- I01RULE SHIFTERS
- I02429 SWARMLINGS
- II03CLAIM CRAWLERS
- II04MIMIC WARDENS
- III05GREY FOG
- III06THE FUNNEL
- IV07PUPPETEER HUNTERS
- V08INFRINGER LEDGER
THE HUNTERS THAT TAKE WHOLE NETWORKS
The deadliest front has nothing to do with content. Fake-account, spam and inauthentic-behavior systems watch how accounts behave — registration, cadence, linkage — and they action accounts by the billion per quarter, automatically. They do not hunt cargo. They hunt puppets, and when they find one, they follow its strings.

THE NETWORK IS THE UNIT OF LOSS
Every other front costs you something you can replace — an upload, a post, a month of reach. This one costs the accounts themselves, together. The platform's own policy stack is four-deep here: fake accounts, spam, inauthentic behavior, and — for operations built on false identities — coordinated inauthentic behavior. Nearly all enforcement is automated and enormous: on the order of a billion accounts actioned in a single quarter. An operation never meets the famous investigations; it meets the machine. And every published signal category the machine uses is relational or temporal — computed across accounts. Not one is a property of an uploaded file, which is why nothing done to content can reach this front.
- R1
The pattern
Accounts that move in lockstep read as one hand holding many strings: same cadence, shared credentials, coordinated linkage. The hunters' documented signals are network topology, engagement anomalies, creation timing — behavior, never content. Networks are removed for how they operate, "no matter what they post."
- R2
The correlation
Enforcement propagates through "close linkage with a network of accounts" that violate. The network, not the account, is the unit — losses arrive correlated, all at once, not one at a time on independent odds.
- R3
The ratchet
Replacing a removed account is itself the violation: an account "created or repurposed to evade a previous removal" is restricted on those grounds alone. Rebuilding is not recovery — it is a fresh offense that feeds the next sweep. This front is rated rarely recoverable for a reason.
NO PUPPETS, NO STRINGS TO FOLLOW
The hunters cannot be fooled and are not fought — they are given nothing to find. TokenShield never pools credentials: one shield per account, so no two accounts ever share a token or move in lockstep. Around it sits the operator doctrine, tracked as real work in the supply line's own ledger: a register of operator and machine identities, least-privilege account assignment, and an attribution log that can answer for every credential use. Few accounts, real identities, every action attributable — an operation shaped like a publisher, because it is one.
STATUS: BEING BUILT — CAPABILITIES LANDING WITH TESTS, GAPS DOCUMENTED. SEE THE FULL MANIFEST →Tests assert it
Never pooling credentials is not a habit — it is an invariant with a test on it. Per-account shields give per-account rhythms; the correlated-removal clause finds no correlation to seize.
Real names, least privilege
Every account maps to a registered operator or machine identity holding only the access it needs. The systems that hunt identity deception have nothing to work with when there is no deception.
A log that can answer
When any question lands — internal or from the platform — the attribution log says who used which credential, when, for what. The operation survives scrutiny by inviting it.
You do not out-disguise a system that reads strings instead of costumes. The only architecture that survives this front is one with nothing to conceal: real identities, least privilege, and a log that can answer for every credential it holds.
WHY THE FLEET FLIES UNDER ITS OWN FLAG