IARPG-OPS-1 online Intelligence operations standard Fictional missions · neutral authorities
CI-01 Current Counterintelligence Version 1.0.0

Counterintelligence Investigation

Counterintelligence identifies compromise through competing explanations, evidence provenance, access analysis, behavioral change, and controlled tests.

Normative requirements

What conforming mission design must express.

01
MUST required for conformance

Separate access, opportunity, action, motive, and attribution as distinct investigative questions.

02
MUST required for conformance

Counterintelligence consequences require case evidence and reason codes rather than omniscient server accusation.

03
SHOULD recommended unless a documented reason applies

Offer controlled tests, source validation, audit, surveillance, and damage assessment as different investigative tools.

04
MAY optional supported behavior

The apparent compromise be a deception operation intended to redirect investigators.

Mission lifecycle fit

Where this record applies.

Task Plan Collect Validate Deliver

This list identifies the mission stages where the record is most likely to be implemented or reviewed. It does not prevent the requirement from influencing adjacent phases.

Search and implementation terms

Vocabulary carried by this record.

Supporting research

Deep links into the complete report archive.

The canonical record stays concise. These links preserve the longer argument, design context, limitations, and source lineage in the `/docs/` archive.

Connected tools and standards

Explore the wider AI ecosystem.