CORE PATH Stop 10 / 106
Also on the Essential Path · 9/18

How We Prove Hidden Operations: From Suspicion to Document

How do we distinguish suspicion from a documented hidden operation? This article sets out a method based on claim decomposition, provenance, authenticity, chronology, triangulation, FOIA, declassification, archival gaps, and calibrated confidence.

When something is hidden, an unusual problem appears: the absence of public evidence may mean that the evidence is not yet accessible — or it may mean that the claim is false. Suspicion alone cannot distinguish between those possibilities. A historian, journalist, or researcher examining secret activity therefore needs not weaker standards than for open events, but usually stronger ones.

This article sets out a method for such cases. It does not ask whether a claim has been labelled a "conspiracy theory". It asks: what exactly is being claimed, which parts are testable, where the documents came from, what a document actually establishes, which independent traces converge, and what remains missing?

The central rule is simple: secrecy reduces the amount of publicly available information; it does not lower the evidentiary standard. Unknown does not automatically mean false — but it does not automatically mean true either.

A label is not evidence: remove the phrase ‘conspiracy theory’ first

The phrase ‘conspiracy theory’ can describe a kind of explanation, function as a political or media label, or serve as a rhetorical weapon. The label itself tells us nothing decisive about whether a specific claim is true. History contains real conspiracies, false suspicions, partly accurate reconstructions, and stories in which true facts are connected by false inferences.

This article therefore avoids the symmetrical error. It does not reject a claim because it sounds conspiratorial, and it does not accept a claim because some conspiracies in history were real. The method begins before the label: who is alleged to have coordinated, what did they allegedly do, when, by what means, toward what objective, and which relationship was allegedly concealed?

Once a claim is broken into testable components, much of the rhetorical fog disappears. The question is no longer ‘do you believe in the conspiracy?’ but ‘which concrete components are established, and by what evidence?’

Large hidden-operation narratives often arrive as a package: a programme existed; it performed a specific action; the order came from a particular level; every participant knew the overall objective; and the eventual outcome was intended from the beginning. Those are five different claims, not one.

An archive may strongly establish the programme’s existence, fairly strongly establish its funding, only weakly establish a specific operational act, and provide no support for the motive later attributed to it. If the components are fused together, evidence for one part begins to function illegitimately as evidence for every other part.

Covert Operations: How Power Acts Outside Public View introduced component-level language discipline. This article turns it into a method: for each important subclaim, keep a separate record of supporting evidence, counterevidence, ambiguity, and confidence. A documented component is not permission to jump across an undocumented one.

Archival work begins before we read the dramatic sentence. The U.S. National Archives defines provenance in part as information about the chain of ownership and custody of records, and organises holdings through creators, record groups, series, file units, and items. That matters because a document located within an official archival context is not evidentially identical to an image of the same-looking document circulating without origin on social media.

Provenance helps answer: which fonds or record group contains the item, which institution created or maintained it, which series it belongs to, whether there is a catalogue entry, file number, transfer history, declassification marking, or other custody trail. A document becomes stronger when it can be placed inside a records system, not merely when it looks official.

Good provenance still does not mean that every statement inside the document is true. It primarily gives us better reason to believe that the record is what it purports to be and tells us the institutional context from which it came.

Microfilming of public records in New Jersey in 1937 as part of the Historical Records Survey.
Microfilming public records in New Jersey in 1937. The photograph illustrates the material side of archival provenance: records are preserved, reproduced, described and transferred through concrete custody procedures. That trace helps distinguish an archival record from an unattributed copy circulating without context. Image: U.S. National Archives / Works Progress Administration / Wikimedia Commons Public domain — U.S. federal government

An authentic document can contain false information

This is one of the most important distinctions in the entire method. Document authenticity and truth of content are not the same thing. A genuine intelligence memorandum may contain rumour, a source error, or a flawed assessment. A genuine minute may accurately record what someone said without making the statement itself true. A genuine propaganda plan proves the existence of the plan, not the truth of the propaganda claims.

