IARPG-OPS-1 online Intelligence operations standard Fictional missions · neutral authorities

Research archive / Espionage operations and tradecraft

RogueIntelligence.org: Comprehensive Classification of Intelligence Operatives and Skill Matrices

The conceptualization of a faction-agnostic, morally ambiguous international espionage simulation requires a fundamental departure from the binary geopolitical narratives of the Cold War. The contemporary intelligence landscape is a multipolar, hyper-capitalist ecosystem where state actors, multinational defense corporations, private military companies, corporate syndicates, and independent operatives constantly…

RogueIntelligence.org: Comprehensive Classification of Intelligence Operatives and Skill Matrices

The conceptualization of a faction-agnostic, morally ambiguous international espionage simulation requires a fundamental departure from the binary geopolitical narratives of the Cold War. The contemporary intelligence landscape is a multipolar, hyper-capitalist ecosystem where state actors, multinational defense corporations, private military companies, corporate syndicates, and independent operatives constantly shift allegiances based on profit, ideology, or survival. In this environment, the traditional concepts of "good" and "bad" are entirely obsolete; there are only operators, objectives, and the consequences of their actions. To populate the world of RogueIntelligence.org with authentic non-player characters (NPCs) and establish deeply realized, playable character archetypes, a granular taxonomy of the global intelligence ecosystem is essential. This exhaustive report categorizes every major type of intelligence operative by operational domain, detailing their real-world inspirations, psychological profiles, specific skill matrices, and tradecraft methodologies. Furthermore, this analysis synthesizes historical case studies and systemic mechanics derived from established tabletop espionage frameworks to provide a structural foundation for simulated geopolitical conflict.

The Global Intelligence Ecosystem: Factions and Structures

The modern espionage landscape is characterized by the privatization of intelligence and the "revolving door" between public service and private enterprise. Operatives frequently transition between state agencies and corporate entities, transferring their highly specialized, taxpayer-funded training into the private sector to function as mercenaries, corporate spies, or strategic advisors1. Understanding the foundational structures of these factions is critical, as an operative's skills and limitations are inherently dictated by their organizational origin. State intelligence apparatuses, such as the Central Intelligence Agency (CIA), the Secret Intelligence Service (MI6), the Mossad, and the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU), operate under the authority of national governments. These organizations possess massive bureaucratic infrastructures, access to global surveillance networks, and diplomatic protections4. However, they are often constrained by political oversight, rigid hierarchies, and the slow pace of governmental decision-making. State operatives are trained to execute the intelligence cycle—planning, collection, processing, analysis, and dissemination—with the ultimate goal of preserving national security, conducting foreign policy, and neutralizing transnational threats such as terrorism and weapons proliferation1. Conversely, Private Intelligence Agencies (PIAs) and Private Military Companies (PMCs) operate on a for-profit basis, unbound by national security mandates and parliamentary oversight. Organizations such as Black Cube, Psy-Group, Kroll, and Hakluyt represent the commercialization of espionage, offering bespoke intelligence gathering, corporate due diligence, asset recovery, and perception management to high-net-worth individuals and multinational corporations8. These entities favor aggressive social engineering, open-source intelligence (OSINT), and legal loopholes to achieve client-driven outcomes. PMCs, ranging from the Wagner Group to Triple Canopy and Aegis, provide armed combat, tactical training, and logistics, often acting as proxy forces for states or multinational extractive industries operating in volatile regions11. Finally, the ecosystem includes corporate competitors and independent lone wolves. Multinational corporations engage in competitive intelligence—a legal practice of monitoring market trends—but frequently cross the line into illicit corporate espionage to steal trade secrets, source code, and strategic planning data14. Lone wolves and independent contractors navigate this fractured landscape without institutional safety nets, selling their skills to the highest bidder on the black market or pursuing ideological vendettas.

Faction Type Primary Objectives Operational Advantages Structural Vulnerabilities Typical Operative Archetypes
State Intelligence National security, foreign policy, counter-proliferation. Massive funding, diplomatic immunity, global technical infrastructure (satellites). Bureaucratic oversight, slow reaction times, strict legal/political constraints. Operations Officers, Intelligence Analysts, Paramilitary Officers.
Private Intelligence Agencies (PIAs) Client-driven outcomes, litigation support, opposition research. Agility, lack of parliamentary oversight, deniability, creative social engineering. Legally vulnerable (no diplomatic immunity), profit-dependent, highly controversial. Private Intelligence Contractors, Social Engineers, FININT Analysts.
Private Military Companies (PMCs) Contractual combat operations, logistics, asset protection. Rapid deployment, heavily armed, utilization of elite former-state operatives. Subject to contract termination, international law scrutiny, lack of patriotic loyalty. PMC Operators, Tactical Specialists, Security Consultants.
Corporate Syndicates Market dominance, intellectual property acquisition. Massive financial reserves, access to cutting-edge R\&D, global supply chains. Vulnerable to insider threats, highly regulated public image, prime targets for APTs. Competitive Intelligence Analysts, Insider Threats, Corporate Spies.
Independent / Lone Wolf Survival, personal vendettas, freelance profit. Total operational freedom, zero bureaucratic footprint, high agility. Severely limited resources, reliance on ad-hoc networks, no exfiltration support. Burned Agents, Freelance Hackers, Mercenary Assassins.

