Do We Even Trust This Report?
Part 4 of Inside the Risk Model: how ShadowIQ grades source reliability and claim corroboration with the NATO Admiralty system — and why confidence routes an alert rather than inflating its risk.
A government advisory and an anonymous post claiming the same thing are not equal evidence. Any serious intelligence process treats them differently. ShadowIQ's fourth axis — confidence — is where that judgement lives.
This is the final axis in Inside the Risk Model, after consequence, likelihood, and exposure. It's also the one that's easiest to get subtly wrong.
Two questions, not one
Confidence isn't a single "trust score." It's two separate questions, graded on the NATO Admiralty system used by militaries and intelligence services worldwide:
- Source reliability (A–F) — is the outlet trustworthy, based on its track record? A government advisory sits near A. A well-established news wire is high. An anonymous social account starts low, near E.
- Claim corroboration (1–6) — is this specific claim backed up? 1 means confirmed by multiple independent sources; the scale runs down to 6, "cannot be judged." A lone, uncorroborated report can never be graded "confirmed," no matter who posts it.
Splitting reliability from corroboration matters because they move independently. A reliable outlet can carry an unconfirmed early report. An unreliable source can occasionally be first to something that's later corroborated everywhere. Grading them separately captures both.
The critical rule: confidence routes, it doesn't rate
This is the design decision we're proudest of, and the one that most tools get backwards.
When ShadowIQ is unsure about a report, it does not give it a scarier risk score. Uncertainty is not danger. Instead, low confidence changes what happens to the alert, not how alarming it looks:
- A credible alert that intersects your itinerary can notify you immediately.
- A serious-but-shaky alert — single source, uncorroborated, questionable outlet — is held for a human analyst to verify before it's allowed to interrupt anyone.
In other words: we don't wake people up for rumours. We check them first. This keeps two bad outcomes at bay — crying wolf over unverified noise, and burying a real signal because it arrived through a weak channel. The uncertainty is handled by routing to a person, not by faking a number.
Kept out of the risk score, on purpose
Notice what confidence is not: it is not blended into consequence, likelihood, or exposure. This follows a formal principle of intelligence analysis — never mix how sure you are of your information with your assessment of the world itself. A rock-solid report of a minor event is still minor. A shaky report of a major one is still potentially major — it just needs verifying before it drives action. Collapsing certainty into the risk score corrupts both.
Why it matters to you
Confidence is the quiet axis that determines whether an alert earns an interruption or a verification. It's why your team isn't paged over every unverified social post, and why — when ShadowIQ does escalate something immediately — it's because the reporting cleared a real bar. Trustworthy alerting isn't just about finding signals; it's about being honest about which ones you can stand behind.
Next in the series: we step back from the four axes to how they combine — alerts that ease, not just pile up.