Course Architecture — OSINT Analyst Program
The master plan. Shelves hold module cards; cards are built one at a time (see CLAUDE.md → Pace).
Sources are registered in sources; the figures cited here map to that canon.
Canon (six books): kahneman · bazzell · clark · heuer-psych · sat (Heuer & Pherson) · mcdowell.
Military doctrine stubs are dropped (2026-07-29). ICD 203 / 206 / 208 remain as public ODNI standards
(cited where product standards apply — not mil doctrine).
1. The model: calibrate the mind, teach the process once, then compose
The hard problem this course solves: tradecraft cross-sections across deliverables. ACH, source grading, and collection planning appear in a subject dossier, a corporate DD, and a national estimate. Teaching per-deliverable would re-teach ACH 60 times; teaching per-technique would never show how it assembles into a product. And upstream of all of it, a great analyst is made by cognitive habits — knowing how judgment works, where intuition misleads, holding uncertainty honestly — that no template conveys. So:
- Foundations (F1–F2) — the pre-process layer, taught first: F1 The Analyst’s Mind (Kahneman-led dual-process, biases, calibration, judgment under uncertainty, mental models) then F2 Orientation (what intelligence is).
- Core process (L1–L5) — the cross-cutting tradecraft primitives of the intelligence process (Requirements → Production), taught once.
- Applied tracks (A–G) — one per target shape, composing core cards against real deliverables.
They reference core cards (
applies L4-03); they never re-teach. - Capstone — one investigation end-to-end, producing a real deliverable, graded against ICD 203.
Shelves = 2 foundations + 5 core + 7 applied + 1 capstone = 15 shelves, not a fixed module count.
Module count is emergent (~55–75), tiered by complexity: a POI dossier is Thin; an intelligence estimate is Deep.
2. Source-ownership map (from the source scout)
Trust each source where it leads, not everywhere it’s “relevant.”
| Module | Owns it (lead) | Reinforced by | Fusion load |
|---|---|---|---|
| F1 The Analyst’s Mind | Kahneman (System 1/2, heuristics & biases, calibration, judgment under uncertainty) | Heuer-Psych (analyst-specific mental models / mindsets — bridge card F1-05); SAT (18 traps, reinforcing) | medium |
| F2 Orientation | McDowell + Clark (what intel is; cycle vs target-centric) | Heuer, Bazzell (analyst OPSEC), house (ethics) | light |
| L1 Requirements | McDowell (ICP / TOR / 12-step strategic process) + SAT (indicators gen/validate/evaluate) + Clark (gap→collection) | — | medium (3) |
| L2 Collection | Bazzell (sock puppets, VM OPSEC, breach/leak data) | — | clean (1) ⚠ perishable |
| L3 Processing | Bazzell (6 pivot chains, EXIF) + Clark (SNA, target model) + SAT (network charting) | — | medium (3) |
| L4 Analysis | Heuer-Psych (ACH origin, cognition) + SAT (six-families taxonomy, KAC, deception) + Clark (evidence-eval, estimative) + McDowell (4×4 grading) | — | crowded (4) — crown jewels |
| L5 Production | McDowell (assessment layout) + Bazzell (case report) + Clark (briefing) | ICD 203 / 206 / 208 (public ODNI standards — product rigor, not mil doctrine) | medium |
3. Shelves — planned cards
Status legend:
· planned·· drafting·· review·· done. IDs are stable; ordering may shift.
F1 · The Analyst’s Mind — taught first (cognitive calibration; Kahneman-led)
| ID | Card | Lead source(s) | Status |
|---|---|---|---|
| F1-01 | Two minds — System 1 / System 2, WYSIATI: the analyst’s default settings ⭐ pattern-setter | Kahneman | done |
| F1-02 | Cognitive biases & intuitive traps — anchoring, availability, representativeness, substitution | Kahneman; Heuer-Psych reinforcing | review |
| F1-03 | Overconfidence & calibration — illusion of validity, planning fallacy, inside vs outside view | Kahneman | planned |
| F1-04 | Judgment under uncertainty — small numbers, regression to the mean, framing | Kahneman | planned |
| F1-05 | Mental models & mindsets — why more information does not equal better judgment (bridge to L4) | Heuer-Psych (lead); Kahneman reinforcing | planned |
F2 · Orientation — what intelligence is
| ID | Card | Lead source(s) | Status |
|---|---|---|---|
| F2-01 | What intelligence is — intel vs information; the analyst’s role | McDowell, Heuer | planned |
| F2-02 | The intelligence cycle vs the target-centric model | Clark, McDowell | planned |
| F2-03 | Ethics, authorities, PII & legal limits | house + civ | planned |
| F2-04 | OPSEC for the analyst — intro (hands off to L2) | Bazzell | planned |
L1 · Requirements & Planning
| ID | Card | Lead source(s) | Status |
|---|---|---|---|
| L1-01 | PIR → indicator → SIR (each pinned to NAI + LTIOV) ⭐ format pattern-setter · built on ATP 2-01 (dropped) — re-anchor to mcdowell/clark in revision pass | McDowell, Clark (target leads post-revision) | review |
| L1-02 | Writing good PIRs & the “so what” | McDowell (TOR) | planned |
| L1-03 | The collection plan / ICP | McDowell | planned |
| L1-04 | Terms of Reference / project tasking | McDowell | planned |
| L1-05 | Gap analysis & collection strategy (cue / mix / redundancy) | Clark | planned |
| L1-06 | Indicators: generation, validation, evaluation | SAT, McDowell (cycle) | planned |
L2 · Collection & Managed Attribution ⚠ LIVE / quarantined
Concepts are stable; specific tooling is perishable and operator-owned. Each card carries a
last-verified:date; tool lists live in a dated appendix, not the card body.