The National Archives therefore teaches primary-source analysis by asking not only who wrote a record and when, but why it was created, what was happening at the time, and what other documents are needed to understand the event. A primary source is a more direct trace of the past, not an infallible camera.

A careful formulation is therefore: ‘the document shows that the author reported or believed X at the time’, until other evidence supports the stronger statement ‘X occurred’.

Documents have functions. An invoice records payment. An order directs action. Minutes record discussion. An intelligence estimate assesses an uncertain situation. A press release communicates outward. An internal memorandum may seek to persuade a superior or protect its author from responsibility. The genre of a record affects what we can reasonably infer from it.

An operational order is usually stronger evidence of intent to carry out an action than a decades-later memory that such an order existed. But the order alone still does not prove execution. For execution, we look for an after-action report, logistical trace, financial record, field communication, or an independent event that fits the chronology.

A useful question is: what would this document establish even if my preferred explanation were wrong? That helps prevent us from importing a conclusion the record does not contain.

Hidden operations unfold in time. An evidentiary chain therefore needs a chronology: when was a decision made, when was money authorised, when was a communication sent, when did the public event occur, and when were later recollections recorded? A document created before an event has a different evidentiary role from a memory recorded thirty years later.

Chronology also exposes impossible links. If a decision supposedly caused an event, it must precede it. If a particular phrase or narrative appears only after public disclosure, it is a different kind of trace from a contemporaneous internal record. If a document is undated or its date is uncertain, that uncertainty belongs in the conclusion.

In MKUltra and ARTICHOKE: When Mind-Control Research Became a Secret Program and TPAJAX and PBSUCCESS: Anatomy of a Covert Coup, chronology will be one of the main safeguards against collapsing decades of different programmes into one story.

Distribution, copies, and administrative traces can show who may have known what

Important evidence often sits outside the main prose of a document: recipient lists, copy numbers, initials, attachments, reference numbers, stamps, marginalia, or citations to earlier memoranda. Such traces can help reconstruct the flow of information.

But caution still matters. A name on a distribution list does not prove that the person actually read the document, understood every detail, or approved everything that followed. A signature may indicate authorisation, acknowledgement, or an administrative step depending on the system.

Proving ‘who knew’ therefore requires more than a screenshot containing names. The strongest reconstruction links distribution with subsequent communications, decisions, or actions.

One document can change a question; several genuinely independent records can change confidence. Triangulation means comparing different kinds of evidence that are not merely copies of one original source: archival memoranda, budget or financial records, correspondence from another institution, judicial or legislative records, contemporaneous reporting, material traces, and testimony.

The key word is independent. Ten websites citing the same anonymous source are not ten confirmations. Three newspapers repeating the same wire report are not three independent traces. Two official documents may likewise descend from the same faulty initial report.

The Berkeley Protocol for digital open-source investigations and later methodological guidance emphasise source tracing, context, metadata, and—where possible—triangulation with documentary, testimonial, or physical evidence. Source count is not source independence.

Large operations rarely exist only as ideas. They require people, travel, invoices, contracts, storage, communications, permissions, expenditures, or transfers. Administrative traces are therefore often less dramatic but highly valuable.

A financial record can establish that money moved from A to B; it does not necessarily tell us what it funded or whether the recipient knew the ultimate source. A travel order may establish presence in a place, not purpose. A contract can show an institutional relationship without automatically proving covert operational control.

A strong reconstruction therefore does not hunt for one ‘smoking gun’ at all costs. Often a pattern of mutually consistent bureaucratic traces is stronger, especially when plausible alternatives explain it poorly.

Testimony matters — and has limits

Witnesses, former operatives, victims, officials, and whistleblowers may reveal information absent from documents. Testimony can lead researchers to correct names, codewords, or archival files. But Memory Is Not a Recording: How We Reconstruct the Past has already shown that human memory is reconstructive, especially across long intervals.

