ASOM-Fedv6.1Open the explorer
Operating procedure · Phase 0

A Thousand Devices Is Not a Hunt Scope.

No hypothesis fits a thousand hosts. Ask “is there anything bad on the network” and there is no query that answers it, no population to run against, and no condition under which you are finished. This is the procedure that replaces the question: reduce the estate to rooms, rank them, and clear them one at a time by a drill that produces a dated, falsifiable statement each time it runs.

1,000 devices26 segments80 rooms2 hunters to hold it
Step One

Stop Counting Devices.

The unit of work is the room: one segment, examined at one terrain layer, against one hypothesis. Not a subnet — a subnet is a piece of ground, and a room is a piece of ground plus the question being asked of it. The same subnet therefore appears three or four times, once per layer that matters on it.

The pairing is what makes a clearing statement decidable. “The finance VLAN is clear” cannot be falsified by anybody. “On the finance VLAN, at the device layer, no host executed an unsigned binary from a user-writable path in the last thirty days” has a population, a window, and a way of being wrong.

Exhibit 1

The Reduction, at True Proportion — One Dot per Device.

A thousand devices is not the unit of work — 80 rooms is Every count here is computed from the archetype estate, including the dots. WHAT YOU HAVE 1,000 devices HOW IT IS GROUND 26 segments Public service tier ×2 Public service tier — 2 segments, 60 devices. The portal and what stands directly behind it. Small, and first every time. Mission application tier ×4 Mission application tier — 4 segments, 180 devices. Case processing and the services it calls. Holds the CI/CD decisive point. Identity and directory ×1 Identity and directory — 1 segment, 25 devices. The high ground. One segment, and the one whose compromise makes the other twenty-five academic. Supplier and partner inte… ×2 Supplier and partner interconnect — 2 segments, 20 devices. Twenty devices and the widest exposure on the estate. Standing access outlives the work order it was granted for. Records and data stores ×2 Records and data stores — 2 segments, 40 devices. What the adversary came for. Rarely the first ground touched, always the objective. Management and out-of-band ×2 Management and out-of-band — 2 segments, 45 devices. The path that bypasses every obstacle you sited. Under-hunted in proportion to how dangerous it is. Facilities and building s… ×3 Facilities and building systems — 3 segments, 90 devices. Ground the endpoint console has never heard of. Most of its rooms exit at NOT COMPUTED the first time through, and that is the finding. Enterprise IT and user VL… ×8 Enterprise IT and user VLANs — 8 segments, 520 devices. Half the device count and a fifth of the priority. This is the arithmetic that makes a thousand devices survivable. Lab and development ×2 Lab and development — 2 segments, 20 devices. Clears fast and cheaply. Worth doing when a cycle has slack, never worth doing first. WHAT YOU CLEAR 80 rooms Public service tier #1 × T2 — one room Public service tier #1 × T3 — one room Public service tier #1 × T4 — one room Public service tier #2 × T2 — one room Public service tier #2 × T3 — one room Public service tier #2 × T4 — one room Mission application tier #1 × T2 — one room Mission application tier #1 × T3 — one room Mission application tier #1 × T4 — one room Mission application tier #1 × T5 — one room Mission application tier #2 × T2 — one room Mission application tier #2 × T3 — one room Mission application tier #2 × T4 — one room Mission application tier #2 × T5 — one room Mission application tier #3 × T2 — one room Mission application tier #3 × T3 — one room Mission application tier #3 × T4 — one room Mission application tier #3 × T5 — one room Mission application tier #4 × T2 — one room Mission application tier #4 × T3 — one room Mission application tier #4 × T4 — one room Mission application tier #4 × T5 — one room Identity and directory #1 × T1 — one room Identity and directory #1 × T2 — one room Identity and directory #1 × T3 — one room Supplier and partner interconnect #1 × T1 — one room Supplier and partner interconnect #1 × T3 — one room Supplier and partner interconnect #1 × T9 — one room Supplier and partner interconnect #2 × T1 — one room Supplier and partner interconnect #2 × T3 — one room Supplier and partner interconnect #2 × T9 — one room Records and data stores #1 × T3 — one room Records and data stores #1 × T5 — one room Records and data stores #2 × T3 — one room Records and data stores #2 × T5 — one room Management and out-of-band #1 × T2 — one room Management and out-of-band #1 × T3 — one room Management and out-of-band #1 × TX — one room Management and out-of-band #2 × T2 — one room Management and out-of-band #2 × T3 — one room Management and out-of-band #2 × TX — one room Facilities and building systems #1 × T3 — one room Facilities and building systems #1 × T6 — one room Facilities and building systems #1 × T8 — one room Facilities and building systems #2 × T3 — one room Facilities and building systems #2 × T6 — one room Facilities and building systems #2 × T8 — one room Facilities and building systems #3 × T3 — one room Facilities and building systems #3 × T6 — one room Facilities and building systems #3 × T8 — one room Enterprise IT and user VLANs #1 × T2 — one room Enterprise IT and user VLANs #1 × T3 — one room Enterprise IT and user VLANs #1 × T7 — one room Enterprise IT and user VLANs #2 × T2 — one room Enterprise IT and user VLANs #2 × T3 — one room Enterprise IT and user VLANs #2 × T7 — one room Enterprise IT and user VLANs #3 × T2 — one room Enterprise IT and user VLANs #3 × T3 — one room Enterprise IT and user VLANs #3 × T7 — one room Enterprise IT and user VLANs #4 × T2 — one room Enterprise IT and user VLANs #4 × T3 — one room Enterprise IT and user VLANs #4 × T7 — one room Enterprise IT and user VLANs #5 × T2 — one room Enterprise IT and user VLANs #5 × T3 — one room Enterprise IT and user VLANs #5 × T7 — one room Enterprise IT and user VLANs #6 × T2 — one room Enterprise IT and user VLANs #6 × T3 — one room Enterprise IT and user VLANs #6 × T7 — one room Enterprise IT and user VLANs #7 × T2 — one room Enterprise IT and user VLANs #7 × T3 — one room Enterprise IT and user VLANs #7 × T7 — one room Enterprise IT and user VLANs #8 × T2 — one room Enterprise IT and user VLANs #8 × T3 — one room Enterprise IT and user VLANs #8 × T7 — one room Lab and development #1 × T2 — one room Lab and development #1 × T3 — one room Lab and development #1 × T4 — one room Lab and development #2 × T2 — one room Lab and development #2 × T3 — one room Lab and development #2 × T4 — one room Not a work queue. No hypothesis fits a thousand hosts. Height is device count. Order is clearing priority. One segment × one layer. About 13 devices each. TM-1 overlay × layer in scope

