Whitepaper / Practitioner Framework

Multi-INT fusion:a practitioner's framework.

How fifteen intelligence disciplines are unified into a single operational graph — and why the seams between them are the points of least resistance for adversaries.

AuthorSovereignty Infinium Intelligence Practice
DateQ2 2026
Reading time38 minutes
ClassificationConfidential · NDA

The adversary's campaign is fused. Your intelligence function is siloed. The seam is the target.

EWEG

Evidence-Weighted Entity Graph

15

INTs in a single graph

3+3

Confidence dimensions (A-F / 1-6 / 7-step)

6

Cross-INT correlation techniques

1. The Context

The federation problem, precisely stated.

The fusion problem is not a data-engineering problem. It is an epistemological problem. The hard part is not merging the data. It is merging the claims.

1.2

The fusion problem has three components.

Problem 01

The claim-merging problem.

OSINT asserts jurisdiction A. HUMINT asserts jurisdiction B. CYBINT is consistent with both. FININT shows a third. The four claims are partially corroborative, partially inconsistent, and partially orthogonal. A naive merge either keeps all four or drops three.

Problem 02

The entity-resolution problem.

A threat actor with three personas, four operational aliases, and two financial fronts is one entity. OSINT sees the personas, CYBINT sees the aliases, FININT sees the fronts. Resolving them — with a confidence label — is harder than it sounds. Aliases, role-naming, and deliberate tradecraft conspire to make one entity look like several.

Problem 03

The temporal-alignment problem.

A HUMINT debrief from last week describes a meeting two weeks ago. A CYBINT indicator was logged three days after. GEOINT shows a vehicle at the location between the two. FININT timestamps a transaction a week later. Aligning, weighting, and reconstructing is the temporal-alignment problem.

1.3

The cost of getting fusion wrong is measurable.

Error 01

Spliced reports.

Three reports synthesized into one page in 48 hours. The principal receives a snapshot of three snapshots of partial views.

Error 02

False contradictions.

Two INTs appear to flatly contradict. No way to express partial corroboration, so the principal chooses one and the truth was the third, more nuanced position.

Error 03

Missed coordination.

Three INTs each log a signal about a single adversary campaign. Each is unremarkable in isolation. The fusion that would have flagged the coordination is not done.

A fusion framework that does not solve all three of these problems is, in the strongest sense, not a fusion framework. It is a dashboard.

1.4

Why conventional architectures cannot do it.

01

Data store vs. claim.

Conventional architectures are organized around data stores, not around claims. The doctrinal reason: they treat confidence as a per-report attribute rather than per-claim.

02

Per-claim confidence.

Required for any fusion framework. Each discrete claim carries its own source reliability, information credibility, and estimative probability.

03

Common confidence tradition.

Analysts in different INTs are trained in different confidence traditions and do not share a common framework. All three must be addressed for fusion to work.

2. The Framework

The Evidence-Weighted Entity Graph.

The EWEG is a data structure and a set of operations. Three node types — entities, events, assertions. Three edge types. Every node and edge carries confidence, provenance, and timestamp.

2.1

Definition — three node types, three edge types, all confidence-explicit.

Entity · Person

c = 0.93

knows

Entity · Org-A

c = 0.87

works for

Entity · Person

c = 0.78

linked to

EVENT · Cyber-Intrusion-2026-Q2-014

c = 0.96

ts: 2026-04-12T14:22:31Z

ASSERTION · OSINT

s-rel: B·info-cred: 3

ASSERTION · CYBINT

s-rel: A·info-cred: 2

ASSERTION · HUMINT

s-rel: B·info-cred: 3

2.2

The confidence stack — three dimensions, not redundant.

Admiralty (NATO)

Source reliability

A → F

The channel. How reliable is the source?

Admiralty (NATO)

Information credibility

1 → 6

The specific content of the information.

Sherman Kent (CIA)

Estimative probability

7 ordinal steps

The likelihood of the analytic claim derived from the content.

2.4

The fifteen INTs, mapped to the graph.

INT
Primary contribution
Source reliability

OSINT

OSINT contributes heavily to event and assertion nodes, less to entity nodes (public sources describe the same entity under different names).

B–C

SOCMINT

Events, social-persona entities, narrative-velocity assertions.

B–C

HUMINT

Relation edges, intent assertions, high-confidence entity attributes.

A–B

GEOINT

Location-bearing events, site-organization entities, physical-presence assertions.

A–B

FININT

Entity-resolution via financial flows, sanctions-network entities, transaction events.

A–B

CYBINT

Cyber events, IOC entities, TTP assertions, infrastructure entities.

A

SIGINT

Communication events, network entities, signal-derived assertions.

A

TECHINT

Materiel entities, dual-use entities, technical-capability assertions.

A–B

MASINT

Sensor events, signature-derived entities, anomaly assertions.

A

MEDINT

Public-health events, biological-threat entities, capability assertions.

A–B

BIOMINT

Identity entities, biometric-match assertions.

A

ACINT

Underwater events, platform entities, acoustic-anomaly assertions.

A

CULTINT

Norm entities, frame-assertions, sentiment-aggregated events.

B–C

DOMEX

Document-entities, captured-plan assertions, material-attribute assertions.

A

Identity

Identity entities, role-assertions, document-attribute assertions.

A

2.5

Cross-domain entity resolution — four principles.

