Skip to main content

Investigating an incident

Investigations are the structured workflow that runs after an incident is substantiated. Each investigation has its own code, an investigator (internal or external), a workflow with statements and findings, and a defined start and end.

Written by Taylor Laing
  • Each investigation has a code (for example, INV-2026-0001) and links to its parent incident.

  • Investigators can be internal users or external firms (shown with an External tag).

  • Multiple investigations can run against a single incident.

  • An investigation moves through defined states and can be completed with a final outcome.

Opening investigations

Go to /app/identification/investigations. The page shows a status bar with counts, a filter and sort bar, and a list of investigations, each with its code, parent incident, date opened, investigator, and status. Click any row to open it.

What an investigation contains

An open investigation runs across several tabs:

Tab

What it covers

Overview

Investigation details (status, investigator, dates) and the parent incident's details

Findings

Root cause analysis, contributing factors, and corrective actions

People & Statements

Witnesses, parties involved, and statement-collection progress

Tasks

Tasks linked to this investigation

Comments

The discussion thread

Activity Log

A time-stamped history of changes

A set of cards across the top summarises the status, the outcome, the investigator, the start date, and progress on collecting statements.

Tab labels: The exact tab names may differ slightly in your tenant. Use the live investigation page as the source of truth for the current labels.

Investigation status and outcome

An investigation's status moves through Pending, In Progress, Awaiting Review, Completed, and Closed. Separately, its outcome records the conclusion: Substantiated, Unsubstantiated, Inconclusive, or Withdrawn. Status is where the work is up to; outcome is what the investigation found.

Sensitive investigations and access

Investigations often involve sensitive personal information. Where a report is sensitive, the underlying incident can be flagged Restrict Access during triage, which limits who in your organisation can see it. Combined with the consent trail on the incident, this is how ReFresh keeps an investigation defensible while protecting the reporter and the parties involved. See Triaging an incident for setting the Restrict Access flag.

External investigators

Some investigations are run by external firms. When an external investigator is assigned, an External tag appears next to their name. External investigators can record their work directly in ReFresh, or an internal admin can record on their behalf, depending on your organisation's setup.

Linking back to risks and controls

Investigation findings link back to:

  • The risks on your register, so post-incident learnings update risk ratings.

  • The controls that were meant to mitigate the hazard, so their effectiveness can be re-rated through a Review.

This linkage is what produces the audit trail regulators look for: a clear line from an event, through the investigation, to the changes it drove.

Completing an investigation

Once findings are documented and corrective actions are assigned, select Complete Investigation at the top of the investigation page. This records the completion date, sets the outcome, and can trigger follow-up tasks for control updates and consultation.

Did this answer your question?