Skip to content

Threat Claim Triage

Triage procedure — instantiates Moral Panic De-escalation

Rapidly sorts an alarming claim into facts, unknowns, plausible risks, and unsupported allegations, and routes each bucket to the owner who should act on it.

When fear is spreading, the first casualty is the distinction between what is being said and what is known. Threat Claim Triage is the fast intake step that stops a diffuse atmosphere of dread from being treated as a single actionable fact. It takes the alarming claim exactly as it is circulating, restates it as an inspectable proposition — who is said to be harmed, by whom, on what basis — and drops each part into a bucket: confirmed fact, open unknown, plausible-but-unverified risk, or unsupported allegation. Its defining move is sorting and routing under time pressure, not resolving: triage does not decide the punishment, verify the claim to a courtroom standard, or write the public statement. It produces a structured object and a routing slip so the right people work on the right parts, and so nothing is either ignored or over-actioned because everything arrived as one undifferentiated alarm.

Example

A hospital's patient-safety officer gets three messages in an hour: a family's complaint, a nurse's worried aside, and a screenshot from a private staff group, all circling the same idea — that a night-shift staff member is deliberately harming patients. Panic wants one answer now. Threat Claim Triage instead breaks the alarm apart. Fact: two patients on that unit had unexplained overnight deteriorations last week (documented). Unknown: whether the two events are linked, and whether any staffing pattern connects them. Plausible risk: the deterioration could be a medication-handling error rather than intent. Unsupported: the "deliberately harming" framing, which so far rests only on a coincidence and a screenshot.

Each bucket then gets a routed owner: the clinical incidents go to a formal mortality review; the staffing-pattern question goes to the unit manager to pull the roster quietly; the "intent" allegation is held — not published, not dismissed — pending the review, with a named decision-owner (the chief medical officer) who alone may escalate it to HR or police. Within a day the panic has become a work plan, and no individual has been named to the whole hospital on the strength of a screenshot.

How it works

Triage is a repeatable sort, not an investigation:

  • Restate the claim as a proposition. Convert "something terrible is happening" into a testable sentence with a subject, an alleged harm, and an alleged cause. This is what makes it reviewable at all.
  • Bucket by evidence quality. Sort the pieces into fact / unknown / plausible risk / unsupported, and mark what evidence would move each piece to a different bucket. This is a fast grade for routing, not the deep verification a fact-check performs.
  • Assign an owner and a boundary. Every bucket gets exactly one accountable owner and a rule about who may escalate it. The most dangerous bucket — unsupported-but-alarming — is explicitly held rather than acted on or discarded.
  • Set the next-inquiry trigger. Name the single question whose answer reclassifies the claim, so effort concentrates there.

Tuning parameters

  • Sort speed vs. sort accuracy — a five-minute desk triage versus a half-day review. Faster keeps pace with a spreading rumor but mis-buckets more; match it to how fast the claim is traveling.
  • Bucket granularity — four coarse buckets or a finer ladder. Finer sorting routes more precisely but slows the sort and invites false confidence.
  • Escalation threshold per bucket — how strong the evidence must be before a bucket may be handed up to sanction or law enforcement. Set it low for reversible protective steps, high for anything that names a person.
  • Hold discipline — how firmly the unsupported bucket is quarantined from action and from deletion. Loosen it and you either overreact or look like you are burying something.

When it helps, and when it misleads

Triage's strength is speed with structure: it gives leaders a defensible first response — "here is what we know, here is what we are checking, here is who owns it" — before the facts are in, which is exactly the moment panic exploits. It prevents both the vacuum that rumor fills and the overreach that a single vivid anecdote invites.

