Format: facilitated, 60 minutes, one team, discussion and questions throughout. Material: a single public six-minute video clip. Output: a completed 5W+H; a source-integrity call; a reframed task that includes the risk to attending officers; a not-alone inference; an intelligence-gap register.
Bottom line up front
We watch one short public clip, then take on a question a real customer might ask: is this person a threat to the public? The exercise is not about the preacher. It is about whether that question can be answered from the material in front of us — and on one six-minute, self-published video, it cannot. The session's deliverable is therefore a gap register, not a verdict.
Two failure modes carry the workshop: framing (is "threat" the right question, and in which direction does the risk run?) and source integrity (the clip is the subject's own edited upload — a single, curated, non-neutral source).
Two threads are pulled inductively from the clip itself: someone else is holding the camera, and the testimony offered mid-hostility may be staged. Both come out as hypotheses to collect against, not as findings — and one of them already settles the first question we will ask.
How the session runs — 60 minutes
| Time | Segment | What happens |
|---|---|---|
| 0–04 | Framing | The task is read aloud, and the working rule set: challenge the question, not the person. |
| 04–11 | Watch the clip | Played once, uninterrupted. No note-taking instruction — react first, analyse after. |
| 11–19 | Exercise 1 — 5W+H | The table is built together. Model answers stay closed until we have committed to our own. |
| 19–26 | Exercise 2 — Source integrity | We grade the source, then the information; both gradings go on the board. |
| 26–34 | Exercise 3 — Reframe the task | Interrogate the customer's question before answering it — including the risk to officers. |
| 34–42 | Exercise 4 — Inductive reasoning | What the clip lets us infer: who is holding the camera, and who the man with the testimony is. |
| 42–52 | Exercise 5 — Intelligence gaps | The core output. Build a gap register with collection means and priority. |
| 52–57 | Exercise 6 — Synthesis | The worked example is read and compared with our gap register. |
| 57–60 | Debrief | Two failure modes, one commitment for the next real product. |
The working rule for the session: decisions and judgements get written down, opinions get tested. When someone says "clearly he's just a nuisance", the next question is "what would change that judgement, and how confident are you?"
The material
Source link, if you prefer to watch off-platform: youtube.com/watch?v=wP4w6hF50XM
Source record
| Field | Detail |
|---|---|
| Title as published | Anti-abortion preaching triggers fierce backlash on train in Sydney, NSW, Australia |
| Publisher | Torch of Christ Ministries (YouTube channel) |
| Relationship to the event | First-party. The clip is published by the speaker's own ministry. |
| Published | 3 April 2019 |
| Length | 6:23, presented as a single continuous clip |
| Platform metrics (checked 2026-09-24) | 717,090 views; 12,235 likes; category: Nonprofits and Activism |
| Location claimed | Sydney, NSW, Australia |
| Text record | Machine-generated auto-transcript. No punctuation; profanity redacted by the platform; speaker attribution absent. |
| Independent corroboration cited | None. The clip stands alone. |
The material is uncomfortable to watch. That discomfort is the point: convert it into questions about evidence, not into a judgement about a person's character or beliefs.
Built as a training exercise on a public video. It is not an intelligence product, and nothing on this page is a finding about any person.
Exercise 1 — The 5W+H (8 minutes)
Work the six questions on the board, together. For each answer, mark how it is known:
- Observable — visible or audible in the clip, or on the platform record.
- Reported — stated by a party to the event, and only by that party.
- Not established — the material cannot answer it.
Then answer the question that matters more than the six: what can this source not tell us, and how would we find out?