| ID | Card | Lead source(s) | Status |
|---|---|---|---|
| L2-01 | Managed attribution — concept & the attribution stack | Bazzell + live | planned ⚠ |
| L2-02 | Virtual machines & host isolation | Bazzell + live | planned ⚠ |
| L2-03 | Sock puppets / covert accounts | Bazzell + live | planned ⚠ |
| L2-04 | Source types — surface / deep / dark | Bazzell + live | planned ⚠ |
| L2-05 | Breach & leak data exploitation | Bazzell + live | planned ⚠ |
| L2-06 | Capture, preservation & chain of custody | Bazzell (stable) | planned |
| L2-99 | Current tooling register (dated appendix) | live + operator | planned ⚠ |
L3 · Processing & Exploitation
| ID | Card | Lead source(s) | Status |
|---|---|---|---|
| L3-01 | Entity resolution & disambiguation | Clark, Bazzell | planned |
| L3-02 | The selector pivot — 6 data-type chains | Bazzell | planned |
| L3-03 | Geolocation & EXIF / image exploitation | Bazzell | planned ⚠ |
| L3-04 | Link analysis fundamentals | Clark, Bazzell | planned |
| L3-05 | Social network analysis — centrality, brokers, bridges | Clark, SAT | planned |
| L3-06 | Network charting / meta-network construction | SAT, Clark | planned |
L4 · Analysis & Judgment ⭐ crown jewels
| ID | Card | Lead source(s) | Status |
|---|---|---|---|
| L4-01 | Inference: deduction, induction, abduction | Clark, Heuer | planned |
| L4-02 | Mental models, evidence & diagnosticity | Heuer | planned |
| L4-03 | Analysis of Competing Hypotheses (ACH) — reconciling Heuer-8 / SAT-9 | Heuer, SAT | planned |
| L4-04 | Key Assumptions Check | SAT | planned |
| L4-05 | Quality of Information Check | SAT, Heuer | planned |
| L4-06 | The SAT toolkit — six families & technique selection | SAT | planned |
| L4-07 | Source grading — McDowell 4×4 as house standard; Admiralty/NATO letter-number as a named variant | McDowell (house); Admiralty/NATO variant | planned |
| L4-08 | Confidence vs probability & estimative language | Heuer (dot-plot), ICD 203, Clark | planned |
| L4-09 | Bias mitigation, red teaming, premortem | SAT, Heuer | planned |
| L4-10 | Critical Factors Analysis (CFA) | Clark, SAT (house synthesis) | planned |
L5 · Production & Dissemination
| ID | Card | Lead source(s) | Status |
|---|---|---|---|
| L5-01 | BLUF & analytic writing | ICD 208 | planned |
| L5-02 | The analytic standards — ICD 203 | ICD 203 (public ODNI) | planned |
| L5-03 | Sourcing & citations — ICD 206 | ICD 206 (public ODNI) — full product rigor lives here as course content | planned |
| L5-04 | Report formats — assessment layout, case report, briefing | McDowell, Bazzell, Clark | planned |
| L5-05 | Tailoring to the customer; the analyst-consumer relationship | Clark, Heuer | planned |
| L5-06 | Visualization, classification & handling (TLP) | house + civ | planned |
4. Applied tracks — depth-tiered, mapped to deliverables
Each track composes core cards against its shape’s deliverables. Thin/Med/Deep = teaching depth, not
deliverable count. Full deliverable lists live in each track’s index.md.
| Track | Shape | Depth | # deliverables | Anchored on |
|---|---|---|---|---|
| A Person | A PERSON | Thin | 10 | Bazzell pivots + L1/L3/L5 |
| B Org / Network | B ORG | Deep | 8 | Clark SNA / target model + SAT network charting + UBO; house + live-research for HNA/CFA-style methods |
| C Place / Area | C PLACE | Med-Deep | 8 | house + live-research (PMESII-PT-class area frames) + Clark target model |
| D Asset / Financial | D ASSET | Med | 8 | Clark laundering / financial-target model + house + live-research (threat-finance frames) |
| E Protective | E PROTECTIVE | Deep | 14 | TRAP-18 / TAM (civilian) + recce; house + live-research for terrain frames |
| F Cyber / Infrastructure | F CYBER | Med | 7 | Bazzell breach data + L2 + house + live-research (persona / digital footprint) |
| G Forecast / Estimative | G FORECAST | Deep | 8 | Clark prediction + SAT scenarios; OSINT-029 lives here, anchors capstone |
5. Capstone
CAP-01 — one investigation, end to end: requirements → collection → processing → analysis → a real deliverable, then peer-reviewed against the ICD 203 analytic standards (the L5-02 rubric).
