”
I bring up the second screen so she can see the five times, across different dates at various times.
Vendor files. Invoice clusters. Consulting charges. Supporting documents. Entry logs. All touched after hours. All under valid user names. All without proper authentication capture.
I watch her face as she realizes the scale of it. “Who else knows?”
“No one.”
“Not Silas?”
“No.”