Testimony becomes stronger when it is contemporaneous, specific, against the speaker’s interest, given under conditions of accountability, and corroborated by other traces. It becomes weaker when decades-later accounts expand into increasingly specific details that connect to no independent record. A person’s status does not by itself make every statement true.

Even sworn testimony before a legislature or court is not magical confirmation. It is a more traceable and consequential source, but still one to compare with documents, chronology, and other witnesses.

Investigative journalism has repeatedly opened subjects before public archives were accessible. A leak or anonymous source can therefore rationally change the probability of a claim and trigger further investigation. Its initial weakness, however, is often incomplete provenance.

Where possible, verify the original file, metadata, publication time, prior versions, signatures or visual features, consistency with known records, and institutional response. With digital imagery, location and time may also need verification. The Berkeley Protocol was developed precisely to make the collection, verification, and preservation of open-source digital information professionally traceable.

An anonymous source may be truthful and crucial. But anonymity removes some of the researcher’s ability to independently assess motive, access, and credibility, so it creates a greater need for corroboration, not a smaller one.

The Freedom of Information Act is a powerful route into U.S. federal records, but FOIA.gov explicitly notes that not every record must be released: nine categories of exemptions protect interests including national security, privacy, privileged materials, and law enforcement. Intelligence records may also contain redactions or remain classified longer.

Automatic declassification after 25 years also has exceptions. The National Archives describes extended protection for categories such as sensitive sources and methods. The absence of a record from today’s online archive is therefore not enough to prove that the record never existed or that an event could not have occurred.

The reverse is equally important: ‘perhaps it is still classified’ cannot function as positive evidence. A classified possibility is a zone of ignorance, not a blank cheque for any explanation.

A CIA document on nuclear terrorism with substantial portions redacted.
An example of a publicly accessible CIA document containing extensive redactions. Its release establishes that the record exists and that some content is available; the blacked-out portions also make visible why “declassified” or “released” does not necessarily mean “complete”. Image: Central Intelligence Agency (CIA) / Wikimedia Commons Public domain — U.S. federal government

An archive is a sample of the past, not a perfect copy of it

Even an open bureaucracy does not preserve everything. NARA explains that some federal records are permanent and transferred to the National Archives, while others are temporary and may be lawfully destroyed under approved retention and disposition schedules. Part of the historical record is therefore selected through records management long before a historian arrives.

Intelligence archives add classification, redaction, delayed transfer, and institutional differences. NARA explicitly warns that the CIA retains many records longer because of their sensitivity and that transferred collections may still be redacted. Scholarship on intelligence history likewise stresses problems of incomplete sources, selective release, and the motives surrounding disclosure.

An archival gap is a fact about our sources, not a direct fact about the event. It may weaken a positive conclusion and require more caution, but by itself it does not prove concealment.

A declassification stamp is an important provenance trace, but the process is not infallible. NARA’s own audits have documented inappropriate reclassification, overbroad withdrawal of previously open material, and insufficient documentation about the classification status of some records. This is a reminder to separate the content of a record from the administrative status of a record.

Such errors do not make the entire archive unreliable. On the contrary, procedures, audits, catalogue systems, and change records allow researchers to see part of the institutional history of a document. But the ideal ‘once declassified = completely settled’ is too simple.

For sensitive records, it is therefore useful to preserve version information, release dates, redactions, and the original archival identifier—not only the sentences that support our interpretation.

Official acknowledgement is powerful — but not an absolute summit of evidence

When a government, legislative committee, court, or official historical series confirms a previously denied or unacknowledged programme, the evidentiary position changes substantially. The Church Committee, for example, produced a public legislative record after an extensive intelligence investigation. FRUS is legally designed to provide a thorough, accurate, and reliable documentary record of major U.S. foreign-policy decisions.

But official records have histories too. The Office of the Historian describes the crisis surrounding an older FRUS Iran volume that omitted documentation of a significant covert operation; that controversy helped drive the 1991 statutory reforms. Institutional acknowledgement is therefore important, but official status alone does not make a collection complete.

