Case Lifecycle Overview

  • Updated

The Case Lifecycle represents the complete journey of an investigation in OWL, from the moment a case is created until it is closed, archived, and eventually deleted according to organizational retention policies.

A case acts as the central workspace where investigators collect evidence, manage subjects, collaborate with team members, document investigative activities, and maintain a complete audit trail. Throughout its lifecycle, the case evolves as new information is added, investigative actions are performed, and the investigation progresses toward completion.

The lifecycle helps investigators follow a structured investigative process while ensuring data integrity, compliance, collaboration, and accountability.

Case Lifecycle Flow

The lifecycle of a case typically progresses through the following stages:

  1. Case Creation
  2. Active Investigation
  3. Case Status Progression
  4. Investigation Completion
  5. Case Closure
  6. Archive and Retention
  7. Case Deletion

Organizations may configure additional statuses or workflow stages to align with their internal processes.

 

Case Lifecycle Stages

1. Case Creation

The lifecycle begins when an investigator creates a new case in the Case Management module.

During case creation, users provide the primary information required to initiate the investigation, including case details, ownership, governance settings, access permissions, attachments, and intake notes.

Typical information captured includes:

  • Case Number
  • Case Name
  • Case Owner
  • Department
  • Case Status
  • Classification
  • Governance and Retention settings
  • Access Rights
  • Legal Hold
  • Supporting Attachments
  • Intake Notes

Once the case is saved, it becomes available in the Case Dossier, which serves as the central workspace for managing the investigation.

2. Active Investigation

After a case has been created, investigators begin the investigation from the Case Dossier.

The Case Dossier provides a centralized location where investigators can organize evidence, manage investigative activities, collaborate with other users, and monitor the progress of the investigation.

During this phase, investigators continuously update the case as new information becomes available.

The following activities are commonly performed during an active investigation.

  • Case Template

    Investigators can apply a Case Template from the Template Library to standardize the structure of the investigation. Templates help populate predefined sections, ensuring consistency across investigations and reducing manual configuration.

  • Subjects

    Investigators can add and manage subjects associated with the case.

    Subjects may include:

  1. Suspects
  2. Victims
  3. Witnesses
  4. Persons of Interest
  5. Organizations
  6. Vehicles
  7. Locations

    Subject information can be updated throughout the investigation as additional intelligence becomes available.

  • Associated Cases

    Related Cases can be associated when they involve common individuals, organizations, vehicles, locations, or criminal activities.

    Associated Cases help investigators:

  1. Identify connected investigations
  2. Share intelligence
  3. Reduce duplicate investigations
  4. Discover larger criminal patterns
  • Tasks

    Investigators can create and assign investigative tasks to field officers, analysts, or other team members.

    Tasks may include:

  1. Evidence collection
  2. Witness interviews
  3. Surveillance activities
  4. Background verification
  5. Site inspections
  6. Digital forensic analysis

 

Completed tasks contribute to the overall investigation and help ensure all required activities have been performed before the case is closed.

  • Documents

    Additional documents can be uploaded throughout the investigation whenever new information becomes available or if supporting documentation was not included during case creation.

    Examples include:

  1. Investigation reports
  2. Court orders
  3. Search warrants
  4. Forensic reports
  5. Financial records
  6. Witness statements
  7. Crime scene photographs
  8. CCTV footage

Investigators can also perform document intelligence operations from OWLDocs page such as:

  • OWLidentify for image analysis
  • OWLxtract for text extraction from documents
  • Translation for multilingual evidence
  • Tips and Leads

    Investigators can record and manage tips received from various sources.

    Examples include:

  1. Confidential informants
  2. Public tips
  3. Partner agencies
  4. Internal intelligence
  5. Anonymous sources

    Reliable tips can be linked directly to the case and incorporated into the investigation.

  • Forms

    Forms provide standardized templates for collecting investigative information.

    Examples include:

  1. Witness Interview Forms
  2. Incident Reports
  3. Property Seizure Forms
  4. Crime Scene Documentation
  5. Intelligence Collection Forms
  6. Standardized forms improve consistency and reporting accuracy.

  • Reports

    Investigators can prepare reports to document investigative findings and recommendations.

    Examples include:

  1. Investigation Progress Reports
  2. Intelligence Reports
  3. Field Investigation Reports
  4. Forensic Reports
  5. Investigation Summaries

Reports support supervisors and investigators throughout the investigation.

  • Deconfliction

    Deconfliction automatically compares investigation records against existing organizational data to identify potential overlaps.

