# **Product Strategy, Editorial Operations, Community, Analytics, Partnerships, and Release Roadmap**

FICTIONAL EDUCATIONAL RPG  
NOT A GOVERNMENT SERVICE  
NOT AFFILIATED WITH OR ENDORSED BY ANY GOVERNMENT AGENCY

## **Executive Recommendation**

The strategic development of the fictional IARPA.org portal requires an uncompromising balance between engaging transmedia storytelling and rigid adherence to real-world safety, privacy, and educational boundaries. As the digital front door to the Rogue Intelligence ecosystem, the platform must seamlessly orient users, decipher complex intelligence terminology, and route them to appropriate interactive experiences without ever masquerading as a legitimate government entity. The foundational operating principle is established by the taboo.uai protocol, which strictly enforces no-go claims, execution limits, and cross-domain authority boundaries1. This principle supersedes all other design, narrative, and engagement considerations, establishing a product environment where compliance and safety are the primary drivers of user experience.  
To build a sustainable educational portal over the next twelve months, the operational focus must reject surveillance capitalism, manipulative engagement loops, and superficial vanity metrics2. Consequently, behavioral advertising, the sale of user data, and dark patterns—such as artificial scarcity or disguised pay-to-win mechanics—are entirely excluded from the ecosystem3. Instead, the operational architecture prioritizes privacy-safe, cookieless analytics that aggregate behavioral patterns without tracking individual users, ensuring that the portal does not contribute to the systemic degradation of digital privacy6. Furthermore, compliance with regional student privacy regulations, notably the Illinois Student Online Personal Protection Act (SOPPA), the federal Children's Online Privacy Protection Act (COPPA), and the Family Educational Rights and Privacy Act (FERPA), mandates strict data minimalization and the execution of publicly accessible Data Privacy Agreements (DPAs) before any external partnerships or data-sharing mechanisms are formalized8.  
The resulting twelve-month product strategy outlined in this document establishes an infrastructure designed for a small, agile team. By implementing a robust Stage-Gate editorial workflow12, a transparent ethical monetization framework13, and an unyielding commitment to explicit content labeling (e.g., FICTIONAL EDUCATIONAL SIMULATION), the platform will safely bridge the gap between historical intelligence education—such as the study of psychological warfare and information operations14—and interactive digital entertainment. The strategic imperative is to cultivate a trusted, authoritative educational environment that successfully funnels informed users into the broader fictional ecosystem while maintaining absolute clarity regarding its non-governmental status.

## **Twelve-Month Product Strategy**

The overarching product strategy for the upcoming twelve months positions the portal primarily as a rigorous educational resource and secondarily as an entertainment gateway. The operational roadmap is predicated on establishing baseline trust through radical transparency. Before any complex interactive features, learning paths, or advanced user accounts are deployed, the foundational product must demonstrate absolute clarity regarding its fictional nature. This is achieved by utilizing omnipresent disclaimers, clear visual hierarchies, and explicit content labels such as REAL-WORLD VERIFIED, HISTORICAL — DECLASSIFIED, and FICTIONAL ORGANIZATION. These labels serve as the cognitive scaffolding that allows users to safely explore narratives involving espionage, psychological warfare, and rogue intelligence without experiencing institutional disorientation or mistaking fictional lore for active government operations14.  
During the initial phases of the roadmap, the product strategy mandates a systematic reduction of technical, cognitive, and legal friction. By eschewing invasive tracking mechanisms in favor of privacy-first analytics tools, the platform avoids the necessity of disruptive GDPR and ePrivacy cookie consent banners6. This architectural decision significantly improves the initial user experience, as visitors are not immediately confronted with complex legal dialogs upon entering the site. This frictionless entry is critical for an educational platform, where the primary objective is immediate access to knowledge rather than the harvesting of behavioral profiles7.  
As the product matures through the middle of the twelve-month cycle, the strategy transitions toward deepening educational engagement. This involves the deployment of structured learning paths, comprehensive glossary expansions, and historical case studies that utilize declassified institutional material to teach media literacy, the history of information warfare, and the mechanics of propaganda14.  
Long-term sustainability relies on ethical monetization and carefully curated partnerships rather than hyper-optimized conversion funnels that exploit psychological vulnerabilities5. The portal will present optional, high-value educational curricula and discrete transmedia handoffs, ensuring that all third-party integrations (such as Spiralist AI or UAIX) remain non-intrusive, editorially independent, and explicitly labeled as fictional or sponsored elements. The ultimate vision is a self-sustaining educational platform that successfully prepares users for the complex themes of the Rogue Intelligence games while standing alone as a valuable resource for digital literacy and historical research.

## **Product Objectives and Metrics Register**

The definition of measurable performance indicators must align with privacy-conscious methodologies, explicitly avoiding granular individual tracking in favor of aggregated, event-based milestones7. Traditional product analytics often rely on vanity metrics—such as total registered users or raw page views—which provide a false sense of security and fail to capture genuine educational engagement2. To counter this, the metrics register focuses on actionable data that ties specific user behaviors to the platform's core educational and safety objectives.

