Survivable under scrutiny.
A national information capability is judged twice: once on what it produced, and once — usually later, usually publicly — on how it produced it. The second judgment is the one that ends programmes. Everything below is contractual, displayed to the client, asserted in code where code can assert it, and reviewed externally.
The restraint is the product.
This is not a values statement bolted onto a capability. It is written into the engagement, enforced at the collection layer, and tested in continuous integration — a regressed permission fails the build. It is also the commercial argument: Phase 2 counters manipulation the way a credible institution should, because anything else would make the response indistinguishable from the operation it exists to expose.
The governing doctrine. A response that would be indefensible if it came to light is a liability, not a capability. When in doubt: collect less, grade more, log every access, and keep a human in the loop.
Never done, by design
No fake accounts, sock puppets or manufactured personas — in any phase, for any reason
No covert messaging or paid amplification disguised as organic support
No deception of audiences — every credible voice we equip speaks in their own name, with checkable material
No private accounts, private messages or authenticated content — the collection code cannot reach them
No device surveillance, interception, location tracking or private-life monitoring of any person
No candidate polling — issue-mood only; the boundary is contractual and machine-checked
No protected attributes in any model — race, religion, health, orientation excluded at the feature layer and verified at every model change
No machine output reaching a client surface without a named human decision
No inauthenticity finding from a single signal, or from third-party bot scores alone
Five boundaries, printed in every report.
They appear on the operational screens because the analysts work inside them, and in the deliverables because the client is entitled to see the limits of what they are being told.
- OSINT only
- Public posts, public groups, public online news. No private accounts, no private messages, no authenticated content, no device surveillance. The boundary is enforced in the collection adapters — it is a machine rule, not an instruction to staff.
- Data protection
- Lawful basis documented per collection stream. Special-category data is never collected. Data-subject access request route defined. Author identities pseudonymised at rest; re-identification only in an open case, logged with a reason on an auditable view.
- Platform terms of service
- Collection methods are reviewed against each platform's terms quarterly. Enforcement uses the platforms' own published rules — legitimacy is the weapon; the evidence pack is built to meet their coordinated-inauthentic-behaviour reporting thresholds.
- Compliance & ethical framework
- The engagement's own written boundary: overt, lawful, attributable response only. Reviewed at the monthly service review; changes require written client agreement and appear as an audit event.
- Scope is consented
- What may be watched is a decision, recorded — never a drift. Entities are added or re-prioritised only by written client agreement at the monthly review. Opposition figures are monitored in their public role only, never their private life. Exclusion filters remove homonyms and unrelated namesakes at collection: precision protects innocents.
Every model named, versioned, measured — and gated.
The oversight console runs on the model registry: what each model may propose, what it may never do, and how its quality is scored. Quality figures are published to the client alongside the SLA table — including the misses. Trustworthy because it is measured, gated and honest about its limits.
| Model | Phase | May propose | May never | Current quality |
|---|---|---|---|---|
| sentiment_v4 | P1 | Sentiment labels, 5 languages | Publish unvalidated high-impact items | 85–88% precision (code-switched) · declared |
| anomaly_v2 | P1 | Velocity / baseline flags | Raise client alerts directly | 92-min flag on 30 Jul event → threshold retuned |
| cib_fingerprint_v3 | P1 | Cluster candidates, similarity scores | Confirm a CIB cluster (two-person human rule) | 0 false clusters confirmed to date |
| forecast_v1 | P3 | Surge / decay forecasts + confidence | Appear unreviewed in any brief | 78% backtest hit-rate · published monthly |
| netmap_v1 | P3 | Inferred structure with grades | Assert attribution as fact | Graded per node · analyst-checked |
| synthmedia_v1 | P3 | Synthetic probability + forensics | Notify the client pre-verification | 1 confirmed / 1 scare correctly cleared |
| briefwriter_v2 | P3 | Draft analysis & report paragraphs | Use free-text probabilities (yardstick lint) | 11% edit/override rate · falling |
Standing prohibitions — asserted in tests
No protected attributes in any model — excluded at the feature layer, verified at every model change
No auto-publication paths — CI fails if any model output route bypasses the review queue
No single-signal findings — inauthenticity requires converging indicators; bot scores corroborate only
No content generation for influence — models draft analysis and rebuttals for named human release, never covert or unattributed content
Training-data provenance
Models train on this engagement's own validated casework, plus the platform's cross-client pattern library where contracts permit — never on another client's identifiable material. Every model change carries a completed governance checklist, and override analysis is the primary feedback loop rather than an afterthought.
