ShieldPST.ai · Technology Explainer Series

Data Fusion, Link Analysis & Investigative Analytics

How agencies connect people, vehicles, phones, accounts, addresses, locations, incidents, records, transactions, cameras, and other data to identify relationships and investigative leads—and what personnel should understand about entity resolution, link charts, timelines, association versus causation, data quality, source reliability, inference, privacy, discovery, auditability, and human judgment.

Technology Data Fusion & Investigative Analytics
Core Function Connect Information Across Sources
Key Principle A Link Is Not Proof of a Relationship

What this explainer does

Investigations frequently involve information distributed across many systems. A suspect's name may appear in an RMS report. A vehicle may appear in ALPR data. A phone number may appear in another case. A business address may be associated with several people. A camera may capture the same vehicle near a crime scene.

Data-fusion and investigative-analytics systems help analysts bring those records together, normalize them, identify possible common entities, visualize relationships, create timelines, and search for patterns that may be difficult to see when each database is reviewed separately.

The technology can reveal relationships within information. It does not automatically establish what those relationships mean. A shared address may indicate relatives, roommates, former residents, a business relationship, a data error, or nothing relevant at all. Investigative interpretation and corroboration remain essential.

Operational reality

Modern analytical environments increasingly combine records from multiple government systems and, where lawfully available, external information sources. Their value often comes from reducing the time required to discover connections among people, places, vehicles, devices, incidents, and records.

DHS describes fusion centers as state and local information-sharing hubs that gather, analyze, and share information for terrorism, crime-prevention, and broader public-safety purposes. The same basic analytical principle— receive, analyze, connect, and disseminate information—also appears in many local investigative and RTCC systems.

1. Overview

Investigative analytics is the process of organizing and examining information so that relationships, patterns, sequences, and anomalies become easier to identify.

Link analysis itself is not new. Law-enforcement analysts have used association matrices and link diagrams for decades to visualize connections among people, organizations, events, and records. Early police-intelligence literature described a process of assembling information, identifying relevant relationships, creating an association matrix, developing a link diagram, and refining the resulting network as more information became available.

What has changed is scale. Modern systems can ingest millions of records, resolve entities across datasets, query multiple databases rapidly, map relationships geographically, and generate visual networks in seconds.

Central Concept Data fusion can make connections easier to see. It does not transform weak, incorrect, stale, ambiguous, or unlawfully obtained source data into reliable evidence.

2. Potential Data Sources

Records Management Systems

Incident reports, persons, vehicles, addresses, narratives, case numbers, and investigative records.

Computer-Aided Dispatch

Calls for service, locations, units, timestamps, dispositions, and incident histories.

ALPR

Vehicle observations, timestamps, camera locations, plate information, and associated metadata.

Jail & Booking Records

Identity, aliases, booking information, associates, contact information, and custody history.

Digital Evidence

Phones, computers, messages, accounts, photographs, documents, and extracted information.

Video Systems

Public cameras, private cameras, BWC, RTCC video, and video-analytics results.

Location Information

Lawfully obtained device, vehicle, account, commercial, or other location-related information.

Open Sources

Publicly available websites, business records, news reports, social media, and other OSINT.

External Databases

Authorized governmental, commercial, investigative, or intelligence databases.

Data-Source Principle The fact that a system can technically ingest a dataset does not determine whether the agency is legally authorized to obtain it, retain it, combine it with other information, or use it for a particular purpose.

3. A Typical Data-Fusion Workflow

1. Acquire Authorized records are obtained from one or more systems
2. Normalize Dates, names, addresses, identifiers, and formats are standardized
3. Resolve Records that may represent the same real-world entity are associated
4. Connect Relationships among people, places, vehicles, devices, events, and records are identified
5. Analyze Timelines, networks, geography, patterns, and anomalies are examined
6. Verify Investigators return to source records and obtain independent corroboration
Workflow Principle The analytical platform should help investigators move from data to leads—not from data directly to conclusions.

4. What Is an Entity?

An entity is a real-world person, place, object, organization, account, device, or other thing represented within one or more data sources.

People

Names, aliases, dates of birth, identifiers, photographs, addresses, and contact information.