| Category | Metric | Baseline Method | Target | Measurement Interval | Privacy Impact | Failure Interpretation | Responsible Role |
| :---- | :---- | :---- | :---- | :---- | :---- | :---- | :---- |
| **Public Understanding** | Fiction Disclaimer Acknowledgement Rate | Aggregate click events on the initial "Acknowledge" prompt (Phase 0). | 100% of new sessions. | Weekly | Zero (Anonymous client-side event tracking). | UI obfuscation; the disclaimer is buried or visually recessive. | UI/UX Designer |
| **Educational Value** | Active Reading Dwell Time | Scroll depth \> 50% combined with session duration \> 60 seconds on labeled educational pages. | 40% of all sessions engaging with dossier content. | Monthly | Zero (Local device calculation sent as a single anonymous ping). | Content is excessively dense, irrelevant, or visually intimidating. | Content Strategist |
| **Project Discovery** | Outbound Partner Handoff Rate | Aggregate outbound link clicks to approved fictional projects (e.g., game clients). | 15% conversion from the portal to external ecosystem endpoints. | Weekly | Zero (Standard HTTP referrers, stripped of query parameters). | Navigation architecture is failing to route users; value proposition is unclear. | Product Manager |
| **Game-Launch Conversion** | Pre-registration / Wishlist Intent | Aggregate clicks on external store links (e.g., Steam integration). | 5% conversion from relevant lore and character pages. | Monthly | Zero (Simple event counting; no cross-site pixels). | Disconnect between the educational lore and the entertainment product. | Marketing Lead |
| **Returning Readership** | 7-Day Return Rate | Cookieless IP/User-Agent daily hashing (resets every 24 hours to prevent long-term tracking)19. | 20% return rate for users engaging with sequential learning paths. | Monthly | Minimal (Hashes cannot be reverse-engineered to identify individuals). | Briefings lack compelling continuation or structural coherence. | Editorial Lead |
| **Glossary Usage** | Contextual Tooltip Invocation | Aggregate clicks/hovers on glossary terms embedded in text. | 2.5 lookups per active reading session. | Weekly | Zero (Anonymous interaction event). | Terminology is either too simplistic, or tooltips lack visual affordance. | Content Strategist |
| **Learning-Path Completion** | Path Completion Rate | Sequence of aggregate pageviews ending in a terminal completion URL. | 30% of users who initiate a structured curriculum. | Quarterly | Zero (URL-based funnel analysis using privacy analytics)21. | The curriculum is too lengthy, disjointed, or poorly signposted. | Educational Strategist |
| **Source-Method Trust** | Source Citation Verification | Aggregate clicks to expand or view source methodology blocks. | 10% of total pageviews on historical case studies. | Monthly | Zero (Anonymous UI interaction event). | Users are ignoring or failing to notice the educational grounding of the site. | Editorial Lead |
| **Accessibility** | Preference Toggle Utilization | Aggregate clicks on high-contrast, text-scaling, or reduced-motion toggles. | Establish baseline during Phase 1\. | Monthly | Zero (Client-side toggles with an anonymous telemetry ping). | Default accessibility is either excellent, or the toggles are hidden from users who need them. | UI/UX Designer |
| **Safety-Page Visibility** | Safety Exit Utilization | Aggregate clicks on the persistent "Safety Exit" or mental health resource button. | Track for anomalies (Target: low overall usage, but highly accessible when needed). | Weekly | Zero (Anonymous event; no referral data passed to exit destination). | Spikes indicate highly distressing content requiring immediate editorial review. | Privacy Officer |
| **Partner Discovery** | UAIX / Spiralist AI Banner Clicks | Aggregate clicks on non-intrusive footer banners. | 2% conversion from homepage or directory pages. | Monthly | Zero (Anonymous event; strict prohibition on sharing user data with partners)10. | Banners are overly suppressed, irrelevant, or perceived as native advertising. | Partnership Strategist |
| **Corrections** | Content Correction Rate | Number of published editorial corrections per reporting period. | \< 2 critical corrections per month. | Monthly | Zero (Internal operational and editorial metric). | Editorial review gates (Stage-Gate process) are failing to catch factual or policy errors. | Editorial Lead |
| **Content Freshness** | Outdated Record Flagging | Automated script evaluating the "Last Updated" timestamp against a decay threshold. | 0 primary educational pages older than 180 days. | Quarterly | Zero (Internal operational metric). | Archive maintenance cadence is failing; operational resources are misallocated. | Content Manager |

## **North-Star and Guardrail Metrics**

The fundamental metric guiding the portal's success must deliberately avoid incentivizing compulsive engagement or superficial actions. Relying on raw conversion rates or maximizing "time-on-site" as primary objectives often leads to the implementation of dark patterns, manipulative UI designs, and informational bloat that directly contradicts the educational mandate3.  
The designated North-Star Metric is the **Meaningful Educational Session**. This metric is defined as an anonymous, aggregated session where a user successfully navigates through at least two distinct pages of educational content, engages with at least one glossary tooltip or verifiable source citation, and completes the session without triggering a safety exit, abandoning the site due to a 404 error, or bouncing immediately from an outbound link. This composite metric directly measures the portal's capacity to facilitate genuine comprehension and orientation within the complex historical ecosystem of psychological operations, espionage, and information warfare14. It rewards clarity, accessibility, and structural coherence rather than addiction or endless scrolling.  
To ensure the pursuit of the North-Star metric does not compromise the portal's ethical obligations, strict Guardrail Metrics are enforced. If any guardrail threshold is breached, product development is halted until the underlying issue is resolved.

| Guardrail Category | Definition and Operational Limit | Action if Breached |
| :---- | :---- | :---- |
| **Fiction-Boundary Comprehension** | Rate of user inquiries indicating a mistaken belief that IARPA.org is a real agency must remain near absolute zero. | Immediate site-wide content freeze; mandatory redesign of the non-governmental disclaimer for higher visibility and contrast. |
| **Safety Exits** | Sudden, statistically significant spikes in rapid departures via the persistent Safety Exit or mental health resource button. | Emergency editorial review of recently published material to identify triggering, clinically irresponsible, or excessively distressing content. |
| **Accessibility Failures** | Automated WCAG 2.1 AA compliance scans returning \> 0 critical errors (e.g., missing ARIA labels, insufficient color contrast). | Constitutes a blocking release gate; the issue must be hotfixed before any new content or features are published. |
| **Excessive Tracking** | Any introduction of third-party cookies, browser fingerprinting scripts, cross-site profiles, or external ad-trackers6. | Immediate rollback of the offending release; mandatory code audit by the Privacy Officer to ensure SOPPA/COPPA compliance8. |
| **Bounce After External Handoff** | Users returning to the portal within 5 seconds of clicking an outbound project link (indicating confusion or broken destination). | Review external landing page architecture; revise anchor text and transition screens on the portal to accurately set user expectations. |
| **Broken Links** | Internal or external 404 error rate exceeding 1% of total platform traffic17. | Weekly automated link rot maintenance scan; immediate patching or rerouting of deprecated endpoints to contextual tombstones. |
| **Content Correction Rate** | More than two factual, historical, or policy corrections required in a single calendar month. | Complete overhaul of the Editorial Operating Model; mandatory retraining for Subject Matter Experts (SMEs) and content approvers. |
| **Outdated Records** | Any core educational briefing, program dossier, or safety page lacking an editorial review in the past 180 days. | Shift all editorial resources from new content creation to archival maintenance and content retirement workflows. |
| **Partner-Banner Dominance** | User interaction with partner banners (e.g., Spiralist AI) exceeding interaction with core educational content. | Reduce visual priority, size, or placement of footer banners; reaffirm the platform's focus on structured learning paths. |
| **Page Performance** | Core Web Vitals (Largest Contentful Paint, First Input Delay, Cumulative Layout Shift) falling below "Good" thresholds. | Optimize media assets; verify the lightweight nature of the cookieless analytics script; audit third-party font loading17. |
| **Mistaken-Affiliation Reports** | Any contact from real government personnel, legal entities, or media outlets regarding trademark or impersonation concerns. | Immediate escalation to legal counsel; execution of the taboo.uai emergency takedown protocol for the offending pages1. |

