Forty-four working screens.
Not a brochure's mock-ups. Every screen below is a working design of a surface the service actually produces — real fields, real rules, real states, fictitious data. They tell one story in order: a manufactured storm detected in minutes, a measured lawful response, and the platform that anticipates the next one.
The watch floor.
The running service: the week in one look, sentiment split into real and manufactured, the narrative register, one event chain end to end, the cluster proof, the diffusion map, structured attribution, the CRITICAL alert, media framing, the voices that matter, geography — and the graded judgments that carry it all.
Cluster CL-2026-019 — proving the storm is manufactured
214 accounts assessed with HIGH confidence to be coordinated and inauthentic · evidence pack BC-EV-2026-019 preserved
| Indicator | Observation | Weight |
|---|---|---|
| Creation clustering | 174 of 214 accounts (81%) created within 60 days; two single-day bursts on 12 Jun and 03 Jul | High |
| Content similarity | 81% of posts fall into 9 near-duplicate templates (n-gram ≥ 0.92); identical typo "acountability" replicated | High |
| Temporal sync | 68% of activity 06:00–08:00 SAST in 4–7 minute waves; near-zero weekend variance | High |
| Amplification ratio | 96% retweets/quote-posts vs 4% original; median 11s from wave-leader to first 20 amplifications | High |
| Audience authenticity | Median follower count 47; 77% of followers are other cluster members — a closed loop | Moderate |
| Profiles | Bios from a 12-phrase pool; stock or synthetic-suspected imagery (formal detection is Phase 3) | Moderate |
Third-party bot scores (S10, C3) are used as corroboration only — never the sole basis for an inauthenticity finding.
| Tactic stage | Technique | Observed |
|---|---|---|
| Establish Assets | T0080 | 214 accounts pre-positioned Feb–Jul |
| Develop Content | T0085 | 9 near-duplicate templates, localised vernacular |
| Establish Legitimacy | T0097 | "Concerned citizen" personas, 12-phrase bio pool |
| Maximise Exposure | T0049 | Synchronised waves to force trending placement |
| Maximise Exposure | T0119 | X → Facebook 09:10 → TikTok 09:40 |
Escalation awaits decision D-1 · recommended YES by 05 Aug
Screen 05 · Coordinated Activity. Six mutually corroborating behavioural indicators, the creation-date histogram with its single-day bursts, the template library with its replicated typo, DISARM technique mapping, and the handling doctrine — document, never engage.
The 30 July amplification event — anatomy of a managed campaign
One anonymous seed, six wave-leaders, a closed inauthentic ring, limited authentic breakout — not organic virality
Operational meaning: a takedown aimed at the six wave-leaders and the seed degrades the operation's capacity far faster than reporting ring accounts one by one — the targeting logic of the Phase 2 enforcement campaign.
Honest limit: this map was assembled by hand from one platform's public data in Phase 1. Continuous, cross-platform, machine-assembled mapping is what Phase 3 automates — calibrated by exactly this casework.
Screen 06 · Diffusion Network. Takedowns aimed at the hubs degrade the operation fastest — and the hand-mapped effort is exactly what Phase 3 automates.
ALR-2026-0142 — coordinated amplification detected
The most dangerous window in any reputational incident is the hours between something starting and leadership finding out
| # | Action | Urgency | Owner |
|---|---|---|---|
| A-1 | Do not engage the hashtag from official or personal accounts; brief handlers immediately | Critical | Office of the Minister |
| A-2 | Holding statement ready (attached); respond to journalists, not to the hashtag | Critical | Head, Strategic Comms |
| A-3 | Authorise preservation-plus-escalation: CIB reports filed within one business day of instruction | High | Chief of Staff |
| A-4 | Continue scheduled positive content — do not go dark; silence is read as confirmation | High | Digital team |
| A-5 | 15-minute situational call at 12:00 — live dashboard presented | High | Engagement Manager |
Likely trajectory: artificial amplification typically decays within 48–72 hours without fresh material. The key escalation risk is publication of purported "documents" — tripwired for automatic re-alerting (I-1).
Screen 08 · Significant Event Alert. The alert as the client meets it: anomaly numbers against baseline, the detection→notification timeline inside SLA, what this is and is not, and five recommended actions with owners.
The response cell.
Intelligence turned into lawful action: the response command picture, one narrative's playbook, claims graded against evidence in four hours, takedowns tracked to conclusion, effectiveness measured with honest attribution, proof-points staged ahead of forecast pressure, the principal's own footprint hardened — and the monthly review that earns Phase 3.
Proof it works — the N-04 campaign scorecard
For each response campaign: what changed, and how much of the change is attributable to the intervention
| Measure | Before | After | Change |
|---|---|---|---|
| N-04 share of voice | 26% | 7% | −19 pts |
| Allegation-led media framing | 71% | 24% | −47 pts |
| Inauthentic cluster active | 214 | 56 | −74% |
| Verified positive reach (7-day) | 1.1M | 4.2M | +282% |
| Composite reputational risk | 68 ELEV | 54 MOD | −14 |
| Alert → public response | — | 74 min | In SLA |
Attribution, conservatively: the narrative would likely have decayed somewhat on its own once artificial amplification exhausted itself; the response accelerated and deepened that decline. The 47-point framing shift follows directly from same-day facts publication and would not have occurred without it. We report the outcome and our confidence in the attribution — never the outcome alone.