Human Intelligence (HUMINT) and Clandestine Field Operations

The foundation of traditional espionage remains Human Intelligence (HUMINT), which involves the collection of information from human sources through interpersonal contact, manipulation, and covert operations17. Field operatives are deployed globally to recruit assets, infiltrate organizations, and manage networks of informants, relying on psychological acumen and strict operational security. The Operations Officer, traditionally referred to as a Case Officer, Spymaster, or Handler, is the architect of clandestine HUMINT collection. Contrary to popular media depictions, these officers rarely steal documents or execute assassinations themselves; instead, their primary function is to identify, groom, and recruit foreign nationals who possess access to desired intelligence, subsequently managing these individuals as assets4. The psychological profile of a successful Operations Officer requires adaptability, extreme discretion, resilience, and the ability to operate comfortably within complex, ambiguous environments18. Their core skill matrix relies heavily on interpersonal abilities such as elicitation, negotiation, linguistic fluency, and the capacity to project false empathy to manipulate sources22. In a simulation environment, Operations Officers function as network builders, excelling at establishing communication channels and managing cover identities to maneuver through hostile territories without drawing attention. The Deep Cover or Sleeper Agent represents a profound psychological commitment to espionage. These operatives are embedded in a foreign nation for extended periods—often years or decades—living under a meticulously fabricated identity known as a "legend." This legend is supported by forged documents, backstopped personal histories, and seemingly mundane civilian employment5. A prominent real-world example is the Russian "Illegals" program targeted by the FBI's Operation Ghost Stories, where operatives assimilated into American society, married, and raised families while covertly transmitting intelligence back to Moscow26. Sleeper agents require extreme psychological endurance and the ability to seamlessly compartmentalize their lives. Their primary skills involve acting, cultural assimilation, and covert communication techniques such as steganography or burst transmissions. In gameplay, sleepers are invaluable for long-term infiltration, remaining dormant to bypass counterintelligence sweeps until activated for a critical sabotage or exfiltration directive. The intelligence ecosystem is further complicated by the presence of Double Agents and Triple Agents. A Double Agent is a spy who ostensibly works for one intelligence service while secretly providing intelligence to, or disseminating disinformation on behalf of, a rival service5. These individuals are often recruited through ideological alignment, financial incentive, or coercion via blackmail (kompromat)25. A Triple Agent introduces an additional layer of deception, pretending to betray their original employer to a rival agency while actually remaining loyal to the first, serving as an ultimate conduit for strategic deception25. Handlers must constantly monitor these agents for signs of re-betrayal. Operatives engaging in these roles must master disinformation dissemination and interrogation evasion. Within the context of simulated faction dynamics, Double Agents serve as high-risk assets capable of feeding rival organizations "chicken feed"—accurate but low-level, non-damaging information designed to establish credibility before springing a catastrophic trap6. Specialized HUMINT roles also include the Dangle and the Agent Provocateur. A Dangle is an operative intentionally made accessible to a foreign intelligence agency, presenting a fabricated vulnerability or willingness to defect, with the explicit goal of being recruited to function as a pre-planned double agent25. Conversely, the Agent Provocateur infiltrates a target organization not to gather intelligence, but to tempt its members into incriminating actions, violence, or self-sabotage, thereby discrediting the group or justifying a severe crack-down by state authorities20. These roles require exceptional psychological manipulation and legal maneuvering capabilities.

HUMINT Archetype Primary Function Core Skills and Tradecraft Psychological Profile
Operations Officer Recruiting and managing foreign assets. Elicitation, agent handling, surveillance detection, brush contacts. Adaptable, persuasive, culturally fluid, comfortable with ambiguity.
Sleeper Agent Long-term dormant infiltration. Legend maintenance, acting, covert communication, backstopping. Extreme endurance, compartmentalization, ideological dedication.
Double / Triple Agent Strategic deception and counterintelligence. Disinformation dissemination, interrogation evasion, canary trap evasion. Opportunistic, highly stressed, manipulative, deceptive.
The Dangle Intentional recruitment by enemy agencies. Feigned vulnerability, counter-surveillance, psychological manipulation. Risk-tolerant, deceptive, highly disciplined.
Agent Provocateur Sabotage and organizational discreditation. Entrapment, agitation, legal manipulation, inciting violence. Charismatic, manipulative, unburdened by ethical constraints.

