| name | counter-deception-and-the-mirror |
| description | Review the reasoning about whether you are the one being deceived — the mirror discipline that keeps a running deceiver honest; use when reviewing this facet of a deception or counter-deception case. |
| kind | skill |
| status | ready |
| provenance | {"principles":["P011","P045","P048","P050","P059","P070","P074","P077","P078"],"claims":["C00023","C00030","C00031","C00038","C00059","C00060","C00061","C00127","C00160","C00164","C00174","C00252"],"evidence":[],"source_anchors":[],"authored_from_digest":"7ef790580c39dd03a7439488e4152a0d34e9cf9e0d237c7d9ffdb6c239ebe195"} |
Counter Deception And The Mirror
Purpose
This skill audits the evidence chain behind a deception or counter-deception judgment for the
one failure mode the other skills in this package cannot catch: that the reviewing side is
itself the one being deceived. It puts the mirror question to a claim that a channel is
controlled, that a case is clean, or that "we are not being deceived" — checking whether
confidence was calibrated to the wartime and theatre asymmetry that should set it, whether the
enemy's own tradecraft habits were turned to advantage rather than merely watched for, whether
an absence of enemy activity was credited as evidence rather than discounted as silence, and
whether the judgment still leaves room for a stray signal or a changed circumstance to
overturn it. This is a review of the counter-deception reasoning itself, never an instruction
to run a deception, recruit or turn an agent, or make the operational call.
When to use
- An assessment concludes a channel is controlled, trusted, or that "we are not being
deceived," and that conclusion has not yet been tested against the possibility that the
reviewing side is the one being played.
- A counterespionage effort's confidence needs checking against whether it operates on home
ground, where the odds favour the defender, or tries to run agents inside the enemy's own
territory, where the odds are reversed.
- A case is being checked for whether it exploited the enemy's own tradecraft habits — a
captured agent's fallback contact, a stay-behind network left in newly retaken territory —
rather than only defending against them.
- A review needs to check whether a quiet period, or an absence of enemy activity, was
credited as evidence of control or dismissed instead as merely a gap in the record.
- A volunteer who surfaced an operation on their own initiative, or a recruitment candidate
with a genuine pre-existing enemy contact, needs their disposition checked against the
narrow conditions under which recruiting them succeeds.
- A running channel's tasking has started to demand something the reviewing side cannot
safely supply, and whether it should be dropped or limited needs checking.
- A control method that worked in a past case is being carried over unchanged to a new one,
and whether the favourable conditions behind it will actually recur needs checking.
Procedure
- Isolate the specific claim under review — that a channel is controlled, that a case is
clean, or that "we are not being deceived" — and put the mirror question to it directly:
could the enemy be running this same play back against the reviewing side? Flag any case
that treats an unbroken run of apparent successes as proof of safety, or that credits
success to the reviewing side's own superior skill rather than to genuinely checkable
control, since this adversary's tradecraft could rival the reviewing side's own (P070).
- Check the case's baseline confidence against the wartime asymmetry: counterespionage on
home ground is the higher-yield, lower-effort activity, while running agents deep inside
enemy territory is the harder, less rewarding one — and that relationship flips in
peacetime. Flag confidence pitched for the wrong side of that asymmetry (P011).
- Audit whether the case actively exploited the enemy's own tradecraft rather than only
watching for it: was a captured or turned agent's fallback contact cross-checked against
the reviewing side's own controlled roster, since the enemy often hands a newcomer
straight to an asset already run (P050); and, in newly liberated or newly contested
territory, were officers already trained and positioned in advance to capture and turn the
resulting stay-behind networks before the opportunity passed (P048)?
- Check how the case counts success. Counterespionage's core purpose is prevention, whose
biggest wins leave no visible trace — nothing happens because the threat was headed off
before it could act. Flag a review that only credits positive catches and treats a quiet
stretch as a blank in the record rather than as intelligence about the enemy's
non-response (P059).
- Audit the handling of unsolicited or informal leads: a volunteer who, on their own
initiative, surfaced the reviewing side's own operation or the enemy's should have been
recruited rather than turned away (P077); and a candidate for active recruitment with a
genuine, pre-existing enemy contact — and only that candidate — should be the one
redirected back toward the enemy, since near-coat-trailing rarely succeeds any other way
(P074, applies only where that prior connection is real).
