The case board
The case board is the screen every case opens on. Think of it as the wall of an incident room: you pin up the evidence, write your theories next to it, draw lines between the things that belong together, and step back to see the picture. Unlike a wall, the board also knows how your data is connected, so it can show you what you have not pinned up yet.
The screen has six parts:
| Part | Where | What it is for |
|---|---|---|
| Top bar | Along the top | The case’s name, status and severity; counters that light things up; search |
| Canvas | The middle | The board itself: evidence, findings, hypotheses, notes and the lines between them |
| View | Bottom left | What the board shows: neighbours, kinds of relation, settled findings, highlights |
| Tool dock | Bottom centre | The tools you work with: select, pan, note, frame, hypothesis, comment, link |
| Zoom controls | Bottom right | Zoom, fit, zoom to the selection, and the mini-map |
| Side panels | The right edge | Details, hypotheses, adding evidence, the timeline, the case file and more |
The top bar
From left to right:
- The case’s name, with its status (open, in progress, closed) and its severity. Click the name to open the Case file panel, where you rename the case and change what it says about itself.
- What’s on the board: three counters for evidence, findings and
hypotheses. Click one to spotlight everything of that kind: it lights
up and the rest fades, and the view zooms to fit it. Click it again, or press
Esc, to show everything again. - Search: the wide box in the middle. Click it or press
⌘K(Ctrl Kon Windows) to search the board, find assets and findings anywhere in your data and add them, or run an action. See the search. - Who else is here: the initials of anyone else with the board open.
- More: run Autopilot, tidy up the board, export it as an image, open or take board snapshots, open the shortcuts and visual key, and close the case.
The counters are the quickest way to check the case at a glance. Lighting up Findings, for example, shows every finding in the case at once, however spread out the board is.
The canvas
The canvas is where the case lives. Everything on it keeps the place you gave it, for everyone who opens the case. What you will see there:
- Evidence: circles with a kind icon and a lime ring. The name is written underneath. See Evidence & findings.
- Findings: small coloured circles around their asset, joined to it by a thin “contains” line.
- Lines between things, with what they mean written along them. See Lines & links.
- Hypothesis cards: your theories, with their verdict and the evidence for and against. See Hypotheses & threads.
- Notes, frames and comment pins. See Notes, frames & comments.
- Suggested neighbours and connections: assets connected to your evidence that are not in the case yet. See Connections & neighbours.
Clicking something selects it: it gets a glowing ring, and everything that is not connected to it fades, so you see its neighbourhood at once. Double-clicking opens it in the side panel: an asset or a finding opens its details, a hypothesis opens its thread.
Right-click anything, or the empty canvas, for everything you can do with it in that spot. That covers opening it, linking from it, showing its connections, highlighting it, moving it into a frame, and removing it from the case.
The tool dock
| Tool | Key | What it does |
|---|---|---|
| Select | V | Click to select, drag to move, drag on empty canvas to select everything in a box |
| Pan | H, or hold Space | Drag anywhere to move around the board without selecting or moving anything |
| Note | N | Click on the board to place a sticky note |
| Frame | F | Drag to draw a frame: a named, coloured group |
| Hypothesis | T | Click on the board to place a new hypothesis card |
| Comment | C | Click to pin a comment and start a conversation on that spot |
| Link | L | Drag from one thing to another to link them. Every node becomes a place to start a link |
| Undo / Redo | ⌘Z / ⇧⌘Z | Step back and forward through your changes. The tooltip names the change |
When a case is closed, the tools that change the board are switched off; select and pan still work.
