The doctrine,
built in.
The College of Policing intelligence cycle, MIRSAP and the National Intelligence Model are built in as rules the system enforces, not a binder on a shelf. A small team runs to national doctrine, with authority, provenance and every decision gate written to the record.
National doctrine assumes a big team. Most units run it by memory.
Authorised Professional Practice was written for forces with dedicated intelligence units, major incident room staff and standing analytical capacity. A two or three person back office is expected to meet the same standard with none of the structure. In practice the discipline lives in the heads of experienced officers and holds only as long as they do.
Doctrine as a PDF
Guidance sits in a document nobody opens mid case. The gap between what the manual says and what actually happens is invisible until an inspection or a court finds it.
Held by goodwill
The intelligence cycle, source grading and the separation of roles depend on individuals remembering to apply them. When they are busy or absent, the standard quietly slips.
No record of the gate
Even where the right decision is taken, the reason often is not captured. A reviewer cannot tell a considered judgement from an omission after the fact.
The answer is not more training on top of goodwill. It is to encode the doctrine as rules the system applies, so the standard holds by default and every decision gate is answerable.
Not a diagram on the wall. A workflow that stops.
The APP intelligence cycle runs as an enforced sequence with quality gates that block progression rather than describe it. A request cannot leave Direction without a complete set of terms of reference, and the gates hold the product until the standard is met.
Each gate requires a supervisor to pass it, and anyone who spots a problem can block it, because a quality control that only the authoriser can invoke is not a control. Every pass and every block carries an attributed, timestamped rationale captured in the app.
Terms of reference are mandatory
All seven APP fields are required before a request advances out of Direction. An amendment creates a new version and keeps the previous one, so the brief the work was done against is never overwritten.
Research cannot carry a judgement
The separation of research from analysis is a structural rule, not a convention. A research product has nowhere to record an inference, so a judgement can only ever sit in an analytical product, attributed to the analyst who made it.
Tasking is deterministic and shown
Instructions are scored against the team's specialisms before anything runs, and only analytical capability can take analysis class work. The selection and its alternatives are visible before the task starts.
A refused advance is the gate working
A blocked product is the control doing its job, recorded as such rather than logged as a fault, so the discipline is legible to a later reviewer.
HOLMES-style discipline, built to a two-person minimum.
MIRSAP, the NPCC's major incident room standardised administrative procedures, implemented as an enforced mechanism rather than a staffing model. The room is built so one officer plus the system can run a major incident to the same discipline a large room provides.
The two-person split
The human holds the judgement roles: Receiver, Document Reader, Action Manager. The system holds the disciplined administration: Indexer and Office Manager. The split is data, not a fixed assumption, so a deployment that differs is visible on the record.
Separation as a check
Receiver, Reader and Action Manager are three passes over the same material asking different questions. The room does not refuse one person holding two of them, MIRSAP plans for that, it refuses the silence: a combined pass demands a recorded reason and is flagged so reduced scrutiny is visible, not inferred.
Self-review is impossible
The officer who submitted a result cannot be the one who decides it met the standard. Enforced in the logic and by a database constraint, so bypassing the interface does not bypass the rule.
Policy decisions are generated
Every role combination and every combined pass writes a policy decision carrying the reason and the accepted effect. The rationale field cannot be left empty, so the record is compiled as the work happens rather than reconstructed afterwards.
Nine indexes that do not deduplicate
Nominal, Location, Vehicle, Telephone, Category, Sequence of Events, Organisations, Digital Communications and Exhibits normalise on write so one entity is one entity, but the repeat sighting is kept, because the repetition is itself the intelligence. Collisions are reported to the indexer at the moment of entry.
Links require a reason
Asserting a relationship between two records means stating why, because MIRSAP's instruction to interrogate and link is a claim, not a mechanical join. One ordered registry interleaves messages and actions, and outstanding work leads with unread material.
Control strategy and the four intelligence products, as structured outputs.
NIM sets the direction and the products that carry it. The platform holds both as governed structures, so priorities are set once and collection is measured against them.
Priorities you can hold the force to.
Three headings, one live strategy
Priorities are set under the three NIM headings per jurisdiction and period. One strategy is live per jurisdiction, and activating a new one supersedes the last, so there is no ambiguity about what direction is current.
A requirement must name a parent priority
An intelligence requirement has to point at a priority its strategy actually states, because a requirement with no parent is collection without direction.
