About Contact Careers
UNCLASSIFIED // FOR HUMOROUS USE ONLY
Photo by Markus Winkler on Unsplash
Policy Briefing

INVESTIGATING DENIABLE OPERATIONS

Author The Uncertainty Department
Published March 15, 2026
Document UD-MANUAL-004
Abstract A field manual for investigative journalists, oversight staff, and civil liberties attorneys examining tacitly sanctioned COINTELPRO-like activity, built around the systematic exploitation of the mundane residual records — fuel logs, scheduling, invoices — that deniable operations were never designed to sanitize.

INVESTIGATING DENIABLE OPERATIONS

THE UNCERTAINTY DEPARTMENT
Practitioner Manual Series


PREFACE

When the FBI’s COINTELPRO program was exposed by the Church Committee in 1975, the revelation was not merely that the Bureau had broken the law. It was that a systematic, years-long campaign of surveillance, harassment, and political disruption had operated in plain sight of supervisors who understood exactly what was happening — and that the existing legal and oversight architecture had been entirely inadequate to stop it.

The institutional conditions that enabled COINTELPRO have not been eliminated. They have been refined.

Contemporary deniable operations are more legally sophisticated than their predecessors, more diffuse in their network structures, and more deliberately calibrated to exploit the gaps between what the law prohibits and what it can prove. The Church Committee’s methodologies — public hearings, document discovery, insider disclosure — remain available but face a more deliberately resistant architecture. This manual is written to supplement those methodologies with an analytical framework designed for the architecture as it currently exists.

The manual is intended for investigative journalists working national security and civil liberties beats; congressional oversight staff conducting agency investigations; inspector general offices examining systemic patterns in law enforcement conduct; and civil liberties attorneys building federal civil rights cases where the harm is distributed across actors rather than concentrated in any single chargeable act.

A fundamental methodological principle: The most important records in a deniable operation investigation are frequently the ones that were never supposed to exist in the first place — the mundane documentation generated by ordinary operational activity that no one thought to sanitize. Fuel records. Personnel scheduling. Grant disbursements. Contractor invoices. The investigative strategy described in this manual is built around the systematic exploitation of these residual records.


PART ONE: THE LEGAL ARCHITECTURE OF DENIABILITY

The Core Problem Federal Actors Face

Direct federal participation in surveillance, harassment, or political disruption triggers Fourth Amendment constraints, Bivens civil liability, statutory limits under FISA and the Privacy Act, and congressional oversight obligations. The operative solution developed over decades is not to avoid the activity. It is to avoid the legal nexus between the activity and the state actor.

Layer 1: The Private Actor Doctrine Exploit

The Fourth Amendment and most federal surveillance statutes constrain only state actors. This creates a structural loophole: private individuals conducting surveillance, harassment, or disruption campaigns generate no constitutional violation as long as federal handlers do not direct the specific conduct.

The legal line is agency — whether the private actor is functioning as a government instrument. Courts apply a totality test that is notoriously difficult to satisfy. Passive encouragement, general funding, and after-the-fact receipt of information gathered by a private party have all been held insufficient to establish agency. This means a federal actor can:

  • Brief a private party on a target
  • Receive information gathered by that party
  • Decline to prosecute conduct that party engages in
  • Provide general resources to an organization the party belongs to

…without converting that party into a state actor, provided there is no specific direction of specific investigative acts. The investigative challenge is establishing direction where the architecture is specifically designed to prevent it from appearing in any record.

Layer 2: The Fusion Center Model

Fusion centers — regional intelligence-sharing facilities that combine federal, state, and local law enforcement personnel under deliberately ambiguous command structures — were created with the stated purpose of improving information sharing. A secondary effect is the production of accountability gaps.

When an activity is conducted by state or local law enforcement personnel operating under federal information sharing protocols, the question of whether the activity was federally directed depends on which command structure is operative at any given moment, which is not always clear even to the participants. Federal personnel can access, direct, and benefit from activities conducted nominally under state or local authority, while maintaining plausible distance from those activities’ legal exposure.

Layer 3: Prosecution Declination as Authorization

The most underappreciated element of deniable operation architecture is the role of prosecution declination. When a private party engages in conduct against a target and the relevant U.S. Attorney’s office declines to prosecute, the non-prosecution is not merely inaction. It is a signal to the private party — and to other potential participants — that this category of conduct will not be criminally enforced.

Prosecution declination is difficult to distinguish from ordinary prosecutorial discretion without access to the internal deliberations behind the decision. The investigative question is whether declination was explained to the acting party, by what channel, and whether the explanation amounted to tacit authorization to continue. This is one of the most important questions an investigation can ask and one of the hardest to answer from available records.

Layer 4: Classification as Accountability Shield

Classification authority can be used as a mechanism to prevent oversight of activity that would not survive oversight. When a program is classified, its existence, its authorization, its conduct, and its outcomes are all removed from the arenas — courts, Congress, journalism — where accountability would otherwise be applied.