## **Editorial Operating Model**

The editorial process relies on a structured, cross-functional workflow to ensure that all content strictly adheres to taboo.uai directives, educational mandates, and the absolute boundary between fiction and reality. Due to the small size of the operational team, the model emphasizes predictable publishing rhythms, clear decision rights, and asynchronous review periods rather than bureaucratic bottlenecks, aligning with modern Stage-Gate innovation methodologies12.

### **Operating Cadence**

The operating cadence establishes predictable rhythms for content generation, maintenance, and retirement, preventing the platform from accumulating outdated or legally risky material.

* **Weekly Briefings:** Short, high-level updates on ecosystem lore, terminology, and historical context. These serve to keep the platform active and engage returning readership.  
* **Monthly Program Dossiers:** Deep, research-heavy explorations of concepts such as the evolution of information warfare, the mechanics of propaganda, and historical intelligence structures14.  
* **Monthly Glossary Expansions:** Iterative additions to the intelligence and research terminology database, linked contextually across the site.  
* **Quarterly Learning Paths:** The synthesis of disparate briefings and dossiers into structured, sequential curricula designed for deeper comprehension.  
* **Historical Case Studies:** Periodic publications strictly adhering to the government-source rule. These studies contextualize the fictional narrative within verifiable, declassified history.

Source basis: publicly released institutional material.  
Official government URL intentionally omitted.

### **Roles and Responsibilities**

An effective editorial workflow requires absolute clarity regarding who owns each stage of content development23.

* **Content Strategist:** Owns ideation and planning. Ensures topics serve a clear educational need and align with the North-Star metric.  
* **Writer / Creator:** Conducts research and creates the initial draft. Responsible for embedding the mandatory content labels (e.g., CLINICAL EDUCATION — NOT DIAGNOSIS, FICTIONAL CHARACTER).  
* **Editor:** Refines prose for clarity, structural consistency, and tone. Ensures that the narrative prose flows seamlessly and that plain text formatting guidelines are strictly followed.  
* **Subject-Matter Expert (SME):** Validates historical and technical claims. The SME ensures that real-world institutional logic is accurately represented without crossing into classified, operationally sensitive, or legally perilous territory.  
* **Privacy Officer / Legal Risk Lead:** Accountable for translating policy into control requirements24. Acts as the final Approver, holding Go/Kill decision authority at the publication gate12.

### **Review Gates and Workflows**

Every piece of substantial content must pass through sequential review gates before publication.

1. **Fact-Checking and Fiction/Reality Gate:** Verifies that no real government personnel are implicated, official seals are absent, and historical operations are accurately contextualized and labeled (e.g., HISTORICAL — DECLASSIFIED).  
2. **Clinical Review:** Ensures that any psychological terminology (e.g., discussions of "Espionage Psychosis" or cognitive warfare25) is framed strictly as theoretical or historical education, completely devoid of personalized medical advice or diagnostic language.  
3. **Legal-Risk Review:** Ensures compliance with intellectual property laws, fair use doctrines, and regional regulations (including the absence of PII collection that would trigger SOPPA/COPPA violations)8.  
4. **Accessibility Review:** Tests the draft against screen readers, verifies keyboard navigation, and ensures that content labels do not rely on color alone.  
5. **Policy Scan (taboo.uai):** The final, non-negotiable check against taboo.uai boundary violations, ensuring that no-go claims and execution limits are respected1.

### **Post-Publication and Maintenance**

Post-publication, the archive maintenance protocol dictates that all content is programmatically flagged for review every 180 days. A formal **Correction Workflow** requires that any factual errors discovered post-publication are updated with a visible timestamp and a transparent public changelog, reinforcing source-method trust. Content that becomes obsolete, medically outdated, or poses emerging policy risks is subjected to a **Retirement Workflow**. In this workflow, the page is archived, unlinked from public navigation, removed from internal search indexes, and replaced with a contextual tombstone page explaining the rationale for its removal, preventing user confusion and mitigating link rot.