Technical and Cyber Operations

As the global infrastructure has become increasingly digitized, espionage has evolved to bridge the gap between human intelligence and signal intelligence. Technical and cyber operatives are responsible for penetrating hardened physical facilities and exploiting complex network architectures to steal data, intercept communications, and disrupt enemy operations. The Technical Operations Officer operates at the intersection of physical infiltration and advanced engineering. These operatives are tasked with collecting intelligence in direct, highly stealthy manners, frequently executing "black bag jobs"—covert, unauthorized entries into target facilities to plant surveillance equipment, clone digital drives, photograph sensitive documents, and exit without leaving forensic evidence4. According to profiles from the CIA's Directorate of Science and Technology, these officers possess backgrounds in aerospace engineering, materials science, or digital signal processing4. Their operational duties require them to pick locks, bypass biometric alarm systems, and deploy additive manufacturing to create custom tools in the field4. Furthermore, they engage in defensive operations, conducting thorough sweeps of critical environments to detect and neutralize enemy listening devices (bugs)27. The psychological profile of a Technical Operations Officer demands intense inquisitiveness, extreme composure under stress, and profound technical creativity30. In a simulation, these operatives are the ultimate infiltrators, capable of manipulating analog and digital hardware to bypass environmental obstacles that would halt a traditional combat operative. The Cyber Operations Officer conducts digital espionage, network exploitation, and offensive cyber warfare. These individuals are responsible for mapping enemy networks, executing penetration tests, hunting malicious actors on internal systems, and deploying bespoke malware4. Cyber operatives frequently belong to state-sponsored Advanced Persistent Threat (APT) groups, which conduct prolonged, targeted campaigns against specific organizations or nations21. Their skill sets include zero-day exploitation, SQL injections to manipulate backend databases, and the development of ransomware designed not for financial extortion, but for systemic sabotage and data destruction16. A critical tactic employed by highly skilled Cyber Operations Officers is the False Flag attack. A false flag operation involves deliberately manipulating digital evidence to make a cyberattack appear as though it originated from a rival nation or competing hacker group34. For example, during the 2018 Olympic Destroyer attack against the Pyeongchang Winter Olympics, Russian military hackers intentionally planted code artifacts mimicking North Korean malware to mislead forensic investigators and trigger geopolitical confusion35. Similarly, the Iranian state-sponsored group MuddyWater has been observed masquerading as a financially motivated ransomware gang to obfuscate their true espionage and data exfiltration objectives33. Cyber operatives dominate the digital battlespace, possessing the capability to blind enemy sensors, drain corporate financial reserves, and frame rival factions to incite proxy conflicts.

Technical/Cyber Archetype Primary Function Core Skills and Tradecraft Real-World Precedents
Technical Operations Officer Physical infiltration and hardware manipulation. Lockpicking, alarm bypass, circuit design, audio/visual bugging, black bag jobs. CIA DS\&T, MI6 "Q" Branch, KGB Technical Units.
Cyber Operations Officer Network exploitation and offensive cyber warfare. Malware development, zero-day exploitation, penetration testing, DDoS. NSA Tailored Access Operations, Russian Sandworm, Chinese APTs.
False Flag Specialist Digital deception and attribution manipulation. Code obfuscation, planting linguistic artifacts (e.g., Cyrillic/Mandarin), framing. Olympic Destroyer (2018), Guccifer 2.0 (2016), MuddyWater.

Paramilitary and Private Military Contractors (PMCs)

