Why map an investigation
A table lines objects up side by side. An investigation is about what happens between them. Here is the moment a list stops being enough, what a map brings out, and the cases where it is useless.
The moment a list stops being enough
The first hours of an investigation fit in a text document. A dozen names, a few links, two or three open questions. The spreadsheet comes next, and it holds for a while.
Then something breaks. It is not the volume, it is the nature of what you are handling. A table lines objects up side by side. An investigation, though, is about what happens between the objects: who controls what, who registered that domain, which company shares an address with which other. That information has no column. You put it in a comment, then you forget it.
The sign that it is time to change form is always the same: you open your file and it takes you several minutes to work out why two rows sit next to each other.
What a map brings out
A map puts each piece of information somewhere and makes the link visible. Three things follow that a table does not give you.
The clusters. When linked entities are pulled together, the groups become visible to the naked eye. Five companies sharing an address and a director form a patch, not five distant rows.
The choke points. Some entities concentrate the links. An email address present everywhere, a person at the centre of three structures: those are your pivots, and a map points at them without you having to count.
The gaps. A table never shows what is missing. A map does. Two groups that do not touch although you believe they are connected, an isolated entity nothing attaches to: those are tasks the form puts in front of you.
The three objects on a map
An investigation map needs only three notions, and it is better to stick to them.
The entity. An object in the real world: a person, a company, a domain, an address, a document. It carries a kind, because the kind decides which fields mean anything for it. A domain has a host and a creation date, a person does not.
The link. The relationship between two entities, with a name and often a direction. “Controls”, “employed by”, “registered to”, “located at”. The name of the link is what turns a drawing into a statement.
The field. What you know about an entity, and above all where you know it from. That is where the source, the date of consultation and the exhibit number belong.
The glossary covers these terms and the rest of the craft’s vocabulary.
Name the links, every time
This is the simplest rule and the most often skipped. A line between two entities that does not say what it represents will be useless to you in six weeks, and useless to anyone else.
A named link does three things at once: it forces you to decide while the information is still fresh, it makes the reasoning readable by someone else, and it lets you spot the links you cannot qualify, which are precisely the ones worth digging into.
If you hesitate between two wordings, take the more cautious one. An “in contact with” link you later refine into “employed by” beats an “employed by” link you will not dare correct.
When a map is useless
It is worth saying plainly: the form is not always the right one.
- When you are after a value, not a structure. Comparing amounts, sorting dates, taking an average: a table stays better.
- When there is no relationship. A list of three hundred unconnected customers does not get clearer as a graph, it becomes a cloud.
- When the question is already settled. Mapping after the fact to illustrate a conclusion produces a pretty diagram and teaches nobody anything.
The map serves during the investigation, to think with. The final diagram is only a by-product.
The usual traps
Putting everything in. A map is not a warehouse. Whatever does not answer the question clutters it and makes it unreadable.
Confusing position with meaning. Two entities sitting next to each other on screen are not connected for that reason. Only the line says something, and only its name says what.
Forgetting sources. A map without references is an opinion drawn out. It will not hold in front of a demanding reader.
Stopping at the first layout. The same map rearranged differently shows something else. The method sets out the four useful layouts and when each one helps.
Move from reading to mapping.
Ositra brings your entities and their links onto one surface, on your own computer.
Open Ositra