1C – Institutional-Level Analysis¶
Institutional-Level Analysis is the work that requires more than a desk and a browser: partner-mediated access to enterprise tooling, Python-or-R proficiency for behavioural-data work, evidentiary-grade methodology for defamation defence or coalition-wide attribution. The cells here take two hours or more on a typical case and routinely run across a full half-day. The intended reader is on the institutional side of the room – Rappler's investigations desk, MAFINDO's research team, a Watchdog OSINT lead with LIRNEasia collaboration, a coalition partner at the Indo-Pacific Convening – or is escalating a case from 1B Professional Verification into the kind of work a desk reporter alone cannot close. This section covers the three 1C cells, the honesty discipline the toolkit applies to access-barrier tooling at this tier (where most readers will not have routine deployment access to half the tools and the toolkit needs to say so), and the sideways route into 2C Large-Scale Intelligence when narrative attribution requires coordinated-operation framing.
When this tier applies¶
A wave of accounts on Facebook Groups in Indonesia start sharing variations of the same anti-vaccine claim in the week before a regional health summit. The posting cadence is suspiciously uniform; the accounts have similar creation dates; the imagery rotates through a narrow set of templates. MAFINDO's research team takes the case for behavioural analysis. That is the work 1C.1 is designed for: Python or R notebooks running over user-supplied data, looking for coordinated patterns across accounts, posts, and timing.
A six-second clip showing what appears to be a Filipino senator's family in a compromising scene is about to break on YouTube and Rappler's investigations editor needs broadcaster-grade certification before the story runs. The desk-tier detector readings disagree. 1C.2 is where institutional-grade aggregation lives – Sensity, Reality Defender, DeepfakeBench – with the documented Doc Willie Ong / Brawner casework as the operational reference. Access is the constraint: enterprise pricing, partner agreements, IFCN-signatory gating in places.
A Watchdog Sri Lanka story is heading to print on a synthesised image of a contested election event. The lawyers want a pixel-level visualisation showing what made the system flag the image as AI-generated, in case the defamation suit lands. 1C.3 is the explainability layer that produces GradCAM heatmaps, reliability maps, and the WITNESS-evaluation framework reference – the methodological scaffolding that an institutional fact-check operation needs when a published claim faces legal challenge.
The three cells share a common honesty: institutional tooling at this tier sits behind real access barriers. Enterprise pricing puts Sensity and Reality Defender out of routine SEA-newsroom reach; IFCN signatory status gates Meta Content Library; CSIRT-level integration is the realistic deployment ceiling for DISARM Navigator. The toolkit names these access barriers as part of the operational reality of the tier, with the repeated redirect pattern: cite institutional research output, plan with partners, treat the tool as a destination for cases the desk has already structured.
How techniques in this tier connect¶
The three cells are sequential more often than parallel, which is unusual in the pillar map. 1C.1 surfaces a network – a coordinated cluster, a synchronised cadence, an actor pool. 1C.2 certifies the synthetic-generation status of artefacts inside the network when the broadcaster-grade question arises. 1C.3 produces the explainability layer when one of those artefacts is heading to publication and needs visual justification. Most institutional cases pass through more than one cell; cases that close at 1C.1 alone are the exception.
Two of the architectural anchors carry forward into this tier with sharper teeth. Anchor 3 binds harder at 1C.2 than anywhere else: an enterprise platform that internally aggregates ten ensemble models is still one detector signal class, no matter how confident the platform's interface looks. Anchor 2 binds across all three cells: a 1C.2 verdict of 98% facial-manipulation, however authoritative, still requires a non-detector signal alongside before a public claim – source-history evidence, provenance evidence, or behavioural-pattern evidence from 1C.1.
The editorial discipline the toolkit applies at this tier is editorial honesty about access barriers. Sensity, Reality Defender, Graphika, Meta Content Library, and DISARM Navigator sit at progressively higher access barriers, and the toolkit handles each one by naming the barrier directly and giving readers a path that does not pretend the barrier is not there. The Sensity vendor-headline / Brawner-field-case / Ha-2024-baseline three-leg pairing, the Graphika "cite as external source" redirect, the institutional-CSIRT framing on DISARM Navigator – these are not workarounds. They are the operational pattern the toolkit uses to talk about access-barrier tools without pretending they are operationally available to most readers.
