Skip to Content
InvestigationsCasesEvidence & findings

Evidence & findings

Evidence is an asset you added to the case: a document, a spreadsheet, an email, a page, a table. Findings are what the detectors found in it: an IBAN, a name, a salary, a social security number. On the board, every piece of evidence is a circle, and each of its findings is a small circle of its own, joined to it by a thin contains line.

One contract with a finding in every state, an archive with its findings folded away, a spreadsheet with more findings than the case holds, and an asset deleted at its source. Point at anything for its full description.

Reading an asset

Each asset shows its kind (file, email, table, page…) as an icon in the circle and its name underneath. Everything else is a ring, a colour or a small badge:

  • EvidenceAn asset in the case: its kind icon inside, the lime ring around it, its name underneath.
  • Suggested neighbourConnected to your evidence but not in the case. No ring; point at it and press + to add it.
  • ↑2Found by Show connectionsDashed and faint, with how far away it is: ↑ upstream, ↓ downstream, ≈ alongside.
  • Deleted at its sourceRed dashed circle, name struck through. The case keeps what it knew.
  • ▸9Findings folded awayA ring of severity colours shows the mix. ▸9 unfolds them.
  • +3More on this asset+3: findings of this asset that are not in the case yet. Press it to see them as ghosts.
  • NEWNewArrived since you last looked, usually from a watch feeding the case.
  • Hypothesis dotsOne dot per hypothesis that cites this evidence, in the hypothesis colour. Click one to focus it.
  • HighlightedA marker colour you gave it, to group things by eye or filter by later.
  • SelectedA glowing ring. Everything not connected to it fades.

Reading a finding

A finding’s colour is its severity:

CriticalHighMediumLowInfo

The letters inside name the detector that raised it: the first letters of a one-word detector (IBAN, SSN) or the initials of a longer name (a custom detector called Austrian company ID shows ACI). Under the circle, at full zoom, you read the finding itself: its type and the value found.

A finding’s look tells you where it stands:

  • IBANOpenFilled with its severity colour. The letters name the detector (IBAN, SSN, ACI…).
  • PNNEWNewBrought in by the latest scan of a watch that feeds this case.
  • PHOResolvedHollow, ringed in its colour, with a green tick.
  • EMADismissedHollow, grey and dashed: marked a false positive or ignored. Its label is struck through.
  • SSNGone from its sourceA red dashed ring: the latest scan no longer finds it. The case keeps its copy.
  • CARDDeletedFaint and dotted: the finding's record was deleted. The case keeps its snapshot.
  • ADDNot in the caseA dashed grey ghost with an italic label: on the asset, not attached to the case yet.
  • IBANEscalatedA ring and a warning flag in the colour of high severity: an escalation rule of the case matched it. Its asset shows the flag with how many of its findings escalated.

Settled findings do not disappear from the board on their own. A resolved, dismissed, gone or deleted finding keeps its place, because it is part of the record of the case. If they get in the way, switch them off in View → Findings and they fade instead, or let the case take them out with automatic clean-up.


How findings are arranged

  • A few findings fan out to the right of their asset. Four or more go all the way round it, starting at twelve o’clock.
  • Drag a finding anywhere. It keeps that spot, and it travels with its asset when the asset moves.
  • An asset shows up to twelve findings. The rest wait behind ▸n: click it to show them all, and ◂ to show fewer again.
  • Fold an asset’s findings away (select it and press E, or right-click → Collapse findings) and the asset wears a ring of severity colours instead, with ▸n to unfold them. Zoomed far out, every asset shows its ring.
  • +n on an asset means it has n more findings that are not in the case. Click it to see them around the asset as dashed grey ghosts, and − to hide them again.

