Sightings become entities.
Entities become a network.
The network stays accountable.
Resolve selectors — ICAO-hex, MMSI, callsign, plate, a name spelled six ways — to named actors, then map how they connect. Ownership webs, laundering typologies and co-travel patterns render as legible graph shapes; named algorithms and a graph neural network propose, an analyst decides. Organised crime becomes a network you can read — case-bound, mandate-expiring, covered by a court-ready audit.
RESOLVE QUEUE
MERGES · LIVE
Thirty records, one actor.
One person or hull arrives under a hex address, an MMSI, a callsign, a plate, a phone, an IBAN, an email, and a name spelled six ways. Resolution folds them into one canonical entity — scored, banded, and reviewable rather than automatic.
Blocking narrows an astronomically large pair space to a handful of candidates; a calibrated scorer then rates each pair as a probability in [0,1], and the score routes to a band rather than merging on its own.
Deterministic strong keys — a normalised E.164cellphone, an exact ID number — short-circuit to the Strong band, while orthography-aware name indexes co-bucket pairs that plain trigram matching drops across isiZulu, isiXhosa and Afrikaans spellings.
A person-class entity is never auto-merged, even on a perfect deterministic key; the pair is queued for an analyst with both surface forms and the shared address shown.
Every merge is written as a reversible event that re-homes each source record onto the canonical person with provenance intact — an unmerge restores both aggregates losslessly.
SEE ALSO
Selectors arrive already normalised and provenanced from → OSINT
People, companies, and the address that ties them.
Assets sit behind companies, trusts, and nominees; registry linkage turns a name list into an ownership picture. Eleven close corporations at one Umhlanga address, four sharing a director who resolves to a PEP’s relative, seven incorporated in one six-week window with no returns filed — apparent independent bidders collapsing into a single beneficial-ownership cluster.
Juristic entities — Person / Company / Trust / Address / Bank account — are first-class nodes, joined to people by typed directorship / shareholding / trustee edges.
Shared-attribute edges — a shared registered office, a shared director, a shared bank account — are what a spreadsheet cannot hold and the graph makes obvious.
Linking to the company registry (CIPC) resolves who ultimately controls an entity and which entities move together — a controller reads as one actor no matter how many shells front for it.
Incorporation dates, filing gaps and shared registration details are structural tells the ownership graph surfaces directly, without a name in common.
SEE ALSO
Registry records and sanctioned-entity data enter already sourced through → OSINT
Layering, structuring, and the loop that closes.
Laundering hides a controller behind movement, and every typology has a graph shape. Accounts are nodes, payments are amount-and-time-stamped directed edges — so a scheme that looks innocuous one transaction at a time renders as one legible subgraph.
A layering chain is a long thin path: value moves hop by hop through personal accounts, each keeping a slice, before landing in an asset.
A structuring fan-out credits many accounts just under the reporting line, each drained in cash before any per-account rule can accumulate.
A circular flow is a cycle: remittances route back upstream of the controller, closing a loop a linear transaction monitor never joins up.
A pass-through node balances in and out over hours; a mule hub shows high out-degree over a short window — structure exposes what any per-transaction rule is blind to.
SEE ALSO
Transaction and beneficial-ownership feeds arrive sourced and normalised via → OSINT
One operator behind many aliases.
A fraudulent site or scam network leaves an identity-and-infrastructure footprint separate from any legal name. Each reused selector is a weak tie — inconclusive alone, conclusive fused — and the graph draws the aliases, the infrastructure, and the physical selectors that converge on a single operator.
Weak ties — a reused email alias, a handle stem recycled across platforms, a device fingerprint on two accounts — are each inconclusive alone; the graph fuses them into one strong attribution.
Shared infrastructure — a hosting address, a reused TLS certificate, a sibling domain — ties five bank-impersonating phishing domains to one operator.
A single cellphone number appearing in both a domain registration and a legitimate second-hand-car listing is the edge that bridges the anonymous infrastructure to a real name.
Every edge is labelled by what links it — shared-cert, reused-handle, shared-phone — so the reach from a phishing domain to a person is auditable edge by edge.
SEE ALSO
Infrastructure and identity selectors are collected and sourced upstream in → OSINT
Community, centrality, path, prediction.
The pictures above are outputs of named graph algorithms run over the governed store. None of them assert; they scope, rank, and propose — and an analyst confirms every result against source.
COMMUNITY · LOUVAIN / LEIDEN
Partitions a large graph into densely-connected clusters by optimising modularity; Leiden guarantees well-connected communities stable over millions of nodes.
CENTRALITY · PAGERANK / BETWEENNESS
Scores every node by its importance to network flow — degree, the brokers every path crosses, and importance propagated from important neighbours — over the whole graph.
