Investigation tasks
Tasks turn an investigation plan into accountable work. A task contains a title, optional description, optional assignee, optional due date, status, and a flag that marks it as required.
Task statuses are PENDING, IN_PROGRESS, COMPLETED, and CANCELLED. Required tasks prevent resolution while they
remain pending or in progress. Cancelling a required task should follow the institution's exception policy and be
explained in an investigation note.
Use tasks for concrete actions such as:
- Review the customer's KYC history.
- Compare a counterparty across related transactions.
- Request a source-of-funds document.
- Obtain MLRO review.
- Confirm whether a restriction was applied in the core banking system.
Investigation notes
Notes are append-only and support four types:
| Note type | Use |
|---|---|
INVESTIGATION | Analysis, observations, and evidence interpretation |
DECISION | The reasoning supporting an investigation decision |
ESCALATION | Why the case moved to another team or senior reviewer |
CORRECTION | A correction that preserves, rather than overwrites, the earlier note |
Write factual notes that distinguish source data from analyst conclusions. Do not place credentials, unnecessary personal data, or unverified allegations in free text.
Timeline versus notes
The timeline and notes serve different purposes. Notes contain authorized analyst-authored investigation content. The timeline records system actions such as creation, assignment, status changes, evidence links, and task changes. A timeline event includes a sequence, actor, action, summary, timestamp, previous hash, and event hash.