Cluster 10 · Cognitive Security & Influence Defense

Eight tools. One boundary. Enforced in code.

The working toolset for the sister discipline to cybersecurity — a warning desk, an attribution engine, a provenance desk, a coalition hub, a public scam watch, a red-team range, an incident log, and the Resilience Corps. All mount one shared BB2G CORE; all stay inside the same hard line.

1 · DETECT
QUORUM · ASIG2
Coordinated inauthenticity in public data
2 · ATTRIBUTE
AZIMUTH
A bearing on the actor — to the evidence, no further
3 · WARN
BEACON WATCH · REDOUBT
Narrative I&W; threats to defenders
4 · INOCULATE
LAMPLIGHTERS
Train the public before the real thing
5 · RECOVER
TOCSIN · AHOY
Off-ramps & repair
The toolset

Eight tools, each on its correct standard

Desk tools rate evidence on the two-axis Admiralty scale; public tools use the three confidence states; the coalition hub moves items under TLP. Never mixed on one surface. Every tool ships a boundary.test.js that must stay green.

BEACON WATCHWarn
Admiralty + three-state
The daily driver: narrative indications & warning, amplification anomalies, and a public "manipulation weather" digest.
Desk & digest are separate routes; the digest never renders Admiralty.
Open →
AZIMUTHAttribute
Admiralty
Turn a behavior into a rated, DISARM-mapped attribution — assessed only to the level the evidence supports.
Confidence can't exceed the evidence; ≥2 hypotheses stay open.
Open →
TOUCHSTONEVerify
Admiralty
Media provenance & authentication — synthetic forensics + C2PA. The goal is verified human origin, not "caught the fake."
≥2 signals to assert; a 4-condition gate before anything publishes.
Open →
REDOUBTWarn / Infra
Admiralty
A secure incident log for threats against defenders — chain-of-custody evidence, referral routing, duty-to-warn.
Defenders only; no citizen dossier; evidence append-only; no auto-link.
Open →
WATCHFIRECoalition
TLP + Admiralty
An ISAC-style hub where member orgs pool indicators of coordinated inauthentic behavior — never data on private citizens.
TLP governs who sees what; only CLEAR goes public; indicators aren't people.
Open →
SHOALPublic
three-state
A public scam & fraud watch: what a circulating scam is, who it targets, and the one tell that gives it away.
Three-state only; every hazard carries "the one tell"; no fake contacts.
Open →
PROVING GROUNDInstitutional
exercise
Red-team tabletop exercises against a consenting org — every inject maps to a DISARM technique.
No outbound content path exists; live requires signed consent.
Open →
LAMPLIGHTERSInoculate → Reach
program
The Resilience Corps platform: certify local instructors, hand them a teaching kit, and route aggregate field reports back to the desk.
No credential without the boundary oath; field reports aggregate-only.
Open →
RUTTERDoctrine
reference
The field manual the eight tools cite — threat taxonomy, DISARM + ABCDE, the five-front doctrine, the boundary.
A document, not software.
Read RUTTER →
The credibility charter

The boundary is the whole difference

Cognitive security, not cognitive warfare.

Every tool here enforces the same line — not in a README, but as tests that must stay green. It's a competitive advantage and a legal shield, and it's why an 80-year nonprofit's version of this work is defensible. Any capability that can't run inside it isn't built.

Defensive only
We counter operations; we never run them. No tool has an outbound publish-to-platform path.
Public-source only
Public data + consenting-partner submissions. No general-population crawl; no private-citizen dossier.
Nonpartisan
Taxonomy names techniques (DISARM), never parties or sides. Party names are rejected as actor labels.
Transparent
Every rated claim shows its rating and its basis; nothing publishes without provenance.
Consent-based
Subjects and partners require a consent flag; training and alerts are opt-in.
— per RUTTER §6 · owned & operated by BB2G, licensed to America’s Future · names pending McAuliffe + Olson