Computed from the archetype estate, including the dots. A thousand hosts is not a work queue; 26 segments is a map; 80 rooms is a schedule. Eighty is a number you can put dates against, and a thousand is not.

It Comes from the Overlay, Not the Console

That is not a preference. An endpoint console reports on what it is installed on, so it will always answer 100%, and the hosts it never knew about are precisely the ones worth hunting. The population comes from terrain inventory (TM-1), which is the only artifact that knows about ground no agent was ever deployed to.

It Scales Sublinearly

Ten thousand devices is not ten times the work. It is more segments, but the same layers, and the room count grows with how the estate is partitioned rather than with how many things are in it. Estates acquire hosts far faster than they acquire segments, which is why this is the reduction that makes the problem finite.

Step Two

Decide Which Room Is First.

A command decision, taken at Array and owned by the Authorizing Official. It is the point at which the main effort is designated (SM-4) and the only point at which the estate is looked at whole. It is not the analyst’s call, and it is not a standing preference.

The rank is deliberately crude — three small integers multiplied, then decayed by how recently the room was cleared: consequence × exposure × proximity × staleness.

Consequence 1–5
What it costs if this ground is held by someone else. Mission impact, not asset price. Source: Your asset register.
Exposure 1–5
How many mapped avenues terminate in this segment or transit it. Source: Avenues of approach (KT-3).
Proximity 1–3
Contains a decisive point (3), adjacent to one (2), or neither (1). Source: Decisive points (KT-1).
Staleness ×1 to ×3
Cycles since this room was last cleared, capped. Never cleared takes the cap. Source: Hunt results — last clearance date.

A more sophisticated score would be harder to argue with in a room full of people who disagree, and being argued with is the entire point of publishing the order. A stakeholder who thinks their segment is ranked too low can see exactly which of the three numbers to contest.

Exhibit 2

The Same Nine Classes, Plotted.

Device count is not priority — the board shows it before you read a number Consequence × exposure, area by room count, numbered in clearing order. Both axes from the estate’s own scoring. CLEAR FIRST WATCH SCHEDULE WHEN THERE IS SLACK 8 8. Enterprise IT and user VLANs — consequence 3, exposure 4, 24 rooms, 520 devices. Half the device count and a fifth of the priority. This is the arithmetic that makes a thousand devices survivable. 2 2. Mission application tier — consequence 5, exposure 3, 16 rooms, 180 devices. Case processing and the services it calls. Holds the CI/CD decisive point. 7 7. Facilities and building systems — consequence 4, exposure 3, 9 rooms, 90 devices. Ground the endpoint console has never heard of. Most of its rooms exit at NOT COMPUTED the first time through, and that is the finding. 1 1. Public service tier — consequence 5, exposure 5, 6 rooms, 60 devices. The portal and what stands directly behind it. Small, and first every time. 4 4. Supplier and partner interconnect — consequence 4, exposure 5, 6 rooms, 20 devices. Twenty devices and the widest exposure on the estate. Standing access outlives the work order it was granted for. 6 6. Management and out-of-band — consequence 5, exposure 2, 6 rooms, 45 devices. The path that bypasses every obstacle you sited. Under-hunted in proportion to how dangerous it is. 9 9. Lab and development — consequence 2, exposure 2, 6 rooms, 20 devices. Clears fast and cheaply. Worth doing when a cycle has slack, never worth doing first. 5 5. Records and data stores — consequence 5, exposure 2, 4 rooms, 40 devices. What the adversary came for. Rarely the first ground touched, always the objective. 3 3. Identity and directory — consequence 5, exposure 3, 3 rooms, 25 devices. The high ground. One segment, and the one whose compromise makes the other twenty-five academic. 1 1 2 2 3 3 4 4 5 5 CONSEQUENCE → EXPOSURE → IN CLEARING ORDER 1 Public service tier 6r 2 Mission application tier 16r 3 Identity and directory 3r 4 Supplier and partner inte… 6r 5 Records and data stores 4r 6 Management and out-of-band 6r 7 Facilities and building s… 9r 8 Enterprise IT and user VL… 24r 9 Lab and development 6r Area is room count. The biggest circle on the board is 24 rooms holding 520 of 1000 devices — 52% of the fleet — and it lands at middling consequence, outside CLEAR FIRST. The 2 classes inside that quadrant hold 80 devices between them. Sequencing by device count would invert this board, and that is the argument the whole clearing order rests on.

The ranking table below is this picture sorted. Reading them together is the point: the matrix shows why the order is what it is, and the board shows where this cycle stops.

Exhibit 3

The Board, with the Arithmetic Showing and a Line Where This Cycle’s Throughput Runs Out.