    It compares:

  1. Cases
  2. Subjects
  3. Documents
  4. Forms
  5. Reports
  6. Searches

This helps prevent duplicate investigations and identifies related records.

  • Case-Level Connectors

    Investigators can search integrated internal and external data sources directly from the case.

    Searches may include:

  1. Suspect names
  2. Phone numbers
  3. Email addresses
  4. Vehicle registrations
  5. Addresses
  6. Social media identifiers

Search results can be used to enrich the investigation.

  • Monitoring

    Monitoring allows investigators to schedule recurring searches.

    The system automatically performs searches at configured intervals and alerts investigators whenever new information becomes available.

  • Collaboration

    Investigators can collaborate with users, departments, or external agencies.

    The Collaboration section displays:

  1. Shared users
  2. Departments
  3. External organizations
  4. Collaboration history
  5. This enables secure information sharing while maintaining access controls.

  • Query Logs

    Query Logs maintain a history of all searches performed within the case.

    Each log includes:

  1. Search criteria
  2. Date and time
  3. User
  4. Connector
  5. Search results

Investigators can also create Monitoring jobs directly from Query Logs.

  • Case Compliance

    Compliance settings allow investigators to manage regulatory requirements associated with the investigation.

    Examples include:

  1. Classification
  2. Legal Hold
  3. Record Retention
  4. 28 CFR Part 23
  5. Access Permissions

These settings ensure investigations comply with organizational policies.

  • Imports

    When structured data files (such as Excel spreadsheets or CSV files) are imported into OWLDocs using OWLimport and linked to the case, the imported datasets become available within the Imports section.

    Investigators can review imported records without reopening the original files, making it easier to reference structured evidence throughout the investigation.

  • AI Narratives

    AI Narratives automatically generate a concise summary of the investigation based on information currently associated with the case.

    Narratives help investigators:

  1. Understand case progress quickly
  2. Review investigative activities
  3. Summarize evidence
  4. Save time preparing reports
  • Audit History

    The Audit History provides a complete record of all actions performed on the case.

    It records activities such as:

  1. Case creation
  2. Updates
  3. Status changes
  4. Evidence uploads
  5. Document modifications
  6. User access
  7. Collaboration activities
  8. Ownership transfers

This ensures transparency, accountability, and a complete audit trail throughout the investigation.

  • Case Ownership Transfer

When necessary, ownership of a case can be transferred to another investigator.

Common reasons include:

  • Investigator reassignment
  • Department changes
  • Workload balancing
  • Extended leave
  • Organizational restructuring

The complete investigation history remains preserved after the ownership transfer.

3. Case Status Progression

As the investigation progresses, the case status should be updated to reflect its current stage.

Typical statuses include:

StatusPurpose
OpenCase has been created and is awaiting investigation.
Pending / On HoldInvestigation is temporarily paused while awaiting additional information, approvals, or external input.
AchieveRecord cannot be edited and is not available in the View - Edit lists. Filter must be used to find the record
DeleteRecord is transferred to the Trash Bin and will be deleted as per the module policies.

Organizations may configure additional statuses to align with their internal investigative workflows.

4. Investigation Completion

Before closing a case, investigators typically ensure that all required work has been completed.

This may include:

  • Completing assigned tasks
  • Reviewing evidence
  • Finalizing reports
  • Verifying linked records
  • Confirming subject information
  • Documenting investigative findings
  • Performing final review

The case then becomes ready for closure.

5. Case Closure

Once the investigation is complete, the case status is changed to Closed.

A closed case generally indicates:

  • Investigation completed
  • Findings documented
  • Required reports finalized
  • Evidence preserved
  • Audit history retained
  • No further routine investigative activity expected

Although closed, authorized users may still view the case according to their permissions, while all historical activities remain available through the audit trail.

6. Archive and Retention

Closed cases may be archived according to the organization's retention policy.

Archived cases:

  • Remain searchable 
  • Preserve all investigative records
  • Retain complete audit history
  • Support future review or legal requirements

Retention policies determine how long cases are preserved before final disposition.

7. Case Deletion

Where organizational policies and user permissions allow, cases may eventually be deleted after their retention period has expired.

Deletion is typically governed by:

  • Organizational retention policies
  • Administrative permissions
  • Compliance requirements
  • Legal hold restrictions
  • Audit and governance controls

Cases under legal hold or active retention requirements cannot be removed until those restrictions are lifted.