← Adversarial Analysis

§9.7

Open Problems

This section inverts the tables in §9.6.21. Where that subsection states what the material proposes against each entry in the catalog, this one treats the entries the material proposes nothing against, together with the questions §9.6 raises and does not settle. Nothing recorded here is a proposal. Where the text goes beyond what a source states, the elaboration is marked as this chapter’s.

Two items below are properties of the material as a whole rather than gaps against a particular threat. The first is that no element of the framework resolves the framework-capture case, which the source developing that case states in its own terms and presents as a condition of the framework rather than as a defect in it (§9.7.3). The three vulnerabilities that scenario is used to identify — metrics-versus-values divergence (§9.3.3), resilience as private capture (§9.3.4), and optimization pressure (§9.3.5) — are open in the same sense and are treated there. The second is that the coverage recorded in §9.6.21 registers what bears on a threat far more often than what anyone proposed for one (§9.7.8).

Two further observations already recorded in §9.6 are not developed again here. The polycentric countermeasure material reproduces general public-administration content rather than mechanisms specific to this model, per limit 3 of that section and §9.6.20. And no source connects the game-theoretic modeling specified in docs/15-advanced/06-systems-simulation-and-stress-testing.md to any threat in this catalog; §9.6.15 records that, and drawing the connection would be new work rather than extraction.

9.7.1 Founder and Insider Capture

Founder Capture is the chapter’s central open problem. Two independent source families reach it from different directions, and neither answers it.

The first is the pair of adversarial interview passes. p13r01 develops the pattern narratively under two names, “Idealist Turned Cynic” and, in the more developed variant, “Disillusioned Savior”, and §9.2.9 catalogs both as one pattern: a founding or long-committed member converts standing informal authority into control of the leadership pipeline and reframes dissent as disloyalty. The second is the worked scenario document. ~/code/papr/icn/security-bad-actors-and-mmm.md closes by raising the case in which the unit exploiting the legal gap is itself a founding entity, influential within the network’s informal structures, states that this would require holding members in leadership positions to a higher standard than the one applied generally, and stops. It names no mechanism and invokes no element of the framework to answer it (§9.3.7). One source reaches the problem through an individual’s turn against the network; the other reaches it through a unit justifying its own conduct in the network’s vocabulary. The two are not cross-referenced anywhere in the material.

The primary-source sweep recorded at §9.6 checked both interview passes, the worked scenario, all four polycentric-governance responses, and both glossary files for a mechanism directed at the informal legitimacy a founder holds by having founded the network. None holds one. The finding is about the sources rather than about the staged extraction.

Why the mechanisms in §9.6 do not reach it. §9.6.21 lists the five mechanisms the extraction maps onto this pattern, and each fails against it for a stated reason. Rotation as a principle (§9.6.5) acts on tenure in a formal role, and the authority the pattern converts is not held in a formal role, so a rotation requirement can run in full while that authority is untouched. Mandatory devil’s advocate apprenticeship (§9.6.11) conditions entry to formal office on prior service in a contrarian role, and conditions the same surface. Shadow governance and shadow boards (§9.6.6) supply a parallel body selected by lot whose recommendations are compared against the official body’s decisions, or which holds veto standing over decisions it judges too risky. Virtuous viruses (§9.6.9) act on the persistence of any position held long enough to be captured. Breakaway provisions (§9.6.8) do not act on the pattern at all; they change what a capture retains by letting units exit on pre-negotiated terms.

The following reading is this chapter’s rather than any source’s. Each of those mechanisms terminates in the same place. A rotation requirement has to be applied, a parallel body has to exercise its standing, a veto has to be cast, an exit has to be declared. Every one of those is an act by some body against the people who defined the rules that body applies, and the property the pattern turns on is precisely the informal weight those people carry in the bodies that would have to act. The detection mechanisms of §9.6.1 to §9.6.4 and §9.6.17 do not close the gap either, on the same reading: their output is a finding, a divergence, or a cluster warranting examination, and a finding is not an action. The route from a finding to a consequence runs through a decision body, which is the surface in question.