The clearing board — which room first, and where this cycle stops consequence × exposure × proximity × staleness. Three small integers and a decay, so the order can be argued with in a meeting. SEGMENT CLASS C × E × P × STALE PRIORITY ROOMS DEVICES Public service tier T2 T3 T4 5 × 5 × 3 × 3 225 6 60 Public service tier — priority 225, 6 rooms, 60 devices. The portal and what stands directly behind it. Small, and first every time. Mission application tier T2 T3 T4 T5 5 × 3 × 3 × 3 135 16 180 Mission application tier — priority 135, 16 rooms, 180 devices. Case processing and the services it calls. Holds the CI/CD decisive point. Identity and directory T1 T2 T3 5 × 3 × 3 × 3 135 3 25 Identity and directory — priority 135, 3 rooms, 25 devices. The high ground. One segment, and the one whose compromise makes the other twenty-five academic. Supplier and partner interconnect T1 T3 T9 4 × 5 × 2 × 3 120 6 20 Supplier and partner interconnect — priority 120, 6 rooms, 20 devices. Twenty devices and the widest exposure on the estate. Standing access outlives the work order it was granted for. Records and data stores T3 T5 5 × 2 × 3 × 3 90 4 40 Records and data stores — priority 90, 4 rooms, 40 devices. What the adversary came for. Rarely the first ground touched, always the objective. Management and out-of-band T2 T3 TX 5 × 2 × 2 × 3 60 6 45 Management and out-of-band — priority 60, 6 rooms, 45 devices. The path that bypasses every obstacle you sited. Under-hunted in proportion to how dangerous it is. Facilities and building systems T3 T6 T8 4 × 3 × 1 × 3 36 9 90 Facilities and building systems — priority 36, 9 rooms, 90 devices. Ground the endpoint console has never heard of. Most of its rooms exit at NOT COMPUTED the first time through, and that is the finding. Enterprise IT and user VLANs T2 T3 T7 3 × 4 × 1 × 3 36 24 520 Enterprise IT and user VLANs — priority 36, 24 rooms, 520 devices. Half the device count and a fifth of the priority. This is the arithmetic that makes a thousand devices survivable. Lab and development T2 T3 T4 2 × 2 × 1 × 3 12 6 20 Lab and development — priority 12, 6 rooms, 20 devices. Clears fast and cheaply. Worth doing when a cycle has slack, never worth doing first. THIS CYCLE ENDS HERE — 31/32 ROOMS Device count is not priority. The top four classes hold 285 of 1000 devices and all of the decisive points; the user VLANs hold 52% of the fleet and rank eighth of nine. That inversion is the finding, and it is arithmetic rather than taste. Staleness is shown at its cap (×3) — the state every room is in before the first pass. It falls to ×1 the cycle after a room is cleared, which is what rotates the board.

Device count is not priority. The user VLANs hold 52% of the fleet and rank eighth of nine, while twenty-five identity hosts rank second. A hunt program that works an asset list in numerical order has already forfeited most of the value available to it — and the inversion here is arithmetic rather than taste.

Step Three

The Drill.

The drill is seven steps, performed identically in every room. Each sits inside a cycle step that already exists, cites the controls that govern it, and carries a gate — the condition that must hold before the next step may begin. A step whose gate fails is not skipped. It sends the room somewhere.

Exhibit 4

The Drill as a Flow, Bracketed by the Two Cycle-Scope Steps Around It.

