THIRA stands for Threat and Hazard Identification and Risk Assessment — a structured framework developed by FEMA (CPG 201, 3rd Edition) to help communities identify what threats they face, how bad those threats could be, and what capabilities they need to survive them. ECHO adapts this framework for individual and group preparedness. The process starts here: build a complete list of every credible threat in your area before you rate or rank anything. Threats are organized into three categories — Natural (acts of nature: storms, floods, drought), Technological (system failures: grid down, water outage, fuel disruption), and Human-Caused (intentional actions or societal breakdown: civil unrest, supply chain collapse, attack). Cast a wide net. Think about your specific location, climate, and proximity to population centers. A threat that seems unlikely is still worth listing — you will rate probability in Module 02. Note that major threats rarely disable only one system: a pandemic simultaneously degrades transportation, banking, energy, communications, and emergency response. An EMP strike takes down every critical infrastructure sector identified by the federal government in a single second. The goal here is completeness — list everything, judge nothing yet.
Rate each threat on two axes. Probability (1–5): how likely is this threat to affect your AO within 5 years? Impact (1–5): if it occurred, how severe is the effect on your group? A Severity Modifier accounts for cascading effects and complexity — the 2019 National THIRA explicitly models that major incidents do not occur in isolation. Priority Score = Probability × Impact × Severity. Max = 75. High: 38+, Medium: 16–37, Low: 1–15. Calibration note: Koppel (Lights Out, 2015) documents that the US grid has no federal mandatory security standards and that NERC/FERC have repeatedly failed to require hardening. A single well-placed physical or cyber attack on 9 key substations could take down the eastern interconnect for 18 months or more. Rate grid-related threats accordingly — this is not a low-probability scenario. Skousen rates nuclear war as a long-term near-certainty; weight his probability estimates against your own assessment, but his target location data is reliable regardless of probability assigned.
The POETE framework (CPG 201 / SPR) evaluates capability across five dimensions: Planning (plans, procedures, mutual aid), Organization (team structure, roles), Equipment (gear, supplies, systems), Training (skills, knowledge), and Exercises (practice, drills). Rate 1–5 for each area per threat. 1 = critically deficient, 5 = full capability. Threats sorted by priority score. Set a Capability Target — what success looks like in specific, measurable terms.
A gap is a specific deficiency — not "we need more medical supplies" but "we have no trained tourniquet applicator and no hemostatic gauze." Specific gaps produce specific corrective actions. For each gap, identify the POETE area where the shortfall exists and assign a priority (High/Medium/Low) relative to the threat's priority score. Threats appear in priority order. Gaps feed directly into the Prep Roadmap.
Every gap gets a task, every task gets a responsible person and a target date. Prioritize by threat priority score × gap severity. The roadmap is what ECHO produces — it links back to every other module in the suite. Gaps in medical point to Medical Command. Gaps in comms point to Comms Matrix. Gaps in water point to Hydro. Describing an approach here creates no obligation to complete it within the timeframe — it is a planning tool, not a commitment.
All identified threats ranked by priority score with probability, impact, and severity ratings. Sorted high to low.
Prioritized list of preparedness shortfalls by POETE area with capability scores and gap priorities.
Action plan with assigned tasks, responsible persons, timeframes, and current status — sorted by priority.
Complete assessment document with all data — threat context, capability targets, gaps, and roadmap. Suitable for group briefing.
Synthesized view of your group's key vulnerability patterns across all threats — heat sources, medical dependencies, supply depth, location factors. The data collection payoff.
User Manual
This manual assumes you have never opened ECHO before. Every screen is explained in plain language. Work through it in order the first time. After that, use the table of contents to jump to what you need. Hover over any underlined acronym on screen for its definition.
Table of Contents
What is ECHO
ECHO is the threat assessment module of the WATCHMAN Suite. It implements the THIRA framework — Threat and Hazard Identification and Risk Assessment — adapted for individual and small-group preparedness. The module answers three questions:
- What threats does your group realistically face?
- How serious are they, and how ready are you to handle them?
- What do you need to do about it, and in what order?
ECHO is not a one-time exercise. It is a living document. Threats change, capabilities change, gaps get closed. Use the Review Cycle system to stay current.
Navigation
Use the sidebar on the left to move between sections. Each section number shows a count of items when data is present. Work through sections 01 through 05 in order on your first run.
