Investigation Management System (IMS)

Enterprise Investigation Platform — Case Management, Evidence Handling, Intelligence Analysis, Digital Forensics & AI-Powered Pattern Detection

✓ Production Ready Enterprise Grade 30+ Database Tables

Module Overview

Enterprise Investigation Platform

The Investigation Management System (IMS) is a comprehensive, enterprise-grade platform for managing the complete investigation lifecycle — from case intake through closure, with AI-powered intelligence, digital forensics tools, and built-in compliance controls. It supports fraud investigations, compliance reviews, HR cases, law enforcement operations, and any organizational investigative process.

IMS combines case management, evidence handling (with chain of custody), team collaboration, digital statement collection, geospatial analysis, CDR toll analysis, financial transaction tracking, OSINT integration, AI-driven intelligence, and professional report generation — all within a single, integrated system that monitors itself automatically every 60 seconds without requiring manual cron job setup.

Case Management

Full lifecycle from creation to archival with 10 status states and parent-child reinvestigation linking

Chain of Custody

Complete evidence audit trail with user, timestamp, and action logging for legal defensibility

AI Intelligence

Machine learning risk scoring, anomaly detection, cross-case pattern matching, and automated recommendations

Geospatial Analysis

Interactive maps with entity location plotting, heatmaps, and marker clustering

CDR Analysis

Call detail record import, frequency charts, contact network analysis

Financial Forensics

Transaction import, money flow visualization, auto-flagging for suspicious amounts

Digital Statements

Secure token-based portal for witnesses — time-boxed links, revocation, acceptance tracking

Automated Maintenance

Self-maintaining system monitors all modules every 60 seconds — no cron required

IMS Investigation Workflow

1. Case Intake
2. Team Assignment
3. Evidence + POI
4. Intel Collection
5. AI Analysis
6. Quality Review
7. Final Report

Key Features

Complete Investigation Toolkit

Case Creation

Cases with complaint/infraction types, priority (Low to Critical), source tracking, and location details. Auto-generated case numbers.

10-State Lifecycle

New → Open → Pending → Assigned → In Progress → Review → Completed → Reinvestigation → Closed → Archived. Parent-child linking for reopened cases.

Lead + Support Team

Lead investigator (primary), lead supervisor (secondary), and supporting team members — distinct roles with contribution tracking.

Evidence Upload

Secure file upload with type classification (document/image/audio/video), chain of custody logging, and document redaction tools.

Digital Statement Portal

Send secure time-limited links to witnesses. They submit via a public portal — no login needed. Revoke, resend, or track acceptance.

LE Intelligence Suite

Entity registry, link analysis graph, watchlist, cross-case scanning, network gap detection, and investigator dossier views.

AI & Machine Learning

Neural network priority prediction, isolation forest anomaly detection, KNN risk regression, and automated intelligence recommendations.

Report Generation

4 professional templates (Standard, Executive, Detailed, Professional) with PDF/Word export, AI enhancement, and versioning.

Case Lifecycle Management

Complete workflow from case creation through final closure.

Case Status Flow

StatusDescriptionNext Action
New Case created, awaiting assignment Assign investigator and supervisor
Assigned Team assigned, investigation starting Begin evidence collection
In Progress Active investigation underway Collect evidence, interview witnesses
Review Investigation complete, awaiting review Quality review and approval
Completed Report finalized and approved Case closure and archiving

Creating a Case

Navigate to IMS Dashboard

Go to IMS → Dashboard or click "New Investigation" button.

Fill Case Details

Enter case information:

  • Title: Brief case description
  • Description: Detailed case background
  • Complaint Type: Category of complaint
  • Infraction Type: Type of violation
  • Priority: Low/Medium/High/Urgent
  • Source: How case was received (email, manual, other)
  • Location: State, business unit, government area
Assign Team

Assign investigation team:

  • Primary Investigator: Lead investigator
  • Supervisor: Case supervisor
  • Support Team: Additional team members
Set Due Date

Set investigation due date for tracking and overdue alerts.

Create Case

Click "Create Case" to save. Case number is auto-generated (e.g., INV-2025-0001).

Evidence & Document Redaction

Secure evidence handling with chain of custody tracking and document redaction tools.

Evidence Types

TypeDescriptionExamples
DocumentText-based evidencePDFs, Word docs, emails, contracts
ImageVisual evidencePhotos, screenshots, scanned documents
AudioAudio recordingsInterview recordings, voicemails
VideoVideo recordingsSurveillance footage, interview videos
OtherOther evidence typesSpreadsheets, databases, etc.

