Evidence & findings
Evidence is an asset you added to the case: a document, a spreadsheet, an email, a page, a table. Findings are what the detectors found in it: an IBAN, a name, a salary, a social security number. On the board, every piece of evidence is a circle, and each of its findings is a small circle of its own, joined to it by a thin contains line.
Reading an asset
Each asset shows its kind (file, email, table, page…) as an icon in the circle and its name underneath. Everything else is a ring, a colour or a small badge:
- EvidenceAn asset in the case: its kind icon inside, the lime ring around it, its name underneath.
- Suggested neighbourConnected to your evidence but not in the case. No ring; point at it and press + to add it.
- ↑2Found by Show connectionsDashed and faint, with how far away it is: ↑ upstream, ↓ downstream, ≈ alongside.
- Deleted at its sourceRed dashed circle, name struck through. The case keeps what it knew.
- ▸9Findings folded awayA ring of severity colours shows the mix. ▸9 unfolds them.
- +3More on this asset+3: findings of this asset that are not in the case yet. Press it to see them as ghosts.
- NEWNewArrived since you last looked, usually from a watch feeding the case.
- Hypothesis dotsOne dot per hypothesis that cites this evidence, in the hypothesis colour. Click one to focus it.
- HighlightedA marker colour you gave it, to group things by eye or filter by later.
- SelectedA glowing ring. Everything not connected to it fades.
Reading a finding
A finding’s colour is its severity:
The letters inside name the detector that raised it: the first letters of a one-word detector (IBAN, SSN) or the initials of a longer name (a custom detector called Austrian company ID shows ACI). Under the circle, at full zoom, you read the finding itself: its type and the value found.
A finding’s look tells you where it stands:
- IBANOpenFilled with its severity colour. The letters name the detector (IBAN, SSN, ACI…).
- PNNEWNewBrought in by the latest scan of a watch that feeds this case.
- PHOResolvedHollow, ringed in its colour, with a green tick.
- EMADismissedHollow, grey and dashed: marked a false positive or ignored. Its label is struck through.
- SSNGone from its sourceA red dashed ring: the latest scan no longer finds it. The case keeps its copy.
- CARDDeletedFaint and dotted: the finding's record was deleted. The case keeps its snapshot.
- ADDNot in the caseA dashed grey ghost with an italic label: on the asset, not attached to the case yet.
- IBANEscalatedA ring and a warning flag in the colour of high severity: an escalation rule of the case matched it. Its asset shows the flag with how many of its findings escalated.
Settled findings do not disappear from the board on their own. A resolved, dismissed, gone or deleted finding keeps its place, because it is part of the record of the case. If they get in the way, switch them off in View → Findings and they fade instead, or let the case take them out with automatic clean-up.
How findings are arranged
- A few findings fan out to the right of their asset. Four or more go all the way round it, starting at twelve o’clock.
- Drag a finding anywhere. It keeps that spot, and it travels with its asset when the asset moves.
- An asset shows up to twelve findings. The rest wait behind ▸n: click it to show them all, and ◂ to show fewer again.
- Fold an asset’s findings away (select it and press
E, or right-click → Collapse findings) and the asset wears a ring of severity colours instead, with ▸n to unfold them. Zoomed far out, every asset shows its ring. - +n on an asset means it has n more findings that are not in the case. Click it to see them around the asset as dashed grey ghosts, and − to hide them again.
Adding evidence
There are several ways in. Use whichever matches where you are:
| Way | When to use it |
|---|---|
| Add evidence panel | You know what you are looking for. Search assets, findings or both by name or text, narrow with filters, then click a result to drop it in the middle of your view, or drag it exactly where you want it |
Search (⌘K) | You are already on the board and want one thing fast. The Corpus scope searches all your data; press Enter to add |
| Many findings at once | You are triaging a long list. The Add evidence panel links to the findings table, where you can pick many findings at once and add them to the case |
| Watches | You want the case to keep itself up to date. New matches of a linked inquiry arrive on their own, marked NEW |
| Leads | The case suggests something it may be missing: a look-alike document, a watch answer, a similar finding, or an Autopilot proposal. Accept a lead, or drag it onto the board. See Leads |
| Neighbours and connections | The board shows you something connected to your evidence. Press + on it and it joins the case where it stands. See Connections & neighbours |
Adding something that is already on the board does not add it twice: the board says so. A finding whose asset is already on the board simply joins that asset.
