← all hypothesesExecutive Impersonation Escalation Gate for Support Teams
graduated [TRIANGULATED] filter 9.5/15 spread ±2.0 signals: 2 independent
What is this?
A pre-send interrogation gate for support and trust-and-safety leads at mid-sized SaaS companies handling high-risk inbound requests that appear to come from executives, customers, or partners via video, voice note, or urgent email. The product does not try to be a generic deepfake detector. Instead, it forces evaluators to log the external request as a concrete commitment-risk artifact before action: requested action, claimed identity, urgency basis, verification evidence present, and challenge questions asked. AE then runs adversarial debate against a structured constraint set built from prior resolved incidents and miss patterns, surfacing failure modes like concession laundering ('voice sounds right, but callback failed') or temporal blindness ('request bypasses normal approval timing'). Resolution comes from the existing ticket/incident record: was the request legitimate, blocked, escalated, or did it become a fraud/security incident? This fits AE because the hard problem is not media forensics alone; it is pre-action judgment under uncertainty with fast external resolution, reusable miss-pattern encoding, and objective grading from incident outcomes rather than model self-scoring.
Why did we consider it?
AE is well matched to an executive-impersonation escalation gate because the real problem is structured pre-action risk judgment with fast, objective incident outcomes, not media forensics alone.
What breaks?
- Breaks the <24h feedback loop constraint: BEC and impersonation fraud discovery often takes days or weeks, starving the AE of immediate objective grading.
- Introduces fatal workflow friction by forcing TTR-measured support reps to manually log complex artifacts during urgent, high-pressure requests.
- Severe Commander mismatch: selling security gates to mid-market SaaS requires SOC2, deep ticketing integrations, and high-touch sales incompatible with a part-time solo founder.
What did we learn?
Engine verdict: GATHER_MORE_SIGNAL (WORTH_SKIMMING). Excellent AE wedge, but buyer proof is still simulated and the real failure mode may be authority pressure, not analysis.
Filter scores
Five axes, each scored 0-3. Three independent runs by different model perspectives. Median shown.
| Axis | What it measures |
|---|
| data moat | Does this product accumulate proprietary data that compounds? |
| 10x model test | Does a better model make this more valuable, or redundant? |
| fast feedback loops | Can outputs be graded against reality in <30 days? |
| solo founder feasible | Can a solo operator build and run this without a team? |
| AI providers cant eat it | Do hyperscalers have structural reasons NOT to build this? |
Composite median: 9.5 / 15. Graduation threshold: 9.0. IQR across runs: 2.0.
Evidence
Signal A — Primary source
Interactive URL Triage via Decoupled Checklist Adjudication
Signal D — Demand proxy
{"found":true,"summary":"Multiple demand proxies indicate active concern around executive/helpdesk impersonation, Teams-based social engineering, and spear-phishing incidents affecting SMBs and senior employees.","sources":["https://blog.knowbe4.com/phishing-attacks-target-executives-via-microsoft-teams","https://github.com/muaddibco/RealWorldProblems/issues/184","https://www.reddit.com/r/sysadmin/comments/1rhaevx/help_please_had_my_first_real_email_compromise/","https://thehackernews.com/2026/04/unc6692-impersonates-it-helpdesk-via.html"],"reason":"These are blogs, forum/GitHub discussions, a…
Evaluation history
| When | Stage | Phase |
|---|
| 2026-05-06 02:03 | deep_council_verdict | graduated |
| 2026-05-06 01:48 | deep_claude_take | graduated |
| 2026-05-06 01:45 | deep_90day_plan | graduated |
| 2026-05-06 01:37 | deep_risk | graduated |
| 2026-05-06 01:29 | deep_distribution | graduated |
| 2026-05-06 01:22 | deep_pricing | graduated |
| 2026-05-06 01:13 | deep_moat | graduated |
| 2026-05-06 01:07 | deep_buyer_sim | graduated |
| 2026-05-06 01:01 | deep_icp | graduated |
| 2026-05-06 00:51 | deep_competitor | graduated |
| 2026-05-06 00:39 | deep_market_reality | graduated |
| 2026-05-06 00:24 | filter_score | scored |
| 2026-05-06 00:21 | filter_score | scored |
| 2026-05-06 00:18 | filter_score | scored |
| 2026-05-06 00:15 | evidence_search | evidence_hunt |
| 2026-05-06 00:12 | evidence_search | evidence_hunt |
| 2026-05-06 00:09 | evidence_search | evidence_hunt |
| 2026-05-06 00:06 | evidence_search | evidence_hunt |
| 2026-05-06 00:03 | evidence_search | argument |
| 2026-05-06 00:00 | audience_simulation | argument |
| 2026-05-05 23:57 | red_team_kill | argument |
| 2026-05-05 23:54 | steelman | argument |
| 2026-05-05 23:51 | genesis | argument |