6. Doctrinal conflicts to adjudicate (operator calls the house standard)
These are taught as features, not hidden — a single-source course can’t do this:
- ACH step count — Heuer 8 vs Pherson/SAT 9. → L4-03 teaches one canonical form + names the variant.
- Source grading — McDowell 4×4 (house standard) vs Admiralty/NATO letter-number dual-rating (named variant). → L4-07.
- Process frame — traditional intelligence cycle vs Clark’s target-centric network model. → F2-02.
7. Build order
- ✅ L1-01 — the format pattern-setter (built; in review). Proved the card shape. Revision needed: re-anchor claims from dropped ATP 2-01 to McDowell / Clark (do not treat mil doctrine as live canon).
- F1 · The Analyst’s Mind — the cognitive layer, next, starting with F1-01 (inherits L1-01’s shape; Kahneman lead).
- Remainder of L1, then L4 (the crowded, high-value core shelves).
- F2, L5 (lighter shelves).
- L2 / L3 tooling — live-research pass, operator-led, date-stamped (Bazzell concepts stable; tool lists perishable).
- Applied tracks A–G, shallowest first (A) to deepest (E, G).
- Capstone.
Each step: draft → operator review → refine → next. No fan-out without explicit go.
8. Canonical filename registry — the stable link targets
This table fixes the canonical filename (<ID>-<slug>.md) for every planned card. The ID is the
stable anchor; this registry fixes the slug, so a [[wikilink]] written today resolves automatically
the moment the card is built — as long as the card is created with exactly the stem registered here.
Only [[L1-01-requirements-chain]] exists today; every other entry below is an intentional unresolved
(“planned”) link target — that is how the graph is pre-wired. Add a row here before linking any card
not yet listed, and never rename a stem casually (it breaks every inbound link).
Link form: full filename stem, ID as the piped display label —
[[L4-03-analysis-of-competing-hypotheses|L4-03]]. Inside a Markdown table cell the pipe must be escaped:[[…\|L4-03]]. Shelf/track references link to the folder index, path-qualified to stay unambiguous:[[L4-analysis/index|L4]],[[A-person/index|A]]. (Cells below display the full stem so the registry doubles as a human-readable filename list.)
Foundations (F1–F2)
| Shelf | Cards — canonical filenames |
|---|---|
| F1 The Analyst’s Mind | F1-01-two-minds · F1-02-cognitive-biases · F1-03-overconfidence-calibration · F1-04-judgment-under-uncertainty · F1-05-mental-models-mindset |
| F2 Orientation | F2-01-what-intelligence-is · F2-02-cycle-vs-target-centric · F2-03-ethics-and-authorities · F2-04-analyst-opsec-intro |
Core process (L1–L5)
Applied (A–G)
Capstone
| Card — canonical filename | |
|---|---|
| CAP | CAP-01-end-to-end-investigation |
Shelf/track index notes (link targets for shelf-level references):
[[F1-analyst-mind/index]],[[F2-orientation/index]],[[L1-requirements/index]],[[L2-collection/index]],[[L3-processing/index]],[[L4-analysis/index]],[[L5-production/index]],[[A-person/index]],[[B-org-network/index]],[[C-place-area/index]],[[D-asset-financial/index]],[[E-protective/index]],[[F-cyber-infrastructure/index]],[[G-forecast-estimative/index]],[[30-capstone/index]].
9. Tag registry & style gates
The tags: frontmatter is the cross-cutting inverse-index (Dataview’s “every card that touches
calibration”). Draw tags only from this controlled list — free-text tags fragment and the index silently
rots. Propose a new tag here before using it. Kebab-case, theme-level (not per-card).
- Cognition & method:
calibration·cognitive-bias·hypothesis-testing·red-teaming·deception·forecasting - Process:
requirements·collection-planning·indicators·managed-attribution·opsec·entity-resolution·network-analysis·geolocation·source-evaluation·estimative-language·analytic-writing·provenance-sourcing - Domain / ethics:
ethics-authorities·protective-intel·financial-intel·cyber-exposure
Banned-hype list (verifier grep — flag for review, not auto-fail)
Cut from card prose: powerful · fascinating · incredible · superhuman · magic / magical · transformative · revolutionary · game-changing · seamless · world-class · cutting-edge · unprecedented · paradigm-shift · robust (as filler) · leverage (as a hype verb). Legitimate uses exist (a cited quote, “statistical power”), so the grep flags for the operator/verifier to clear — it does not auto-reject.