Operational protocol

Crisis Narrative Coordination Protocol

A practical protocol for helping foreign ministries coordinate assessment, authority and action when a narrative incident may create diplomatic consequence.

Operational Protocol | Version 1.0 | August 2026 | Adaptable to national structures

Context

The coordination problem

A narrative incident rarely belongs to one team.

A diplomatic mission may see the local meaning first. A monitoring team may detect propagation across platforms. A geographic desk may understand the bilateral stakes. Policy, legal and security functions may identify constraints or wider consequences. A spokesperson or strategic communications team may need to advise whether, when and how the institution should speak. A senior authority may need to decide among diplomatic, operational and public options.

These capabilities already exist in many foreign ministries. The operational risk appears in the handoffs: when evidence, context, policy judgement, communication and authority move at different speeds.

The Crisis Narrative Coordination Protocol provides a common incident sequence, a four-level severity model, a minimum common operating picture and a responsibility structure that ministries can adapt to their existing organisation.

It is designed to strengthen institutional judgement, coordination and readiness.

Relationship

How this protocol fits

The Narrative Resilience Framework explains the enduring capability an institution builds over time. The Crisis Narrative Coordination Protocol explains what the institution does during a material incident.

Narrative Resilience function

Ground

Incident-time application in this protocol

Establish the policy facts, official position, evidence and boundaries relevant to the incident.

Narrative Resilience function

Sense

Incident-time application in this protocol

Detect, preserve and register the signal; verify its source, content and distribution.

Narrative Resilience function

Interpret

Incident-time application in this protocol

Assess severity, context, intent, reach, uncertainty and diplomatic consequence.

Narrative Resilience function

Align

Incident-time application in this protocol

Assign a lead and create a common operating picture across Mission and HQ.

Narrative Resilience function

Choose posture

Incident-time application in this protocol

Select, authorize and coordinate the institutional posture and delivery.

Narrative Resilience function

Learn

Incident-time application in this protocol

Monitor effects, stand down responsibly, preserve the record and update practice.

The framework and protocol use the same institutional logic without duplicating one another.

Review the Narrative Resilience Framework

Definition and activation scope

The object of the protocol: a narrative incident

For this protocol, a narrative incident is a time-bounded development in the information environment that may materially affect a ministry's diplomatic position, institutional credibility, operational activity, personnel, public responsibilities, or bilateral and multilateral relationships - and therefore requires coordinated assessment or action.

It may involve:

  • manipulated, synthetic, falsely attributed or miscontextualized content;
  • a coordinated information operation or a possible component of a wider campaign;
  • an authentic event whose meaning is being distorted in a consequential way;
  • impersonation of an official, mission or institutional account;
  • a leak, mistranslation or false quotation;
  • conflicting public lines across missions, partners or government functions;
  • an information vacuum during a diplomatic or consular crisis;
  • a fast-moving claim with potential safety, security or bilateral consequences.

The protocol is broader than FIMI. It can be used before foreign involvement, manipulation or intent is established. It does not convert routine criticism, contested policy debate or unfavourable reporting into a crisis.

Design principles

Design principles

  1. 01

    Use existing structures first. Map the protocol onto the ministry's current crisis, policy, communication, legal, security and records arrangements.

  2. 02

    Keep the response proportionate. Most signals do not require a crisis cell or a public correction.

  3. 03

    Separate evidence, assessment and decision. A verified fact, an analytical judgement and an authorized posture are different institutional objects.

  4. 04

    Keep confidence separate from severity. A low-confidence signal can still have high potential consequence; a verified falsehood can remain low severity.

  5. 05

    Preserve local context. The mission contributes language, culture, stakeholder knowledge and host-country consequence that central monitoring cannot reliably infer alone.

  6. 06

    Retain institutional authority. Tools and AI may assist triage and analysis; people retain responsibility for severity, attribution, posture and authorization.

  7. 07

    Treat restraint as an active posture. Monitoring, private engagement or deliberate non-response may be more effective than public rebuttal.

  8. 08

    Record the decision trail. The institution should be able to reconstruct what was known, assessed, decided and authorized at each material point.

  9. 09

    Protect lawful expression. Criticism, disagreement or inconvenient reporting does not become a narrative incident merely because it is uncomfortable. Activation requires a plausible diplomatic, institutional, operational, security or public-interest consequence that needs coordination.