Vehicles

License plates, VINs, make, model, color, registered owner, and observations.

Devices

Phones, identifiers, accounts, IP-related records, device IDs, and network information.

Locations

Residences, businesses, incident locations, coordinates, cameras, and geographic areas.

Organizations

Businesses, groups, agencies, associations, institutions, and other entities.

Events

Incidents, arrests, calls, transactions, meetings, communications, and observations.

5. Entity Resolution — Are These Records the Same Person or Thing?

One of the most important functions in data-fusion systems is entity resolution: determining whether records from different systems likely refer to the same underlying person, vehicle, device, address, or other entity.

Exact Identifiers

A VIN, driver's-license number, unique account identifier, or other precise identifier may strongly connect records.

Names

Names can be misspelled, abbreviated, changed, duplicated, or recorded in different orders.

Addresses

The same address may appear as “Street,” “St.,” apartment variants, historical addresses, or data-entry errors.

Phone Numbers

Numbers can be shared, reassigned, spoofed, temporary, or associated with several people.

Aliases

Nicknames, alternate spellings, maiden names, false names, or identifiers may connect records.

Probabilistic Matching

Software may use several imperfect attributes together to estimate whether records likely represent the same entity.

Entity-Resolution Caution A system that merges two records incorrectly can propagate that error across every downstream link, chart, alert, report, and investigative conclusion.

7. Timeline Analysis

Data fusion can place information from several sources onto a single chronology. That can be especially useful where no one system captures the entire event.

CAD

Dispatch events can establish call, assignment, arrival, and communication times.

Video

Cameras may document movement, vehicles, people, and physical events.

ALPR

Plate observations may place a vehicle at particular locations and times.

Phones

Messages, calls, application data, or lawful location information may contribute timestamps.

Access Systems

Locks, badges, cameras, accounts, or IoT systems may record events.

Records

Transactions, logins, bookings, reports, and other records may contribute temporal anchors.

Timeline Caution Data sources may use different clocks, time zones, synchronization methods, reporting delays, or event definitions. A visually precise timeline can create false confidence if those differences are not examined.

8. Network Analysis

Network analysis examines the structure of relationships among many entities. It can help identify central actors, clusters, bridges among groups, highly connected entities, or unusual relationships requiring additional review.

Degree

How many direct relationships an entity has within the selected network.

Centrality

Mathematical measures may attempt to identify entities occupying influential or structurally important positions.

Clusters

Groups of entities may appear more densely connected to one another than to the wider network.

Bridges

An entity may connect otherwise separate portions of a network.

Temporal Networks

Relationships may be examined over defined periods rather than treated as static.

Weighted Links

Systems may assign different significance or frequency to different types of association.

Network-Analysis Caution Mathematical importance inside a dataset is not the same as criminal significance. A highly connected person may simply be a business owner, landlord, dispatcher, family member, service provider, or other legitimate hub.

9. Geospatial Analysis

Investigative analytics can add geography to entity and timeline information, helping personnel visualize where events occurred and how locations relate.

Incident Mapping

Plot offenses, calls, encounters, or events to identify geographic relationships.

Vehicle Movement

Lawfully obtained ALPR or other records may help reconstruct vehicle movement.

Camera Coverage

Analysts can identify public or private cameras potentially covering a route or incident area.

Proximity

Systems may identify entities or events occurring within a defined distance or geographic zone.

Routes

Investigators can compare sequences of known locations against roads, travel paths, or relevant facilities.

Temporal Geography

Time and location can be examined together to reconstruct movement and event sequence.

10. Investigative Uses

Violent-Crime Investigations

Connect cases, vehicles, locations, communications, suspects, associates, weapons, and digital evidence.

Organized Crime

Identify relationships among people, organizations, transactions, addresses, and events.

Serial Offenses

Compare incidents for common people, vehicles, locations, methods, devices, or other features.

Gun Crime

Connect firearm evidence, shootings, people, vehicles, locations, and related cases.

Fraud

Connect accounts, addresses, devices, transactions, businesses, identities, and communications.

Missing Persons

Combine records, vehicles, devices, video, locations, contacts, and timeline information.