The material states neither who would hold a leadership member to the higher standard the worked scenario names nor on what authority. Chapter 03 specifies affirmative governance design for a Humanized Autonomous Organization (HAO) — the network’s coordinating framework — and nothing in the extraction connects that design to this case. This chapter does not supply the connection, because no source supports one.

9.7.2 The Threats Nothing Is Directed At

Six of the 22 cataloged threats are recorded in §9.6.21 as having nothing proposed against them: Founder Capture, Talent & Idea Poaching, Greenwashing Through Imitation, Inaction as a Weapon, Tyranny of Small Kindness, and Weaponized Burnout. All six were checked directly against every primary source, four in the first sweep and two in a supplementary sweep covering the pair the first passed over. All six therefore stand at the same evidential strength: the finding is that the sources hold nothing directed at them, not that the staged extraction failed to record something.

They also share a property of how they appear. Each is named once, in a single sentence, inside a block that its source does not tag with a countermeasure. The material carries five attachments made at the source level, in which a source states a mechanism against a named pattern or scenario (§9.6 limit 2), and none of the five lands on any of these six. Every countermeasure block that follows them covers several threats at once without distinguishing between them, which is the condition under which §9.6.21 records a correspondence as inferred rather than stated.

Grouped by what the absence has in common, they fall into three sets.

Patterns acting from outside the network’s boundary. Greenwashing Through Imitation and Talent & Idea Poaching are conducted by parties the network does not govern, against a countermeasure inventory that is almost entirely internal. Nothing in the material addresses distinguishing the network from firms that adopt its language without its structures, and nothing addresses retaining governance-skilled members against a competitor’s financial incentives. The research avenues sitting beside each of them in their own source address other subjects: stress testing, game theory, and adversarial tooling beside Greenwashing Through Imitation, and data governance and internal groupthink beside Talent & Idea Poaching.

Patterns acting on support and participation norms. Tyranny of Small Kindness, Weaponized Burnout, and Inaction as a Weapon each turn on how work, support, or participation is distributed among members rather than on a decision procedure, a tool, or the network’s vocabulary. The nearest candidate mechanisms are directed elsewhere: at factional pattern detection, at review of a particular risky decision, at entry to leadership, or at a single initiative’s exploitability. For Inaction as a Weapon the nearest material is an open research question rather than a proposed mechanism. §9.2.4 records separately that this pattern’s first precondition is the absence of a mechanism that docs/10-evaluation/02-participation-quality-and-alignment-audits.md specifies, which is existing coverage rather than a countermeasure in this material.

The informal-legitimacy case. Founder Capture stands alone and is treated in §9.7.1.

Read across the three sets, the following is this chapter’s observation rather than a claim any source makes. The mechanisms the material does propose act on four surfaces: tenure in formal office, the conduct of a decision procedure, the design and output of a tool, and the usage of shared terms. None of the six threats above acts on any of those four. They act on the network’s external boundary, on the distribution of work and support inside it, and on standing held without office.

9.7.3 The Framework-Capture Case Has No Resolution in the Framework

The source that develops the framework-capture scenario states that no single element of the framework resolves it and that no clear-cut correct ethical position is available within it. The scenario is unresolved by the source’s own design: its stated purpose is to force a debate and a systemic reassessment, which the source treats as conditions of the network’s long-term health. §9.3.7 records this, and the open ending is preserved here rather than closed.

The structural reason the source gives is that the unit’s justification is assembled from three commitments the network itself holds — an obligation to its members’ economic security, compliance with the law as the operative standard, and efficient use of an available resource (§9.3.2). Answering it requires ranking those commitments against one another, and the source states that the framework contains no such ranking. What is open is therefore not a missing rule but a missing ordering among rules the network already has.