Uncovered priorities are reported
The pack surfaces the priorities a force said mattered that nobody is collecting against, and refuses to let a strategy go active with a heading left empty.
Self-auditing techniques
Results analysis can recommend discontinuing an ineffective strategy as a first-class outcome, and an operational intelligence assessment recommending refocus must name the drift, because preventing mission creep is its job.
Assembled, not authored by one hand.
Strategic assessment
The longer-view picture that informs the control strategy for the period.
Tactical assessment
The near-term picture that drives tasking and coordination.
Subject profile
APP is explicit that the factual sections are compiled by the intelligence unit and are not the analyst's responsibility, so a product is an assembly of sections, each with its own author and output class, and the research and analysis rule applies section by section.
Problem profile
The focused study of a specific crime series, location or method. A product cannot be approved with a section outstanding, and the commissioner cannot approve their own.
The roles the standard turns on, each enforced rather than described.
SIO policy book
Decisions carry a mandatory rationale and a per-case sequence, and nothing is overwritten. A reversal writes a new entry linked to the one it supersedes, because the decision that was later reversed is exactly what a review asks about. What else was on the table is recorded alongside it.
Interview adviser
PEACE for suspects and significant witnesses, ABE for vulnerable, intimidated and child witnesses. The framework follows the subject, not the officer's preference: a child witness cannot be planned under PEACE, a vulnerable-witness plan with no recorded intermediary decision is refused, and a witness plan carrying points to prove is refused because rehearsing the evidence contaminates the account. The planner cannot approve their own plan.
Intrusion classifier
Four levels from a single open lookup to interaction with the subject. An unrecognised technique defaults to level two, not level one, so the unknown is never laundered as approved. Raising the level needs no justification, lowering it does, and the original view stays on the record. The requester cannot self-authorise or act as their own single point of contact.
Each role is enforced in the application logic and, where it matters most, by database constraints as well, so the actor is taken from the authenticated session and never from the request. The rule holds even against someone trying to route around the interface.
Point it at your current system. It shows you the case for change.
Intelligence Health reads a force's existing records management system rather than competing with it. Read-only, no dual entry, immediate value, and every finding is built from the force's own data and mapped against what HMICFRS inspections actually find. It is the adjunct phase that earns the replacement, because it makes the gaps visible before anyone is asked to migrate.
Submission discipline
The most common single inspection criticism is that intelligence is not submitted at all. It detects records where material plainly existed and no report followed, with a readable reason per gap, and closing a gap as not required demands a note, because recording why is the difference between a decision and an omission.
Backlog by threat, not age
Inspections repeatedly find backlogs risk-assessed and then left. Deterministic scoring keeps its components of threat, harm and vulnerability so the ranking can be argued with, and a fresh high-threat item outranks an old low-threat one by design.
Grading consistency
Flags drift against a single source of truth for the 3x5x2 scheme and its legacy 5x5x5 mapping. Nothing about the scheme is reimplemented, so the platform and the audit agree by construction.
Cross-cutting threat
A 2018 inspection found no process to identify criminality spanning more than one threat type. It correlates subjects across threat silos, keeps the evidence so a signal can be checked rather than believed, and normalises subject keys conservatively because merging distinct people is the more dangerous error.
Analyst access audit
Inspections found assessment officers unable to reach the material they were assessing. A denial is not treated as a security success by default, so denials where the actor was working on a named product are separated from routine ones.
The case, in their own data
Each finding is drawn from the force's live records, so the argument for modernising is not a vendor claim. It is the force's own picture, measured against the standard the inspectorate holds it to.
The migration path is enforced in the schema, not left to convention: ownership of a data class has one owner with no way to express both, a transfer is refused without confirmed disclosure continuity and evidence, and the export used to prove a force could leave is read from the live database so a table added later cannot quietly go missing from it.
Doctrine as enforced rules, with a human at every gate.
Rules, not documentation
The standard is applied by the system as work happens, so it holds by default rather than depending on someone remembering to apply it.
Human decisions, recorded
Every gate is passed or blocked by a named person with a timestamped rationale, so the judgement is answerable in the same way as any other investigative step.
Built for a small team
Designed for a two or three person back office to meet the national standard, punching above its size because the discipline is in the platform, not only in the people.
See your doctrine, running.
Walk your intelligence cycle, major incident room and control strategy through with us, and see how Intelligence Health reads your current system to build the case for change.