One example, five steps
The video above follows a suspicious sample email using fictional data. Pause it, view full screen or jump to a chapter. Audio and subtitles are in Russian.
- Ask a question: create a case and define the question and success criterion.
- Collect data: attach the email and documents; review source availability and cost before a search.
- Examine evidence: documents, files, scans, fragments, graph and timeline remain in the case. Compare OCR text with the scan and check the source of every relationship.
- Prepare a conclusion: record supported claims, limitations and recommendations; accept the answer after review.
- Get a report: check conclusions and recommendations, save a version and download PDF. Later edits do not change the saved version.
Find your materials
All materials opens the case collection. Graph, Files and scans, Timeline and Relationships are views of the same work. Research archive keeps runs and stops. Features depend on organisation permissions and configuration. Paid external searches and cloud models were not run in the demonstration; sample file extraction was local.
Other workflows and help
Chapters cover verification, AI modes, budgets and recovery, monitoring, resources, disclosure requests, blocklists, Feed API, TAXII and organisation management. See «getting started», «blocked actions» and «research archive». The How to use button in the workspace opens this guide in a new tab, keeping the case open.