Understanding Cases vs. Subjects

  • Updated

The OWL Intelligence Platform separates Cases and Subjects because they serve different purposes within an investigation. Understanding the distinction helps ensure information is organized correctly, promotes reuse across investigations, and supports governance and compliance requirements.

Cases

A Case is the primary investigative container. It represents an investigation, incident, claim, inquiry, or other body of work that users are managing.

Cases provide the organizational framework for related information, including:

Cases also manage ownership, collaboration, status, reporting, and the overall lifecycle of an investigation.

Learn more: Cases Overview

 

Subjects

A Subject represents the person, organization, vehicle, location, asset, or other entity that is being investigated or documented.

Unlike a Case, a Subject focuses on a single entity and stores information specific to that entity, including:

  • Documents
  • Notes
  • Forms
  • Tips & Leads
  • Reports
  • Evidence
  • Data Query Logs
  • Monitoring information
  • Subject details (in global and custom attributes)

A Subject can exist independently or be linked to a Case whenever appropriate. This allows investigators to capture and manage information before deciding whether it belongs within a formal investigation.

Learn more: Subjects Overview

 

How Cases and Subjects Work Together

Cases and Subjects are designed to complement one another.

  • A Case organizes the investigation.
  • A Subject represents the entity involved in that investigation.

A Case can contain multiple Subjects, and Subjects can be attached to Cases as investigations evolve. This flexible approach allows organizations to begin collecting intelligence immediately without requiring every record to be associated with a Case from the outset.

 

Attaching Other Records

Most investigative records in OWL can be attached directly to either a Case or a Subject, depending on the context.

Generally:

Attach to a Case when... Attach to a Subject when...
The information applies to the investigation as a whole. The information relates to one specific person, organization, asset, or other entity.
Multiple subjects may be involved. The record belongs to a single subject's history or profile.
The record should be viewed as part of the overall case file. The record should remain associated with that subject regardless of which Case it is linked to.

Common record types that can be attached include:

  • Forms
  • Information Sharing
  • Tips & Leads
  • Reports
  • Evidence
  • Data Query Logs
  • Documents

 

Choosing Between a Case and a Subject

Use a Case when you need to organize and manage an investigation or operational workflow.

Use a Subject when you need to manage information about a specific entity, whether or not a formal investigation currently exists.

This separation allows information to remain organized, reusable, and governed throughout its lifecycle while supporting collaboration, auditing, and regulatory compliance.