“I love the topic of risk… an innovator thinks risk is their thing not working, and an operator often views risk as losing the opportunity to do something… you might want to think about risk in a bidirectional way.”
— The Honorable Susan M. Gordon, former Principal Deputy Director of National Intelligence[1]
I. We Have Been Answering the Wrong Question
Carmen Medina once taught me that the single greatest factor in getting a satisfactory answer is spending more time on the question than on the research. Sue Gordon calls the same discipline thinking about risk bidirectionally: the innovator’s risk is that the thing does not work; the operator’s risk is losing the chance to try it at all.
For six decades the federal government has researched the answer to a single question: Is this person trustworthy? It is the wrong question. It is not scientifically answerable, and the pursuit of it has cost us more than any adversary ever took.
The right question is narrower, and it is engineerable: given what is verifiably true right now, what should this person be able to access in the next hour?
II. Trust Is a contingent variable, Not an Attribute
No one asks whether an airliner is trustworthy. They ask whether it is airworthy, a status that expires. Cycles, flight hours, calendar limits, and inspection intervals govern it, and it is revoked by a logbook entry, not by a judgment of character. The same logic governs the crew: federal rules cap flight and duty time and mandate rest[2]. This policy is not because pilots are suspect, but because fatigue degrades every human being. The captain who flew you home last night is no less virtuous this morning. He is simply out of duty hours.
Bridges work the same way: load-rated, inspected on a cycle, posted or closed when the rating drops. Nobody calls that an insult to the bridge. That is the model we need to move to: dynamic, contingent, non-judgmental, applied equally to everyone all the time. The security clearance, as it is done now - is its opposite: a single retrospective verdict based on imprecise and un-repeatable human judgments of a person’s character, rendered by a stranger, valid for years, and structurally blind to everything that has happened since that point in time. Continuous evaluation started in the correct direction but has not gone far enough.
III. The Science Does Not Hold
Strip away the procedure and clearance adjudication process can be summarized in three questions: (1) do you work for someone else’s government; (2) are you “normal” enough across every domain of life; and (3) does the adjudicator like how you look, sound, and answer questions. The third is unmeasured, unscientific, and undeniable.
The instruments themselves fail on arithmetic. The National Research Council’s review of the polygraph, still wrongly considered to be an the authoritative scientific assessment by some agencies: concluded the polygraphs accuracy “is insufficient to justify reliance on its use in employee security screening in federal agencies,” and that screening a population in which the target behavior occurs at rates below 1 in 1,000 demands accuracy far beyond anything the instrument achieves.[3] More than 3.8 million people in the national security population are enrolled in continuous vetting.[4] Documented American espionage cases number in the low hundreds across eight decades.[5] The base rate is not 1 in 1,000; it is closer to 1 in 20,000. Any instrument that flags at that rate delivers a haystack of innocents and misses the needle from the haystack.
This is not a fringe critique. The Government Accountability Office placed the government-wide personnel security clearance process on its High-Risk List in 2018[6] and it is still there in 2026. As of February 2026, GAO reports agencies missing timeliness goals at nearly every phase, average initial Top Secret processing trending longer every year since fiscal 2022, and $2.4 billion spent on the replacement investigations IT system with another $2.2 billion projected through 2031.[7] We are paying billions to industrialize the wrong answer to the wrong question.
IV. The Clearance Is a Lagging Indicator – Trust is a temporary, contingent variable
The traitors Ames, Hanssen, Manning. Every one of them held a favorably adjudicated clearance on the day they began betraying our great nation. Studies show 60 percent of American espionage offenders were what we call “volunteers,” people who decided to spy, after they were judged to be “good people.”[8]
We tend to compensate for the lag in adjudicative timelines with additional monitoring, yet according to studies from Deloitte, Harvard and MIT, monitoring employee’s behavior too closely, creates additional trust gaps between employee and employer.[9]
Thiel and colleagues found that monitored employees broke rules more often, because surveillance shifts felt responsibility for one’s own conduct onto the monitor.[10] Deloitte reports that 79 percent of employees who highly trust their employer feel motivated to work, against 29 percent of those who do not.[11] Distrust does not produce security. It produces performance theater.