The View menu
View, at the bottom left, decides what the board draws. Nothing you switch off here is deleted: it only stops being drawn, or fades.
| Section | What it controls |
|---|---|
| Neighbours not in the case | How far out to draw suggested neighbours: Off, 1, 2 or 3 hops, or ∞ for as far as the connections go. Shows how many are drawn |
| Connections | Which kinds of relation are drawn and followed to neighbours: Lineage, Links, Duplicates, Similar |
| Findings | Show resolved, Show dismissed and Show gone / deleted. Turned off, those findings fade rather than disappear |
| Highlight by | Light up everything from one source, one detector or one hypothesis, or show only highlighted items |
| Comments | Show resolved comments too |
| Expand all / Collapse all | Unfold or fold the findings of every asset at once |
Zoom controls and the mini-map
At the bottom right sit zoom out, zoom in, fit the board (⇧1),
zoom to the selection (⇧2) and the mini-map. The mini-map is a small
overview of the whole board with a frame showing where you are; drag the frame
to jump. How much the board shows at each zoom is explained in
Navigating & shortcuts.
The side panels
The rail on the right opens one panel at a time next to the board. Click an icon
to open its panel and click it again to close it. The last icon hides or shows
the panel you had open. Esc closes it too.
| Panel | What you find there |
|---|---|
| Details | What you selected. For an asset, four tabs: the findings in the case, its other findings (pick some and Attach them), its duplicates and its lineage. For a finding: an overview, similar findings and where else its value turns up. For a line: what the relation is, and for a link you drew, its kind, label and note to edit. See the Details panel |
| Hypotheses | Every hypothesis of the case, on the board or not, with its verdict, confidence and balance of evidence. Click one to open its thread |
| Add evidence | Search for assets and findings to add. Click one to drop it in the middle of your view, or drag it onto the board |
| Evidence | The case’s evidence as a table, with notes on each asset and finding. Click a row to fly to it on the board |
| Leads | What the case may be missing: documents that look like your evidence, important answers of its watches, similar findings, and Autopilot’s proposals, each with its reason. They refresh by themselves. Accept one, drag it onto the board where you want it (which accepts it too), or dismiss it for good. Reviewed leads that are not in the case can be dragged in again. A badge counts the ones waiting. See Leads |
| Watches | The inquiries that feed this case with new matches, as a grid of small cards (auto-add, filters, escalations and hypothesis rules at a glance). Click one to open it and its answers below; its card stays marked in the grid. The last card links another watch, or creates a new one in a new tab. A badge counts new matches |
| Timeline | Three tabs. Activity is everything done on the case. Chronology is the story you reconstruct: real-world events in the order they happened, which you add, date and mark as verified. Threads lists every discussion, with Show on board or Place on board. Warnings elsewhere on the board (evidence gone from its source, answers a watch lost) link to the entry that explains them |
| Case file | The case’s title, description, severity and status, and its automatic clean-up switches; the AI mode and Autopilot; the conclusion; and Close case. Everything saves as you change it, and a mark says when it is saved |
| Board snapshots | Saved pictures of the board: one is taken when the case closes, and you can take one any time. Open one to see the board exactly as it was, read-only |
Hypothesis threads and Show connections open in the same place, from the board itself.
The address in your browser follows the panels: which one is open, its tab, the watch you opened, the timeline entry you are reading. Reload the page, or send the address to a teammate, and the board opens the same way.
At the foot of the rail, a small mark says whether your changes are saved: a tick once everything is saved, a spinner while saving, and a warning if a save failed. The board retries on its own.
Working together
The board is shared. Several people can work on it at once:
- Changes from others appear as they happen, and something new that arrives from a watch is marked NEW.
- The initials in the top bar show who else is looking at the board.
- If two people edit the same note at the same moment, the second save is refused rather than overwriting the first. The board says who changed it and copies your text to the clipboard, so nothing is lost.
- Every change is recorded in the timeline under the name of whoever made it, a teammate or Autopilot.
Tidy up, export and snapshots
Tidy up
More → Tidy up board arranges the board for you. Things that are joined are laid out from left to right along their lines, groups that are not connected sit side by side, and findings you dragged away go back around their asset. It is one step, so Undo puts everything back where it was.
Export
More → Export PNG saves the board as an image, ready for a report or a hand-over.
Snapshots
More → Take snapshot keeps the board exactly as it is now. Open old snapshots from the Board snapshots panel. A snapshot is read-only; Back to the live board returns to the current one.
AI clients can read, arrange and snapshot the board over MCP, with a token that has the Case Board scope. See AI agents & MCP.