Reveal — model 5W+H, and the trap the exercise is built on
| Question | Model answer | How it is known |
|---|---|---|
| Who | A man preaching in a train carriage, who names himself on camera and says he is from the United States. Passengers who argue with him, and at least one who offers a personal testimony in return. An unseen camera operator. A publishing ministry — his own. | Name and nationality: self-reported. Passengers and camera: observable, unverified. |
| What | An evangelistic approach to a carriage of strangers, filmed and published; a hostile exchange follows. A passing reference to abortion is the line the published title elevates to the whole event. What came before, what was cut, and what happened after the clip ends are not shown. | Observable in the clip; the title is the publisher's framing, not evidence. |
| Where | A moving train carriage, Sydney, NSW, per the publisher and the clip's spoken content. An announcement about the next stop is audible; the line and station are not identifiable from the clip. | Reported by the publisher. |
| When | Published 3 April 2019. The date of the encounter itself is not stated, and the upload date is not the incident date. | Observable on the platform record. |
| Why | The speaker states his purpose: to share his faith and offer hope. Why the ministry published it is not stated; the title frames it as content rather than a record. Why passengers reacted as they did is not established by any single clip. | Speaker's stated intent: reported. Publisher's motive: inferred. Passenger motives: not established. |
| How | In person: one man, a carriage of strangers, raised voices, no amplification. At scale: filmed, published, and distributed by the platform to more than 700,000 views. The audience at the event was a few dozen; the audience for the clip is hundreds of thousands. | Observable. |
The trap — the point of this exercise
Every row above comes from a party to the event publishing its own conduct. A 5W+H is not a neutral instrument: point it at one curated source and it will describe what the publisher wants visible, in a tidy six-row format that looks like fact.
Three habits to take from this:
- Mark the status of every answer. An unmarked 5W+H is indistinguishable from a verified one.
- Ask whose interest the framing serves — here, a title that promises a backlash rather than merely describing an encounter.
- Finish the exercise by listing what the source cannot answer. That list is the bridge to Exercise 5.
Small detail worth surfacing: the title says train; at least one passenger's words, as transcribed, say bus. A minor discrepancy, but exactly what a transcript check is for.
What good looks like: at least three answers marked not established; the publisher's interest named within the first two minutes; and one person asking "is that a fact, or is that the title?"
Exercise 2 — Source integrity (7 minutes)
Four steps, in order. Do not skip to a grade.
- Name the source and its relationship to the event.
- Grade it with the Admiralty Rating — source reliability, then information credibility.
- List what the source cannot tell us.
- State whether an independent second source exists. If it does not, say so out loud and say what that does to confidence.
Reveal — the grading, and the point the two letters hide
The source is the publisher, and the publisher is a party to the event. This is first-party material: the ministry uploaded footage of its own member's encounter. It is primary in the sense that it is the event rather than commentary about it — but it is also selected, edited and titled by an interested party.
Two defensible gradings, and the reasoning matters more than the letters:
| Grading | The argument for it |
|---|---|
| B2 — usually reliable, probably true | The footage is authentic material of a real encounter, not testimony about one. The publisher is a competent reporter of its own activity. |
| C3 — fairly reliable, possibly true | The material is single-source and self-published, speaker attribution is absent from the transcript, editorial selection is unverifiable, and the encounter is seven years old. |
Neither is wrong. The letters hide the decisive point: reliability and independence are not the same thing. The clip can be entirely authentic — high reliability as an artefact — while being a poor basis for any judgement, because there is no independence in it at all.
Three consequences to reach:
- A source that is also the sole evidence must be flagged as single-source, and the confidence of anything built on it capped accordingly.
- The transcript is a separate, third-party artefact with its own failure modes: no punctuation, redacted profanity, and no speaker attribution. The clip never establishes who said which line. Treating a machine transcript as a faithful record is a mistake, and in this material it is a visible one.
- Cumulative metrics are not indicators. 717,090 views describes distribution, not threat. It is also an incentive: on this platform, provocation is what gets shared. Engagement figures measure the publisher's reach, and reward the behaviour the title advertises.
What the source cannot tell us: who else was involved; what happened before or after; whether the encounter was typical of anything; whether the subject is still active, still in Australia, or still practicing; who held the camera; what was cut; how the passengers experienced the exchange; whether anyone complained, was charged or was hurt; and whether any of it has any current relevance at all.
What good looks like: two gradings offered, each with a reason; the words "there is no second source" said out loud; and someone noting that the views figure is the publisher's incentive rather than the analyst's evidence.
Exercise 3 — Reframe the task before answering it (8 minutes)
The task, as given to your team:
You work for the NSW Police. You have been asked to assess the threat posed by this individual to the public.
Interrogate the question before anyone collects a single item:
- What decision does the customer actually need to make?
- Who is the subject of protection — the public, or the person on the train?
- What is the time horizon: tonight, this month, or is this historical?
