F1-01 · Two minds: System 1 / System 2, WYSIATI
Learning objectives
- Terminal: after this module the analyst can identify which system produced a first-hour judgment, state what evidence that judgment actually rests on, and force a deliberate System 2 check before a rush deliverable leaves the desk.
- Enabling:
- State the System 1 / System 2 division of labor in plain language and apply it to triage and pivoting.
- Detect cognitive ease and the lazy controller in live casework (busy, depleted, time-pressured).
- Spot WYSIATI and substitution in a draft judgment, and name what is still missing before confidence rises.
Concept
Calibrate: A bat and a ball together cost $1.10. The bat costs one dollar more than the ball. How much does the ball cost? Write your answer down before reading on. Hold it.
1. Two characters, one desk
Kahneman’s working model is a two-character model of the mind (Kahneman Ch. 1):
- System 1 operates automatically and quickly, with little or no effort and no sense of voluntary control. It generates impressions, feelings, intuitions, and impulses.
- System 2 allocates attention to effortful mental work: complex computation, deliberate search, rule-following, comparison, self-control. It feels like the “I” that chooses and concentrates.
You identify with System 2. Most of what you think and do still starts in System 1. When things run smoothly, System 2 endorses System 1’s suggestions with little change. System 2 is mobilized when System 1 has no answer, when surprise breaks the model of the world, or when an error is about to be made. System 2 also has the last word when it bothers to take it.
Division of labor is efficient most of the time. System 1 is usually good at familiar situations and short-term prediction. It also has systematic biases, little grasp of statistics, and cannot be turned off. Continuous full vigilance by System 2 is impractical. The workable compromise: learn the situations where intuitive error is likely, and spend scarce effort when stakes are high.
A useful fiction. “System 1” and “System 2” are nicknames for automatic and effortful processes rather than organs. They make the story teachable. Use them as labels for operations you can observe in yourself.
Desk frame (hold this case). Real company, real outcome; run the clock as it stood on the morning of 22 July 2026. A new subject hits the queue at 09:00: Corporativo de Seguridad Privada Alfa y Gama S.A. de C.V., a private security firm operating out of Jalisco and Michoacán, Mexico; owner Miguel Ángel Ayala Botello. Your firm meets them at 11:00 to decide whether they will provide guard services in Mexico for a client. The tasking: find integrity risk or any negative findings before the meeting. The first tabs are reassuring. The DGSP registry shows a current authorization (DGSP/108-19/3850, seven years on the books, valid into 2026), the directory profile at https://www.mercadoseguridad.mx/empresa/corporativo-de-seguridad-privada-alfa-y-gama-sa-de-cv reads like any legitimate mid-size firm, and the company’s Facebook presence (https://www.facebook.com/CdsAyG) carries uniformed guards and polished promotional video. Open both and look before reading on; the ease is the exhibit. Cognitive ease is high from the first minute. Your first three moves and the judgment you form by 09:20 are the OSINT version of what System 1 and a lazy System 2 do under a clock. The case resolves in section 7; do not search ahead.
Q: On that 09:00 subject, which of your first three moves would be pure System 1, and which, if any, would already be a deliberate System 2 task set? Sort them before reading on.
Nudge: “open the Facebook page and scroll until I get a feel for them” produces an impression all by itself; that is System 1 driving. “Pull the DGSP license record first and confirm the registered legal name before touching social media” is a rule you chose and imposed on yourself; that is a System 2 task set. Sort your own three moves the same way.
2. Attention, effort, and the lazy controller
System 2 is limited capacity. Effort is a cost. A general law of least effort applies: if several ways reach the same goal, people gravitate to the least demanding (Kahneman Ch. 2).
- Intense focus can make you blind to the obvious (the gorilla while counting passes). You can also be blind to that blindness.
- Time pressure and working-memory load force a sprint pace. Mental multiplication and multi-step juggling are near the limit for most people. Routine browsing is a stroll.
- System 2 is often lazy: it monitors System 1 poorly (Kahneman Ch. 3).
Return to your Calibrate answer. The number that came to mind first was almost certainly 10 cents. That is System 1: fast, fluent, wrong. The correct answer is 5 cents (if the ball is $0.05, the bat is $1.05, total $1.10). Checking costs a few seconds of arithmetic. If you wrote 10 cents and moved on, your System 2 endorsed an intuition it could have rejected. If you wrote 5 cents, you still felt the pull of 10 cents first; the difference is whether System 2 checked. That is the lazy-controller demonstration on your own page. The same pattern runs on the 09:00 desk: an intuitive story arrives fast; checking is cheap; many sessions never check.
