Module Overview
Enterprise Investigation Platform
The Investigation Management System (IMS) is a comprehensive, enterprise-grade platform for managing the complete investigation lifecycle — from case intake through closure, with AI-powered intelligence, digital forensics tools, and built-in compliance controls. It supports fraud investigations, compliance reviews, HR cases, law enforcement operations, and any organizational investigative process.
IMS combines case management, evidence handling (with chain of custody), team collaboration, digital statement collection, geospatial analysis, CDR toll analysis, financial transaction tracking, OSINT integration, AI-driven intelligence, and professional report generation — all within a single, integrated system that monitors itself automatically every 60 seconds without requiring manual cron job setup.
Case Management
Full lifecycle from creation to archival with 10 status states and parent-child reinvestigation linking
Chain of Custody
Complete evidence audit trail with user, timestamp, and action logging for legal defensibility
AI Intelligence
Machine learning risk scoring, anomaly detection, cross-case pattern matching, and automated recommendations
Geospatial Analysis
Interactive maps with entity location plotting, heatmaps, and marker clustering
CDR Analysis
Call detail record import, frequency charts, contact network analysis
Financial Forensics
Transaction import, money flow visualization, auto-flagging for suspicious amounts
Digital Statements
Secure token-based portal for witnesses — time-boxed links, revocation, acceptance tracking
Automated Maintenance
Self-maintaining system monitors all modules every 60 seconds — no cron required
IMS Investigation Workflow
Key Features
Complete Investigation Toolkit
Case Creation
Cases with complaint/infraction types, priority (Low to Critical), source tracking, and location details. Auto-generated case numbers.
10-State Lifecycle
New → Open → Pending → Assigned → In Progress → Review → Completed → Reinvestigation → Closed → Archived. Parent-child linking for reopened cases.
Lead + Support Team
Lead investigator (primary), lead supervisor (secondary), and supporting team members — distinct roles with contribution tracking.
Evidence Upload
Secure file upload with type classification (document/image/audio/video), chain of custody logging, and document redaction tools.
Digital Statement Portal
Send secure time-limited links to witnesses. They submit via a public portal — no login needed. Revoke, resend, or track acceptance.
LE Intelligence Suite
Entity registry, link analysis graph, watchlist, cross-case scanning, network gap detection, and investigator dossier views.
AI & Machine Learning
Neural network priority prediction, isolation forest anomaly detection, KNN risk regression, and automated intelligence recommendations.
Report Generation
4 professional templates (Standard, Executive, Detailed, Professional) with PDF/Word export, AI enhancement, and versioning.
Case Lifecycle Management
Complete workflow from case creation through final closure.
Case Status Flow
| Status | Description | Next Action |
|---|---|---|
| New | Case created, awaiting assignment | Assign investigator and supervisor |
| Assigned | Team assigned, investigation starting | Begin evidence collection |
| In Progress | Active investigation underway | Collect evidence, interview witnesses |
| Review | Investigation complete, awaiting review | Quality review and approval |
| Completed | Report finalized and approved | Case closure and archiving |
Creating a Case
Navigate to IMS Dashboard
Go to IMS → Dashboard or click "New Investigation" button.
Fill Case Details
Enter case information:
- Title: Brief case description
- Description: Detailed case background
- Complaint Type: Category of complaint
- Infraction Type: Type of violation
- Priority: Low/Medium/High/Urgent
- Source: How case was received (email, manual, other)
- Location: State, business unit, government area
Assign Team
Assign investigation team:
- Primary Investigator: Lead investigator
- Supervisor: Case supervisor
- Support Team: Additional team members
Set Due Date
Set investigation due date for tracking and overdue alerts.
Create Case
Click "Create Case" to save. Case number is auto-generated (e.g., INV-2025-0001).
Evidence & Document Redaction
Secure evidence handling with chain of custody tracking and document redaction tools.
Evidence Types
| Type | Description | Examples |
|---|---|---|
| Document | Text-based evidence | PDFs, Word docs, emails, contracts |
| Image | Visual evidence | Photos, screenshots, scanned documents |
| Audio | Audio recordings | Interview recordings, voicemails |
| Video | Video recordings | Surveillance footage, interview videos |
| Other | Other evidence types | Spreadsheets, databases, etc. |
Document Redaction
IMS includes built-in document redaction for images and evidence files. Investigators can draw rectangular redaction zones directly on images to obscure sensitive information before sharing or filing. Redaction actions are logged to the chain of custody for audit purposes.
Chain of Custody
All evidence uploads are logged with: who uploaded it, when, source information, and handling notes. Redaction operations are also tracked. This ensures evidence integrity for legal proceedings in compliance with ISO/IEC 27037.