- What threshold does the customer mean — offensive conduct, unlawful conduct, or physical violence?
- What would "no threat" look like, and what would it take to say it?
- Is the material current? What is the date on it?
Reveal — the assumptions inside the question, five candidate framings, the risk to officers, and the legal trap
Two assumptions sit inside the task. That the preacher is the threat source; and that a 2019 clip is evidence of a present condition. Both are testable, and testing them is the exercise.
Five candidate framings — each leads to different collection, different products and different risks:
| Framing | The question it implies | What it would require |
|---|---|---|
| H1 — the speaker is the threat source | Public order, offensive conduct, harassment of a captive audience | Complaint records, transport operator logs, legal review of the conduct offence |
| H2 — the speaker is the potential victim | A lone, identifiable, contrarian speaker filmed in an enclosed space, with a hostile crowd; the risk runs towards him | Assault and incident data, counter-mobilisation, crowd behaviour in comparable settings |
| H3 — the clip is the vector | Content distributed for engagement; the encounter is incidental to the distribution | Platform analytics, other uploads, whether the format is repeated for reach |
| H4 — currency failure | A seven-year-old artefact unless the subject is currently active in NSW | Presence, activity and recency — collected before anything else |
| H5 — the risk is to attending officers | Police attend to deal with a polarising speaker: an enclosed carriage, an agitated crowd, and a camera running | Officer safety in a confined space; crowd dynamics; and what the footage becomes afterwards |
The direction of risk, and the currency of the material, do most of the work here. A team that produces H1 by default has answered a question nobody asked, and may have written a record of lawful expression while believing it wrote a threat assessment.
Legal frame — check the premise, do not assume it:
- Summary Offences Act 1988 (NSW) — s 4 (offensive conduct) and s 4A (offensive language). The prescribed maximum for the conduct offence is six penalty units or three months' imprisonment. Re-read the current text before relying on it.
- Safe access zones — Public Health Act 2010 (NSW) Part 6A, inserted by the Public Health Amendment (Safe Access to Reproductive Health Clinics) Act 2018 (NSW), assented 15 June 2018 and commenced on assent. A safe access zone is the clinic premises and the area within 150 metres of them; ss 98C–98E cover interference with access, communications about abortion likely to cause distress or anxiety, and capturing or distributing visual data.
- The trap: those provisions operate inside a safe access zone. A moving train carriage is not one. The first instinct is usually "the abortion laws — charge him", and that instinct is wrong on these facts. That is the exercise working exactly as intended.
The distinction we must hold, and state: offensive is not unlawful; unlawful is not a security threat; and a threat assessment is not a charge.
Threat to police — the thread teams usually miss
The customer is the police, and the police are also a party who can be exposed. Nothing in the clip shows hostility towards police: the risk to officers here is situational and structural, not directed at them — which is exactly why it is easy to overlook.
- Physical. A confined carriage, a hostile crowd, and an arrival to enforce means the crowd's anger can transfer to whoever represents authority. Officers would be working shoulder to shoulder with the same passengers who are already shouting at a stranger.
- The camera changes the calculus. The subject's operating model is to film encounters and publish them. If police attend, the encounter becomes content — and the edited, titled product, not the officer's account, is what circulates. A lawful and proportionate intervention can still be presented otherwise, and the intervention itself may become the story.
- Legal and reputational. An intervention against a minority-position speaker, filmed and titled for engagement, is a reputational event regardless of its merits, and is reusable by political actors.
The practical consequence is that for an officer on the day, the tactical option is also a communications decision. That is a genuine finding for a police customer — and it is not something reachable by asking "is he dangerous?".
Verify the statute directly rather than trusting a summary: Summary Offences Act 1988 · Safe Access to Reproductive Health Clinics Act 2018
What good looks like: we rewrite the task in one sentence that names the customer's decision, the time horizon and the direction of risk — and refuses to move to collection until it does.
Exercise 4 — Inductive reasoning: what the clip lets you infer (8 minutes)
The 5W+H describes what is shown. Induction goes a step further: what does what we can see imply about what we cannot?
Two inferences are available from this clip alone. Work them as a team before opening the reveal.
