Laptop CareGuide
Local Backups as an Authorship Record
A backup exists to get files back after a spill or a theft. It has a second use that most people never think about: every snapshot is a dated copy of your work as it stood that day, made by a process you did not have to remember to run. That makes local backups as proof of authorship one of the quietest and most convincing records a laptop keeps.

Quick answer
Local backups work as proof of authorship because File History and Time Machine copy your documents folder on a schedule and label every copy with the date it was made. A draft found in a snapshot from a given day existed on that day. Keep snapshots long enough to cover a whole project.
On this page
- Why a backup snapshot is hard to fake after the fact
- Reading snapshot dates on Windows and macOS
- What to keep so backups as proof of authorship actually work
- Retention settings that decide how far back you can go
- Backup methods compared for evidential value
- How to present a backup snapshot to a reviewer
- Mistakes that weaken the record
- Common questions
- Sources
Why a backup snapshot is hard to fake after the fact
A snapshot is a copy of a folder taken at a scheduled moment and stored under that moment's date. Microsoft describes File History as a feature that automatically saves copies of your files so you can restore an earlier version; Apple's documentation says Time Machine keeps hourly, daily and weekly backups on the backup disk, plus hourly local snapshots on the internal disk that last about 24 hours. Neither asks you to do anything once it is set up, which is the point: the record accumulates whether or not you ever expect to need it.
Faking that record later means inventing a chain of dated copies that looks like weeks of small changes, on a drive whose own catalogue has to agree, without disturbing the genuine snapshots around it. A determined expert with time could do it. It is far harder than editing a single timestamp, and the effort tends to show. NIST's guide to forensic techniques, SP 800-86, treats backups in the same spirit: as one of several independent data sources whose agreement is what gives a timeline its weight.
Reading snapshot dates on Windows and macOS
| Tool | Where the dates appear | How often it runs by default | Where the copies live |
|---|---|---|---|
| File History (Windows 10 and 11) | Restore personal files view: a dated page per snapshot, with arrows to step back | Every hour while the drive is connected | A folder tree on the external drive, with the date and time in each file name |
| Time Machine (macOS) | Enter Time Machine: a timeline on the right, one entry per backup | Hourly, thinned to daily and weekly | Dated backup folders on the external disk; local snapshots on the internal disk for about a day |
| Dated external drive (manual) | The folder name you gave it, plus each file's modified date | When you remember | Wherever you put it |
| Cloud version history | The version list inside the document | On every change | The provider's servers |
On Windows, open Control Panel, System and Security, File History, choose Restore personal files, and step back through the dated pages until the file first appears. On a Mac, open the folder in the Finder, launch Time Machine from the menu bar or from Applications, and move back along the timeline. In both, the date you are reading is the date the snapshot was taken, which is the date on which the file existed in that form; the file's own modified date inside the snapshot tells you the last edit before that.
What to keep so backups as proof of authorship actually work
A backup only records what is inside the folders it watches. Both tools default to your user folders, which is usually enough, but the record is more convincing if the folder contains more than the final draft.
- Drafts in the file you will submit. Work in one document from first note to final version, as the guide to keeping draft version history recommends, so each snapshot catches it growing.
- Notes, outlines and source lists. Keep them in the same project folder. A snapshot showing notes on Monday, an outline on Wednesday and a draft on Friday is the shape of real work.
- Exports and submitted copies. Save the PDF or file you actually handed in, with the date in its name, so a later comparison has a fixed reference; the hash comparison guide explains how to use it.
- Original photos and recordings. Camera files with their EXIF intact, before any editing app touches them.
- A short log. A plain text file where you note the date and what you did in each session takes a minute and reads well months later.
Retention settings that decide how far back you can go
The default retention on both tools is generous but has limits, and those limits decide whether a snapshot from the start of a long project still exists at the end.
- File History. Under Advanced settings, Keep saved versions defaults to Forever, with options from one month to two years, and Until space is needed. Leave it on Forever for a project that matters, and choose a drive large enough that it does not run out.
- Time Machine. There is no retention menu. Time Machine keeps everything until the disk fills, then deletes the oldest weekly backups first and tells you when it does. A disk two to three times the size of what you back up gives months of history.
- Local snapshots. Time Machine's on-disk snapshots last about 24 hours. They are a convenience for recovering a file you just broke, and no substitute for the external disk.
