Skip to main content

Guidance, Collaboration, and Next Steps with Co-Case Agent

How Co-Case Agent checks your graph for issues, runs deconfliction and case workflows, and suggests next steps.

Co-Case Agent is available to all Forensics users in environments that have AI tools enabled. AI enabled tool access is set at the Environment level, and must be enabled by an environment administrator. Reach out to your TRM representative or [email protected] for more support if needed.

This article is part of the Using Co-Case Agent guide.

Guardrail Alerts and "Check my graph"

You can ask Co-Case Agent to "Check my graph." It will scan the graph for unresolved issues, such as missing hops, suspicious withdrawals, over‑plotted services, or untrimmed VASP withdrawals. Any identified issues are then listed so you can review and fix them before exporting evidence. Examples of issues and alerts Co-Case Agent can identify during a graph check include:

  • Tracing through services
    If you follow funds straight through an exchange, mixer, or unattributed service as if ownership never changed, Co-Case Agent warns you, explains why this is incorrect, and recommends typical off‑chain next steps (for example, subpoenas or standard exchange CSV exports) rather than continuing on‑chain beyond the service.

  • Missing bridge or swap hops
    If you plot a deposit to a bridge or DeFi service without the corresponding cross‑chain or same‑chain swap signature, Co-Case Agent alerts you and prompts you to plot the correct signature from the Transfers table, reducing the risk of broken continuity.

  • Exposure vs counterparties misuse
    If you treat exposure wheels as direct counterparty lists, Co-Case Agent reminds you that wheels are approximate visuals and directs you to the Exposure table and Counterparties view for exact entity breakdowns suitable for reports.

  • Graph hygiene and performance
    On large or cluttered graphs, Co-Case Agent suggests collapsing hot wallets into entities under strict rules, trimming other outputs on VASP withdrawals, and hiding rather than deleting elements so you keep a complete record while presenting a readable, performant view.

Deconfliction and Case Workflows

Co-Case Agent can also run collaboration workflows directly in the chat, without opening a separate panel.

  • Deconfliction. For a selected element, ask which other saved graphs contain it. Co-Case Agent returns the matching graph names as links that open in a new tab, along with the investigators who have shown interest, so you can coordinate before duplicating work.

  • Adding addresses to a case. Ask Co-Case Agent to add selected addresses to a case. It lists your available cases, confirms your choice, and then adds the addresses.

  • Registering interest. Ask Co-Case Agent to register your interest on the deconfliction network. You choose the audience (your agency or all TRM users) and whether the entry is open or private, and you can add an optional note. Co-Case Agent summarizes what will be shared and asks you to confirm before registering.

Follow Suggested Next Steps

Co-Case Agent can provide next‑best‑action guidance when you are starting a trace or stuck on a complex node.

Typical patterns include:

  • When you plot your first address or transaction, Co-Case Agent can suggest best‑practice first moves such as plotting first funding, checking gas‑funding relationships, and reviewing recent counterparties.

  • At very busy services (exchanges, mixers, relayers), it can recommend collapsing internal flows, focusing on nodes with active balances, opening exposure views for indirect high‑risk destinations, or generating legal‑process CSVs instead of expanding every hop.

Generating Court-Ready Reports

Co-Case Agent can draft a court-suitable Word document from the investigation you just ran in Graph Visualizer. Ask for a report and Co-Case Agent writes a facts-only narrative in the numbered paragraphs and neutral attribution language that legal teams expect, then returns a download card at the bottom of its reply. The output is an editable .docx file, so you finish a draft rather than starting one from a blank page.

Two report types are available:

  • Off-ramp report. After you run a find-off-ramps seizure assessment, ask Co-Case Agent for a report. The off-ramp report covers the custodial exit points from the assessment, with volume, provenance, and the endpoints excluded as non-seizable.

  • Investigation report. From any graph investigation, such as fund-origin tracing, theft, CSAM purchase tracing, or terrorism financing, ask Co-Case Agent for a report. The investigation report is a chronological fund-flow narrative built from the graph and from what Co-Case Agent found getting there.

To generate a report:

  1. Open Co-Case Agent alongside your graph in Forensics.

  2. Run the investigation: a find-off-ramps seizure assessment, or any graph investigation.

  3. Ask for a report. Co-Case Agent generates it and returns a download card at the bottom of its reply in the chat panel.

  4. Select the card to download the .docx, then edit it as your own draft.

Both report types follow one section order: status banner, affiant background, purpose and scope, summary, definitions, factual narrative, and disclosure annex. The language is facts-only throughout, with no legal conclusions, no "suspicious" or "illicit" labels, and no invented addresses, hashes, or amounts. Every draft opens with the line "DRAFT, NOT ADOPTED. FOR INVESTIGATIVE AID ONLY." You verify the facts and adopt the draft before it becomes a filing.

Each report export writes an entry to the Forensics Audit Log, attributed to the user, the organization, and the time of export, so your agency can show who generated which document and when.


This article is one part of the Using Co-Case Agent guide, which links to the full set of Co-Case Agent articles.

Did this answer your question?