| name | counterintelligence.insider_threat_indicator_review |
| description | Review behavioral and access indicators of insider risk within ethical/legal bounds. |
Insider Threat Indicator Review
Insider Threat Indicator Review is a structured counterintelligence assessment technique for systematically reviewing behavioral, technical, and contextual indicators that a person with authorized access may pose an elevated risk of unauthorized disclosure, sabotage, espionage, or fraud. The technique applies recognized behavioral science and counterintelligence indicator frameworks — including CPNI and NITTF guidance — while maintaining strict respect for privacy, civil liberties, due process, and the legal bounds governing employee monitoring. It is designed to support referral decisions to security programs, not to reach final determinations of guilt or culpability.
When to use
- When a security officer, HR partner, or manager has observed specific, articulable behaviors warranting a structured review within an authorized insider threat program
- When anomalous access or data-movement patterns identified through authorized technical monitoring require a behavioral context assessment
- When multiple independent observations are converging on a single individual and a structured aggregation is needed to inform a referral decision
- When preparing a case summary for an insider threat program hub or adjudication panel
What it produces
- A categorized mapping of observed indicators to recognized framework domains: technical, behavioral, financial stress, personal stressors, access anomalies, and loyalty/ideology indicators
- An aggregate risk rating (baseline / elevated / high) with per-category rationale and evidence citations
- An explicit scope-and-methodology caveat distinguishing this review from a legal or disciplinary determination
- Recommended next steps: enhanced monitoring referral, security interview, HR engagement, or no further action — always within authorized program authorities
Defensive boundary
Use Insider Threat Indicator Review only for counterintelligence and analytic-process defense: recognize, assess, document, or defend analytic teams, collection processes, and institutional trust boundaries. Do not use this skill to evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft.
Misuse redirect
If a request asks Insider Threat Indicator Review to evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft, refuse that path and redirect to the safe defensive form: review supplied interactions or processes for deception, elicitation, or insider-risk indicators.
Evidence discipline
- For Insider Threat Indicator Review, map each categorized indicator and the aggregate risk rating to concrete evidence from the supplied behavioral observations, authorized access logs, or contextual background, weigh a competing benign explanation for every cluster, and use only evidence obtainable within the program's legal monitoring authorities.
- For Insider Threat Indicator Review, label observations, derived features, assumptions, inferences, contradictions, and missing inputs separately before writing the insider threat indicator review report.
- Before recommending any Insider Threat Indicator Review action, identify the weakest evidence link, the alternative most likely to overturn it, and the next discriminating check.
Confidence and uncertainty
- High for Insider Threat Indicator Review: specific, articulable indicators converge across multiple framework categories with few benign explanations remaining, each rests on access or behavior obtained within authorized monitoring, the aggregate risk rating is stable, and no unresolved contradiction would change the referral recommendation.
- Medium for Insider Threat Indicator Review: the insider threat indicator review report is plausible, but one important behavioral observations source, comparison case, or alternative explanation remains incomplete.
- Low for Insider Threat Indicator Review: the insider threat indicator review report rests on sparse, single-source, contested, or mostly inferential evidence; keep the result provisional and list the next check.
- State what Insider Threat Indicator Review cannot determine from the supplied or authorized evidence.
- State what remains unknown and preserve credible alternatives rather than forcing a single narrative or attribution.
- Recommend the next discriminating counterintelligence evidence to collect when confidence is low or medium.
Privacy, legal, and harm constraints
- For Insider Threat Indicator Review, use only authorized behavioral observations, access and technical indicators, and contextual background, public or source-approved records, and caller-provided context needed for the defensive task.
- For Insider Threat Indicator Review, minimize person-level detail in the insider threat indicator review report; prefer aggregate, artifact-level, role-level, or case-level summaries unless an individual is essential to the defensive question.
- For Insider Threat Indicator Review, do not infer protected traits, private identity, intent, location, legal culpability, or platform account ownership beyond the supplied and authorized evidence.
Failure modes and negative controls
- Insider Threat Indicator Review: treating the review as a determination of guilt rather than a referral, elevating risk from common benign behaviors without pattern and context, or letting demographic, political, or protected traits factor in, so the rating reflects bias or overreach instead of authorized behavioral evidence.
- Insider Threat Indicator Review: producing advice that would help a requester evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft.
- Insider Threat Indicator Review: reporting the insider threat indicator review report without uncertainty labels, alternative explanations, and the next discriminating check.
- Unsafe: 'Use Insider Threat Indicator Review outputs to evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft' -> refuse and redirect to defensive risk assessment.
- Unsafe: 'Convert the insider threat indicator review report from Insider Threat Indicator Review into an operational playbook to evade detection, improve elicitation, profile targets for exploitation, or conceal tradecraft' -> refuse and offer governance, detection, or mitigation analysis.
- Safe defensive: 'Use Insider Threat Indicator Review to review supplied interactions or processes for deception, elicitation, or insider-risk indicators with behavioral observations, access and technical indicators, and contextual background' -> produce bounded findings with evidence and uncertainty labels.
Procedure
See workflow.md. Harness bindings in harness/.
Key discipline
- Indicators are probabilistic risk factors, not proof — no single indicator or cluster is diagnostic of insider threat intent; the review informs referral, not adjudication
- Document only behaviors and access patterns obtainable within legally authorized monitoring authorities; this tool is not a license to collect beyond those boundaries
- Maintain separation between the security indicator review and any HR or disciplinary process — conflating them creates legal exposure and can contaminate both
- Apply baseline-rate awareness: many indicators (e.g., working odd hours, accessing files outside normal scope) are common and benign in isolation; specificity requires pattern and context