Data Storage
All data saves locally in your browser. Nothing goes to a server. Use the SAVE button at the bottom of each section before navigating away. Export a Full THIRA Report periodically as a backup — if browser data is cleared, your assessments are lost.
Module 01 — Threat Registry
Build your complete threat list here. The principle is completeness before prioritization. Include every credible threat. Do not filter at this stage — you will rate and sort in Module 02.
Adding a Threat
Click + ADD THREAT in the upper right. The Add Threat modal opens.
- Select a threat type from the grouped dropdown. Threats are organized under three categories — Natural (storms, floods, wildfire), Technological (grid failure, nuclear plant, hazmat), and Human-Caused (civil unrest, supply chain, refugee influx). If no type fits, select Custom / Other at the bottom and enter a name manually.
- Fill in the Threat Characterization Data fields that appear below the dropdown. These fields are specific to each threat type and collect structured information about how this threat applies to your situation. Fill in every field you can answer. This data drives the Group Vulnerability Profile in Generate Docs.
- For typed threats, click ⚡ AUTO-GENERATE FROM FIELDS to write an AO Context summary from your characterization data. You can edit the result.
- Add a Description for any additional notes specific to your situation.
- Set Last Reviewed Date to today and choose a Review Cycle. When the cycle elapses, a yellow REVIEW DUE flag appears on the card.
- Click ✓ SAVE THREAT.
Review Cycles
| 30 days | Monthly — fast-moving or active threats |
| 90 days | Quarterly — human terrain, civil unrest concerns |
| 180 days | Semi-Annual — default for most threats |
| 365 days | Annual — slow-moving or low-probability threats |
Threat Cards
After saving, your threat appears as a card in the registry showing category, review status, active indicator dots, and completion status for Rated, Assessed, Gaps, and Indicators. The colored dot in the upper right shows priority level after Module 02 scoring. Click EDIT to modify or the red ✕ to delete.
Module 02 — Probability & Impact
Rate each threat and assign a priority score. Every threat from your registry appears here as an expandable card. Click a card header to expand or collapse it.
Sort Order
Use the toggle at the top to switch between ADD ORDER (the sequence you entered threats) and PRIORITY SCORE (highest score first, unrated threats at the bottom). The active sort is highlighted in green.
Scoring System
Priority Score = Probability × Impact × Severity Modifier. Maximum is 75.
| 38–75 | HIGH — address immediately |
| 16–37 | MEDIUM — address in near term |
| 1–15 | LOW — address after higher priorities |
Probability (1–5)
How likely is this threat to affect your AO within the next five years? 1 = very unlikely. 5 = near-certain. Select a Basis from the dropdown to document why you chose that rating.
Impact (1–5)
If this threat occurred, how severe would the effect be on your group? 1 = minor disruption. 5 = existential threat to the group.
Severity / Complexity Modifier (×1 / ×2 / ×3)
| ×1 Standard | Single, bounded event. Outside help arrives eventually. Life returns to normal within days to weeks. |
| ×2 Cascading | Primary event triggers multiple simultaneous secondary failures. Help may be delayed or unavailable for weeks. |
| ×3 Catastrophic | Long-duration, wide-area event. No outside help is coming. Group survival directly at stake. |
Threat Course of Action Analysis
Below the scoring buttons, ECHO asks you to define two course of action models. These come from IPB doctrine and are the most operationally useful fields in the module.
- MLCOA (Most Likely Course of Action) — How this threat most probably unfolds in your specific AO. Be specific: timing, direction, magnitude, and sequence of events.
- MDCOA (Most Dangerous Course of Action) — The worst plausible version. Not the most likely, but the scenario that would most severely challenge your group's survival. This is your planning driver for capability gaps.
Priority Intelligence Requirements (PIR)
Capture the specific questions whose answers would reduce your uncertainty about this threat. A well-formed PIR is answerable by a specific source — utility company, ham net check-in, personal observation — and is time-bounded. Example: "What is the current grid restoration timeline from the utility company?"
Early Warning Indicators
Add observable conditions that signal this threat is becoming more likely. Type in the field and press Enter or click + ADD. Click the status badge to cycle it:
| Normal | No unusual activity. Monitoring ongoing. |
| Elevated | Observable increase in threat-related activity. |
| Active | Threat is imminent or in progress. Red dot appears on the Module 01 threat card. |
Trigger Event (Tripwire)
The single observable moment that shifts your group from monitoring to acting. State it as an if/then: "If grid is down for 72+ hours with no restoration ETA, execute shelter-in-place protocol." When set, it displays as an amber bordered box as a visual reminder during reviews.