Its failure mode is treating a vivid, easily-pictured story as if it were high-quality evidence — base-rate neglect, where the memorability of a scenario is mistaken for its likelihood.[n1] A sloppy triage quietly promotes the "unsupported" bucket to "plausible" because the story is frightening, and once a claim is mis-bucketed the whole downstream response inherits the error. The classic misuse is the reverse: using triage as a shredder, filing every uncomfortable claim under "unsupported" to make it disappear. The guarding discipline is to keep the routing slip and the buckets visible to more than one owner, and to re-triage as the named next-inquiry question gets answered rather than freezing the first sort.

How it implements the components

  • threat_claim — its core output: the diffuse alarm rewritten as an inspectable proposition with subject, harm, and alleged cause.
  • evidence_quality_check — the bucketing step grades each piece by evidence quality, though as a rapid routing sort rather than definitive verification.
  • decision_authority_boundary — assigning one accountable owner per bucket and a rule for who may escalate is the authority boundary.

It does not craft the public corrective_message — that is Crisis Communication Update — nor decide whether a resulting measure is proportional_response_rule-justified, which belongs to Proportionality Review.

Editorial Notes

Form Classification

Form family: Decision, Gate & Allocation

Rationale: Threat Claim Triage is defined in the frozen evidence as: Rapidly sorts an alarming claim into facts, unknowns, plausible risks, and unsupported allegations, and routes each bucket to the owner who should act on it. Its operative deployed or enacted form is therefore Decision, Gate & Allocation.

Nearest alternative: Protocol, Workflow & Routine — Protocol, Workflow & Routine can support this mechanism, but the evidence centers the concrete operation described above rather than the alternative family's defining operation.

Review outcome: Adjudicated after independent review; high confidence.

Origin Attribution

Primary origin: Security Studies & Intelligence Analysis

Origin pattern: Cross-disciplinary synthesis

Present-day reach: Universal

Rationale: Threat claim triage derives most directly from security's adversarial analysis, integrity, and incident-response tradition; its defining operation is to rapidly sorts an alarming claim into facts, unknowns, plausible risks, and unsupported allegations, and routes each bucket to the owner who should act on it.

Related originating lineages:

  • Communication & Media Studies — Communication and media research supplies a parallel or contributing lineage for the mechanism's defining operation: rapidly sorts an alarming claim into facts, unknowns, plausible risks, and unsupported allegations, and routes each bucket to the owner who should act on it.
  • Computer Science & Software Engineering — Computer science and software-engineering practice supplies a parallel or contributing lineage for the mechanism's defining operation: rapidly sorts an alarming claim into facts, unknowns, plausible risks, and unsupported allegations, and routes each bucket to the owner who should act on it.
  • Law & Governance — Law and governance's rule, authority, accountability, and due-process tradition provides a formative adjacent lineage for the same threat claim triage operation.
  • Psychology — Experimental, clinical, and behavioral psychology supplies a parallel or contributing lineage for the mechanism's defining operation: rapidly sorts an alarming claim into facts, unknowns, plausible risks, and unsupported allegations, and routes each bucket to the owner who should act on it.

Review resolution: Both blind reviewers independently select security_intelligence as the primary historical origin for the concrete operation—Rapidly sorts an alarming claim into facts, unknowns, plausible risks, and unsupported allegations, and routes each bucket to the owner who should act on it. The queued differences concern alternate origin disagreement, origin mode disagreement, not the primary lineage. I retain every alternate that either reviewer explains, without a numeric cap, and choose origin_mode=cross_disciplinary_synthesis because the reviewers' combined evidence identifies material construction from multiple disciplines. domain_reach=universal records later portability rather than multiplying historical origins; confidence=medium is the conservative shared evidentiary level, and encyclopedia_synthesis=true preserves either reviewer's affirmative synthesis finding.

Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.

Review outcome: Reconciled after independent review; medium confidence.

Notes

[n1] Base-rate neglect — the tendency, documented by Kahneman and Tversky, to judge how likely something is by how easily a vivid instance comes to mind rather than by how common it actually is. In triage it is the reason a frightening anecdote gets over-graded, which is why each bucket carries an explicit "what would move this" test.