- A dated drive. Nothing expires, and nothing is added unless you do it. Copy the project folder at milestones and name each copy with the date.
Check the earliest snapshot available every few months. If it is later than the start of a piece of work you may need to defend, copy a milestone folder to a second drive now.
Backup methods compared for evidential value
| Method | Made automatically? | Date recorded by | Independent of your laptop? | Evidential value |
|---|---|---|---|---|
| File History or Time Machine on an external drive | Yes | The backup tool, at each run | Partly: the drive is separate, the clock is the laptop's | Good: a dated chain of many small changes |
| Local snapshots on the internal disk | Yes | The system | No | Low: short retention, same disk |
| Dated external drive copied by hand | No | You, in the folder name, plus modified dates | Partly | Moderate: single points in time, easy to backdate |
| Cloud version history | Yes | The provider's servers | Yes | Strong: server-side dates you cannot edit |
| Sent email with attachment | No | The mail server | Yes | Strong for one moment; no chain |
The local and cloud methods complement each other. Cloud version history has the stronger dates because the provider stamps them; a local backup has the wider coverage because it captures every file in the folder, including notes and exports that never went near a cloud editor. Keeping both is also simply the 3-2-1 backup plan this site recommends: three copies, two kinds of media, one somewhere else.
How to present a backup snapshot to a reviewer
- Find the earliest snapshot that contains the file and note its date and time.
- Restore that version to a new folder named with the snapshot date. Never restore over the current file.
- Repeat for two or three later snapshots that show the draft changing.
- Screenshot the File History or Time Machine view with the snapshot date visible.
- Compute a hash of each restored copy and of the submitted file, so anyone can confirm the last snapshot matches what was handed in.
- Put the restored copies, screenshots and hashes in one folder with a one-page timeline, and offer to show the backup drive itself if asked.
Keep the tone factual. You are showing a process, and the guide to answering an AI detector flag covers how to present the whole record, backups included, without sounding defensive.
Mistakes that weaken the record
- Backing up to the same disk. A laptop that dies takes the evidence with it, and a snapshot on the internal disk is easy to dismiss.
- Leaving the drive in a drawer. File History and Time Machine only run while the drive is connected. Plug it in at the end of every working day.
- Letting the drive fill up. Both tools drop the oldest snapshots first, which are the ones that prove when a project began.
- Restoring over the original. That overwrites the current file and muddles the dates. Restore to a separate folder.
- Excluding the project folder. Check the exclusion list once. A folder on the desktop or in a cloud-synced location is sometimes skipped.
- Starting the backup the week it is needed. The record starts when the backup does. Set it up now, before there is anything to prove.
This article belongs to the authorship record series, alongside the guide to establishing when a file was created. Used this way, backups as proof of authorship cost nothing beyond the drive you should own anyway.
This article is part of the care and maintenance section. The drive it relies on is the same one in the base backup plan for a laptop, so set that up first, and because a backup only runs while the machine is on and connected, the advice on a laptop left plugged in is worth a read. For the record inside the document rather than around it, see version history kept inside the document.
Common questions
Is a backup snapshot better evidence than version history?
They answer different questions. Version history shows the sequence of edits inside one document with server dates. A snapshot shows the whole folder as it stood on a date, including files that have no version history. Together they are stronger than either alone.
Can a backup date be faked?
The laptop's clock can be set wrong before a backup runs, so a single snapshot is weak on its own. A long chain of snapshots with consistent gaps and content is very hard to construct after the fact.
How long should I keep backups as proof of authorship?
Until well after any review or dispute is possible: for coursework, until the grade is final and any appeal window has closed; for professional work, for as long as the contract or your professional body requires.
Does File History back up cloud-synced folders?
Only if those folders are inside the libraries it watches and are not excluded. Check the settings, and remember that a cloud folder set to online-only holds placeholders that the backup cannot copy.
What if my backup drive was not connected for weeks?
The gap shows in the timeline. Say so, and fill it from other records: cloud history, sent email, or the document's own properties.
Sources
- Microsoft Support: Backup and restore with File History: what File History saves and how to restore an earlier version.
- Apple Support: Back up your files with Time Machine on Mac: hourly, daily and weekly backups and 24-hour local snapshots.
- Apple Support: Back up your Mac with Time Machine: setting up a backup disk, backup frequency and restoring.
- NIST: SP 800-86, Guide to Integrating Forensic Techniques into Incident Response: using multiple independent data sources to build a timeline.