FILE 1: Cell SOP Template (sop-template.txt)
=====================================================
CELL STANDARD OPERATING PROCEDURES
VERSION: [0.1]   
LAST REVIEWED: [YYYY-MM-DD]
NEXT REVIEW DUE: [YYYY-MM-DD] — QUARTERLY, MANDATORY
DOCUMENT OWNER: [CODENAME]
DISTRIBUTION: [MEMBER CODENAMES, COMMA SEPARATED]

WARNING: This document maps your cell. Loss of this file
triggers the breach protocol in Section Five. Store only
in encrypted volumes. Never transmit unencrypted.

CANARY PROVISION: Distribute a copy with one unique,
harmless detail varied per member (a version digit, a
date in an example, a placeholder name). If a copy ever
surfaces, the detail names the holder who leaked it.


=====================================================

SECTION ONE: MISSION
- Purpose of this cell: [WRITE 2-3 SENTENCES]
- Scope — what we do: [LIST]
- Scope — what we never do: [LIST]
- Active members (codename, role, rung level, entry date): [LIST]

SECTION TWO: THREAT MODEL
- Our collective adversaries, ranked by likelihood: [LIST]
- What each member inherits by joining: [ONE PARAGRAPH]
- Current threat level and date set: [FIELD]
- Trigger for raising threat level: [DEFINE]

SECTION THREE: COMMUNICATIONS
- Core channel (sensitive ops): Session or Briar. Never
  Signal unless phone-linked identity is acceptable for
  this specific context. Write here which and why: [FIELD]
- Surface channel (logistics only): [FIELD]
- Fingerprint verification: face-to-face or voice, logged
  by date, before any first operational message: [LIST]
- Traffic rules — never in surface channel: locations,
  threat models, member identities, operational content
- Check-in interval and window: [FIELD]
- Failsafe channel if core is down: [FIELD — physical
  meet, agreed location. Note: no steganography in
  standard procedure]

SECTION FOUR: TECHNICAL BASELINE
(Completion of these items is Rung One. Verified by
another member physically. Screenshots do not count.)
- Mobile: approved OS, verified boot, no vendor telemetry
  — inspected by [NAME] on [DATE]
- Desktop: hardened Linux, LUKS full disk encryption,
  keys offline — recovery-boot test failed correctly on
  [DATE]
- Browser: script-blocking defaults, fingerprint
  consistent across three sessions on [DATE]
- Authentication: hardware keys on all critical accounts,
  SMS 2FA retired (verify none remain) on [DATE]
- Storage: LUKS standard. No nested encrypted containers
  — nesting adds fragility and entropy-flaggable artifacts
- Devices showing a failed secure boot check are
  quarantined and investigated, not used

SECTION FIVE: BREACH RESPONSE
Severity rubric — before anything else, classify:
  TIER ONE (MINOR): surface-level leak, no identities,
    no locations, low-sensitivity material
  TIER TWO (SERIOUS): operational content exposed, or
    member identity/location leaked
  TIER THREE (CRITICAL): credential compromise, device
    loss, or sustained targeting
Response by tier:
  TIER ONE: silent fix, logged in AAR ledger, no alert
  TIER TWO: full sequence below, 48-hour alert
  TIER THREE: full sequence below, alert until threat
    source is identified and contained
Full sequence:
  0-5 MINUTES: panic code on core channel. Implicated
  channels silent. Suspect devices dark. Contain first,
  investigate second.
  5-60 MINUTES: all member statuses confirmed. Credentials
  rotated ON CLEAN DEVICES ONLY — never on a device you
  suspect. You would be handing the new password to
  whatever took the old one.
  WITHIN 2 HOURS: triage call, by voice, not text. What
  leaked, how, and what the canary detail says about
  the source.
  THEN: AAR within 24 hours. An SOP change or it WILL
  repeat.

SECTION SIX: PERSONNEL
Removal matrix — decided while calm, applied while not:
  Three unintentional slips: additional training
  One intentional breach: immediate offboarding
  Reckless or concealed compromise: investigation first
  Refusal to train: offboarding — probation terms were
  explicit from day one
Offboarding summary (full protocol in its own file):
  Within 24 hours mechanically complete, departing member
  supported, friendship continues with boundaries.

