Phase 1 of 6
Scoping, Mission & Classification
Define the mission question, customer, classification ceiling, and consumer constraints that will govern every architectural and tradecraft decision downstream.
0/9
Phase Progress
Required Recommended Optional Open-Source Proprietary Trinidy
Mission Definition & Intelligence Question
Specify the intelligence problem class the fusion model supports
Why This Matters
Fusion models framed as a generic "analyst helper" almost always fail ICD 203 evaluability review because the problem class determines which sources are authoritative, which analytic standards apply, and which customer cares about the answer. DIA MARS is scoped to foreign military capabilities; NGA Project Maven is scoped to GEOINT object detection; the two cannot share a single entity-resolution schema without compromise. Name the problem class before you touch a model.
Note prompts — click to add
+ Which CCMD, national customer, or Title 50 component has named the requirement?+ Is this a standing requirement under ICD 204 NIPF, or an ad-hoc task?+ What is the finished intelligence product family this will feed (NIE, DITSUM, INTSUM, spot report)?
Required
Every all-source fusion effort needs a named intelligence problem — not a generic "analytic assistant" framing.
Select all that apply
Foreign military order of battle / capabilities (DIA MARS-aligned)
Indications & Warning (I&W) tip-off
Counterterrorism target development
Counterintelligence / insider threat
Cyber threat intelligence
Counter-proliferation / WMD
Maritime domain awareness
Space domain awareness
Gray-zone / great-power activity tracking
Humanitarian / foreign disclosure support
required
✓ saved
Name the primary consumer and command relationship
Why This Matters
Consumer identity is the single biggest driver of acceptable latency, confidence threshold, and format — PDB-bound product tolerates hours of analytic review while a CCMD JOC needs minutes. It also determines ICD 209 dissemination controls, foreign disclosure status, and whether the output is a finished product or support-to-analysis. A fusion model that cannot name its consumer is a science project.
Note prompts — click to add
+ Who signs the finished product, and what is their tempo?+ Is the consumer authorized for the highest classification the model will ingest?+ Does the customer have a standing PIR or KIQ this maps to?
Required
Identify the principal customer — the downstream decision-maker whose tempo and confidence thresholds govern the product.
Single choice
National: President / NSC / PDB cycle
National: Cabinet principal / SecDef / DNI
CCMD commander / J2 (theater)
Component / service intelligence staff
Tactical echelon — brigade and below
Interagency partner (FBI, DHS, State INR, Treasury OIA)
Foreign partner under authorized disclosure
required
✓ saved
Set the product latency budget
Required
Select the end-to-end time from collection availability to analyst-reviewed fusion output.
Single choice
Seconds to minutes (I&W / tactical tip-off)
<1 hour (CCMD current intelligence)
<24 hours (daily production cycle)
1–7 days (target development, deep-dive)
Campaign / long-form assessment (weeks)
requirededgetrinidy
TrinidyCross-domain round-trips and commercial cloud inference add hours of latency that are incompatible with tactical and I&W tempos. On-node fusion inside the classified enclave keeps the entire workflow local to the SCIF — no CDS transit during normal operation.
✓ saved
Declare classification ceiling and compartments
Why This Matters
ICD 710 (Classification Management) and E.O. 13526 require every derivative product to carry source-derived classification — a model trained on TS/SCI data produces TS/SCI outputs, not the lowest-watermark version of its prompt. DoD 5200.01 Vols 1–4 operationalize the marking and handling rules. Getting the ceiling wrong on day one is the single fastest way to lose an ATO.
Note prompts — click to add
+ Has the original classification authority signed off on the planned model enclave level?+ Do you have an aggregation review — could combined sources classify higher than any single source?+ Which SCI compartments does the analyst workforce using this actually hold?
Required
Specify the highest classification, SCI compartments, and caveats the model must operate within.
Select all that apply
UNCLASSIFIED / CUI
SECRET / SECRET//REL
SECRET//NOFORN
TOP SECRET
TS//SCI (SI, TK, G, HCS compartments)
Special Access Program (SAP) enclave
FVEY / bilateral release caveats
ORCON / PROPIN handling
requiredtrinidy
TrinidyA single model that "spans" TS/SCI and below without an NSA-evaluated CDS is not a design — it is a spillage waiting to happen. Trinidy deploys a classification-matched instance per enclave so inference, embeddings, and logs all inherit the correct marking.