The three vulnerabilities the scenario is used to identify are open in the same way, and none of the three has a mechanism directed at it. Metrics-versus-values divergence (§9.3.3) is the case in which measured performance and stated values move in opposite directions while every measurement remains truthful; an audit of the figures returns nothing because the figures are correct, and the network holds no measure of the comparison that would show the divergence. Resilience as private capture (§9.3.4) is the case in which adaptive capacity built to absorb network-level shocks is exercised for one unit’s benefit; the distinction is in who benefits, and the mechanism does not record that. Optimization pressure (§9.3.5) is the case in which a capable governance-aware process finds moves that are rule-legal and value-harmful as a matter of course, which sets a limit on rule revision as a response: closing a gap adds a rule, and the rule joins the set being optimized against.

Three responses are recorded against the scenario, and the source offers none of them as a resolution: rule revision closing the specific gap, on which the source states an explicit limit; audits extended beyond financial matters, on which it states none; and a redefinition of member wellbeing that would count the psychological cost borne by the members of a unit asked to rationalize conduct they judge harmful, which the source poses as a question rather than as a specification (§9.6.1, §9.6.10). §9.7.8 records that this is the only entry in the coverage table whose partial status rests on an attachment a source makes itself.

9.7.4 The Network Immune System

The material uses one term for two things and does not reconcile them. This chapter records both and takes no position, because the two usages sit in different source families and neither refers to the other.

In the glossary pass, the function is treated as a capability of a named entity. Term 11 defines provide.io by its multiple functions and lists an “immune system” for the network among them, alongside incubator and resource optimizer, in the present tense and without qualification (~/code/site-provide-coop/!! Localization.md, term 11; the same term is also present in ~/code/site-provide-coop/Values--.txt, which carries terms 11 to 20). Separately, term 17 of the same glossary defines the network “immune system” as the self-correcting mechanisms triggered by certain thresholds, and describes an interplay between human-led intervention and algorithmic detection of negative patterns. Term 17 states what the function consists of; term 11 attributes it to provide.io.

In the adversarial interview material, the same function is an unbuilt research question. p12r01, Response 1 lists “Immune Systems for Networks” among its research avenues and poses it as a question about whether principles drawn from biological systems could be applied to the network’s growth strategy in order to develop self-correcting mechanisms triggered at thresholds of stress, conflict, or detected deviation from the network’s mission. The passage asks whether such mechanisms could be developed. It does not describe mechanisms that exist or assign them to any party.

§9.6.15 catalogs the mechanism on the terms of the glossary definition and marks the question as unresolved. The difference is not a difference in what the mechanism would do; both descriptions name self-correcting responses triggered at thresholds, combining human intervention with algorithmic detection. The difference is in status and in ownership: whether the function is one an existing entity already performs, or a research direction nobody has built. Which reading is correct determines whether the mechanism can be cited as available coverage against any threat in §9.1.2, and no source in the extraction has standing over both usages. The item is recorded and left open.

9.7.5 The “Trojan Horse” Naming Collision

§9.1.6 records that two source documents use the term “Trojan Horse” for concepts of opposite valence, and that neither refers to the other. In p12r01 the term names an attack: tools presented as improvements to decision efficiency that carry a bias toward financial return, whose recommendations drift as their data degrades in a way the source describes as undetectable without a deliberately conducted audit. In the glossary pass, a “Trojan Horse” Cell is a sanctioned influence tactic: a deliberate placement of values-aligned members into ventures with the stated intent of knowledge-sharing and advocacy, aimed at influencing external partners, and explicitly disclaimed by that source as not subversive (~/code/site-provide-coop/!! Localization.md, term 9; the term does not appear in Values--.txt, which begins at term 11).

Chapter 09 uses the attack sense throughout, and the catalog entry at §9.1.2 and the treatment at §9.4.5 both carry that sense. The collision itself is unresolved.

