Cases
A case gathers an incident into one record: what happened, the evidence, who worked it, and what was concluded.

Why cases exist
Investigations produce material scattered across places: a video export in a downloads folder, a screenshot in an email, notes in somebody's head. Six months later, when it matters, none of it is together and half is gone.
A case is where that material lives instead — with the notes explaining why each piece is there.
What is in one
| Creating a Case | Opening one and describing it |
| Working a Case | Media, comments, people and review status |
| The Activity Log | Recording what you did while you did it |
| Exporting a Case | A package for somebody outside eConnect |
Cases and the Workspace
They are complements, not alternatives.
| Workspace | Case | |
|---|---|---|
| Purpose | Your working thread | The permanent record |
| Audience | You, and colleagues you share with | Whoever handles this incident later |
| Content | Where you have been | What you concluded, and the evidence |
| Lifetime | This investigation | Indefinite |
Work in the Workspace; record in a case. The Workspace remembers your route, the case holds what came out of it.
Finding the cases you want
Cases carries the same Query Manager as the other modules, so a case search worth repeating is saved, shared and run by name rather than rebuilt. The sidebar scopes the list to a saved query, and the ordinary filters narrow it further.
With media only is the filter worth knowing about: it reduces the list to cases that actually have clips or images attached, which is usually what you want when you are looking for evidence rather than for a record.
The date window
The case list covers a period, shown on the header control, and the KPI tiles above it count the same period. All time is one of the choices, and it is the one to reach for when a case you know exists is not in the list.
The window travels in the address, so a link to the case list carries the period you were looking at rather than dropping the reader on a different one.
Counting cases rather than reading them
The Cases home page carries the same Results / Aggregate toggle as every other module grid. Aggregate groups the case list by whoever created it, its type, status, location or resolution, or by the hour, day, date or month it was created or last updated — and each group drills through to the cases behind it.
That turns the case list into a management view without exporting anything: how many cases were opened per shift, which locations produce most of them, how resolutions divide. See Aggregation for how the panel works; it behaves here exactly as it does elsewhere.
Attach evidence properly
Video exports, images and documents belong in the case, not in a downloads folder.
An exported clip on somebody's desktop is outside eConnect's permission system, unattributed, and gone when the machine is replaced. The same clip attached to a case is where the next person will look for it.
See Exporting Video, which offers Export to Case directly.
Everything is recorded
Case work is comprehensively audited — creation, updates, media added and removed, review, and every activity-log action. The full list is in the Audit Catalog.
That record is what lets a case stand up later: not just what was concluded, but who did what and when.
Audit record
What eConnect writes to the audit trail for the actions on this page.
CLOSED CASE {number}: {incident name}