PATHFINDING · BOUNDED k-HOP BFS
Finds the shortest typed-edge chain between two entities, or everything within k hops, via a bounded bidirectional search that meets in the middle and stays fast on a dense graph.
LINK PREDICTION · RANKED LEADS
Scores not-yet-connected node pairs for how likely a real edge is, from shared neighbours and structural proximity, and ranks the proposals the data has not yet drawn.
What the network learns, a human decides.
A graph convolutional network refines each node by aggregating its neighbours’ features — one message-passing step per hop — so after several hops a node’s representation carries the character of its whole neighbourhood. It is deliberately untrusted: the model says this neighbourhood resembles risk; the analyst decides what it means.
The representation feeds two heads: node classification risk-scores an account or entity from the company it keeps, and link prediction proposes probable hidden edges.
A score can flag a laundering-shaped neighbourhood without any single rule firing — which is exactly why it is treated as untrusted, thresholded and routed to review rather than acted on.
Every run is stamped with model name and version; the output is never an authoritative accusation and never an automatic action against a person.
SEE ALSO
Why a model signal can never merge a person or act unreviewed is set out under → GOVERNANCE
Three networks. One graph. Five questions.
The infrastructure, the identities and the ownership ring are not three cases — they are one graph, fused by a few weak ties. Run a different algorithm over it and it answers a different question. Select a lens and watch the same network re-read itself.
Three clusters that most tools keep in three tools — internet-facing infrastructure, fabricated usernames, accounts and IDs, and CIPC beneficial ownership — are one store here, so a lead in one becomes a lead in all three.
A handful of weak ties fuse them: a phone on both a WHOIS record and a car listing, a handle reused as a domain registrant, a controller signing in from a known device. Each is a bridge— cut it and the graph splits back into islands.
The picture never changes; the question does. Community detection draws the boundaries, centrality ranks the hubs, bounded pathfinding returns the typed chain, link prediction proposes the undrawn edge, and the GNN lights a risk field — five reads of one layout.
None of the five asserts. They scope, rank, propose and flag; every edge stays typed and sourced, and an analyst confirms the result against the record before it means anything.
Sanctions and PEP, one hop out.
A resolved entity and its immediate neighbours are screened against a consolidated sanctions and politically-exposed-person set — OFAC, UN, EU, national lists, plus PEP and beneficial-ownership data. What a flat name-list check misses, the neighbourhood surfaces.
Screening runs on the canonical entity, not a surface name, so a spelling variant cannot slip a list.
The walk reaches one hop out to the immediate neighbourhood — a director, a co-signatory, a spouse, a trustee — and is bounded so it stays proportionate.
A clean company surfaces a director who resolves through an isiXhosa variant to a national PEP, and a co-director two hops from an OFAC-listed entity through a shared trust — neither matches the company’s own name.
Every hit returns ranked, with its connecting path shown, for an analyst to confirm or dismiss — never an automatic accusation; the list version is written to the audit spine.
SEE ALSO
Sanctions, PEP and registry sources are ingested and version-stamped in → OSINT
Coincidence, or a relationship.
Under a lawful mandate, link analysis over accumulated sightings turns time-stamped points into behaviour: repeated co-occurrence separates coincidence from relationship. Rendezvous land on one timeline, the shared route on one map — and when the mandate expires the correlation stops and the retention clock starts.
Co-occurrence— two subjects, or a subject and a vehicle, at the same place inside the same short window, repeatedly — is the signal a pair of separate position lists can never show.
It is descriptive of what was observed, never a prediction of intent and never a behavioural score on a person; every point carries its sensor, timestamp, and authorising mandate.
SEE ALSO
The ANPR reads and sightings the temporal read leans on originate in → SENSORS
Every edge lawful, every read logged.
None of this is capability without governance, and the governance is structural, not policy. The four guarantees below hold by construction — they are how the graph operates, not rules layered on top.
A person enters the graph only under a mandate carrying subject, scope, lawful basis, and a hard expiry capped at ninety days the system enforces automatically.
Every access — read as well as write — writes a hash-chained, tamper-evident audit row, so who saw what, and when, is answerable end to end.
Model output is an untrusted feed the analyst confirms; a merge, a screening hit, and a pattern are all analyst-confirmed and reversible — and person risk-scoring is excluded by construction.
A query that would cross a tenant boundary or run without a lawful basis does not execute — governance the graph cannot express its way around.
Resolve the selector, map the network, keep the audit.
Talk to our team about a Graph Intelligence walkthrough — entity resolution over your selectors, link analysis across your area of operations, and a governance review against POPIA.