When diplomacy, covert theft, and digital intrusion prove insufficient or are compromised, intelligence apparatuses and private corporations deploy kinetic force. Paramilitary operatives and private military contractors operate in the gray zone between traditional military engagements and espionage, providing deniable, lethal solutions to complex geopolitical problems17. The Paramilitary Operations Officer serves as the lethal action arm of state intelligence agencies. Unlike standard military personnel, these operatives do not wear uniforms and operate clandestinely, ensuring the sponsoring government can maintain plausible deniability regarding their actions17. They are responsible for executing direct action missions, including high-risk raids, ambushes, targeted killings, hostage rescues, and unconventional warfare operations where they train and lead foreign guerrilla forces17. In the United States, these personnel are typically drawn from elite Special Operations Forces (SOF) and recruited into elements like the CIA's Special Activities Center (SAC)17. Their skill matrices emphasize overwhelming physical superiority, martial arts, advanced marksmanship across various weapon systems, demolitions (referred to in tradecraft as "bang and burn"), and tactical driving ("the wheelman")18. The psychological profile of a paramilitary officer demands a high tolerance for violence, exceptional physical fitness, and tactical pragmatism18. They are deployed to resolve situations where the objective is absolute destruction or the physical extraction of a high-value target. Operating parallel to state paramilitary forces are Private Military Contractors (PMC Operators). These individuals are employed by private corporations that provide armed combat, security consulting, and logistical support for profit11. The market for private force has expanded massively; multinational extractive industries, shipping conglomerates, and even non-governmental organizations (NGOs) rely heavily on PMCs for protection in hostile territories11. For instance, mining giants like Freeport-McMoRan have utilized firms like Triple Canopy to secure operations in conflict zones, while Chinese petroleum corporations employ DeWe Security in South Sudan13. PMCs range in capability from providing unarmed facility guards to deploying heavy aviation support, attack helicopters, and sophisticated counter-insurgency operations11. Some state actors heavily utilize PMCs, such as the Russian Wagner Group, to seize strategic resources (like oil fields in Syria) or conduct deniable combat operations without officially committing state military assets13. The PMC Operator is motivated primarily by contractual obligation and financial reward rather than patriotism. Their skills focus on site fortification, convoy protection, anti-piracy, and logistics management11. In a simulation framework, PMCs represent a highly fluid faction; they can be hired to defend critical infrastructure, but they can also be bought off by rival syndicates if a more lucrative contract is offered.

Paramilitary Archetype Primary Function Core Skills and Tradecraft Operational Motivations
Paramilitary Operations Officer State-sponsored direct action and covert kinetic operations. Advanced marksmanship, CQB, demolitions, guerrilla training, escape and evasion. National security, ideological duty, mission accomplishment.
PMC Operator Corporate/Proxy combat and security logistics. Convoy protection, site fortification, anti-piracy, heavy machinery operation. Profit, contractual obligation, mercenary pragmatism.
Hack-Back Contractor Active cyber deterrence and retaliatory attacks. Network defense, counter-intrusion, retaliatory payload deployment. Corporate asset protection, deterrence by punishment.

Analytical, Strategic, and Specialized Intelligence Disciplines

The raw data acquired by field operatives and technical sensors holds no intrinsic value until it is processed, contextualized, and transformed into actionable intelligence. Analytical operatives operate primarily from headquarters, synthesizing vast streams of disparate information to dictate the strategic flow of the clandestine war1. The Intelligence Analyst is responsible for studying intelligence from multiple sources and preparing comprehensive assessments for senior decision-makers18. These operatives must possess deep regional or functional expertise, excellent writing skills, and the capacity to derive accurate conclusions from incomplete or contradictory data22. Analysts rely heavily on Open-Source Intelligence (OSINT)—information gathered from public records, news media, social platforms, and academic journals7. Specialized sub-roles include Targeters, who perform rigorous pattern-of-life and network analyses to identify vulnerabilities within enemy organizations, subsequently feeding these targets to paramilitary or cyber units for exploitation18. The analytical profile demands methodical patience, logical rigor, and a profound understanding of human terrain. A highly specialized and increasingly critical analytical role is the Financial Intelligence (FININT) Analyst. These specialists focus on analyzing financial transactions to trace the flow of illicit funds through the global banking system7. They utilize forensic accounting, blockchain analytics, and the monitoring of Suspicious Activity Reports (SARs) to identify money laundering operations, terrorist financing, and hidden offshore assets7. By identifying the beneficial ownership of shell companies, FININT analysts can expose the corporate backers of rival espionage operations21. In a strategic game layer, FININT capabilities allow players to cripple enemy factions economically, freezing their operational budgets or exposing their illicit funding streams to international regulatory bodies38. Another vital strategic role is the Staff Operations Officer, or Collection Manager. These officers act as the integration point between field offices and headquarters, establishing intelligence requirements, coordinating collection activities across various disciplines, and managing operational logistics18. They are the ultimate project managers of the espionage world, ensuring that resources are allocated efficiently and that field operatives receive the intelligence and funding necessary to execute their missions. The scope of analysis is categorized by specific intelligence disciplines, commonly referred to as "The INTs." A comprehensive simulation must integrate these disciplines as distinct skill trees or data streams that operatives can master.

