Templates Investigative Case Management
The Vault · Investigative Case Management

The Foundation Every
Investigation Runs On

Every specialized hub in Hubstream's template library — from law enforcement to brand protection to cybercrime — is built on top of this core. Start here if your team needs a single, secure home for all investigative work before adding domain-specific workflows.

Template type Foundation Hub
Applies to All Investigative Teams
Workflow stages 6 stages
Entity types 10 core entities
Built on this template

This is the shared foundation underneath every specialized hub. Each domain template extends these workflows, entity types, and integrations with vertical-specific configurations.

How It Works · 01–06

Case Workflow

The full lifecycle of an investigation — from first intake to final closure. Every domain template in the library maps onto this same spine, with vertical-specific stages and entities layered on top.

01
Stage 1 · Intake

Intake & Case Opening

A new case opens when a report arrives — from a web form, an email tip, a phone referral, a partner agency, or a proactive internal lead. Each channel maps to a structured intake form that captures the minimum required information. Hubstream creates a case record automatically, assigns a reference number, and routes the case to the appropriate queue for triage. Duplicate detection flags potential matches against existing open cases before a new record is created.

Web Form Intake Email & Phone Partner Referral Internal Lead Duplicate Detection Auto Case Number
02
Stage 2 · Triage & Assignment

Case Triage & Investigator Assignment

Incoming cases are reviewed, prioritized, and assigned by a supervisor or automated triage workflow. Priority scoring considers case type, severity, available evidence, and time sensitivity. Cases are routed to the appropriate team or investigator, with full workload visibility across a team dashboard. High-priority or multi-team cases can be escalated immediately, with notification to relevant stakeholders.

Priority Scoring Case Classification Investigator Assignment Team Routing Workload Dashboard Escalation Alerts
03
Stage 3 · Investigation & Analysis

Evidence Collection, OSINT & Link Analysis

The investigator builds the case — gathering evidence, conducting interviews, running OSINT enrichment against identifiers (names, emails, phone numbers, usernames, financial accounts), and mapping connections. Hubstream's DataSpace automatically links persons, organizations, locations, and prior cases into a network graph. AI surfaces patterns across structured and unstructured data, suggesting connections that would take hours to find manually.

Evidence Logging OSINT Enrichment (200+ Sources) Link Analysis Network Graph AI Pattern Detection Timeline View Cross-Case Matching
04
Stage 4 · Coordination & Collaboration

Cross-Team Coordination & External Partners

Complex cases rarely stay within a single team. Hubstream tracks every collaboration point — shared case access for partner agencies, task assignments to outside counsel, formal referrals to law enforcement, and secure evidence sharing with authorized external parties. Each access grant, file share, and handoff is logged in the case audit trail. Permissions are enforced at the field level so sensitive details remain controlled even when collaboration is broad.

Partner Agency Access Secure Evidence Sharing Task Delegation Outside Counsel Portal Law Enforcement Referral Field-Level Permissions
05
Stage 5 · Action & Escalation

Formal Action & Case Escalation

When investigation reaches a threshold requiring formal action — a referral to law enforcement, a legal filing, a takedown request, a regulatory submission, or an internal disciplinary proceeding — Hubstream tracks the action, its authorization chain, and its outcome. Every formal action links back to the evidence and case record that supported it, maintaining the chain of custody needed for legal or regulatory review.

Law Enforcement Referral Legal Filing Tracking Authorization Chain Regulatory Submission Action Outcome Logging Evidence Chain of Custody
06
Stage 6 · Closure & Reporting

Case Closure, Reporting & Intelligence Retention

When a case closes, the outcome is recorded — resolved, referred, dismissed, or pending — and the case is locked for audit purposes. AI assembles a draft closure report from case data: timeline, evidence summary, actions taken, and outcome. Analytics dashboards update automatically with caseload trends, resolution rates, and team performance metrics. Intelligence developed during the investigation — subject profiles, network maps, risk indicators — is retained and made available to future cases.

Outcome Classification AI Closure Report Draft Audit Lock Intelligence Retention Analytics & KPI Dashboard Executive Summary Export
Connects with
Web Form Builders Email & Phone Intake OSINT Data Sources (200+) Identity Verification Document Management Legal & Court Systems Partner Agency APIs BI & Reporting Tools
Data Model · 10 Entity Types

What Gets Captured

The universal entity set that underpins every investigative workflow. Domain-specific templates extend these entities with additional fields and relationships — the core structure stays consistent.

📁

Case / Investigation

The central record every other entity links to. Tracks the full lifecycle of a matter from intake to final disposition, across any investigative domain.

Case Number · auto-generated Case Type · configurable by domain Status · open / active / suspended / closed Priority · scored + supervisor override Assigned Investigator(s) Team / Unit Outcome / Disposition Date Opened / Closed
📋

Lead / Report

An incoming tip, referral, or report before it becomes a full case. Leads can be triaged, merged, escalated to a case, or closed without further action.

Source · web form / email / phone / referral Received Date / Time Description Triage Status · new / under review / escalated / closed Escalated to Case Assigned Reviewer
👤

Person

Any individual connected to the case — subject, victim, witness, complainant, or point of contact. Role on the case is set per association, not on the record itself, so the same person can be a witness in one case and a subject in another.