  10. 10

    Learn without creating permanent crisis mode. Stand down the acute coordination structure when its thresholds are no longer met, preserve lessons and return ownership to normal structures.

Operating sequence

The eight-stage operating sequence

Stage 1Detect and register the incidentStage 2Verify the content, source and current distributionStage 3Assess severity and potential diplomatic consequenceStage 4Assign an incident lead and responsible institutional rolesStage 5Build a common operating picture with explicit confidence levelsStage 6Select the institutional postureStage 7Coordinate authorization, timing and Mission-HQ deliveryStage 8Monitor the effects, recover and conduct an after-action review

1. Detect and register the incident

Create a traceable record as soon as a signal crosses the ministry's reporting threshold. Preserve the original content and relevant metadata where lawful and safe. Do not rely on screenshots alone when links, files, timestamps or account information can be retained.

Minimum output

  • incident identifier;
  • date, time and detecting function;
  • original content or secure reference;
  • platform, channel, language and location;
  • initial source and distribution observations;
  • affected official, mission, policy or relationship;
  • immediate safety or operational concern;
  • next review time and provisional owner.

Registration does not imply that the content is false, coordinated, foreign or severe. It creates continuity while those questions are assessed.

2. Verify the content, source and current distribution

Establish what can be confirmed and what remains unresolved. Examine the content's authenticity, provenance and context; the source account or channel; translation accuracy; first observable appearance; current reach; cross-platform movement; and signs of coordinated or artificial amplification.

Where appropriate, use existing analytical approaches such as ABCDE, TTP catalogues, STIX-compatible sharing or IMS. The protocol does not replace specialist analysis.

Minimum output

  • content status: authentic, altered, synthetic, miscontextualized, false or unresolved;
  • source status: confirmed, probable, unknown or spoofed;
  • observed distribution and trajectory;
  • evidence preserved and checks completed;
  • key gaps, competing explanations and collection requests;
  • confidence level with a short rationale.

Avoid premature attribution. Technical association, likely sponsorship and authorized public attribution are separate judgements.

3. Assess severity and potential diplomatic consequence

Assess the incident against the ministry's interests and responsibilities, not visibility alone. Consider:

  • diplomatic and policy consequence;
  • effect on personnel, operations, security or consular responsibilities;
  • sensitivity of the target, timing and audience;
  • reach, velocity, cross-border movement and persistence;
  • actor capability or evidence of coordination;
  • potential for escalation, miscalculation or partner divergence;
  • reversibility and the likely cost of delay;
  • the risk that an institutional response would amplify the incident.

Assign a provisional level from 1 to 4. Record the rationale and the trigger that would move the incident up or down. Severity may change as facts, distribution or political context change.

4. Assign an incident lead and responsible institutional roles

Name one incident lead with responsibility for the coordination process, not ownership of every specialist judgement. The lead may sit in a mission, geographic desk, crisis structure or other designated function depending on the incident and the ministry's organisation.

Confirm:

  • the incident lead and alternate;
  • the policy owner;
  • the local mission contact;
  • monitoring and verification support;
  • communication lead;
  • legal and security advisers;
  • required decision authority;
  • secure working channel and reporting rhythm;
  • out-of-hours and handover arrangements.

Functional roles matter more than organisational titles. In a smaller foreign ministry, one person may perform more than one function, but the distinction between evidence, advice and authorization should remain visible.

5. Build a common operating picture with explicit confidence levels

Produce a concise, time-stamped account that allows the institution to act from the same baseline.

A common operating picture is not forced consensus. It should preserve disagreement, uncertainty and alternative assessments where these are material to the decision.

Minimum content

  1. 01confirmed facts;
  2. 02current analytical assessments;
  3. 03unknowns and active information requests;
  4. 04content, source and distribution status;
  5. 05affected interests, audiences and stakeholders;
  6. 06actual and plausible diplomatic or operational consequences;
  7. 07current severity and confidence, with rationale;
  8. 08decisions already taken and actions under way;
  9. 09decision points, owners and deadlines;
  10. 10next update and escalation or stand-down triggers.

The picture should be versioned. Material corrections must remain traceable rather than silently overwriting earlier assessments.

6. Select the institutional posture

Choose the posture that best protects the institution's objectives, credibility and room for diplomatic action.