Taxonomy of Intelligence Disciplines (The INTs)

Discipline Abbreviation Definition and Focus Analytical Application
Signals Intelligence SIGINT Intercepting and analyzing electronic signals and communications7. Breaking encryption, tracking enemy troop movements via radio.
Open-Source Intelligence OSINT Gathering and analyzing publicly available information (internet, media, databases)7. Building target profiles without risking detection, tracking market trends.
Financial Intelligence FININT Analyzing financial transactions, banking records, and cryptocurrency ledgers7. Exposing shell companies, tracking terrorist funding, freezing assets.
Geospatial Intelligence GEOINT Utilizing geographic information and imagery to map physical landscapes19. Identifying hidden facilities, planning infiltration routes.
Imagery Intelligence IMINT Interpreting satellite and aerial photography to gather information on foreign activities19. Monitoring troop build-ups, verifying destruction of targets.
Measurement and Signature MASINT Detecting and tracking the unique physical signatures of targets (e.g., radar profiles, chemical plumes)19. Identifying specific weapon systems or covert manufacturing plants.
Communications Intelligence COMINT Intercepting communications between people to uncover valuable information5. Wiretapping, intercepting emails and text messages.
Electronic Intelligence ELINT Collecting and interpreting non-communications electronic emissions (e.g., radar)19. Mapping enemy air defense networks.
Technical Intelligence TECHINT Analyzing captured enemy weapons and equipment to assess capabilities and vulnerabilities5. Reverse-engineering rival technology to develop countermeasures.
Medical/Biological MEDINT/CBINT Analyzing health data and assessing chemical/biological weapon threats19. Tracking pandemics, identifying bio-warfare laboratories.

Corporate Espionage, Competitive Intelligence, and Private Spies

In a simulation where defense corporations and corporate syndicates are playable factions, the mechanics of industrial espionage are paramount. Corporations spy on each other continually, balancing on a razor's edge between legal market research and criminal theft15. The Competitive Intelligence (CI) Analyst operates strictly within legal and ethical boundaries to systematically gather, analyze, and manage information on industrial competitors14. CI analysts utilize advanced OSINT techniques to monitor patent filings, executive hires, pricing shifts, and supply chain logistics14. They synthesize this data to create "battlecards" for sales teams, predict market shifts, and conduct win/loss analyses42. While their actions are entirely legal, their outputs are vital for corporate survival, allowing a faction to proactively counter a rival's strategic moves3. When legal means are insufficient, organizations turn to Industrial or Corporate Spies. These individuals commit economic espionage, utilizing illegal methods to steal proprietary operational data, trade secrets, intellectual property, and source code14. Historically, this includes cases such as the 1997 Gillette incident, where a subcontractor stole and shared $750 million worth of trade secrets regarding a new shaving system, or the 2006 case where a disgruntled Coca-Cola employee attempted to sell unreleased product formulas to Pepsi43. The most pervasive form of corporate espionage is the Insider Threat. An insider threat involves an employee, contractor, or business partner who intentionally (through bribery or blackmail) or unintentionally leaks sensitive information45. Corporate spies utilize physical infiltration—posing as janitorial staff or repairmen to access unattended laptops, a tactic known as a "bag-op"14. They also employ sophisticated social engineering, such as phishing, pretexting (fabricating a scenario to obtain data), and tailgating (following an authorized person into a secure area)32. Once inside, they execute "low and slow" data exfiltration, slowly extracting files over months or years to avoid triggering network anomaly detection, as seen in the espionage cases against semiconductor companies Avago and Skyworks45. In the game, insider threats are highly lethal assets that can bypass the most robust firewalls by walking the data out the front door on a physical drive. Operating at the apex of the private intelligence market is the Private Intelligence Contractor. Firms like the Israeli agency Black Cube rely heavily on former elite state intelligence officers to execute complex corporate operations, often acting as the "Mossad of the business world"47. These agencies specialize in generating actionable leverage through aggressive, and often highly controversial, social engineering1. They establish elaborate front companies and utilize false identities to lure targets—ranging from senior government officials to corporate executives—into meetings across international jurisdictions49. Their objectives include unearthing hidden assets for litigation, discrediting whistleblowers or victims of high-profile clients, and orchestrating strategic disinformation campaigns to manipulate public perception or corporate valuations1. The skillset of a private intelligence contractor relies entirely on human manipulation, emotional elicitation, and the generation of Kompromat (compromising material used for blackmail)10.

Espionage Tradecraft, Terminology, and Systemic Implementation

To elevate RogueIntelligence.org from a standard tactical game to a true espionage simulation, the esoteric tradecraft and specialized terminology of the intelligence community must be translated into actionable gameplay mechanics5. Drawing upon established tabletop RPG frameworks—such as the investigative point pools of GUMSHOE (Night's Black Agents), the detailed class structures of Spycraft, and the psychological attrition systems of Delta Green—these concepts provide a rigid mechanical backbone for NPC behavior and player interaction36.

Tradecraft Terminology as Actionable Mechanics

The vocabulary of espionage describes specific maneuvers that operatives execute to collect intelligence or evade capture. Integrating these as specific skills or strategic actions provides depth to the simulation.

