Professional Templates & Deliverables
2026 Expansion45.1 Intelligence Information Report (IIR) — NATO/OSINT Adapted Format
The IIR is the atomic deliverable: one question, one source, one time, one evaluation. It is not a dossier (that is the Target Package). The IIR feeds a dossier.
====================================================================
INTELLIGENCE INFORMATION REPORT (IIR)
====================================================================
--- HEADER ---
REPORT NUMBER: [ORG]-IIR-[YYYY]-[NNNN]
CLASSIFICATION: UNCLASSIFIED // FOR OFFICIAL USE ONLY
SUBJECT COUNTRY: [Country ISO 3166-1 alpha-3]
PREPARED BY: [Analyst name or team]
REPORT DATE: [ISO 8601: YYYY-MM-DDThh:mmZ]
PERIOD OF REPORT: [Start date → End date]
REQUESTING OFFICE: [Team/Department that requested the analysis]
--- SOURCE EVALUATION (NATO A-F / 1-6 system) ---
SOURCE RELIABILITY: [A/B/C/D/E/F]
A=Confirmed · B=Usually reliable · C=Fairly reliable
D=Not usually reliable · E=Unreliable · F=Cannot be judged
INFO CREDIBILITY: [1/2/3/4/5/6]
1=Confirmed by others · 2=Probably true
3=Possibly true · 4=Doubtfully true · 5=Improbable
6=Cannot be judged
SOURCE DESCRIPTION: [One line, do not expose sensitive source]
SOURCE ACCESS: [Public / Aggregated / Paid / Provided by third party]
--- CONFIDENCE LEVEL (ICD 203) ---
CONFIDENCE: [HIGH / MODERATE / LOW]
JUSTIFICATION: [2-3 lines. High = corroborated by ≥2 independent sources
with solid causal logic. Moderate = 1 reliable or 2 moderate.
Low = single or weak source]
KEY ASSUMPTIONS: [List of assumptions that, if broken, lower confidence]
--- BODY ---
BLUF (Bottom Line Up Front):
[1-3 sentences. The reader must understand the critical finding from this alone.]
KEY FINDINGS (numbered, max 5):
1. [Critical finding #1]
2. [Critical finding #2]
3. [Critical finding #3]
EVIDENCE (each finding with support):
- Finding #1:
* Sources: [URL + capture date]
* Capture: [SHA-256 of original document / screenshot]
* Archive: [archive.org snapshot URL if applicable]
ANALYSIS (interpretation, not evidence):
[What it means, what it implies, what it does not imply. Apply SATs from Appendix B]
KNOWLEDGE GAPS (what you DO NOT know):
- [Gap 1]
- [Gap 2]
RECOMMENDATIONS (prioritized next steps):
1. [Action — who, what, when]
2. [Action]
3. [Action]
--- ANNEXES ---
A. Sources list (URLs, dates, hashes)
B. Charts/maps/graphs (ownership diagram, timeline, geo)
C. Raw data (PDFs, screenshots, exports)
D. Methodology note (which SATs were applied)
E. Chain of Custody log (see 45.5)
--- DISTRIBUTION ---
TO: [Nominal list]
CC: [Nominal list]
NOFORN: [Y/N]
--- REVISION HISTORY ---
| Rev | Date | Author | Changes |
|-----|------------|---------------------|-------------------------------|
| 0.1 | 2026-07-19 | A. Senior | Initial draft |
| 1.0 | 2026-07-20 | A. Senior+Reviewer | Peer review, approval |
====================================================================
45.2 Target Package (Person) Template — 20 Fields
| # | Field | Typical Source |
|---|---|---|
| 1 | Full canonical name + aliases | LinkedIn, civil registry |
| 2 | Date and place of birth | Adverse media, public records |
| 3 | Nationality(ies) | Public visas, public records |
| 4 | Official identifiers (RFC/CURP/CPF/CUIT/DNI) | Public registry |
