Research project · CDR Analyzer · 2025

Turning phone records into leads for police investigators

Call records reach police investigators as a spreadsheet thousands of rows long. Nobody on the team had seen one, so I went to the police and designed a tool that shows the record first. It shipped inside Jarvis One, and when we went back after a week, the investigators had gone to the tabs first.

Role
Product designer
Timeline
2 months
Users
Police investigators
Team
PM, design, engineering, AI research
CDR Analyzer showing a call record as one table, with tabs for common questions and repeated values in color

Quick look

I designed a tool that helps police read phone call records.

Investigators were reading records by hand. The tool shows the record first, with a tab for each question they ask.

CDR Analyzer showing a call record as one table, with tabs for common questions and repeated values in color

Who it is for

Three kinds of investigator I met in Lucknow and New Delhi.

The line readerNeeds repeats to show without reading every row.
The question askerNeeds the same three answers without building them.
The name chaserNeeds a name for a number without leaving the record.
The idea

Let color find the repeats

A record is thousands of rows that look the same. Every repeated number, date, and tower gets its own color, so a pattern shows before anyone reads a row.

Drag the handle to turn color off and on.

Color on: repeated numbers, dates, and towers carry a color
Color off: the same table with no color
Color offColor on

How the project went

  1. Ritesh at the Special Task Force office in Lucknow
    StudyI visited police in Lucknow and New Delhi to watch records being read.
  2. Version one up close: repeated numbers and dates share a color
    DesignVersion one put the whole record in one table, with color.
  3. The filter builder with three rules for call type
    TestInvestigators rebuilt the same filters for every record.
  4. Version two: a row of tabs, with Max night stay open
    SimplifySo each filter they kept rebuilding became a tab.
What testing led to

Their questions became tabs

Every investigator asked the same things: who he calls most, which phone, where he stays. Each question is now a tab, named in the words they already use.

The CDR Analyzer with tabs for Max B party, Max IMEI, Max day stay, and more above the call table
No more switching tools

A name for any number

Investigators left the record to look numbers up in other tools. Decode brings the owner back beside the row instead.

The owner card for a decoded number: name, phone company, email, and address
The shape of a record

Patterns you can see

The graphical view turns rows into pictures: calls per day, the busiest hours, and who talks to whom.

The graphical view: call totals and a chart of calls per day
The heatmap of calls by hour and day
The network of who the phone talks to

Where we started

First, I had to see a real call record

A call detail record, or CDR, is the log a phone company keeps for every phone. It is the kind of case where a phone number is the only lead the police have to start from. We did not know what a record looks like, which parts matter, what makes a lead, or how police get one.