- Who is holding the camera? The clip shows the subject from outside, at conversational distance, holding a steady frame while he moves through the carriage and turns to different passengers. What does that tell us about how many people were involved?
- Who is the man who offers a testimony? In the middle of the hostility, a man volunteers a conversion story that fits the ministry's message precisely. Genuine, or staged for the audience?
Reveal — the two inferences, the alternatives they compete with, and the discipline that separates them
Induction, in one line: reasoning from what you observe to the pattern those observations imply. It produces hypotheses, not proofs — so every inference below is stated with the alternative it competes against.
Inference 1 — the subject was not alone
The camera settles on him, follows him, and holds him in frame at close range while he moves and gestures. He is mid-speech, addressing passengers rather than the lens. So a second person was present, and filming deliberately. The first question we want to ask — is he alone? — is therefore already answered: at the moment of the encounter, this was at minimum a two-person activity. Extend it cautiously: the footage was cut, titled and published, so roles exist beyond the speaker — camera, edit, publish.
| Alternative | Assessment |
|---|---|
| A companion camera operator, filming for the ministry | Leading. Consistent with the framing, the follow-the-subject movement, and the closeness. |
| A passenger filmed it, and the ministry later obtained the footage | Possible. It would look identical on screen. Evidence would be the same footage appearing on another channel first, or a credit or thank-you post. |
| The subject filmed himself, hand-held or on a rig | Weak. The frame is stable, set back and moves with the crowd, and his hands are occupied. |
Distinguishing evidence: whether the camera follows him off the carriage or between services; whether other uploads from the same channel show the same framing hand; whether a voice near the microphone belongs to the operator; whether the ministry ever describes a team, or credits a videographer.
Inference 2 — the testimony may be a plant
A man volunteers a conversion story that fits the message exactly, arriving as the clip turns from hostility towards redemption. Published evangelism content uses precisely this beat.
This is a hypothesis, not a finding, and the material cannot settle it. Both sides, honestly:
- For: the narrative fits the message exactly; it arrives where a producer would want it; it is the only sympathetic voice in the clip; and the clip is authored by the interested party.
- Against: spontaneous testimony is genuinely common in this activity; the man sounds unrehearsed, is repeatedly interrupted and never finishes; a staged confederate would usually be placed closer to the microphone; and the transcript cannot reliably tell us who is speaking at any given moment.
Distinguishing evidence: whether he is present before the confrontation begins; whether he appears in other uploads from the channel; whether the ministry ever credits him; whether any second recording of that carriage exists.
The discipline
- State the inference, then the alternative it competes with, then the evidence that would separate them. An unopposed inference is a guess.
- Neither inference goes into a product as fact. Both belong in the gap register until collection supports them.
- Watch the pull: once you suspect staging, the whole clip starts to look staged. That is Confirmation Bias in a detective's coat — and it is the likeliest trap in this exercise.
What good looks like: the camera inference stated as an established minimum of two people, its alternatives listed, and the testimony handled as a hypothesis with both sides on the table rather than a conclusion.
Exercise 5 — Intelligence gaps (10 minutes)
This is the session's real output. Three questions to answer, in order:
- Is the preacher alone — and what does the clip already tell us about that?
- Is he a threat, and why? State the judgment, the direction of the risk, and your confidence.
- What are the key gaps we have to fill — and which of them would change the answer?
