Investigations and graphs
Investigations stores cases with notes and graph content. Use Pivot to discover relationships, then retain the observations that support your investigation.
A personal investigation belongs to your account. An organization case belongs to its client space or asset scope: use the case editor there, capture evidence and set visibility before sharing. Opening a graph does not grant access to the underlying client space.
Changes to text and graph content save after a short pause where autosave is available. Wait for the save status before leaving. If someone else edits the same revision, review the conflict instead of overwriting their changes.
Use the organization's report workflow for versioned client deliverables. A graph link and a published report have different access rules; revoke each share you no longer need.
Explore connections in saved evidence
Open an organization engagement's Evidence tab. Your saved records appear beside Evidence connections; on a narrow screen, the graph follows the records. This view extracts supported attributes from evidence you can currently read. It does not run a search, contact an external source or charge research credits.
Hover over a record or graph node to highlight its connections. The attribute list offers the same exploration with keyboard focus or touch: select an attribute, then choose View evidence to return to a supporting record. Use Find an attribute, Shared attributes only, zoom and Fit graph to inspect the view.
A shared attribute occurs in at least two included evidence records. Its Evidence records count measures those distinct records, not the number of matching assets in the index. A line means an attribute was observed in saved evidence; it does not establish common ownership or a verified relationship.
What can be missing?
The view reads at most 500 accessible evidence records, extracts up to 32 unique attributes per record, and includes at most 1,500 nodes and 4,000 connections. When a limit omits content, the graph displays a warning. A missing connection is not evidence that no relationship exists. Unsupported attributes or text outside the recognized evidence fields do not become graph nodes.
Permissions and the current plan determine the available evidence and fields. Shared counts do not include inaccessible records, and opening the graph does not grant access to another member's private evidence. An empty graph can mean that the readable evidence contains no supported attributes.
The view refreshes when its evidence or access context changes. Refresh graph reloads the saved-evidence view without launching a search. If loading fails, your evidence remains available and you can retry explicitly.
Enrich selected attributes
Staff with write access can select up to 25 supported attributes using Enrich, then choose Review enrichment. Supported seeds include domains, IP addresses, favicon hashes and tracking identifiers where the saved data supplies a valid value. Not every displayed attribute can start a pivot.
Opening the enrichment dialog does not run a search. Choose Get free quote, review the selected client and Maximum credits reserved, then explicitly choose Run with up to … credits to collect new connections. This uses the organization/client credit envelopes. Recent, unindexed or fully failed seeds release their unused reservation. Selecting or hovering over evidence never starts this paid operation. Client accounts and read-only readers cannot initiate enrichment from this view.
Use Infrastructure Pivot to interpret the levels shown on collected pivot connections. The free evidence graph shows presence in saved records; its lines do not carry those pivot assessments.
Assess a saved graph item
In an organization engagement's Overview, expand Saved graph items, then choose Graph decisions and comments beside an entity or relationship. You can also select a saved item in the graph and open the same dialog from its inspector. Save newly created items before opening their discussion.
The dialog shows the current assessment, validator and date where available. An owner, administrator or analyst with write access can choose a decision and select Save graph decision:
| Decision | Result |
|---|---|
| Validate this graph item | Records your assessment with your account and the time. It is not proof of common ownership. |
| Mark as hypothesis | Leaves the item as an unvalidated hypothesis. |
| Exclude from investigation | Requires a reason of 1–1,000 characters and removes any validation. The item remains listed with its reason; the saved graph hides it and affected connections. |
| Restore as hypothesis | Makes an excluded item available for assessment again, without restoring an earlier validation. |
Restore an excluded item before validating it or marking it as a hypothesis. Each decision creates an engagement revision. Changing an item's meaning clears its validation; moving a node's position alone does not. An imported or copied graph does not inherit another graph's validation or exclusions.
Client accounts and read-only readers can inspect accessible items but cannot make these decisions. Service integrations cannot validate items on behalf of a human. The server supplies the validator and date; an imported value cannot establish a validation.
These decisions apply to the saved engagement graph. They do not change the separate Evidence connections view or automatically promote its observations into the saved graph. To review those observations before adding them, use Compare graph versions.
Discuss a node or relationship
Use Notes on this graph item in the dialog to read or add context. The thread is attached to that saved node or relationship, separately from the engagement's Discussion and Notes streams. Staff can choose an allowed Personal, Team or Report audience and mention colleagues using the existing picker; client accounts use the shared audience. A mention notification opens the referenced graph thread.
A note is readable only when the reader can access the graph item, its supporting evidence and the note's audience. Counts include only readable comments. Removing the graph item makes its thread unavailable; a reused label does not transfer the old discussion to another item. This dialog does not invite external guests.