01 / 04

Multi-signal matching.

An ensemble of matchers: name similarity, network topology, temporal co-occurrence, financial flow, behavioral pattern, biographical attributes. The ensemble's output is a match-score with confidence.

02 / 04

Explicit non-resolution.

The framework allows the operator to express that two records are NOT the same entity, with a confidence label — even if some matchers return high similarity. Essential when a deliberate look-alike operation is under way.

03 / 04

Human adjudication.

Entity resolutions above a configurable confidence band are routed to a human adjudicator. The adjudicator's decision is logged and used to retrain the matchers.

04 / 04

Network-context disambiguation.

Two records that look similar in isolation often disambiguate through their network context. Graph embeddings capture this context and refine the match score.

2.6

The six cross-INT correlation techniques.

01 / 06

Co-occurrence correlation.

When to use:

Two INTs produce events in the same temporal window.

Output: Time-aligned co-occurrence events.

02 / 06

Network correlation.

When to use:

Two INTs produce overlapping entity networks.

Output: Merged entity graph with confidence.

03 / 06

Assertion correlation.

When to use:

Two INTs produce overlapping or contradictory claims.

Output: Confidence-weighted resolution.

04 / 06

Pattern correlation.

When to use:

Two INTs produce behavior patterns consistent with a known TTP.

Output: TTP-matched event with confidence.

05 / 06

Counter-narrative correlation.

When to use:

Two INTs produce narrative patterns consistent with a known IO playbook.

Output: IO-matched narrative with confidence.

06 / 06

Lead-lag correlation.

When to use:

One INT's signal leads another's by a characteristic interval.

Output: Predicted future event with lead time.

3. The Practice

Two representative workflows.

The same fusion logic in two domains. The framework is the substrate; the workflows are its operational deployment.

3.1

Workflow — APT pre-emption, four INTs in four weeks.

W-3

01 / 04

OSINT deep-web

Volume spike around network appliance category. Bot-detection: not CIB. Narrative analysis: early-staging signature. Threat-scoring advisory issued.

W-2

02 / 04

CYBINT + HUMINT

IOC cross-reference matches. HUMINT source report corroborates. Two assertions enter the EWEG as supporting evidence.

W-1

03 / 04

FININT + GEOINT

FININT flags infrastructure rental in known-jurisdiction pattern. GEOINT flags logistical pattern matching a comparable historical campaign.

W-0

04 / 04

Day-zero correlation

Confidence crosses 80%. Warning-level alert. CYBINT detects initial probing — correlated to the staged campaign within seconds. Critical alert. Pre-positioned posture contains.

3.2

Workflow — Influence-operation pre-emption, six weeks.

W-6

01 / 05

Account cluster detected

SOCMINT flags new account cluster. Bot-detection: low-confidence inauthentic. Account-creation pattern matches known pre-staging profile. Cluster added to watch list.

W-4

02 / 05

Coordinated narrative frame

Cluster begins publishing content consistent with one of 17 known influence-operation frames. Cluster reclassified as CIB. Advisory issued.

W-3

03 / 05

Cross-platform amplification

OSINT detects amplification on a second platform. Cross-platform coordination graph constructed. Warning issued.

W-2

04 / 05

Counter-narrative activated

Playbook engine activates: 5 phases — detect, characterize, attribute, pre-position, respond. Pre-position options generated for client's strategic-comms team.

W-0

05 / 05

Mainstream breakthrough

Narrative breaks into mainstream coverage. Real-time alert fires. Pre-positioned counter-assets deployed within hours. Share-of-voice impact capped at a fraction of baseline projection.

3.7

Four lessons learned across deployments.

Lesson 01

Entity resolution is the bottleneck.

Most operational pain in fusion systems is at the entity-resolution layer. Successful practitioners invest disproportionately here and treat it as ongoing engineering, not a one-time project.

Lesson 02

Calibration is more important than precision.

A system producing well-calibrated 70% confidence is more useful than one producing badly-calibrated 95%. The framework's design point is calibration.

Lesson 03

Provenance is a feature, not a tax.

Practitioners who initially resisted the provenance-record requirement became its strongest advocates once they saw how it enabled institutional trust and post-hoc analysis.

Lesson 04

The human role is irreducibly central.

The framework amplifies human judgment. It does not replace it. The boundary between AI and human must be designed explicitly, audited continuously, and respected.

4. Implications

For chiefs, architects, and procurement.

Intelligence chiefs.

Architectural redesign of the intelligence function. A fusion capability cannot be built by adding a fusion cell to a siloed structure. First year is hardest.

Technical architects.

The fusion problem is a graph problem with a confidence model, not a database problem with a query language. The talent profile is hybrid: practitioner + ML engineer.

Procurement leads.

Evaluate on architecture: how is entity resolution implemented? How is confidence propagated? How is provenance tracked? How is calibration validated?

One-sentence summary

Multi-INT fusion is the discipline of unifying fifteen intelligence traditions into a single confidence-explicit graph, with provenance at every step, calibration as a first-class engineering concern, and human judgment respected in its proper place.

Request This Whitepaper

Confidential briefing · Under your security protocols

Sovereignty Infinium is built for sovereign clients · All engagements operate under mutual non-disclosure · Some capabilities subject to national export controls

SOC 2 Type IIISO 27001GDPRFedRAMPFIPS 140-3Common Criteria EAL5+