The clearing drill — seven steps, run once per room, with the gate on each Every step sits inside a cycle step that already exists. Nothing here is a new object; the scope is the new part. SEQUENCE · ONCE PER CYCLE · ARRAY Rank the rooms and draw the line at what this cycle can actually reach. Choosing the order is a command decision, not an analyst’s. It is where the main effort is designated, and it is the only step at which the estate is looked at whole. Sequence — Rank the rooms and draw the line at what this cycle can actually reach. Choosing the order is a command decision, not an analyst’s. It is where the main effort is designated, and it is the only step at which the estate is looked at whole. 1 Declare FRAME · CE-2 Write the hypothesis, and write what would falsify it. Declare — Write the hypothesis, and write what would falsify it. Fails as: Collecting first and forming the question from what came back. The finding is then guaranteed and worthless — it is a description of the telemetry, not a test of the ground. GATE Can you state what you would have to see to be wrong? No falsifier means no hunt. Return the room to the queue and re-frame it. 2 Bound MAP · TM-1 · TM-6 · TM-7 Take the room’s population from the terrain overlay, not from a tool console. Bound — Take the room’s population from the terrain overlay, not from a tool console. Fails as: Letting the EDR console define the population. It reports on what it is installed on, so it will answer 100% every time, and the hosts it never knew about are exactly the ones worth hunting. GATE Is the overlay entry for this segment younger than its refresh cadence? A stale overlay makes every later percentage a guess. Refresh the entry first; that is Map work, and it is cheap next to a wrong denominator. 3 Reach MAP · DV-3 · KT-4 · M1 Split the population into what your telemetry can actually see in the window, and what it cannot. Reach — Split the population into what your telemetry can actually see in the window, and what it cannot. Fails as: Treating the unreachable set as an inconvenience to be resolved later. It is the finding. An adversary that has chosen its ground has chosen ground you cannot see. GATE Is the reachable share above the floor this room’s consequence requires? Below the floor the sweep cannot produce a clearance, only an anecdote. Run it anyway if it is cheap, but the room exits at NOT COMPUTED and the gap goes to the backlog. 4 Sweep MANEUVER · SM-2 · CG-3 · M1 · M5 Run the technique against the reachable set. The technique’s stated indicator is the clearing standard — do not invent a looser one at the keyboard. Sweep — Run the technique against the reachable set. The technique’s stated indicator is the clearing standard — do not invent a looser one at the keyboard. Fails as: Widening the query until something comes back. The hunt then measures the analyst’s persistence rather than the ground’s condition. GATE Did the sweep complete over the whole reachable set, or did it time out part-way? A partial sweep silently shrinks the denominator you already fought for. Re-run against the remainder or move the remainder into the unreachable set explicitly. 5 Adjudicate FUSE · CE-3 Assign one of three verdicts and a confidence with a stated basis. Adjudicate — Assign one of three verdicts and a confidence with a stated basis. Fails as: Collapsing three outcomes into two. Everything that is not contact becomes "clear", the unreachable remainder disappears into it, and coverage becomes a number that only goes up. GATE Which of the three exits does the evidence support? There is no fourth exit. "Probably fine" is NOT COMPUTED wearing a confident face. CONTACT The indicator was observed. The hypothesis survived the attempt to kill it. Stop clearing. The cycle changes phase and the reactive path takes over. CONTACT (verdict met) — The indicator was observed. The hypothesis survived the attempt to kill it. Stop clearing. The cycle changes phase and the reactive path takes over. Does not add to coverage. Clearing resumes after the engagement, from a re-derived overlay. CLEARED The hypothesis was falsified across the reachable population, inside the window. Mark it, hold it, take the next room. CLEARED (verdict not-met) — The hypothesis was falsified across the reachable population, inside the window. Mark it, hold it, take the next room. Adds to coverage — for as long as its expiry says, and no longer. NOT COMPUTED The reachable share was too small, or the window too short, to decide either way. Re-queue the room and raise the collection gap as next cycle’s intelligence requirement. NOT COMPUTED (verdict not-computed) — The reachable share was too small, or the window too short, to decide either way. Re-queue the room and raise the collection gap as next cycle’s intelligence requirement. Adds to the remainder, which is published beside coverage rather than netted out of it. only CLEARED continues leaves the loop — reactive path re-queue, raise a PCIR — 6 Hold MANEUVER · SM-2 · SM-7 · KT-5 · M2 · M4 · M5 Emplace something that keeps the room clear after you leave — an obstacle, a sensor, or a policy. Hold — Emplace something that keeps the room clear after you leave — an obstacle, a sensor, or a policy. Fails as: Clearing without holding. That is patrolling: the same rooms are re-hunted forever, coverage never accumulates, and the team’s effort is spent re-establishing what it already knew. GATE Is there now something in the room that would notice a change? Then the clearance expires the moment you leave, and the honest expiry is one cycle rather than three. Record it that way. 7 Mark ASSESS · CE-4 · CE-6 · CG-4 Write the clearance record: scope, window, fidelity, falsifier, holder, and expiry. Mark — Write the clearance record: scope, window, fidelity, falsifier, holder, and expiry. Fails as: Recording the verdict without the window and the fidelity. A clearance with no window is undated, so it can never expire, so the coverage figure built on it never decays and quietly becomes fiction. GATE Could a different analyst re-run this from the record alone? Then it is a memory, not a mark, and the next cycle will clear this room again from scratch. NEXT ROOM — 80× PER PASS ROLL UP · ONCE PER CYCLE · ASSESS Publish coverage with the unreachable remainder in the same sentence. A cleared fraction reported without its remainder is the number that made everyone comfortable last quarter. The two travel together or neither is published. Roll up — Publish coverage with the unreachable remainder in the same sentence. A cleared fraction reported without its remainder is the number that made everyone comfortable last quarter. The two travel together or neither is published.

