# Identity and Relationship Analysis **Entity class:** Analytic method **Domain:** Intelligence / law enforcement / knowledge graphs **Doc Type:** Canonical Concept Node **Maturity:** Developed ## Plain-Language Definition **Identity and relationship analysis asks two elementary questions: _Who is this?_ and _Who knows whom—or what is connected to what?_** Identity analysis attempts to determine whether records with different names, aliases, dates of birth, account numbers, document numbers, addresses, devices, vehicles, biometrics, or encounter histories refer to the same person or entity. Relationship analysis then maps typed connections among people, organizations, accounts, phones, email addresses, locations, vehicles, transactions, events, and cases. ## From Records to a Graph The method converts records into a graph: - **nodes** represent people, organizations, places, accounts, vehicles, devices, documents, or events; - **edges** represent a documented or inferred relationship such as shared address, communication, transaction, co-travel, co-employment, encounter, ownership, or organizational affiliation; and - **provenance** records which system, observation, report, or analyst supplied the identity or connection. [[wiki/ICEPIC|ICEPIC]] was designed to resolve identities and discover non-obvious relationships across selected DHS data. A shared address or identifier could reveal a legitimate connection worth investigating. It could also reflect a former tenant, reused phone, clerical error, stolen credential, family member, service provider, or coincidence. The edge therefore needs a type, time, source, and confidence; “connected” is not synonymous with “knows,” “controls,” “supports,” or “conspires with.” ## Relationship to Contact Tracing [[wiki/Contact Tracing|Contact tracing]] is a specialized biological form of identity-and-relationship analysis. It begins with a confirmed or probable case, identifies people meeting a defined exposure condition, reconstructs relevant contact windows, and follows the resulting chain to interrupt transmission. Counterterrorism network analysis uses a formally similar graph expansion—start from an identified actor or event, resolve contacts and resources, test which ties are operationally meaningful—but the object and legal consequences differ. The useful common abstraction is **case → typed contacts → temporal chain → risk assessment → intervention**. The critical boundary is that exposure to a pathogen can be defined biologically, while social contact with a suspect does not establish violent intent, membership, or material support. ## Sources / Provenance - [[research/Immigration and Customs Enforcement Pattern Analysis and Information Collection (ICEPIC)|ICEPIC research dossier]] - [[research/A Network-Epidemiological Analysis of Radicalization and Real-Time Counterterrorism Observability|Network-Epidemiological Analysis]] - [DHS — ICEPIC Privacy Impact Assessment](https://www.dhs.gov/xlibrary/assets/privacy/privacy_pia_ice_icepic.pdf) - [Oxford Journal of Conflict and Security Law — social network analysis and counterterrorism](https://academic.oup.com/jcsl/article/29/1/165/7603867) - [WHO — contact tracing definition and process](https://www.who.int/news-room/questions-and-answers/item/contact-tracing) ## Relationships - **historical analytical system:** [[wiki/ICEPIC|ICEPIC]]. - **public-health specialization:** [[wiki/Contact Tracing|Contact Tracing]]. - **threat-network application:** [[wiki/Epidemiological and Threat Network Analysis|Epidemiological and Threat Network Analysis]]. - **data foundations:** [[wiki/Treasury Enforcement Communications System|TECS]], [[wiki/Enforcement Integrated Database|EID]], and [[wiki/Financial Transaction Data|Financial Transaction Data]]. - **evidentiary boundary:** a graph edge is a lead whose meaning depends on its type, time, provenance, authority, and corroboration.