ABCDEFGH
1A party numberB party numberCall typeDateTimeDurationIMEIIMSI
299282929249922323232CALL-IN07/02/202418:48:12390357006162552730404980191149918
399282929249922323232CALL-OUT07/02/202423:10:00180357006162552730404980191149918
499282929249922323232CALL-OUT07/02/202422:50:00171357006162552730404980191149918
599282929249922323232CALL-OUT07/02/202422:30:00151357006162552730404980191149918
699282929249922323232CALL-OUT07/02/202422:10:00140357006162552730404980191149918
799282929249922323232CALL-OUT07/02/202421:50:00120357006162552730404980191149918
899282929248222523232CALL-IN07/02/202421:30:00120357006162552730404980191149918
999282929248222523232CALL-IN08/02/202421:10:0020357006162552730404980191149918
1099282929248222523232CALL-IN08/02/202420:50:0028357006162552730404980191149918
1199282929248222523232CALL-IN08/02/202420:30:0012357006162552730404980191149918
1299282929247722323232CALL-IN08/02/202420:10:0011357006162552730404980191149918
1399282929249922323232CALL-IN07/02/202418:48:12390357006162552730404980191149918
1499282929249922323232CALL-OUT07/02/202423:10:00180357006162552730404980191149918
1599282929249922323232CALL-OUT07/02/202422:50:00171357006162552730404980191149918
1699282929249922323232CALL-OUT07/02/202422:30:00151357006162552730404980191149918
1799282929249922323232CALL-OUT07/02/202422:10:00140357006162552730404980191149918
1899282929249922323232CALL-OUT07/02/202421:50:00120357006162552730404980191149918
1999282929248222523232CALL-IN07/02/202421:30:00120357006162552730404980191149918
2099282929248222523232CALL-IN08/02/202421:10:0020357006162552730404980191149918
2199282929248222523232CALL-IN08/02/202420:50:0028357006162552730404980191149918
2299282929248222523232CALL-IN08/02/202420:30:0012357006162552730404980191149918
2399282929247722323232CALL-IN08/02/202420:10:0011357006162552730404980191149918
2499282929249922323232CALL-IN07/02/202418:48:12390357006162552730404980191149918
2599282929249922323232CALL-OUT07/02/202423:10:00180357006162552730404980191149918
2699282929249922323232CALL-OUT07/02/202422:50:00171357006162552730404980191149918
2799282929249922323232CALL-OUT07/02/202422:30:00151357006162552730404980191149918
2899282929249922323232CALL-OUT07/02/202422:10:00140357006162552730404980191149918
2999282929249922323232CALL-OUT07/02/202421:50:00120357006162552730404980191149918
3099282929248222523232CALL-IN07/02/202421:30:00120357006162552730404980191149918
3199282929248222523232CALL-IN08/02/202421:10:0020357006162552730404980191149918
3299282929248222523232CALL-IN08/02/202420:50:0028357006162552730404980191149918
3399282929248222523232CALL-IN08/02/202420:30:0012357006162552730404980191149918
3499282929247722323232CALL-IN08/02/202420:10:0011357006162552730404980191149918
One row per call

A call record as it arrives, one row per call. The first eleven rows are from the design, and the rest repeat them.

Going to the source

Investigators read records by hand, and ask the same three questions

I went twice: to the Special Task Force in Lucknow, and to I4C, India's cybercrime centre in New Delhi. I watched investigators work through call records on real cases. Records come back as one file per number, and they are read by hand.

Ritesh standing in front of the Special Task Force emblem of the Uttar Pradesh Police
Ritesh standing outside the Ministry of Home Affairs building in New Delhi

The Special Task Force office in Lucknow, and the Ministry of Home Affairs in New Delhi, which runs I4C.

Who I was designing for

Three investigators, as I met them

Line sketch of an investigator circling one row on a printed call sheet

The line reader

"I go down the sheet. If a number comes back, I mark it."

The pattern
Reads the record the way it arrives, row by row, and spots repeats by memory.
What they needed
To see which numbers repeat without reading every row.
Line sketch of an investigator at a laptop with question marks above her head

The question asker

"Who does he call most? Which phone? Where does he sleep?"

The pattern
Asks the same three questions of every record, and has no time to learn a menu.
What they needed
Answers to the same three questions, without building them each time.
Line sketch of an investigator checking a number on his phone, with a profile on a screen beside him

The name chaser

"A number is nothing until I know whose it is."

The pattern
Leaves the record to look a number up somewhere else, then loses the row.
What they needed
A name for a number, without leaving the record.

What already existed

The existing tools show nothing until you fill in a search form

Investigators were not short of software. The tools sold for this work are old, and most are a spreadsheet with a window around it. They ask for the right question before they show anything.

A search screen with radio buttons for number, IMEI, first cell, and tower address, and two empty data tables
You start with a form

The tables stay empty until you already know what to search for.

A desktop app with a ribbon menu, a spreadsheet grid, and small panes for max call, max duration, max tower, and max IMEI
The right questions, the wrong shape

The questions the investigators asked us, split across small panes and menus.

A report window with two dense grids of numbers side by side, checkboxes, and dropdown filters
Every answer opens another grid

Rows all look the same, and nothing on screen says which one matters.

What I decided

Show the whole record first, and color every repeat

The obvious version was a search screen like the tools already sold, a form first and rows after. I did not build it, because every investigator we watched started by reading, not by asking. So the case opens on every call, and each repeated value carries a color.