Note the fan at step 5: three exits, not two. Every hunt flowchart ever drawn has “found” and “not found”. The third exit is where the honesty lives, and dropping it is what turns a hunt program into a reassurance service.

SEQUENCE · ONCE PER CYCLE · ARRAY

Rank the rooms and draw the line at what this cycle can actually reach. Choosing the order is a command decision, not an analyst’s. It is where the main effort is designated, and it is the only step at which the estate is looked at whole.

  1. 1

    Declare

    Write the hypothesis, and write what would falsify it.

    Gate. Can you state what you would have to see to be wrong? No falsifier means no hunt. Return the room to the queue and re-frame it.

    Fails as: Collecting first and forming the question from what came back. The finding is then guaranteed and worthless — it is a description of the telemetry, not a test of the ground.

    FRAME · CE-2

  2. 2

    Bound

    Take the room’s population from the terrain overlay, not from a tool console.

    Gate. Is the overlay entry for this segment younger than its refresh cadence? A stale overlay makes every later percentage a guess. Refresh the entry first; that is Map work, and it is cheap next to a wrong denominator.

    Fails as: Letting the EDR console define the population. It reports on what it is installed on, so it will answer 100% every time, and the hosts it never knew about are exactly the ones worth hunting.

    MAP · TM-1 · TM-6 · TM-7

  3. 3

    Reach

    Split the population into what your telemetry can actually see in the window, and what it cannot.

    Gate. Is the reachable share above the floor this room’s consequence requires? Below the floor the sweep cannot produce a clearance, only an anecdote. Run it anyway if it is cheap, but the room exits at NOT COMPUTED and the gap goes to the backlog.

    Fails as: Treating the unreachable set as an inconvenience to be resolved later. It is the finding. An adversary that has chosen its ground has chosen ground you cannot see.

    MAP · DV-3 · KT-4 · M1

  4. 4

    Sweep

    Run the technique against the reachable set. The technique’s stated indicator is the clearing standard — do not invent a looser one at the keyboard.

    Gate. Did the sweep complete over the whole reachable set, or did it time out part-way? A partial sweep silently shrinks the denominator you already fought for. Re-run against the remainder or move the remainder into the unreachable set explicitly.

    Fails as: Widening the query until something comes back. The hunt then measures the analyst’s persistence rather than the ground’s condition.

    MANEUVER · SM-2 · CG-3 · M1 · M5

  5. 5

    Adjudicate

    Assign one of three verdicts and a confidence with a stated basis.

    Gate. Which of the three exits does the evidence support? There is no fourth exit. "Probably fine" is NOT COMPUTED wearing a confident face.

    Fails as: Collapsing three outcomes into two. Everything that is not contact becomes "clear", the unreachable remainder disappears into it, and coverage becomes a number that only goes up.

    FUSE · CE-3

  6. 6

    Hold

    Emplace something that keeps the room clear after you leave — an obstacle, a sensor, or a policy.

    Gate. Is there now something in the room that would notice a change? Then the clearance expires the moment you leave, and the honest expiry is one cycle rather than three. Record it that way.

