DAC | Digital Asset Claims

Evidence Graphs · 6 April 2026 · 8 min read

How Evidence Graphs Connect Digital Records

By Digital Asset Claims Research Desk·Investigation Team

  • Digital Evidence
  • Evidence Graph
  • Methodology

Evidence graphs give investigators, and readers of their reports, a structural way to see how digital records connect, without flattening every relationship into a single confident narrative line. This article explains how they are constructed and used.

A graph shows relationships and their supporting evidence side by side, which a linear narrative often cannot do as clearly.

Entity relationship map connecting multiple record types
Each connection in an evidence graph is tagged with its supporting evidence and confidence classification.

Nodes: representing discrete entities

Every node in an evidence graph represents a single, discrete entity, whether that is a wallet address, an exchange account, an email address, or a piece of infrastructure such as an IP address or autonomous system number.

Each node carries attributes sourced directly from verified records, and the source of each attribute is retained alongside it, so any later reviewer can check exactly where a given detail came from.

Nodes are added to the graph only once their underlying data has been verified, which keeps the graph's structure grounded in checked evidence rather than provisional leads that have not yet been confirmed.

Edges: representing relationships and their evidence

An edge connects two nodes and represents a specific, named relationship: a transaction, a shared login credential, a matching device fingerprint, or a documented business association, among other possibilities.

Every edge carries a confidence classification and a citation to the specific evidence supporting it, meaning the graph never presents a relationship without also showing how strongly, and on what basis, that relationship is asserted.

Where two entities appear related through more than one type of evidence, this is represented as multiple distinct edges rather than merged into one, preserving the individual strength of each supporting data point.

Correlation engine visualising links between multiple data points
Automated correlation can surface candidate relationships, but each is manually verified before being added as a confirmed edge.

Building the graph from multiple data sources

Constructing a usable evidence graph requires normalising data from disparate sources, on-chain explorers, exchange disclosures, infrastructure logs, and open-source material, into a common schema before relationships can be compared meaningfully.

This normalisation step is where errors are most likely to be introduced if not handled carefully, since timestamp formats, address encodings, and identifier conventions differ across sources and must be reconciled precisely.

Automated tooling assists with ingesting and normalising large volumes of data, but every candidate relationship it surfaces is manually reviewed before being confirmed as an edge in the working graph.

Using the graph to identify patterns

Graph analysis techniques, including centrality measures and cluster detection, can highlight nodes or groups of nodes that warrant closer investigation, such as an entity connected to an unusually high number of otherwise unrelated wallets.

These techniques generate leads, not conclusions. Any pattern identified through graph analysis is individually investigated and its supporting evidence separately verified before being included as a finding in the final report.

The graph is maintained as a living structure throughout the investigation, updated as new evidence changes existing confidence levels or adds new entities and relationships to the overall picture.

Components of an evidence graph and their evidentiary function

ComponentRepresentsEvidentiary function
NodeA discrete entity such as a wallet, account, or IPAnchors verified attributes to a single traceable object
EdgeA specific relationship between two entitiesCarries confidence rating and supporting evidence
ClusterA densely connected group of nodesSurfaces candidate relationships for individual verification
Confidence tagThe strength of an edge's supporting evidencePrevents flattening of uncertainty into a single narrative

Frequently asked questions

Is an evidence graph the same as a narrative report?

No. The graph is a structural representation of entities and relationships, typically presented alongside, not instead of, a written narrative report.

How is confidence represented in a graph?

Each edge is tagged with a confidence classification and a citation to its supporting evidence, so the graph shows uncertainty explicitly rather than implying uniform certainty.

Can automated tools build the graph without review?

Automated tools assist with ingestion and pattern surfacing, but every candidate relationship is manually verified before being confirmed as an edge.

Does the graph change during an investigation?

Yes. It is updated continuously as new evidence is obtained, with confidence ratings revised to reflect the current state of the investigation.

Evidence graphs make the structure of an investigation visible: what is connected, how strongly, and on what evidence. That visibility is what allows complex digital asset cases to be reviewed, challenged, and relied upon with appropriate care.

More in Digital Evidence