- When System 2 is busy (load) or depleted (prior self-control, fatigue, hunger), System 1 has freer rein. Superficial judgments rise. Default answers win under strain.
For the OSINT desk: the first hour of a new subject is high associative load under a clock. That is the condition in which the controller goes lazy and endorses the first coherent story.
3. The associative machine and cognitive ease
System 1 is an associative machine (Kahneman Ch. 4). Ideas activate related ideas in a spreading cascade. Coherence forms fast. Most of that work is silent.
- Priming changes what is easy to retrieve and, sometimes, how you act, without conscious access to the cause.
- Cognitive ease (Kahneman Ch. 5) is a dial from easy to strained. Ease comes from repetition, clear display, priming, good mood. Ease makes things feel familiar, true, good, and effortless. Strain mobilizes System 2 and can reduce intuitive errors (even a hard-to-read font improved checking on reflection problems).
- Familiarity is easy to confuse with truth. A name you saw once can feel “known.” A fluent story can feel solid when the evidence is thin.
On triage: the first search hits, the first photo, the first adverse headline all prime what you notice next. Ease is not evidence.
4. Jumping to conclusions: WYSIATI
System 1 builds the best story from activated ideas. Information not retrieved might as well not exist. The measure of success is coherence of the story; quality and quantity of data barely move it (Kahneman Ch. 7).
- Ambiguity is resolved silently. Doubt and incompatible interpretations require System 2.
- System 1 is biased to believe and confirm. Unbelieving is System 2 work, and System 2 is often busy or lazy.
- Halo effect: early good (or bad) impressions color later reading of ambiguous items.
- WYSIATI (what you see is all there is): confidence tracks the story you can tell about what you see, even if you see little. Missing evidence never registers as a hole. One-sided material can raise confidence above balanced material because the story is cleaner.
Q: By 09:20 on Alfa y Gama you have: a current government license, a clean directory profile, and a Facebook page full of professional video and no adverse posts. Your gut says “legitimate operator, no findings.” What does WYSIATI predict about your confidence, and what single missing class of evidence would most damage the story if it appeared?
Nudge: WYSIATI ties confidence to the coherence of the story, not to how much of the record you have seen, and three clean tabs make a very coherent story. For the missing class, ask what a company’s own shop window can never show you: who actually owns it, and what governments say about the owners.
5. Substitution (intro only)
When a hard target question has no quick answer, System 1 often answers a related easier question and maps that answer onto the hard one (substitution; Kahneman Ch. 9). Deep treatment of specific heuristics (anchoring, availability, representativeness) is F1-02.
| Target question (hard) | Heuristic stand-in (easy) |
|---|---|
| How serious is this subject’s integrity risk for our client? | How bad does the first adverse hit make me feel? |
| Are these two accounts the same person? | Do the photos and names “feel” like a match? |
| What should we collect next under the PIR? | What is easiest to open in the next five minutes? |
System 2 can reject the stand-in. Lazy System 2 often does not notice the swap.
6. Heuer’s bridge: the analyst’s machinery
Heuer states the same problem in intelligence language (Heuer Ch. 1-2):
- Analysts have little conscious access to most mental processing. What appears in awareness is the result of thinking; the process itself stays hidden.
- Perception is active construction. People tend to perceive what they expect to perceive. Mind-sets form quickly and resist change. New information is assimilated to existing images.
- Intelligence work runs on ambiguous data, incremental arrival, and pressure for early judgment: the conditions that most degrade accurate perception.
- The response “collect more” is often wrong. Bounded mental capacity means a better model and better process often beat more volume.
F1-01 gives the Kahneman labels for the machinery. F1-05 will make the mental model itself the object of inspection. L4 will turn that into ACH and diagnosticity.
7. Default settings on an OSINT desk
Still on the 09:00 subject: during first-hour triage and pivoting, expect the following defaults unless you intervene.
| Default (System 1 + lazy S2) | What it looks like at the desk | Deliberate interrupt |
|---|---|---|
| Story from first hits | Narrative locks after 2-3 tabs | Write the question before the search |
| Ease = truth | Current license, uniforms, polished page feel clean | Ask what would falsify, not what fits |
| WYSIATI confidence | High certainty on thin open source | List missing source classes before confidence language |
| Substitution | ”Looks sketchy” answers “integrity risk” | Restate the client’s decision question |
| Halo from first impression | One red flag taints every later fact | Score items independently, then integrate |
| Busy / depleted controller | Rush brief copies the first story | 60-second check: coherence vs completeness |
Q: Back to Alfa y Gama: it is now 09:30, you burned the first half hour on the license record and the Facebook videos, and the 11:00 meeting leaves 90 minutes for a one-page integrity note. The defaults in the table above fire on their own; the interrupt column is what you choose to run against them. Which check do you run first, and which default does it target? Decide before reading on.