Digital Statement Collection
Secure, time-limited portal for witness statement collection without requiring user accounts.
How It Works
Send Request
From the investigation page, click "Send Statement Request." Enter the recipient name and email, set an expiry period (3-30 days), and add a custom message. If no email is provided, share the link manually.
Recipient Visits Portal
The recipient clicks the unique 64-character cryptographic link. The portal shows the case reference, investigation subject, and your message. No login or account is required.
Statement Submission
The recipient writes their statement, confirms their full name, and accepts terms confirming the statement is true and voluntary. Their IP address and timestamp are recorded for verification.
Investigator Controls
Track status (sent/viewed/accepted/declined/expired), revoke links at any time, resend reminders, and view submitted statements from the investigation dashboard.
Automated Reminders
The system automatically sends email reminders to recipients who viewed the link but haven't submitted after 48 hours. Maximum 3 reminders are sent. Expired links are automatically deactivated.
Team Collaboration
Powerful collaboration tools for investigation teams.
Collaboration Features
Threaded Discussions
Start discussion threads with replies, internal/external flags, and pinning
Task Assignments
Create tasks with assignees, priorities, due dates, and time estimates
Time Tracking
Track estimated vs actual hours for tasks and overall investigation
Role-Based Access
Primary investigator, supervisor, and support team roles with permissions
Using Collaboration Dashboard
Access Collaboration Dashboard
From investigation view, click "Collaboration" button or navigate to Collaboration Dashboard from IMS menu.
Start Discussion
Click "New Discussion" to:
- Write message
- Mark as Internal (team only) or External (shareable)
- Pin important discussions
- Reply to existing threads
Create Task
Click "New Task" to:
- Enter task title and description
- Assign to team member
- Set priority (Low/Medium/High/Urgent)
- Set due date
- Estimate hours
Track Progress
Monitor task status:
- Update task status (Not Started/In Progress/Completed)
- Log actual hours worked
- View task statistics
LE Intelligence Suite
Law enforcement-grade intelligence analysis with entity registry, link analysis graphs, network gap detection, and investigator dossiers.
Entity Registry
A centralized database of persons, vehicles, phones, addresses, organizations, and assets. Each entity can have multiple identifiers (BVN, NIN, passport, phone, email, IMEI, plate number) and aliases. Entities link to all cases they appear in, enabling cross-case intelligence.
Link Analysis Graph
Interactive vis.js network visualization showing all connections between entities. Drag, zoom, and click nodes to see entity details. Edges are colored by relationship type and strength (weak/moderate/strong/confirmed).
Investigator Dossier
Each entity profile is a complete tabbed dossier combining:
- Connections Tab: Relationship graph + known connections + Network Gap Detection (entities in the same cases with no direct link — these are potential missing persons or bridges)
- Map Tab: Interactive Leaflet map with all entity locations plotted
- CDR Tab: Call record summary linked to this entity
- Financial Tab: Money flow summary for this entity
- Statements Tab: All witness statements from this entity across cases
- OSINT Tab: Live OSINT lookup + search history
- Timeline Tab: Unified chronology of all entity activity
Intelligence Center
The Intel Center aggregates all cross-case alerts — identifier matches, alias matches, name similarity matches, and AI-generated risk predictions. Alerts follow an investigation workflow: New → Reviewed → Investigating → Resolved/Dismissed.
AI Intelligence Dashboard
The LE Dashboard includes a live AI Intelligence Analysis card showing: overall organizational risk score (0-100), ML-predicted risk adjustments for entities, relationship spike detection, temporal anomaly detection, and prioritized recommendations.
Geospatial Analysis
Interactive mapping with entity location tracking, heatmaps, and marker clustering.
Features
- Entity Location Plotting: Add locations (home, work, last seen, crime scene, meeting point) with latitude/longitude, address, date, and notes
- Interactive Leaflet Map: OpenStreetMap-based with zoom, pan, and marker clustering for large datasets
- Heatmap Overlay: Toggle heatmap visualization showing density of entity activity
- Per-Type Color Coding: Each entity type (person, vehicle, phone, address) has a distinct color marker
- Entity Filtering: Filter map to show locations for a specific entity or all entities
- Popups: Click any marker to see entity name, location type, address, and date
CDR Toll Analysis
Call detail record import and analysis for phone intelligence.
Features
- CSV Import: Upload call records with columns: caller_number, receiver_number, call_type (incoming/outgoing/missed/sms), call_date, duration_seconds
- Call Distribution Chart: Bar chart showing call frequency by hour of day
- Top Contacts: Most frequently contacted numbers with total call count and duration
- Statistics Dashboard: Total records, outgoing/incoming/SMS breakdown, total duration, average call length
Financial Intelligence
Transaction import and money flow analysis for forensic accounting.
