Two connected learning models Explore the linear model at KillChains.com

Operating model

How kill webs work

A functioning web turns distributed observations and capabilities into one or more executable, authorized mission paths—then updates the option space as evidence, availability, and constraints change.

Research basis KW-RPT-002 KW-RPT-009 KW-RPT-013

Sense, make sense, decide, authorize, act, assess

  1. 01

    Sense

    Distributed sources produce observations, health state, confidence, time, and provenance.

  2. 02

    Make sense

    Edge and fusion services correlate evidence, preserve competing hypotheses, and mark age and uncertainty.

  3. 03

    Compose options

    Capability registries and orchestration services screen compatible pathways against reachability, capacity, quality, timing, and dependencies.

  4. 04

    Apply trust and policy

    Identity, classification, releasability, safety, legal, and command constraints exclude invalid options.

  5. 05

    Authorize and act

    The responsible authority selects or rejects a bounded option; execution remains within the approved task and constraints.

  6. 06

    Assess and update

    Outcome evidence returns to the data fabric, changes confidence and availability, and may trigger another cycle.

Capabilities must be machine-readable

The network cannot compose useful paths if it knows only platform names. It needs bounded capability descriptions: what function is offered, what input is required, what output is produced, when and where it is available, what dependencies it has, and which authority owns it.

Sensitive implementation details can remain abstracted. A consumer needs enough information to judge fitness without receiving unnecessary sources-and-methods data.

  • Identity and owning authority
  • Function, inputs, outputs, and semantic version
  • Availability, capacity, health, and state age
  • Quality, confidence, and communications dependencies
  • Classification, releasability, and policy constraints
  • Opportunity cost and conflicts with other commitments

Recomposition is a controlled state change

When a node fails, the architecture should not blindly route around it. It must first detect the loss or loss of trust, update the graph, reject stale reservations, discover alternatives, reapply policy, and communicate the changed path to responsible operators.

The safest alternate may be slower, lower fidelity, or restricted to continued sensing rather than action. Graceful degradation means preserving a safe reduced function, not pretending the original mission remains unchanged.

Assessment closes the web

Assessment is not an afterthought. It verifies whether the intended effect occurred, detects unintended consequences, updates data quality, and reveals whether the selected path actually performed as expected.

Without a trustworthy feedback path, the web can optimize activity while losing sight of mission outcome.

Research basis: KW-RPT-002, KW-RPT-009, and KW-RPT-013.

Answer-ready summary

Direct answers

What does How Kill Webs Work cover?

Follow the sense, make sense, decide, authorize, act, and assess cycle through a governed, distributed architecture.

Read the supporting page