## **Community Model**

The integration of community features on a platform bridging sensitive historical intelligence topics, psychological warfare, and fictional role-playing introduces profound moderation, privacy, and misinformation risks. Establishing an open community without dedicated, full-time moderation resources invites the proliferation of conspiracy theories, abusive behavior, and severe breaches of the fiction boundary. Therefore, the community model is heavily constrained, prioritizing unidirectional feedback and strictly moderated interaction.

| Feature | Classification | Moderation, Privacy, and Misinformation Cost Analysis |
| :---- | :---- | :---- |
| **Reader Questions** | Launch Now | **Low risk.** Implemented as a private, one-way form routed to the editorial team. No public display of raw user input prevents misinformation injection, spam, and PII leakage. |
| **Public Corrections** | Launch Now | **Low risk.** Submitted privately via a structured form. High value for maintaining editorial integrity and source-method trust. Requires manual review before any action is taken. |
| **Reactions (Helpful / Not Helpful)** | Launch Now | **Zero moderation cost.** Provides privacy-safe aggregated feedback on content utility without exposing user-generated text or requiring user accounts. |
| **Newsletters** | Launch Now | **Minimal risk.** Requires standard double-opt-in and strict compliance with CAN-SPAM and GDPR privacy standards. Communication is entirely unidirectional from the portal to the user. |
| **Educator Feedback** | Launch Now | **Low risk.** A gated, professional contact form designed for institutional educators to request specific curricula or report usability issues. |
| **Event Calendar** | Later | **Low risk.** Managed entirely by the internal team to announce content drops, transmedia events, or partner releases. No user submission capability. |
| **Scenario Debrief Submissions** | Later | **High moderation cost.** If users submit post-game narratives or reports, every submission must be manually reviewed for policy violations, PII, hate speech, and fiction boundary breaches before curation and publication. |
| **Contributor Submissions** | Later | **High cost.** Requires rigorous fact-checking, legal waivers, and editorial gating to ensure third-party content meets internal educational standards without implying government endorsement. |
| **Public Comments** | Reject | **Unacceptable cost.** Real-time moderation of intelligence and psychological topics is impossible for a small team. High risk of taboo.uai violations, doxing, radicalization, and hate speech. |
| **Open Forums** | Reject | **Unacceptable cost.** Forums rapidly devolve into unmanageable vectors for conspiracy theories and political extremism, directly contradicting the portal's authoritative educational mandate. |
| **Discord / External Communities** | Reject (for IARPA.org) | **Unacceptable cost.** IARPA.org is an educational front door, not a social hub. While the games themselves (e.g., Rogue Intelligence) may host Discords, the public portal must maintain clinical distance to preserve its tone. |
| **Contributor Profiles** | Reject | **Medium cost, High Risk.** Encourages cults of personality and potential harassment of writers. All content must be authored under institutional branding or clearly designated fictional pseudonyms. |
| **Public Leaderboards** | Reject | **High privacy risk.** Encourages the toxic gamification of educational consumption (chasing vanity metrics) and risks exposing user identifiers, violating the privacy-safe analytics ethos2. |

## **Partnership and Disclosure Framework**

Strategic partnerships are essential for expanding the educational reach and transmedia depth of the portal, but they must never compromise editorial independence, the platform's non-governmental status, or user privacy. All external affiliations must be explicitly disclosed and structurally isolated from verified historical content.  
**Primary Ecosystem Partners** The primary fictional properties include *Rogue Intelligence* (the overarching transmedia universe), *Psychological War* (a thematic property exploring the weaponization of information15), and *Espionage Psychosis* (a clinical narrative exploration of the toll of covert operations). These core properties are presented contextually within the portal's Program Atlas and learning paths.

* **Placement and Link Behavior:** Links to these properties utilize standard outbound behavior but are gated by clear transition screens or iconography indicating the user is departing the educational portal and entering a fictional simulation space.  
* **Disclosure:** A persistent banner must reiterate that the destination is a FICTIONAL EDUCATIONAL SIMULATION.

**Secondary Software Integrators** Conceptual software integrators like UAIX and Spiralist AI are treated as ecosystem sponsors rather than authoritative educational sources.

* **Placement and Priority:** Their presence is restricted to non-intrusive, locally hosted image banners located near the footer of the interface, ensuring they do not interrupt core educational consumption.  
* **Data Sharing:** Data sharing with these partners is strictly prohibited. No user analytics, session data, IP addresses, or form inputs are ever transmitted to UAIX or Spiralist AI, maintaining strict compliance with SOPPA and COPPA vendor management regulations8.

**Educational Collaborators and Reviewers** For future educational collaborators, academic researchers, and lived-experience accessibility reviewers, the portal maintains a strict conflict-of-interest policy.

* **Editorial Independence:** Any content produced in collaboration with external researchers must feature a prominent disclosure statement outlining the exact nature of the partnership, any financial compensation provided, and a guarantee of the portal's ultimate editorial control.  
* **Review Cadence:** Partnership agreements are subject to a biannual review by the Privacy Officer and Legal Risk Lead to ensure ongoing alignment with the portal's safety, privacy, and taboo.uai objectives.

## **Ethical Monetization and Sustainability Options**

To ensure the long-term viability of the portal without resorting to the exploitative tactics prevalent in modern digital ecosystems, the monetization strategy adheres to stringent ethical guidelines4. The platform recognizes that the "games as a service" model has normalized aggressive, manipulative retention strategies that reach the level of dark patterns3. The portal categorically rejects behavioral advertising, the sale of user data, and sponsored content disguised as verified research. Furthermore, dark patterns—such as loot-box mechanics with unclear odds, artificial time-gates, pay-to-win structural advantages, or paywalling critical safety and mental health information—are explicitly forbidden across the ecosystem3.  
During the initial release phase (Phase 0 and Phase 1), the portal will operate with **no monetization mechanisms**, focusing entirely on building trust, establishing the fictional boundary, achieving SOPPA/FERPA compliance, and refining the educational architecture.  
Sustainable options slated for Phase 2 and beyond include:

1. **Premium Downloadable Curricula:** Highly structured, deeply researched PDF dossiers and lesson plans intended for educators, academics, or advanced enthusiasts. These are offered for a transparent, one-time fee. This model ensures that effort to obtain premium content is reasonable and the transaction is transparent4.  
2. **Institutional Licensing:** Bulk access to premium educational materials for academic institutions and libraries, managed through standard B2B contracts. This model relies on institutional budgets rather than extracting microtransactions from individual users.  
3. **Optional Memberships / Donations:** A support model (similar to Patreon) where users can voluntarily contribute to the platform's upkeep. In exchange, they receive non-essential perks such as high-resolution digital artwork, behind-the-scenes architectural design documents, or early access to historical case studies. This preserves the fundamental ethical principle that all core educational and safety content remains freely accessible to everyone, ensuring no paywalled content restricts baseline learning4.  
4. **Merchandise:** The sale of clearly marked fictional ecosystem apparel or physical lore artifacts (e.g., replica "Rogue Intelligence" field manuals). This reinforces the transmedia experience and provides tangible value without gatekeeping digital knowledge.  
5. **Grants and Sponsorships:** Seeking funding from educational foundations or privacy-advocacy groups.