Adding evidence

There are several ways in. Use whichever matches where you are:

WayWhen to use it
Add evidence panelYou know what you are looking for. Search assets, findings or both by name or text, narrow with filters, then click a result to drop it in the middle of your view, or drag it exactly where you want it
Search (⌘K)You are already on the board and want one thing fast. The Corpus scope searches all your data; press Enter to add
Many findings at onceYou are triaging a long list. The Add evidence panel links to the findings table, where you can pick many findings at once and add them to the case
WatchesYou want the case to keep itself up to date. New matches of a linked inquiry arrive on their own, marked NEW
LeadsThe case suggests something it may be missing: a look-alike document, a watch answer, a similar finding, or an Autopilot proposal. Accept a lead, or drag it onto the board. See Leads
Neighbours and connectionsThe board shows you something connected to your evidence. Press + on it and it joins the case where it stands. See Connections & neighbours

Adding something that is already on the board does not add it twice: the board says so. A finding whose asset is already on the board simply joins that asset.


Attaching and detaching findings

Evidence brings its asset into the case; the findings on it are attached one by one, so the case holds exactly the findings that matter.

  • Attach a finding that is not in the case: click +n to see the ghosts, then right-click one → Attach to case, or use Attach next to it in the Details panel.
  • Detach a finding: right-click it → Detach from case…. The finding stays in its source; only its place in this case goes. The timeline records it, and Undo brings it back.
  • Detach & filter out every finding like it: right-click → Detach & filter out this type… or …this value…. A finding filter takes them all out and keeps them out.

Settling findings from the board

Right-click a finding to change its status without leaving the case:

ActionResult
Mark resolvedThe finding goes hollow, ringed in its colour, with a green tick
Mark false positiveThe finding goes hollow, grey and dashed, and its label is struck through
Reopen findingBack to open

The change is made to the finding itself, so it shows everywhere the finding appears, not only in this case.


Everything you can do with evidence

Right-click an asset or a finding for its menu:

On an assetOn a finding
Open asset: its full page, in a new tabOpen finding: its full page, in a new tab
Open details in the side panelExplain finding: its details in the side panel
Link from hereLink from this finding
New hypothesis from selection, or Add to hypothesis as supporting, contradicting or neutralComment
CommentHighlight in a marker colour
Show neighbours and Show connectionsMark resolved, Mark false positive, Reopen finding
Collapse or Expand findingsEscalate this type… or this value…, and Clear escalation on an escalated finding
Highlight in a marker colourDetach from case…, Detach & filter out this type… or this value…
Move to frame, Bring to front, Send to back
Remove from case…

A finding that is not in the case (a dashed ghost) offers Open finding, Attach to case, and escalating or filtering out findings like it.

An escalated finding (a ring and a warning flag in the colour of high severity) matched one of the case’s escalation rules.

Removing evidence takes its attached findings out of the case too. The timeline records it, and Undo restores everything, including notes and hypothesis stances.


The Details panel

Click an asset or a finding and the Details panel follows your selection (double-click opens it if it is closed). Its header says where the asset came from, with buttons to open the asset or finding in full or to Show connections. Below it, tabs:

ForTabWhat it shows
An assetIn caseIts findings that are in the case, with their severity, state and note
Other findingsIts findings that are not in the case yet, searchable and loaded page by page. Tick some and press Attach, or attach one at a time. Resolved too includes resolved ones
DuplicatesThe documents that look like it, as in Duplicate review
LineageWhere its data comes from and where it goes, as in lineage
A findingOverviewIts detector, confidence, status and note, and Finding page for everything else
SimilarFindings like it elsewhere, as a graph or a list
Where elseThe other places its value was found

In the Duplicates and Lineage graphs, and in the similar findings, anything already in the case carries an In case mark. Right-click one that is not for Add to this case: an asset joins as evidence, a finding brings its asset along. The same graphs outside a case, on an asset’s own page, offer Add to case… instead, to pick any open case or start one.

Double-click a line between two things, or right-click it and choose Details (Why is this here? on a relation the platform found), and the panel describes that relation. For a line the platform found, that is what it means (a likely duplicate with its match score and shared values, a lineage step with its columns, a reference), how it was found and how sure the platform is. For a link you drew, you edit its kind, label, certainty, confidence and note right there.

Evidence is a record. When a later scan changes the source (a finding is no longer found, a file is deleted), the case keeps what it knew and marks what changed: gone from its source, deleted. You never lose what the investigation was based on, unless you ask the case to let go of it with automatic clean-up.

Last updated on