| name | assessing-enemy-trust-and-belief |
| description | Review how far the adversary is judged to trust a channel — the belief on which every deception rests; use when reviewing this facet of a deception or counter-deception case. |
| kind | skill |
| status | ready |
| provenance | {"principles":["P004","P013","P021","P022","P038","P064","P091"],"claims":["C00057","C00074","C00083","C00087","C00088","C00093","C00094","C00095","C00108","C00112","C00120","C00143"],"evidence":[],"source_anchors":[],"authored_from_digest":"33a5a84883cfc13d8355a1afee67e8e5d66dcd66f9581cc83fb520d4daa68a5a"} |
Assessing Enemy Trust And Belief
Purpose
This skill audits whether an analytic product's claim that the adversary trusts, doubts, or
has "blown" a channel is actually grounded in evidence the enemy himself has produced — his
questions, his payments, the codes and resources he has entrusted, his handler's conduct, and
any secret intelligence on his own state of mind — rather than asserted from the analyst's
confidence or a run of apparent success. It also checks that an agent's value in that chain is
graded by the verifiable facts he supplies rather than his social standing, and that "not yet
blown" is never quietly read as "unblowable." Trust is the belief on which every deception
rests, so a chain that inflates, stales, or under-evidences it is the specific denial-and-
deception risk this skill exists to surface.
When to use
- A product asserts the enemy trusts, doubts, or has "blown" a channel — or a channel is about
to carry a critical task — and the judgment needs checking against the enemy's own
observable behaviour rather than the analyst's confidence or the calendar.
- A handler's personal conduct toward an agent is cited as proof the enemy believes in him, and
the strength of that showing needs testing.
- An agent's value is being graded, and the grade appears to rest on his social or
organizational access rather than the hard, verifiable facts he actually supplies.
- A "never blown" or "survived scrutiny" track record is being read as proof the channel is
secure, rather than as the benign story the enemy may simply prefer to believe.
- A recovery, reassurance, or "the enemy suspects nothing" narrative is offered as evidence of
continued confidence, and its escalation pattern needs checking.
- A newly recruited agent is being proposed for long-term strategic work, or a veteran's
standing is being discounted for a fresher recruit, without evidence for the reversal.
- A forward tactical source's report is being preferred over a rear or home-base source's,
purely for immediacy, without weighing positional reliability.
Procedure
- Establish the object under review: the specific claim about the enemy's belief (trust,
doubt, or "blown") toward a named channel, and locate the evidence the product offers for
it, before judging whether that evidence is sufficient for what rests on it.
- Check that the trust claim traces to the enemy's own observable behaviour — the questions
he has asked, the payments he has made, the sensitivity and reuse of the codes and methods
entrusted to the agent, the training and resources invested in him, remarks from personal
contact, and any secret intelligence on how he is regarded — rather than to the analyst's
confidence or the mere passage of time; because standing oscillates, flag any critical-task
reliance built on a stale assessment (P013).
- Where the product cites a handler's conduct as proof of belief, test it against the
strongest signature: a handler who manages his own superiors to reward and protect the
agent, even securing him an enemy decoration. A weaker showing — routine correspondence, an
occasional bonus — does not license "the enemy is fully invested" language (P004).
- Check how the product grades the agent: it should rest on the verifiable facts he supplies,
not his social or organizational access. Flag a review that treats a well-connected source
relaying gossip or embassy rumour as high-grade, or that undervalues a lowly placed source —
a seaman, a wireless operator — whose reports are hard, checkable fact; the enemy's own
staff needs facts, not access, to build its appreciations (P022).
- When the product treats a channel as secure because it has "never been blown," test whether
that conclusion rests on positive counter-evidence or only on the absence of a bad outcome
so far. A well-established, trusted agent is expected to be hard to blow because the enemy
prefers a benign explanation — misled, the plan abandoned, the cover held — over the truth,
even against contrary evidence; name the benign story the enemy could be telling itself
instead of accepting "unblown" as "unblowable" (P021).
- If the product narrates a recovery or reassurance effort meant to preserve enemy confidence,
check that the escalation was gradual and calibrated — visibly concerned without visible
panic — so importance is inferred rather than announced. A narrative that jumps straight to
alarm, or shows no urgency at all, is itself a signature worth flagging (P038).
