Case study · investigations

One system instead of folders, email and hope

39 cases run through the system 288 evidence items, hashed and archived 2 sources required before anything becomes a finding

The situation

A private investigations firm, led by a former big-tech global investigations lead, ran on manual open-source research: a stack of separate paid tools, hand-run searches, hand-built reports. The owner's own words about the tools he was evaluating: "Everything's a big word. You're not getting everything... what is it checking?" And nothing in the toolchain enforced the discipline that separates a finding from a guess.

What we did

We built an investigation operating system the investigator directs in plain English, like writing an email to an intern investigator. Under the hood: seven search engines queried in parallel, over 55 social-platform collectors, and domain, archive, and threat-intelligence lookups, all feeding one case file.

The collection is not the point. The discipline is:

The number

39 numbered cases have run through the system. 288 chain-of-custody evidence items captured, each hashed and archived at collection time. 16 invoices shipped, themselves generated by a script from the same case records. The firm liked the case work enough to buy the system itself: a fixed-price deployment into their own environment is now underway.

Anonymized: the client has not yet approved being named. Every number is from the engagement record.

An investigator's tools should argue with them. If your team's work product depends on judgment nothing checks, the same discipline can be built into your process in a week. $1,000 fixed.

Start with one thing: $1,000, one week

How the week works

More work: the analyst that refuses to guess · the pipeline that failed 95 times silently · the research desk that runs itself