Requires durable sensitive records linking personas, identifiers, and case activity
Source references: 5The runbook requires recording every identifier, its creation date and use, plus every session, and retaining burned numbers or addresses after retirement. Although the parent guidance recommends encrypted storage, these centralized records still become high-value data linking people, cases, devices, and operational timing.
If a case directory, vault, backup, or shared report is accessed without authorization, it could reveal investigation targets, activity patterns, account identities, and organizational attribution. It could also let an observer correlate personas that were intended to remain separate. Long retention extends the exposure window.
The runbook explicitly centralizes persona identifiers, creation dates, usage locations, session history, and case actions, while retaining burned numbers or addresses after retirement. Encrypted case storage and retention-based deletion mitigate the risk, but the identifier record is still retained. If exposed or broadly accessible, it could reveal cases, timelines, and investigative infrastructure and indirectly link operators. Users can ask for mandatory encryption, least-privilege access, auditing, fixed retention periods, and irreversible fingerprints instead of full retired numbers or addresses.
Every identifier gets recorded in the persona's file with its creation date andwhere it was used. An untracked persona is one you cannot safely retire.Show 4 other places
- Let it acquire a few incidental connections organically. Do not solicit them.- Keep a log of every session, so the persona's own pattern-of-life stays consistent when a different analyst uses it.Retire personas that were challenged, that touched a case that went adversarial,or that were used across cases by mistake. Retirement means: stop using it,record the retirement date and reason, keep the identifier record so a futureanalyst does not reuse a burned number or address, and delete the persona'scollected data under the case's retention rules in `write-the-intel-brief`.One case, one environment. A dedicated VM per case is the clean answer; adedicated browser profile is the minimum. Containerised tab isolation separatescookies but not fingerprint — a convenience, not a boundary. Across setups: nopersonal accounts ever signed in; snapshot clean and roll back between cases;keep notes and downloads in the case's encrypted store; never open a target'sdocument or PDF in an environment that can reach your real identity. pretext you have no authorization to make, or elicit information from people.- Log what the persona did, when, and what it saw, and archive the pages via `read-deleted-pages` — the persona's access may not survive to be re-checked.