What this tier produces¶
An institutionally defensible record – the kind that survives editorial review at Rappler or MAFINDO, the kind that holds up against a defamation suit, the kind that goes into a coalition report. The output usually carries: a network or actor-pool description grounded in 1C.1 work, an artefact certification grounded in 1C.2 if applicable, an explainability layer grounded in 1C.3 if the case is heading to publication, plus the non-detector evidence inherited from 1B and the operational context inherited from earlier tipline or claim-extraction work.
When to escalate, when to stop¶
Stop when the institutional record is complete and the case can be published or sealed for archival reference. Most 1C work closes at 1C – this is the institutional ceiling of Pillar 1 and there is no higher tier inside the pillar to climb to.
Move sideways into 2C Large-Scale Intelligence when the unit of analysis shifts from the artefact to the operation, and narrative attribution requires the codification frameworks (ABCDE, DISARM, the Online Operations Kill Chain) that 2C codifies. A 1C.1 network description that needs to be shared across organisations under a common vocabulary belongs in 2C.3. A 1C.2 certification of a video that turns out to be one of fifty similar clips in a coordinated operation belongs in 2C.1 monitoring and 2C.2 visualisation. The T5 escalation tree carries the conflict-resolution logic when 1C tools disagree, and reaffirms the Anchor 3 reset whenever multi-detector consensus is being treated as multiple signals.
The cells in detail¶
1C.1 – CIB detection¶
The largest single landscape in the toolkit's inventory: 38 candidate entries reduced to a four-tool ladder built around what is actually deployable at SEA institutional scale. The work begins when 1B source-history or 2B tipline volume surfaces a coordination signal – similar posting cadences, overlapping account-creation dates, a narrow template space, synchronised burst patterns across what should be unrelated accounts.
CIB Mango Tree is the open-source primary – it runs locally on user-supplied data, which matters in countries where uploading account data to a cloud service has its own threat profile. Coordination Network Toolkit and CooRTweet are the academic R and Python alternatives; CooRTweet specifically benefits from Meta Content Library data when IFCN-signatory partners (MAFINDO, Rappler, VERA Files) can pull it. Graphika is the enterprise escalation option – realistically out of routine SEA-newsroom reach, which the tool card handles through the "cite as external source" Quickstart redirect: readers learn how to cite Graphika institutional reports without planning a deployment that probably is not realistic for their organisation.
CIB analysis sits on the behaviour pillar under Architectural Anchor 1 and combines with claim extraction (2B.2) and monitoring (2C.1) in the standard institutional pipeline. The cell-level honest gap is that no SEA-specific worked-example casebook for CIB detection exists in the toolkit's source base – the analytical methods are well-documented; the regional case material from which a SEA practitioner could learn pattern recognition is thin. The entry from below is from 1B.1 when source-history work surfaces coordination signals; the bridges sideways are to 2C.2 visualisation and 2C.3 taxonomic codification.
1C.2 – Enterprise / open-source deepfake platforms¶
When a Rappler-grade investigative pipeline needs to certify whether a video is AI-generated for publication, this cell is the institutional ladder. Three tools cover it at three different access tiers.
Sensity AI is primary because it is the documented Rappler / #FactsFirstPH workhorse with concrete casework: the Doc Willie Ong eye-drop deepfake at 98% facial-manipulation, 75.5% AI-object-generation, 94% audio-manipulation – the case that anchors the Philippines country page – plus the Brawner "Dark Eagle" case at 79.3% AI-generated. The Sensity card applies the three-leg vendor-wrapping pattern: vendor headline figures from Sensity's marketing, the Brawner field reading at 79.3%, and the Ha-2024 image-detector baseline at 98.03% on a Western dataset – three legs that together let a reader interpret a Sensity verdict honestly without treating the vendor figure alone as evidence. Reality Defender is the alternative for broadcaster-grade deployments. DeepfakeBench is the academic evaluation suite used in research labs – a benchmark, not an in-the-loop detector, framed as such on its card.
