[Developers]

Cross-Investigation Multi-Track Timeline

The Cross-Investigation Multi-Track Timeline brings authorised case events together around a shared entity, on parallel event tracks, so analysts can see sequence, overlap, and escalation across the investigations they a

Category: InvestigationLast Updated: Jul 16, 2026
investigationgeospatial

Overview#

The Cross-Investigation Multi-Track Timeline brings authorised case events together around a shared entity, on parallel event tracks, so analysts can see sequence, overlap, and escalation across the investigations they are cleared to view.

An entity may appear in several investigations at once: a phone number in a fraud case, a vehicle in a surveillance case, a person in a safeguarding case, and a location in a public order incident. Looking at each case separately hides the pattern. The module builds an entity-centred timeline that keeps each class of case activity on its own track, so the combined picture stays readable instead of collapsing into one long list.

The timeline runs as its own dedicated workspace, so it opens faster and the main analyst workspace stays lighter. It preserves the access rules of each source investigation, so analysts see only the tracks they are cleared to view while still gaining a coherent picture of activity across the cases they are authorised to handle.

Key Features#

  • Entity-Centred Case Discovery: Find investigations linked to a person, organisation, device, vehicle, location, account, or other entity.
  • Multi-Track Presentation: Separate tracks keep different classes of activity, such as case milestones, evidence events, alerts, location observations, and analyst decisions, readable without flattening them into one list.
  • Dedicated Timeline Workspace: The timeline is served from its own faster-loading workspace, so analysts open a full-screen chronology without loading the wider analyst suite.
  • Investigation Context Picker: Entering the timeline without a case pre-selected presents a picker so the analyst can choose which investigation to visualise.
  • Consistent Timeline Routing: Timeline links from anywhere in the platform land on the same full-featured investigations timeline.
  • Interactive Timeline Controls: Parallel event tracks come with an event editor, relationship overlay, minimap, and keyboard shortcuts for fast review.
  • Access-Preserved Views: Access is governed by the same investigation capability set as the rest of the case tooling, so every track reflects only the cases and events the analyst is authorised to view.
  • Deconfliction Support: Analysts can identify where two teams are unknowingly working the same subject, vehicle, account, or location.
  • Temporal Pattern Review: Detect bursts, gaps, recurring cycles, and event order across otherwise separate investigations.
  • Briefing-Ready Output: Export a timeline summary for supervisors, tasking meetings, disclosure preparation, or operational briefings.
  • Evidence Linkage: Timeline events preserve links back to their source evidence and case records so reviewers can move from pattern to underlying material.

Use Cases#

  • Organised Crime Deconfliction: Two regional teams discover that the same vehicle and phone number appear in separate investigations and coordinate activity before compromising each other.
  • Safeguarding Escalation Review: Analysts review incidents, visits, referrals, and evidence across several cases involving the same vulnerable person.
  • Financial Crime Patterning: Investigators align account activity, device use, reports, and interviews across related fraud matters.
  • Public Order Intelligence: Commanders see how individuals, locations, and events recur across incidents before planning a high-risk operation.
  • Briefing Preparation: A senior investigator receives a concise multi-track chronology instead of manually assembling dates from multiple case files.
  • Rapid Timeline Entry: An analyst jumps from any case view straight into the full-screen timeline workspace, using the context picker to select an investigation when none is pre-selected.

Integration#

The timeline connects to case management, entity profiles, evidence provenance, alerting, geospatial history, profile briefing, export packaging, and role-based access control. Timeline links across the platform route consistently to the dedicated workspace, so every entry point reaches the same full-featured view. It is not a global search bypass. It is an authorised analytical view that respects the source rules of every contributing case.

Open Standards#

  • ISO 8601: Timeline events and date filters use standard date-time formatting for unambiguous ordering.
  • W3C PROV-DM: Event lineage can be represented as activities, entities, and agents for review and export.
  • GeoJSON, RFC 7946: Location-linked events can carry standard geographic geometry for mapping and spatial review.
  • STIX 2.1: Threat intelligence entities and observations can align with STIX object conventions where cyber or intelligence cases are involved.
  • Traffic Light Protocol, FIRST: Information sharing labels can be applied to timeline outputs that leave the originating team.
  • OAuth 2.0 and JWT Bearer Token: Authenticated context enforces organisation, role, and case visibility controls.

Last Reviewed: 2026-07-16 Last Updated: 2026-07-16

Ready to Build?

Get started with our APIs or contact our integration team for support.