The safeguard, in one line. The platform proposes; the analyst disposes. Automation is trustworthy exactly because it is supervised — AI at machine scale, judgment at human standard.
Every claim traceable, every probability fixed.
Two scales do most of the work. The Admiralty system grades source reliability against information credibility on every stream and every claim. The probability yardstick binds estimative language to numeric ranges, and a release lint blocks any free-text probability that falls outside them — so a judgment can never soften in the retelling.
Admiralty grading
Source reliability
| A | Reliable — consistent accuracy |
| B | Usually reliable |
| C | Fairly reliable |
| D | Not usually reliable |
| E | Unreliable |
| F | Cannot be judged |
Information credibility
| 1 | Confirmed by independent sources |
| 2 | Probably true, partly corroborated |
| 3 | Possibly true, not corroborated |
| 4 | Doubtful |
| 5 | Improbable |
| 6 | Cannot be judged |
The F6 rule. An ungradeable source can still be reported — as a claim under observation, never as fact. That is how an anonymous allegation enters the narrative register without the register endorsing it.
The probability yardstick
Printed in every report. Enforced at release.
| Almost no chance | <5% |
| Very unlikely | 5–20% |
| Unlikely | 20–45% |
| Roughly even | 45–55% |
| Likely / probable | 55–80% |
| Very likely | 80–95% |
| Almost certain | >95% |
Why it matters. "Likely" always means 55–80%. "Almost certain" always means >95%. A judgment cannot be strengthened by a briefing, or hedged away by a summary.
ACH on every attribution
Evidence is scored against rival hypotheses; the strongest hypothesis is the one with the fewest inconsistencies — never the most confirmations. Where public data cannot support specific-actor attribution, the report says so explicitly rather than implying more.
Coordination findings
No single person can move an account set from cluster candidate to confirmed coordinated inauthentic behaviour. A duty analyst and the technical lead must both sign before any coordination claim exists.
Mandatory before release
Any product carrying an attribution or coordination claim goes to an independent reviewer whose brief is to break the judgment, in writing. Findings and their resolution are recorded — the client sees the review that produced what they read.
The service is graded like it grades everything else.
Computed from the same append-only event stream that produces the intelligence, published monthly in the executive report, with credits when missed. The SLA table drives engineering, not just reporting: July's detection review lowered the wave-detection threshold because the numbers said it should.
| Service element | Contracted level | How it is measured |
|---|---|---|
| CRITICAL alert notification | ≤15 min | From analyst confirmation to client notification — secure email, liaison channel and phone call |
| ELEVATED alert notification | ≤60 min | Same chain; every alert plotted against its line in the monthly report |
| Verification brief turnaround | ≤4 h | From tasking to graded verdict with cleared rebuttal material (Phase 2) |
| Weekly Intelligence Report | Mon 08:00 | Delivered through the client portal with read receipts |
| Human validation of high-impact items | 100% | Contractual; item count published monthly |
| False-positive rate | ≤5% | Analyst corrections as a share of machine classifications, published monthly |
| Monitoring availability | 24×7 · ≥99.5% | Duty-analyst roster plus platform uptime, including load-shedding contingency |
| Escalation chain | Tested monthly | Duty analyst → Engagement Manager → Director, exercised and recorded |
Preserved, hashed, lawful.
Every finding is built to survive scrutiny: capture provenance, chain of custody, retention and access rules on one screen. A pack that reaches a platform, a regulator or a court carries its own audit trail.
See the back-office screens →- Integrity
- SHA-256 manifest per evidence pack. Capture timestamp, capturing analyst, hash at rest, and every access logged.
- Retention
- Evidence packs — engagement + 5 years, or per legal hold. Raw collection — rolling 12 months. Client data — SA-region processing under operator agreements on every vendor.
- Access
- Named analysts and the Engagement Manager only. Staff SSO with hardware keys; client portal 2FA with device binding, 15-minute idle timeout and watermarked, logged downloads.
- Traceability
- Everything is an event. One finding runs from 18,700 public posts to a client decision in six evented hops — and the platform is built to pass a one-hour auditor test on any figure in any report.
- External review
- The compliance and ethical framework is reviewed by external legal counsel quarterly. A breach-response runbook is filed and drilled.
Why this section exists at all. Any competent vendor can show a client a dashboard. Very few can hand a client's inspector-general, auditor or court the complete provenance of a number that was published under the state's name. That is the difference this framework is for.