Skip to Content
InvestigationsCasesClean-up & filters

Clean-up & filters

A case keeps everything you put in it until you say otherwise. Two tools let it say otherwise for you:

  • Automatic clean-up takes out findings and assets that no longer hold up: findings the scans no longer see, findings someone resolved, assets deleted from their source.
  • Finding filters keep a kind of finding out of the case: a finding type (say IP_ADDRESS), or a value that matches a regular expression. A filter holds for the whole case, or only for what one watch brings in.

Both are off until you switch them on, and every removal is written on the case timeline: which finding or asset left, and why.

Their counterpart is escalation: the same rules with the other action. Instead of keeping a kind of finding out, an escalation marks it, highlights it and brings it in.


Automatic clean-up

Three switches, in the Case file panel of the board and when you open a new case:

SwitchWhat leaves the case
Remove findings that disappearA finding a scan no longer detects, or one that was deleted outright (a purge, a deleted source)
Remove resolved findingsA finding someone marked resolved. False positives and ignored findings stay
Remove assets that disappearAn asset deleted from its source, together with its findings

When does it happen?

  • Right away when you switch one on. Before it applies, the board asks, and says what it will take out, with examples, so nothing leaves without you having seen it coming. The toast afterwards says how much left, with What changed to open its timeline entry. Switching one off applies at once and takes nothing out.
  • After every scan of a source the case cites.
  • When someone changes a finding’s status, from the board, the findings table or a bulk update.
  • On a routine check when the case board is opened, which catches anything else (a purge, a deleted source).

A closed case is never touched: it is a record.

A finding the clean-up took out keeps its note and its hypothesis stances. If you attach it again from the board, it comes back exactly as it was.


Finding filters

Some findings are noise for one investigation and signal for another: internal IP addresses, your own company’s name, a test account. A filter keeps them out of this case without touching the finding or any other case.

What a filter does

  • Findings in the case that match are detached now. The filter dialog says how many before you confirm, and the button carries the number.
  • Assets left with nothing go too, if you like. When a filter keeps findings out, Also take out assets left without findings (on by default) removes the assets whose only findings in the case were the ones filtered out. Say two documents hold a Secret keyword, and one of them also a Public IP: filtering out Secret keyword takes the first document off the board and keeps the second, with its Public IP. The dialog says how many assets that is, and names some. It happens once, when you add the filter; assets you added without any finding stay, and you can add a removed one back from the board.
  • No watch adds them again, neither by itself (auto-add) nor with Pull all.
  • Attaching one by hand still works. Picking a finding yourself is a deliberate choice, and the filter does not override it.
  • Autopilot respects case-wide filters, and leads stop suggesting filtered findings: waiting leads the filter matches go away, and no new ones are suggested.
  • Filters win over escalations. A finding that matches both never comes in.

Case-wide or one watch

ScopeApplies to
Every watch in this caseEvery finding of the case, whichever watch finds it (and findings you added by hand, when the filter is added)
Only one watchOnly the answers of that watch. The same finding still comes in through another watch that does not filter it. Unlinking the watch removes its filters

By type or by value

  • Finding type: pick from the types the case holds and its watches answer, with how many of each are in the case and how many the watches answer. Select several at once.
  • Value: a regular expression tested against the matched value, with a short note on why. Use ^…$ to match the whole value, for example ^10\. for internal addresses; matching is case-sensitive. Add several patterns at once. The dialog shows how many findings each pattern matches, and says so if one is not a valid expression.

Where to add them

  • Watches panel: Rules for every watch at the top, and Rules on each watch card. Press + in the Filter out row. The filters show as chips; click a value filter to edit it, × to remove it.
  • On the board: right-click a finding → Detach & filter out this type… or Detach & filter out this value… (the value is filled in as an exact match). A finding that is not in the case offers Filter out this type… and Filter out this value….

Removing a filter puts nothing back. What it took out stays out; the watches simply stop skipping it. Pull the watch again, or attach findings on the board, if you need them back.


On the timeline

EntryWhat it tells you
Clean-up settings changedWhich switch went on or off, and who changed it
Finding filter added / changed / removedThe filter, its scope and its note; a changed filter shows the old and the new pattern
Taken out: no longer detectedFindings a scan retired or that were deleted, marked which is which
Taken out: resolvedFindings someone resolved
Detached by a filterThe findings a filter took out, and the filter
Taken out: no findings left after a filterThe assets that left with the filter’s findings, when Also take out assets left without findings was on
Taken out: asset gone from its sourceThe assets, and how many findings left with them
Evidence pulled from inquiryNow also how many matches the filters kept out

Each removal says what set it off: the switch being turned on, a scan of a named source, a status change or a routine check. It lists the findings it took out (type, value and asset) with a shortcut to their asset on the board.

What the clean-up does by itself does not write a row per scan: its passes fold into one entry per reason while they keep coming (a pass within the hour since the last), which says how many passes, which sources and when: Taken out: no longer detected, 12 findings, after 4 scans of Firmenbuch between 09:10 and 10:05. Switching a rule on or adding a filter is always an entry of its own.


From MCP and the assistant

Every step here has an MCP tool, and every one that takes something out can be previewed first without changing anything:

  • Clean-up: preview_case_cleanup reports what the switches would take out now (all three, or the ones named); update_case switches them on (removeGoneFindings, removeResolvedFindings, removeGoneAssets) and applies them at once.
  • Filters: preview_case_finding_filters reports what unsaved rules would take out (per rule, with a sample, and the assets they would leave empty); add_case_finding_filters adds them, update_case_finding_filter changes a rule’s pattern or description, remove_case_finding_filter removes one, and list_case_finding_filters lists them with the finding types to pick from.

The token needs the Cases scope. See AI agents & MCP.

Last updated on