About cases
A case (also called an investigation) is the core workspace of the platform: the full record of an organized retail crime investigation, from creation through to close. A case pulls together the people involved, the activities worked, the evidence gathered, the financials, and a network picture, so an investigation lives in one place instead of scattered across documents.
In the app, this area is labeled Cases.
External and internal cases
Cases come in two shapes, and the shape decides which sections and fields appear.
- External cases are the standard ORC investigation: a crew, a fence, a booster network operating against your stores. They support AI document import and have sections for members, activities, evidence, financials, the network graph, and more.
- Internal cases cover pharmacy diversion and front-store loss. They use a dedicated, path-driven workspace with a journal, regulatory sections, and audience-based export packages. See Create an internal case.
You never choose "external" or "internal" directly: the shape is set by the label bound to the case when it is created, and it never changes afterward. See Labels and case visibility.
The case lifecycle
A case is Open or Closed: there is no third status and no pre-case status. (Earlier "Pending Review" and "On Hold" states have been removed.) Two actions move a case between the two:
- Close records the closed date and the final resolution, and adds a "Case Closed" entry to the activity timeline.
- Reopen clears the closed date and final resolution and adds a "Case Reopened" entry. It leaves the charges-filed date alone, that records a real-world fact, not a consequence of closing.
There is no whole-case delete, soft or hard. Individual records inside a case (members, activities, notes, evidence, case items) can each be deleted, and deletion is recoverable-by-design retention rather than true erasure. A case that should stop being worked is Closed, not removed.
How a case is created
Three ways, and only three, bring a case into existence:
- New Case: the manual form (for external cases) or guided intake (for internal cases).
- AI import: upload documents and review what the platform extracts. External cases only.
- Open as case: promote a cluster of connected incidents from the Intake page. See Cluster review.
The case workspace
A case opens on a detail page with a header, a row of KPI cards, and a set of sections reached through a section switcher (as many as fit sit on one line, the rest behind a More control; on a phone the whole set becomes a dropdown, with a "Jump to a section…" filter once a case has more than eight sections).
An external case has these sections: Overview, Involved Persons, Activities, Notes, Evidence, Case Items, Addresses, Vehicles, Contacts, Organizations, Financials, Incidents, Case Intelligence, Matches, BOLO, Network, and LENS.
An internal case has a different set: Overview, Journal, Regulatory (pharmacy path only), Involved Persons, Case Items, Evidence, Resolution, Activities, Contacts, Addresses, Vehicles, Organizations, Matches, and LENS.
Most sections carry a live count of the records they hold. Because the section sets differ, do not assume a section exists on both shapes.
The header shows the case's readable ID, name, case type, a category badge (External or Internal), a status badge (Open or Closed), and a severity badge (1 highest, 3 lowest). Its actions are Close/Reopen, Export, AI Import (external cases only), Edit, and, for internal cases, Export package. The Edit form no longer changes status; status moves only through Close and Reopen.
The KPI cards differ by shape. External cases show Case Value, Members, Activities, Evidence, and Case Items. Internal cases show Case Value, Involved Persons, Journal Entries, Evidence, and Case Age. Every count excludes deleted records.
Who can do what
| Role | Access |
|---|---|
| Supervisor | Full: view, add, edit, delete, and export any case data |
| Investigator | Add and view on cases they own or are assigned to |
| ORC Analyst, Auditor, Viewer, External Partner | Read-only |
| Regional / District Asset Protection Manager | No case access at all |
This sits on top of category visibility (the Chinese Wall): a role only grants what it grants on cases you can already see. See Roles and access.
The Cases area is available only if your organization is entitled to Cases. Without that entitlement, the Case Ops Board, the case dashboards, Report Builder, and management reporting are all unavailable too.