Observer

Investigations and the watchlist

Some harm never trips a per-message filter: grooming, harassment campaigns, radicalization — patterns that only exist across dozens of messages and days of time. Investigations are Observer's long-form layer.

Cases

An investigation is a case file: a subject (an actor, a cohort, or a channel), a time window, the pattern types in question, priority, an assignee, and notes. Open one manually from the Investigations page — or Observer opens one automatically when screening severity, category signals, or a watchlist hit warrants a deeper look.

Scans

A scan hands the subject's message history (bounded to a window of up to 90 days) to a pattern-specific AI scanner. Scans run in the background; each records its model, cost, and confidence on the case.

Findings — verdicts you can verify

A finding names the pattern, its severity and confidence, the actors involved, and — the part that matters — citations: exact quotes with the reason each one is relevant. A verdict you can't verify is a verdict you can't act on, so findings carry their evidence. Findings land in the moderation queue like any other flag, and acknowledging them there resolves them on the case.

The watchlist

The watchlist is per-actor attention: put a handle on it with a reason, and optionally a scan cadence so Observer re-scans them on a schedule (or leave it manual). Watchlist additions and removals are recorded — who, when, why — because surveillance of a specific person is a decision that should leave a trail.

Investigations follow the same principle as everything else: Observer assembles evidence, humans decide. A finding is never auto-enforced.