Attaching and detaching findings
Evidence brings its asset into the case; the findings on it are attached one by one, so the case holds exactly the findings that matter.
- Attach a finding that is not in the case: click +n to see the ghosts, then right-click one → Attach to case, or use Attach next to it in the Details panel.
- Detach a finding: right-click it → Detach from case…. The finding stays in its source; only its place in this case goes. The timeline records it, and Undo brings it back.
- Detach & filter out every finding like it: right-click → Detach & filter out this type… or …this value…. A finding filter takes them all out and keeps them out.
Settling findings from the board
Right-click a finding to change its status without leaving the case:
| Action | Result |
|---|---|
| Mark resolved | The finding goes hollow, ringed in its colour, with a green tick |
| Mark false positive | The finding goes hollow, grey and dashed, and its label is struck through |
| Reopen finding | Back to open |
The change is made to the finding itself, so it shows everywhere the finding appears, not only in this case.
Everything you can do with evidence
Right-click an asset or a finding for its menu:
| On an asset | On a finding |
|---|---|
| Open asset: its full page, in a new tab | Open finding: its full page, in a new tab |
| Open details in the side panel | Explain finding: its details in the side panel |
| Link from here | Link from this finding |
| New hypothesis from selection, or Add to hypothesis as supporting, contradicting or neutral | Comment |
| Comment | Highlight in a marker colour |
| Show neighbours and Show connections | Mark resolved, Mark false positive, Reopen finding |
| Collapse or Expand findings | Escalate this type… or this value…, and Clear escalation on an escalated finding |
| Highlight in a marker colour | Detach from case…, Detach & filter out this type… or this value… |
| Move to frame, Bring to front, Send to back | |
| Remove from case… |
A finding that is not in the case (a dashed ghost) offers Open finding, Attach to case, and escalating or filtering out findings like it.
An escalated finding (a ring and a warning flag in the colour of high severity) matched one of the case’s escalation rules.
Removing evidence takes its attached findings out of the case too. The timeline records it, and Undo restores everything, including notes and hypothesis stances.
The Details panel
Click an asset or a finding and the Details panel follows your selection (double-click opens it if it is closed). Its header says where the asset came from, with buttons to open the asset or finding in full or to Show connections. Below it, tabs:
| For | Tab | What it shows |
|---|---|---|
| An asset | In case | Its findings that are in the case, with their severity, state and note |
| Other findings | Its findings that are not in the case yet, searchable and loaded page by page. Tick some and press Attach, or attach one at a time. Resolved too includes resolved ones | |
| Duplicates | The documents that look like it, as in Duplicate review | |
| Lineage | Where its data comes from and where it goes, as in lineage | |
| A finding | Overview | Its detector, confidence, status and note, and Finding page for everything else |
| Similar | Findings like it elsewhere, as a graph or a list | |
| Where else | The other places its value was found |
In the Duplicates and Lineage graphs, and in the similar findings, anything already in the case carries an In case mark. Right-click one that is not for Add to this case: an asset joins as evidence, a finding brings its asset along. The same graphs outside a case, on an asset’s own page, offer Add to case… instead, to pick any open case or start one.
Double-click a line between two things, or right-click it and choose Details (Why is this here? on a relation the platform found), and the panel describes that relation. For a line the platform found, that is what it means (a likely duplicate with its match score and shared values, a lineage step with its columns, a reference), how it was found and how sure the platform is. For a link you drew, you edit its kind, label, certainty, confidence and note right there.
Evidence is a record. When a later scan changes the source (a finding is no longer found, a file is deleted), the case keeps what it knew and marks what changed: gone from its source, deleted. You never lose what the investigation was based on, unless you ask the case to let go of it with automatic clean-up.