Features
- CSV Import: Upload transactions with columns: transaction_type, amount, from_account, to_account, from_entity_name, to_entity_name, transaction_date, description
- Monthly Flow Chart: Stacked bar chart showing inflow vs outflow by month
- Money Flow Paths: Visual Sankey-style display of top money movement paths with proportional bars
- Auto-Flagging: Transactions above ₦5,000,000 (configurable) are automatically flagged for review
- Summary Cards: Total inflow, total outflow, transaction count, and flagged count
OSINT Integration
Open-source intelligence tools integrated directly into the investigation workflow.
Available Lookups
| Lookup Type | What It Checks |
|---|---|
| Phone | Number format validation, country code detection, carrier identification (MTN, Glo, Airtel, 9mobile), line type |
| Format validation, domain extraction, free email detection, MX record check | |
| Domain | WHOIS availability, IP resolution, DNS record check |
| Social | Checks username existence on Twitter, Instagram, GitHub, LinkedIn (HTTP status check) |
All OSINT results are cached in the database and linked to the entity. Search history is preserved for audit and future reference.
AI & Machine Learning
Neural networks, anomaly detection, and risk prediction powered by Rubix ML.
ML Models
| Model | Algorithm | Purpose |
|---|---|---|
| Investigation Classifier | Neural Network (MLP with TF-IDF) | Predicts investigation priority (Low/Medium/High) based on case description text |
| Risk Regressor | K-Nearest Neighbors (KNN) | Predicts entity risk scores based on case count and relationship density |
| Anomaly Detector | Isolation Forest | Detects unusual entity behavior patterns in relationship networks |
AI Intelligence Analysis
- Cross-Case Entity Risk Scoring: Composite score based on case count × 10 + relationship count × 5 + watchlist status × 20
- Case Network Density: Scores each case by internal links and external case connections
- Temporal Anomaly Detection: Identifies spikes in entity additions using standard deviation analysis
- Relationship Spike Detection: Flags cases where entity linking activity exceeds historical average + 2σ in a 7-day window
- Automated Recommendations: Priority-ranked intelligence recommendations with actionable detail
Privacy
All ML predictions run locally on the StrataGRC server. Models are trained on anonymized, standardized datasets — organizational data is never used to train models for other customers.
Automated Maintenance
The system monitors and maintains itself automatically — no manual cron job configuration required.
Automatic Operations (every 60 seconds)
| Job | Frequency | What It Does |
|---|---|---|
| Email Inbox Polling | Every 30 minutes | Checks configured email inboxes for new evidence submissions |
| Cross-Case Intel Scan | Every 30 minutes | Scans for duplicate identifiers across cases and generates intelligence alerts |
| Overdue Status Update | Every 60 minutes | Automatically marks cases past their due date as "Pending" |
| Workflow Rule Escalation | Every 60 minutes | Applies auto-escalation rules (e.g., escalate to supervisor if overdue > 3 days) |
| Statement Reminders | Every 6 hours | Sends reminders for viewed-but-unsubmitted statement requests; auto-expires past-due links |
| Watchlist Risk Adjustments | Every 30 minutes | Auto-escalates watchlist risk levels when entity relationships grow |
| AI Intelligence Scan | Every 30 minutes | Runs ML models across entity data, generates risk predictions and anomaly alerts |
Quality Reviews
Professional quality assurance for investigations.
Quality Review Process
Request Review
When investigation is complete, request quality review from Quality Management section.
Reviewer Assignment
Quality manager assigns reviewer (not involved in investigation).
Review Against Criteria
Reviewer evaluates investigation against quality criteria:
- Evidence completeness
- Interview documentation
- Legal compliance
- Report quality
- Timeline adherence
Scoring
Reviewer assigns scores (0-100%) for each criterion.
Approval Decision
Reviewer decides:
- Approve: Investigation meets standards
- Request Changes: Revisions needed
- Reject: Major issues, re-investigation required
Review Templates
| Template Type | Use Case | Criteria |
|---|---|---|
| Standard Review | Regular investigations | Basic quality criteria |
| Enhanced Review | High-priority cases | Comprehensive criteria with legal review |
| Expedited Review | Urgent cases | Essential criteria only |
Report Generation
Professional investigation reports with customizable templates.
Report Types
PDF Reports
Professional PDF format with company branding and digital signatures
Word Reports
Editable Word documents for further customization
Executive Summaries
High-level summaries for management presentation
Generating Reports
Access Report Generator
From investigation view, click "Generate Report" button.