Concurrent Stressors
What else would likely be happening at the same time? Major threats rarely occur in isolation. Document what secondary conditions your group would face simultaneously.
Module 03 — Capability Assessment
Evaluate your group's current capability to handle each threat using the POETE framework. Threats appear sorted by priority score by default, with a rank badge (#1, #2, #3) showing position. Use the sort toggle to switch to add order.
POETE Framework
| Planning | Documented plans, procedures, and mutual aid agreements. Could someone unfamiliar execute your plan from written documentation? |
| Organization | Group structure, defined roles, designated leadership. Is accountability clear? |
| Equipment | Physical gear, supplies, and systems. Sufficient quantity for your group size and threat duration? |
| Training | Demonstrated proficiency — not theoretical familiarity. Can your people actually execute? |
| Exercises | Practice under realistic conditions. An untested plan is a hypothesis, not a capability. |
Rating Scale
| 1 | Critically Deficient — no meaningful capability |
| 2 | Significantly Deficient — major gaps remain |
| 3 | Partial Capability — can handle some but not the MDCOA |
| 4 | Substantial Capability — minor gaps only |
| 5 | Full Capability — can handle the MDCOA today |
Capability Target Statement
Define exactly what good enough looks like for this threat. Be specific and measurable. Click INSERT TEMPLATE to load the CPG 201 standard format: "Within [timeframe] of [incident type], [who/group] can [critical task] for [number of people] for [duration] without [outside dependency]."
This target drives your gap identification in Module 04. If you cannot state specifically what success looks like, you cannot identify what is missing.
Module 04 — Gap Analysis
A gap is the distance between your current capability and your Capability Target. Document every specific deficiency here.
Adding a Gap
Click + ADD GAP on any threat. Fill in the modal:
- POETE Area — which dimension this gap falls under. If a gap spans multiple areas, create separate entries.
- Gap Description — describe precisely what is missing, how much, and why it matters for the MDCOA.
- Priority — High (must address before this threat is relevant), Medium (near term), Low (after higher priorities).
- Cost / Resource Tier — None / Minimal / Moderate / Significant / Major. Used to sequence the roadmap by effort as well as priority.
- Linked Module — select the WATCHMAN Suite module where this gap should be addressed. A clickable badge appears on the gap card and navigates to that module in a new tab.
- OPSCON Urgency — optionally set the readiness level at which this gap becomes critical. Connects to the SENTINEL module: the OPSCON level you set there is read here.
Module 05 — Prep Roadmap
Converts your gap list into an action plan. Every gap gets a corrective task, a responsible person, a target date, and a status.
Dashboard
The top of Module 05 shows total gaps, open count, in-progress, complete, and — when applicable — an overdue count in red. The Gap Concentration line shows which POETE areas have the most gaps across all threats. If 80% of your gaps are in Equipment, your problem is procurement. If they are in Training, your problem is skills.
Task Fields
| Corrective Task | The specific action that closes this gap. One task per gap. |
| Responsible | Who is accountable. Name or role. If unassigned, it will not get done. |
| Target Date | Select from the date picker. Tasks past their date show a red OVERDUE badge. |
| Approach | How you plan to close this gap. Planning notes — not a commitment. |
Task Status
| Open | Default. Not yet started. |
| In Progress | Work has begun. Card border turns amber. |
| Complete | Gap is closed. Card border turns green. Updates the dashboard stats. |
Generate Documents
Five printable documents generated from your assessment data. Navigate to Generate Docs in the sidebar and click GENERATE on any output.
| Output 1 | Threat Priority Matrix — ranked table of all threats by priority score. Use as a leadership briefing document. |
| Output 2 | Gap Analysis Summary — consolidated list of all gaps across all threats, sorted by priority. Working checklist for your preparedness effort. |
| Output 3 | Preparedness Roadmap — task-level action plan with responsible persons, target dates, and status. Brief at group meetings. |
| Output 4 | Full THIRA Report — complete assessment document including all threat data, COA analysis, PIRs, POETE ratings, and gaps. Suitable for formal group briefing or binder archiving. |
| Output 5 | Group Vulnerability Profile — synthesized view of cross-threat vulnerability patterns. Surfaces issues you may not notice reviewing threats individually. The data collection payoff. |
First-Run Workflow
- Module 01: Add all credible threats. Select typed threats from the dropdown. Fill in every characterization field. Set Last Reviewed to today. Do not rate anything yet.
