Friendly Reliance Probe¶
Monitoring method — instantiates Deception Blowback Containment
Samples the organization's own decisions, reports, and metrics for signs that friendly actors have started treating the planted signal as genuine evidence.
Containment can look perfect on paper and still fail the moment a planted signal loops back through the originator's own systems and gets read as independent truth. The Friendly Reliance Probe is the running check that watches for exactly that. It does not watch the adversary and it does not watch the channel in the abstract; it samples the deceiver's own decision artifacts — incident tickets, planning documents, dashboards, model outputs, briefings — for the fingerprint of the planted signal reappearing as if it were genuine evidence. Where the Audience-Channel Matrix predicts return paths and the Re-Entry Red-Team Review imagines them before release, the probe is empirical and continuous: it catches reliance as it actually starts to happen.
Example¶
A security team runs authorized phishing simulations against its own staff — a benign, consented deception. The decoy emails and the "you clicked" events are the planted signals. Weeks in, the probe sweeps the SOC's incident queue and the monthly risk dashboard and finds two things: automated tooling has logged several simulated clicks as real credential-compromise incidents, and the dashboard's "accounts at risk" figure now folds in simulated victims. The organization is about to spend real incident-response hours and brief executives on a threat that is its own drill. The probe flags it — friendly systems are relying on the simulation as genuine evidence — and the incidents are reclassified and the metric corrected before the executive briefing goes out. The tell it caught is the planted signal returning as apparent independent corroboration.[n1]
How it works¶
Its distinctive move is sampling plus fingerprint-matching against the truth, not prediction. It defines a small set of decision artifacts to watch, searches them for the signature of the specific planted signal, and scores whether friendly actors are treating it as true. It is a sensor, not a fixer: a hit raises an alarm and escalates, but the correcting is done by other mechanisms. That narrowness is deliberate — it is the one component that empirically verifies immunity is holding rather than assuming it.
Tuning parameters¶
- Sampling surface — which artifacts are watched (tickets, dashboards, briefings, model outputs). A wider surface catches more re-entry but consumes more attention.
- Cadence — continuous versus periodic sweeps. Faster catches contamination before it hardens into a decision, at higher cost.
- Fingerprint specificity — how tightly the probe keys on the exact planted signal. Tight matching means fewer false alarms but misses summarized or mutated copies.
- Reliance threshold — how much friendly use counts as "reliance" worth escalating, versus incidental mention.
- Escalation coupling — whether a hit auto-freezes the affected decision or merely alerts. Auto-freeze is safer and more disruptive.
When it helps, and when it misleads¶
Its strength is turning "believing your own cover" from an invisible drift into a detectable, catchable event — it is the only empirical confirmation that friendly-decision immunity is actually holding. Its honest limits: it sees only where it samples, so contamination outside its surface is invisible; a copy that has been paraphrased or re-typed until it lost the fingerprint slips past; and it detects but does not correct, so a probe with no correction path behind it merely accumulates alarms. The classic misuse is scope creep — quietly widening the sampling into general surveillance of staff under the "reliance" banner. The discipline is to keep the surface scoped to decision artifacts and to wire every hit to a real correction path.
How it implements the components¶
re_entry_monitor— it is the runtime monitor: the mechanism that samples internal decision artifacts for the planted signal's return.friendly_decision_immunity_guard— it supplies the guard's detection facet, empirically confirming that friendly decisions have not begun relying on the signal.
It does not hold the ground truth it checks against — that reference is the Truth Anchor Memo, which supplies the guard's mandate facet. It does not trace return paths before release — that design-time review is the Re-Entry Red-Team Review. And it does not correct what it finds — bounded correction is the Bounded Correction Protocol and record isolation the Contaminated Record Quarantine.
Related¶
- Instantiates: Deception Blowback Containment — the probe is the runtime detector that tells the containment its immunity is failing.
- Consumes: Truth Anchor Memo supplies the ground-truth reference the probe samples against.
- Sibling mechanisms: Truth Anchor Memo · Re-Entry Red-Team Review · Audience-Channel Matrix · Deception Blowback Register · Bounded Correction Protocol · Contaminated Record Quarantine · Compartmented Briefing · Synthetic or Exercise Marker · Training-Data Exclusion List · Sunset and Debrief Trigger · After-Action Truth Reconciliation
Editorial Notes¶
Form Classification¶
Form family: Monitoring, Sensing & Alerting
Rationale: Friendly Reliance Probe operates as an ongoing sensing arrangement that repeatedly observes actual state and surfaces changes or alerts because it samples the organization's own decisions, reports, and metrics for signs that friendly actors have started treating the planted signal as genuine evidence.
Independent corroboration: The frozen evidence defines Friendly Reliance Probe as 'Samples the organization's own decisions, reports, and metrics for signs that friendly actors have started treating the planted signal as genuine evidence', so its operative form is Monitoring, Sensing & Alerting.
Review outcome: Independent reviewer agreement; high confidence.
Origin Attribution¶
Primary origin: Security Studies & Intelligence Analysis
Origin pattern: Single lineage
Present-day reach: Specialized
Rationale: It operationalizes intelligence analysis's longstanding concern with circular reporting and source laundering.
Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.
Review outcome: Independent reviewer agreement; high confidence.
Notes¶
[n1] Circular reporting is a failure of intelligence analysis in which one piece of information is laundered into apparent corroboration: it is reported, picked up by a second source, and the two are then counted as independent confirmation of each other. A planted signal that re-enters friendly channels is the self-inflicted version of this pattern — precisely what a reliance probe is built to catch. ↩