Select Template
Choose from available report templates:
- Standard Investigation Report
- Executive Summary
- Legal Brief
- Custom Template
Customize Formatting
Configure:
- Company logo
- Color scheme
- Font family
- Section inclusion
Review Content
Report auto-populates with:
- Case details
- Evidence list
- Team members
- Timeline
- Findings
- Recommendations
Export
Choose export format:
- PDF (final, non-editable)
- Word (editable)
- Save as Draft (for later)
Case Intelligence
Advanced analytics and pattern detection for investigations.
Intelligence Features
Case Relationships
Link related cases manually or through duplicate detection
Duplicate Detection
AI-powered similarity scoring to identify potential duplicate cases
Pattern Analysis
Identify trends by time, type, location, and other dimensions
Case Clustering
Group related cases into clusters for coordinated investigation
Using Duplicate Detection
Open Case
Navigate to the investigation case.
Run Duplicate Detection
Click "Detect Duplicates" button. System analyzes:
- Title similarity (30% weight)
- Description similarity (25% weight)
- Complaint type match (20% weight)
- Infraction type match (15% weight)
- Priority match (10% weight)
Review Results
System shows potential duplicates with:
- Similarity percentage
- Match details
- Case status
- Assigned investigator
Link Cases
If confirmed duplicate, click "Link" to create relationship.
Pattern Analysis
Use pattern analysis to identify:
• Time-based spikes (e.g., more cases in certain months)
• Type trends (e.g., increasing harassment complaints)
• Location hotspots (e.g., specific departments with more cases)
• Investigator workload distribution
Database Structure
30+ tables supporting comprehensive investigation management, intelligence, and digital forensics.
Core Investigation Tables
| Table | Purpose | Key Fields |
|---|---|---|
| ims_investigations | Main case records | case_number, title, status (10 states), priority (5 levels), parent_investigation_id, complaint_type, infraction_type |
| ims_investigation_team | Team assignments | investigation_id, user_id, role (primary/secondary/support) |
| ims_evidence | Evidence records | file_name, file_path, evidence_type, chain_of_custody |
| ims_working_papers | Investigator notes | title, content, paper_type (notes/findings/analysis) |
| ims_reports | Final reports | title, content, template, version, ai_enhanced |
| ims_activity_log | Audit trail | activity_type, activity_description, user_id, investigation_id |
| ims_recommendations | Case recommendations | recommendation_text, complaint_type, infraction_type |
| ims_poi | Persons of interest | first_name, last_name, email, phone, identifier |
| ims_witness_statements | Witness statements | witness_name, statement_text, statement_type (in_person/digital/uploaded), file_path |
| ims_statement_requests | Digital statement collection | access_token, recipient_email, status, expires_at, accepted_terms, accepted_ip |
Collaboration Tables
| Table | Purpose | Key Fields |
|---|---|---|
| ims_discussions | Threaded discussions | message, parent_id, is_internal, is_pinned |
| ims_tasks | Task management | title, description, assigned_to, priority, status, due_date, estimated_hours, actual_hours |
Law Enforcement Intelligence Tables
| Table | Purpose | Key Fields |
|---|---|---|
| le_entities | Entity registry (persons, vehicles, phones, addresses, orgs) | entity_type, display_name, alias, risk_score, risk_level |
| le_entity_identifiers | Entity identifiers (BVN, NIN, phone, email, plate) | identifier_type, identifier_value |
| le_entity_cases | Entity-investigation links | entity_id, investigation_id, role_type (suspect/victim/witness/poi) |
| le_relationships | Entity-to-entity relationships | source_entity_id, target_entity_id, relationship_type, strength |
| le_intel_alerts | Intelligence alerts | alert_type, title, severity, status, confidence_score |
| le_watchlist | Watched entities | entity_id, risk_level, reason, status |
| le_entity_locations | Geospatial locations | entity_id, latitude, longitude, location_type, address |
| le_phone_records | CDR toll data | caller_number, receiver_number, call_type, call_date, duration_seconds |
| le_financial_records | Transaction data | transaction_type, amount, from_account, to_account, flagged |
| le_osint_results | OSINT lookup cache | source_type, query_value, result_data |
Best Practices & Compliance
Guidelines for effective investigation management and regulatory compliance.
Compliance Standards Supported
ISO/IEC 27037
Guidelines for identification, collection, acquisition, and preservation of digital evidence
ACFE Standards
Association of Certified Fraud Examiners investigation standards
IIA Standards
Institute of Internal Auditors professional practices framework
CJIS Compliance
Criminal Justice Information Services security requirements for law enforcement data