H3AD-REF / GUIDES / STRUCTURED ANALYTIC TECHNIQUES

Structured Analytic Techniques.
Pressure-Test The Call Before It Ships.

A static reference for the structured analytic techniques (SATs) intelligence analysts use to catch their own bias before a judgment goes out the door. These methods trace back to Richards Heuer's Psychology of Intelligence Analysis and the CIA's Tradecraft Primer, written for the intelligence community but built for exactly the problem a CTI analyst has: a conclusion that has to survive contact with someone who'll act on it. No scoring engine here, just the methods, the actual steps, and which one earns its hour when the queue doesn't have hours to spare.

Analysis of Competing Hypotheses

The best-known SAT, built by CIA veteran Richards Heuer specifically to counter confirmation bias. Use it when two or more hypotheses are genuinely plausible and the evidence is thin enough that whichever one you favor first could quietly steer the analysis.

The Eight Steps (Heuer)

1. Identify the hypotheses:
List every plausible hypothesis, not just the front-runner
└── Best done with a small group covering different perspectives, not solo
    // a hypothesis that never gets written down never gets tested against the evidence

2. List the evidence:
Significant evidence and arguments, for and against each hypothesis
└── Includes assumptions and logical deductions, not just hard evidence
    // what "counts" as evidence here is broader than it first looks

3. Build the matrix:
Hypotheses across the top, evidence down the side
└── Mark each item as consistent, inconsistent, or not diagnostic against each hypothesis
    // work across one piece of evidence at a time against every hypothesis, not down one hypothesis at a time

4. Refine the matrix:
Reconsider the hypotheses, drop evidence that doesn't discriminate
└── Non-diagnostic evidence, the kind that's consistent with every hypothesis, adds noise, not signal
    // this is also where a hypothesis nobody thought of in step 1 usually surfaces

5. Draw tentative conclusions:
Work to disprove hypotheses rather than prove the favored one
└── The hypothesis with the least evidence against it wins, not the one with the most evidence for it
    // this step is the whole point of ACH, and the one people skip under time pressure

6. Test sensitivity:
Check how much the conclusion depends on a small number of critical items
└── If one or two pieces of evidence turn out wrong, does the conclusion flip too
    // a conclusion that rests on one uncorroborated report is not the same confidence as one backed by ten sources

7. Report the conclusions:
Give the relative likelihood of all hypotheses, not just the winner
└── Say why the rejected ones were rejected, not just what the answer is
    // this is what lets a reader push back on the reasoning instead of just the verdict

8. Identify future indicators:
Define what future evidence would signal the conclusion is wrong
└── So the team notices the shift instead of being the last to know
    // this step is what connects ACH to the Indicators technique further down this page

Key Assumptions Check

Listing and testing the premises a judgment actually rests on, most of which were never written down because nobody thought to question them. Run it at the start of an analytic effort, or any time before a judgment goes final.

The Four Steps

1. Write down the current line:
State the judgment as it stands right now, in one place everyone can see
└── Not the polished write-up, just the working conclusion
    // you can't check assumptions against a judgment that's still only in someone's head

2. List every premise it depends on:
Both the assumptions stated in the write-up and the ones nobody wrote down
└── The unstated ones are the point of this exercise, not the stated ones
    // an assumption held unconsciously is, by definition, one that was never examined

3. Challenge each one:
Ask why it has to be true, and whether it holds in every scenario under consideration
└── Not just the expected scenario, the edge cases too
    // "this has always held before" is not the same claim as "this must hold now"

4. Refine the list:
Keep only what the judgment can't survive without
└── For each one, note what evidence or event would break it
    // this is the list that gets rechecked if new information contradicts the call later

Devil's Advocacy & "What If?" Analysis

Two ways of deliberately arguing against your own conclusion. Devil's Advocacy stress-tests the case you already built; What If Analysis stress-tests it by assuming the opposite conclusion already happened and working backwards to see if that's plausible too. Use either one when a team converges on an answer suspiciously fast.

