{
  "code": "CI-02",
  "slug": "counterintelligence-case-development",
  "title": "Counterintelligence Case Development",
  "category": "Counterintelligence",
  "status": "Current",
  "version": "2.0.4-wip",
  "summary": "Defines anomaly intake, suspect files, corroboration, protective actions, warrant thresholds, and closure.",
  "keywords": [
    "case development",
    "anomaly",
    "suspect file",
    "insider risk",
    "protective action"
  ],
  "mission_phases": [
    "Access",
    "Collect",
    "Validate",
    "Debrief"
  ],
  "canonical": "https://iarpg.com/standard/counterintelligence-case-development",
  "json": "https://iarpg.com/records/counterintelligence-case-development.json",
  "requirements": [
    {
      "level": "MUST",
      "text": "The case distinguish anomaly, suspect file, confirmed finding, and active protective action."
    },
    {
      "level": "MUST",
      "text": "Escalation identify evidence threshold, jurisdiction, reviewing authority, and reversible versus irreversible consequence."
    },
    {
      "level": "SHOULD",
      "text": "Alternative explanations remain available until explicitly closed."
    }
  ],
  "research": [
    {
      "label": "Dual-axis case development",
      "href": "/docs/report/justice-system-and-warrant-escalation-for-rogue-intelligence#strategic-fit-with-rogue-intelligence",
      "note": "Severity and evidentiary certainty as separate case dimensions."
    }
  ],
  "related": [
    "counterintelligence-investigation",
    "evidence-based-jurisdiction-and-warrants",
    "contradiction-handling"
  ],
  "roles": [
    "Operative",
    "Handler",
    "Intelligence Analyst",
    "Technical Operator",
    "Counterintelligence Officer",
    "Liaison Officer",
    "Logistics Specialist",
    "Source Handler"
  ],
  "interaction_types": [
    "Review",
    "Decide",
    "Record",
    "Handoff"
  ],
  "authority_types": [
    "Civil administration",
    "Military command",
    "Commercial intelligence service",
    "International verification body",
    "Scientific or infrastructure consortium",
    "Independent investigative network"
  ],
  "collection_disciplines": [
    "HUMINT",
    "SIGINT",
    "OSINT",
    "Technical collection",
    "Surveillance",
    "Liaison reporting"
  ],
  "conformance_level": "Level C — Auditable",
  "implementation_maturity": "Published WIP",
  "release": "IARPG-OPS-2",
  "revised_utc": "2026-07-20T12:04:07Z",
  "purpose": "Model detection, manipulation, insider risk, compromise, and competing explanations without omniscient accusation.",
  "rationale": "Counterintelligence play depends on case development, corroboration, and procedural consequences rather than instant server certainty.",
  "game_interaction": [
    "Open suspect file",
    "Test contradiction",
    "Review access anomaly",
    "Escalate or close case"
  ],
  "inputs": [
    "Anomalies",
    "Access logs",
    "Witness reports",
    "Behavioral indicators"
  ],
  "outputs": [
    "Case file",
    "Compromise assessment",
    "Protective action"
  ],
  "state_transitions": [
    {
      "from": "not-applicable",
      "event": "record requirement evaluated",
      "to": "conforming-or-documented-exception"
    }
  ],
  "evidence_and_provenance": [
    "The implementation records the source, UTC event time, mission identifier, responsible role, and reason code for consequential state changes.",
    "Generated dialogue and player interpretation are not stored as authoritative facts without a separate verification event."
  ],
  "ui_requirements": [
    "Show the record code and requirement level at the point of use.",
    "Expose the reason for blocked, failed, escalated, or irreversible actions.",
    "Provide a direct link to the canonical standard and machine-readable record."
  ],
  "accessibility_requirements": [
    "Essential information is available without reliance on color, audio, motion, or a VR-only gesture.",
    "Keyboard, screen-reader, reduced-motion, seated-play, and high-contrast equivalents are documented where the interaction applies."
  ],
  "telemetry_events": [
    {
      "name": "standard.counterintelligence-case-development.evaluated",
      "required_fields": [
        "event_id",
        "timestamp_utc",
        "mission_id",
        "record_code",
        "result",
        "reason_code"
      ]
    }
  ],
  "abuse_and_exploit_cases": [
    "A participant attempts to omit required context so another role accepts a misleading task.",
    "A generated or user-authored statement is presented as server-authoritative without verification.",
    "A consequential state transition occurs without a durable reason code."
  ],
  "failure_behavior": "Fail closed for irreversible or settlement-bearing actions. Preserve the current state, show the missing requirement, and allow correction or documented exception review.",
  "recovery_behavior": "Restore from the last authoritative event, retain the rejected transition in the audit log, and require a new validated event before continuing.",
  "example_implementation": "A mission interface evaluates CI-02 before advancing the relevant state and writes the result to the local event log with a UTC timestamp and reason code.",
  "evidence_requirement": "Reviewable provenance required",
  "related_examples": [
    "port-access-anomaly-investigation"
  ],
  "revision_history": [
    {
      "version": "1.0.0",
      "date_utc": "2026-07-19",
      "note": "Initial IARPG-OPS-1 publication."
    },
    {
      "version": "2.0.1-wip",
      "date_utc": "2026-07-19",
      "note": "Expanded for IARPG-OPS-2 workbench, simulation, evidence, accessibility, telemetry, and machine-readable publication."
    },
    {
      "version": "2.0.2-wip",
      "date_utc": "2026-07-19T16:42:07Z",
      "change": "Reviewed for operation-package lifecycle compatibility and local tool integration."
    },
    {
      "version": "2.0.3-wip",
      "date_utc": "2026-07-19T18:45:50Z",
      "note": "Reviewed for integrity-aware package verification, merge, multi-role replay, custody comparison, batch review, backup, publication preview, and release-promotion workflows."
    },
    {
      "version": "2.0.4-wip",
      "date_utc": "2026-07-20T12:04:07Z",
      "note": "Reviewed for canonicalization, round-trip portability, recovery, provenance, compatibility, accessibility, hosting evidence, and stable-promotion gates."
    }
  ]
}