    Fails as: Clearing without holding. That is patrolling: the same rooms are re-hunted forever, coverage never accumulates, and the team’s effort is spent re-establishing what it already knew.

    MANEUVER · SM-2 · SM-7 · KT-5 · M2 · M4 · M5

  7. 7

    Mark

    Write the clearance record: scope, window, fidelity, falsifier, holder, and expiry.

    Gate. Could a different analyst re-run this from the record alone? Then it is a memory, not a mark, and the next cycle will clear this room again from scratch.

    Fails as: Recording the verdict without the window and the fidelity. A clearance with no window is undated, so it can never expire, so the coverage figure built on it never decays and quietly becomes fiction.

    ASSESS · CE-4 · CE-6 · CG-4

The Three Exits

CLEARED

The hypothesis was falsified across the reachable population, inside the window.

Mark it, hold it, take the next room.

Adds to coverage — for as long as its expiry says, and no longer.

CONTACT

The indicator was observed. The hypothesis survived the attempt to kill it.

Stop clearing. The cycle changes phase and the reactive path takes over.

Does not add to coverage. Clearing resumes after the engagement, from a re-derived overlay.

NOT COMPUTED

The reachable share was too small, or the window too short, to decide either way.

Re-queue the room and raise the collection gap as next cycle’s intelligence requirement.

Adds to the remainder, which is published beside coverage rather than netted out of it.

ROLL UP · ONCE PER CYCLE · ASSESS

Publish coverage with the unreachable remainder in the same sentence. A cleared fraction reported without its remainder is the number that made everyone comfortable last quarter. The two travel together or neither is published.

Step Four

The Arithmetic That Says Whether You Can Afford It.

The question behind the question. A procedure that works beautifully on one segment and cannot be run across the estate is a demonstration, not a capability. The governing fact is that a clearance expires.

Which makes coverage a rate rather than an achievement. A team clearing R rooms per cycle, where a clearance stands for 3 cycles, sustains R × 3 cleared rooms and no more — however the result is written up, and no matter how much reporting discipline is applied to it. Terrain change takes a slice off the top first: about 6% of rooms per cycle are invalidated by a change to the ground beneath them, which is roughly 5 rooms here.

Exhibit 5

Throughput Against the Coverage It Can Honestly Hold.

Is it scalable? — throughput against the coverage it can honestly hold A clearance expires, so coverage is a rate, not an achievement. The curve is a ceiling no reporting discipline raises. 0% 25% 50% 75% 100% CHURN EATS IT ALL 12% 8 0.5 hunters 0.5 hunters at 8 hunt-days a cycle clears 8 rooms, sustaining 12% of the estate. 42% 16 1 hunter 1 hunter at 8 hunt-days a cycle clears 16 rooms, sustaining 42% of the estate. 100% 32 2 hunters 2 hunters at 8 hunt-days a cycle clears 32 rooms, sustaining 100% of the estate. ROOMS CLEARED PER 30-DAY CYCLE CLEARED, HONESTLY THE CEILING cleared fraction = (R × 3 cycles) ÷ 80 rooms R = rooms cleared per cycle, less 4.8 lost to churn 3 cycles = how long a clearance stands before it expires THE ANSWER 2 hunters hold all 80 rooms — 1,000 devices — at 32 rooms and 16 analyst-days a cycle.

The curve is a ceiling. Below the churn line a team is losing ground faster than it takes it, and its published coverage figure describes rooms whose clearance has already lapsed — the most common failure state for a hunt program, and an invisible one from the inside.

1,000DevicesIn 26 segments
80RoomsSegment × layer — the unit of work
32Rooms per 30-day cycleTo hold all of them
2Hunters16 analyst-days a cycle

Two hunters. That is the answer to “is this scalable”, and it is worth being precise about what makes it true: the estate is held not because two people can examine a thousand devices, but because eighty rooms at half an analyst-day each is sixteen analyst-days, and sixteen analyst-days is two people spending eight days a cycle hunting. Change any input and the arithmetic follows honestly. Halve the hunt time and coverage settles at 49% — a defensible posture, as long as it is reported as 49%.

