Course Architecture — OSINT Analyst Program

The master plan. Shelves hold module cards; cards are built one at a time (see CLAUDE.md → Pace). Sources are registered in sources; the figures cited here map to that canon.

Canon (six books): kahneman · bazzell · clark · heuer-psych · sat (Heuer & Pherson) · mcdowell. Military doctrine stubs are dropped (2026-07-29). ICD 203 / 206 / 208 remain as public ODNI standards (cited where product standards apply — not mil doctrine).


1. The model: calibrate the mind, teach the process once, then compose

The hard problem this course solves: tradecraft cross-sections across deliverables. ACH, source grading, and collection planning appear in a subject dossier, a corporate DD, and a national estimate. Teaching per-deliverable would re-teach ACH 60 times; teaching per-technique would never show how it assembles into a product. And upstream of all of it, a great analyst is made by cognitive habits — knowing how judgment works, where intuition misleads, holding uncertainty honestly — that no template conveys. So:

  • Foundations (F1–F2) — the pre-process layer, taught first: F1 The Analyst’s Mind (Kahneman-led dual-process, biases, calibration, judgment under uncertainty, mental models) then F2 Orientation (what intelligence is).
  • Core process (L1–L5) — the cross-cutting tradecraft primitives of the intelligence process (Requirements → Production), taught once.
  • Applied tracks (A–G) — one per target shape, composing core cards against real deliverables. They reference core cards (applies L4-03); they never re-teach.
  • Capstone — one investigation end-to-end, producing a real deliverable, graded against ICD 203.

Shelves = 2 foundations + 5 core + 7 applied + 1 capstone = 15 shelves, not a fixed module count. Module count is emergent (~55–75), tiered by complexity: a POI dossier is Thin; an intelligence estimate is Deep.


2. Source-ownership map (from the source scout)

Trust each source where it leads, not everywhere it’s “relevant.”

ModuleOwns it (lead)Reinforced byFusion load
F1 The Analyst’s MindKahneman (System 1/2, heuristics & biases, calibration, judgment under uncertainty)Heuer-Psych (analyst-specific mental models / mindsets — bridge card F1-05); SAT (18 traps, reinforcing)medium
F2 OrientationMcDowell + Clark (what intel is; cycle vs target-centric)Heuer, Bazzell (analyst OPSEC), house (ethics)light
L1 RequirementsMcDowell (ICP / TOR / 12-step strategic process) + SAT (indicators gen/validate/evaluate) + Clark (gap→collection)medium (3)
L2 CollectionBazzell (sock puppets, VM OPSEC, breach/leak data)clean (1) ⚠ perishable
L3 ProcessingBazzell (6 pivot chains, EXIF) + Clark (SNA, target model) + SAT (network charting)medium (3)
L4 AnalysisHeuer-Psych (ACH origin, cognition) + SAT (six-families taxonomy, KAC, deception) + Clark (evidence-eval, estimative) + McDowell (4×4 grading)crowded (4) — crown jewels
L5 ProductionMcDowell (assessment layout) + Bazzell (case report) + Clark (briefing)ICD 203 / 206 / 208 (public ODNI standards — product rigor, not mil doctrine)medium

3. Shelves — planned cards

Status legend: · planned · · drafting · · review · · done. IDs are stable; ordering may shift.

F1 · The Analyst’s Mind — taught first (cognitive calibration; Kahneman-led)

IDCardLead source(s)Status
F1-01Two minds — System 1 / System 2, WYSIATI: the analyst’s default settings ⭐ pattern-setterKahnemandone
F1-02Cognitive biases & intuitive traps — anchoring, availability, representativeness, substitutionKahneman; Heuer-Psych reinforcingreview
F1-03Overconfidence & calibration — illusion of validity, planning fallacy, inside vs outside viewKahnemanplanned
F1-04Judgment under uncertainty — small numbers, regression to the mean, framingKahnemanplanned
F1-05Mental models & mindsets — why more information does not equal better judgment (bridge to L4)Heuer-Psych (lead); Kahneman reinforcingplanned

F2 · Orientation — what intelligence is

IDCardLead source(s)Status
F2-01What intelligence is — intel vs information; the analyst’s roleMcDowell, Heuerplanned
F2-02The intelligence cycle vs the target-centric modelClark, McDowellplanned
F2-03Ethics, authorities, PII & legal limitshouse + civplanned
F2-04OPSEC for the analyst — intro (hands off to L2)Bazzellplanned

L1 · Requirements & Planning

IDCardLead source(s)Status
L1-01PIR → indicator → SIR (each pinned to NAI + LTIOV) ⭐ format pattern-setter · built on ATP 2-01 (dropped) — re-anchor to mcdowell/clark in revision passMcDowell, Clark (target leads post-revision)review
L1-02Writing good PIRs & the “so what”McDowell (TOR)planned
L1-03The collection plan / ICPMcDowellplanned
L1-04Terms of Reference / project taskingMcDowellplanned
L1-05Gap analysis & collection strategy (cue / mix / redundancy)Clarkplanned
L1-06Indicators: generation, validation, evaluationSAT, McDowell (cycle)planned

L2 · Collection & Managed Attribution ⚠ LIVE / quarantined

Concepts are stable; specific tooling is perishable and operator-owned. Each card carries a last-verified: date; tool lists live in a dated appendix, not the card body.

