The first useful output is a clear account of what is known, where it came from, and what remains unverified.
Preserve the original lead
Begin with the report you actually received. Record the address, network, transaction reference if available, reporting source, and the time the lead reached your team. A copied address without its original context is easy to misinterpret.
Give the case a descriptive title and state the question it is intended to answer. Keep the original report separate from the conclusions you develop during the review.
- Original report or source reference
- Network and complete address
- Reason for escalation
- Known time window
Set a review boundary
Decide which address, activity window, and relationships are relevant to the initial question. A recent-activity view can help establish a starting point, but it does not represent the complete history of the address.
Record indexing gaps or unavailable sources as part of the case. If the question concerns token transfers, internal calls, or historical flows beyond the returned window, identify that as a separate evidence requirement.
Test a hypothesis against the sources
Write down the proposed explanation for the activity and the observation that supports it. Then list another plausible explanation. Shared infrastructure or a shared counterparty can justify further investigation without establishing common control.
Use technical or commercial intelligence to address specific questions. Retain the provider, reference, retrieval time, and relevant coverage limits with each assessment.
Make the next action explicit
The first handoff should state what the team observed, what it currently infers, and what another analyst should verify. Include the evidence references required to reproduce the review.
Assign a next investigative question in the brief, even when the outcome is to gather more information. An unresolved case can still be a useful case when its boundaries are clear.
GroundTruth field notes describe an investigation method. Apply the review scope, source licensing, and information-handling requirements appropriate to your organization.