Follow one evidence request from case to courtroom-ready record.
See who acts at each point, what safeguards apply, and which accountability record is created. The journey follows a fictional investigation and contains no production data.
Six steps. Clear responsibility at every hand-off.
Choose a step or use the controls to move through the journey in order.
Guided walkthrough
of 6
Step 01 · Case foundation
Open the case
Responsible: Police investigator
The journey begins with an authorised investigation, not a free-standing search for personal data. The investigator records the case context before requesting evidence.
What happens here
Create a case reference and concise investigation summary.
Record the investigating unit, priority and responsible officer.
Identify the suspected fraud pattern and relevant subjects.
Step 02 · Scoped evidence request
Build the request
Responsible: Requesting officer
The officer turns the investigative need into a specific, reviewable request. Broad or vague collection is avoided by defining exactly what is required.
What happens here
Select the target, data categories, providers and date range.
State the legal basis, purpose, urgency and retention need.
Attach supporting authority and submit for independent review.
Step 03 · Independent decision
Review legal authority
Responsible: Legal reviewer
An authorised reviewer checks whether the proposed collection is lawful, necessary and proportionate before any provider receives it.
What happens here
Examine the legal basis, requested period and supporting documents.
Compare the requested records with the stated investigative purpose.
Approve, reject or request clarification with recorded reasons.
Step 04 · Controlled provider response
Respond within scope
Responsible: Data provider
Only the approved provider receives the authorised request. Its response is tied to the approved data types, subject and period.
What happens here
Review the approved scope and response deadline.
Prepare only the records covered by the authorisation.
Return an encrypted response package through the controlled channel.
Step 05 · Evidence integrity
Verify and preserve
Responsible: Evidence officer
The received package is checked and preserved before investigative use. Every handling event extends the chain of custody.
What happens here
Confirm the package source and cryptographic integrity details.
Record collection, receipt, verification and storage events.
Protect the original item while controlling access and downloads.
Step 06 · Investigation and oversight
Analyse and account
Responsible: Investigator and auditor
Authorised teams can use verified evidence while oversight staff retain a complete view of access, decisions and custody activity.
What happens here
Connect evidence to the case and examine relevant relationships.
Prepare a case report without altering the preserved source item.
Review access history, decisions and custody events for accountability.