Posture

Monitor

Appropriate when

Evidence, spread or consequence remains limited.

Typical expression

Continue collection; define escalation triggers.

Posture

Clarify

Appropriate when

Genuine uncertainty or information gaps are driving confusion.

Typical expression

Provide verified context, privately or publicly.

Posture

Engage

Appropriate when

A targeted stakeholder, partner, platform or host authority can reduce risk.

Typical expression

Diplomatic contact, stakeholder briefing or platform engagement.

Posture

Correct

Appropriate when

A material factual falsehood is established and correction is likely to reduce harm.

Typical expression

Factual correction, spokesperson line or coordinated statement.

Posture

Pre-empt

Appropriate when

A credible threat is expected and accurate information can reduce vulnerability.

Typical expression

Prepared facts, advance briefing or trusted-messenger engagement.

Posture

Escalate

Appropriate when

The incident exceeds one team's authority or requires wider government, legal, security, platform or multilateral action.

Typical expression

Senior referral, crisis activation or partner mechanism.

Posture

Deliberately refrain

Appropriate when

Public response would amplify the incident, compromise another objective or move ahead of the evidence.

Typical expression

Continue monitoring, private action or documented non-response.

The posture is an institutional decision, not automatically a public message. Several postures may be combined across different channels and time horizons.

7. Coordinate authorization, timing and Mission-HQ delivery

Translate the chosen posture into controlled action. Confirm who may approve which element, what can be adapted locally and what must remain consistent across the network.

Minimum coordination questions

  • What is the intended institutional effect?
  • Which audience or counterpart matters most?
  • Who has final authorization at the assigned level?
  • Is a holding line required before a full assessment is complete?
  • Which facts, policy boundaries and wording must remain common?
  • What may the mission adapt for local language, culture and channel?
  • Which private diplomatic, public, legal, security, platform or partner actions are sequenced together?
  • Who speaks, through which channel and at what time?
  • How will instructions and approvals be recorded?
  • What change would pause, alter or escalate delivery?

The objective is coordinated judgement, not identical wording in every context. Local adaptation should remain inside clearly defined policy and authority boundaries.

8. Monitor the effects, recover and conduct an after-action review

Track whether the institutional action changed the risk, created unintended amplification or exposed a wider vulnerability. Update the common operating picture and severity level as the information environment changes.

Stand down acute coordination when:

  • the incident no longer meets the activation threshold;
  • immediate response objectives have been met or transferred;
  • there is no material risk of near-term resurgence;
  • normal governance is again the most suitable structure;
  • any enduring issue has a named owner and handover record.

Conduct an after-action review while the decision trail is still recoverable. Review the timeline, evidence, assumptions, decisions, approvals, delivery effects, missed signals, staff pressure and handoffs. Convert findings into assigned changes to policy facts, contact lists, authority routes, templates, tools, training or exercises.

Severity

Severity model

Severity describes potential institutional consequence and the coordination required. It does not describe whether the content is true, whether attribution is complete or how confident the assessment is.

Level

1 - Signal

Condition

Local or low-confidence signal with no material consequence established.

Default institutional response

Monitor, preserve and verify.

Default coordination level

Mission or monitoring function; desk informed as required.

Level

2 - Material

Condition

Material narrative with limited or growing spread, or a bounded diplomatic consequence.

Default institutional response

Conduct a coordinated assessment and prepare options.

Default coordination level

Geographic desk or designated operational lead with Mission, monitoring and communications input.

Level

3 - Serious

Condition

Significant institutional, bilateral, multilateral, personnel, security, consular or operational risk.

Default institutional response

Activate response coordination, maintain a common operating picture and establish a decision rhythm.

Default coordination level

Designated senior official or crisis lead; relevant functions actively engaged.

Level

4 - Critical

Condition

Strategic, cross-government, crisis or leadership-level consequence, including serious risk of escalation or miscalculation.

Default institutional response

Immediate senior escalation and controlled response through the appropriate national structure.

Default coordination level

Top official, political authority and/or national crisis mechanism as law and policy require.

