SOP

SECTION ONE: MISSION
- Purpose of this cell: [WRITE 2-3 SENTENCES]
- Scope — what we do: [LIST]
- Scope — what we never do: [LIST]
- Active members (codename, role, rung level, entry date): [LIST]

SECTION TWO: THREAT MODEL
- Our collective adversaries, ranked by likelihood: [LIST]
- What each member inherits by joining: [ONE PARAGRAPH]
- Current threat level and date set: [FIELD]
- Trigger for raising threat level: [DEFINE]

SECTION THREE: COMMUNICATIONS
- Core channel (sensitive ops): Session or Briar. Never
  Signal unless phone-linked identity is acceptable for
  this specific context. Write here which and why: [FIELD]
- Surface channel (logistics only): [FIELD]
- Fingerprint verification: face-to-face or voice, logged
  by date, before any first operational message: [LIST]
- Traffic rules — never in surface channel: locations,
  threat models, member identities, operational content
- Check-in interval and window: [FIELD]
- Failsafe channel if core is down: [FIELD — physical
  meet, agreed location. Note: no steganography in
  standard procedure]

SECTION FOUR: TECHNICAL BASELINE
(Completion of these items is Rung One. Verified by
another member physically. Screenshots do not count.)
- Mobile: approved OS, verified boot, no vendor telemetry
  — inspected by [NAME] on [DATE]
- Desktop: hardened Linux, LUKS full disk encryption,
  keys offline — recovery-boot test failed correctly on
  [DATE]
- Browser: script-blocking defaults, fingerprint
  consistent across three sessions on [DATE]
- Authentication: hardware keys on all critical accounts,
  SMS 2FA retired (verify none remain) on [DATE]
- Storage: LUKS standard. No nested encrypted containers
  — nesting adds fragility and entropy-flaggable artifacts
- Devices showing a failed secure boot check are
  quarantined and investigated, not used

SECTION FIVE: BREACH RESPONSE
Severity rubric — before anything else, classify:
  TIER ONE (MINOR): surface-level leak, no identities,
    no locations, low-sensitivity material
  TIER TWO (SERIOUS): operational content exposed, or
    member identity/location leaked
  TIER THREE (CRITICAL): credential compromise, device
    loss, or sustained targeting
Response by tier:
  TIER ONE: silent fix, logged in AAR ledger, no alert
  TIER TWO: full sequence below, 48-hour alert
  TIER THREE: full sequence below, alert until threat
    source is identified and contained
Full sequence:
  0-5 MINUTES: panic code on core channel. Implicated
  channels silent. Suspect devices dark. Contain first,
  investigate second.
  5-60 MINUTES: all member statuses confirmed. Credentials
  rotated ON CLEAN DEVICES ONLY — never on a device you
  suspect. You would be handing the new password to
  whatever took the old one.
  WITHIN 2 HOURS: triage call, by voice, not text. What
  leaked, how, and what the canary detail says about
  the source.
  THEN: AAR within 24 hours. An SOP change or it WILL
  repeat.

SECTION SIX: PERSONNEL
Removal matrix — decided while calm, applied while not:
  Three unintentional slips: additional training
  One intentional breach: immediate offboarding
  Reckless or concealed compromise: investigation first
  Refusal to train: offboarding — probation terms were
  explicit from day one
Offboarding summary (full protocol in its own file):
  Within 24 hours mechanically complete, departing member
  supported, friendship continues with boundaries.

SECTION SEVEN: ROLES AND ROTATION
Current assignments: Comms Lead [NAME], OpSec Watch
[NAME], Debrief Lead [NAME]
Rotation: monthly, mandatory, every member fills every
seat at least once per year

SECTION EIGHT: DOCUMENT CONTROL
Storage locations (encrypted): [LIST, MAX 3 COPIES]
Change log: every edit dated, initialed, archived
Quarterly review: whole cell reads the SOP aloud,
proposes edits