Skip to Content

Use cases

The case board has many tools. Most investigations need only a few of them, in a particular order. Here are the common ones, each with the tools to use and why.

Quick chooser

I want to…Reach for
Find out where some data came from, or where it wentShow connections
Decide between two or more explanationsHypotheses with stances, then focus each one
Find every copy of a fileShow connections following Duplicates and Similar
Work through many findingsWatches, the Findings spotlight, and settling findings from the board
Let a standing question feed a theoryA watch with a hypothesis rule
Make sure nothing obvious is missingSuggested neighbours at 2 hops
Hand the case over or report on itFrames, notes, highlights, snapshots and Export PNG
Review what Autopilot didLeads, the Timeline, and Chronology events to verify

Tracing a data leak

The situation. A monthly payroll file turned up attached to an email sent to a private address. You need to know where the data came from, how it got out, and whether other copies exist.

Start from what you know

Press ⌘K, switch to Corpus, find the email and press Enter to put it on the board.

Trace the trail

Right-click the email → Show connections. Set Direction to Both, Follow to Lineage and Links, and How far to ∞. Upstream, to the left, you see the export that was attached and the spreadsheet it was transformed from. Further upstream you reach the HR database.

Bring the chain into the case

Right-click the source spreadsheet’s ghost → Add the route to it. Every asset between the email and the source joins the case in one step.

Look alongside

Switch Follow to Duplicates and Similar. Any copy of the export, such as one on a backup share, shows up alongside with ≈. Add the ones that matter.

Say what you think happened

Press T, click near the evidence and type “Payroll data was forwarded to a private mailbox”. Drag from the card to the private email-address finding and choose Supports. In the hypothesis’s thread, note why: sent at 23:40, outside working hours.

Frame the path, note the next step

Press F and draw a frame around the export and the email; name it Exfiltration path. Add a sticky note: Ask IT for the mail gateway logs.

The trace from step 2: upstream to the left, downstream to the right, copies and look-alikes below.

Testing competing explanations

The situation. A supplier’s bank account changed just before a large payment. Was it fraud, or a legitimate change?

Put the evidence on the board

Add the invoice, the vendor master record and the email announcing the change.

Write both explanations down

Create H1 “The bank details were changed by a fraudster” and H2 “The supplier changed banks legitimately”. Writing down the explanation you do not believe yet is the point: it stops the case from only collecting evidence for the first idea.

The look-alike sender domain supports H1 and contradicts H2. The old account in the vendor master is neutral to H2. Write down why in each hypothesis’s thread.

Focus each hypothesis in turn

Click H1’s card: only its evidence stays lit. Then click H2’s. How strong is each one, really? Contested evidence carries both hypotheses’ dots.

Record the verdict

In each thread, set the verdict and your confidence, and write why in the note box. On the Test tab, write what you would expect to find if the hypothesis were true. For example: every invoice since the change carries the new IBAN. Then go and check.

The two hypotheses from this example. Click either card to focus it.

Finding every copy

The situation. A customer export must be deleted everywhere, but people have copied it around.

  1. Put the export on the board and right-click it → Show connections.
  2. Set Follow to Duplicates (identical content) and Similar (near copies), and How far to 2 or more. Copies of copies show up too.
  3. Add n connections on the Alongside group puts every copy in the case.
  4. As copies are deleted and sources are rescanned, their findings get the red dashed gone from its source ring. The case keeps the record, and you can see at a glance what is still out there.
  5. Mark findings resolved from the board as each copy is dealt with.

Working through many findings

The situation. An inquiry matches new findings every day, and the case should keep up without drowning you.

  1. Link the inquiry in the Watches panel. New matches arrive on the board on their own, marked NEW, and the panel’s badge counts them.
  2. Click the Findings counter in the top bar to spotlight every finding in the case, wherever it sits.
  3. Settle findings where they are: right-click → Mark resolved or Mark false positive. The change applies to the finding everywhere.
  4. Switch settled findings off in View → Findings, so they fade and the open ones stand out.
  5. Fold busy assets with E. The severity ring still shows what is inside.
  6. Check the Leads panel. The case keeps it current by itself: important answers of the watches, documents that look like your evidence, similar findings and Autopilot’s proposals. Accept or dismiss them, or filter by reason and Dismiss all shown once you have picked what matters.
The Findings spotlight: the findings stay lit, everything else fades.

Letting a watch feed a theory

The situation. You hold a theory (companies that stop filing accounts disappear from the register) and a standing question already finds the evidence: which companies did the court strike off? You do not want to link every answer by hand, and you want new ones to turn up where the theory sits on the board.

  1. Put the hypothesis on the board, inside a frame if you like to keep each theory’s evidence together.
  2. In the Watches panel open the watch. Under Link to hypothesis press +, pick the hypothesis, and choose a stance: Supports, Contradicts or Neutral.
  3. Narrow it if only some answers belong, for example one finding type, and leave Also link what the case already holds on.
  4. From then on every answer the watch brings in is linked and lands in that hypothesis’s frame, or next to its card. The timeline records which watch linked how many findings to which hypothesis.
  5. Open the hypothesis: its balance of evidence already moves with the data. Where the watch is too broad to say for or against, give the rule Neutral and upgrade the stance of the few findings that decide it.

Details and edge cases are in Hypothesis rules.


Making sure nothing is missing

The situation. Before you conclude, you want to know whether the case overlooks something obvious.

  1. Open View → Neighbours not in the case and choose 2 hops, with every kind of connection on.
  2. Suggested neighbours appear around the evidence without the lime ring, joined to it by the relation that connects them.
  3. Add what belongs with +. Hide what does not, so you can see what is left.
  4. If the board says there are more neighbours than it drew, use Show connections on the evidence that matters most, to see everything around it.
  5. Open Leads and pick Look-alikes: copies of your evidence and documents sharing its key values, strongest match first. Dismiss what does not matter; it will not come back.
Three suggested neighbours around two pieces of evidence.

Handing over a case

The situation. The case goes to legal, to management, or to a colleague taking over, and they need to understand it quickly.

  1. Frame the story. One frame per chapter: Background, 12 March: what happened, Open questions. Collapse the background frame so it doesn’t distract.
  2. Write the facts on notes. Use a team colour code, such as green for confirmed and pink for risks.
  3. Highlight the key evidence, and check View → Highlight by → Only highlighted reads as a summary.
  4. Tidy up if the layout has grown messy. Undo if you prefer your own.
  5. Take a snapshot (More → Take snapshot), so the hand-over state is kept exactly.
  6. Export PNG for the report.
  7. Write the conclusion in the Case file panel. When the work is done, close the case: the board becomes read-only and a final snapshot is taken.
A hand-over layout: a frame for the day's events, notes for questions, facts and warnings, and a collapsed background frame.

Working alongside Autopilot

The situation. Autopilot works on your cases too, and you want to stay in control of what it does.

  • Leads holds what it proposes, with its reasoning. Nothing it suggests joins the case until someone accepts it or drags it onto the board, and what you dismiss it never proposes again.
  • In the Timeline, Activity shows every action on the case with an AI badge on Autopilot’s. Chronology events it proposed are marked, and you verify them before they count as established.
  • The Case file panel sets the case’s AI mode. Freeze a sensitive case to observe-only, or run Autopilot on it now.
  • Hypothesis threads show which entries Autopilot wrote, so its reasoning can be checked like anyone else’s.

Whatever the case, two habits pay off: write hypotheses down early, even tentative ones, and write your reasons in the threads. The board shows what is connected; the notes say why it matters.

Last updated on