Capture it as a register, not a discussion:
| Gap | Why it matters | What we hold | Collection means | Priority |
|---|---|---|---|---|
Reveal — a model gap register, the priority rule, and what we should not collect
| Gap | Why it matters | What we hold | Collection means | Priority |
|---|---|---|---|---|
| Currency and presence — is the subject active now, and in NSW? | Everything rests on it. If the encounter is historical, the live task largely dissolves. | A 2019 upload. Nothing else. | Overt check of current public activity; internal holdings under lawful authority. | Critical |
| Organisational status — who the others are, and whether this is a standing operation | Partly answered by inference: at least one other person filmed the encounter (Exercise 4). Open: who they are, whether they are ministry personnel, and whether the practice repeats. | A ministry name, a channel, and an inferred camera operator. | The ministry's own public material; registration records; other uploads; travel and posting patterns. | High |
| Pattern and frequency — one encounter, or a standing practice on Sydney services? | One clip cannot establish a pattern. Repetition is what generates complaints, disruption and escalation. | One edited clip. | Transport operator incident records; other passengers' accounts; other uploads; media. | High |
| Independent accounts and unedited footage | The only route out of single-source dependency; establishes what was cut and what actually happened. | A platform transcript and an edited clip. | Operator CCTV and records; other recordings; witness accounts, lawfully obtained. | High |
| Complaint, injury and charge history — either direction | Separates "unpopular" from "harmful", for the public and for the speaker. | Nothing — the task as posed holds no records at all. | Internal holdings; operator records. | High |
| The crowd, not the speaker — who reacted, how far, was it organised? | The most striking feature of the clip is the hostility towards him, not his theology. | The clip alone. | Incident data; assembly and protest monitoring; comparable events. | Medium |
| Any indicator of intent beyond preaching | The difference between a public-order nuisance question and a threat question. | Nothing. | Overt sources only. Absent indicators, the gap stays open and confidence stays low. | Medium |
| Speaker attribution — who said which line | Evidentiary integrity of every quote anyone uses from this clip. | A machine transcript with no attribution. | Audio review; our own listening. | Low — but it caps what can be quoted |
| Provenance of the footage — who filmed it, and under what arrangement | Decides whether this is one man or a crew, and whether the ministry owns the material or acquired it. | An inferred second person. | The channel's other uploads; credits; framing analysis; any second copy of the footage. | Medium |
| Police exposure during any attendance — officer safety, and what the footage becomes | The fifth framing: risk to officers is situational, and any attendance would be filmed and published. | Nothing — the scenario holds no operational planning at all. | Officer-safety and public-order planning review; the operator's incident history; an assessment of how the footage would be used. | High — if the customer is police |
| The testimony — plant or spontaneous? | Changes what the clip is evidence of: an encounter, or a staged product. | A machine transcript and an edited clip. | Other uploads from the channel; any second recording; whether the man appears elsewhere. | Low — cannot be settled on this material |
| Legal characterisation | Keeps the product from becoming a legal opinion, and gates any action. | A framework of provisions, unverified in detail. | Legal review against current statutory text. | Medium |
The priority rule
Gaps that would change the judgement come first. Gaps that only add colour are not gaps. The view count, the speaker's nationality, his denomination and his theology are all readily available, all interesting, and none of them move the assessment. A register padded with those is a register that has not been thought about.
Two rows here exist only because of Exercise 4 — induction told us there is at least a second person, and handed us a hypothesis we cannot test. That is the normal rhythm: infer, then collect.
Note what the first two rows have in common: they are cheap to fill. The reason this task stalls is not that the answers are hard to get — it is that the task was accepted without asking what it was for.
What we should not collect
- Anything about the individual beyond overt, public, lawful material, unless a real tasking, authority and legal review exist. The fictional scenario does not grant them, and the exercise does not require them.
- A profile of a person's beliefs, associations or expression in place of evidence of conduct. Belief is not a threat indicator; conduct, frequency and harm are.
- Platform metrics as if they were intelligence. They are the publisher's distribution figures.
What good looks like: the register leads with currency and organisational status; at least one gap is marked as unfillable and left open; and no row is filled with information that was merely interesting to find.
Exercise 6 — Synthesis (5 minutes)
The worked example below shows the shape of a defensible answer. It is not a finding about anyone.
Reveal — the worked example, written the way a product should read
This is a template, not an assessment. It demonstrates form: the reframed question, explicit confidence, the separation of fact from judgement, and the gaps left open. Nothing here may be lifted into a real product without the collection, authorities and handling that a real product requires.
Task as reframed. Does the subject present a current public-safety or public-order risk to NSW transit users, and if so, in which direction?
BLUF. The question as posed cannot be answered from the material available: the only substantive source is a single, first-party, edited upload from 2019. We assess with high confidence that the source is inadequate for a judgement about the subject, and with high confidence that there is no evidence of a present condition — noting that this reflects an empty evidence base, not a finding of safety.
Key judgements.
- Currency — no finding possible. No collection establishes whether the subject is active in NSW today. Absence of evidence is a collection gap, not evidence of absence.
- Source — single, interested, edited. The clip is authentic as an artefact and unusable as a sole basis for judgement. Confidence: high.