SECTION SEVEN: ROLES AND ROTATION
Current assignments: Comms Lead [NAME], OpSec Watch
[NAME], Debrief Lead [NAME]
Rotation: monthly, mandatory, every member fills every
seat at least once per year

SECTION EIGHT: DOCUMENT CONTROL
Storage locations (encrypted): [LIST, MAX 3 COPIES]
Change log: every edit dated, initialed, archived
Quarterly review: whole cell reads the SOP aloud,
proposes edits
FILE 2: Vetting and Proficiency Tracker (tracker.csv)
codename,role,rung_level,vetting_start,tool_migration_result,social_probe_result,black_box_result,rung_zero_date,rung_one_date,rung_two_date,rung_three_date,deployed_date,last_drill_score,last_aar_incidents,status,risk_notes
alpha,comms_lead,4,2026-06-01,on_time,pass,clean,2026-06-05,2026-07-01,2026-07-28,2026-08-24,2026-09-21,95,0,cleared,
bravo,opsec_watch,1,2026-06-02,late,pass,clean,2026-06-10,2026-09-01,,,,,,in_progress,needs_metadata_training
charlie,debrief_lead,2,2026-05-20,on_time,marginal,canary_detail_surfaced_via_mutual,2026-05-28,2026-08-15,,,,,,restricted,failed_black_box_retest_scheduled
delta,member,0,2026-06-10,on_time,pending,,,pending,,,,,,,,,recruit,awaiting_social_probe

Note the columns trace the article exactly — vetting results, then rung dates. The risk_notes field carries failure specifics. CSV imports cleanly to any spreadsheet or reads linearly in a text editor.

FILE 3: Drill Library (drill-library.txt)

Same four-element structure for every drill. Honest adversary framing.

DRILL 1: ACCIDENTAL GEOTAG
Objective: Detect and neutralize a metadata leak in 60 seconds.
Setup: Actor posts a photo with EXIF intact to the core channel.
Execution: Group spots it, deletes, verifies deletion, runs clean-slate if viewed externally.
Success: Detected by a non-designated member within 60s. Deleted within 2 minutes.

DRILL 2: COMPROMISED DEVICE
Objective: Verify wipe and comms-shift speed.
Setup: Member sends panic signal on surface channel, powers device off.
Execution: 15 minutes to rotate shared credentials and shift to failsafe.
Success: Rotation under 15 minutes, no info-flow interruption.

DRILL 3: DATA BROKER CAMPAIGN (QUARTERLY, NOT OPTIONAL)
Objective: Reduce every member's broker footprint.
Setup: Each member lists broker sites they appear on.
Execution: Coordinated opt-outs over 72 hours.
Success: Five documented removal attempts with receipts, per member.

DRILL 4: WORKPLACE PROBE
Objective: Deflect employer curiosity without burning cover.
Setup: Confederates play colleagues probing about off-hours life.
Execution: Defender holds surface persona.
Success: No contradictions, no accidental operational disclosure.

DRILL 5: MISSING COMMS CHECK
Objective: Correct response to a silent member.
Setup: One member goes dark unannounced.
Execution: Lost-contact protocol — alternates, intervals, extraction at 2 hours.
Success: Protocol followed exactly, no panic escalation.

DRILL 6: VENDOR REQUEST
Objective: Respond to a subpoena or service ToS change.
Setup: Simulated notice to one member.
Execution: Triage call in 30 minutes, migration plan in 48 hours.
Success: No panic-driven decisions, matrix documented.

DRILL 7: SOCIAL ENGINEER
Objective: Verbal deflection under pressure.
Setup: Attacker asks increasingly specific personal questions.
Execution: Defender deflects, code word to exit if needed.
Success: Cover held, exit clean, no disclosure even joking.

DRILL 8: PHYSICAL TAIL
Objective: Spot surveillance during movement.
Setup: One member tails the group on a normal route.
Execution: Detection turns; on spotting, silent signal, break contact, disperse.
Success: Tail identified in 3 cycles, rally within 30 minutes.

DRILL 9: BREACH INJECTION (CANARY CANONICAL)
Objective: Catch an insider threat or active compromise.
Setup: Red team attempts a phish. Planted material carries
a member-specific canary detail.
Execution: Squad detects, isolates, reports. If the material
spreads, the canary names the path.
Success: Threat caught before success. Origin traced.

DRILL 10: TOTAL BLACKOUT
Objective: Operate with digital comms cut.
Setup: Announced blackout, analog only.
Execution: Exchange one message via dead drop or physical
meetup. NOTE: this is a storm-outage drill, not a siege
fantasy. Mesh radio and shortwave are optional adaptation
notes, not standard kit.
Success: Message delivered, understood, zero digital trace.