§9.1.6 states the operational consequence and the reason the choice is not made there. A term naming both an attack vector and an approved practice cannot appear in an audit finding or a detection rule without a qualification attached each time it is used, so one of the two usages should be renamed. Which one should be renamed determines which body of existing material has to be revised, and no source in the extraction has standing over both. §9.1 also fixes the constraint that any renaming has to work within: threat names in this chapter are the sources’ own, retained so that a later reader can trace an entry back to the material that produced it. Renaming the attack sense would break that traceability for one catalog entry and for the two sub-patterns filed under it at §9.4.6 and §9.4.7. Renaming the sanctioned-practice sense would leave the catalog intact and would instead require revision of the glossary material and of anything downstream of it. That comparison is this chapter’s, and it is recorded as a description of the cost on each side rather than as a recommendation. The choice is left open.

9.7.6 Who Conducts the Mechanisms

Limit 4 of §9.6 states that the mechanisms cataloged there name no one to run them. The gap is recorded here in the specific form it takes in each case.

Several entries specify a body or a role and stop at that. §9.6.3 names a designated role that analyzes patterns in word usage across the network, and does not say who designates it. §9.6.2 is one line in a terminology list: it specifies standing scrutiny of the network’s decision-support tools and states no procedure, no cadence, and no party responsible for conducting the audit. §9.6.1 extends audit coverage past financial anomalies to patterns of conduct without naming the auditor. §9.6.4 specifies analytical systems examining network data for patterns of factional alignment, and §9.6.17 specifies analysis that highlights unusual clusters of activity for human examination, with the source stating as part of the mechanism that the output is a starting point for an investigation rather than a substitute for one; neither entry says whose examination or whose investigation. §9.6.16 specifies a mandatory transparency rotation on the committees that allocate resources and public dashboards recording the justification given for a decision, without naming the party that administers either.

§9.6.6 is the partial exception. Its two forms specify how members of the parallel body are chosen, by lot, and the second form specifies strictly limited terms and veto standing. Selection by lot answers who sits on the body. The following is this chapter’s reading: it does not answer who convenes the body, what supplies it with the information a comparison would require, or what obliges the official body to respond when the two diverge.

One source raises the question against its own proposal. The analytical systems in the first form of §9.6.4 are to be kept under constant scrutiny so that they do not become instruments of control in their own right. The source states the condition and names no mechanism for meeting it, so the proposal that most clearly identifies the problem also leaves it open.

The consequence for this chapter is bounded. Chapter 03 specifies affirmative governance design, including how bodies are composed and how authority over a decision is settled, and this chapter cross-references it rather than restating it. Nothing in the extraction connects any mechanism in §9.6 to that design, and no source assigns any of these mechanisms to a body the model already specifies. The mechanisms are recorded as the sources state them, with the appointment, funding, and accountability questions unanswered.

9.7.7 Whether the Scenario at §9.6.16 Warrants a Catalog Row

§9.6.16 records a mechanism the primary-source sweep recovered: a single prevention line combining a mandatory transparency rotation on resource committees, public dashboards recording decision justifications, and gamified challenges in which members analyze the network’s own data for resource manipulation conducted in the form of oversight. The source attaches that line directly beneath a scenario of its own, which makes it one of five source-level attachments in the whole material. It is one of two that land on nothing §9.1.2 catalogs; the other is the onboarding prevention line at §9.6.19, whose scenario is a member presenting as a mentor to newly formed units and misrepresenting the network’s policies to them. The scenario treated here is an internal coalition circulating accounts of bias in resource-allocation decisions, algorithmic and human, in order to portray the network’s leadership as corrupt and to degrade trust in it.

The scenario is close to two cataloged entries without matching either. Manufacturing Dissent (§9.4.8) works by manipulating what the network’s health-monitoring systems display, so that members respond to a displayed pattern the underlying records do not support; this scenario works by circulating accounts about decisions, and requires no manipulation of a system. Divide and Conquer (§9.4.4) works by circulating unverified accounts, which is the same mechanism, but the source assigns it to outside parties and directs it at trust between units; this scenario is conducted by an internal coalition and directed at the standing of the bodies that allocate resources. §9.6.16 records the link to Manufacturing Dissent as inferred for those reasons.

