---
title: "Counterintelligence: Leads, Hypotheses, and Due Process"
canonical_url: "https://psychologicalwar.org/wiki/counterintelligence"
release: "2026.07.18-education-wip.16"
generated_at_utc: "2026-07-20T11:27:44Z"
primary_provenance: "REAL-WORLD INTERPRETIVE"
review_status: "Editorial synthesis — external subject-matter review pending"
content_sha256: "4c596c49e97dc5e03265a471ef6ff9f403c50bd75e5e2a60aac890c6cdc4866a"
---

> **Offline public educational edition.** This file contains only the public, non-operational edition available at the canonical URL. It contains no private UAI memory, protected original report, provider detail, credential, or runtime implementation record.
# Counterintelligence: Leads, Hypotheses, and Due Process

> **Primary provenance:** REAL-WORLD INTERPRETIVE
> **Confidence:** moderate  
> **Jurisdiction:** International / varies by jurisdiction  
> **Date range:** Historical and contemporary  
> **Review status:** Editorial synthesis — external subject-matter review pending  
> **Review date:** 2026-07-18 UTC

## Orientation

A defensive approach to insider risk and hostile collection that separates access from action, anomaly from proof, and institutional concern from guilt.

### Why it matters

Counterintelligence can protect people and institutions, but poorly bounded suspicion can also create false positives, retaliation, and self-confirming investigations.

### Three key points

- Access creates opportunity, not proof.
- Canary or compartment markers are leads, not verdicts.
- Independent corroboration and appeal are essential.

## Insider-risk governance

**Primary provenance:** REAL-WORLD INTERPRETIVE

Define protected assets, lawful monitoring, reporting thresholds, review authority, data retention, anti-retaliation safeguards, and appeal before a crisis occurs.

## Access versus action

**Primary provenance:** REAL-WORLD INTERPRETIVE

A person may have access without using it, act without the suspected access path, or appear in records because of routine work. Build explicit access, opportunity, and action timelines.

## Anomaly versus proof

**Primary provenance:** REAL-WORLD INTERPRETIVE

An anomaly is a deviation from a baseline. It can arise from error, maintenance, legitimate exception, compromise, deception, or incomplete data. Consequential conclusions require corroboration.

## Competing hypotheses

**Primary provenance:** REAL-WORLD INTERPRETIVE

Maintain several explanations, including innocent, procedural, technical, medical, organizational, and hostile possibilities. Record what evidence would increase or decrease each one.

## Source and chain of custody

**Primary provenance:** REAL-WORLD INTERPRETIVE

Preserve who collected evidence, when, how, under what authority, how it was transformed, who accessed it, and what may be missing. A technically genuine item can still be misleading outside context.

## Institutional false positives

**Primary provenance:** REAL-WORLD INTERPRETIVE

Pressure to find a culprit, protect leadership, close a case, demonstrate vigilance, or defend an existing theory can distort inquiry. Independent review and documented dissent reduce that risk.

## Known limitations and gaps

- Public evidence about intelligence institutions is incomplete by design and often uneven across jurisdictions.
- Historical cases can illuminate methods but should not be treated as universal templates.
- Game examples are fictional abstractions and do not establish real-world facts.

## RogueIntelligence.org connections

**GAME MECHANIC**

- [Shadow Chorus](/operations/shadow-chorus) — Tests whether a copied persona assessment was evidence, camouflage, or institutional convenience.

## Source notes and safety transformation

This is a complete public educational edition authored from the protected research corpus. Full internal reports remain preserved for maintainers where their original wording contains implementation strategy or operational detail that is inappropriate for the public companion. Public material intentionally omits executable intrusion, interception, evasion, coercion, document-fraud, targeting, and real-person profiling instructions.

- Protected source record: **Alliance Counter-Intelligence Directive: Leak Investigation**
- Protected source record: **Counterintelligence Directive: Alliance Leak Investigation**
- Protected source record: **Post-Mortem: Catastrophic Breach of the Agency Data Core**

## Review, corrections, and reuse

This WIP edition was last generated on 2026-07-18 UTC. External subject-matter, cultural, legal, accessibility, clinical, or lived-experience review remains pending wherever the review status says so. Material corrections are published in the [corrections ledger](/corrections).

Citation should identify this page as a PsychologicalWar.org public educational edition rather than as a primary historical or clinical source.