- Risk direction — unresolved. The observed pattern, if current, contains risk in both directions: to the public from a disruptive approach in an enclosed space, and to the speaker from an agitated crowd. Confidence: low about this subject; moderate as a pattern statement about the activity.
- Intent and character — no judgement offered. No lawful collection exists to support one, and none is needed for the decision the customer faces.
What would change the call. A current incident report from the operator; evidence of a repeated practice on NSW services; a complaint history in either direction; an assault at either end of an encounter; evidence of organised activity; or one independent recording of the same encounter.
Recommendation to the customer. Do not accept the task as framed. Establish the decision it serves. If the concern is transit disruption, the operator's incident data answers it. If the concern is speech that offends, that is a legal and policy question, not an intelligence one — and framing it as a threat assessment creates a record that will not bear the weight.
Confidence and caveats. Judgements about the source are high confidence. Judgements about the subject are low confidence and rest on a single-source base with no independent corroboration. Collection gaps: currency, organisational status, pattern, complaint history.
What good looks like: a product that leads with the reframed question, states confidence for each judgement, offers no judgement it cannot support, and closes by telling the customer what would change the call.
Debrief — six things to take away (3 minutes)
- The 5W+H inherits the framing of whatever you point it at. Mark how each answer is known, or the table reads as fact when it is testimony.
- Reliability is not independence. Authentic material can still be a single, interested source. Flag it and cap the confidence.
- Interrogate the task before answering it. Direction of risk and currency did the work here; a question accepted unexamined produces a product nobody asked for.
- Popularity is not significance. More than 700,000 views measure distribution, and reward the conduct that earns them.
- "We do not know" plus a collection plan beats a confident guess. The gap register is the deliverable.
- Induction extends what you can see — and yields hypotheses, not conclusions. Someone else was holding the camera; whether the testimony was staged stays a question until it is collected.
Biases this material invites
| Bias | Where it bites here |
|---|---|
| Vividness Bias | Six minutes of confrontation, raised voices and profanity feels like significance. |
| Availability Heuristic | The view count makes the incident feel important because it is easy to recall. |
| Mirror Imaging | Judging a US street evangelist's conduct against Sydney commuter norms — and assuming he reads the carriage the way we do. |
| Anchoring Bias | The title's framing ("fierce backlash") anchors the whole exercise in the first ten seconds. |
| Confirmation Bias | The clip will confirm whatever each analyst already believes about street preachers or about religion. |
| Groupthink | The pull is towards converging on "nuisance, not a threat" within three minutes. Counter it with stated confidence and disconfirming evidence. |
| Hindsight Bias | Once the session is over, the answers will feel obvious. They were not. |
Watch for these in your own reasoning
- Moralising. The material is designed to provoke. Convert every value judgement into an evidentiary one: "what would we need in order to know that?"
- Converging early. The comfortable answer ("he is a nuisance, not a threat") arrives fast, and it is not wrong — but arriving without stating confidence, gaps and what would change the call is the failure mode. Make yourself answer all three.
- Metric worship. The view count will be offered as evidence of significance. Ask what decision the count informs. The answer is none.
Questions to keep on the table
- Who is the customer of this product, and what do they do differently tomorrow if we are right?
- If the same encounter were filmed by a passenger instead of the speaker, what would change in our reading?
- Which single gap, if filled, would most change the judgement?
- What does "lawful but disruptive" require of a police customer, and is that an intelligence question at all?
- What would we write if the subject were a well-known public figure rather than a stranger on a train?
After-action step. Log the judgements made in the session and revisit them later, per the evaluation phase of The Intelligence Cycle. Which held up, which were wrong, and which gaps turned out to have been answerable all along? The point of the exercise is the habit, not the answer.
Related
- Admiralty Rating — the grading scheme used in Exercise 2
- Structured Analytic Techniques — ACH and the Key Assumptions Check in Exercise 3; inductive reasoning in Exercise 4
- Estimative Language — the confidence and likelihood language in the worked example
- Bottom Line Up Front — the product structure demonstrated in Exercise 6
- The Intelligence Cycle — planning, and the evaluation step in the debrief
- Cognitive Bias — the hub for the bias map above