Applying the levels

  • Assess the highest material consequence, rather than averaging dimensions into a reassuring score.
  • A small but highly sensitive incident can be Level 4. Reach is not the sole measure of severity.
  • Low confidence does not automatically mean low severity. It means the uncertainty must be visible in the decision.
  • Set an escalation trigger and a stand-down trigger whenever a level is assigned.
  • Map each level to the ministry's existing authority and out-of-hours arrangements before operational use.
Confidence

Confidence model

Use confidence to communicate how much weight decision-makers should place on an analytical judgement.

Confidence

High

Working definition

The information base is good quality and corroborated; the analysis is rigorous; the judgement is reasonably stable despite the environment.

Required note

State the strongest supporting evidence and any residual uncertainty.

Confidence

Moderate

Working definition

The judgement is supported but important gaps, mixed evidence or credible alternatives remain.

Required note

State the principal gap and what could change the assessment.

Confidence

Low

Working definition

The information base is limited, uncorroborated or rapidly changing, or analytical complexity materially weakens the judgement.

Required note

State why the judgement is still being presented and what verification is needed.

Confidence and probability are not interchangeable. Confidence concerns the foundations of the judgement; probability concerns how likely the judgement is to be true.

Every confidence label should include a short rationale. A model-generated score is not an institutional confidence rating.

Responsibilities

Responsibility matrix

These are functional responsibilities. Ministries should map them to their existing units, grades, legal mandates and duty systems.

Function

Diplomatic mission

Primary responsibility during the incident

Detect and localize the incident; supply host-country context; execute authorized local engagement or communication.

Distinct contribution

Language, culture, local stakeholders, political meaning, local media and operational consequences.

Decision boundary

Does not independently alter national policy or make high-consequence attribution unless already authorized.

Function

Regional or geographic desk

Primary responsibility during the incident

Connect the incident to bilateral, regional and foreign-policy interests; coordinate HQ input; usually provide or support the incident lead.

Distinct contribution

Policy ownership, relationship history, partner positions and consequences across the country or region.

Decision boundary

Escalates decisions beyond delegated policy or communication authority.

Function

Digital monitoring team

Primary responsibility during the incident

Preserve, verify and analyse content, source, distribution, behaviour and trajectory; maintain analytical updates.

Distinct contribution

OSINT, platform and network analysis, TTPs, technical indicators and confidence rationale.

Decision boundary

Provides analysis; does not independently determine diplomatic posture or public attribution.

Function

Spokesperson or strategic communications

Primary responsibility during the incident

Advise on information effects, audiences, response options, lines, channels and timing; coordinate public delivery and monitor effects.

Distinct contribution

Media judgement, message discipline, trusted messengers, amplification risk and evaluation.

Decision boundary

Public communication remains inside approved policy facts and authorization.

Function

Policy, legal and security functions

Primary responsibility during the incident

Confirm institutional facts and policy; assess legal, personnel, security, intelligence, records and operational implications.

Distinct contribution

Guardrails, evidence requirements, rights, protection duties, classified context and available non-communication levers.

Decision boundary

Specialist advice does not replace the designated decision authority.

Function

Senior decision authority

Primary responsibility during the incident

Resolve material trade-offs and authorize high-consequence posture, escalation, attribution or coordinated response.

Distinct contribution

Institutional risk appetite, cross-government authority and political or senior-official accountability.

Decision boundary

Acts through applicable law, policy, ministerial responsibility and national crisis arrangements.

Stage ownership at a glance

Stage

Detect and register

Default lead

Mission or digital monitoring

Core contributors

Geographic desk; security if immediate risk

Authorization point

Operational threshold only

Stage

Verify

Default lead

Digital monitoring or designated analytical function

Core contributors

Mission; communications; legal/security

Authorization point

None for analysis; escalation if protected data or capabilities are required

Stage

Assess severity

Default lead

Geographic desk or incident lead

Core contributors

Mission; monitoring; communications; policy/legal/security

Authorization point

Assigned authority confirms material Level 3-4 activation

Stage

Assign lead and roles

Default lead

Geographic desk, duty manager or crisis function

Core contributors

All affected functions

Authorization point

Authority depends on incident level

Stage

Build common operating picture

Default lead

Incident lead

Core contributors

All affected functions

Authorization point

Lead clears the version for decision use

Stage

Select posture

Default lead

Policy owner and communications lead advise jointly

Core contributors

Mission; monitoring; legal/security

Authorization point

Designated authority chooses within the level-specific ladder

Stage

Authorize and deliver

Default lead

Incident lead coordinates; Mission and communications execute

Core contributors

Monitoring; policy/legal/security

Authorization point

Required authority explicitly recorded

Stage

Monitor, recover and review

Default lead

Incident lead or enduring owner

Core contributors

All affected functions

Authorization point

Designated authority confirms stand-down or handover

Authority

Authority ladder

The protocol does not prescribe titles. It requires each institution to map severity to real decision rights.

