Casebook Home

THE DEMO LADDER

Each demo doesn’t show a feature.
Each proves an architectural law.

One operator's workday, from teaching Casebook your data to watching it remember — every step a real product surface, each proving one law. No feature tours; no internals explained.

DEMO 0 OF 10

Teach Casebook Your Data

Does it understand your logs — or just parse them?

Before any investigation, map a company log source into Casebook’s language and prove understanding by reconstructing an event.

DEMO 0Fully interactive

Real action → persisted state change → inspectable → engine-validated completion.

Teach Casebook Your Data

“Does it understand your logs — or just parse them?”

Before any investigation, map a company log source into Casebook’s language and prove understanding by reconstructing an event.

Detect fieldsMap to canonical languageCorrect a wrong mappingResolve an unknownReconstruct & compareEstablish normal baseline

Architecture proven

Data UnderstandingSemantic Round-TripScoped Baselines

Understanding is measurable — field vs meaning coverage, not a parse

DEMO 1Guided on real UI

Paced walkthrough over the real product. Actions are genuine (navigate, inspect) but change no stored state.

The Incident Arrives

“Can it work on day one — before you configure anything?”

A 2 AM page. Casebook has already produced a Case File from its default knowledge. Read what it understood on its own.

PagerDuty firesOpen the default Case FileInspect what was recognized→ A useful default — but is it complete?

Architecture proven

RecognitionCase File

A useful default understanding out of the box — zero setup

DEMO 2Guided on real UI

Paced walkthrough over the real product. Actions are genuine (navigate, inspect) but change no stored state.

Inspect the Unexplained

“Will it hide what it can’t explain?”

Work the default findings, then open Needs Review — seven events Casebook perceived but never explained, preserved in the open rather than guessed.

Inspect a findingOpen Needs ReviewSee 7 preserved gaps→ Recognized, not explained

Architecture proven

RecognitionResidual Preservation

What can’t be fully explained stays visible — no fabricated confidence

DEMO 3Guided on real UI

Paced walkthrough over the real product. Actions are genuine (navigate, inspect) but change no stored state.

Make the Operator Call

“Can a human decide what the gap means?”

Select one unresolved item. Casebook shows exactly what it recognized and exactly what’s missing — then you decide what kind of knowledge closes it.

Select an unresolved itemSee recognized vs missingJudge: real gap or noise?→ Decide what’s missing

Architecture proven

Residual PreservationOperator Judgment

The human makes the call on an auditable gap — the tool doesn’t guess

DEMO 4Fully interactive

Real action → persisted state change → inspectable → engine-validated completion.

Teach Casebook Your Language

“Can it adapt to your words?”

Evidence arrives in unknown language. The knowledge is present — only the words are missing. Map your terms and watch coverage rise.

usr_id → usersrc → source_iphostname → host→ Patterns activate · coverage increases

Architecture proven

TerminologyRecognition

Adapts to your language — your terms, mapped to Casebook’s patterns

DEMO 5Fully interactive

Real action → persisted state change → inspectable → engine-validated completion.

Add Company Knowledge

“Can it learn a new pattern?”

The individual events are recognized; the larger pattern is not. Define the pattern your organization knows — and propose it.

Failed loginsPrivilege changeSensitive access→ Define the pattern → submit proposal

Architecture proven

ResidualPatternKnowledge Draft

New operational knowledge, authored by a named human

DEMO 5bFully interactive

Real action → persisted state change → inspectable → engine-validated completion.

Derive a Pattern from Evidence

“Can it build recognition logic from the evidence itself?”

The bottom-up counterpart to teaching a pattern top-down. Select an unexplained cluster and let Casebook derive the recognition logic from what those events share — then test it on the real stream, freeze it, replay it, and promote it.

Select the unexplained clusterDerive recognition logicTest on the real streamFreeze → Replay → Promote→ A pattern earned from evidence

Architecture proven

RecognitionReplayOperator Judgment

Recognition logic derived from real evidence — computed, tested, and promoted, never scripted

DEMO 6Fully interactive

Real action → persisted state change → inspectable → engine-validated completion.

Govern the Change

“Is learning controlled — or does it just drift?”

A proposal isn’t knowledge until it’s approved. Review it, approve it, and freeze an immutable version the system will reason from.

Review the proposalApprove itVersion frozen→ Governed, not automatic

Architecture proven

GovernanceImmutable Version

Every learning is reviewed and versioned before it changes reasoning

DEMO 7Fully interactive

Real action → persisted state change → inspectable → engine-validated completion.

Replay Proves It

“Can it improve safely?”

Run the original sealed evidence against the approved knowledge. Watch the outcome change — measured against reality, without rewriting history.

Same evidenceNew approved knowledgeBefore vs after coverage→ A measured difference

Architecture proven

Case FileReplayDeterminism

Controlled evolution — a change proven before it’s trusted

DEMO 8Guided on real UI

Paced walkthrough over the real product. Actions are genuine (navigate, inspect) but change no stored state.

Growing Company Intelligence

“Does it remember — so the next case starts ahead?”

The proven learning is appended to the sealed Case File (original untouched), and the same knowledge recognizes the pattern on the next investigation.

Learning appendedOriginal conclusion sealedNext case: pattern recognized→ The floor rises for every case

Architecture proven

PreservationOperational Memory

A knowledge system, not a detection system — memory that compounds