§9.0
Adversarial Analysis
Adversarial analysis examines how the mechanisms of a Humanized Autonomous Organization (HAO) — the network’s coordinating framework — can be turned against the purposes those mechanisms are specified to serve. The subject is the model’s own machinery: consensus procedures, mutual-support systems, value-alignment vocabulary, algorithmic decision support, and the distribution of authority across partly independent units. Each is a surface an actor can work against, and in several of the patterns cataloged here the property that makes a mechanism function is the same property that makes it available for misuse. The chapter is diagnostic. It names attack patterns, states the conditions under which each becomes available, describes what each would look like from outside, and records which of them the source material leaves unanswered.
Scope
The chapter covers five areas, which are also the five categories the threat catalog uses. §9.1.1 defines them and fixes their names; the names below are those names.
- Mission and values — patterns in which the network’s stated purpose is eroded by increments, hardened into criteria that cannot be tested, or invoked selectively against members (§9.1).
- Governance capture — patterns in which decision-making influence accumulates outside the channels specified to carry it, and patterns in which the specified procedure is used against its own purpose (§9.2).
- Framework capture — the case in which a unit acts against the network’s stated purpose and justifies the action in the network’s own vocabulary, so that the justification remains internally coherent on the network’s own terms (§9.3).
- External and technical vectors — co-option applied from outside the network, together with attacks on the shared technical systems and shared vocabulary the network depends on (§9.4).
- Polycentric structural failure — failure modes that follow from distributing authority across many partly independent centers, which the model inherits by adopting that structure (§9.5).
Detection and resistance mechanisms are cataloged in §9.6, and problems that no source resolves in §9.7. Affirmative governance design — how decision bodies are composed, how proposals pass, how disputes between units are resolved — belongs to chapter 03 and is cross-referenced here rather than restated.
Relationship to Existing Chapters
Four existing sections specify machinery that the threat model in this chapter applies to.
docs/06-lifecycle/03-collapse-and-containment-protocols.mdspecifies what happens once a United Micro Enterprise (UME) — a small, self-managing venture team of up to ~15 people — or a Strategic Enterprise Partnership (SEP) — a joint venture between teams — is already failing: five classes of collapse trigger, tiered containment protocols, deconstruction steps, a retrospective autopsy report, and system-level safeguards such as the distributed trust graph and standby crisis cells. It is the response machinery. This chapter describes the attack patterns that lead to those triggers being reached.docs/10-evaluation/02-participation-quality-and-alignment-audits.mdspecifies participation auditing: consent decision audits, role health assessments, equity-engagement correlation mapping, and network-level engagement distribution. A number of the observable indicators listed in this chapter are quantities that auditing machinery already collects.docs/10-evaluation/04-ai-augmented-governance-monitoring.mdspecifies the Collaborative Intelligence Network (CIN) as AI-augmented rather than autonomous governance support, across three layers: human-in-the-loop deliberation aids, anomaly detection and scenario simulation (centralization drift, exit clustering, governance fatigue signals, SEP imbalance), and alignment monitoring against the network’s stated values. It is the standing detection layer. This chapter supplies the concrete patterns that layer would be configured to look for.docs/15-advanced/06-systems-simulation-and-stress-testing.mdspecifies agent-based modeling of unit, member, and network-level agents, failure-mode and antifragility scenario modeling — trust collapse in a regional Member Trust Union (MTU) — the network’s credit-union-like financial institution — governance fragmentation from versioning conflicts in the operating agreement, model misalignment producing decision drift, and reputation hoarding or sybil attacks in trust networks — and game-theoretic modeling of incentives and strategic behavior. It is the quantitative layer. This chapter catalogs qualitatively the behaviors that layer would simulate.
In each case the existing section specifies a mechanism, and this chapter supplies the threat model against which that mechanism is measured. None of the four is restated here.
Method and Its Limits
The material derives from red-team exercises conducted against the model’s own documentation. Three families of source contribute. Two adversarial interview passes were run against the Integrated Cooperative Network (ICN) — the reference cooperative business network — under prompts asking how the network could be ruined and how it could be destroyed (gemini_icn-interview-1_p12r01_ruin-the-icn.mdx and gemini_icn-interview-1_p13r01_destroy-the-icn.mdx, referred to below as p12r01 and p13r01). A single worked document, ~/code/papr/icn/security-bad-actors-and-mmm.md, develops one scenario in which a unit exploits a legal gap and defends the act in the network’s own terms. Four model variants in ~/code/papr/polycentric-governance/ respond to a deliberately solution-free prompt asking for gaps in polycentric governance, and the same four respond to a follow-on prompt asking for solutions to those gaps; §9.5 draws on the first set and §9.6.20 on the second. All three families were consolidated into a single staged extraction before drafting, and the claims in this chapter trace to that extraction rather than to independent review of the archives.
Five limits follow from that provenance, and the first is the chapter’s principal limitation.
- No operating experience underlies any entry. No unit described in this chapter has been observed. Every pattern is analytical: a statement of what the documented mechanisms would permit, derived from documentation rather than from deployment. No claim is made about how often any pattern occurs, how likely it is, or how damaging it would be in practice.
- The catalog is not closed. It is the union of what these particular exercises produced under these particular prompts. Absence of a pattern from §9.1 is evidence about the source material, not about the model.
- Threat names are the sources’ own. They are retained so that later work can be traced back to the material that produced them, including where a name carries rhetorical framing. Where two sources use one name for unrelated things, or separate names for closely related things, both are recorded and neither is reconciled (§9.1.2, §9.1.6).
- One source contains constructed dialogue.
security-bad-actors-and-mmm.mdpresents a unit’s self-justification as an authored illustration, and labels it as such. It is a construct, not testimony. No quotation attributed to a person appears anywhere in this chapter, and §9.3 treats the scenario as the analytical construct it is. - The polycentric material is general governance literature. The four variants converge on findings that public-administration research had already established about polycentric systems. §9.5 uses that material for its taxonomy of failure modes and marks it as inherited rather than as a finding about this model specifically.