  • The Canary Trap (Barium Meal): A counterintelligence technique utilized to identify a leak within an organization. A suspected mole is fed a uniquely altered version of sensitive information; if that specific version appears in the press or is intercepted by a rival, the source of the leak is confirmed29. In-game, players or AI administrators can deploy Canary Traps to weed out embedded Double Agents or Insider Threats within their corporate hierarchy.
  • Brush Contact / Brush Pass: A clandestine, momentary encounter in a public space where two operatives discreetly exchange documents, funds, or equipment without speaking or acknowledging each other20. This serves as a stealth mechanic allowing field operatives to transfer critical items without generating a digital footprint or triggering surveillance alerts.
  • Dead Drop: A secure, pre-arranged, hidden location (e.g., a hollowed-out brick, a magnetic box under a bench) where an operative can leave information or materials for another agent to retrieve later5. Dead drops allow for asynchronous communication, ensuring that a Case Officer and their recruited asset are never seen together, minimizing the risk of a network being rolled up simultaneously.
  • Concealment Devices and Pocket Litter: A concealment device is an ordinary object modified with a hidden cavity to smuggle data or micro-tools25. "Pocket litter" refers to the curated mundane items—receipts, transit tickets, business cards—an operative carries to authenticate their cover identity if searched25. Mastery of these elements determines an operative's success rate during border crossings or security checkpoints.
  • The Honeypot: A trap that utilizes romantic or sexual relationships to lure an enemy agent into a compromising position29. The goal is to either extract classified information during moments of vulnerability or capture photographic evidence to generate Kompromat, forcing the target to become a Double Agent under the threat of exposure25.
  • Pavement Artist: A slang term for an operative specialized in trailing a target on foot in an urban environment25. Pavement Artists rely on blending into crowds and utilizing surveillance detection routes (SDRs) to ensure they themselves are not being followed while tracking a high-value target.
  • Starburst Maneuver: A vehicular counter-surveillance tactic. If a "Wheelman" detects they are being tailed, they coordinate with allied vehicles of the identical make and model to intersect at a specific junction, suddenly speeding off in completely different directions to force the surveillance team to guess which vehicle contains the true target29.

Character Progression, Attrition, and "The Burn"

Espionage is inherently destructive to the operatives who practice it. To accurately simulate this environment, character progression should not strictly focus on acquiring new skills, but also on managing the inevitable degradation of an operative's resources and sanity. Inspired by the Night's Black Agents "Cover and Network" abilities and the Delta Green sanity mechanics, operatives face specific career risks23.

  1. Cover Degradation and "Blowback": Operatives rely on a generated "Cover" score to operate in hostile territory. Every time an operative performs a highly suspicious action, utilizes a weapon, or fails a social engineering check, their Cover degrades50. If an operative's identity is discovered by the enemy, they are considered "Blown" or "Burned"5. A burned agent loses access to their institutional resources, rendering them useless for clandestine operations and forcing the parent faction to either execute a costly "Exfiltration" to save them or designate them as a "Discard"—an expendable asset sacrificed to protect the broader network20. The consequences of a botched operation resulting in public exposure or geopolitical crisis are known as "Blowback"25.
  2. Network Attrition: A successful operative relies on a web of "Bagmen" (who handle covert payments) and "Cut-outs" (intermediaries who insulate the core agent from direct contact)5. In the simulation, this represents a "Network" resource pool50. Relying too heavily on a specific asset risks exposing them to enemy counterintelligence. If a rival faction compromises a player's network, they lose critical avenues for acquiring safehouses, weapons, and localized intelligence.
  3. Trust and Betrayal Economics: In a faction-agnostic game populated by mercenaries and spies, loyalty is a currency. Utilizing mechanics similar to the "Trust and Betrayal" dials in RPGs, operatives can invest points to assist an ally, but these points can be instantly converted into a devastating mechanical advantage if one operative decides to betray the other52. This mechanically enforces the paranoia inherent to espionage, where an Agent Handler must constantly weigh the utility of an asset against the probability that they are secretly a Double Agent feeding them chicken feed.