Full Name / Aliases Date of Birth Contact Information Identifiers · email, phone, username, ID number Role on Case · subject / victim / witness / contact Known Associates Linked Cases
🏢

Organization

A company, agency, network, or group relevant to the investigation. Organizations link to persons, locations, and other cases — enabling network mapping across related entities.

Organization Name Type · company / agency / network / group Registration / Identifiers Known Members / Contacts Known Addresses Linked Cases
📍

Location

A physical or geographic reference connected to the case — an incident site, a subject's address, a meeting point, or a jurisdiction boundary.

Street Address City / Region / Country Coordinates (Lat/Long) Location Type · incident site / address / jurisdiction Linked Persons & Organizations Linked Cases
🗂️

Evidence

Any item — document, file, photo, recording, or physical exhibit — collected to support the case. Chain of custody is maintained automatically on every evidence record.

Evidence Type · document / photo / digital / physical Description Collection Date & Source Collected / Uploaded By Chain of Custody Log Linked Case / Person / Event

Task

An action item assigned to an investigator or team — an interview to conduct, a record to pull, a follow-up to complete. Tasks are tracked with deadlines, reminders, and completion status.

Task Title Assigned To Due Date Status · pending / in progress / complete / overdue Priority Linked Case Completion Notes
📝

Note

An internal observation, interview summary, field note, or investigative memo. Notes are linked to a case, person, or evidence item, and carry the author and timestamp for audit purposes.

Note Type · observation / interview / memo / update Body Author Date / Time Linked Case / Person / Evidence Visibility · team / restricted / confidential
📊

Report

A formal output generated from the case — an incident report, a closure summary, a referral package, or an executive brief. Hubstream AI drafts report content from case data; investigators review and approve.

Report Type · incident / closure / referral / executive Generated From · linked case Draft / Approved / Final Author & Approver Date Issued Recipients
💬

Communication

A logged interaction relevant to the case — an email thread, a phone call record, a witness interview transcript, or a message exchange. Communications are linked to the person and case they relate to.

Communication Type · email / phone / interview / message Date / Time Participants Summary / Transcript Linked Person(s) Linked Case
Link Analysis · Key Relationships

How the Entities Connect

The relationship paths that surface hidden patterns across cases — turning individual records into a connected intelligence picture of the people, organizations, and events at the center of each investigation.

Lead Case (Escalation)

When a lead passes triage, it is escalated directly into a case — carrying its source details, intake data, and attached evidence with it. The original lead record is preserved alongside the case for audit purposes.

Person Prior Cases

When a person is added to a case, Hubstream automatically surfaces every prior case they appear in — as a subject, a witness, or an associate — giving investigators immediate context on history and patterns.

Person Known Associates

Associates linked to a person are surfaced from across the entire case database — identifying networks, co-conspirators, and organizational ties that span multiple unrelated cases and teams.

Organization Persons & Cases

An organization linked to multiple people and cases reveals the full scope of coordinated activity — connections that are invisible when cases are managed in isolation across separate spreadsheets or systems.

Evidence Case & Person

Every piece of evidence is linked to the case and the person it relates to. Chain of custody is logged automatically on every access, transfer, or modification — maintaining a defensible record through closure and beyond.

Task Investigator

Tasks assigned from a case carry full context — linked evidence, linked persons, and case history — so investigators arrive at each action item with what they need already surfaced.

Case Related Cases

Cases sharing a person, organization, location, or behavioral pattern are linked automatically — surfacing connections between matters that appear unrelated when viewed in isolation, and enabling coordinated multi-case action.

Report Case Record

Every formal report is generated from and linked to the case record it documents. Approvals, revisions, and recipient logs are tracked on the report — giving investigators a defensible record of what was shared, with whom, and when.

Add-On Modules · 03

Extend the Foundation

The Case Management Hub covers the full investigative lifecycle. These add-ons extend specific stages when your team needs a dedicated sub-workflow for a specialized capability.

Extends Stage 1 · Intake

Public Intake Portal

A branded web portal for receiving tips, reports, and referrals from the public, partner agencies, or internal units — automatically creating a lead record and routing it for triage, with no manual data entry required.

Configurable intake form fields by case type Anonymous submission support File and photo attachment Auto-lead creation and routing on submit Triage dashboard for incoming volume Duplicate detection before record creation
Extends Stage 6 · Closure & Reporting

AI Report Writer

Hubstream's AI assembles a structured draft of any case report — incident narrative, closure summary, referral package, or executive brief — directly from the case record. Investigators review, edit, and approve; they don't start from a blank page.

Draft generation from case data (no templates to fill in) Configurable report formats by audience Inline review and approval workflow Version history and approval log Export to PDF, Word, or secure link
Extends Stage 3 · Investigation & Analysis

Cross-Case Intelligence Analytics

A persistent intelligence layer that retains person profiles, network maps, and risk indicators across case closures — so knowledge built on one investigation is automatically available to the next one that involves the same entities.

Cross-case entity matching and deduplication Persistent network and relationship maps Risk scoring for recurring subjects Trend detection across case cohorts Intelligence retention beyond case closure
Ready to build on this?

Start with the Foundation.
Add What Your Team Needs.

Request a demo and we'll walk you through how this template works inside a real Hubstream environment — and how quickly you can add the domain-specific workflows your team actually uses.

Request a Demo → Browse All Templates