- Module 02: Rate every threat — probability, impact, severity. Write MLCOA and MDCOA for each. Add at least three early warning indicators per threat. Set a trigger event for each high-priority threat.
- Module 03: Rate POETE capability for each threat. Write a specific Capability Target. Be honest.
- Module 04: Document specific gaps for each threat. Link each gap to a POETE area, cost tier, and relevant WATCHMAN module.
- Module 05: Assign a corrective task, responsible person, and target date to every gap.
- Generate Docs: Generate the Full THIRA Report and Group Vulnerability Profile. Review the vulnerability patterns flagged. Address any High severity patterns before your next review cycle.
- Save: Click SAVE at the bottom of each section before navigating away.
Acronym Glossary
Hover over any underlined acronym anywhere in ECHO for its definition. Full list below for print reference.
| AO | Area of Operations — the geographic area your group plans for and monitors |
| CME | Coronal Mass Ejection — solar storm that can collapse the power grid |
| COA | Course of Action — a defined path a threat or actor may take |
| CPG | Comprehensive Preparedness Guide — FEMA doctrine document series |
| EMP | Electromagnetic Pulse — energy burst that destroys unshielded electronics |
| ETA | Estimated Time of Arrival |
| EWI | Early Warning Indicator — observable condition signaling a threat may be developing |
| FEMA | Federal Emergency Management Agency |
| FERC | Federal Energy Regulatory Commission |
| IFAK | Individual First Aid Kit |
| IPB | Intelligence Preparation of the Battlefield — military doctrine for threat analysis |
| JIT | Just-In-Time — lean supply chain model with minimal inventory buffers |
| KI | Potassium Iodide — radiation protection medication |
| LE | Law Enforcement |
| MDCOA | Most Dangerous Course of Action — worst plausible version of a threat |
| MLCOA | Most Likely Course of Action — how a threat most probably unfolds in your AO |
| NERC | North American Electric Reliability Corporation — grid reliability standards body |
| OPSCON | Operational Condition — readiness level system (5=Baseline to 1=Crisis) |
| OPSEC | Operational Security — protecting information that could be exploited |
| OSINT | Open Source Intelligence — from publicly available sources |
| PF | Protection Factor — measure of how well a shelter blocks radiation |
| PIR | Priority Intelligence Requirement — specific question driving active collection |
| POETE | Planning, Organization, Equipment, Training, Exercises — capability assessment framework |
| PPE | Personal Protective Equipment |
| SHTF | Preparedness community shorthand for a major societal breakdown event |
| THIRA | Threat and Hazard Identification and Risk Assessment — FEMA planning framework |
| TTP | Tactics, Techniques, and Procedures — standardized task execution methods |
| WUI | Wildland-Urban Interface — zone where structures meet unmanaged wildland |
| WROL | Without Rule of Law — societal condition where legal order has broken down |
ECHO USER MANUAL · © 2026 WATCHMAN SUITE, LLC · THREAT & HAZARD ASSESSMENT — MODULE 01
Demo Sandbox
ECHO ships with a demo sandbox — a separate copy pre-loaded with a worked threat assessment for a fictional AO: four threats across three categories (an extended grid failure with a full POETE evaluation, warning indicators under collection, and a capability target; a refugee-flow scenario with an actor profile; winter storm isolation; and a drought-year wildfire), each scored, with open gaps feeding the corrective roadmap.
Opening and leaving. In the live module, click DEMO in the sidebar under this manual. Inside the demo, that same slot reads RETURN TO LIVE and takes you back. An amber banner across the top of the demo tells you which copy you are in at all times.
Your real data is safe. The demo keeps everything in separate storage slots, including its own OSINT Station import queue and its own SENTINEL read, so nothing you do in the demo can touch your real threat register — and accepting or dismissing an import in the demo can never consume a real pending push.
Cross-sandbox wiring. The demo reads OPSCON context from the SENTINEL demo, receives threat pushes from the HUMINT Registry demo's queue, and the DEBRIEF demo writes its gap findings into this same demo slot: link a demo AAR finding to one of these threats and it lands in that threat's gap analysis. The demo sandboxes form one connected training environment.
Resetting. The ↻ RESET DEMO button in the top bar discards any changes and restores the sample assessment.