Every acceptable monetization option requires an explicit conflict-of-interest statement verifying that commercial pressures do not dictate editorial calendars, influence historical fact-checking standards, or lead to misleading endorsements.

## **Privacy-Safe Analytics Dictionary**

The analytics architecture is fundamentally designed to measure product health and educational efficacy without engaging in user surveillance. In strict compliance with the Illinois Student Online Personal Protection Act (SOPPA), the Children's Online Privacy Protection Act (COPPA), and global directives like GDPR, the platform utilizes cookieless analytics technologies6.  
Platforms like Google Analytics 4 (GA4) require persistent identifiers and often trigger mandatory cookie consent banners that degrade the user experience and result in massive data gaps when users decline tracking6. By migrating to privacy-first, cookieless alternatives like Plausible or Fathom7, the portal relies on aggregated event data and transient IP hashing. In this model, an IP address and User-Agent string are hashed to generate a daily unique identifier that cannot be reverse-engineered to identify an individual; furthermore, this hash is automatically purged and rotated every 24 hours18. This architecture eliminates the need for cross-site profiles, browser fingerprinting, precise geolocation, and session replays6. No raw form content or raw search queries containing potentially sensitive psychological terminology are ever retained, preventing the inadvertent collection of Personally Identifiable Information (PII).

| Event Name | Purpose | Fields Collected | Retention | Aggregation | User Control | Deletion | Reporting Cadence |
| :---- | :---- | :---- | :---- | :---- | :---- | :---- | :---- |
| pageview | Measure general traffic flow and structural utility. | URL path, coarse region (country/state level only), referrer domain, basic device type. | 36 months (Aggregated format only). | By URL, Daily | Respects Global Privacy Control (GPC) and Do Not Track (DNT) headers10. | Auto-purged after 36 months. | Weekly |
| outbound\_click | Measure transmedia project handoff success. | Target URL, Source URL. | 36 months (Aggregated). | By Target, Daily | Respects GPC/DNT. | Auto-purged after 36 months. | Weekly |
| path\_complete | Measure learning path and curriculum success. | Path ID, Step Count, Completion Status. | 36 months (Aggregated). | By Path ID, Monthly | Respects GPC/DNT. | Auto-purged after 36 months. | Monthly |
| broken\_link | Identify 404 navigation errors to prevent link rot. | Attempted URL, Source URL. | 90 days. | By Error, Real-time | None required (Purely a system health diagnostic metric). | Auto-purged after 90 days. | Daily |
| accessibility\_toggle | Measure UI accessibility demand to justify further inclusive design investment. | Feature invoked (e.g., High Contrast, Text Scale). | 12 months. | By Feature, Monthly | Respects GPC/DNT. | Auto-purged after 12 months. | Quarterly |
| safety\_exit | Monitor distress triggers and identify potentially harmful content. | Source URL where the exit was triggered. | 12 months. | By URL, Real-time | None required (Critical safety diagnostic). | Auto-purged after 12 months. | Daily |
| voluntary\_feedback | Collect editorial corrections and reader questions. | Category, heavily sanitized text input (PII algorithmically scrubbed prior to database insertion). | Indefinite (Forms part of the editorial archive). | Manual review | User-initiated explicit consent required upon submission. | Upon verified user request. | Monthly |

## **Twelve-Month Roadmap**

The execution of the product strategy is sequenced across five highly structured phases. This phased approach ensures that critical compliance, safety, and architectural blockers are fully resolved before advanced features or deeper educational content are introduced. Each item is strictly governed by acceptance criteria and impact assessments.

### **Phase 0 — Release Blockers (Months 1-2)**

The foundational phase addresses all structural, legal, and policy mandates required before any public traffic is permitted. Failure to complete Phase 0 constitutes an absolute block on the platform's launch.

| Roadmap Item | Outcome | Dependency | Effort | Risk | Owner | Acceptance Test | Release Gate | Privacy/Policy Impact |
| :---- | :---- | :---- | :---- | :---- | :---- | :---- | :---- | :---- |
| **Fiction and Affiliation** | Mandatory non-governmental disclaimer hardcoded into global header/footer. | UI Design | Low | Critical | Product Manager | Disclaimer is visible on all viewport sizes without scrolling. | Policy Gate | Enforces baseline fiction boundary. |
| **Government-Reference Removal** | Total absence of official seals, actual .gov domains, and real personnel names. | Content Audit | High | Critical | Legal Risk Lead | Automated and manual scan confirms zero real-world institutional assets. | Policy Gate | Mitigates impersonation liability. |
| **Privacy & Security (SOPPA)** | Execution of Data Privacy Agreements (DPAs); implementation of cookieless analytics10. | Legal Counsel | High | Critical | Privacy Officer | DPAs are publicly posted; zero cookies are dropped on initial load6. | Privacy Gate | Ensures SOPPA/COPPA compliance8. |
| **Accessibility Baseline** | WCAG 2.1 AA compliant semantic HTML foundation. | Frontend Dev | Medium | High | UI/UX Designer | Lighthouse accessibility score of 100; full keyboard navigation support. | Accessibility Gate | Prevents exclusionary design. |
| **Content Labeling UI** | Reusable UI components for mandatory visible text labels (e.g., HISTORICAL). | UI Design | Low | Medium | UI/UX Designer | Labels remain readable in high-contrast mode and on screen readers. | Editorial Gate | Enforces context comprehension. |