Then there is the branding. Walk into a federal facility and you will find posters instructing the most heavily vetted workforce on earth to trust no one and nothing, under the banner of “ZERO Trust.” Are we so tone-deaf that we can’t consider the impact this campaign has on people’s morale?
NIST SP 800-207 is a network architecture standard; it eliminates implicit trust zones between machines, not confidence between colleagues. Yet, no one in the Department of Defense/War, or national security community has - to my knowledge - studied this programs effect on morale.[12] We took an engineering, network control and made it a personnel slogan. What is done backstage should stay backstage. If DISA, and other network security gurus find flashy terms like “zero trust” – let them keep them in the background as IT policy, in their own agency. There is no need to inform uniformed and civilian officers that we don’t trust them, AFTER they have been completely cleared.
The cost of answering the wrong question, tends to show up in reverse. The 9/11 Commission concluded that “the biggest impediment to all-source analysis is the human or systemic resistance to sharing information,” and called for replacing a need-to-know culture with a need-to-share one.[13] IRTPA and the creation of the Office of the Director of National Intelligence (ODNI) were built on that finding. After the security breach of 2013 we re-siloed data. One breach; a generation of retreat from our principles and “lessons learned,” a retreat that is still going on almost 13 years later. Nothing our adversaries have done to harm us, could do as much harm as we are doing to ourselves by encouraging trusted, vetted and cleared professionals to hide data from one another. Carmen Medina and Zach Brown noted this challenge in the Foreign Affairs Magazine in “The Declining Market for Secrets,” in May 2021.
V. The Statutory Window Is Open Right Now
Congress is already legislating at the edges of this problem, which is precisely why the argument matters this year rather than next decade. The FY2026 NDAA extends the period a departing service member or DoD civilian remains eligible for classified access from 24 months to as long as five years, and adds authority for cleared contractors to fund background investigations on a bench of additional staff so classified programs are not held hostage to a single career move.[14] In parallel, revisions to 5 C.F.R. Part 731 effective 17 January 2025 extended investigation, reciprocity, and continuous-vetting standards across essentially everyone working for or on behalf of the federal government.[15]
The FY2027 bills are still being considered even as I write. HASC reported H.R. 8800 on 15 June 2026; SASC reported S. 4784 the same day; neither has been enacted.[16] Separately, the Security Clearance Review Act would move clearance determinations for White House political appointees to the FBI Director, with mandatory congressional notification whenever a President reverses one.[17]
Read them together and the pattern is unmistakable: every one of these is a throughput fix. Faster verdicts, longer-lived verdicts, more verdicts, better-insulated STATIC verdicts on character.
Not one of them changes the question being asked or proposes clearer designs that can be engineered into the process to enhance our nations security. Congress is optimizing the clock on a lifetime judgment of character. The conference on the FY2027 NDAA could still be updated to include more dynamic access control processes.
VI. The Engineered alternative
In his Lecture on Ethics, Wittgenstein imagined a book containing every fact in the world. Consider for a moment, that your company or federal agency had access to that book. You know and will know every detail about every person that applies to work, or who currently works in your organization. What would you screen for? And which variables and contingent conditions would you put on that trust? As one clearly realizes, trust between organizations and individuals tends to have so many contingent variables, that the only way to meet these high standards is to monitor ones employees 24-7 for things that would make them an unreliable component of the larger organization. Fortunately (and unfortunately if you are a privacy hawk) current federal law governing publicly available information, does not restrict companies from gathering and analyzing this data.
In short, we already have SEAD 3 and SEAD 4 to set the conditions for what can be monitored. What is missing is the control system on the federal agency side, which should be designed for a Dynamic Trust System (DTS) that is always evaluating and adjusting levels of access for each employee/troop.