Incident level

Level 1

Minimum authority design question

Who may close, continue or elevate routine monitoring?

Incident level

Level 2

Minimum authority design question

Who may convene a coordinated assessment and approve a holding line or bounded engagement?

Incident level

Level 3

Minimum authority design question

Who may activate cross-functional response coordination and authorize material public or diplomatic action?

Incident level

Level 4

Minimum authority design question

Which senior official, ministerial and national crisis authorities must be engaged immediately?

Every level requires a named alternate and an out-of-hours route. An authority that cannot be reached under pressure is not an operational authority.

Record

The minimum common operating picture

The protocol can be run with one controlled page or record containing:

Field

Control

Required content

Incident ID, version, timestamp, handling level, incident lead, next update

Field

Classification

Required content

Severity level, content status, source status and analytical confidence

Field

Confirmed

Required content

Facts supported by current evidence

Field

Assessed

Required content

Key judgements, alternatives and confidence rationale

Field

Unknown

Required content

Information gaps, collection tasks and owners

Field

Distribution

Required content

Observed channels, audiences, geography, velocity and trajectory

Field

Consequence

Required content

Current and plausible diplomatic, institutional, operational or security effects

Field

Posture

Required content

Agreed objective, posture, constraints and triggers for change

Field

Action

Required content

Action, owner, deadline, dependency and completion status

Field

Authority

Required content

Decision, approver, time, rationale and any conditions

Field

Coordination

Required content

Mission-HQ instructions, partner contact and local adaptation boundaries

Field

Transition

Required content

Escalation, de-escalation, handover and stand-down criteria

Tooling

The role of AI and digital tools

Approved tools may help teams:

  • detect unusual propagation or coordinated behaviour;
  • cluster related content and identify duplicates;
  • support translation and transcription;
  • compare versions of audio, video, images or text;
  • summarise large open-source collections;
  • prepare draft timelines, information requests or briefing structures.

Human authority should remain explicit for:

  • deciding whether the incident threshold is met;
  • assigning severity and institutional confidence;
  • determining policy and diplomatic consequence;
  • attributing an operation or actor;
  • choosing the institutional posture;
  • authorizing communication, diplomatic or other action;
  • closing the incident and accepting lessons.

Sensitive or protected material should not be entered into tools that are not approved for the relevant information. Material AI assistance should be traceable by tool, user, time and verification status. AI confidence is not institutional confidence.

Illustration

A worked incident

A video appears to show an ambassador making an inflammatory statement during a bilateral dispute. The first posts have limited reach, but several local accounts are beginning to share it.

  1. 01The mission preserves the video, source link and timestamp, registers the incident and alerts the geographic desk.
  2. 02Monitoring checks the source, media artefacts, earlier versions, translation and distribution. The content is assessed as probably synthetic with moderate confidence.
  3. 03Because the video targets an ambassador during a live dispute and could affect personnel safety and bilateral handling, the incident is assigned Level 3 despite still-limited reach.
  4. 04The geographic desk is named incident lead. The mission, monitoring team, spokesperson, security and legal advisers join a secure coordination channel.
  5. 05A one-page common operating picture separates confirmed facts from the synthetic-media assessment, records confidence and identifies the next distribution threshold.
  6. 06The institution chooses a combined posture: private engagement with the host authority, prepared factual correction, stakeholder briefing and continued monitoring. Public release is held unless agreed triggers are met.
  7. 07The designated authority approves the posture, local-language boundaries and spokesperson line. Mission and HQ actions are sequenced and recorded.
  8. 08Monitoring shows whether distribution crosses the agreed threshold, whether the private intervention reduces risk and whether a public correction becomes necessary. After stand-down, the ministry reviews detection, authorization time, local adaptation and the response's amplification effect.

The protocol does not determine the answer in advance. It ensures that the institution reaches and records an answer through the right evidence, context and authority.