Document Redaction

IMS includes built-in document redaction for images and evidence files. Investigators can draw rectangular redaction zones directly on images to obscure sensitive information before sharing or filing. Redaction actions are logged to the chain of custody for audit purposes.

Chain of Custody

All evidence uploads are logged with: who uploaded it, when, source information, and handling notes. Redaction operations are also tracked. This ensures evidence integrity for legal proceedings in compliance with ISO/IEC 27037.

Digital Statement Collection

Secure, time-limited portal for witness statement collection without requiring user accounts.

How It Works

Send Request

From the investigation page, click "Send Statement Request." Enter the recipient name and email, set an expiry period (3-30 days), and add a custom message. If no email is provided, share the link manually.

Recipient Visits Portal

The recipient clicks the unique 64-character cryptographic link. The portal shows the case reference, investigation subject, and your message. No login or account is required.

Statement Submission

The recipient writes their statement, confirms their full name, and accepts terms confirming the statement is true and voluntary. Their IP address and timestamp are recorded for verification.

Investigator Controls

Track status (sent/viewed/accepted/declined/expired), revoke links at any time, resend reminders, and view submitted statements from the investigation dashboard.

Automated Reminders

The system automatically sends email reminders to recipients who viewed the link but haven't submitted after 48 hours. Maximum 3 reminders are sent. Expired links are automatically deactivated.

Team Collaboration

Powerful collaboration tools for investigation teams.

Collaboration Features

Threaded Discussions

Start discussion threads with replies, internal/external flags, and pinning

Task Assignments

Create tasks with assignees, priorities, due dates, and time estimates

Time Tracking

Track estimated vs actual hours for tasks and overall investigation

Role-Based Access

Primary investigator, supervisor, and support team roles with permissions

Using Collaboration Dashboard

Access Collaboration Dashboard

From investigation view, click "Collaboration" button or navigate to Collaboration Dashboard from IMS menu.

Start Discussion

Click "New Discussion" to:

  • Write message
  • Mark as Internal (team only) or External (shareable)
  • Pin important discussions
  • Reply to existing threads
Create Task

Click "New Task" to:

  • Enter task title and description
  • Assign to team member
  • Set priority (Low/Medium/High/Urgent)
  • Set due date
  • Estimate hours
Track Progress

Monitor task status:

  • Update task status (Not Started/In Progress/Completed)
  • Log actual hours worked
  • View task statistics

LE Intelligence Suite

Law enforcement-grade intelligence analysis with entity registry, link analysis graphs, network gap detection, and investigator dossiers.

Entity Registry

A centralized database of persons, vehicles, phones, addresses, organizations, and assets. Each entity can have multiple identifiers (BVN, NIN, passport, phone, email, IMEI, plate number) and aliases. Entities link to all cases they appear in, enabling cross-case intelligence.

Link Analysis Graph

Interactive vis.js network visualization showing all connections between entities. Drag, zoom, and click nodes to see entity details. Edges are colored by relationship type and strength (weak/moderate/strong/confirmed).

Investigator Dossier

Each entity profile is a complete tabbed dossier combining:

  • Connections Tab: Relationship graph + known connections + Network Gap Detection (entities in the same cases with no direct link — these are potential missing persons or bridges)
  • Map Tab: Interactive Leaflet map with all entity locations plotted
  • CDR Tab: Call record summary linked to this entity
  • Financial Tab: Money flow summary for this entity
  • Statements Tab: All witness statements from this entity across cases
  • OSINT Tab: Live OSINT lookup + search history
  • Timeline Tab: Unified chronology of all entity activity

Intelligence Center

The Intel Center aggregates all cross-case alerts — identifier matches, alias matches, name similarity matches, and AI-generated risk predictions. Alerts follow an investigation workflow: New → Reviewed → Investigating → Resolved/Dismissed.

AI Intelligence Dashboard

The LE Dashboard includes a live AI Intelligence Analysis card showing: overall organizational risk score (0-100), ML-predicted risk adjustments for entities, relationship spike detection, temporal anomaly detection, and prioritized recommendations.

Geospatial Analysis

Interactive mapping with entity location tracking, heatmaps, and marker clustering.

Features

  • Entity Location Plotting: Add locations (home, work, last seen, crime scene, meeting point) with latitude/longitude, address, date, and notes
  • Interactive Leaflet Map: OpenStreetMap-based with zoom, pan, and marker clustering for large datasets
  • Heatmap Overlay: Toggle heatmap visualization showing density of entity activity
  • Per-Type Color Coding: Each entity type (person, vehicle, phone, address) has a distinct color marker
  • Entity Filtering: Filter map to show locations for a specific entity or all entities
  • Popups: Click any marker to see entity name, location type, address, and date

CDR Toll Analysis

Call detail record import and analysis for phone intelligence.