HOW TO RUN THE LIBRARY
One drill per week. Rotate variables — time, place, personnel
— so nobody pattern-matches. AAR within 24 hours, every time.
Log results in the tracker. Increase difficulty as scores
plateau: shorter windows, more confounders, layered scenarios.
FILE 4: Offboarding Protocol (offboarding.txt)
OFFBOARDING — NEVER LEAVE A MAN BEHIND

Mechanical, within 24 hours. Non-negotiable regardless of
reason for departure:
1. Core channel access revoked
2. Shared credentials rotated by remaining members
3. Unit-provisioned hardware wiped, verified by two members
4. Their canary variant of the SOP retired and reissued
5. Watch assignments reassigned at next rotation

Human, at the same time. Equally non-negotiable:
6. Help securing their own independent systems — they
   leave with hardened devices, not stripped ones
7. Documented transfer of shared responsibilities
8. Exit conversation: honest closure, what worked, what
   didn't
9. Friendship continues with boundaries — they no longer
   know unit business, members don't discuss ops with them

Why both halves matter: a sloppily offboarded ex-member is
a threat vector who resents you. A well-offboarded one is
an ally outside the perimeter. And if offboarding is
brutal, current members hide problems and delay their own
departures past the point of safety.

DECISION MATRIX — COPY INTO YOUR SOP
Decided while calm, applied while not:
- Three unintentional slips: training, no penalty
- One intentional breach: immediate offboarding, no vote
- Reckless or concealed compromise: investigate first
- Refusal to train: offboarding, terms were explicit

FILE 5: Emergency Cards (emergency-cards.txt)

Five cards, one page each, 18pt minimum when printed, high contrast.

CARD 1: PANIC SEQUENCE
1. GO DARK. Power off non-essential devices. Do not send
   "I am running" messages. Silence is the signal.
2. ISOLATE. Airplane mode or power down.
3. NOTIFY. Panic code via the one surviving channel.
4. ROTATE. Keys for critical accounts, clean devices
   only, offline backup codes.
5. LOCK. Close documents, unmount volumes.
6. ACCOUNT. Check-in loop, confirm safe/compromised/
   missing, no movement until all-clear from lead.

CARD 2: DEVICE LOSS
1. Verify loss. If it reappears, assume compromised.
2. Trigger remote wipe.
3. Rotate ALL linked credentials from a clean device.
4. Notify the cell. Shift to backup channel.
5. Post-incident audit — what was on it.

CARD 3: SURVEILLANCE ON FOOT
STOP: Enter a busy public space, observe from inside.
RUN: Sharp turn or double-back. Did they adjust?
TEST: Building in one door, out another.
IF CONFIRMED: Do not engage. Disperse at agreed splits.
Nearest safe public location. "TAIL DETECTED" code to
the cell. Never lead them home.

CARD 4: QUESTIONING
Remain silent, invoke counsel. Name and date of birth if
legally required, nothing more. Do not lie, do not
volunteer. No physical resistance.
DURESS CODE: [WORD] means everything I say now is false.
Post-contact: notify cell, rotate everything since the
incident, assume total compromise, prepare cold status.

CARD 5: CONTACTS
Cell lead, codenames and channels. Backup lead. Legal
counsel number. Rally points, two. Physical copy only —
never store with a device. Destroy if compromised.
FILE 6: AAR Form (aar-form.md)
AFTER ACTION REVIEW
Conducted within 24 hours. Blame-free by design —
corrections are procedural, not personal. "That image had
GPS data. Let's scrub next time."

Header: Operation name, date, attendees, absent members
notified, facilitator.

1. OBJECTIVE: What was success supposed to look like?
   Understood by all before starting? [YES/PARTIAL/NO]

2. OUTCOME: What actually happened? Facts only, no
   justification of failures. Objective achieved
   [YES/NO/PARTIAL].

3. GAP ANALYSIS: Training gap? Equipment failure? SOP
   failure? Communications breakdown? External factor?
   Name the system failure, not the person.

4. CORRECTIVE ACTIONS — for each gap, one entry:
   Gap, corrective action, responsible party, deadline,
   status [OPEN/IN PROGRESS/COMPLETE]. Incomplete items
   roll forward to the next AAR. Nothing closes open-ended.

5. SOP CHANGES REQUIRED: [YES/NO]. If yes, document the
   edit, approver, effective version number. A breach that
   produces no SOP change will repeat.

6. PATTERNS — NOT INDIVIDUALS: Is this the same failure
   as last quarter's AAR? Read the ledger. Near-misses
   logged without names. Same mistake twice means the
   training or SOP is wrong, not the member.

7. MORALE: [HIGH/MEDIUM/LOW]. Burnout warning signs.
   Wellness actions. Security work burns people out —
   the drill where someone finally cracks is not the
   moment to find out nobody was watching.

Sign-off: All attendees concur [YES/NO]. Dissent noted
separately. Archived to encrypted volume with date-stamped
filename.