Readiness

Testing readiness

A ministry can test the protocol with five questions:

  1. 01Can a mission or duty function register a material narrative signal at any hour?
  2. 02Can the institution name an incident lead and decision authority without debating the organisation chart during the incident?
  3. 03Can Mission and HQ produce one time-stamped operating picture that distinguishes facts, assessments and unknowns?
  4. 04Does each severity level trigger a real coordination and authorization route?
  5. 05Can the institution later reconstruct what was known, decided, authorized and learned?

If one answer is no, the next investment may be a clearer handoff, template, contact route or exercise rather than a new monitoring tool.

Adoption

Adoption and adaptation

Before operational adoption, a ministry should:

  • map the six functions to existing teams and alternates;
  • define the incident threshold and locally relevant consequence domains;
  • connect Levels 1-4 to existing crisis and authority arrangements;
  • approve secure reporting, evidence handling and record-retention procedures;
  • establish out-of-hours contacts and handover expectations;
  • approve the incident register and common operating picture templates;
  • define local adaptation boundaries for missions;
  • integrate existing FIMI, cyber, intelligence, consular, policy and communication mechanisms;
  • test the protocol through tabletop exercises;
  • review it after material incidents and at a regular institutional interval.

This public version is an independent coordination architecture. It should be adapted to national law, institutional mandates, information classifications, operational culture and existing procedures.

Performance

Protocol performance

The protocol should be evaluated through institutional performance, not through claims of narrative victory.

Useful indicators include:

  • time from detection to registration;
  • time to first verified assessment;
  • time to a named lead and decision authority;
  • time to an agreed posture at the required level;
  • proportion of material judgements with confidence and rationale;
  • number of conflicting external lines issued;
  • completion of actions by named owner and deadline;
  • unintended amplification or partner divergence caused by the response;
  • time to stand-down or formal handover;
  • after-action changes assigned and completed.

Metrics should support learning. They should not reward speed at the expense of evidence, legality or diplomatic judgement.

Evidence

Research basis and limits

The protocol draws on publicly available foreign-ministry crisis arrangements, government crisis-management and communication doctrine, and current FIMI detection and response practice. Relevant sources include Global Affairs Canada's Rapid Response Mechanism, the EEAS FIMI Toolbox and Rapid Alert System, the G7 RRM, France's 2026-2030 national strategy on foreign information manipulation, NATO's approach to information threats, the UK Government Communication Service crisis model and STOP guide, and the UK Amber Book.

Public documentation cannot reveal the full internal operating procedures, classifications, intelligence relationships or authorization rules of individual foreign ministries. The protocol therefore identifies transferable functions and decision requirements rather than claiming to reproduce any ministry's internal system.

Selected sources

  1. 01Global Affairs Canada - Rapid Response Mechanism Canada
  2. 02G7 Rapid Response Mechanism - 2025 Annual Report
  3. 03G7 RRM - Common Understanding of the Information Manipulation Set Framework
  4. 04EEAS - Information Integrity and Countering FIMI
  5. 05France - National Strategy Against Foreign Information Manipulation 2026-2030
  6. 06NATO - Approach to Counter Information Threats
  7. 07UK Government Communication Service - Crisis Communications Operating Model
  8. 08UK Government Communication Service - STOP Crisis Communications Planning Guide
  9. 09UK Government - The Amber Book: Managing Crisis in Central Government
  10. 10UK Government - Explaining Uncertainty in UK Intelligence Assessment
  11. 11UK National Audit Office - Responding to Sudden-Onset Humanitarian Crises
  12. 12France Diplomatie - The Crisis and Support Centre
Citation

Citation

Suggested citation

Diplomats.Digital (2026). Crisis Narrative Coordination Protocol. Version 1.0. August 2026.

Relationship note

Use with the Narrative Resilience Framework. The framework defines the enduring institutional capability; this protocol defines the incident-time coordination sequence.

Closing section

Build coordination before the next incident

The most useful protocol is one that has already been mapped, authorized and exercised before pressure arrives.

Diplomats.Digital welcomes practitioner review from foreign ministries, diplomatic missions, strategic communications teams, crisis managers and public-sector analysts. Feedback can help test whether the protocol remains proportionate, adaptable and operationally clear across different institutional settings.