### **Phase 1 — Useful Public Portal (Months 3-4)**

Deployment of the core information architecture necessary for basic user orientation and ecosystem navigation.

| Roadmap Item | Outcome | Dependency | Effort | Risk | Owner | Acceptance Test | Release Gate | Privacy/Policy Impact |
| :---- | :---- | :---- | :---- | :---- | :---- | :---- | :---- | :---- |
| **Homepage & About** | Establishment of overarching narrative context and educational mandate. | Phase 0 | Medium | Medium | Content Strategist | Page clearly explains the purpose of IARPA.org as a fictional front door. | Editorial Gate | Establishes taboo.uai context. |
| **Projects & Program Atlas** | Directories routing users to external fictional properties (e.g., Rogue Intelligence). | Partner Assets | Medium | Low | Product Manager | All outbound links feature explicit transition warnings. | Technical Gate | Manages cross-domain boundaries. |
| **Glossary** | Foundational intelligence and research terminology database. | SME Review | High | Medium | Editorial Lead | 50+ terms published, labeled as REAL-WORLD INTERPRETIVE. | Editorial Gate | Deepens educational value. |
| **Safety & Privacy Hub** | Transparent documentation detailing user rights, data policies, and exit protocols. | Privacy Officer | Low | High | Privacy Officer | SOPPA breach notification policy and data element list are publicly accessible11. | Privacy Gate | Mandated transparency compliance. |
| **Privacy-Safe Search** | Client-side search index that does not transmit raw queries to servers. | Frontend Dev | High | Medium | Technical Lead | Search functions offline/client-side; no query data is present in analytics payload. | Privacy Gate | Prevents collection of sensitive search terms. |

### **Phase 2 — Educational Depth (Months 5-7)**

Expansion of the platform's core value proposition through structured learning and deep historical context.

| Roadmap Item | Outcome | Dependency | Effort | Risk | Owner | Acceptance Test | Release Gate | Privacy/Policy Impact |
| :---- | :---- | :---- | :---- | :---- | :---- | :---- | :---- | :---- |
| **Historical Cases** | Deep-dive dossiers contextualizing information warfare and espionage history14. | SME Review | High | High | Editorial Lead | Content adheres strictly to the government-source rule. | Policy Gate | High risk of crossing into classified/sensitive territory. |
| **Learning Paths** | Sequential guided curricula synthesizing glossary terms and historical cases. | Historical Cases | Medium | Low | Educational Strategist | Users can navigate from start to finish via persistent "Next Step" UI. | Editorial Gate | Increases Meaningful Educational Sessions. |
| **Briefing Archive & Timelines** | Interactive, accessible UI elements mapping historical events against fictional timelines. | UI Design | High | Medium | UI/UX Designer | Timeline is navigable via keyboard and screen reader. | Accessibility Gate | Zero privacy impact; improves chronological comprehension. |
| **Educator Resources** | Downloadable PDF lesson plans and curriculum integration guides. | Educational Strategist | Medium | Low | Content Strategist | PDFs are tagged for accessibility and clearly state terms of use. | Editorial Gate | Supports institutional engagement. |

### **Phase 3 — Sustainable Operations (Months 8-9)**

Institutionalization of internal processes, external partnerships, and operational resilience.

| Roadmap Item | Outcome | Dependency | Effort | Risk | Owner | Acceptance Test | Release Gate | Privacy/Policy Impact |
| :---- | :---- | :---- | :---- | :---- | :---- | :---- | :---- | :---- |
| **Editorial Calendar & Operations** | Full transition to the weekly/monthly/quarterly Stage-Gate publishing cadence12. | Phase 2 | Medium | Low | Editorial Lead | Three consecutive weeks of on-time content deployment without emergency rollbacks. | Editorial Gate | Internal operational milestone. |
| **Corrections Workflow** | Public changelog and structured correction submission forms. | Backend Dev | Low | Low | Content Manager | Form submissions successfully route to internal ticketing system without storing PII. | Privacy Gate | Reinforces source-method trust. |
| **Partnerships** | Deployment of non-intrusive footer banners for Spiralist AI and UAIX. | Legal Review | Low | Low | Partnership Strategist | Banners load locally (no third-party ad networks) and do not interrupt core content. | Technical Gate | Ensures zero third-party tracking10. |
| **Community Feedback** | Enabling one-way reader question and reaction mechanisms. | UI Design | Medium | Low | Product Manager | Reaction clicks register in cookieless analytics without user identification. | Privacy Gate | Provides safe, aggregated qualitative data. |
| **Accessibility Review Cycle** | Scheduled, rigorous manual accessibility audits. | Phase 0 | Low | Medium | UI/UX Designer | Quarterly report published detailing accessibility improvements and known issues. | Accessibility Gate | Proactive compliance maintenance. |

### **Phase 4 — Advanced Portal Features (Months 10-12)**

Implementation of optional, user-centric capabilities strictly gated by explicit consent and ethical monetization.

| Roadmap Item | Outcome | Dependency | Effort | Risk | Owner | Acceptance Test | Release Gate | Privacy/Policy Impact |
| :---- | :---- | :---- | :---- | :---- | :---- | :---- | :---- | :---- |
| **Optional Accounts** | Users can create accounts for bookmarking and curriculum export. | Security Audit | High | Critical | Technical Lead | Accounts require minimal PII (email only) and feature instant, self-serve data deletion11. | Security/Privacy Gate | Introduces massive PII retention risk; requires strict COPPA/SOPPA compliance9. |
| **Reading History** | Progression tracking for learning paths. | Optional Accounts | Medium | High | Product Manager | History is stored via explicit opt-in server-side profiles or local storage only. | Privacy Gate | Data minimization must be strictly enforced. |
| **Structured Evidence Packets** | Users can compile and export customized dossiers of verified historical documents. | Backend Dev | High | Medium | Educational Strategist | Exported PDFs retain all mandatory disclaimers and source-method citations. | Policy Gate | Prevents context collapse when content leaves the portal. |
| **Multilingual Content** | Localization of core safety, privacy, and fiction-boundary pages. | Translation Svc | High | Low | Content Strategist | Translated pages verified by native speakers for precise safety and boundary terminology. | Editorial Gate | Broadens accessibility; reduces cognitive friction. |