A Dynamic Trust System does not ask whether you are trustworthy for life or for the next five years. Instead it would monitor for objectively concerning behavior of the cleared population on an ongoing basis. Rather than concluding an individual is “trustworthy” as an adjudicated character trait (which we have seen are unreliable indicators) but rather the DTS system should lend trust for a verified and auditable current state and dynamically adjust access rather than adjudicating human character traits as though they are immutable and permanent.
Naturally defenders of the status quo will rally to argue that some people ARE inherently trustworthy. My response would be rather straightforward, under the three scenarios below – would you “trust” these already trusted individuals?
● Would you hand full discretion over your life savings to an advisor who was T-boned this morning by another car, left his blood pressure medication at home, and whose family walked out without warning three weeks ago?
● Would you want your Senator casting a floor vote after 49 hours without any sleep?
● Would you leave your dog with your closest friend, if he was out drinking until 0400 and the dog was supposed to be dropped off at 0600 when the friend is still inebriated?
In none of those does race, sex, age, faith, education, or identity carry any weight whatsoever. That is precisely the point. Engineered, contingent, dynamic access is the only trust model that is structurally incapable of the biases that whole-person review invites. The human stays in the loop, reviewing federally approved indicators with no narrative or judgement placed on reported facts.
VII. Guardrails, Stated Up Front
A system like this becomes a social credit score unless it is engineered against that outcome from the first line of code. Four constraints should be considered for such a system:
● Specified variables only. Signals or “warning signs” must trace to a published SEAD 4 guideline. No inferred sentiment, no associational graphing, no lifestyle scoring.
● Access effects, not employment effects. The system throttles what a network exposes. It does not fire people, and it does not feed human resources every detail about the individual’s life, which can always be – and currently is – weaponized against their political opponents.
● Contestability. Every adjustment is logged, disclosed to the individual, and appealable. The written-notice and independent-panel rights already guaranteed under Executive Order 12968 Section 5.2[18] must attach to an algorithmic determination, or the system would be violating current law.
● Reversion by default. Restrictions expire automatically when the triggering condition clears. Trust that cannot return is not trust. It is punitive punishment.
VIII. Risk as Reward
Here is the return on the investment. The current system systematically prices out unconventional minds. Our British allies have gone the other direction and recruited for neurodiverse thinking, on the straightforward argument that pattern recognition and anomaly detection, are easier for neurodiverse minds than “normal” people.[19] The director GCHQ strategy, policy and management stated:
“Since our inception we have looked to hire individuals who are neurodiverse, and as a result we have a thriving community of colleagues who think differently.”[20]
Here in the United States, we screen the same types of cognition from being considered and call it “prudence,” seeking “normal” people.
The stigma tends to outlive changes in military and security clearance eligibility policy. ODNI rewrote the SF-86 questions on mental health, so that seeking care is no longer the question: the question is whether a condition significantly impairs judgment, reliability, or trustworthiness.[21] A decade on, the culture in the military and in our nations national security workforce has not caught up to the policy change. And it is unlikely that it will anytime soon. As long as we view people as static entities that never change, the policy will stay as it is rewarding troops who conceal rather than those that reward disclosure.
There is a class bias in the system too, and it is not subtle. Financial “responsibility” is an explicit adjudicative criterion – explain how this criteria can be applied equitably to our current American citizens who do not choose the families or degree of wealth they are born into.
IX. Change the Question
Clearances were built for a world of filing cabinets, by a culture with old habits of testing people for hidden defects of character that knew very little about the human mind, or about the number of variables that can be used to strengthen positive behavior and restrain negative behavior. As a society, our science has outpaced our implementation of its findings by decades.
Engineering the environments and access levels that our “cleared population” has, is a logical approach to replace one currently based on a highly contingent static determination – made years ago, too frequently based on sentiment and human emotion.
The answer is not zero trust. It is instead, earned, contingent trust within a specific time-period which expires. Of course the Dynamic Trust System (DTS) would need to be auditable. As a community we need to stop researching the answer to the wrong question and move the question to one of engineered dynamic trust.
