Skip to main content

Trust, Limits, and Feedback with Co-Case Agent

What Co-Case Agent will and will not do, how it keeps your work auditable and defensible, and how to give feedback on its responses.

Co-Case Agent is available to all Forensics users in environments that have AI tools enabled. AI enabled tool access is set at the Environment level, and must be enabled by an environment administrator. Reach out to your TRM representative or [email protected] for more support if needed.

This article is part of the Using Co-Case Agent guide.

What Co-Case Agent Is Good At

Co-Case Agent is optimized for certain types of questions:

  • Concrete, graph‑scoped tasks

    • "Plot the cross‑chain swap that moves these funds off this chain"

    • "Find exchanges that received funds from this address in my graph"

  • Interpretation and explanation

    • "Explain why this address is high risk and what to do next"

    • "Explain how to interpret Exposure vs Counterparties for this graph"

  • Training and tradecraft

    • "Walk me through tracing pig‑butchering victim funds from this starting hash"

    • "What should I know about this address before I decide on next steps?"

What Co-Case Agent Will Not Do

Co-Case Agent is intentionally constrained in several ways:

  • IP analysis is limited to TRM's INET data
    Co-Case Agent's IP triage draws only on TRM's INET data set. It has no access to off-platform login or session data, or to network telemetry beyond that set. IP triage also requires INET to be enabled for your environment, which is covered under Investigating IP Observations.

  • No automatic entity creation or merging
    Creating or merging addresses into custom entities is a manual action in Graph Visualizer. If you ask Co-Case Agent to "merge these addresses into an entity," it can explain how to do it, but it will not perform the operation for you.

  • No silent destructive graph edits
    When you ask to "clean up" or "simplify" a graph, Co-Case Agent is constrained to recommend hiding elements, trimming other outputs on VASP withdrawals, or collapsing hot wallets under strict rules, and will warn you before any action that could remove data you may need later.

  • No misrepresentation of inherited exposure
    Co-Case Agent is required to distinguish direct counterparties from multi‑hop or inherited exposure. For report‑ready outputs, it will steer you toward counterparty‑filtered and time‑scoped exposure tables rather than lifetime aggregate wheels.

When a request falls outside its tools entirely, Co-Case Agent is expected to return a clear "can't do that" message instead of fabricating an answer.

Audit, Privacy, and Defensibility

Co-Case Agent is designed to support investigations that must stand up to regulatory, audit, and courtroom scrutiny.

  • Audit logging
    Co-Case Agent interactions (chat prompts, responses, and key actions) are written into the Forensics Audit Log, so your organization can understand how AI influenced any given investigation.

  • Privacy‑aware collaboration
    When an action might expose sensitive work (for example, using Deconflict, indicating interest, or sharing a graph), Co-Case Agent will summarize what is and is not shared and obtain your explicit confirmation before proceeding.

  • Copilot‑only model
    Co-Case Agent follows TRM's "copilot, not autopilot" principle: it suggests, explains, and documents but does not silently rewrite graphs or issue conclusions. You remain responsible for tracing decisions, accounting methods (FIFO/LIFO/PIFO), and the final narrative that appears in your reports.

Used in this way, Co-Case Agent helps you move faster from on‑chain data in Graph Visualizer to defensible, court‑ready investigative outcomes, while keeping a clear record of how AI assisted your work.

Providing Feedback on Co-Case Agent Responses

You can rate any Co-Case Agent response directly in the chat using the inline feedback buttons. After each response, a thumbs up and thumbs down appear at the bottom of the message.

  • Thumbs up marks the response as helpful

  • Thumbs down marks the response as unhelpful; an optional text field will appear so you can describe what was wrong or missing

Feedback is used by TRM to improve the Co-Case Agent's recommendations and guardrail accuracy over time. Your feedback is associated with the response type, not with any personally identifiable information.

You do not need to provide feedback on every response. Rate responses when an answer is notably useful or when the Co-Case Agent makes a recommendation you disagree with. Those signals are the most actionable for the team reviewing them.


This article is one part of the Using Co-Case Agent guide, which links to the full set of Co-Case Agent articles.

Did this answer your question?