Conclusion and Systemic Synthesis for Game Design

To create an authentic, multi-layered espionage simulation in RogueIntelligence.org, the rigid constraints of traditional "combat classes" must be abandoned in favor of the nuanced, interdependent archetypes detailed in this report. The global intelligence ecosystem is not a battlefield of armies, but a shadow war of networks, algorithms, and psychological manipulation10. The design must enforce the functional differences between the factions. A player controlling a State Intelligence Paramilitary Officer will have access to immense satellite surveillance (GEOINT) and heavy tactical weaponry, but they will be shackled by the bureaucratic necessity to avoid an international incident (Blowback)19. Conversely, a player operating as a Corporate Spy or Private Intelligence Contractor must rely on highly developed social engineering, OSINT, and illegal Insider Threat infiltration, operating with total agility but facing absolute ruin if burned, as no state government will claim them16. By structuring NPC behavior and player capabilities around the specific domains of HUMINT, SIGINT, Cyber, and FININT, and by embedding real-world tradecraft maneuvers—such as False Flags, Canary Traps, and Low-and-Slow Exfiltration—directly into the action economy, the simulation will force players to engage in genuine intelligence cycles29. Success in this environment is rarely achieved through direct kinetic violence; it is achieved by out-thinking the adversary, compromising their financial networks, peeling away their cover identities, and exploiting the human vulnerabilities at the core of their operations.