This does not mean that classified programs cannot be investigated. It means that the investigation must proceed from unclassified residual records — the activity’s footprint in financial systems, personnel records, and contractor databases — rather than from the program’s own documentation.


PART TWO: PROXY NETWORK TYPOLOGY

Understanding the proxy network is the analytical prerequisite for the investigative methodology. Operations do not consist of a single identifiable actor committing identifiable acts. They consist of multiple partially-informed participants, each acting within a plausible frame, whose aggregate activity produces an effect that no single participant’s activity would generate or could be accountable for.

Type 1: Formal Informant Networks

Paid informants operating under formal FBI or other agency handling relationships. These relationships are documented internally but not publicly. The informant’s conduct can be authorized by their handler in ways that are not apparent to outside observers and that generate no publicly accessible record.

Investigative approach: FOIA requests targeting informant payment records (often heavily redacted but structurally informative), cross-referencing names appearing in civil rights litigation, and identifying individuals who appear in proximity to multiple targets over time.

Type 2: Civil Society Cutouts

Organizations that appear to be independent civic entities but are funded through attenuated channels that lead back to federal or federal-adjacent sources. These are the most difficult proxy type to identify because their apparent independence is often genuine at the organizational level — members may sincerely believe in the organization’s stated mission — while the funding architecture creates structural dependencies that shape activity.

Investigative approach: Deep financial analysis of nonprofit filings (Form 990), grant databases (USASpending.gov, SAM.gov), and contractor relationships. Look for funding patterns that shift when operational targets shift.

Type 3: Local Law Enforcement as Federal Operational Arm

Local law enforcement agencies operating in fusion center environments can be directed toward targets through information-sharing channels without formal federal direction of specific acts. Officers may believe they are acting on independent investigative judgment while the judgment is structured by federally provided information about specific individuals.

Investigative approach: Public records requests for communications between local agencies and fusion centers; personnel assignments to fusion center roles; training records that may reveal federal operational priorities being transmitted to local personnel.

Type 4: Private Intelligence Contractors

Contractors who hold clearances and can access federal intelligence systems may conduct activities on behalf of federal clients while maintaining the legal status of private actors. The contractor relationship creates plausible distance between federal direction and private conduct.

Investigative approach: Contract databases (USASpending.gov, FPDS); subcontractor relationships; personnel cross-referencing between contractor rosters and individuals appearing in target-adjacent activity.

Type 5: The Aggregated Network

The critical analytical point is that each proxy type is designed to be investigatable in isolation and to reveal nothing. The operation lives in the pattern — in the coordination across proxy types that no single proxy can describe.

Identifying the aggregated network requires a methodology that begins with pattern detection rather than actor identification. The investigator who begins by looking for a single responsible actor will not find the operation. The investigator who begins by documenting the pattern of effects on the target, and works backward to the actor network that could produce that pattern, has the correct analytical orientation.


PART THREE: THE MECHANICS OF INSTITUTIONAL BLINDNESS

Deniable operations are sustained not only by active concealment but by the structured production of non-knowledge within the institutions that nominally oversee them.

Structured Ignorance

Supervisors can maintain operational awareness while preserving plausible non-knowledge through several mechanisms:

  • Oral briefings that are never committed to writing, on topics that will never appear in any retrievable record
  • Need-to-know compartmentalization that is applied not to protect classified information but to prevent supervisors from acquiring knowledge they would be required to act on
  • Euphemistic reporting in which activities are described in language that is accurate but does not communicate the nature of what is occurring to a supervisor who has not been separately briefed

The investigative question is not whether a supervisor knew. It is whether the institutional structure created conditions under which knowing or not knowing was a choice the supervisor could exercise — and whether that structure was designed with that optionality in mind.

Assignment Architecture as Implicit Direction

Personnel can be directed toward targets through assignment decisions rather than operational orders. An agent assigned to a geographic area where a target resides, paired with a supervisor who has a particular interest in that target, provided with information about the target’s activities, and given performance evaluations that reward activity in the target’s vicinity is being operationally directed without any single instruction that could be characterized as such.

The Coincidence Doctrine as Design Principle

Operations are calibrated to produce individual acts that are each, in isolation, defensible as coincidence — ordinary law enforcement activity, routine community engagement, normal commercial behavior — while the aggregate pattern of acts constitutes targeted disruption. The operation resides in the pattern; each element is plausibly coincidental.

This design principle is the central target of the pattern-first investigative methodology.


PART FOUR: INVESTIGATIVE METHODOLOGY

Step 1: Document the Effect Pattern

Begin with the target’s experience. Document, in contemporaneous and corroborated detail, the pattern of effects: what occurred, when, in what sequence, through what actors, with what apparent coordination. This is the evidentiary foundation for everything that follows. It is also the evidence that is hardest for the operation’s architecture to prevent from existing, because it is produced by the target rather than by the operation.

Step 2: Build the Actor Network

From the effect pattern, identify the actor network that could produce it. This requires reasoning from effects to causes: what level of coordination is implied by the observed pattern? What categories of actors would be required? What information flows are implied by the coordination?