Features

  • CSV Import: Upload call records with columns: caller_number, receiver_number, call_type (incoming/outgoing/missed/sms), call_date, duration_seconds
  • Call Distribution Chart: Bar chart showing call frequency by hour of day
  • Top Contacts: Most frequently contacted numbers with total call count and duration
  • Statistics Dashboard: Total records, outgoing/incoming/SMS breakdown, total duration, average call length

Financial Intelligence

Transaction import and money flow analysis for forensic accounting.

Features

  • CSV Import: Upload transactions with columns: transaction_type, amount, from_account, to_account, from_entity_name, to_entity_name, transaction_date, description
  • Monthly Flow Chart: Stacked bar chart showing inflow vs outflow by month
  • Money Flow Paths: Visual Sankey-style display of top money movement paths with proportional bars
  • Auto-Flagging: Transactions above ₦5,000,000 (configurable) are automatically flagged for review
  • Summary Cards: Total inflow, total outflow, transaction count, and flagged count

OSINT Integration

Open-source intelligence tools integrated directly into the investigation workflow.

Available Lookups

Lookup TypeWhat It Checks
PhoneNumber format validation, country code detection, carrier identification (MTN, Glo, Airtel, 9mobile), line type
EmailFormat validation, domain extraction, free email detection, MX record check
DomainWHOIS availability, IP resolution, DNS record check
SocialChecks username existence on Twitter, Instagram, GitHub, LinkedIn (HTTP status check)

All OSINT results are cached in the database and linked to the entity. Search history is preserved for audit and future reference.

AI & Machine Learning

Neural networks, anomaly detection, and risk prediction powered by Rubix ML.

ML Models

ModelAlgorithmPurpose
Investigation ClassifierNeural Network (MLP with TF-IDF)Predicts investigation priority (Low/Medium/High) based on case description text
Risk RegressorK-Nearest Neighbors (KNN)Predicts entity risk scores based on case count and relationship density
Anomaly DetectorIsolation ForestDetects unusual entity behavior patterns in relationship networks

AI Intelligence Analysis

  • Cross-Case Entity Risk Scoring: Composite score based on case count × 10 + relationship count × 5 + watchlist status × 20
  • Case Network Density: Scores each case by internal links and external case connections
  • Temporal Anomaly Detection: Identifies spikes in entity additions using standard deviation analysis
  • Relationship Spike Detection: Flags cases where entity linking activity exceeds historical average + 2σ in a 7-day window
  • Automated Recommendations: Priority-ranked intelligence recommendations with actionable detail
Privacy

All ML predictions run locally on the StrataGRC server. Models are trained on anonymized, standardized datasets — organizational data is never used to train models for other customers.

Automated Maintenance

The system monitors and maintains itself automatically — no manual cron job configuration required.

Automatic Operations (every 60 seconds)

JobFrequencyWhat It Does
Email Inbox PollingEvery 30 minutesChecks configured email inboxes for new evidence submissions
Cross-Case Intel ScanEvery 30 minutesScans for duplicate identifiers across cases and generates intelligence alerts
Overdue Status UpdateEvery 60 minutesAutomatically marks cases past their due date as "Pending"
Workflow Rule EscalationEvery 60 minutesApplies auto-escalation rules (e.g., escalate to supervisor if overdue > 3 days)
Statement RemindersEvery 6 hoursSends reminders for viewed-but-unsubmitted statement requests; auto-expires past-due links
Watchlist Risk AdjustmentsEvery 30 minutesAuto-escalates watchlist risk levels when entity relationships grow
AI Intelligence ScanEvery 30 minutesRuns ML models across entity data, generates risk predictions and anomaly alerts

Quality Reviews

Professional quality assurance for investigations.

Quality Review Process

Request Review

When investigation is complete, request quality review from Quality Management section.

Reviewer Assignment

Quality manager assigns reviewer (not involved in investigation).

Review Against Criteria

Reviewer evaluates investigation against quality criteria:

  • Evidence completeness
  • Interview documentation
  • Legal compliance
  • Report quality
  • Timeline adherence
Scoring

Reviewer assigns scores (0-100%) for each criterion.

Approval Decision

Reviewer decides:

  • Approve: Investigation meets standards
  • Request Changes: Revisions needed
  • Reject: Major issues, re-investigation required

Review Templates

Template TypeUse CaseCriteria
Standard Review Regular investigations Basic quality criteria
Enhanced Review High-priority cases Comprehensive criteria with legal review
Expedited Review Urgent cases Essential criteria only

Report Generation

Professional investigation reports with customizable templates.

