A clear investigation record
Name the case, describe its purpose, and keep the address, network, snapshot, and recent activity together. Give the next reviewer enough context to begin.
Build a case another analyst can understand. Connect the original question, public observations, review notes, and evidence exports in a single investigation record.
Source evidence → Analyst assessment → Next action
01What did we observe?
02What do we infer?
03What happens next?
A strong case does more than preserve data. It preserves a line of reasoning.
Name the case, describe its purpose, and keep the address, network, snapshot, and recent activity together. Give the next reviewer enough context to begin.
Record competing hypotheses, the source references that support them, and the questions still open. Keep interpretation distinct from the data itself.
Keep active investigations open. Mark a case reviewed once you have documented the rationale and the follow-up that remains.
Use JSON for the structured record, CSV for transaction analysis, and Markdown for a readable brief. Choose the format that fits the recipient’s work.
State the decision being supported and identify the evidence inside the review boundary.
Explain the observed relationships, the alternative explanations, and the unresolved gaps.
Select a useful export, review its contents, and share it through your team’s approved channel.
Choose the workflow, sources, and outcomes that matter to your team.