Every investigation has a turning point.
Perhaps it’s a phone recovered during a search, a vehicle sighting, or just a name appearing in an unexpected place. Those moments may seem obvious in hindsight, but at the time, they were just another piece of information flowing through a busy team.
Huge volumes of information sit in siloed systems that were never designed to connect: case management platforms, digital forensics tools, company registries, suspect databases. And new information continues to arrive throughout the lifetime of an investigation, but it is often incomplete, messy, and out of sequence.
Successful investigations recognise those turning points while there’s still time to act. But new information rarely arrives with a label saying “this changes everything”. Its significance only becomes clear when it is seen in the context of everything else an organisation already knows.
And the organisation often knows more than it can use.
Huge volumes of information sit in siloed systems that were never designed to connect: case management platforms, digital forensics tools, company registries, suspect databases. And new information continues to arrive throughout the lifetime of an investigation, but it is often incomplete, messy, and out of sequence.
Important decisions about public safety cannot wait three days for people to search across systems and reconcile spreadsheets. By the time the connected intelligence picture becomes clear, the opportunity to take action may already have passed.
We think of this as the investigation gap: the time between new information becoming available and its significance becoming clear.
When the investigation gap is narrow, teams are better placed to identify suspects earlier, share intelligence more effectively, and ultimately help keep societies safe.
When the investigation gaps widen, links are discovered too late (or not at all), and dangerous criminal networks remain active for longer.
At a time when policing organisations need to do more with fewer resources, facing increasingly complex crimes, reducing the investigation gap is an operational necessity.
Why does the investigation gap exist?
The investigation gap exists because policing organisations work with fragmented, disconnected data. Each system can answer its own question correctly, but nothing exists to answer the question that matters most: “How does this new detail change what we already know?”
That question requires a connected approach to intelligence, one that can bridge the gaps between systems and work across organisational boundaries.

The operational understanding required to turn fragmented, reactive units into proactive, intelligence-led forces cannot be built one record at a time. Knowing whether two investigations are connected, how a criminal network operates, and where resources should be allocated requires reasoning across relationships, rather than isolated records.
Building the connected intelligence picture
This is where graph technology changes the nature of intelligence analysis. Unlike traditional data architectures that primarily work with records, graph technology is designed around relationships in data, making it possible to understand how people, organisations, devices, locations and events connect.
Instead of leaving information scattered across disconnected systems, a graph intelligence approach unifies intelligence as a single knowledge layer that forms the basis of operational intelligence analysis.

As new information arrives, it is integrated into an evolving graph-based network of people, devices, vehicles, organisations, locations, and events. Teams don’t have to build the network manually. It’s already there, ready to be searched and explored.
Organisations keep using the systems they already trust, but gain the ability to reason across them at pace. Because the knowledge layer is grounded in structured relationships, leaders can quickly get answers to questions that would otherwise require days of manual analysis.
That doesn’t mean the analysis is done automatically. No system should tell an investigator or analyst what to think. But they can reduce the hours spent researching and collating. Instead of repeatedly asking “where have I seen this before?” analysts can focus on understanding how the intelligence picture has changed, and what action that change calls for.
Understand the network, not just the case
In a time-pressured policing environment, it’s often easy to treat every investigation as a self-contained problem.
Operationally, that’s unavoidable. Teams are assigned to investigate specific offences. Cases have defined boundaries. Evidence is seized for specific purposes.
But while investigations often have clearly defined boundaries, criminal networks do not.
The same suspect may be connected to multiple different offences. Their vehicle might turn up in a drugs investigation, and a year later in a firearms enquiry. Their money laundering infrastructure could be owned by a network of seemingly disconnected shell companies.
The right tools can close the investigation gap by creating a connected intelligence picture that reveals the wider criminal networks behind individual investigations, enabling earlier intervention, stronger collaboration across teams and agencies, and more effective disruption of crime.
A practical example
Imagine two separate investigations into serious organised crime.
One centres on a series of drug seizures. The other focuses on suspicious financial activity involving a complex network of shell companies. On the surface, they appear unrelated. Different suspects. Different offences. Different investigation teams.
Viewed independently, neither investigation reveals much about the wider organisation behind the activity.
A graph-powered approach allows investigators to bring information from both inquiries into a connected intelligence picture, combining arrest records, seized devices, vehicle movements, financial intelligence, and previous investigations.
As relationships begin to emerge, so does the network itself.

A mobile device recovered from Kai in one operation is linked to a suspect, Dana, in the other. The two also control a Luxembourg-based shell company. A recurring individual, previously considered peripheral, turns out to connect people, companies, and devices across the wider network.

What initially looked like two separate operations is revealed as a single criminal enterprise.
More importantly, investigators can now move beyond identifying individual offenders to understanding how the organisation functions. Rather than repeatedly targeting those carrying out day-to-day criminal activity, they can identify the main coordinators, facilitators, and shared infrastructure that enable the network to operate.
Leaders can focus resources on the people and assets that matter most, different agencies can coordinate activity around a shared intelligence picture, and disruption efforts can be aimed at the structure of the organisation rather than its individual members.
AI needs connected intelligence
As policing organisations increasingly adopt AI, the investigation gap becomes even more important.
Used well, AI doesn’t replace the analyst. It helps them make sense of vast, complex operational information, surface connections worth investigating, and accelerate the development of intelligence.
But AI inherits the same limitation as human analysts: it can only reason over what it can see. When pointed at fragmented, siloed systems, AI may well fill the gaps with hallucinations.
Connected intelligence changes that. When information is unified, AI can follow the relationships across sources and ground what it surfaces in the organisation’s collective knowledge rather than isolated pieces of information.
Importantly, the analysts still decide. They review the connections, assess their meaning, and recommend whether to act.
That’s human work because a machine cannot be held accountable for the crucial decisions being made. Especially when those decisions may have significant consequences for individuals and communities, or ultimately be scrutinised in court, challenged by defence teams, and reviewed by oversight bodies.
The standards AI must meet are the same ones analysts hold themselves to. If analysts are answerable for their output, they need to be able to verify what AI puts in front of them and how it got there. If a connection cannot be explained or traced, it becomes a liability.
This is another advantage of a connected approach. When information and the relationships between it are brought into a single operational picture, every entity and relationship can be connected to its source and quality. So when AI surfaces something, the chain behind it is already there to be examined.
Analysts can understand and explain how a conclusion was reached, giving them confidence in the intelligence they produce. Trust is a consequence of the architecture, not a feature bolted on afterwards.
Closing the investigation gap
Organisations already hold enormous amounts of valuable information. Every day, more arrives. The question is how quickly that information can be understood in relation to everything that has come before it.
The investigation gap is not measured by how quickly information enters the organisation. It’s measured by how quickly the investigation team can use that information to change the intelligence picture.
The longer that process takes, the wider the gap becomes.
Ultimately, intelligence work has always been about driving better decisions. The faster teams move from isolated facts to a coherent understanding of the network behind them, the sooner those decisions can be made.
Learn more
Every policing organisation faces its own version of the investigation gap. The technology, data landscape and operational challenges may differ, but the underlying question remains the same:
How quickly can your organisation turn new information into operational understanding?
To learn how this approach is being applied across policing, intelligence and public safety, visit the GraphAware website: https://graphaware.com/
About the author
Luanne Misquitta leads Neo4j’s global public sector practice. With more than 18 years’ experience delivering graph technology in production, and as co-author of Neo4j: The Definitive Guide (O’Reilly), she advises government organisations on applying connected intelligence to mission-critical operations.