The strongest cases arise when official acknowledgement converges with archival records, independent institutions, and chronologically consistent traces. Then we do not need faith in a single authority; we have convergence across different routes.

Sometimes the absence of an expected record is informative. If a system routinely generates a particular record, the relevant series is well preserved, and records exist immediately before and after the alleged event, a missing trace can reduce the claim’s probability. But we must first show why the record should have existed and why we should expect it to have survived.

Without those conditions, an argument from silence is weak. Secret operations may involve oral decisions, compartmentalisation, different record systems, lawfully destroyed temporary records, still-classified material, or archives held by another state. These are possibilities, not proof, but they limit how strong a negative inference can be.

The careful formulation is often: ‘we found no confirmation in the public material reviewed’, rather than automatically ‘it did not happen’. Equally important: lack of confirmation does not permit the claim ‘therefore it was definitely hidden’.

Test alternatives, not only your hypothesis

A good hidden-operation hypothesis must compete with alternatives. Could the same money flow be an ordinary contract? Could the timing be explained without coordination? Is the unusual phrase standard bureaucratic language? Does the document describe a plan that was never implemented? Evidence becomes stronger when it reduces the plausibility of reasonable alternatives, not merely when it is compatible with our story.

This is especially important with anomaly stacking: piling up ten unusual details, none of which has a clear connection to the alleged mechanism. A large number of weak anomalies does not automatically become strong evidence if they are dependent or each has a simple alternative explanation.

Where Does Fact End and Interpretation Begin? separated fact from interpretation. This article adds the specialist question: what alternative would produce the same archival pattern, and what new source could distinguish between them?

For THY-REALITY publications, a five-level discipline is useful. 1. Claim or suspicion: a question exists but the public evidence is insufficient. 2. Indicator: a trace is consistent with the claim but allows multiple explanations. 3. Partly documented: one or more important components are established while others remain open. 4. Well documented: multiple independent, high-quality sources establish the key components. 5. Very well documented or institutionally confirmed: primary records, independent corroboration, and official investigative or archival records substantially converge.

This is not a mathematical probability scale, and level five does not mean ‘100 percent of every detail’. Even a very well documented event may retain disputed questions about motive, numbers of participants, side operations, or long-term effects.

The key is that language follows evidence. If programme existence is documented, say that. If a specific effect is only probable, qualify it. If something is unknown, do not fill the gap with certainty.

From suspicion to a publishable conclusion

The method can be compressed into nine steps. (1) Decompose the claim into testable components. (2) State what would support or weaken each component. (3) Find the best primary source and establish provenance. (4) Separate document authenticity from truth of content. (5) Build a chronology. (6) Seek genuinely independent traces in other archives or evidence types. (7) Test alternatives and identify missing information. (8) Assign a confidence level to each component. (9) In publication, clearly distinguish established, probable, disputed, and unknown claims.

Add research hygiene: preserve a stable URL or archival identifier, access date, document title, creator, creation date, page or relevant section, and where appropriate a lawful local copy. For digital sources, preserve the original file and metadata when legally and ethically permitted.

The process is slower than a viral narrative, but it has one decisive advantage: it allows the reader to distinguish what was actually hidden from what we merely assumed had been hidden.

The next articles will not begin by asking whether we ‘believe’ in MKUltra, ARTICHOKE, TPAJAX, or PBSUCCESS. They will begin with records and components. For each programme we will separate existence, purpose, authorisation, methods, participants, actual events, later investigations, and open questions.

That matters because some of these cases have long been historically documented. The interesting question is no longer only ‘was something hidden?’ but what exactly is established today, which parts of the popular narrative exceed the archive, and what does the difference teach us about how historical knowledge is built?

This article is therefore not a manual for proving a favourite secret explanation. It is a protocol against double standards: do not believe authority merely because it is official—and do not believe suspicion merely because authority has lied before. Follow the evidentiary chain.

