Outcome · Fraud and SIU
The investigation that recovers the money is the one most likely to be thrown out for how it was run.
Open-source collection on a claimant is lawful in narrow circumstances and unlawful just outside them. The line is drawn by what was authorised, by whom, how far the collection went and how long the material was kept — and none of that is usually written down while it is happening.
The one metric
No pilot has run, so the slot is empty. It will be calibrated against a paired baseline in the first pilot cohort — the same referral mix, the same period, one lane governed — because a recovery figure with no baseline beside it measures the referrals, not the method.
The one mechanism: authorisation before collection, not after the dispute
The authority to look is a recorded decision with a named owner, taken before the first query runs. It states the grounds, the scope and the expiry, and it is part of the file from the beginning rather than an account of it written later (UC015).
Every external tool call lands in the investigation trace with its provenance, so what was searched, when, and against which source is legible without reconstructing an analyst’s browser history (UC025).
Retention limits attach to the material at collection and expire on their own. A retention policy that depends on someone remembering to delete something is the one that fails at exactly the moment it is examined.
The European Court of Human Rights has already held that covert surveillance of a claimant by an insurer can violate the right to private life. The control that survives that judgement is a record of authorisation and scope made before the collection, not a justification assembled after the dispute.[V]
[O]ROS/src/routes/osint*.ts
[O]NX/services/nexus-workflows/src/services/tool-executors/
Convening Triage + Graduated Escalation
A meta-decision agent scores each submission or claim and convenes the right room, the right chair and the right autonomy tier — and the routing decision is itself a logged event.
shipped(shipped)One-Log, Many-Regulator Evidence Fabric
One governed event stream compiles into every regulator’s artefact, instead of four teams reconstructing four different stories from the same week.
shipped(shipped)The one honest bound
WHAT THIS DOES NOT DO YET
- Tiers 3–5 of the dispatch ladder. Tiers 1 and 2 run in production.
- The jurisdiction-pack emitters.
Read plainly: the collection connectors, the trace and the recorded authorisation run on the two dispatch tiers that are in production, and the tiers above them are designed. The per-regime renderings of an investigation file are not built either, so a data-protection request today is answered from one complete stream by a person rather than compiled.
REFUSED
AUTHORITY_EXCEEDED
Collection outside the recorded authorisation does not proceed and get flagged afterwards. It refuses, names the authority it exceeded, and the refusal stays in the file.
An investigation is judged on the boundary it respected, and a boundary is only evidence if crossing it leaves a mark. A refusal in the file is worth more to your legal team than a clean file with nothing in it.
Start with the referrals you already make
Nothing about this changes which claims your model refers. It changes what exists afterwards: an authorisation with a name on it, a scope that was set before the search, and material that expires without anyone having to remember it.