Real-Time Operations

RTCC analysts may connect incoming events with historical records or existing investigative information.

Intelligence Analysis

Analyze authorized information to identify threats, networks, patterns, or information gaps.

Case Coordination

Identify when investigators in different units may be examining related entities or events.

11. Association Is Not Causation—and Proximity Is Not Participation

The greatest analytical risk is turning a machine-discovered relationship into a factual conclusion the underlying data does not support.

Shared Address

May reflect family, roommates, former occupancy, mailing records, or stale data.

Shared Phone

May reflect family use, reassignment, business use, spoofing, or account errors.

Vehicle Association

Registration does not establish who was driving during a particular observation.

Location Proximity

Being near an incident does not establish knowledge, intent, participation, or even precise presence.

Communication

A communication record may establish contact but not necessarily its content or significance.

Common Associate

Two people connected to the same third person may never have met one another.

Inference Rule Analytical software should identify facts contained in data and possible relationships. Investigators remain responsible for distinguishing documented fact, reasonable inference, investigative hypothesis, and unsupported assumption.

12. Data Quality Controls the Analysis

Analytical systems can process data very quickly, but they cannot automatically repair every defect in the information they receive.

Stale Information

Addresses, phone numbers, ownership, employment, and other attributes change.

Duplicate Records

The same person or event may appear multiple times under slightly different identifiers.

Incorrect Records

Data-entry mistakes, misidentification, outdated information, or source errors can propagate.

Missing Context

A field extracted from a record may lose explanatory narrative or limitations present in the source.

Unknown Provenance

Imported information may lack clear source, date, collection method, or reliability indicators.

Conflicting Information

Multiple systems may contain inconsistent names, dates, addresses, or identifiers.

Data-Quality Principle Analytical confidence should never exceed the reliability and relevance of the underlying information.

13. Source Reliability and Provenance

A strong analytical platform should preserve the connection between a displayed fact and the source record supporting it.

Source System

Identify which database, report, provider, agency, or evidence source supplied the information.

Date

Show when the information was created, observed, reported, or last updated.

Original Record

Allow analysts to return to the source rather than relying only on an extracted field or link-chart label.

Confidence

Distinguish verified facts from uncertain, inferred, or probabilistic information where appropriate.

Legal Authority

Maintain awareness of restrictions attached to information obtained through particular sources or processes.

Update History

Understand whether a displayed relationship changes when source records are corrected or updated.

Analyst Principle A useful analytical system should make it easy to answer: “What source supports this link?”

14. AI Is Expanding Investigative Analytics

Artificial intelligence can make large, heterogeneous datasets easier to search and analyze, but it also introduces new forms of inference and error.

Natural-Language Search

Investigators may ask questions conversationally rather than construct complex database queries.

Entity Extraction

AI can identify names, places, vehicles, dates, accounts, and other entities from narratives or documents.

Relationship Extraction

Systems may infer possible relationships described within reports, communications, or records.

Timeline Generation

AI may assemble events from multiple records into a proposed chronology.

Case Summaries

Large analytical collections may be summarized for investigators or command personnel.

Suggested Connections

Systems may identify relationships or patterns the investigator did not specifically request.

AI Caution A generative-AI system can create a plausible relationship that is not actually supported by the source records. AI-generated links, summaries, timelines, and explanations should remain traceable to the underlying evidence.

15. Privacy, Civil Rights, and Civil Liberties

The privacy significance of data fusion comes from aggregation. Information that appears relatively limited when viewed in isolation can become much more revealing when combined with other records.

DHS foundational guidance for fusion centers expressly treats privacy, civil rights, and civil liberties protections as integral to information-sharing and analytical operations. Federal guidance has also emphasized written privacy policies, training, accountability, auditing, and controls over information use.

Authorized Purpose

Define why each dataset is being collected, searched, combined, and retained.

Access

Restrict sensitive analytical systems to personnel with a legitimate operational need.

Query Controls

Establish appropriate rules for searching persons, groups, locations, and other sensitive information.

Retention

Consider whether derived relationships and analytical records should persist indefinitely.