Recommendation. This chapter recommends that the scenario receive its own row in §9.1.2, and states this as a recommendation rather than as a change made here. The argument is the catalog’s stated function: §9.1 exists so that a countermeasure can be traced back to what a source directed it at, and leaving this scenario uncataloged means one of the five source-stated threat-to-countermeasure links in the entire material has no anchor in the catalog, which is the same directedness deficit §9.7.8 records for the chapter as a whole. The row would belong in the external and technical vectors category alongside §9.4.4 and §9.4.8, and its name would have to come from the source’s own heading text so that §9.1’s naming rule holds; the source supplies a timeline heading and a target rather than a threat name, which is a weaker naming basis than the other 22 rows rest on.

The same argument stands for the onboarding scenario at §9.6.19, whose naming basis in its source is of the same kind and of the same weakness. It is not carried into the recommendation here, because the arithmetic below was worked for one added row against the catalog in its current form. A later editor weighing one of the two should weigh both.

The arithmetic consequences are set out so that a later editor can weigh them, and they are this chapter’s. The catalog would hold 23 rows. The new row would be addressed, since its mechanism carries a source-level attachment, raising the addressed count from two to three. Manufacturing Dissent would then rest on §9.6.18 alone, which the sweep rates its least confident item and which §9.6.21 already states its status does not rest on, so that row would move from partial to none proposed. The resulting distribution is three addressed, thirteen partial, and seven with nothing proposed. The change is not made here because the counts recorded in §9.6.21 were verified against the catalog in its current form.

9.7.8 What the Coverage Table Records

The tables at §9.6.21 cover 22 threats and eight failure modes. Two threats are recorded as addressed, fourteen as partial, and six as having nothing proposed against them. No failure mode is recorded as addressed; seven are partial and one has nothing proposed.

Fourteen partial entries overstates how much of the material is directed at a named threat, and the cells in §9.6.21 state why one at a time. Exactly one of the fourteen rests on an attachment a source makes itself: the framework-capture scenario of §9.3, which the source presents as unresolved and answers with three responses it does not offer as a resolution. Six rest on correspondences this chapter or the primary-source sweep drew. The remaining seven rest on correspondences the staged extraction drew. A reader counting what the sources actually direct at a named threat should count the two addressed entries and that single partial, and should read the other thirteen as a record of what bears on a threat rather than of what anyone proposed for one.

The failure-mode table carries the same qualification in a different form. Its seven partial entries all rest on the instruments §9.6.20 assigns to chapter 03, which are general public-administration content rather than mechanisms specific to this model: the extraction says so of the material it carried, and the fourth polycentric response, recovered into that subsection, is of the same kind. No failure mode in §9.5 has a mechanism specific to this model directed at it.

The reason is a property of how the sources are written, and §9.6 limit 2 states it. In the source documents the countermeasures appear as lists attached to a response’s overall subject rather than as a mapping onto named threats. Five attachments in the whole material are made at the source level, and two of those five land on scenarios the catalog does not name (§9.7.7). Every other correspondence in §9.6.21 was drawn afterward — in the staged extraction, in the primary-source sweep, or in this chapter — and each is marked in the cell where it appears.

The following statement of what that implies is this chapter’s. A status in §9.6.21 answers the question of whether anything in the material bears on an entry. It does not answer whether anyone proposed a mechanism for that entry, and it does not answer whether the mechanism would work, since nothing in §9.6 has been built or tested. Those are three separate questions, and the table answers the first. Three of the 22 threats have an answer to the second — Mission Creep, Lexical Drift, and the framework-capture scenario, the three rows whose entries carry a source-level attachment. None has an answer to the third.