The operational discipline at this cell binds two of the architectural anchors at once. Anchor 3 binds: Sensity, Reality Defender, and Hive video may each aggregate multiple internal ensemble models, but their outputs together are still one detector signal class. Anchor 2 binds: a 1C.2 certification, however confident, requires a non-detector signal alongside before a public claim. The honest gap is that the Deepfake-Eval-2024 anonymised pool – the Deepfake-Eval-2024 anonymised pool — the strongest independent video benchmark – does not publish per-vendor scores, so the user must understand that the platform-by-platform comparison usually quoted in vendor marketing is not separable from the broader 0.78-accuracy ceiling the pool documented. Source-protection at this cell is non-trivial: the upload step transmits the source file to a hosted enterprise platform, and the S1 source-identifying upload override binds on every card in the cell. T6 source-protection is the routing layer; the cell does not run on identifying material without an S1 mitigation pass.
The cell does not have a downward bridge to anything below it – this is the deepfake ceiling of Pillar 1. The sideways bridge is to 1C.3 when explainability is required for legal or defamation use.
1C.3 – Explainable AI forensics¶
When a fact-check needs to withstand a defamation suit or a legal challenge, a probability score is not enough. The lawyers want to see the pixel-level map showing what made the system decide. The cell ships three tools at three different layers of institutional integration.
XAI Deepfakes is the primary – the GradCAM / SHAP / LIME-on-EfficientNet stack that produces heatmaps a forensic report can embed. TruFor is the alternative, the vera.ai-partner reliability-map tool, which functions as a non-detector signal in its own right under Architectural Anchor 1's reliability-map-non-detector-declaration framing – TruFor's output is not "this is fake at probability X" but "the integrity map of this image looks like this, and the reliability of that map is Y". TRIED Benchmark is the institutional WITNESS evaluation framework – not a tool the user runs but the methodological reference for whether the 1C.3 pipeline meets WITNESS's six-pillar Global South framework before publication. The TRIED card uses the institutional-reference card pattern: the "Why this is a framework reference, not a tool card" sub-section in place of a conventional Quickstart.
The cell-level honest gap is that explainability infrastructure is mostly built and benchmarked on English-language and Western-face data. Defamation defence in Sinhala or Lao contexts requires manual interpretation alongside the visualisation – the GradCAM heatmap is not self-explanatory for a regional readership without the analyst's narrative attached. Bridges: from 1C.2 when an enterprise verdict needs visual justification; downward to 1B.4 ELA when the case does not warrant institutional-grade explanation; sideways to 2C.3 when the operation is the unit of analysis instead of the artefact.
Cross-references¶
- T5 escalation – conflict-resolution layer for 1C tools disagreeing, plus the Anchor 3 reset
- T6 source-protection – binding on any 1C.2 upload to a hosted enterprise platform
- 1A First-Line Triage, 1B Professional Verification – entry tiers
- 2C Large-Scale Intelligence – sideways move when the unit of analysis shifts from artefact to operation
- Methodology: architectural anchors – Anchor 2 and Anchor 3 in their sharpest application
- Methodology editorial-patterns – the three reference-card patterns (Sensity three-leg, Graphika redirect, TRIED institutional-reference) as documented patterns
- Country pages: Philippines (Rappler / Sensity / #FactsFirstPH 1C.2 anchor case)
Sources¶
- Rappler. Fact Check: Deepfake videos use image of Dr. Willie Ong to promote unregistered eye drops. Rappler, January 2026. rappler.com. (Doc Willie Ong 1C.2 anchor case; Sensity 98% / 75.5% / 94% detector scores; Brawner 79.3% field reading.)
- Lyu, S. et al. Deepfake-Eval-2024: A Real-World Benchmark for Deepfake Detection. 2025. arxiv.org/abs/2503.02857. (Sensity / Reality Defender / Hive in anonymised commercial pool; no public per-vendor scores; category baseline for 1C.2.)
- Ha, B. et al. Organic or Diffused: Can We Distinguish Human Art from AI-generated Images? ACM CCS 2024. (Baseline for image detector performance on adversarial inputs.)
- WITNESS Media Lab. TRIED Benchmark: Synthetic Media Detection Benchmarking. WITNESS, 2025. lab.witness.org/projects/synthetic-media-and-deep-fakes. (WITNESS Philippines workshops at 1C.3; institutional-tier verification reference.)
- Country pages: Philippines (Rappler / Sensity / #FactsFirstPH 1C.2 anchor case; provenance-platform survival in SEA distribution context).
- Architectural Anchors — Anchors 1, 2, and 3 as operationalised across the 1C cells.