[1]Remarks recounted by the author. Gordon served as PDDNI, Office of the Director of National Intelligence, 2017–2019.
[2]14 C.F.R. Part 117, Flight and Duty Limitations and Rest Requirements: Flightcrew Members. https://www.ecfr.gov/current/title-14/chapter-I/subchapter-G/part-117
[3]National Research Council, The Polygraph and Lie Detection (Washington, DC: National Academies Press, 2003), Executive Summary. https://www.nationalacademies.org/read/10420/chapter/2
[4]GAO-25-107325, Federal Workforce: Observations on the Implementation of the Trusted Workforce 2.0 Personnel Vetting Reform Initiative (DCSA reported over 3.8 million enrolled as of September 2024). https://www.gao.gov/products/gao-25-107325
[5]K. L. Herbig, The Expanding Spectrum of Espionage by Americans, 1947–2015 (PERSEREC, August 2017), 209 cases. https://apps.dtic.mil/sti/tr/pdf/AD1040851.pdf
[6]GAO, High Risk: Government-wide Personnel Security Clearance Process. https://www.gao.gov/highrisk/govwide_security_clearance_process
[7]GAO-26-108838, Personnel Vetting: Leadership Attention Needed to Prioritize System Development and Achieve Reforms (24 Feb. 2026). https://www.gao.gov/products/gao-26-108838
[8]Herbig, Expanding Spectrum, supra. Sixty percent volunteered; forty percent were recruited.
[10]Chase Thiel et al., “Monitoring Employees Makes Them More Likely to Break Rules,” Harvard Business Review, 27 June 2022. https://hbr.org/2022/06/monitoring-employees-makes-them-more-likely-to-break-rules
[11]Deloitte Insights, “Trust deficit in the workplace,” and 2025 Global Human Capital Trends. https://www.deloitte.com/us/en/insights/topics/leadership/workplace-monitoring-and-the-lack-of-trust-in-the-workplace.html
[12]NIST Special Publication 800-207, Zero Trust Architecture (August 2020). https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-207.pdf
[13]The 9/11 Commission Report, ch. 13, “How to Do It? A Different Way of Organizing the Government.” https://govinfo.library.unt.edu/911/report/911Report_Ch13.pdf
[14]Justin Doubleday, “Security clearance reforms advancing in 2026 defense bill,” Federal News Network (2025), describing the SASC five-year eligibility provision and the Wittman contractor-bench amendment. https://federalnewsnetwork.com/inside-ic/2025/08/security-clearance-reforms-advancing-in-2026-defense-bill/
[15]5 C.F.R. Part 731, Suitability and Fitness Vetting, as revised effective 17 January 2025. https://www.ecfr.gov/current/title-5/chapter-I/subchapter-B/part-731
[16]Congressional Research Service, FY2027 NDAA: Status of Legislative Activity, IN12704 (10 July 2026). H.Rept. 119-698; S.Rept. 119-127. https://www.congress.gov/crs-product/IN12704
[17]H.R. 1591, Security Clearance Review Act, 119th Cong. (introduced 26 Feb. 2025). https://www.govtrack.us/congress/bills/119/hr1591
[18]Exec. Order No. 12968, Access to Classified Information, § 5.2 (2 August 1995). https://sgp.fas.org/clinton/eo12968.html
[19]“GCHQ: Dyslexic thinkers key to solving UK cyber security challenges,” Computer Weekly, 2020. https://www.computerweekly.com/news/252499960/GCHQ-Dyslexic-thinkers-key-to-solving-UK-cyber-security-challenges
[20] See: https://www.computerweekly.com/news/252499960/GCHQ-Dyslexic-thinkers-key-to-solving-UK-cyber-security-challenges
[21]ODNI revision to SF-86 Question 21, effective November 2016; see Military OneSource, “Psychological Health and Security Clearance.” https://www.militaryonesource.mil/health-wellness/mental-health/does-receiving-psychological-health-care-affect-security-clearance/
