Skip to content
← UserSearch.comLog in ↗

Produce your first court-ready export

This tutorial walks you end to end: you enable Forensic Mode on a Case before you start searching, bookmark the results you want to keep, and then generate a downloadable Report from those Bookmarks. The result is an audited, exportable record of your search scoped to one Case.

The order matters. Forensic Mode is what makes a Case retain Bookmarks and History and provide chain-of-custody, so you switch it on at the start — before you collect anything (per Lee, 2026-07-08).


  • You need a Case to collect into. Every account starts with a built-in Default Case, or you can create your own in Case Management.
  • Forensic Mode determines whether a Case keeps a durable record. With Forensic Mode on, the Case retains bookmarking and history and provides chain-of-custody. A Private Case (Forensic Mode off) keeps no bookmarking and no history — it is effectively ephemeral (per Lee, 2026-07-08).
  • Because that retention is decided by the Case’s setting, turn Forensic Mode on before you run the searches you intend to preserve.

  1. Open Case Management from the left navigation.
  2. Review the case table. Each Case shows its NAME, CREATED AT, SHARE state, FORENSIC MODE switch, PRIVATE KEY indicator, and an ACTIONS column.
  3. To collect into a fresh, dedicated Case, select + Add Case (top-right) and give it a name.
  4. To use an existing Case instead, note its name so you can select it as your active Case when you search.
Case Management modal: case table with NAME, CREATED AT, SHARE, FORENSIC MODE, PRIVATE KEY, ACTIONS columns and the + Add Case button
Case Management modal: case table with NAME, CREATED AT, SHARE, FORENSIC MODE, PRIVATE KEY, ACTIONS columns and the + Add Case button

Forensic Mode is set per-Case, using the FORENSIC MODE switch on that Case’s row in Case Management.

  1. Find your Case’s row in the case table.
  2. Set its FORENSIC MODE switch to on (the orange position).
  3. Confirm the switch reads on before you continue. This is the step that makes the Case retain your Bookmarks and History and provide chain-of-custody (per Lee, 2026-07-08).

Step 3 — Run your searches and bookmark your findings

Section titled “Step 3 — Run your searches and bookmark your findings”

With Forensic Mode on for your Case, collect your evidence.

  1. Make your Case the active search context using the Case selector.
  2. Run your searches from the Dashboard.
  3. For each result you want to preserve, bookmark it. A Bookmark is a single saved result, associated with your Case, kept for later review and export.

Bookmarking is distinct from an ad-hoc Export of the current results table, and distinct from a Report. In this workflow you bookmark first, then generate a Report from those bookmarks.

Each saved result appears on the Bookmarks page, where every row records its ID, CASE, TYPE, CATEGORY (the underlying data source or enrichment source behind the result), VALUE, and BOOKMARKED AT time.

Bookmarks page: report-generation panel above the Bookmarks table, showing saved result rows
Bookmarks page: report-generation panel above the Bookmarks table, showing saved result rows

Reports are generated from the Bookmarks page. (The Reports page only lists, downloads, and deletes them.)

  1. Open Bookmarks from the left navigation.
  2. In the report-generation panel at the top, set FILTER BY CASE to your Case. This scopes both the bookmarks table and the Report to that single Case.
  3. Set FILE TYPE to Xlsx.
  4. Enter a FILENAME for the Report file.
  5. Optionally enable INCLUDE BASIC CASE DETAILS to embed basic case details, and INCLUDE CASE HISTORY to embed the Case’s history, into the Report.
  6. Select Generate Report.

The Report is produced from your selected Case, file type, filename, and include options, and then appears on the Reports page.


  1. Open Reports from the left navigation.
  2. Set the FILTER BY CASE dropdown to your Case to narrow the Saved Reports table.
  3. Find your Report in the list. Each row shows its ID, NO. OF RECORDS, NO. OF DOWNLOADS, FILE NAME, FIRST DOWNLOADED, and LAST DOWNLOADED.
  4. Select Download on that row to save the file.
Reports page: Saved Reports table with Download and Delete actions per row
Reports page: Saved Reports table with Download and Delete actions per row

Use the Case Summary panel at the bottom of the Bookmarks, Reports, and History pages to verify your Case’s totals before you rely on the export.

The panel lists, per Case, the CASE NAME, NUMBER OF BOOKMARKS, REPORTS CREATED, and LAST UPDATE. Confirm your Case shows the bookmark count you expect and that its REPORTS CREATED count reflects the Report you just generated.

You can also open the History page to review the Case’s retained search and login activity — the audit trail that Forensic Mode preserves. History is retained for Forensic-on Cases and is not kept for Private Cases (per Lee, 2026-07-08).

History page: search/login activity log for the Case, with the Case Summary panel below
History page: search/login activity log for the Case, with the Case Summary panel below

  • A Case with Forensic Mode on, retaining bookmarking, history, and chain-of-custody.
  • A set of Bookmarks — your preserved findings — scoped to that Case.
  • A downloadable .xlsx Report generated from those Bookmarks, verifiable against the Case Summary counts.

Verified against UserSearch v2.0.20