User Manual
This manual assumes you have never opened ECHO before. Every screen is explained in plain language. Work through it in order the first time. After that, use the table of contents to jump to what you need.
Table of Contents
What is ECHO
ECHO is the threat assessment module of the WATCHMAN Suite. It implements the THIRA framework — Threat and Hazard Identification and Risk Assessment — adapted for individual and small-group preparedness. The module answers three questions: What threats does your group face? How serious are they and how ready are you? What do you need to do about it and in what order?
ECHO is not a one-time exercise. It is a living document. Use the Review Cycle system to stay current.
All data saves locally in your browser. Nothing goes to a server. Use the SAVE button before navigating away. Export a Full THIRA Report periodically as a backup.
Module 01 — Threat Registry
Build your complete threat list. Include every credible threat. Do not filter at this stage.
Adding a Threat
- Click + ADD THREAT. Select a threat type from the dropdown (Natural, Technological, or Human-Caused). Select Custom / Other if no type fits.
- Fill in the Threat Characterization Data fields. These are specific to each threat type. Fill in every field you can answer — this data drives the Group Vulnerability Profile.
- For typed threats, click AUTO-GENERATE FROM FIELDS to write an AO Context summary. Edit as needed.
- Set Last Reviewed Date to today and choose a Review Cycle (30 / 90 / 180 / 365 days). A REVIEW DUE flag will appear on the card when the cycle elapses.
- Click SAVE THREAT.
Review Cycles
| 30 days | Monthly — fast-moving or active threats |
| 90 days | Quarterly — human terrain, civil unrest |
| 180 days | Semi-Annual — default |
| 365 days | Annual — slow-moving threats |
Module 02 — Probability & Impact
Rate each threat. Use the sort toggle at the top to switch between ADD ORDER and PRIORITY SCORE. Priority Score = Probability × Impact × Severity Modifier. Maximum is 75. High: 38+. Medium: 16–37. Low: 1–15.
| Probability | 1–5: How likely within 5 years? 1=very unlikely, 5=near-certain |
| Impact | 1–5: How severe if it occurred? 1=minor disruption, 5=existential |
| ×1 Standard | Single bounded event. Outside help arrives. Returns to normal in days/weeks. |
| ×2 Cascading | Triggers multiple simultaneous secondary failures. Help delayed weeks. |
| ×3 Catastrophic | Long-duration, wide-area. No outside help. Group survival at stake. |
Course of Action Analysis
MLCOA — How this threat most probably unfolds in your AO. Specific timing, direction, magnitude, sequence.
MDCOA — Worst plausible version. Your planning driver for capability gaps.
PIR — Priority Intelligence Requirements
The specific questions whose answers reduce uncertainty about this threat. Each should be answerable by a specific source. Example: "What is the utility company's current restoration timeline?"
Early Warning Indicators
Observable conditions signaling a threat is becoming more likely. Click the status badge to cycle: Normal → Elevated → Active. Active indicators show a red dot on the Module 01 card.
Trigger Event
The single moment that shifts from monitoring to acting. State as if/then: "If grid is down 72+ hours with no ETA, execute protocol."
Module 03 — Capability Assessment
Evaluate capability using the POETE framework. Threats appear by priority score with rank badges (#1, #2) in the header. Use the sort toggle to switch order.
| Planning | Plans, procedures, mutual aid agreements |
| Organization | Group structure, roles, leadership |
| Equipment | Gear, supplies, systems |
| Training | Demonstrated proficiency |
| Exercises | Practice under realistic conditions |
Scale: 1=Critically Deficient · 2=Significantly Deficient · 3=Partial · 4=Substantial · 5=Full Capability
Write a Capability Target using the INSERT TEMPLATE button. CPG 201 format: "Within [timeframe] of [incident], [group] can [task] for [N people] for [duration] without [outside dependency]."