## **Release Governance**

To maintain the absolute integrity of the platform, the release governance model establishes strict definitions, sequential validation gates, and robust incident response protocols.  
**Definition of Done** A feature, content block, or historical dossier is only considered "Done" when it is completely drafted, clinically reviewed by a Subject Matter Expert, checked for taboo.uai boundary violations, verified against WCAG accessibility standards, and staged in a test environment without triggering console errors or analytics tracking anomalies.  
**Deployment Gates and Content Freeze** A formal content freeze is instituted 48 hours prior to any major technical release to prevent database synchronization conflicts and allow for comprehensive pre-flight checks. The deployment pipeline is guarded by sequential gates:

1. **Editorial Gate:** Final sign-off on narrative tone, factual accuracy, and the correct application of mandatory content labels.  
2. **Accessibility Gate:** Automated scans must return zero critical errors; complex UI components require manual screen-reader and keyboard navigation verification.  
3. **Privacy Gate:** Absolute verification that no new cookies, local storage tracking objects, or external behavioral trackers have been introduced6.  
4. **Security Gate:** Routine vulnerability scanning, dependency checking, and confirmation of data encryption standards (e.g., AES-256 for data at rest, TLS 1.2+ in transit)10.  
5. **Policy Gate:** The final, overarching review verifying the preservation of the fictional boundary, the non-governmental disclaimer, and adherence to taboo.uai parameters1.

**Rollback Criteria and Incident Response** Rollback criteria are strictly defined and aggressively enforced. If a release introduces broken primary navigation, violates the fiction boundary (e.g., the accidental publication of a real government phone number or unauthorized use of a seal), introduces an unapproved third-party tracker, or triggers a critical accessibility failure, the operations team will initiate an immediate, automated rollback to the previous stable state.  
Incident response protocols for data breaches are dictated by regional compliance laws. Any breach of student data privacy, unauthorized access to user accounts, or severe taboo.uai parameters violation will trigger public status communication on the portal within 24 hours. Furthermore, mandatory legal notifications will be dispatched to affected parties and regulatory bodies no later than 30 calendar days after the discovery of the breach, as explicitly stipulated by SOPPA guidelines11. A comprehensive post-release review (retrospective) is conducted after every major phase transition or incident to calibrate the editorial operating model, update the risk register, and refine internal operational efficiencies.

## **Risk Register**

The continuous monitoring of operational, legal, and reputational risks is essential for a platform navigating the intersection of historical intelligence, psychological themes, and transmedia fiction.

| Risk Identification | Probability | Impact | Mitigation Strategy and Monitoring |
| :---- | :---- | :---- | :---- |
| **Fiction/Reality Blur** | Medium | Critical | Ubiquitous deployment of mandatory disclaimers; rigorous editorial review against the government-source rule. Monitored via the "Mistaken-Affiliation Reports" guardrail metric. |
| **SOPPA / COPPA Violation** | Low | Critical | Enforcement of strict zero-cookie analytics architecture6; execution and public posting of mandatory DPAs for all vendors11; zero collection of PII from minors. Monitored via the Privacy Gate during release governance. |
| **Moderation Overload & Radicalization** | Low | High | Complete rejection of open forums, Discord communities, and public comments on the portal; restriction of community features to one-way, private feedback loops. Monitored by the Editorial Lead. |
| **Accessibility Degradation** | Medium | Medium | Hard automated scanning at the deployment gate; inclusion of lived-experience reviewers in the partnership framework. Monitored via the "Accessibility Toggle Utilization" and automated Lighthouse scans. |
| **Monetization Backlash** | Low | High | Total rejection of dark patterns, gacha mechanics, and pay-to-win elements4; transparent separation of premium educational downloads from core safety material. Monitored via user feedback and industry benchmarking. |
| **Link Rot / External Handoff Failure** | High | Low | Implementation of automated daily 404 scanning; utilization of the broken\_link cookieless analytics event to drive immediate editorial patching. Monitored daily by the Content Manager. |
| **Policy Scope Creep (taboo.uai Violation)** | Medium | High | Strict adherence to the Stage-Gate editorial model12; mandatory SME and Legal Risk Lead review before publication. Monitored via the Policy Gate and bi-annual content audits. |