| 5 | Reference photo(s) (min. 1 frontal) | LinkedIn, press |
| 6 | Chronological professional bio | LinkedIn, OCCRP Aleph |
| 7 | Current positions | LinkedIn, corporate registry |
| 8 | Relevant historical positions (10 years) | OpenCorporates, EDGAR |
| 9 | Key personal relationships | LittleSis, adverse media |
| 10 | Corporate relationships (UBO/director) | OpenOwnership, OpenCorporates |
| 11 | PEP status + since when + level | OpenSanctions PEP |
| 12 | Sanctions status + designation date | OpenSanctions aggregator |
| 13 | Adverse media (3-5 incidents) | Google News, OCCRP, ICIJ |
| 14 | Litigation (civil/criminal/admin) | PACER, local judicial registry |
| 15 | Digital footprint (email/phone/domains) | Maigret, HIBP, WhoisXML |
| 16 | Real estate footprint | Property registry |
| 17 | Declared net worth (if PEP) | Asset declaration |
| 18 | Travel and residences (5 years) | Press, Instagram geotags |
| 19 | Identified associated risks | Output of analysis |
| 20 | Analytic confidence + gap list | — |
45.3 Executive Briefing Template (1 Page)
┌──────────────────────────────────────────────────────────────────┐
│ EXECUTIVE BRIEFING — [Topic] │
│ Classification: CONFIDENTIAL // C-Suite only Date: YYYY-MM-DD │
├──────────────────────────────────────────────────────────────────┤
│ │
│ BLUF (Bottom Line Up Front): │
│ [2-3 sentences, no jargon] │
│ │
│ Confidence: HIGH ▓▓▓ / MODERATE ▓▓░ / LOW ▓░░ │
│ │
├──────────────────────────────────────────────────────────────────┤
│ 1. CONTEXT (what was investigated and why) [3-4 lines] │
│ │
│ 2. KEY FINDING [4-6 lines] │
│ - Central fact │
│ - Source(s) │
│ - Implication for the organization │
│ │
│ 3. RISK AND IMPACT (financial/reputational/operational/legal) │
│ [2x2 table or list; A/B/C marks by severity/probability] │
│ │
│ 4. RECOMMENDATIONS (3, prioritized) │
│ 1. [Immediate action — 24-72h] │
│ 2. [30-day action] │
│ 3. [90-day action] │
│ │
│ 5. NEXT STEPS / KNOWLEDGE GAPS │
│ - What is missing and how to close it (cost/effort estimate) │
│ │
├──────────────────────────────────────────────────────────────────┤
│ Full annex: [link to full IIR / Target Package] │
│ Analyst contact: [name, email, phone] │
└──────────────────────────────────────────────────────────────────┘
45.4 Fact-Check Report Template (Journalism)
FACT-CHECK REPORT
=================
1. CLAIM (the verified statement)
Literal text: "..."
Claim source: [URL + date + capture]
Who said it: [person/entity + position]
2. VERIFICATION DATE: YYYY-MM-DD
3. VERIFIER(S): [name(s)]
4. VERIFICATION STATUS:
[ ] True [ ] Mostly true
[ ] Misleading [ ] Mostly false
[ ] False [ ] Unverifiable
5. EVIDENCE COLLECTED
5.1 Source 1: [type, URL, date, hash]
5.2 Source 2: ...
5.3 Source 3: ...
6. ANALYSIS (what weighs more and why)
7. OMITTED CONTEXT (what the claim does not say)
8. CONTACT WITH ORIGINAL SOURCE
Was the claimant contacted? Yes/No · Response: [...]
9. REFERENCES [verifiable URLs]
10. POST-PUBLICATION CORRECTIONS [log]
11. LICENSE AND REUSE
45.5 Digital Chain of Custody Checklist — 12 Steps
Before capturing:
- 1. Synchronise the device clock with NTP (difference <1s).
- 2. Verify the browser is clean (no logged-in session that biases served content).
