← research
Archived field note26 April 2026

ThreatWatch Evidence Quality

Why incomplete source material should lower confidence, and where I draw the evidence boundary between ThreatWatch and RedBlue.

ThreatWatchRedBlueThreat Intelligence

ThreatWatch

Collection reliability remained the main constraint on analysis quality. When full source material is unavailable, I want the system to lower confidence and preserve the distinction between source text, structured enrichment, and automated interpretation.

Fallbacks can keep a pipeline moving, but they should never make weak evidence look complete. The briefing should show uncertainty directly and avoid generic classifications that add little value.

RedBlue connection

ThreatWatch findings can inform RedBlue threat profiles and detection priorities once they pass an evidence gate. Developing leads remain visible for research, while operational workflows use only sufficiently supported findings.

That boundary is becoming the shared design principle across both projects: deterministic evidence first, optional analysis second, and clear human review before consequential action.