Automatable: verification-brief assembly and framing-shift measurement are repetitive and rules-based — strong candidates for Phase 3 automation.
Human-essential: the decision to respond and the message discipline remain human judgments — Phase 3 supports them, it does not replace them.
Speed ceiling: the 74-minute response was limited by approval steps, not analysis — the finding that shapes the Phase 3 workflow-automation requirement.
Screen 17 · Counter-Narrative Effectiveness. The campaign scorecard measured against the unassisted-decay model with conservative attribution — plus the lessons filed to the Phase 3 ledger: what to automate, what stays human, where the speed ceiling was.
The intelligence platform.
The destination: one command screen fed by every capability, narrative surges forecast five weeks out, a deepfake caught in forty minutes, the hidden network reconstructed and graded, risk triaged automatically, an election fortnight run as a managed operation — and the evidence flywheel plus the human gate that keep it honest.
SD-2026-014 — is this recording of the Minister real?
Detection at the point of emergence, rebuttal armed before the fake spreads — the only window in which a deepfake denial fully works
| Detection signal | Finding | Confidence |
|---|---|---|
| Acoustic forensics | Spectral artefacts at 7 word boundaries consistent with AI splicing | High |
| Biometric voiceprint | 62% match to verified voiceprint — below the 85% authenticity threshold | High |
| Breath / prosody | Absent inter-sentence breath; unnatural cadence uniformity | High |
| Provenance / metadata | No original traceable; first appearance on an anonymous account | Moderate |
| Overall verdict | SYNTHETIC — fabricated audio, not a genuine recording. AI-probability 94%, analyst-verified. | Critical |
Why speed is everything: a convincing fake can reach millions before a denial is drafted. Flagged within the first hour, the response can be live before the fake reaches a general audience.
Calibration: the detector is tuned against the principal's consented, verified voiceprint and imagery baseline — captured in Phase 2, which is why this capability could not be bought off a shelf.
Screen 23 · Synthetic Media Detection. A fabricated 38-second clip caught at three accounts and 1,200 plays — CONFIRMED SYNTHETIC, analyst-verified, with the response kit pre-built and awaiting approval.
Nothing machine-published, ever — the review gate at work
Every AI output queues for a duty analyst: approval, edit or rejection is logged with a reason — the audit trail of trust
| Queued | Type | Proposal | Conf. | Decision |
|---|---|---|---|---|
| 05:58 | Forecast | #KhanyisaFail to cross 10k uses by 17 Aug | 0.74 | Approved · analyst A |
| 05:41 | Cluster grouping | 12 accounts → provisional CL-2026-022 (0.88 fingerprint match) | 0.88 | In review |
| 05:39 | Brief paragraph | Daily-brief line on E. Cape mood shift | 0.69 | Edited · softened per yardstick |
| 05:12 | Takedown draft | 3 re-upload reports · SD-2026-014 fingerprints | 0.97 | Awaiting legal check |
| 04:26 | Risk re-score | Raise "document-drop" likelihood MED→HIGH | 0.58 | Rejected · single weak signal, logged |
Rejections are data: every rejection feeds the monthly model review — the 11% override rate and its direction of error is reported to the client alongside the SLA table.
Screen 28 · AI Oversight Console. Approvals, edits, rejections with reasons, an 11% override rate reported to the client, and the standing rules asserted in code — including the one that matters most: no bypass routes exist.
The back office that makes it defensible.
PIR-driven collection with declared gaps, the validation queue, the QA release chain, the graded source register, the contractual entity register, the service graded against its own SLAs, the evidence vault — and the client portal where decisions are cleared.
The service graded like it grades everything else
Contracted service levels, measured and published to the client monthly — with credits when missed
| Service element | SLA | Performance | Status |
|---|---|---|---|
| CRITICAL alert notification (from analyst confirmation) | ≤15 min | avg 11 min (2 events) | Met |
| ELEVATED alert notification | ≤60 min | avg 19 min (5 events) | Met |
| Weekly Intelligence Report delivery | Mon 08:00 | 4 of 4 on time | Met |
| Human validation of high-impact items | 100% | 100% (5,880 items) | Met |
| False-positive rate | ≤5% | 3.4% | Met |
| Monitoring availability | 24×7 · ≥99.5% | 99.92% | Met |
Detection anatomy, July's CRITICAL event: anomaly flag 92 min after the first wave → analyst confirmation 73 min later → client notified 11 min after that. The tuning review that followed lowered the wave-detection threshold — the SLA table drives engineering, not just reporting.
Screen 34 · SLA & Service Performance. Every alert plotted under its line, and the scorecard published monthly — including the misses when there are misses.
All forty-four screens.
The complete screen pack — each shown at readable size with an explanation, and again as a full A4 landscape plate for detail, printing or projection. Available under NDA as part of the capability pack.