Investigations
An investigation (or case) is a formal look into why an event happened. You gather a team, collect evidence and hold reviews, work out the root causes, score the risk, and agree corrective actions, which become action items.
Your organization can rename the investigation fields, so the labels you see may differ from the default ones used here. See Investigation settings.
Who can see an investigation
Section titled “Who can see an investigation”An investigation is private. Only the person who opened it and the people on its team can see it; to everyone else, it doesn’t exist. This applies to admins too, because investigations can hold sensitive matters. To give someone access, add them to the team.
Open an investigation
Section titled “Open an investigation”You can open an investigation from:
- Investigations in the sidebar: select New Investigation.
- An event: on the event page, select Actions → Create Investigation. The event becomes the case’s Source Record.
- Several events at once: select them on the Events list, then Actions → Create Investigation. Choose One investigation per report to open a case for each, or One investigation, the rest linked to it to open one case with the first event as its source and the others linked.
- Enter a Title: what is being investigated.
- Choose the Investigation Driver: Actual Severity, Potential Risk, LDAR Reportable or Voluntary.
- Check the Methodology, the root-cause map the case is analyzed against. It starts on your organization’s default.
- Optionally pick the Source Record (the event it’s about), a Facilitator and the role they join the team in, and a Proposed Completion Date.
- Optionally write the Narrative: what happened, in plain words. You can add to it later.
- Select Create Investigation.
If the event already has an open investigation, you’ll see This report is already being investigated. Continue only if this is a separate investigation.
The new case opens at the first status of your flow (Calibration by default).
The investigation page
Section titled “The investigation page”The case page brings everything together:
- Status and Assignee, with a bar showing every status. See Lifecycle and status gates.
- Case Details: the record’s fields and the narrative.
- Concern Reports: the source event and any other linked events.
- Root Cause Analysis, Risk Assessment Matrix and Management Reviews. See Analysis and reviews.
- Activity: the history of the case.
- Investigation Team and Evidence. See Team and roles.
Case Details
Section titled “Case Details”Select Edit on Case Details to change the Title, Investigation Driver, Methodology, Location (the unit, area or equipment the case sits under), Location Note, Management Sponsor, Facilitator, Proposed Completion Date, Report (a link to the final report, once there is one) and Narrative.
The Methodology can be changed until analysis begins: once the root cause analysis has its first causal factor, it’s locked. To change it after that, remove the analysis first.
The Investigations list
Section titled “The Investigations list”The list shows the cases you can see, newest first, with their Title, Source Record ID, Status, Investigation Driver, Location, Facilitator and Proposed Completion Date. Search cases… looks in the title, narrative and Source Record ID. Filter by Status, driver or location.