Devil's Advocacy

1. Outline the mainline judgment:
State it plus its key assumptions, and characterize the evidence backing it
└── This is the target the devil's advocate argues against
    // you can't argue against a position that was never pinned down precisely

2. Pick the weakest assumptions:
Select one or more that look most susceptible to challenge
└── Not every assumption is worth attacking, some are genuinely solid
    // spend the effort where the case is actually thin

3. Review the evidence behind it:
Look for gaps, questionable sourcing, or the possibility of deception
└── Same evidence the mainline judgment used, read with an adversarial eye
    // this is where a single-source claim that got treated as fact usually gets caught

4. Surface the contrary evidence:
What supports an alternative hypothesis, or contradicts current thinking outright
└── Evidence that was present all along but didn't fit the narrative getting built
    // this is the evidence confirmation bias quietly deprioritized the first time through

5. Present the findings:
Flawed assumptions, thin evidence, or plausible deception, presented to the team
└── On the record, before the judgment ships, not after
    // the goal isn't to win the argument, it's to make sure the argument happened

6. Draft the alternative, if warranted:
A contrarian paper laying out the opposing conclusion, not just a footnote
└── Only if the review actually turned up something serious
    // most devil's advocacy exercises end with the original call surviving, stronger for having been tested

"What If?" Analysis

1. Assume the event already happened:
Treat the low-probability outcome as fact, not as one possibility among many
└── The whole technique depends on committing to this premise
    // arguing "if it happened" keeps the exercise hypothetical and toothless

2. Pick a triggering event:
Something plausible that could have set the scenario in motion
└── Makes the "what if" concrete instead of abstract
    // a vague trigger produces a vague chain of argument

3. Build the chain of argument backwards:
What had to happen at each stage for this to be where things ended up
└── As much logic as evidence, since the event hasn't actually happened
    // this is "thinking backwards" from the outcome, not forecasting forwards from today

4. Lay out plausible pathways:
One or more routes that could get from today to that outcome
└── More than one pathway if more than one looks plausible
    // a single forced pathway is a sign the scenario was reverse-engineered too hard

5. Pull indicators from each pathway:
The observables that would show the scenario is starting to unfold
└── This is what turns the exercise into something actionable, not just a thought experiment
    // feeds directly into the Indicators technique below

6. Monitor those indicators going forward:
Not just for this exercise, but as an ongoing watch list
└── The value of the exercise compounds the longer the indicators get checked
    // a what-if exercise that ends when the meeting ends wasted the meeting

Indicators & Signposts of Change

Defining observable indicators ahead of time so a shift in the situation gets noticed as it happens, instead of being reconstructed after the fact. Use it any time a judgment is meant to hold for more than a single report cycle.

STEP 1

Identify Competing Hypotheses

The same set ACH or What If Analysis would have already produced
Start from the hypotheses or scenarios already on the table. This technique isn't meant to generate them from scratch, it's meant to track which one is actually happening.
STEP 2

Build A List Per Hypothesis

Separate, hypothesis-specific indicator lists, not one shared list
List the activities, statements, or events you'd expect to observe if that specific hypothesis were the correct one. An indicator that fits every hypothesis equally isn't doing any work.
STEP 3

Review On A Set Cadence

A one-time list is a snapshot, not a warning system
Check the lists regularly against what's actually being observed. The point is catching the indicator that changed, not the one that was already expected.
STEP 4

Weight By Confirmed Indicators

Let the observed indicators move the call, not the original favorite
Treat the hypothesis with the most confirmed indicators as the most likely one, even if it wasn't the one the team expected going in. That reversal is the technique working as intended, not a failure of the original analysis.

When SATs Are Worth The Time

A SOC or CTI queue doesn't have hours to spare for every ticket, and it doesn't need to. These techniques earn their keep on the judgments that get acted on, not on routine triage.

FIT

ACH For A Genuinely Ambiguous Attribution Call

Not for the IOC enrichment ticket that closes itself
Run the matrix when two or three actors are all plausible and the evidence is thin enough that whichever hypothesis you reach for first could quietly win by default. A ninety-minute ACH session before an attribution line goes into a report is cheaper than walking that line back after a customer acted on it.
FIT

Key Assumptions Check Before It Reaches Leadership

The cheapest insurance in this guide, reserved for judgments that get acted on
Fifteen minutes listing what a high-stakes assessment assumes to be true, run right before it goes out, catches the premise nobody questioned. Save it for the report leadership will make a decision from, not for the daily digest that gets skimmed and archived.
FIT

Devil's Advocacy When Consensus Forms Too Fast

Fast agreement with no pushback is the signal, not proof the call was right
If a team lands on the same conclusion in the first ten minutes with no real disagreement, that's the moment to assign someone the counter-argument. Skip it for findings with hard technical evidence behind them, like a hash match against a known sample or a validated signed binary, there's nothing left to argue against.