IDCardLead source(s)Status
L2-01Managed attribution — concept & the attribution stackBazzell + liveplanned ⚠
L2-02Virtual machines & host isolationBazzell + liveplanned ⚠
L2-03Sock puppets / covert accountsBazzell + liveplanned ⚠
L2-04Source types — surface / deep / darkBazzell + liveplanned ⚠
L2-05Breach & leak data exploitationBazzell + liveplanned ⚠
L2-06Capture, preservation & chain of custodyBazzell (stable)planned
L2-99Current tooling register (dated appendix)live + operatorplanned ⚠

L3 · Processing & Exploitation

IDCardLead source(s)Status
L3-01Entity resolution & disambiguationClark, Bazzellplanned
L3-02The selector pivot — 6 data-type chainsBazzellplanned
L3-03Geolocation & EXIF / image exploitationBazzellplanned ⚠
L3-04Link analysis fundamentalsClark, Bazzellplanned
L3-05Social network analysis — centrality, brokers, bridgesClark, SATplanned
L3-06Network charting / meta-network constructionSAT, Clarkplanned

L4 · Analysis & Judgment ⭐ crown jewels

IDCardLead source(s)Status
L4-01Inference: deduction, induction, abductionClark, Heuerplanned
L4-02Mental models, evidence & diagnosticityHeuerplanned
L4-03Analysis of Competing Hypotheses (ACH) — reconciling Heuer-8 / SAT-9Heuer, SATplanned
L4-04Key Assumptions CheckSATplanned
L4-05Quality of Information CheckSAT, Heuerplanned
L4-06The SAT toolkit — six families & technique selectionSATplanned
L4-07Source grading — McDowell 4×4 as house standard; Admiralty/NATO letter-number as a named variantMcDowell (house); Admiralty/NATO variantplanned
L4-08Confidence vs probability & estimative languageHeuer (dot-plot), ICD 203, Clarkplanned
L4-09Bias mitigation, red teaming, premortemSAT, Heuerplanned
L4-10Critical Factors Analysis (CFA)Clark, SAT (house synthesis)planned

L5 · Production & Dissemination

IDCardLead source(s)Status
L5-01BLUF & analytic writingICD 208planned
L5-02The analytic standards — ICD 203ICD 203 (public ODNI)planned
L5-03Sourcing & citations — ICD 206ICD 206 (public ODNI) — full product rigor lives here as course contentplanned
L5-04Report formats — assessment layout, case report, briefingMcDowell, Bazzell, Clarkplanned
L5-05Tailoring to the customer; the analyst-consumer relationshipClark, Heuerplanned
L5-06Visualization, classification & handling (TLP)house + civplanned

4. Applied tracks — depth-tiered, mapped to deliverables

Each track composes core cards against its shape’s deliverables. Thin/Med/Deep = teaching depth, not deliverable count. Full deliverable lists live in each track’s index.md.

TrackShapeDepth# deliverablesAnchored on
A PersonA PERSONThin10Bazzell pivots + L1/L3/L5
B Org / NetworkB ORGDeep8Clark SNA / target model + SAT network charting + UBO; house + live-research for HNA/CFA-style methods
C Place / AreaC PLACEMed-Deep8house + live-research (PMESII-PT-class area frames) + Clark target model
D Asset / FinancialD ASSETMed8Clark laundering / financial-target model + house + live-research (threat-finance frames)
E ProtectiveE PROTECTIVEDeep14TRAP-18 / TAM (civilian) + recce; house + live-research for terrain frames
F Cyber / InfrastructureF CYBERMed7Bazzell breach data + L2 + house + live-research (persona / digital footprint)
G Forecast / EstimativeG FORECASTDeep8Clark prediction + SAT scenarios; OSINT-029 lives here, anchors capstone

5. Capstone

CAP-01 — one investigation, end to end: requirements → collection → processing → analysis → a real deliverable, then peer-reviewed against the ICD 203 analytic standards (the L5-02 rubric).


6. Doctrinal conflicts to adjudicate (operator calls the house standard)

These are taught as features, not hidden — a single-source course can’t do this:

  1. ACH step count — Heuer 8 vs Pherson/SAT 9. → L4-03 teaches one canonical form + names the variant.
  2. Source gradingMcDowell 4×4 (house standard) vs Admiralty/NATO letter-number dual-rating (named variant). → L4-07.
  3. Process frame — traditional intelligence cycle vs Clark’s target-centric network model. → F2-02.