Keep drafts through conflicts
Close the dialog and save outstanding engagement edits before making a graph decision. While the dialog is open, ordinary engagement autosave is paused.
If another member saved first, your typed reason and note stay in the dialog. Review the newer revision, choose Use latest graph revision, inspect the current assessment, then choose your decision again and save explicitly. The UI does not overwrite the newer revision or retry the decision automatically.
If a decision's outcome is unknown, use Reload graph state before another attempt. If a note's outcome is unknown, use Reload thread and check whether it was added before posting again. Closing with an unsaved draft asks whether to keep editing or discard it; a failed request does not silently clear your text.
Compare saved graph revisions
In an organization engagement's Overview, choose Compare graph versions. This dialog is available to owners, administrators and analysts; staff with read-only access can consult comparisons without applying changes.
Choose Two saved revisions (read-only), enter From revision and To revision, then choose Load comparison. Opening the dialog does not load a comparison automatically. Neither loading a comparison nor applying a selection runs a search or spends research credits.
Inspect Before and After for each added, changed or removed item. They show the available value or relationship, assessment, visibility, validation details, position and supporting evidence reference. Use Find a change and the page controls for a large comparison. If a relationship's historical endpoint name is not available, the dialog says so instead of substituting its current name.
Historical comparisons are consultative: you cannot accept their operations or apply an older revision from this dialog. Historical reconciliation is not yet available.
Review proposals from team evidence
Choose Current graph and saved team evidence, then Load comparison. The proposals come from persisted internal or client-visible evidence that your current access and plan permit. Personal evidence is excluded, including your own personal records. No external source is queried.
A limited comparison displays a warning. Missing evidence or connections never causes an automatic removal from your saved graph. Proposals may add an item or update a generated item; they do not infer common ownership from a shared attribute. New items are internal to the team, even when their supporting evidence is client-visible.
For each proposal, choose:
| Choice | Effect when you apply the reviewed selection |
|---|---|
| Leave unchanged | Does not select this operation. |
| Accept operation | Applies the proposed addition or change. |
| Ignore in this comparison | Acknowledges this proposal without applying it. It can appear in a later comparison. |
Ignoring a proposal is not a lasting exclusion. Use Exclude from investigation for a durable assessment; restore that item explicitly before trying to accept a proposal for it. Reconciliation never silently restores an excluded item or overwrites manually changed content.
Some operations cannot be accepted. The dialog explains, for example, that an identity belongs to a removed item, that an item is shared with the client, or that a required source is no longer accessible. Unavailable previous content is not shown. A blocked proposal can still be ignored for this comparison.
Choose dependencies and apply once
A proposed relationship can list Required operations, such as a new endpoint. Select each required operation explicitly before accepting the relationship. Selecting a relationship does not select its endpoints for you.
Choose Preview selected operations, inspect the selection and its dependencies, then confirm that you reviewed them and choose Apply reviewed operations. You need current staff write access and a saved engagement with no pending edits. Ordinary engagement autosave pauses while this dialog is open.
The selection applies atomically as one new engagement revision: either the whole selection succeeds or none of it is applied. This also records a revision for a selection containing only ignored proposals. The final saved graph must fit its existing limits of 500 entities, 1,000 relationships and 256 KiB; the comparison can contain more proposals than you can accept together.
Accepted items record your validation and the time. This records your assessment, not proof of ownership. If an accepted change alters a node's meaning, existing incident relationships lose their validation unless you explicitly accept their proposed changes too. Moving a node alone does not invalidate its relationships.
What if the graph changes while you review?
The server checks the current graph revision, evidence, plan and permissions again when you apply. If the comparison is stale or a dependency becomes unavailable, your choices stay available and nothing is retried automatically. Choose Compare again, inspect the fresh proposals and select them deliberately. Previous choices kept for reference are a reminder, not a selection for the new comparison.
If the application outcome is not confirmed, compare again and inspect the saved state before another attempt. Do not assume that a failed network response means nothing was saved. Close the dialog and save outstanding engagement edits before applying a comparison; refreshing a comparison does not overwrite a dirty draft. Closing with choices asks whether to keep editing or discard them.
Share an observation
In an organization engagement's Evidence tab, choose More actions → Share evidence on a non-personal record. Confirm the evidence and annotation to share, wait for preparation, then copy a guest link or formatted text for Jira, Slack/Teams or an email draft. Discussion messages are excluded and nothing is sent automatically. See Share one evidence record for expiry, recovery and revocation.
Continue with an assistant
The engagement's Overview → Continue with Claude or Codex provides a dedicated read-only MCP setup. Its permission covers the whole selected client, including internal content; the current engagement is only a starting point. The preset has a zero credit limit and cannot search, edit or publish. See Continue an engagement with Claude or Codex for roles, one-time keys, configuration and the Claude Desktop limitation.