Skip to main content

Analyzing Your Graph with Co-Case Agent

How to use Co-Case Agent to control your graph and analyze the Custom Entities, Custom Ledgers, and IP observations on it.

Co-Case Agent is available to all Forensics users in environments that have AI tools enabled. AI enabled tool access is set at the Environment level, and must be enabled by an environment administrator. Reach out to your TRM representative or [email protected] for more support if needed.

This article is part of the Using Co-Case Agent guide.

Controlling and Organizing the Graph

Beyond answering questions and plotting flows, you can ask Co-Case Agent to change how the graph looks and how its elements are arranged. You stay in control: the Co-Case Agent applies display and layout changes directly, and asks for explicit confirmation before any action that adds to a case or shares your work.

  • Display settings. Ask Co-Case Agent to switch presets (standard, simplified, or UTXO), change the layout, and toggle individual display options such as address labels and attribution, tags and geo tags, risk rings or risk coloring, portfolio value and total volume indicators, transfer amounts and timestamps, transaction properties, unplotted flows, and grid lines. For example, "Switch to the simplified preset and turn on risk rings."

  • Arranging elements. Ask it to hide or unhide elements, pin or unpin nodes, and group or ungroup addresses by entity. Hiding keeps a complete record while presenting a readable view.

  • Off-chain elements. Ask it to add an off-chain node (for example, a person, organization, email, phone, financial account, or physical location) or a custom connection, to represent context that does not live on-chain.

  • Notes. Ask it to list, update, link, unlink, or delete existing graph notes.

  • Graph actions. Ask it to undo or redo a change, refresh attribution or flow values, plot all unplotted flows, or rename and duplicate the graph.

  • Navigation. Ask it to zoom, fit the graph to the screen, or enter focus mode on a selected element.

Analyzing Custom Entities

Co-Case Agent can analyze the Custom Entities you build in Graph Visualizer. A Custom Entity groups addresses into the real-world subject you are tracking, such as a suspect wallet cluster, a shell company, or an OTC desk, and Co-Case Agent treats it as a subject you can ask about directly.

Select or name a Custom Entity, then ask about it in plain language. Co-Case Agent offers suggested prompts to get you started:

  • "Summarize this Custom Entity"

  • "Summarize this Custom Entity's risk"

  • "Who are this Custom Entity's top counterparties?"

  • "Show this Custom Entity's largest recent transfers"

Six kinds of question are supported, all of them read-only:

  • Summary: what the entity is and what its activity looks like.

  • Risk: the entity's risk profile and what drives it.

  • Counterparties: who the entity transacts with, with filters and paging on longer lists.

  • Transfers: the entity's transfers, also filterable and paged.

  • Member addresses: the addresses that make up the entity.

  • Ownership and category breakdown: how the entity's holdings and activity divide up.

Co-Case Agent can plot supported counterparties and transfers straight onto your graph, and keeps track of which Custom Entity you are asking about as the conversation continues.

Two behaviors are worth knowing before you rely on an answer:

  • A still-loading entity is not the same as one with little activity. When the underlying data for a Custom Entity is still being assembled, Co-Case Agent says so rather than reporting no activity. Treat "still loading" as unknown, not as zero.

  • Plotting a whole transaction depends on the chain. On account-based chains, Co-Case Agent can plot the full transaction behind a transfer. On UTXO chains such as Bitcoin, it plots the transfer legs instead.

If you do not have access to a Custom Entity, Co-Case Agent will tell you so rather than returning partial results. Ask the entity or graph owner for access.

Working with Custom Ledgers

Co-Case Agent can also create and query Custom Ledgers, so you can assemble a ledger from transfers already on your graph and then ask questions about it without building the view by hand.

  • Create a ledger from transfers you have plotted, and rename an existing one.

  • Query a ledger for a summary, for its transfers with paging through longer lists, and for its counterparty flows.

Creating or renaming a ledger changes shared work, so it requires edit access to the graph. Querying a ledger only requires the access you already have to it.

Investigating IP Observations

IP triage in Co-Case Agent is available only in environments with Co-Case Agent AI tools, and INET all enabled. If your organization does not have INET access, IP-related prompts will not appear in the Co-Case Agent. Contact your TRM representative or [email protected] to learn more.

Co-Case Agent can surface and triage IP observations tied to addresses on your graph. Investigators who need a real-world timeline around an on-chain trace will run IP triage inside the investigation flow, without switching to a separate tool.

Three types of IP analysis are available:

  • Graph-wide IP triage. Ask "Which addresses on my graph have IP observations?" Co-Case Agent returns a ranked table, highest-signal IPs first, with heavily shared infrastructure flagged as background noise. Start here to identify which IPs are worth pursuing before drilling deeper.

  • Per-IP deep dives. Select a specific IP and ask for a summary. Co-Case Agent returns the observation count, the full time span of activity, a client vs. server classification, and the infrastructure type: residential ISP, cloud provider, VPN, proxy, or Tor.

  • Pattern-of-life analysis. Co-Case Agent applies built-in triage heuristics including observation frequency, the ratio of addresses sharing an IP, and anonymization flags. IPs with low observation counts, high sharing ratios, or known anonymization infrastructure are explicitly down-weighted, so not every IP hit receives equal weight.

When Co-Case Agent surfaces an IP lead, what you do next depends on the infrastructure type. For residential ISPs or cloud providers with strong signal, legal process is a reasonable next step. For VPN, proxy, or Tor exits, note the anonymization context in your case file but treat the IP as a non-reliable identifier.


This article is one part of the Using Co-Case Agent guide, which links to the full set of Co-Case Agent articles.

Did this answer your question?