Nudge: match the interrupt to the default doing the most damage right now. Half an hour of license pages and promotional video has been feeding “ease = truth” hard, so “ask what would falsify” is a defensible first pick, but so is restating the client’s actual decision question. Make your own call and say in one sentence why.
Case close-out (what the record now shows). On 23 July 2026, one day after the clock you just ran, OFAC designated Corporativo de Seguridad Privada Alfa y Gama in the largest US Treasury action ever taken against the Cartel de Jalisco Nueva Generación (E.O. 14059; https://home.treasury.gov/news/press-releases/sb0573). The designated owner, Miguel Ángel Ayala Botello, is a cousin of senior CJNG figure Gerardo Botello Rozalez, “El Cachas.” While El Cachas oversaw CJNG operations in Michoacán, Ayala Botello directed the Public Safety Directorate of Tepalcatepec and brought two CJNG-affiliated nephews of El Cachas onto the municipal police under him. The security firm held a state-level license to carry firearms throughout. Search the company today and the designation is the first thing you see. On 22 July it was not: the license was current, the videos were professional, and the surface said “no findings.” The defaults in the table would have shipped exactly that sentence to a client about to place its people under CJNG-linked armed guards. The only thing standing between your firm and that outcome was whether anyone treated ease as ease, wrote the absence list (ownership, principals, sanctions and watchlist screening, adverse media past page one), and spent the 90 minutes filling it.
Procedure
A first-hour System 2 interrupt for new-subject triage (use under time pressure; not a full collection plan).
- Freeze the question. Write the decision the client must make and one priority question that would change that decision. Do not open a browser yet.
- State the System 1 story. In one sentence: what does your gut already believe about the subject? Label it as impression.
- List activated evidence only. Bullet what you have actually seen (URLs, docs, timestamps). Only what is on the list counts as evidence.
- List absences (anti-WYSIATI). Three classes of evidence you do not have that would matter (e.g. corporate filings, adverse media beyond first page, identity resolution on the name collision).
- Check for substitution. Rewrite: “I answered ___ when the question was ___.” If the blanks differ, stop and re-aim.
- Task set for the next 30 minutes. Two pivots that address the priority question; one that could falsify the impression. Ignore interesting but off-question rabbit holes.
- Confidence language. State confidence as a function of story coherence and coverage of the absence list. Thin coverage caps confidence regardless of how neat the narrative is.
- Exit check (60 seconds). Read the draft as if you had only the absence list: what would a hostile reviewer say is missing?
Pre-mortem. Imagine the 11:00 meeting goes badly: the client later finds a decisive public record you never opened, and your note’s confidence was high. Which step above did you skip, and at which minute of the morning did the story lock?
Worked example
Real case from operator casework (public records linked). Findings as of the investigation date. Beneficial-owner detail is stated without naming the individual.
Tasking (compressed): Counterparty diligence on Apex Group International before engagement. Clock is short.
09:00: System 1 (automatic). apexgroupintl.com is polished and corporate. Press coverage announces a landmark $350 million agreement with Westwin Elements (expansionsolutionsmagazine.com/westwin-elements-signs-landmark-350-million-agreement). Cognitive ease is at maximum. The three-tab story: major, credible counterparty.
09:10: Interrupt (procedure). Decision question: Is this a reliable commercial counterparty on open-source evidence? Activated evidence: professional site; $350M press. Absences: ownership chain; trade records for the trading entity; litigation / enforcement.
09:25: One cheap System 2 check. Ownership resolves to a UAE free-zone entity, Golden Age FZE. Volza trade-data profile (volza.com/company-profile/golden-age-fze-2773574/import): no commodity trade history at all, ever. An alleged $350M commodities counterparty whose owning entity has never traded a commodity. Story no longer coherent.
Coda. The full investigation confirmed the incoherence: the FZE’s beneficial owner was deeply in debt, facing multiple criminal actions, with claimed assets seized. WYSIATI at hour one would have shipped “credible”; the absence list bought the contradiction.
Practical exercise: the competency gate
Setup: Your firm is vetting a potential new security contractor before offering a contract. The contractor is you. Work the case from the screener’s seat, not the subject’s: the packet is your own name, one of your own social handles, and your claimed work history. Decision due in 2 hours: engage, hold, or decline, on open source alone. Live public data only; no simulated packets. Go through your own social media and digital footprint the way you would a stranger’s.
