Investigations rarely depend on one search. A user may begin with a name, phone number, address, document, or internal record and then run additional connector, keyword, geospatial, OWL product, and pivot searches as new leads emerge. Without a reliable way to preserve those searches, teams can lose the context behind a result, repeat paid or time-consuming queries, overlook earlier findings, or struggle to explain how information was collected.
The challenge becomes greater when multiple users, departments, cases, and subjects are involved. Investigators need to know what was searched, which source was used, who performed the search, when it occurred, and where the result belongs—without manually rebuilding the investigative trail.
OWL automatically creates a Data Query record when a search is performed. The record preserves the search context and makes the results available for later review through Data Query Logs, Case and Subject records, and the Data Visualization result screen. Connector searches and searches across OWL records are maintained in the same workflow, allowing users to return to earlier work without reconstructing the original query.
Searches linked to a Case or Subject remain associated with that record unless detached. Searches performed without a selected Case or Subject are maintained as temporary ("orphan") searches and can be accessed from Data Query Logs. Users can later attach an orphan search to an existing Case or Subject when the investigative context becomes known.
This has benefits across multiple industries:
- Law enforcement - Preserves query history and investigative context, supports supervisory review, and strengthens continuity, accountability, and auditability.
- Insurance investigations - Helps investigators return to prior identity, asset, address, and relationship searches while reducing duplicate work across a claim or subject.
- Corporate risk and security - Keeps due-diligence, threat, fraud, insider-risk, and third-party searches connected to the appropriate case and available for later reassessment.
- Legal and compliance - Maintains a traceable record of search activity, source, user, department, case association, and applicable record status for review and reporting.
- Financial and fraud investigations - Allows analysts to build on prior results, launch pivot searches, compare identities across searches, and revisit the complete investigative dataset.
Data Query Logs
Data Query Logs provide a centralized history of searches run by the logged-in user or shared through collaboration. Depending on the query and its association, the log can include:
- Search date, product name, search criteria, dataset, and source
- Record owner, department/team, and the user who performed the search
- Case number, case name, and subject name when the query is linked to those records
- Record status and the relationship between a main search and any subsequent pivot or spyglass searches
- The returned data and associated records that can be reopened in Data Visualization
The Data Query Logs page includes Whooster and other connector products, OWL products and records, keyword searches, geospatial searches, spyglass searches, and other Data Query searches.
Relaunching Queries
- Hover over Case Management.
- Click Data Query Logs.
- Use the available filters to locate the search. Filters can include Case Number, Record Owner, Department/Team, Data Query Status, date range, and Collaborated Records.
- Click the value in the Search Criteria column to open the result screen with the same search details; or open the Action menu and select Launch Data Visualization.
- Review the query with its associated records and other searches in the available views, including Link Analysis and Details/Tabular.
Note: Orphan searches—queries performed without a selected Case or Subject—can only be accessed and launched from Data Query Logs. OWL assigns each orphan search a unique temporary case number. The search may later be attached to an existing Case or Subject from the Data Query Log action menu.
Relaunching Queries from a Record Dossier
When a query is linked to a Case or Subject, OWL provides record-centered ways to return to the collected data. This keeps the search history with the investigation instead of requiring the user to locate each query separately.
The Dossier includes Data Query and Connector Searches sections for viewing and/or launching queries.
- Connector Searches will display the results from queries related to the record in a Tabular view.
- Query Logs shows queries themselves, including which source was searched and the criteria used.
All queries related to a record can be relaunched by selecting "Data Visualization" at the top of the Dossier and choosing which view to launch it with.
Automatic saving in Data Visualization
Relaunching a Data Query does more than retrieve a row from a log. OWL reopens the saved investigative dataset on the result screen, where all selected perspectives work from the same underlying Case, Subject, and query scope.
Link Analysis View
Link Analysis presents each search as a Query Node connected to vendor, data source, identity, wrapper, and child nodes as applicable. New pivot searches create additional Query Nodes and remain linked to the identity from which they were launched.
- Node positions are saved automatically when a user moves them. When the result screen is reloaded or reopened, the arranged positions are retained.
- Expanded nodes can be kept in place to preserve the working focus of the canvas.
- Hidden nodes can be restored with View All Hidden Nodes, and Reset Node Position returns the saved view to the default layout.
- Connector Query Nodes may offer Rerun, allowing the user to execute the same query again for an updated response.
Tabular-Report View
The Tabular-Report View presents the same saved query results in a structured parent-child format. Users do not need to export or manually save the table before leaving the result screen. When the query, Case, or Subject is launched again, OWL rebuilds the Tabular view from the retained Data Query records and associated data.
- Queries attached to a Subject appear under Subject Dataset Queries.
- Queries performed at the Case level without a Subject appear under Case Dataset Queries.
- Main searches and sub-searches or pivot searches are retained together and identified separately.
- Display All expands the available Case and Subject containers so users can review associated records and Data Queries in one action.
- The Tabular and Link Analysis views remain interconnected perspectives of the same dataset, maintaining query scope, filters, and permissions.