Aletheia on Symplast — Volume Report Triage

It's like standing under a waterfall, trying to catch it all in a teacup. — Director, Intelligence Triage

01 — The Problem: First In. First Out. Last To Know.

The problem isn't only the volume. You can't catch the whole waterfall. But right now nobody's choosing which drops to catch either. You are catching whatever fell first.

Hundreds of reports land every day. They get read in the order they arrived. Nobody chose that order. The queue chose it.

The Queue — Reading in arrival order isn't triage. It's just what happens.

Here is a day's inbound. An ID, a time, and a subject line someone typed at registration. Nothing on the screen says which of these matters. So the analyst starts at the top.

Eight reports, in the order they were filed. The two-paragraph tip at 13:47 looks like the weakest thing on the list. It is also the seventh thing anyone will read.

When scored by consequence, RPT-04223 moves to the front. It names nobody on a watchlist, so no rule would have caught it. It scores highest because of what it touches: an address you hold under an active priority, a vehicle two steps from a live target, and the third mention of the same associate in 90 days. In arrival order, it was seventh.

02 — The Cost: Working the queue in order costs you four things.

None of them show up as an incident. They show up later — in a review, in a coronial finding, in a question about what you held and when you held it.

Cost 01 — Time you can't get back

The urgent report and the routine one wait the same length of time, because nothing has told anyone which is which. Speed goes to whatever arrived first.

Cost 02 — Links nobody makes

A name here, a vehicle there, a payment three months later. Each looks minor on its own, so each is treated as minor. The risk you act on today was built out of reporting you already had.

Cost 03 — An answer you can't give

Asked why one report was actioned in a day and another sat for three weeks, the honest answer is that it arrived first. That is hard to say to a court, and impossible to fix, because nothing was written down.

Cost 04 — Risk you shouldn't have to carry

The longer a high-consequence report sits unread, the more it weighs on you. Decisions made on arrival order are decisions nobody actually made — and the risk of that lands on the analyst, not the queue.

03 — What It Takes: To sort reports by what matters, you need four things — at the same time.

Each is common on its own, and most centres already have something that does one of them. The queue only moves when all four work together, on the report's first pass.

Test 01 — READ: The words, not the fields

Reports are written by people, in whatever format and language their agency uses. Names, vehicles, accounts, places and events have to come out of that writing as it lands — including the ones nobody planned for.

Test 02 — CONNECT: To everything you already hold

A report is rarely dangerous on its own. It is dangerous because of what it connects to — a watchlist, a live operation, a fragment filed months ago. Those connections sit in a graph, or they don't exist.

Test 03 — WEIGH: Your call on what matters

What counts as important is your judgement, and it changes with the mission. You have to be able to change the weighting yourself, this week, without raising a ticket with a vendor.

Test 04 — SHOW: The working, every time

If an analyst can't see why a report scored high, they will open it and check — and you are back to reading in order. Every factor has to point at the sentence, page and document behind it, and still do that in two years.

Three out of four gets you a ranked list nobody trusts and everybody double-checks. All four have to work at once, on one system, inside your boundary.

04 — Why It Persists: You probably already bought something meant to fix this.

The queue is still in arrival order. Not because these tools are bad. Each does its own job. Each one stops at a different test.

Approach 01 — Keyword Rules

A rule only fires on what someone already wrote down. Flags reports containing words on a list — names, addresses, offence codes. Cheap, fast, and every centre has one. The report that matters most usually mentions nobody on the list. It's a new name, two steps from a live target, described in words no rule was written for. Stops at: READ, CONNECT.

Approach 02 — Search

Search answers questions. Triage is not knowing what to ask. Indexes everything you hold so an analyst who knows what they want can find it. The report nobody has read is the one nobody thinks to search for. Stops at: CONNECT, WEIGH.

Approach 03 — Case Management

It counts the queue. It doesn't read it. Records what arrived, what's open, what's overdue and who holds it. Priority is whatever someone picked from a dropdown at registration. Stops at: READ, CONNECT, WEIGH.

Approach 04 — AI Summaries

It judges the report against itself. A model reads each report and returns a summary, sometimes a risk rating. It only sees the one report. The thin tip that connects to a live network reads thin, so it scores thin. Stops at: CONNECT, WEIGH, SHOW.

Approach 05 — Model-First Graph

The model has to be agreed before the first report is scored. Maps the domain first — entities, types, relationships — then loads reporting into that structure. Agreeing the model is a programme: workshops, sign-off, migration, all based on predicting what future reporting will say. Stops at: READ — anything the model didn't predict.

