To choose entity resolution and link analysis software in 2026, evaluate it on eight things: how well it resolves the same person or company across misspelled, aliased, and duplicated records; whether it maps every connection into one queryable graph; whether you can search in plain language; whether every node and edge traces back to a source record (so findings hold up in audit or court); and whether it can run on-prem or air-gapped for sensitive data. If a tool can't do all five honestly, it isn't ready for real investigations.
Most teams don't fail because they lack data. They fail because the same person appears five different ways across five systems, and no one can prove how two records connect. Below is a practical checklist you can bring to any demo.
What is entity resolution, and why does it matter?
Entity resolution is the process of deciding when two records refer to the same real-world thing — the same person, company, account, phone, vehicle, or address — even when the data doesn't match exactly. "Juan Carlos Pérez," "J.C. Perez," and "Perez, Juan C." may be one man or three. A registry typo, a nickname, a transposed ID number, or a shell company with a slightly different spelling can all hide the connection you're looking for.
Without entity resolution, link analysis is built on sand: you'll draw a network that misses the real links and invents false ones.
What is link analysis?
Link analysis maps how resolved entities connect — who owns what, who called whom, who shares an address, a bank account, or a director. Good link analysis lets you search one name and get the whole network back: multi-hop connections (the supplier of the cousin of the official who signed the contract), not just direct matches.
The question is never "is this name in the data?" It's "who is this person actually connected to, and can I prove it?"
The 8-point evaluation checklist
Use these criteria to compare platforms. Score each honestly.
- Entity resolution quality. Does it merge duplicates, aliases, misspellings, and near-matches across structured and unstructured sources — or just exact-match join keys? Ask for a live test on your own messy data, not a clean sample.
- Everything in one graph. Can it ingest databases, warehouses, APIs, contracts, PDFs, case files, and registries — structured or not — and put them into a single connected graph? Siloed tools force analysts to reconcile by hand.
- Multi-hop link analysis. Can you traverse two, three, four hops out from a name and see indirect relationships? Direct-match-only tools miss the layers where risk usually hides.
- Natural-language search. Can a non-technical investigator ask a question in plain English or Spanish and get an answer, or does every query need a specialist and a query language?
- Source traceability on every node and edge. This is non-negotiable. Every entity and every connection must link back to the exact record it came from, so findings are defensible in audit, procurement, and court. If you can't cite it, you can't use it.
- Deployment control for sensitive data. Can it run on-premises, sovereign, or fully air-gapped? Investigations, financial intelligence, and law-enforcement data often legally cannot leave your environment.
- Human-in-the-loop. The software should surface connections and let a person decide — not auto-accuse. Look for review, confidence, and the ability to confirm or reject a merge.
- Fit to the real workload. Investigations, anti-corruption and procurement review, organized-crime mapping, financial intelligence, and enterprise due diligence / KYC / AML / fraud / supply-chain risk each stress the tool differently. Test against your actual use case.
On-prem vs. cloud: which do you need?
For most investigative, AML, and government intelligence work, the data is sensitive enough that where it runs matters as much as what it does. Ask: Can the vendor deploy inside our environment? Can it run air-gapped for classified or sovereign data? Does any data leave for processing or model calls? A tool that's excellent but cloud-only may simply be disqualified before you compare features.
How is this different from a search engine or a database query?
A search engine finds documents. A database query returns rows that match. Neither one resolves that two differently-spelled rows are the same entity, and neither one maps the network between them. Entity-graph intelligence does both: it decides what's the same, connects everything, and lets you ask the graph questions in plain language — with a citation behind every answer.
Common mistakes buyers make
- Judging a demo on clean sample data instead of your own duplicated, aliased, multilingual records.
- Buying pretty visualizations with no source traceability — beautiful charts you can't defend.
- Ignoring deployment until legal review kills the deal in month three.
- Assuming exact-match search is "good enough" and quietly missing every alias and shell.
Where Axentra Sherloc fits
Sherloc is Axentra's entity-graph intelligence and search platform, built for exactly this checklist. It ingests everything you already hold — databases, warehouses, APIs, contracts, PDFs, case files, registries, structured or not — resolves the real people, companies, accounts, locations, and assets inside (across duplicate, misspelled, and aliased records), and maps how they all connect into one graph. Search one name and get the whole network back, with multi-hop link analysis and natural-language search in English or Spanish.
Every node and edge is source-traceable — defensible in audit, procurement, and court — and Sherloc is built for sensitive data: on-prem, sovereign, or air-gapped. Teams use it for investigations, anti-corruption and procurement, organized crime, financial intelligence, and enterprise due diligence, KYC, AML, fraud, and supply-chain risk. It layers on top of the systems you already run — no rip-and-replace.
If you're evaluating options, bring the eight-point checklist to every demo, including ours. Talk to us and test Sherloc against your own messy data.