- 3. Log pre-capture: exact URL, date/time with explicit timezone, public IP, access method (direct/VPN/Tor).
During capture:
- 4. Capture with visible timestamp on screen.
- 5. Save original format: complete HTML ("Save Page As → Webpage, Complete") + uncropped PNG screenshot.
- 6. Generate a snapshot on archive.org / archive.today and save the returned URL.
- 7. For video: download with
yt-dlppreserving original metadata; do not re-encode.
Immediately after:
- 8. Compute SHA-256 of the original file and log: filename, hash, size, UTC capture date.
- 9. For JS-heavy captures: also save HAR file (Network → Save All as HAR) and WARC if using wpull or archiveweb.
- 10. Rename files with convention
{YYYYMMDDTHHMMZ}_{slug}.{ext}(no spaces or accents).
Storage:
- 11. Store in an append-only repository (git with tags or WORM system). Never overwrite, only version. Second offline repository recommended.
- 12. Maintain a master CSV/JSON log with columns: case_id · filename · sha256 · capture_url · capture_timestamp_utc · capture_method · analyst · notes. One master file per case.
45.6 Verified Templates & Deliverables Tools
| Tool | URL | Function |
|---|---|---|
| Obsidian | https://obsidian.md | Linked notes with graphs |
| TimelineJS | https://timeline.knightlab.com | Interactive timelines |
| Aeon Timeline | https://www.aeontimeline.com | Complex timelines |
| Draw.io / diagrams.net | https://www.diagrams.net | Diagrams and flows |
| Zotero | https://www.zotero.org | Reference management |
| CryptPad | https://cryptpad.fr | Encrypted collaboration |
| Standard Notes | https://standardnotes.com | E2E encrypted notes |
| VeraCrypt | https://www.veracrypt.fr | Container encryption |
| MAT2 | https://0xacab.org/jvoisin/mat2 | Metadata stripping |
| ExifTool | https://exiftool.org | Metadata extraction |
| OpenTimestamps | https://opentimestamps.org | Blockchain timestamping |
| Hunchly | https://www.hunchly.com | Web capture with OPSEC ($129/yr) |
| archive.org Wayback | https://web.archive.org | Historical web archive |
| Archive.today | https://archive.today | Wayback alternative |
| Maltego | https://www.maltego.com | Link analysis and visualization |
| Datasette | https://datasette.io | Explore CSV/SQLite |
| Gephi | https://gephi.org | Graph analysis |
| RAWGraphs | https://rawgraphs.io | Charts from CSV |
| Datawrapper | https://www.datawrapper.de | Visualization for reports |
| QGIS | https://qgis.org | Desktop GIS |
| Mapillary | https://www.mapillary.com | Crowdsourced street-view |
| Atlos | https://www.atlos.org | Collaborative investigation |
| Auto-Archiver (Bellingcat) | https://github.com/bellingcat/auto-archiver | Automatic archiving |
| 4CAT | https://github.com/digitalmethodsinitiative/4cat | Social data analysis |
| Pinpoint (Google Journalist Studio) | https://journaliststudio.google.com/pinpoint/ | Document analysis |
45.7 Common Errors in OSINT Deliverables
- BLUF absent or buried. The executive reader has no time. If the critical finding is on page 7, it does not exist.
- Confusing fact with inference. "Company X is owned by Y" (fact) vs. "probably controlled by Y" (inference). Use markers
[FACT]vs[ANALYSIS]. - No chain of custody. A screenshot without URL, date and hash is anecdotal.
- Overloading with tools. The C-Suite does not care which tools you used, only the findings.
- Not declaring knowledge gaps. A senior declares what they do not know; a junior hides it.
- Unjustified confidence. "High Confidence" without justification = suspicious.
- Wrong format scaling. A 30-page IIR to a CFO = won't be read. A 1-page executive briefing to an auditor = useless.
- No versioning. Without revision history, no one knows if they are reading version 0.1 or 1.4.