Workspace

← Back to Documentation Index

The Workspace (sidebar > Workspace > Investigations) is your investigation index — the central hub where you browse, search, filter, and create investigations.


Investigation Index

Navigate to Investigations in the sidebar, or press G then T (or G then W). You will land on the investigation index, which shows all investigations in your account.

Layout

The index displays investigations in a table (desktop) or card list (mobile). Each investigation row or card shows:

  • Title — The investigation name. Click to navigate to the Overview lens.
  • Health bar — A color-coded bar indicating the investigation's overall health score (0–100).
  • Event count — Total events in the investigation's timeline.
  • Status badge — The current phase (draft, active, paused, resolved, or archived).
  • Updated date — When the investigation was last modified.
  • Star toggle — Click the star icon to add or remove an investigation from your starred list.

Creating an Investigation

  1. Click the + New Investigation button at the top of the index.
  2. Fill in the dialog:

- Title — A descriptive name.
- Status — The current phase.

- Summary — Optional description of scope and goals.

  1. Click Create.

You are taken to the new investigation's Overview lens.

Filtering and Sorting

The filter bar above the list lets you narrow the index:

FilterDescription
SearchFilter by investigation title
StatusShow only investigations with a specific status
UpdatedFilter by recency: anytime, today, this week, this month
HealthFilter by health score range
SortOrder by most recently updated, earliest created, or alphabetical

Click Clear Filters to reset all filters and show the full list.

Empty State

If no investigations exist, the index shows an empty state with a prompt to create your first investigation. If your filters return no results, an empty state suggests clearing the filters.


Recent Investigations

Navigate to Recent (sidebar > Workspace > Recent).

This page shows your recently viewed investigations, ordered by most recently accessed. Click any investigation to return to where you left off.


Starred Investigations

Navigate to Starred (sidebar > Workspace > Starred).

This page shows investigations you have starred. Use stars to bookmark investigations you return to frequently. Click the star icon on any investigation row (in the index or on the investigation header) to toggle the star.

Empty state: "No starred investigations — star investigations to access them quickly here"


Review Queue

The Review Queue is available at sidebar > Tools > Review Queue.

The Review Queue surfaces gaps across all investigations in your account:

Summary Cards

Four stat cards at the top show current counts across all investigations:

CardWhat It CountsColor
Events without claimsEvents that have zero claims attachedAmber
Low confidence claimsClaims with confidence below 50%Orange
Orphan entitiesEntities not linked to any eventGray
Pending status reviewClaims flagged for reviewBlue

Events Without Claims

Lists events that have no claims attached. Click the arrow to navigate to the event within its investigation context.

Low Confidence Claims

Claims with confidence below 50%. Click any claim to open the Claim Review dialog to adjust the confidence score and status.

Orphan Entities

Entities not linked to any event. Link them to an event or delete them if created in error.

Pending Status Review

Claims that may need their status updated. This includes stale claims and claims whose status needs review.


Entity Reconciliation

Available at sidebar > Management > Entity Reconciliation, this tool scans for potential duplicate entities across your account and provides a merge interface.

  1. Click Scan for Duplicates to run a scan.
  2. Review the suggested duplicates — pairs of entities that may represent the same real-world actor.
  3. For each pair, choose to Merge (combine into one entity) or Keep Separate (mark as not duplicates).
  4. When merging, choose which entity's name, type, and aliases to keep. Relationships and event links from both entities are preserved in the merged entity.

Keyboard Shortcuts

KeyAction
NOpen New Investigation dialog (from the index)

Next: Working with Timelines →