#### **Works cited**

1. Teleodynamic Governance Anchors \- Teleodynamic AI, [https://teleodynamic.com/teleodynamic-governance-anchors/](https://teleodynamic.com/teleodynamic-governance-anchors/)  
2. The Unseen Engine: Why Your MVP Fails Without Measurement \- Blog \- LeanPivot.ai, [https://leanpivot.ai/blog/why-your-mvp-fails-without-measurement/](https://leanpivot.ai/blog/why-your-mvp-fails-without-measurement/)  
3. Inclusive Perspectives on Ethical Game Design \- KU Leuven Research, [https://research.kuleuven.be/portal/en/project/3H260010](https://research.kuleuven.be/portal/en/project/3H260010)  
4. Principles of ethical monetization : r/gamedesign \- Reddit, [https://www.reddit.com/r/gamedesign/comments/14p11a6/principles\_of\_ethical\_monetization/](https://www.reddit.com/r/gamedesign/comments/14p11a6/principles_of_ethical_monetization/)  
5. Ethical Considerations in Game Design and Monetisation \- SAE United Kingdom, [https://www.sae.edu/gbr/insights/ethical-considerations-in-game-design-and-monetisation/](https://www.sae.edu/gbr/insights/ethical-considerations-in-game-design-and-monetisation/)  
6. How to choose a privacy-friendly web analytics tool, [https://plausible.io/privacy-friendly-web-analytics](https://plausible.io/privacy-friendly-web-analytics)  
7. Privacy Analytics Tools Comparison: 2026 Guide to GDPR‑Friendly Web Analytics \- Faurya, [https://www.faurya.com/blog/privacy-analytics-tools-comparison](https://www.faurya.com/blog/privacy-analytics-tools-comparison)  
8. Student Data Privacy (SOPPA) \- Township High School District 211, [https://adc.d211.org/students/student-online-personal-protection-act-soppa/student-data-privacy-soppa](https://adc.d211.org/students/student-online-personal-protection-act-soppa/student-data-privacy-soppa)  
9. E. F. Lindop School District 92 \- Student Online Personal Protection Act, [https://www.lindop92.net/student-online-personal-protection](https://www.lindop92.net/student-online-personal-protection)  
10. EdTech Compliance 2026: SOC 2, SOPPA & State Privacy Laws | Hireplicity, [https://www.hireplicity.com/blog/edtech-compliance-roadmap-2026-soc2-soppa-state-privacy-laws](https://www.hireplicity.com/blog/edtech-compliance-roadmap-2026-soc2-soppa-state-privacy-laws)  
11. All About SOPPA: What Illinois Schools Must Know About Student Data Protections, [https://www.cybernut.com/blog/all-about-soppa-what-illinois-schools-must-know-about-student-data-protections](https://www.cybernut.com/blog/all-about-soppa-what-illinois-schools-must-know-about-student-data-protections)  
12. The Stage-Gate Model: An Overview, [https://www.stage-gate.com/blog/the-stage-gate-model-an-overview/](https://www.stage-gate.com/blog/the-stage-gate-model-an-overview/)  
13. Ethical Game Monetization \- Meegle, [https://www.meegle.com/en\_us/topics/game-monetization/ethical-game-monetization](https://www.meegle.com/en_us/topics/game-monetization/ethical-game-monetization)  
14. journal of advanced military studies \- jams \- Marine Corps University, [https://www.usmcu.edu/Portals/218/JAMS\_Spring2021\_12\_1\_web.pdf](https://www.usmcu.edu/Portals/218/JAMS_Spring2021_12_1_web.pdf)  
15. F.B. Eyes: How J. Edgar Hoover's Ghostreaders Framed African American Literature \[Course Book ed.\] 9781400852062 \- DOKUMEN.PUB, [https://dokumen.pub/fb-eyes-how-j-edgar-hoovers-ghostreaders-framed-african-american-literature-course-booknbsped-9781400852062.html](https://dokumen.pub/fb-eyes-how-j-edgar-hoovers-ghostreaders-framed-african-american-literature-course-booknbsped-9781400852062.html)  
16. The Prometheus Deception \- ACT American College of Technology, [https://library.act.edu.et/index.php?p=fstream-pdf\&fid=163\&bid=197](https://library.act.edu.et/index.php?p=fstream-pdf&fid=163&bid=197)  
17. Plausible Analytics | Simple, privacy-friendly Google Analytics alternative, [https://plausible.io/](https://plausible.io/)  
18. Plausible vs Fathom Analytics: Simple Privacy Analytics Compared \- Volument, [https://volument.com/blog/plausible-vs-fathom-analytics-simple-privacy-analytics-compa/](https://volument.com/blog/plausible-vs-fathom-analytics-simple-privacy-analytics-compa/)  
19. Plausible vs Fathom vs Matomo: Privacy Analytics 2026 | Kukie.io, [https://kukie.io/blog/plausible-vs-fathom-vs-matomo](https://kukie.io/blog/plausible-vs-fathom-vs-matomo)  
20. A Quantitative Study of Cultural Differences in Attitude Towards the Ethics on Digital Game Monetization \- DiVA portal, [https://www.diva-portal.org/smash/get/diva2:1997616/FULLTEXT01.pdf](https://www.diva-portal.org/smash/get/diva2:1997616/FULLTEXT01.pdf)  
21. Fathom Analytics vs Plausible: A Detailed Comparison for 2026 | Swetrix, [https://swetrix.com/comparison/fathom-analytics/vs-plausible](https://swetrix.com/comparison/fathom-analytics/vs-plausible)  
22. Conversion Rate Optimization: Complete Guide to Higher Conversions 2026 \- Volument, [https://volument.com/blog/conversion-rate-optimization-complete-guide-to-higher-conver/](https://volument.com/blog/conversion-rate-optimization-complete-guide-to-higher-conver/)  
23. Editorial Workflow: 8 Steps, Examples & Template (2026) \- Multicollab, [https://www.multicollab.com/blog/guide-editorial-workflow/](https://www.multicollab.com/blog/guide-editorial-workflow/)  
24. Delivery Model and Operating Model \- Umbrex, [https://umbrex.com/resources/ai-use-case-discovery-and-prioritization-playbook/delivery-model-and-operating-model/](https://umbrex.com/resources/ai-use-case-discovery-and-prioritization-playbook/delivery-model-and-operating-model/)  
25. MindWar: Psychological Warfare Tactics | PDF | Guantanamo Bay Detention Camp | September 11 Attacks \- Scribd, [https://www.scribd.com/document/727864300/Larouche-Children-of-Satan-Cheney-Rumsfeld-Bush-Complete](https://www.scribd.com/document/727864300/Larouche-Children-of-Satan-Cheney-Rumsfeld-Bush-Complete)  
26. Best Analytics Platforms for Startups in 2026: Complete Guide \- PainOnSocial Blog, [https://painonsocial.com/blog/best-analytics-platforms-startups-guide](https://painonsocial.com/blog/best-analytics-platforms-startups-guide)  
27. (105 ILCS 85/) Student Online Personal Protection Act. \- Illinois General Assembly, [https://www.ilga.gov/Legislation/ILCS/Articles?ActID=3806\&ChapterID=17\&Print=True](https://www.ilga.gov/Legislation/ILCS/Articles?ActID=3806&ChapterID=17&Print=True)  
28. SOPPA \- Pleasant Hill CUSD \#3, [https://www.phwolves.com/vnews/display.v/ART/643b52f4039e7](https://www.phwolves.com/vnews/display.v/ART/643b52f4039e7)