An email investigation or review is never a single action. It is a sequence: receive the archive, hash it, search it, code what you find, write it up. The hard part is showing later exactly which steps you took, in what order, and on which files. mailin 2.0 ships 47 guided workflows across five roles that turn each of those jobs into a numbered, reopenable document, and this post explains how the runner works, what Documents & History keeps, lists every workflow by role, and walks through one of them end to end.

How the guided workflow runner works

You pick the job, for example Phishing Incident or Production Run, and mailin opens a step-by-step runner. A roadmap rail down the side shows every step and marks where you are, so a job you left on Tuesday still makes sense on Thursday. Heavier tools open beside the job rather than replacing it, so you never lose your place. The workflows section on the home page shows the five role sets at a glance.

Each step has fields to fill in. When a step is filled, mailin marks it complete automatically; if you prefer to close steps by hand, that behavior can be toggled off. Everything auto-saves as you go. There is no save button to forget, and because every job is filed as a reopenable document, closing the app mid-job does not lose your work.

Attachments and one-tap sign-off

Two features matter most when someone else will read the record. First, every step can carry attachments: the exact files and emails the step relied on. If step 2 hashed a particular .pst, that file is linked to step 2. If step 3 flagged six messages, those six messages are attached to step 3 rather than described vaguely in a note.

Second, Forensic and Legal workflows offer an optional one-tap sign-off. It records who completed the step and when, as an attestation on the document. It is optional because not every job needs it, but when an examiner or reviewer is expected to stand behind a step, the attestation is right there in the record.

Documents & History

Every job is saved under a document number, and Documents & History is where those documents live. You can reopen any of them, export them to CSV, and build cross-document reports that pull several jobs together. mailin also keeps a per-email history, so you can ask what has been done to one specific message across every job that touched it, and it can produce an end-of-day case activity report summarizing the day's work.

Notes on a document are append-only: you can add to the record but not silently rewrite it. If a decision needs to be undone, you create a reversal document rather than deleting the original. Both choices exist for the same reason the sign-off does. The record should show what actually happened, corrections included.

The built-in workflows are templates, not fixed scripts. On the Professional tier you can clone a workflow, rename it, and reorder its steps to match how your team actually works.

The frameworks behind the templates

The five role sets are modeled on established process references rather than invented from scratch. Forensic workflows are modeled on NIST SP 800-86. Legal / eDiscovery workflows follow EDRM. IT / SOC workflows follow NIST SP 800-61. Journalist / Researcher workflows follow an ICIJ-style sequence: verify, search, cross-reference, annotate, fact-check, publish. Personal workflows follow a simpler chain: Backup, Dedupe, Categorize, Purge, Export.

Being modeled on a framework does not mean mailin certifies anything against it. It means the steps and their order will look familiar to anyone trained on those references, and the documents mailin produces will map onto the language those references use.

All 47 workflows by role

Forensic (10)

Legal / eDiscovery (10)

IT / SOC (10)

Journalist / Researcher (10)

The journalist timeline is produced inside Story Build rather than as a separate job, which is why the role counts as ten.

Personal (7)

Walkthrough: Evidence Intake & Review

Here is how the first Forensic workflow runs, step by step.

  1. Receive & Identify. You record the case number, custodian, source and purpose. Completing this step posts an Import document, so the intake itself becomes part of the numbered record.
  2. Preserve & Hash. You note the acquisition method and the hash algorithm and add a seal note. mailin computes a SHA-256 hash on every email at import regardless; this step is where you document it. The chain of custody post covers what those hashes are later checked against.
  3. Examine & Code. You review the messages and code them, attaching the ones that matter to the step.
  4. Analyze. You work through IOCs and anomalies: extracted IPs, URLs and file hashes, unusual sending patterns, off-hours timing.
  5. Document & Report. You generate an activity report, and the document is filed under its number.

Anomaly detection and IOC extraction rely on mailin's on-device analysis, and like any automated output they can be inaccurate or incomplete. Verify anything you intend to rely on against the underlying emails, which the step keeps attached. The same pattern applies to the Legal set, where the Production Run workflow takes a batch from coding through to a produced set.

These features are designed to support common records-integrity and eDiscovery workflows. Admissibility of digital evidence is jurisdiction-specific and depends on factors beyond any single software tool — consult qualified legal counsel for evidentiary use. mailin makes no warranty of fitness for any specific legal or regulatory purpose.

FAQ

Can I change the built-in workflows?

Yes, on the Professional tier. You can clone any built-in workflow, rename it, and reorder its steps. The originals stay available.

What happens if I quit mailin in the middle of a job?

The job auto-saves as you fill in each step. Reopen it from Documents & History under its document number and the roadmap rail shows where you stopped.

Do the workflow documents leave my device?

No. Documents & History is stored on-device with the rest of your archive, mailin has no account, and the developer collects no data. A document leaves only when you export it, for example to CSV.

Try mailin free

Import up to 500 emails with no account and nothing uploaded. iPhone, iPad and Mac — one purchase.

Download on the App Store