- Check that an otherwise-ideal channel was not kept running once its tasking crossed into
asking for material that cannot be handed over safely — genuine operational data of real
value to the enemy, not a safe substitute — without the case flagging that the channel
should be limited or dropped (P078).
- Confirm the case treats its control methods as adaptable guides for present circumstances,
not as fixed rules carried over from a different operation, theatre, or opponent, since the
favourable conditions behind them are not guaranteed to recur (P045).
- Emit findings highest-impact first in the format set out under Output, keyed to whichever
check failed above: the mirror question, asymmetry-miscalibrated confidence, an
unexploited enemy habit, success measured by presence alone, a missed or mishandled
recruitment, an unsafe tasking left running, or stale doctrine.
Inputs
- The specific claim or assessment under review — that a channel is controlled, that a case
is clean, or that the reviewing side is not being deceived — and the reasoning behind it.
- Whether the setting is wartime or peacetime, and whether the case runs on the reviewing
side's home ground or inside the enemy's own territory.
- Any known enemy tradecraft habits bearing on the case, such as fallback-contact assignment
for new spies or stay-behind network practice in territory about to change hands.
- The record of enemy activity, or its absence, that the case draws its conclusions from, and
how that record was interpreted.
- Any volunteer, walk-in, or recruitment candidate with a claimed pre-existing enemy contact
under consideration, and the disposition the case gave them.
- The channel's current or proposed tasking, including any demand for material the reviewing
side cannot safely supply.
- The origin of the control methods or procedures relied on — a prior operation, an earlier
theatre, a different opponent — so their fit to present circumstances can be checked.
Output
Per finding: name the counter-deception flaw (mirror question left unasked, confidence
miscalibrated to the wrong side of the wartime asymmetry, an enemy habit unexploited, success
measured only by presence and not absence, a recruitment opportunity missed or mishandled, an
unsafe tasking left running, control methods frozen into fixed rules), apply the correction
(ask whether the enemy could be running the same play back, recalibrate confidence to the
theatre and season, cross-check the fallback-contact and stay-behind angles, credit an
absence of enemy activity as intelligence, recruit the volunteer or redirect the genuine
contact, limit or drop the unsafe tasking, treat control methods as adaptable guides), state
the residual uncertainty — including who could still be deceiving whom — and end with a
concrete next step. Order findings highest-impact first. Never issue the caller's go/no-go,
and never certify a channel controlled or clean: the corrected judgment and the residual risk
are handed back to the case's owner.
Anti-patterns to flag
- Treating an unbroken run of apparent successes as proof the reviewing side cannot also be
a victim, or crediting success to its own superior skill rather than to genuine, checkable
control (P070).
- Setting confidence in a home-ground counterespionage effort no higher than confidence in a
foreign-ground agent-running effort, or the reverse, without adjusting for which side of
the wartime asymmetry actually applies (P011).
- A captured or turned agent's fallback contact never cross-checked against the reviewing
side's own controlled roster, or a newly liberated or newly contested area entered without
officers already trained and positioned to capture and turn its stay-behind networks
before the opportunity passes (P050, P048).
- A quiet stretch read as "nothing is happening" instead of logged and weighed as
intelligence that the channel, or the wider effort, is working (P059).
- A walk-in who exposed an operation on their own initiative turned away instead of
recruited, or a candidate with a real pre-existing enemy contact approached cold instead
of redirected back toward the enemy (P077, P074).
- An otherwise-ideal channel left running once its tasking crossed into demanding real,
unsuppliable material, with no flag to limit or drop it (P078).
- A control procedure inherited from a past success applied unchanged to a new operation,
on the unexamined assumption that the same favourable conditions still hold (P045).
References
See ../../references/deception-detection-principles-index.md for the full principle
catalogue. For adjacent concerns, see the sibling skills: assessing-enemy-trust-and-belief
establishes the evidence of enemy trust that this skill's mirror question puts to the test;
turning-and-running-a-controlled-agent and network-security-and-compartmentation cover
the operational and compartmentation discipline this skill assumes is in place; and
strategic-stewardship-and-timing covers the capability-level decision a counter-deception
finding here should feed into.
Provenance
Derived solely from P011, P045, P048, P050, P059, P070, P074, P077, and P078, grounded in
J. C. Masterman's The Double-Cross System (distillation-only); the frontmatter provenance
block above lists the exact principle and claim ids, which resolve into
principles/principles.yaml and analysis/claims.jsonl.