Correction

Determine how incorrect source information and erroneous entity merges are corrected.

Audit

Preserve sufficient records to identify inappropriate, unauthorized, or unusual searches.

Aggregation Principle Agencies should evaluate not only whether each individual dataset may be used, but also what new surveillance or analytical capability is created when several datasets are combined.

16. Investigative Analytics, Evidence, and Discovery

An analytical chart is not the source evidence.

Link diagrams, dashboards, maps, timelines, and AI-generated summaries are derivative analytical products. Their reliability depends on the records from which they were created and the assumptions used to connect those records.

Item Why It May Matter
Source records Provide the underlying factual basis for the analysis.
Queries May show how investigators searched or filtered large datasets.
Entity merges Can be important if several records were treated as one person or object.
Link charts Show relationships relied upon during investigative analysis.
Timelines May reflect investigator or software decisions about sequencing events.
Maps May contain selected data, assumptions, geographic filters, or calculated relationships.
Analytical notes Can distinguish facts from analyst interpretation and hypotheses.
AI outputs May require preservation where generated summaries or suggested links materially influenced the investigation.
Audit records Can document user activity, searches, exports, and system access.
Corrections May show that a relationship or source record was later determined to be inaccurate.

17. Auditability and Accountability

Investigative-analytics systems can provide access to unusually broad collections of information. Auditability is therefore an important governance control.

User Identity

Record which authorized user conducted a search or accessed a record.

Query History

Preserve searches sufficiently to investigate misuse or reconstruct consequential analytical work.

Exports

Record bulk downloads, reports, link charts, and data exports.

Administrative Changes

Log changes to permissions, datasets, integrations, or system rules.

Automated Actions

Preserve information concerning system-generated alerts, entity merges, or other consequential automated operations.

Review

Use periodic or risk-based audits to identify inappropriate access or unusual query patterns.

18. Governance Framework

Data Inventory

Identify every dataset available through the analytical platform.

Legal Authority

Document the authority, purpose, and restrictions associated with each data source.

Entity Resolution

Define how records are merged and how incorrect merges are corrected.

Source Provenance

Preserve the connection between analytical results and source records.

User Permissions

Apply role-based access appropriate to dataset sensitivity and mission.

Query Rules

Establish appropriate restrictions or documentation for sensitive searches.

Human Verification

Require source review and corroboration before consequential action based on an analytical result.

AI Controls

Distinguish machine-generated suggestions from verified relationships.

Audit

Record user access, searches, exports, and significant administrative activity.

Retention

Establish retention rules for queries, charts, derived relationships, and other analytical products.

Correction

Create procedures for correcting inaccurate source data or derivative analytical records.

Periodic Review

Reassess datasets, algorithms, AI functions, privacy risks, and operational use as the system expands.

19. Procurement and Vendor Questions

Area What the Agency Should Understand
Data Sources What government, commercial, open-source, and proprietary datasets can the platform access?
Entity Resolution How does the system decide that two records refer to the same person, vehicle, device, or organization?
Confidence Does the system expose uncertainty, matching scores, or alternative candidates?
Source Traceability Can every displayed fact or link be traced directly to supporting source records?
AI Does the platform generate inferred relationships, summaries, timelines, hypotheses, or suggested connections?
Training Data Are agency records used to train or improve vendor models?
Search Logs Does the platform retain who searched for what and when?
Bulk Export Can users download large datasets, and are those exports logged or restricted?
Permissions Can access be limited by user role, dataset, case, jurisdiction, or purpose?
Corrections How do changes to a source record propagate through linked entities and analytical products?
Retention How long are searches, relationships, analytical products, and cached source data retained?
Commercial Data What third-party datasets are included, what are their sources, and what contractual restrictions apply?
Security How are sensitive cross-system credentials, APIs, datasets, and user accounts protected?
Vendor Changes Can new datasets, algorithms, or AI capabilities be activated without separate agency review?

