Turn on Forensic Mode for defensible records
Forensic Mode is the property of a Case that decides whether your search leaves a durable record. Turn it on before you begin collecting, and the Case retains your bookmarking and history and preserves a chain-of-custody. Leave it off — a Private case — and the Case keeps nothing.
This guide explains what Forensic Mode does, how to enable it per-Case in Case Management, and why the order of operations matters.
What Forensic Mode does
Section titled “What Forensic Mode does”Forensic Mode is set individually on each Case (per Lee, 2026-07-08):
- Forensic Mode ON — the Case retains bookmarking and history and provides chain-of-custody. This is the evidentiary, audit-trail-preserving mode.
- Forensic Mode OFF (a Private case) — the Case keeps no bookmarking and no history. It is effectively ephemeral and records nothing.
The trade-off is simple: audit-trail retention plus chain-of-custody with Forensic Mode ON, versus an ephemeral private case that records nothing with Forensic Mode OFF.
Enable before you collect
Section titled “Enable before you collect”Enable Forensic Mode on the Case before you run the searches you intend to preserve. A Case with Forensic Mode OFF keeps no bookmarking and no history, so anything you collect while it is off is not retained (per Lee, 2026-07-08). Turning the switch on afterwards does not recover work already done in an ephemeral state.
The sequence you want:
- Create or choose the Case for this search.
- Turn Forensic Mode ON for that Case.
- Then begin searching, bookmarking, and building Reports.
Turn on Forensic Mode in Case Management
Section titled “Turn on Forensic Mode in Case Management”Forensic Mode is toggled per-Case from the Case Management modal.
- Open Case Management from the left navigation.
- Locate your Case in the case table.
- In the FORENSIC MODE column, set that row’s switch to on (orange).

Each Case in the table has its own FORENSIC MODE switch, so you can run one Case as an evidentiary case and another as ephemeral. In the captured state, every Case row shows this switch in the on (orange) position.
The case table
Section titled “The case table”The Case Management table lists your Cases with these columns:
| # | NAME | CREATED AT | SHARE | FORENSIC MODE | PRIVATE KEY | ACTIONS |
|---|
- # — a numeric Case ID for Cases you create; the built-in Default Case shows N/A.
- NAME — the Case name.
- CREATED AT — when the Case was created.
- SHARE — the Case’s visibility, Private or Public.
- FORENSIC MODE — the per-Case switch described above.
- PRIVATE KEY — a status indicator for the Case’s key.
- ACTIONS — per-row actions such as Edit Name, Set Password / Change Password, and Delete Case.
Use + Add Case (top-right of the modal) to create a new Case, and Close (bottom-right) to dismiss the modal.
The Default case
Section titled “The Default case”Every account begins with one built-in Default Case. It behaves differently from Cases you create:
- It cannot be renamed — there is no Edit Name action.
- It cannot be deleted — there is no Delete Case action.
- Its SHARE state is fixed text “Private” rather than an interactive toggle.
- Its # shows N/A rather than a numeric ID.
It can still have Forensic Mode set and its password changed via Change Password.
Private vs Public Cases
Section titled “Private vs Public Cases”The SHARE column controls a Case’s visibility: Private (restricted) or Public (shared). A switch in the off (grey) position corresponds to a Private, not-shared Case.
Case sharing is a team-account capability, controlled by a team leader (per Lee, 2026-07-08):
- Team accounts can share Cases among team members, share one common pool of Credits, and are controlled by a team leader.
- Single accounts do not share Cases.
Private key and Case passwords
Section titled “Private key and Case passwords”The PRIVATE KEY column shows a status check for each Case, and the ACTIONS column offers Set Password (for a Case with no password yet) or Change Password (for a Case that already has one).
Setting a custom password on a Case is what creates that Case’s private key: the encryption key is derived from the password you choose. That password encrypts the Case’s Bookmarks on the UserSearch server, so the saved Bookmarks are stored encrypted rather than in the clear, and UserSearch holds neither the password nor the derived key. (per Lee, 2026-07-10)
What the status check in the PRIVATE KEY column indicates — in particular the green-versus-white variant — is not documented beyond the facts above.
Working within a Case
Section titled “Working within a Case”Once Forensic Mode is on, your Case groups the artefacts of the search:
- Bookmarks and Reports are the saved artefacts a Case collects; their retention depends on Forensic Mode being ON.
- History — the search and login record a Forensic-ON Case retains.
- A FILTER BY CASE dropdown on the Bookmarks, Reports, and History surfaces scopes those views to a single Case.
- The Case Summary panel aggregates per-Case totals — NUMBER OF BOOKMARKS, REPORTS CREATED, and LAST UPDATE — so you can confirm a Case is accumulating the record you expect.
Verified against UserSearch v2.0.20