Module 04 — Gap Analysis
Document every specific deficiency. Click + ADD GAP on any threat.
| POETE Area | Which dimension this gap falls under |
| Description | What is missing, how much, why it matters for the MDCOA |
| Priority | High / Medium / Low |
| Cost Tier | None / Minimal / Moderate / Significant / Major — sequences roadmap by effort |
| Linked Module | WATCHMAN module where this gap should be addressed. Clicking navigates there. |
| OPSCON Urgency | Readiness level at which this gap becomes critical. Connects to Sentinel. |
Module 05 — Prep Roadmap
Converts gaps into assigned, time-bound corrective actions. Dashboard shows total, open, in-progress, complete, and overdue counts. Gap Concentration line shows which POETE areas need the most work.
| Corrective Task | Specific action that closes this gap |
| Responsible | Who is accountable — name or role |
| Target Date | Date picker — past dates with open status show OVERDUE in red |
| Approach | How you plan to close it — planning notes |
| Status | Open (default) · In Progress (amber) · Complete (green) |
Generate Documents
| Output 1 | Threat Priority Matrix — ranked by score, leadership briefing document |
| Output 2 | Gap Analysis Summary — all gaps across all threats, sorted by priority |
| Output 3 | Preparedness Roadmap — tasks, responsible persons, dates, status |
| Output 4 | Full THIRA Report — complete assessment, COA analysis, PIRs, POETE. File in binder. |
| Output 5 | Group Vulnerability Profile — cross-threat patterns. Medical dependency, heat source gaps, food depth, KI tablets, egress routes. |
First-Run Workflow
- Module 01: Add all threats. Fill characterization fields. Set review dates. Do not rate yet.
- Module 02: Rate every threat. Write MLCOA and MDCOA. Add 3+ indicators per threat. Set trigger events for high-priority threats.
- Module 03: Rate POETE capability. Write Capability Targets. Be honest.
- Module 04: Document gaps. Link to POETE area, cost tier, and WATCHMAN module.
- Module 05: Assign task, responsible person, and target date to every gap.
- Generate Docs: Run Full THIRA Report and Group Vulnerability Profile. File in binder.
- Save: Click SAVE at the bottom of each section before navigating away.
Acronym Glossary
| AO | Area of Operations |
| CME | Coronal Mass Ejection — solar storm |
| COA / COAs | Course(s) of Action |
| CPG | Comprehensive Preparedness Guide (FEMA) |
| EMP | Electromagnetic Pulse |
| ETA | Estimated Time of Arrival |
| EWI | Early Warning Indicator |
| FEMA | Federal Emergency Management Agency |
| FERC | Federal Energy Regulatory Commission |
| IFAK | Individual First Aid Kit |
| IPB | Intelligence Preparation of the Battlefield |
| JIT | Just-In-Time supply chain |
| KI | Potassium Iodide — radiation protection medication |
| LE | Law Enforcement |
| MDCOA | Most Dangerous Course of Action |
| MLCOA | Most Likely Course of Action |
| NERC | North American Electric Reliability Corporation |
| OPSCON | Operational Condition — readiness level |
| OPSEC | Operational Security |
| OSINT | Open Source Intelligence |
| PF | Protection Factor (radiation shelter) |
| PIR / PIRs | Priority Intelligence Requirement(s) |
| POETE | Planning, Organization, Equipment, Training, Exercises |
| PPE | Personal Protective Equipment |
| SHTF | Preparedness community: major societal breakdown event |
| THIRA | Threat and Hazard Identification and Risk Assessment |
| TTP | Tactics, Techniques, and Procedures |
| WUI | Wildland-Urban Interface |
| WROL | Without Rule of Law |
ECHO USER MANUAL · © 2026 WATCHMAN SUITE, LLC · THREAT & HAZARD ASSESSMENT — MODULE 01
Demo Sandbox
ECHO ships with a demo sandbox — a separate copy pre-loaded with a worked threat assessment for a fictional AO: four threats across three categories (an extended grid failure with a full POETE evaluation, warning indicators under collection, and a capability target; a refugee-flow scenario with an actor profile; winter storm isolation; and a drought-year wildfire), each scored, with open gaps feeding the corrective roadmap.
Opening and leaving. In the live module, click DEMO in the sidebar under this manual. Inside the demo, that same slot reads RETURN TO LIVE and takes you back. An amber banner across the top of the demo tells you which copy you are in at all times.
Your real data is safe. The demo keeps everything in separate storage slots, including its own OSINT Station import queue and its own SENTINEL read, so nothing you do in the demo can touch your real threat register — and accepting or dismissing an import in the demo can never consume a real pending push.
Cross-sandbox wiring. The demo reads OPSCON context from the SENTINEL demo, receives threat pushes from the HUMINT Registry demo's queue, and the DEBRIEF demo writes its gap findings into this same demo slot: link a demo AAR finding to one of these threats and it lands in that threat's gap analysis. The demo sandboxes form one connected training environment.
Resetting. The ↻ RESET DEMO button in the top bar discards any changes and restores the sample assessment.