One capability, from first mention to measured response.
DSM-SOC watches the public information environment around a principal 24×7, turns raw noise into graded, decision-ready intelligence, counters manufactured narratives with lawful measured response — and, when the evidence justifies it, anticipates the next surge before it breaks. Every judgment carries its confidence, its sources and its audit trail. Every claim the client repeats in public can be traced to evidence within the hour.
One picture of the machine.
Collection adapters into an append-only event stream; analytic services that propose; a human gate no output can bypass; six client and operator surfaces. Phase 3 services land on the same spine behind configuration flags. Phases never fork the system.
One picture of the machine
Collection adapters → evidence store + event stream → analytics → human gates → client surfaces · one data spine, three phases, no rebuilds
The one-sentence architecture. One append-only data spine; analytic services propose; named humans dispose; phases are configuration gates earned by evidence. A second principal, a second ministry or a second country is a configuration file — a deployment, not a rebuild.
Separating what is observed from what is assessed.
Sources graded on the Admiralty scale, probability words fixed to numeric ranges, attribution tested against competing hypotheses rather than asserted, and every machine classification human-validated before it reaches a report. When an attack is artificial, the client can prove it — documented behaviourally, not alleged — and calibrate the response to real opinion instead of manufactured outrage.
The picture
The week in one look, and the split that decides the response: excluding cluster-amplified content, the week's negative shift nearly vanishes. Organic criticism is specific and remediable; amplified criticism is generalised and accusatory. They require different answers.
The register
Every storyline under observation, graded CRITICAL to POSITIVE, each carrying origin with source grade, trajectory, authenticity split, verification status and escalation tripwires. Registering a claim never endorses it.
The proof
Six mutually corroborating behavioural indicators, the creation-date histogram, the template library with its replicated typo, DISARM technique mapping — and structured attribution scored against rival hypotheses.
What is real opinion — and what is manufactured
AI-assisted classification across en · zu · xh · st · af · human-validated on every high-impact item
| Positive | 29.7% |
| Neutral | 41.9% |
| Negative | 28.4% |
Organic criticism is specific and remediable ("when will Ward 14 be connected?"). Amplified criticism is generalised and accusatory. They require different answers.
Early indicator: the campaign hashtag itself may be contested territory next week — hijack watch I-5 is live at the 30% trigger.
Screen 02 · Sentiment Intelligence. The number that changes the decision is not the negative share — it is the fact that a third of it was manufactured, and that the organic remainder names a fixable delivery problem.
Intelligence turned into lawful action.
Alerts become action inside agreed rules of engagement: claims graded against evidence within four hours; verified facts published faster than falsehood spreads; inauthentic networks removed through the platforms' own rules, tracked to conclusion; credible neutral voices equipped with checkable material; and every campaign measured — framing shift, share-of-voice decay, honest attribution.
The seven-stage response cycle
Every action has an owner, a status and a measured result. The doctrine is fixed: respond to the claim, never the hashtag; never engage inauthentic accounts directly; measure the framing shift every news cycle.
Message discipline — approved lines
Core line. "The contract followed the full prescribed procurement process. Evaluation scores and the audit trail are published; we invite anyone to examine them."
Bridge from the hashtag. "We understand the concern. Here are the facts, and here is where to verify them independently."
What we do not do. Engage, name or amplify inauthentic accounts; speculate on motive; over-claim.
Who is winning — one shared picture
Every active response operation, enforcement progress, the verification queue and the early-warning watchlist · runs on Phase 1 tooling, no new platform
| Op | Narrative | Stage | Owner | Next |
|---|---|---|---|---|
| NRP-011 | N-04 tender allegation | Amplify · day 9 | Comms + Response Cell | Daily review |
| ENF-019 | CL-2026-019 takedowns | Enforce · 56 pending | Black Cube Defence | Weekly tracker |
| WATCH-021 | #KhanyisaFail variant | Detect · seeded by known amplifiers | Duty analyst | Cluster-linkage test |
| EDP-004 | Executive digital protection | Steady · 2 impersonations down | Response Cell | Monthly harden |
Doctrine on every op: respond to the claim, not the hashtag · never engage inauthentic accounts directly · measure framing shift every news cycle.
Screen 13 · Response Command Dashboard. Risk back below ELEVATED, three active operations with stages and owners, the verification queue inside its four-hour SLA, and the early-warning watchlist for the by-election window — one shared picture on existing tooling.
Anticipation, earned from evidence.
Phase 3 is the platform, and it is specified from two phases of the client's own record — which is exactly why it is aimed at their real threats rather than a brochure's. The forecaster learns from observed narrative lifecycles. The network mapper is calibrated on real coordination signatures. The deepfake detector knows the principal's verified voice. The risk weights reflect what actually threatened this client — not a vendor's averaged industry profile.
The surge before it breaks
Five weeks of forecast per narrative with confidence bands and a published backtest hit-rate. Every miss is reviewed monthly and the model retrained. A forecast is decision-support — never a headline.
Is this recording real?
Acoustic forensics, biometric voiceprint comparison against the consented baseline, breath and prosody analysis, provenance. A fabricated clip caught at three accounts and ~1,200 plays, with the rebuttal kit pre-built.
The highest-tempo fortnight
Election mode is a configuration, not a build: the same platform compressed to what matters in the final twelve days — provincial pressure, integrity watch items, a countdown forecast. Issue-mood only; never candidate polling.
Everything, on one screen, in real time
The single pane of glass every Phase 3 capability feeds — every AI output reviewed by a duty analyst before it surfaces
The safeguard that keeps automation trustworthy: the platform proposes; the analyst disposes. Every card above carries its review state.
Overall risk MODERATE (54/100, ▼2). N-04 continues to decline (SOV 8%→7%); overnight enforcement removed 12 further cluster accounts. Two items rising: #KhanyisaFail seeded by known amplifiers, and the contained synthetic-audio deepfake of the Minister (94% AI-probability). Forecast: hostile-narrative pressure will rise into the 26 Aug by-election peak (W+3, 80% confidence). Recommended focus today: sustain positive delivery amplification in the Eastern Cape; hold the deepfake rebuttal ready; watch #KhanyisaFail for cluster linkage.
Screen 21 · Executive Threat Command Centre. Composite risk, the forecast, synthetic-media flags, active clusters, entity scores, the live feed with its review states, and the 06:00 brief that writes itself from the matrix — with the safeguard on every card: the platform proposes, the analyst disposes.
Which storyline surges next — and when
Learned from the lifecycle of thousands of narratives observed in Phases 1–2 · the difference between bracing for impact and preventing it
| Narrative | Observed | W+1 | W+2 | W+3 · by-election | W+4 | W+5 |
|---|---|---|---|---|---|---|
| N-04 tender allegation | Decaying | |||||
| #KhanyisaFail variant | Surge | |||||
| By-election "referendum" | Surge | |||||
| Load-shedding rumour | ||||||
| Khanyisa delivery (organic) |
Model discipline: forecasts carry confidence bands and a published backtest hit-rate; every miss is reviewed monthly and the model retrained on the growing corpus. A forecast is decision-support — never a headline.
Why this could not be built first: the model is trained on narrative lifecycles observed in Phases 1 and 2 for this client's actual threat environment. Built earlier, it would be powerful in theory and mis-aimed in practice.
Screen 22 · Predictive Narrative Analytics. Five weeks of forecast per narrative: the tender story decaying, the hashtag variant and the referendum frame surging into the by-election week.
Each phase earns the next.
The commercial architecture and the build plan are the same drawing. A single large leap of faith is replaced by three deliberate steps — so by the time the platform is bought, its specification was written by the client's own results.