- Check the service life assigned to each agent against the trust the record actually shows: a
veteran, long-established agent carries far more enemy confidence than a new one. Flag a
plan that slots a newly acquired agent into long-term strategic build-up, or that discounts
a veteran's standing for a fresher recruit, without evidence justifying the reversal (P064).
- Check how the product weighs competing sources for reliability: a source further back — rear
or home base — should ordinarily outweigh a forward tactical source for reliability and
value. Flag a comparison that defaults to the forward source's immediacy without applying
this positional discount (P091).
Inputs
- The specific belief claim under review: a channel judged fully trusted, doubted, or
"blown," and the case record or product it rests on.
- The enemy's documented behaviour toward the channel: questions asked, payments made,
codes/methods entrusted and their sensitivity or reuse, training and resources invested,
personal-contact remarks, and any secret intelligence on how the channel is regarded.
- The evidence offered for the agent's grade: the specific facts he has supplied, set against
any claim of social, organizational, or embassy access.
- The handler's documented conduct, wherever a claim of deep personal investment is made.
- The channel's service history: how long established, how (and whether) it has weathered past
scrutiny, and its position — rear/home base versus forward tactical.
- Any recovery, reassurance, or escalation narrative offered as evidence the enemy remains
confident.
- The time elapsed since the trust assessment was last refreshed, especially where a critical
task is imminent.
Output
Per finding: name the trust-and-belief flaw (an asserted-not-evidenced trust claim, a stale
assessment carried into a critical task, a handler-investment claim resting on a showing
weaker than the strongest signature, an agent graded by access rather than fact, an "unblown"
reading treated as "unblowable," a recovery narrative that over- or under-escalates, a service
horizon mismatched to demonstrated confidence, or a reliability ranking that ignores
rear-versus-forward positioning), apply the correction (re-derive the trust level from the
enemy's questions, payments, and investment; re-grade the agent against the facts he supplies;
name the benign story the enemy could be telling itself; recalibrate the escalation; reassign
the agent's service horizon; reweight source reliability by position), state the residual
uncertainty the correction leaves — including whether the analyst's own confidence in the
channel could itself be a product of the enemy's management — and end with a concrete next
step. Order findings highest-impact first. Never issue the caller's go/no-go: the corrected
judgment and the residual risk are handed back to the operation's owner.
Anti-patterns to flag
- A trust claim ("the enemy fully trusts this channel") stated with no reference to his
questions, payments, codes entrusted, resources invested, or personal remarks — confidence
asserted, not evidenced (P013).
- A trust assessment carried unchanged into a critical decision long after it was last checked,
on the assumption that standing does not change (P013).
- Handler solicitude — routine correspondence, an occasional bonus — inflated into "the enemy
is fully invested," without showing the strongest signature: managing his own superiors to
reward and protect the agent (P004).
- An agent graded high for his social or organizational access while the verifiable facts he
actually supplies are thin, rumour-grade, or absent (P022).
- "The channel has never been blown" read as "the channel cannot be blown," ignoring that the
enemy's own incentive is to prefer a benign explanation over admitting deception (P021).
- A recovery or reassurance narrative that swings to visible panic — risking tipping the enemy
to a plant — or shows no escalation at all, instead of the gradual, calibrated concern the
tradecraft calls for (P038).
- A newly recruited agent slotted into long-term strategic build-up, or a veteran's standing
discounted for a newer recruit, with no evidence offered for the reversal (P064).
- A source comparison that favours a forward tactical report's immediacy over a rear or
home-base source's reliability, without weighing the positional discount (P091).
References
See ../../references/deception-detection-principles-index.md for the full principle
catalogue. For adjacent concerns, see the sibling skills:
turning-and-running-a-controlled-agent, the critical work this trust level must be current
before supporting; counter-deception-and-the-mirror, which asks the deeper question of
whether the enemy's apparent confidence is itself evidence the reviewer's own side is being
deceived; and strategic-stewardship-and-timing, which governs how a veteran's confidence
versus a newly acquired agent's is spent over time.
Provenance
Derived solely from P004, P013, P021, P022, P038, P064, and P091 (J. C. Masterman, The
Double-Cross System; distillation-only; see the frontmatter above for the full claim list).