Report Types

PDF Reports

Professional PDF format with company branding and digital signatures

Word Reports

Editable Word documents for further customization

Executive Summaries

High-level summaries for management presentation

Generating Reports

Access Report Generator

From investigation view, click "Generate Report" button.

Select Template

Choose from available report templates:

  • Standard Investigation Report
  • Executive Summary
  • Legal Brief
  • Custom Template
Customize Formatting

Configure:

  • Company logo
  • Color scheme
  • Font family
  • Section inclusion
Review Content

Report auto-populates with:

  • Case details
  • Evidence list
  • Team members
  • Timeline
  • Findings
  • Recommendations
Export

Choose export format:

  • PDF (final, non-editable)
  • Word (editable)
  • Save as Draft (for later)

Case Intelligence

Advanced analytics and pattern detection for investigations.

Intelligence Features

Case Relationships

Link related cases manually or through duplicate detection

Duplicate Detection

AI-powered similarity scoring to identify potential duplicate cases

Pattern Analysis

Identify trends by time, type, location, and other dimensions

Case Clustering

Group related cases into clusters for coordinated investigation

Using Duplicate Detection

Open Case

Navigate to the investigation case.

Run Duplicate Detection

Click "Detect Duplicates" button. System analyzes:

  • Title similarity (30% weight)
  • Description similarity (25% weight)
  • Complaint type match (20% weight)
  • Infraction type match (15% weight)
  • Priority match (10% weight)
Review Results

System shows potential duplicates with:

  • Similarity percentage
  • Match details
  • Case status
  • Assigned investigator
Link Cases

If confirmed duplicate, click "Link" to create relationship.

Pattern Analysis

Use pattern analysis to identify:
• Time-based spikes (e.g., more cases in certain months)
• Type trends (e.g., increasing harassment complaints)
• Location hotspots (e.g., specific departments with more cases)
• Investigator workload distribution

Database Structure

30+ tables supporting comprehensive investigation management, intelligence, and digital forensics.

Core Investigation Tables

TablePurposeKey Fields
ims_investigationsMain case recordscase_number, title, status (10 states), priority (5 levels), parent_investigation_id, complaint_type, infraction_type
ims_investigation_teamTeam assignmentsinvestigation_id, user_id, role (primary/secondary/support)
ims_evidenceEvidence recordsfile_name, file_path, evidence_type, chain_of_custody
ims_working_papersInvestigator notestitle, content, paper_type (notes/findings/analysis)
ims_reportsFinal reportstitle, content, template, version, ai_enhanced
ims_activity_logAudit trailactivity_type, activity_description, user_id, investigation_id
ims_recommendationsCase recommendationsrecommendation_text, complaint_type, infraction_type
ims_poiPersons of interestfirst_name, last_name, email, phone, identifier
ims_witness_statementsWitness statementswitness_name, statement_text, statement_type (in_person/digital/uploaded), file_path
ims_statement_requestsDigital statement collectionaccess_token, recipient_email, status, expires_at, accepted_terms, accepted_ip

Collaboration Tables

TablePurposeKey Fields
ims_discussionsThreaded discussionsmessage, parent_id, is_internal, is_pinned
ims_tasksTask managementtitle, description, assigned_to, priority, status, due_date, estimated_hours, actual_hours

Law Enforcement Intelligence Tables

TablePurposeKey Fields
le_entitiesEntity registry (persons, vehicles, phones, addresses, orgs)entity_type, display_name, alias, risk_score, risk_level
le_entity_identifiersEntity identifiers (BVN, NIN, phone, email, plate)identifier_type, identifier_value
le_entity_casesEntity-investigation linksentity_id, investigation_id, role_type (suspect/victim/witness/poi)
le_relationshipsEntity-to-entity relationshipssource_entity_id, target_entity_id, relationship_type, strength
le_intel_alertsIntelligence alertsalert_type, title, severity, status, confidence_score
le_watchlistWatched entitiesentity_id, risk_level, reason, status
le_entity_locationsGeospatial locationsentity_id, latitude, longitude, location_type, address
le_phone_recordsCDR toll datacaller_number, receiver_number, call_type, call_date, duration_seconds
le_financial_recordsTransaction datatransaction_type, amount, from_account, to_account, flagged
le_osint_resultsOSINT lookup cachesource_type, query_value, result_data

Best Practices & Compliance

Guidelines for effective investigation management and regulatory compliance.

Compliance Standards Supported

ISO/IEC 27037

Guidelines for identification, collection, acquisition, and preservation of digital evidence

ACFE Standards

Association of Certified Fraud Examiners investigation standards

IIA Standards

Institute of Internal Auditors professional practices framework

CJIS Compliance

Criminal Justice Information Services security requirements for law enforcement data