20. Questions Every Agency Should Answer

What datasets are available through the analytical platform?
What legal authority supports access to each dataset?
What restrictions apply to each data source?
How often is each source updated?
How does the system identify duplicate records?
How does entity resolution work?
Can an analyst see why two records were merged?
Can an incorrect entity merge be reversed?
Do corrections propagate through existing link charts and reports?
Can every analytical link be traced to source records?
Does the system distinguish facts from inferred relationships?
Does the system assign confidence or similarity scores?
What does a displayed link actually mean?
Are temporal differences among records preserved?
Are time zones and clock differences normalized correctly?
Can the platform generate timelines automatically?
Can the platform generate link charts automatically?
Does it perform network-centrality or clustering analysis?
Does it make recommendations or suggest persons of interest?
Does it use generative AI?
Can AI-generated statements be traced to supporting source records?
Does the platform include commercial data?
What is the source and reliability of commercial information?
Who may search the platform?
Are queries logged?
Are bulk exports restricted and audited?
Can users search people without an associated investigation?
Are sensitive datasets subject to additional access controls?
How long are queries retained?
How long are analytical products retained?
How are incorrect records corrected?
How are privacy or misuse complaints reviewed?
What training is required before a user receives access?
What source verification is required before enforcement action?
What analytical products may become discoverable?
Can the agency reproduce an important analytical result later?
What happens when a vendor adds a new dataset?
What happens when a vendor adds a new AI capability?
When will the program receive its next privacy, legal, security, and accuracy review?

21. Where Investigative Analytics Is Going

Natural-Language Investigation

Investigators may increasingly ask complex questions across many databases without constructing specialized queries.

Automated Entity Resolution

AI may connect incomplete or inconsistent identities across increasingly large information environments.

Multimodal Fusion

Text, images, video, audio, location, biometrics, and structured records may be analyzed together.

Real-Time Link Analysis

New events may automatically connect to historical people, vehicles, addresses, or investigations as they occur.

AI-Generated Hypotheses

Systems may suggest relationships, timelines, investigative gaps, or possible explanations.

Agentic Investigation Tools

Future systems may conduct multiple searches, compare records, generate charts, and propose next investigative steps.

Future-Looking Principle As analytical systems shift from showing investigators information to proposing what the information means and what investigators should do next, agencies should increase—not reduce—requirements for provenance, verification, explainability, supervisory review, and human accountability.

22. Key Terms

Data Fusion The process of combining information from multiple sources to support analysis or decision-making.
Link Analysis Analysis of relationships among people, places, organizations, objects, events, or other entities.
Entity A real-world person, place, organization, device, vehicle, account, event, or other thing represented in data.
Entity Resolution The process of determining whether records from different sources likely represent the same real-world entity.
Link Chart A visual diagram showing entities and relationships among them.
Node An entity represented within a link or network diagram.
Edge A represented relationship between two entities within a network.
Network Analysis Examination of the structure, relationships, clusters, and other characteristics of a connected set of entities.
Centrality A family of measures used to describe structural importance or connectedness within a network.
Cluster A group of entities that appear more densely connected with one another than with other portions of a network.
Geospatial Analysis Analysis incorporating location, geography, distance, movement, or spatial relationships.
Temporal Analysis Analysis of events or relationships across time.
Normalization Standardizing data from different systems so comparable information can be analyzed together.
Provenance Information concerning where data came from and its history or transformation.
Inference A conclusion or interpretation drawn from known information rather than a directly recorded fact.
Association Matrix A structured representation showing relationships among a defined set of entities.
Analytical Product A chart, report, timeline, map, dashboard, summary, or other output created through analysis of source information.
Fusion Center A state or locally operated information-sharing and analytical center supporting terrorism, crime-prevention, and public-safety missions.

23. Related ShieldPST.ai Resources

Real-Time Crime Centers

Understand how agencies combine cameras, CAD, ALPR, mapping, records, and other information during active operations.

Open explainer →
Predictive Policing & Algorithmic Crime Forecasting

Examine the distinction between investigative analysis and systems that predict crime risk or future events.

Open explainer →
ALPR & Vehicle Intelligence

Explore vehicle-location data, network sharing, retention, analytics, and investigative use.

Open resource →
Social Media & OSINT

Review publicly available digital information, online research, preservation, authentication, and investigative use.