✓ saved
Map authorities under which collection was acquired
Why This Matters
The Intelligence Reform and Terrorism Prevention Act (IRTPA 2004) did not erase authority boundaries — it created a framework for sharing across them. U.S. person information under §702 minimization is not interchangeable with traditional 12333 collection, and mishandling that in a fusion model is exactly what the 2023 IC AI Ethics framework flags as a prohibited use. Authority must be a first-class metadata field from ingest through output.
Note prompts — click to add
+ Does every source carry authority-of-collection metadata into the pipeline?+ Have you coordinated with OGC on §702 minimization as it applies to model training and retrieval?+ Is the authority tag preserved end-to-end on fusion output, or does it get stripped in transformation?
Required
Intelligence data carries authority-of-collection constraints that follow it into any AI pipeline.
Select all that apply
E.O. 12333 (foreign intelligence, traditional IC)
FISA Title I / III (electronic surveillance / physical search)
FISA Title VII §702 (non-US persons abroad)
Title 10 (military operations)
Title 50 U.S.C. §§ 3001–3020 (IC statutory authorities)
Foreign partner liaison exchange (third-party rule)
Open-source / commercially procured (OSINT / PAI / CAI)
required
✓ saved
Define U.S. Persons handling posture
Why This Matters
IC element AG-approved procedures under E.O. 12333 §2.3 dictate exactly how USPER information may be retained, queried, and disseminated. A retrieval-augmented LLM that surfaces USPER data in response to a generic analyst prompt without an authority check is the textbook example of an auditable violation. Most IC AI ethics findings in the open literature trace back to query-time minimization failures, not training-time ones.
Note prompts — click to add
+ Are your AG-approved procedures reflected in the retrieval-layer authority check?+ Can you audit every query that touched USPER content and show the authority asserted?+ Have you briefed OGC on the LLM's generation behavior over USPER-adjacent retrieval results?
Required
USPER data requires specific minimization, masking, and querying controls under 12333 §2.3 and AG-approved procedures.
Single choice
No USPER in scope — foreign-only targeting
USPER incidental — minimization rules apply
USPER intentional under specific authority (FBI / DHS / Treasury OIA)
Mixed — per-query authority check required
required
✓ saved
Specify deployment enclave and inference topology
Required
Map the enclave where training, inference, and consumption each happen.
Single choice
NIPRNet (UNCLASS/CUI) on-premises
SIPRNet (SECRET) on-premises
JWICS (TS/SCI) on-premises
SAP enclave (air-gapped)
Commercial cloud with IL5/IL6 accreditation
Hybrid — training one enclave, inference another
requirededgetrinidy
✓ saved
Align to JADC2 / CJADC2 data standards
Why This Matters
CDAO-led JADC2 implementation is where service-specific AI efforts converge — Maven Smart System is the reference surface that downstream joint commanders expect. A fusion model that does not speak the JADC2 data fabric schemas will deliver analytic value but never reach the JOC screens it was built to inform.
Note prompts — click to add
+ Is the output schema aligned with Maven Smart System consumer contracts?+ Have you coordinated with CDAO on the data fabric schema version?+ Does your provenance metadata survive the JADC2 transit?
Recommended
If the output will feed joint kill-chain or C2 systems, JADC2 data fabric conformance is mandatory, not optional.
recommended
✓ saved
Document prohibited uses under DoD 3000.09 and IC AI Ethics
Why This Matters
DoD Directive 3000.09 (autonomy in weapon systems) and the DoD AI Ethics Principles (responsible, equitable, traceable, reliable, governable) together define what a fusion model is not allowed to do. A model that drafts an analytic product without a traceable source-of-record or that materially contributes to a targeting decision without human judgment on the loop is in prohibited territory before anyone else reviews it.
Required
Lethal autonomy, disparate-impact targeting, and unattributed analytic product are all explicitly out of scope.
required
✓ saved