Try the switch. The table is from our design. Color coding
SnoA PartyB partyDateDurationTimeTypeFirst cell ID
19928292924992232323207/02/202439018:48:12CALL-IN404-98-8702-230658673
29928292924992232323207/02/202418023:10:00CALL-OUT404-98-8702-230658673
39928292924992232323207/02/202417122:50:00CALL-OUT404-98-8702-230658673
49928292924992232323207/02/202415122:30:00CALL-OUT404-98-8702-230658673
59928292924992232323207/02/202414022:10:00CALL-OUT404-98-8702-230658673
69928292924992232323207/02/202412021:50:00CALL-OUT404-98-8702-230658673
79928292924822252323207/02/202412021:30:00CALL-IN404-98-8702-230658673
89928292924822252323208/02/20242021:10:00CALL-IN404-98-8702-230658673
99928292924822252323208/02/20242820:50:00CALL-IN403-98-8702-230658673
109928292924822252323208/02/20241220:30:00CALL-IN403-98-8702-230658673
119928292924772232323208/02/20241120:10:00CALL-IN403-98-8702-230658673

The groups appear on their own, with no sorting, no filters, and no form to fill in first.

A fair question

If you cannot see the colors, sorting and filters still work

Every group can also be sorted, filtered, or isolated with Show only this number. A reader who cannot tell pink from blue loses the shortcut, not the answer. With hundreds of numbers, colors stop helping, so a ranked list takes over.

Version one

Version one: one table, with color for repeats and filters for questions

Version one put the whole record in one table and used color to do the scanning. It had no tabs and no charts yet.

Start, pick the files from the case, and the report builds. Then you ask a question with a filter, the part that turned out to be the problem.

What testing showed

The answers were there, but investigators had to learn the filters first.

Investigators are investigators first, not software users. Record after record, the same investigator opened the filter builder and rebuilt the same small rules. He did not notice he was doing it. I should have seen that coming.

Version two

Version two: each question became a tab at the top

We kept the table and added a tab across the top for each question from the field. We named every tab in the words investigators already use, like B party and day stay.

Version two: the call table with a row of tabs above it, one for each common question

Each tab answers one question, in one tap.

Reading the shape

A graphical view shows the patterns that rows cannot

Some questions are about routine: when a phone is busy, and who sits at the center of its calls. Rows cannot show that, so we added a graphical view. It turns the record into pictures, so a pattern like late night calls to one number stands out at a glance.

The graphical view: call totals, top numbers, and a chart of incoming and outgoing calls per day

The graphical view, one tab next to the table.

The heatmap: one square per hour for each day, darker for more calls
When the phone is busyThe heatmap shows each hour of each day. Darker squares mean more calls.
Node analysis: the phone in the middle, with the numbers it called around it, sized by calls
Who it talks toThe phone sits in the middle. Each number around it is sized by how often they talked.

What they asked for next

Decode shows who owns a number, without leaving the record

In testing, we watched investigators leave the record to look a number up in other OSINT tools. Switching tools broke their flow, so we built the lookup into the CDR itself. Now the owner appears beside the row, and everything stays in one place.

Jarvis One · CDR Analyzer

One tap on a B party number brings back the name, phone company, and address. The owner card is the design's own sample.

What happened

After a week with the prototype, investigators went to the tabs first.

A short test with us watching is not real work. So the investigators used the prototype on their own cases for a week. Here is what we found when we came back.

  1. Tabs

    They opened a tab, not a filter

    With a question in mind, the investigators we watched went to a tab before the filter builder.

  2. Color

    Repeats stood out first

    They told us repeated numbers and towers were the first thing they noticed, before reading a row.

  3. Shipped

    It is now part of Jarvis One

    CDR Analyzer went live as one tool inside Jarvis One, so a record opens from the case it belongs to.

"I do not want to learn a tool. I want to know who this number talks to."

Investigator, Special Task Force, Lucknow, as I remember it

What I would do differently

I would take a prototype to the field before version one, not after it. We spent a whole round learning that investigators are not software users. One afternoon in Lucknow with a paper mock of the tabs would have told us the same. Two months earlier nobody on our team knew what a call record was. By the end, the investigators were opening their records to the tabs before reading a row.

Next case study

Making an AI assistant easy enough for busy leaders

A chat assistant for store data, and the two changes made after adoption was low.

Read case study
Jarvis GPT home with a greeting, a question box, and a morning summary