What this buys that a coverage percentage does not: which ground is currently cleared, with dates; which ground has never been reachable, which is a collection-gap backlog and a budget argument rather than a shrug; and what a marginal hunter is worth, which turns “we need more people” into a specific claim about a specific percentage.

Step Five

What You Publish at the End of the Pass.

Coverage and the remainder belong in the same sentence, always. CE-4 already requires the denominator to be stated; clearing makes that cheap to satisfy, because the denominator was established at step 2 of every room and the remainder at step 3.

Cycle 7 — 31 rooms attempted, 26 cleared, 1 contact, 4 not computed.
Cleared ground now 58/80 rooms (73%), against a denominator taken from the terrain overlay.
The 4 not-computed rooms are all in facilities and building systems, where sensor coverage reaches 12% of the population; that gap is next cycle’s first intelligence requirement.
Nine cleared rooms expire before cycle 9 and are already queued.

Note what that paragraph makes impossible. It cannot be read as “we are 73% secure”, because the ground and the window are attached to the number. It cannot silently carry a stale clearance, because expiries are stated. And it cannot bury the facilities gap, because the gap is in the same four lines as the result — which is the outcome the worked proactive case arrived at the long way round, on a single corridor, over seven days.

On Scope

No New Objects. One New Scope.

A fair question, and worth answering precisely — “we added a thing to the framework” is the easiest and least useful response to a hard operational question.

Existing
The seven steps

All seven sit inside the six cycle steps. Declare is Frame, Bound and Reach are Map, Sweep and Hold are Maneuver, Adjudicate is Fuse, Mark is Assess.

Existing
Three verdicts

The published hunt cases already carry met, not-met and not-computed, and record what each beat did not establish.

Existing
The clearance record

Hunt results, including negative results — already a first-class published product. Its negative half is the clearance record under another name.

Existing
The honest denominator

CE-4 already requires coverage to be computed over the overlay population, with the denominator stated.

Existing
Sequencing

Main effort designation (SM-4) and remediation backlog prioritization (CE-5), at Array.

New
The room

New — and not an object class. A scope: the (segment × layer) pair a single falsifiable hypothesis fits inside.

New
Expiry

New as a number. The framework said clearances go stale; it did not say how fast, and without a rate the throughput arithmetic cannot be done at all.

So the framework did not need eleven forms of maneuver to become twelve. It needed the cycle run at a scope small enough for a hypothesis to fit, repeatedly, with the results accumulating into a number that decays. If a future version promotes clearing to a named form, that is a decision about the admission criteria for forms — and it should be argued there, on those criteria, rather than settled here.

Getting Started

The Smallest Honest Version Fits in One Cycle.

  1. 1

    Draw the segments

    Not the assets — the segments, with an owner each. If this takes more than a day, that is itself the first finding, and it is a TM-1 finding.

  2. 2

    Score the three factors

    For each segment, in a meeting, in an hour. Publish the order and let people argue with it.

  3. 3

    Clear one room

    The top segment’s highest-consequence layer. Run all seven steps and write the clearance record even though it feels like overhead at a sample size of one. The record is the artifact; the finding is a by-product.

  4. 4

    Count how long it took

    That is your R, and the curve above turns it into a coverage ceiling and a staffing number the same afternoon.

  5. 5

    Publish the ceiling, not the aspiration

    A program that opens with “at current staffing we can honestly hold 45% of the estate” has more credibility than one reporting 100% coverage of an undefined denominator — and it has an argument attached.

Next

Every Step of the Drill Cites a Control That Governs It.

The drill is not a separate methodology bolted onto the framework. It is the same six-step loop, turned at a scope small enough for one falsifiable question to fit inside, many times per cycle instead of once. Reading the loop at full estate scope is the shortest way to see why the room-scale version inherits its gates.