{
  "code": "CI-01",
  "slug": "counterintelligence-investigation",
  "title": "Counterintelligence Investigation",
  "category": "Counterintelligence",
  "status": "Current",
  "version": "2.0.4-wip",
  "summary": "Counterintelligence identifies compromise through competing explanations, evidence provenance, access analysis, behavioral change, and controlled tests.",
  "keywords": [
    "counterintelligence",
    "mole hunt",
    "compromise",
    "insider risk",
    "damage assessment",
    "deception"
  ],
  "mission_phases": [
    "Task",
    "Plan",
    "Collect",
    "Validate",
    "Deliver"
  ],
  "canonical": "https://iarpg.com/standard/counterintelligence-investigation",
  "json": "https://iarpg.com/records/counterintelligence-investigation.json",
  "requirements": [
    {
      "level": "MUST",
      "text": "Separate access, opportunity, action, motive, and attribution as distinct investigative questions."
    },
    {
      "level": "MUST",
      "text": "Counterintelligence consequences require case evidence and reason codes rather than omniscient server accusation."
    },
    {
      "level": "SHOULD",
      "text": "Offer controlled tests, source validation, audit, surveillance, and damage assessment as different investigative tools."
    },
    {
      "level": "MAY",
      "text": "The apparent compromise be a deception operation intended to redirect investigators."
    }
  ],
  "research": [
    {
      "label": "Alliance leak investigation workflow",
      "href": "/docs/report/counterintelligence-directive-alliance-leak-investigation#investigative-workflow-and-timeline",
      "note": "A structured fictional counterintelligence investigation."
    },
    {
      "label": "Counterintelligence matrix",
      "href": "/docs/report/typology-of-intelligence-operatives-and-tradecraft-frameworks-a-comprehensive-architecture-for-clandestine-beh#the-counterintelligence-matrix-and-the-double-agent-paradigm",
      "note": "Double-agent and insider-risk archetypes."
    }
  ],
  "related": [
    "competing-hypotheses-and-assessment",
    "provenance-confidence-and-corroboration",
    "evidence-based-jurisdiction-and-warrants"
  ],
  "release": "IARPG-OPS-2",
  "revised_utc": "2026-07-20T12:04:07Z",
  "purpose": "Model detection, manipulation, insider risk, compromise, and competing explanations without omniscient accusation.",
  "rationale": "Counterintelligence play depends on case development, corroboration, and procedural consequences rather than instant server certainty.",
  "game_interaction": [
    "Open suspect file",
    "Test contradiction",
    "Review access anomaly",
    "Escalate or close case"
  ],
  "inputs": [
    "Anomalies",
    "Access logs",
    "Witness reports",
    "Behavioral indicators"
  ],
  "outputs": [
    "Case file",
    "Compromise assessment",
    "Protective action"
  ],
  "state_transitions": [
    {
      "from": "not-applicable",
      "event": "record requirement evaluated",
      "to": "conforming-or-documented-exception"
    }
  ],
  "evidence_and_provenance": [
    "The implementation records the source, UTC event time, mission identifier, responsible role, and reason code for consequential state changes.",
    "Generated dialogue and player interpretation are not stored as authoritative facts without a separate verification event."
  ],
  "ui_requirements": [
    "Show the record code and requirement level at the point of use.",
    "Expose the reason for blocked, failed, escalated, or irreversible actions.",
    "Provide a direct link to the canonical standard and machine-readable record."
  ],
  "accessibility_requirements": [
    "Essential information is available without reliance on color, audio, motion, or a VR-only gesture.",
    "Keyboard, screen-reader, reduced-motion, seated-play, and high-contrast equivalents are documented where the interaction applies."
  ],
  "telemetry_events": [
    {
      "name": "standard.counterintelligence-investigation.evaluated",
      "required_fields": [
        "event_id",
        "timestamp_utc",
        "mission_id",
        "record_code",
        "result",
        "reason_code"
      ]
    }
  ],
  "abuse_and_exploit_cases": [
    "A participant attempts to omit required context so another role accepts a misleading task.",
    "A generated or user-authored statement is presented as server-authoritative without verification.",
    "A consequential state transition occurs without a durable reason code."
  ],
  "failure_behavior": "Fail closed for irreversible or settlement-bearing actions. Preserve the current state, show the missing requirement, and allow correction or documented exception review.",
  "recovery_behavior": "Restore from the last authoritative event, retain the rejected transition in the audit log, and require a new validated event before continuing.",
  "example_implementation": "A mission interface evaluates CI-01 before advancing the relevant state and writes the result to the local event log with a UTC timestamp and reason code.",
  "roles": [
    "Operative",
    "Handler",
    "Intelligence Analyst"
  ],
  "authority_types": [
    "Civil administration",
    "Military command",
    "Commercial intelligence service",
    "International verification body",
    "Scientific consortium",
    "Independent investigative network"
  ],
  "collection_disciplines": [],
  "interaction_types": [
    "Open suspect file",
    "Test contradiction",
    "Review access anomaly"
  ],
  "evidence_requirement": "Reviewable provenance required",
  "conformance_level": "Level B — Playable",
  "implementation_maturity": "Published WIP",
  "related_examples": [
    "port-access-anomaly-investigation"
  ],
  "revision_history": [
    {
      "version": "1.0.0",
      "date_utc": "2026-07-19",
      "note": "Initial IARPG-OPS-1 publication."
    },
    {
      "version": "2.0.1-wip",
      "date_utc": "2026-07-19",
      "note": "Expanded for IARPG-OPS-2 workbench, simulation, evidence, accessibility, telemetry, and machine-readable publication."
    },
    {
      "version": "2.0.2-wip",
      "date_utc": "2026-07-19T16:42:07Z",
      "change": "Reviewed for operation-package lifecycle compatibility and local tool integration."
    },
    {
      "version": "2.0.3-wip",
      "date_utc": "2026-07-19T18:45:50Z",
      "note": "Reviewed for integrity-aware package verification, merge, multi-role replay, custody comparison, batch review, backup, publication preview, and release-promotion workflows."
    },
    {
      "version": "2.0.4-wip",
      "date_utc": "2026-07-20T12:04:07Z",
      "note": "Reviewed for canonicalization, round-trip portability, recovery, provenance, compatibility, accessibility, hosting evidence, and stable-promotion gates."
    }
  ]
}