05 — How It Works: One report, from the moment it lands to its place in the queue.

Symplast builds and holds the graph. Aletheia is the layer that weighs each new report against it. Five stages. None of them hidden. No score without its sources.

Stage 01 — LAND

The report arrives in whatever form you receive it. OCR handles mixed formats. Page numbers, headings and the exact location of every passage are kept.

Stage 02 — READ

People, companies, vehicles, accounts, places and events are pulled out of the text. The categories come from what the reporting actually says, not from a schema agreed in advance. Each one is tied to the sentence it came from.

Stage 03 — MATCH

Is this the same person you already hold? Several independent signals vote on the answer. Confidence is measured, not assumed. The analyst can merge, split or overrule.

Stage 04 — SCORE

The report is weighed against the graph: your active priorities, watchlist hits, how close it sits to known networks, and timing. 17 graph algorithms do the work. You set the weightings.

Stage 05 — SHOW

The queue reorders. Every position comes with its reasons: the score, the factors that made it, and the document, page and line behind each one.

Test 01 / READ — No modelling phase to sit through

Categories come out of the reporting instead of a committee's guess about it. A report using words nobody had a field for still gets read, sorted and scored — on day one, not after an eighteen-month schema project.

Test 02 / CONNECT — A graph, not a filing cabinet

Graph features bolted onto a document store can't answer multi-step questions, and that's exactly where risk hides: the tip that means nothing on its own and a great deal two steps out. Symplast is a graph at its core, so a new report is scored against everything, not against itself.

Tests 03 & 04 / WEIGH · SHOW — Your analysts stay in charge

The model proposes, the system checks, the analyst decides — confirming, overruling, changing the weights. Every fact links back to the passage it came from, and every change goes into a ledger nobody can edit. Ask what the system held to be true last March and you get the answer, not an estimate.

Aletheia on Symplast passes all four tests: READ, CONNECT, WEIGH, SHOW.

06 — One Score, Explained: Why this report went to the top.

The two-paragraph tip, source not named, filed seventh. Nothing in it stands out. What it touches does. RPT-04223 scores 95 (HIGH). No name in it is on any list, so no rule would have fired. On its own it's a thin document filed mid-afternoon. Against the graph, it's the first report to put two separate holdings in the same place in the same week.

07 — Evaluate: Five questions to ask of any intake and triage system.

  1. Does it read the words, or only the fields? If it only works on structured metadata, it misses everything that wasn't planned for. Reports are written by people. The system has to read them.
  2. Does it connect, or just collect? A pile of reports is not intelligence. A report is only dangerous in relation to what you already hold. If it can't ask the graph, it can't find risk.
  3. Can your analysts change the weighting? If what counts as important is fixed by a vendor, it's not your triage — it's theirs. You have to be able to change the weights this week, yourself.
  4. Does it show the working? A score with no sources gets checked by hand. That is the work you were trying to skip. Every factor has to point at the sentence, page and document behind it.
  5. Do all four work at once, on one system, inside your boundary? Three out of four gets you a ranked list nobody trusts. The fourth test is the one that makes the other three usable.

08 — Deployment: The data is yours. The decisions are yours. Nothing leaves.

Aletheia runs on Symplast, inside the fusion centre. On your infrastructure, under your control, behind your accreditation boundary. Air-gapped, on-premises, or sovereign cloud at the customer's discretion. No tenancy in foreign clouds.

Deployed in your tenancy

Integrates with existing case management, records and partner-agency intelligence systems through standards-aligned data exchange. Role-based access and disclosure controls are first-class concepts.

The pilot is the deployment

Because the ontology is produced from the data, there is no separate ontology phase to fund and wait through. We deploy forward, work alongside your operators, prove the capability on your data.

Deployment modes: Air-gapped, On-premises, Sovereign cloud.

Sovereign Australian Capability

Aletheia on Symplast is sovereign Australian capability. The code, the data and the decisions stay onshore — under Australian law, under Australian accountability. Built in Australia by Australian-owned companies whose founders come from government, law enforcement and national security backgrounds. Australian-owned. Australian-built. Informed by lived experience.

Symplast is patent-pending technology of Psithur Holdings Pty Ltd.

Contact

People Tools Instructions Pty Ltd. Request a briefing to learn how Aletheia on Symplast can be deployed in your fusion centre.

The full machine-readable content snapshot is also available at /content.html .

Volume Report Triage

A high-performance intelligence fusion platform designed for secure, sovereign data triage and executive briefing.