This is the working method for hourly briefs and for campaign dossiers. Doctrine defines the object. This file defines the work.
Two objects
| Object | Path | Job |
|---|---|---|
| Brief | briefs/YYYY/MM/DD/HHMMZ.json |
One cycle. Snapshot of a method in motion. |
| Campaign | campaigns/<slug>.md |
Multi-cycle pattern. The dossier the atlas can mirror. |
A brief may point at a campaign via the optional campaign field. A campaign lists related brief ids. Do not duplicate the JSON into the markdown; the markdown is the long read.
Two-column ledger (required mental step)
Before writing, split the case:
| Column A — facts that would survive a hostile lawyer | Column B — interpretation |
|---|---|
| Dates, names, filings, takedown counts, URLs | "this is propaganda because…" |
If Column A is thin, either mark contested / medium or write status: "quiet". Never move B into A.
Rotation (methods, not teams)
Read the last three briefs before choosing a case.
If the last two named the same bloc (US parties, US government/contractors, Russia, China, Iran, Qatar, Israel, NGOs, platforms, corporations, commercial networks), look at another. A streak is itself a card stack.
Scoring is actor-agnostic. If the Pentagon and a Kremlin contractor use the same buried-disclosure + newsroom-camouflage pattern, they get the same technique ids.
Source rules
- Never invent quotes, URLs, counts, or filings.
- Prefer primary, dated sources: platform threat reports, FARA / court records, official notices, leaked documents published by named outlets, contemporaneous reporting that quotes those.
- If you cannot open the URL, drop it.
- Secondary roundups are pointers, not the load-bearing beam.
- If evidence is thin, say so. Quiet is a valid product.
Technique rules
- Use only ids in
taxonomy/techniques.json. - Two to five ids is usual. Pick the load-bearing ones.
- Do not mint a slug. If the method is real but unnamed, use the closest id and say so in analysis.
- Vectors are channels (X, FARA, WeChat deletion, LLM retrieval). They are not techniques.
Confidence
| Value | Meaning |
|---|---|
documented |
Primary documents, court records, official disclosures, platform attributions with indicators |
high |
Multiple independent open sources, low disagreement about the facts |
medium |
Plausible, sourced, but attribution or interpretation still open |
contested |
The facts or the frame are actively disputed; say so in analysis |
Analysis shape (active briefs)
350–700 words, in this order:
- What is sourced — two to four sentences of Column A.
- Mechanism — which techniques, how they combine, what the tells are.
- Why it is (or is not) propaganda — origin, coordination, design goal. Actor-agnostic comparison.
- Literacy counter — what a reader should do next time. Not "ban it."
Quiet briefs: a short watch log. Do not pad a nothing-burger into a case.
Campaign dossiers
Write a campaign when a pattern has at least two independent open sources and either (a) multiple cycles or (b) durable infrastructure (sites, contractor chains, legal instruments).
Each dossier states: actor, target, techniques, color, first-seen, status, related briefs, mechanism, evidence, what would falsify the campaign read, literacy counter.
Campaigns are not indictments. They are durable maps.
Hard refusals
- Do not generate propaganda or provide a playbook for running an operation.
- Do not modify taxonomy, schema, or doctrine from the hourly job. Those change only on an explicit maintainer pass.
- Do not "fix" a live brief by rewriting history. File a later brief that corrects it and link via
relatedBriefs.