- Produce a one-page contractor integrity screen of yourself using the Procedure. Include: decision question (does this contractor present an integrity risk to the firm or its clients?); impression sentence written before any search (you hold the strongest possible prior about this subject; that is the point); activated evidence list of what you actually find; absence list; two pivots you actually run; judgment; confidence bounded by absences.
- Self-critique. Where did knowing-yourself expectancy shape what you searched and what you dismissed? Which finding would a stranger-analyst weigh differently? What did you not search because you “already know”? Which sentence is System 1 wearing System 2’s clothes?
- Revise. Change at least one judgment or confidence statement. Add one collection task for the worst absence. List one concrete piece of your own exposed data that surprised you.
Self-check: competency means you hold a real artifact: your own exposure list and one surprise, plus a named point where expectancy nearly steered the screen.
Common errors
| Tell (what you’d observe) | Diagnostic question | Fix |
|---|---|---|
| Note reads like a biography of the first three search hits | ”What decision does this sentence change?” | Rewrite from the decision question; cut color that does not answer it |
| High confidence after a short, fluent session | ”What evidence classes are still empty?” | Cap confidence until the absence list has at least one hit or an explicit reason the class is N/A |
| ”Feels off” / “seems solid” as the analytic conclusion | ”What easier question did I actually answer?” | Write down the substitute; re-ask the target question in writing |
| First adverse hit dominates the whole page | ”If I had seen the good hits first, would the tone flip?” | Score items independently, then integrate (tame the halo) |
| Busy afternoon, copy-paste from the company About page | ”Was System 2 depleted or loaded when I endorsed this?” | Run the interrupt before deep scrolling; do not draft while multitasking |
Figures
flowchart TB subgraph S1["System 1 (automatic)"] A[Impressions / intuitions / impulses] B[Associative coherence] C[WYSIATI story from activated ideas] end subgraph S2["System 2 (effortful)"] D[Attention allocation] E[Check / doubt / unbelieve] F[Rules, comparisons, task sets] end S1 -->|suggestions endorsed if unchallenged| S2 S2 -->|programs attention; can overrule| S1 S2 -->|lazy or busy: little monitoring| S1
Division of labor between System 1 and System 2 (after Kahneman Part 1). System 1 generates; System 2 can endorse, modify, or overrule. When System 2 is lazy or loaded, endorsement is the default.
Interactive training aids (hub page): four click-through aids, all on this card’s real case. Work them in order, after reading, before the practical exercise.
Doctrinal notes / variants
- Stanovich’s labels: Type 1 / Type 2 processes are the same distinction under another name. This course uses Kahneman’s System 1 / System 2 vocabulary for consistency across F1.
- Heuer does not use S1/S2. He speaks of mental machinery, perception, and mind-sets. Treat Heuer as the intelligence-application bridge rather than a competing dual-process scheme.
- Substitution deep-dive lives in F1-02 (anchoring, availability, representativeness, full heuristic map).
Adversarial questions
- Point to the sentence in your triage note that is pure System 1 impression. If you cannot find one, you are defending rather than introspecting.
- What evidence would you need to lower confidence in your current story? If that list is empty, WYSIATI is running.
- Which pivot did you skip because it was harder than another tab that felt productive?
- If the first three hits had been adverse instead of clean (or the reverse), would your process have changed, or only your conclusion?
- Under a 30-minute clock, which step of the Procedure do you drop first, and what failure does that buy?
- How would you brief the client that your early confidence was a coherence effect, not a coverage effect?
Links
- Prerequisite cards: none (spine entry)
- Next in shelf: F1-02
- Composed by applied tracks: all A-G (cognitive baseline); heavy reuse in L4 judgment cards
- Deliverable(s): first-hour triage and integrity-style snapshots appear across person and org tracks (e.g. subject dossier / screening workflows in the operational vault)
- Collection map(s): any shape’s early collection branches assume this interrupt before tool-driven wandering
Sources
- kahneman: Ch. 1 (two systems); Ch. 2 (attention and effort); Ch. 3 (lazy controller); Ch. 4 (associative machine); Ch. 5 (cognitive ease); Ch. 7 (jumping to conclusions, WYSIATI); Ch. 9 (substitution intro)
- heuer-psych: Ch. 1 (thinking about thinking; bounded machinery); Ch. 2 (perception constructs; expectancy; mind-sets)
Next: F1-02