Emergency Cards (emergency-cards.txt)

Five cards, one page each, 18pt minimum when printed, high contrast.

CARD 1: PANIC SEQUENCE
1. GO DARK. Power off non-essential devices. Do not send
   "I am running" messages. Silence is the signal.
2. ISOLATE. Airplane mode or power down.
3. NOTIFY. Panic code via the one surviving channel.
4. ROTATE. Keys for critical accounts, clean devices
   only, offline backup codes.
5. LOCK. Close documents, unmount volumes.
6. ACCOUNT. Check-in loop, confirm safe/compromised/
   missing, no movement until all-clear from lead.

-------------------------------------------------------------

CARD 2: DEVICE LOSS
1. Verify loss. If it reappears, assume compromised.
2. Trigger remote wipe.
3. Rotate ALL linked credentials from a clean device.
4. Notify the cell. Shift to backup channel.
5. Post-incident audit — what was on it.

-------------------------------------------------------------

CARD 3: SURVEILLANCE ON FOOT
STOP: Enter a busy public space, observe from inside.
RUN: Sharp turn or double-back. Did they adjust?
TEST: Building in one door, out another.
IF CONFIRMED: Do not engage. Disperse at agreed splits.
Nearest safe public location. "TAIL DETECTED" code to
the cell. Never lead them home.

-------------------------------------------------------------

CARD 4: QUESTIONING
Remain silent, invoke counsel. Name and date of birth if
legally required, nothing more. Do not lie, do not
volunteer. No physical resistance.
DURESS CODE: [WORD] means everything I say now is false.
Post-contact: notify cell, rotate everything since the
incident, assume total compromise, prepare cold status.

-------------------------------------------------------------

CARD 5: CONTACTS
Cell lead, codenames and channels. Backup lead. Legal
counsel number. Rally points, two. Physical copy only —
never store with a device. Destroy if compromised.
FILE 6: AAR Form (aar-form.md)
AFTER ACTION REVIEW
Conducted within 24 hours. Blame-free by design —
corrections are procedural, not personal. "That image had
GPS data. Let's scrub next time."

-------------------------------------------------------------

Header: Operation name, date, attendees, absent members
notified, facilitator.

1. OBJECTIVE: What was success supposed to look like?
   Understood by all before starting? [YES/PARTIAL/NO]

2. OUTCOME: What actually happened? Facts only, no
   justification of failures. Objective achieved
   [YES/NO/PARTIAL].

3. GAP ANALYSIS: Training gap? Equipment failure? SOP
   failure? Communications breakdown? External factor?
   Name the system failure, not the person.

4. CORRECTIVE ACTIONS — for each gap, one entry:
   Gap, corrective action, responsible party, deadline,
   status [OPEN/IN PROGRESS/COMPLETE]. Incomplete items
   roll forward to the next AAR. Nothing closes open-ended.

5. SOP CHANGES REQUIRED: [YES/NO]. If yes, document the
   edit, approver, effective version number. A breach that
   produces no SOP change will repeat.

6. PATTERNS — NOT INDIVIDUALS: Is this the same failure
   as last quarter's AAR? Read the ledger. Near-misses
   logged without names. Same mistake twice means the
   training or SOP is wrong, not the member.

7. MORALE: [HIGH/MEDIUM/LOW]. Burnout warning signs.
   Wellness actions. Security work burns people out —
   the drill where someone finally cracks is not the
   moment to find out nobody was watching.

   Sign-off: All attendees concur [YES/NO]. Dissent noted
separately. Archived to encrypted volume with date-stamped
filename.