Do not begin with named suspects. Begin with structural positions — roles that must exist in the network for the observed pattern to be possible — and identify who occupies them.

Step 3: Exploit Residual Records

The mundane records that operational security did not think to protect:

  • Fuel records and fleet management data — indexed to location, time, and vehicle, often without realizing they constitute an operational log
  • Financial records — grant disbursements, contractor invoices, expenditure reports filed under headings that obscure their operational purpose
  • Personnel records — assignments, training, evaluation criteria, performance records that reveal operational priorities
  • Communications metadata — even when content is unavailable, the pattern of who communicated with whom, when, is often sufficient to map the network structure

Step 4: FOIA Strategy

Design FOIA requests around the assumption that no formal case file exists. Request records that would be generated by the operation as a byproduct of ordinary administrative activity: travel records, expense reports, fleet records, calendar entries, personnel assignments, training records, grant applications and awards, contractor scope of work documents.

File with multiple agencies simultaneously. The same activity leaves records in different administrative systems; a request to one agency that produces nothing may be supplemented by records at another agency with overlapping jurisdiction.

Step 5: Financial Forensics

The financial record is often the most complete and least sanitized record of an operation. Focus on:

  • Non-profit filings (Form 990) for organizations in the target’s environment — funding sources, executive compensation, related-party transactions
  • Federal grant databases — who funded the organizations in the target’s environment, and when funding started and stopped relative to the target’s activities
  • Contractor records — which private intelligence or security contractors received federal funds, for what stated purpose, in what geographic area

Step 6: Network Centrality Analysis

Once the actor network is partially mapped, apply network centrality analysis to identify coordination points — actors who appear in multiple relationships within the network, whose position implies they have access to information that crosses proxy type boundaries, and whose behavior therefore suggests they have a more complete picture of the operation than their nominal role would suggest.


PART FIVE: LEGAL FRAMEWORKS AND REMEDIES

The Pattern-as-Harm Argument

Existing federal civil rights law is almost entirely act-based. It provides remedies for discrete unlawful acts by state actors. It does not provide adequate remedies for coordinated distributed campaigns in which each individual act clears every applicable legal threshold while the aggregate constitutes systematic suppression.

This is the critical jurisprudential gap. The argument that needs to be developed — and that has begun to emerge in recent civil rights litigation — is that coordinated distributed interference with constitutional rights is itself a cognizable harm at the pattern level, independent of whether any single act in the pattern crosses the relevant threshold.

This argument has doctrinal support in RICO’s civil provisions, which recognize that a pattern of acts by a network of actors can constitute a harm greater than the sum of its individual acts. The transfer of this reasoning to constitutional rights suppression is the most important available doctrinal development.

Available Statutory Frameworks

  • Bivens actions (implied constitutional tort against federal officials acting under color of federal law) — limited by recent Supreme Court narrowing but still available in some circuits for First and Fourth Amendment violations
  • Section 1983 (civil rights action against state actors) — particularly relevant for fusion center-coordinated activity involving local law enforcement
  • Civil RICO (18 U.S.C. § 1964) — where the proxy network constitutes an enterprise and the coordinated activity constitutes a pattern of racketeering — most analytically powerful for distributed operations but procedurally demanding
  • Privacy Act — for unauthorized disclosure or use of records maintained in federal systems
  • FISA — for unlawful electronic surveillance where federal actors are involved

The Public Record as Independent Strategy

Formal legal proceedings are one accountability mechanism. The construction of a comprehensive, corroborated public record — through FOIA litigation, congressional correspondence, inspector general submissions, amicus participation in related litigation, and journalism — is an independent strategy that does not depend on the success of any single legal proceeding and that creates the evidential foundation on which future proceedings can build.

The subject of an extended deniable operation who cannot immediately achieve legal accountability may nonetheless be building the record that makes legal accountability possible in a future proceeding where the relevant doctrine has developed, where the right judge is assigned, or where a congressional committee has been constituted with the political will to investigate. The record survives the proceeding.


APPENDIX: STATUTORY REFERENCE

Statute Purpose Key Limitations
42 U.S.C. § 1983 Civil rights claims against state actors Does not reach federal actors
Bivens (implied) Constitutional claims against federal officials Substantially narrowed since Ziglar v. Abbasi (2017)
18 U.S.C. § 1964 Civil RICO — pattern of racketeering by enterprise Requires enterprise + pattern; difficult to plead
5 U.S.C. § 552a Privacy Act — federal records Limited to records in federal systems of records
50 U.S.C. § 1809 FISA criminal provision Requires proving electronic surveillance
18 U.S.C. § 241-242 Federal criminal civil rights Requires DOJ prosecution; rarely pursued

THE UNCERTAINTY DEPARTMENT is a strategic forecasting and institutional accountability organization. This manual was developed from the application of established legal doctrine, documented historical programs, and structural analysis of contemporary deniable operation architecture. Nothing in this manual constitutes legal advice.