Sources and further reading

  1. U.S. National Archives and Records Administration. Analyze a Written Document — primary-source analysis framework asking who created a document, why it was created, its historical context, and what additional evidence is needed.
  2. U.S. National Archives and Records Administration. Archives and Records Management Resources — terminology entry for provenance, including chain of ownership/custody and the archival principle of keeping creators' records distinct.
  3. U.S. National Archives and Records Administration. Using the National Archives Catalog — explains record groups, series, file units, items, creators, and archival hierarchy.
  4. U.S. National Archives and Records Administration. Record Group Concept — explains arrangement according to provenance and the relation between agency creators and record series.
  5. U.S. National Archives and Records Administration. Records of the Central Intelligence Agency — explains delayed transfer, continuing classification, and redactions affecting CIA archival holdings.
  6. Central Intelligence Agency. Freedom of Information Act Electronic Reading Room — official repository for released and declassified CIA historical records.
  7. FOIA.gov. Freedom of Information Act Frequently Asked Questions — official explanation that FOIA contains nine exemptions and does not require release of all agency records.
  8. U.S. National Archives, Office of Government Information Services. Using FOIA to Access Intelligence Community Records (2025) — explains FOIA, Mandatory Declassification Review, and the 25/50/75-year review framework for intelligence records.
  9. U.S. National Archives. Executive Order 13526, Classified National Security Information — automatic declassification framework and exemptions for historically valuable classified records.
  10. U.S. National Archives and Records Administration. Scheduling Records — official explanation that federal records may be permanent or temporary and that approved schedules can authorize lawful destruction or require archival transfer.
  11. U.S. Department of State, Office of the Historian. About the Foreign Relations of the United States Series — official description of FRUS as the statutory documentary record of major U.S. foreign-policy decisions and diplomatic activity.
  12. 22 U.S.C. § 4351. Foreign Relations of the United States historical series — statutory requirement for a thorough, accurate, reliable and comprehensive documentary record, with historical objectivity and accuracy.
  13. U.S. Department of State, Office of the Historian. History of the Foreign Relations Series, Introduction — describes the crisis caused by an Iran volume that omitted documentation of a significant covert operation and the reforms that followed.
  14. U.S. Senate Historical Office. Senate Select Committee to Study Governmental Operations with Respect to Intelligence Activities (Church Committee) — official history of the 1975–1976 investigation and final report.
  15. U.S. Senate Select Committee on Intelligence. Intelligence Related Commissions — official repository linking Church Committee rules, interim reports, staff reports and final books.
  16. Human Rights Center, UC Berkeley & UN Office of the High Commissioner for Human Rights (2020/2022). Berkeley Protocol on Digital Open Source Investigations — standards for collecting, preserving, verifying and analysing digital open-source information.
  17. Human Rights Center, UC Berkeley et al. (2024). Evaluating Digital Open Source Imagery: A Guide for Judges and Fact-finders — guidance on authenticity, metadata, source, location and time when evaluating open-source images and video.
  18. Freeman, L. et al. Cutting-Edge Evidence: Strengths and Weaknesses of New Digital Investigation Methods in Litigation — recommends preservation, transparent methods and triangulation of digital evidence with documentary, testimonial or physical evidence where possible.
  19. Haslam, J. (ed.) (2013). Secret Intelligence in the European States System, 1918–1989 — scholarly overview stressing uncertainty about reliability, completeness and motives behind release of intelligence sources.
  20. Thurlow, R. C. (2008). The Historiography and Source Materials in the Study of Internal Security in Modern Britain (1885–1956), History Compass 6(1), 147–171 — discusses how selective declassification expands evidence while important documentary gaps remain.
  21. Sherman, D. (2020). Barbara Tuchman’s The Zimmermann Telegram: secrecy, memory, and history, Journal of Intelligence History 19(2), 125–148 — case study of secrecy, deliberate misdirection, archival access and persistence of established interpretations even after better evidence appears.
  22. U.S. National Archives, Information Security Oversight Office. 2006 Audit Report — documents improper reclassification/withdrawal and inconsistent documentation in historical declassification processes, illustrating that administrative status itself requires scrutiny.