Works cited

  1. The Privatization of Intelligence: The Black Cube Case \- İnsamer, https://en.insamer.com/the-privatization-of-intelligence-the-black-cube-case\_1761.html
  2. Private Military Companies, https://www.files.ethz.ch/isn/17438/backgrounder\09\_private-military-companies.pdf
  3. Institute for Policy Research \- Corporate and police spying on activists undermines democracy \- University of Bath, https://www.bath.ac.uk/publications/corporate-and-police-spying-on-activists-undermines-democracy/attachments/ipr-corporate-and-police-spying-on-activists-undermines-democracy.pdf
  4. CIA Salaries \- CIA Agent, https://www.ciaagentedu.org/salaries/
  5. The (English) Language of Spies, https://blogs.transparent.com/english/the-english-language-of-spies/
  6. Our Terminology \- Global Intelligence Knowledge Network, https://globalintelligenceknowledgenetwork.com/terminology/
  7. The Role of Intelligence in National Security \- Cognyte, https://www.cognyte.com/blog/intelligence-national-security/
  8. Private intelligence agency \- Wikipedia, https://en.wikipedia.org/wiki/Private\intelligence\_agency
  9. Private intelligence agency \- Grokipedia, https://grokipedia.com/page/Private\intelligence\_agency
  10. Hybrid Warfare II – the forgotten social engineers \- KCS Group, https://kcsgroup.com/hybrid-warfare-ii-the-forgotten-social-engineers/
  11. Private military company \- Wikipedia, https://en.wikipedia.org/wiki/Private\military\_company
  12. Privatizing War? PMCs: The Invisible Force Multiplier \- Domestic Preparedness, https://www.domesticpreparedness.com/commentary/privatizing-war-pmcs-the-invisible-force-multiplier/
  13. Mercenaries and War: Understanding Private Armies Today \- NDU Press, https://ndupress.ndu.edu/Media/News/article/2031922/mercenaries-and-war-understanding-private-armies-today/
  14. Industrial espionage \- Wikipedia, https://en.wikipedia.org/wiki/Industrial\_espionage
  15. Industrial Espionage | Business and Management | Research Starters \- EBSCO, https://www.ebsco.com/research-starters/business-and-management/industrial-espionage
  16. What is Corporate Espionage & How to Prevent It \- Mimecast, https://www.mimecast.com/blog/what-is-corporate-espionage-and-prevention-techniques/
  17. Special Activities Center \- Wikipedia, https://en.wikipedia.org/wiki/Special\Activities\_Center
  18. CIA Careers for Veterans: Complete Guide to Central Intelligence Agency, https://www.militarytransitiontoolkit.com/blog/cia-careers-veterans-guide
  19. (PDF) National Signals Intelligence Leadership Academy (NSILA) \- ResearchGate, https://www.researchgate.net/publication/378804687\National\Signals\Intelligence\Leadership\Academy\_NSILA
  20. The Tradecraft of the Spy Glossary \- Michael Smith \- Author, https://www.michaelsmithauthor.com/pdfs/Traitor-Glossary.pdf
  21. Investigative Definitions & Glossary \- McAfee Institute, https://www.mcafeeinstitute.com/knowledge/definitions
  22. 2026 How To Become a CIA Officer \- Research.com, https://research.com/careers/how-to-become-a-cia-officer
  23. How to Create a Night's Black Agents Character \- Quest Portal VTT, https://www.questportal.com/blog/how-to-create-a-nights-black-agents-character
  24. Preparing for a Career in International Security \- Kent State Online, https://onlinedegrees.kent.edu/blog/international-security-careers
  25. Spy Slang: 24 Top Secret Terms You Should Know \- Mental Floss, https://www.mentalfloss.com/language/slang/spy-slang
  26. Russian spies living among us: Inside the FBI's "Operation Ghost Stories" \- CBS News, https://www.cbsnews.com/news/russian-spies-operation-ghost-stories-fbi-declassified/
  27. Espionage Terminology Guide | PDF \- Scribd, https://www.scribd.com/document/175554450/List-of-Espionage-Terms
  28. Spy archetypes? | Tabletop Roleplaying Open \- RPGnet, https://forum.rpg.net/index.php?threads/spy-archetypes.647160/
  29. 11 Terms Used by Spies \- People | HowStuffWorks, https://people.howstuffworks.com/11-terms-used-by-spies.htm
  30. Technical Ops Officer \- Spyscape, https://spyscape.com/en-US/roles/tech-ops
  31. 7 Best Degrees for CIA That Actually Get You Hired in 2026 \- College Educated, https://collegeeducated.com/online-degrees/best-degrees-for-cia/
  32. Industrial Espionage: An In-Depth Guide \- SearchInform, https://searchinform.com/articles/cybersecurity/cyber-threats/type/espionage/industrial-espionage/
  33. Iranian state-backed spies pose as ransomware slingers in false flag attacks | CSO Online, https://www.csoonline.com/article/4167985/iranian-state-backed-spies-pose-as-ransomware-slingers-in-false-flag-attacks.html
  34. False flag \- Wikipedia, https://en.wikipedia.org/wiki/False\_flag
  35. What is a false flag in cybersecurity? \- Huntress, https://www.huntress.com/cybersecurity-101/topic/what-is-false-flag-in-cybersecurity
  36. Classes | Spycraft 2.0 Wiki \- Fandom, https://spycraft2.fandom.com/wiki/Classes
  37. UN Use of Private Military and Security Companies: Practices and Policies, https://www.dcaf.ch/sites/default/files/publications/documents/SSR\_PAPER3.pdf
  38. Follow the Money \- Leveraging Financial Intelligence to Combat Transnational Threats Matthew Levitt \- Columbia International Affairs Online, https://ciaotest.cc.columbia.edu/journals/gjia/v12i1/f\0026458\_21656.pdf
  39. $40k-$129k Operations Officer Jobs in Chantilly, VA \- ZipRecruiter, https://www.ziprecruiter.com/Jobs/Operations-Officer/-in-Chantilly,VA
  40. John T. Lewis \- ASU Search \- Arizona State University, https://search.asu.edu/profile/1294342
  41. Competitive Intelligence \- SJSU \- School of Information, https://ischool.sjsu.edu/post/competitive-intelligence
  42. What does a competitive intelligence career look like?, https://www.competitiveintelligencealliance.io/what-does-a-competitive-intelligence-career-look-like/
  43. What Is Corporate Espionage? 5+ Shocking Cases \- CurrentWare, https://www.currentware.com/blog/corporate-espionage-cases/
  44. Corporate Espionage: A Guide on How Businesses Behave Badly \- Grey Dynamics, https://greydynamics.com/corporate-espionage-a-guide-on-how-businesses-behave-badly/
  45. A Case of Corporate Espionage \- Securonix, https://www.securonix.com/blog/a-case-of-corporate-espionage/
  46. What is corporate espionage? Prevention techniques \- CyberArrow, https://www.cyberarrow.io/blog/what-is-corporate-espionage/
  47. Israeli private intelligence agency allegedly behind Christodoulides corruption video | Cyprus Mail, https://cyprus-mail.com/2026/04/10/israeli-private-intelligence-agency-allegedly-behind-christodoulides-corruption-video
  48. Black Cube High End Reputation Management Alternative, https://www.reputationmanagement.co/blog/black-cube-high-end-reputation-management-alternative
  49. Why Israeli firm Black Cube really went after Obama's team \- Reddit, https://www.reddit.com/r/TrueReddit/comments/9rj0qi/why\israeli\firm\black\cube\really\went\_after/
  50. Night's Black Agents (role-playing game) \- Wikipedia, https://en.wikipedia.org/wiki/Night%27s\Black\Agents\(role-playing\_game))
  51. \[Delta Green\] Best system? | Tabletop Roleplaying Open \- RPGnet, https://forum.rpg.net/index.php?threads/delta-green-best-system.605848/
  52. Night's Black Agents – Pelgrane Press Ltd, https://pelgranepress.com/nights-black-agents/
  53. Looking for a the right Spy game. : r/rpg \- Reddit, https://www.reddit.com/r/rpg/comments/1r8bea6/looking\for\a\the\right\spy\_game/
  54. CIA Paramilitary Operators (System Recommendations?) : r/rpg \- Reddit, https://www.reddit.com/r/rpg/comments/jbcah4/cia\paramilitary\operators\system\_recommendations/

Connected tools and standards

Explore the wider AI ecosystem.