7. Build order

  1. L1-01 — the format pattern-setter (built; in review). Proved the card shape. Revision needed: re-anchor claims from dropped ATP 2-01 to McDowell / Clark (do not treat mil doctrine as live canon).
  2. F1 · The Analyst’s Mind — the cognitive layer, next, starting with F1-01 (inherits L1-01’s shape; Kahneman lead).
  3. Remainder of L1, then L4 (the crowded, high-value core shelves).
  4. F2, L5 (lighter shelves).
  5. L2 / L3 tooling — live-research pass, operator-led, date-stamped (Bazzell concepts stable; tool lists perishable).
  6. Applied tracks A–G, shallowest first (A) to deepest (E, G).
  7. Capstone.

Each step: draft → operator review → refine → next. No fan-out without explicit go.


This table fixes the canonical filename (<ID>-<slug>.md) for every planned card. The ID is the stable anchor; this registry fixes the slug, so a [[wikilink]] written today resolves automatically the moment the card is built — as long as the card is created with exactly the stem registered here. Only [[L1-01-requirements-chain]] exists today; every other entry below is an intentional unresolved (“planned”) link target — that is how the graph is pre-wired. Add a row here before linking any card not yet listed, and never rename a stem casually (it breaks every inbound link).

Link form: full filename stem, ID as the piped display label — [[L4-03-analysis-of-competing-hypotheses|L4-03]]. Inside a Markdown table cell the pipe must be escaped: [[…\|L4-03]]. Shelf/track references link to the folder index, path-qualified to stay unambiguous: [[L4-analysis/index|L4]], [[A-person/index|A]]. (Cells below display the full stem so the registry doubles as a human-readable filename list.)

Foundations (F1–F2)

Core process (L1–L5)

Applied (A–G)

TrackCards — canonical filenames
A PersonA-01-subject-dossier-workflow · A-02-locate-skip-trace · A-03-threat-approach-profiling · A-04-vetting-screening · A-05-continuous-monitoring
B Org / NetworkB-01-corporate-identity-structure · B-02-due-diligence-tiers · B-03-beneficial-ownership-ubo · B-04-third-party-vendor-integrity · B-05-reputational-dd-adverse-media · B-06-supply-chain-risk · B-07-continuous-counterparty-monitoring
C Place / AreaC-01-country-study-pmesii-pt · C-02-leadership-power-structure · C-03-thematic-deep-dive · C-04-country-entry-risk · C-05-market-entry-risk · C-06-geopolitical-briefing-monitoring
D Asset / FinancialD-01-asset-tracing-discovery · D-02-source-of-wealth-funds · D-03-hidden-assets-nominees · D-04-crypto-tracing · D-05-net-worth-profile · D-06-judgment-recovery · D-07-continuous-asset-monitoring
E ProtectiveE-01-protective-intel-fundamentals · E-02-threat-assessment-management · E-03-kidnap-ransom-risk · E-04-residential-vulnerability · E-05-event-threat-monitoring · E-06-recce-route-analysis · E-07-hostile-surveillance-detection · E-08-pre-travel-threat · E-09-protective-intel-products · E-10-after-action
F Cyber / InfraF-01-digital-footprint-exposure · F-02-doxxing-attack-surface · F-03-family-household-exposure · F-04-dark-web-investigation · F-05-executive-digital-protection · F-06-continuous-darkweb-monitoring
G Forecast / EstimativeG-01-intelligence-estimate · G-02-strategic-forecast · G-03-scenario-analysis · G-04-horizon-scanning · G-05-indications-warning · G-06-probabilistic-forecasting · G-07-situational-crisis-monitoring

Capstone

Card — canonical filename
CAPCAP-01-end-to-end-investigation

Shelf/track index notes (link targets for shelf-level references): [[F1-analyst-mind/index]], [[F2-orientation/index]], [[L1-requirements/index]], [[L2-collection/index]], [[L3-processing/index]], [[L4-analysis/index]], [[L5-production/index]], [[A-person/index]], [[B-org-network/index]], [[C-place-area/index]], [[D-asset-financial/index]], [[E-protective/index]], [[F-cyber-infrastructure/index]], [[G-forecast-estimative/index]], [[30-capstone/index]].


9. Tag registry & style gates

The tags: frontmatter is the cross-cutting inverse-index (Dataview’s “every card that touches calibration”). Draw tags only from this controlled list — free-text tags fragment and the index silently rots. Propose a new tag here before using it. Kebab-case, theme-level (not per-card).

  • Cognition & method: calibration · cognitive-bias · hypothesis-testing · red-teaming · deception · forecasting
  • Process: requirements · collection-planning · indicators · managed-attribution · opsec · entity-resolution · network-analysis · geolocation · source-evaluation · estimative-language · analytic-writing · provenance-sourcing
  • Domain / ethics: ethics-authorities · protective-intel · financial-intel · cyber-exposure

Banned-hype list (verifier grep — flag for review, not auto-fail)

Cut from card prose: powerful · fascinating · incredible · superhuman · magic / magical · transformative · revolutionary · game-changing · seamless · world-class · cutting-edge · unprecedented · paradigm-shift · robust (as filler) · leverage (as a hype verb). Legitimate uses exist (a cited quote, “statistical power”), so the grep flags for the operator/verifier to clear — it does not auto-reject.