Open explainer →
Private Camera Networks & Video-Sharing Platforms

Examine how private video can become part of larger investigative and RTCC information environments.

Open explainer →
Generative AI in Law Enforcement

Understand AI-generated analysis, verification, hallucinations, source attribution, and governance.

Open explainer →
Commercial Data Brokers & Location Intelligence

Review commercial information sources, location data, government access, and governance.

Open explainer →
Police Technology Case Law Center

Research privacy, data, surveillance, digital evidence, and investigative-technology decisions.

Browse case library →
Technology Explainers

Return to the Shield Technology Reference Library.

Browse explainers →

24. Selected Authoritative Sources

U.S. Department of Homeland Security — Fusion Center Foundational Guidance
DHS guidance addressing information sharing, analytical capabilities, operational standards, coordination, privacy, civil rights, civil liberties, security, and accountability within fusion centers.
Review DHS guidance
Office of Justice Programs — Fusion Center Guidelines: Law Enforcement Intelligence, Public Safety, and the Private Sector
Guidance addressing collection, analysis, information sharing, partnerships, governance, and operation of fusion centers.
Review OJP guidance
U.S. Department of Homeland Security — Fusion Centers and Emergency Operations Centers
DHS explains that fusion centers serve as state and local information-sharing hubs supporting terrorism and crime prevention and broader public-safety efforts.
Review DHS overview
National Institute of Justice-Sponsored Research — The Nexus of Data and Technology: A Scoping Review of Established and Emerging Law Enforcement Intelligence Centers
2025 research reviewing RTCCs, crime intelligence centers, crime gun intelligence centers, fusion centers, and the increasing role of integrated data and technology in law-enforcement analysis.
Review research
Office of Justice Programs — Application of Link Analysis to Police Intelligence
Foundational law-enforcement research describing link analysis through collection of information, identification of relationships, association matrices, and development of link diagrams.
Review OJP resource

25. Key Takeaways

Bottom Line
  1. Data-fusion systems combine information from multiple sources so investigators can identify relationships, timelines, patterns, locations, and investigative leads more efficiently.
  2. Link analysis is not new; law-enforcement analysts have used association matrices and link diagrams for decades.
  3. Modern systems dramatically increase scale by allowing millions of records and multiple data sources to be analyzed together.
  4. Entity resolution is a critical step because records from different systems may refer to the same person, vehicle, address, device, or organization—or may only appear to do so.
  5. An incorrect entity merge can propagate errors throughout link charts, timelines, reports, alerts, and investigative decisions.
  6. A link establishes an association represented in the data. It does not automatically establish the nature or significance of the relationship.
  7. Shared addresses, phone numbers, vehicles, locations, or associates can have innocent, historical, inaccurate, or irrelevant explanations.
  8. Timeline analysis is powerful but requires attention to clock accuracy, time zones, synchronization, event definitions, and reporting delay.
  9. Network-centrality or clustering measures describe structure inside a dataset; they do not automatically identify criminal importance.
  10. Data quality, provenance, currency, and source reliability place an upper limit on the reliability of analytical conclusions.
  11. AI can make investigative analytics much more powerful by extracting entities, generating timelines, suggesting relationships, and allowing natural-language search—but those capabilities also increase the risk of unsupported inference.
  12. Significant analytical findings should remain traceable to supporting source records and independently corroborated before consequential enforcement action.
  13. The governing principle is: use analytics to discover relationships worth investigating— not to replace the investigation required to determine what those relationships actually mean.

ShieldPST.ai · Technology Explainer Series

This explainer is provided for training and general informational purposes. It is not legal advice and does not replace review of controlling federal and state constitutional law, criminal-intelligence regulations, privacy and civil-liberties requirements, 28 C.F.R. Part 23 where applicable, criminal discovery obligations, public-records requirements, agency policy, information-sharing agreements, data-use restrictions, evidence rules, cybersecurity requirements, vendor documentation, prosecutorial guidance, or consultation with agency counsel. Analytical platforms, available datasets, AI functions, and legal requirements continue to evolve.

© 2026 Shield Public Safety Training. All rights reserved. · Reviewed August 25, 2026.