# Security Harms Topology
**Entity class:** Master harm map
**Domains:** Security / intelligence / law enforcement / public health / cybersecurity / institutional systems
## Definition
**Security Harms Topology** is the master map of harms that protective systems can produce while preventing, detecting, investigating, containing, or responding to threats. It is wider than predictive security. It includes identity systems, databases, watchlists, cybersecurity controls, screening systems, intelligence fusion, law-enforcement encounters, public-health surveillance, financial-security programs, access systems, autonomous decision support, and human-machine infrastructure.
Its central concern is **compounding downstream destruction across mobility, immigration, employment, education, family, reputation, finances, psychological stability, relationships, and future opportunity**. A root mistake may be small and locally correctable while its distributed consequences reorganize an entire life.
The topology asks five questions:
1. **Where did the harmful state originate?**
2. **How did it propagate across people, records, organizations, and time?**
3. **Which decisions and interventions were made from it?**
4. **How did the affected person or population adapt?**
5. **What damage survived correction of the root state?**
[[wiki/The Second Error Function|The Second Error Function]] is the accounting instrument applied to this map. The topology says **what can be harmed and how harms connect**. The second error function measures frequency, severity, reach, latency, recurrence, compounding, and residual burden.
## The topology
### Root-state harms
The system begins from a corrupted representation, unsupported classification, stale state, weak inference, unauthorized purpose, or compromised input.
- [[wiki/Identity Collision|Identity Collision]] binds one human to another person's record.
- [[wiki/Erroneous Watchlist Inclusion|Erroneous Watchlist Inclusion]] binds the correct human to an unsupported or obsolete security state.
- [[wiki/Model Error|Model Error]], [[wiki/False Positive|False Positive]], and [[wiki/Automation Bias|Automation Bias]] turn uncertainty into mistaken confidence.
- [[wiki/Surveillance Purpose Migration|Surveillance Purpose Migration]] moves data or authority beyond the purpose that justified collection.
### Propagation harms
A bad state moves through shared databases, APIs, caches, exports, reports, edges, alerts, and institutional handoffs.
- [[wiki/Distributed Erroneous State|Distributed Erroneous State]] describes one bad assertion becoming operational across many systems.
- [[wiki/Graph Error Propagation|Graph Error Propagation]] carries the error into associates, places, organizations, and inferred relationships.
- [[wiki/Surveillance Record Persistence|Surveillance Record Persistence]] allows obsolete states or their encounter exhaust to remain discoverable after correction.
- [[wiki/Correction Latency|Correction Latency]] measures the harm window between recognition, authoritative repair, and downstream synchronization.
### Encounter and intervention harms
An abstract state becomes physical or administrative action: questioning, search, delay, denial, detention, account restriction, credential loss, access refusal, investigation, deplatforming, or forced treatment.
- [[wiki/Watchlist Misidentification|Watchlist Misidentification]] supplies the clearest documented distributed example.
- [[wiki/Iatrogenic Security Intervention|Iatrogenic Security Intervention]] names interventions that worsen the state they were intended to improve.
- [[wiki/Opportunity Foreclosure|Opportunity Foreclosure]] closes work, education, mobility, treatment, visibility, or restoration before the predicted event occurs.
### Recursive harms
The system changes the person or population it observes. Adaptation then returns as new data.
- [[wiki/Observation-Induced Ground Truth|Observation-Induced Ground Truth]] describes data produced by the allocation of attention.
- [[wiki/Runaway Predictive Feedback Loop|Runaway Predictive Feedback Loop]] describes interventions that manufacture confirming observations.
- [[wiki/Identity-Rooted Error Amplification|Identity-Rooted Error Amplification]] begins from a bad identity state and compounds through reaction, adaptation, and reinterpretation.
- [[wiki/Surveillance Trust Externality|Surveillance Trust Externality]] degrades future cooperation and therefore the future sensor field.
### Trajectory harms
The deepest harm is cumulative rather than episodic. [[wiki/Life-Trajectory Harm|Life-Trajectory Harm]] occurs when mobility, employment, education, family relations, immigration status, health, money, reputation, and attention reorganize around the system's state. A person can lose years of possibility through many individually explainable events even when no single institution observes the aggregate.
The [[wiki/Rahinah Ibrahim|Rahinah Ibrahim]] record demonstrates this architecture. One incorrectly completed nomination form propagated into arrest, detention, missed travel, visa revocation, inability to return to the United States, disruption of doctoral work and professional relationships, family effects, international watchlist exports, and nearly a decade of litigation. Her daughter was prevented from boarding a flight to attend the trial. The appellate record described litigation costing more than $3.6 million. The initiating error was tiny; the downstream life field was enormous.
### Epistemic and redress harms
- [[wiki/Redress Opacity|Redress Opacity]] prevents the person from seeing the state that must be contested.
- [[wiki/Legibility-Gated Redress|Legibility-Gated Redress]] means only visible harms generate complaints and statistics.
- [[wiki/Disclosure Asymmetry|Disclosure Asymmetry]] gives institutions the causal record while the affected person experiences unexplained consequences.
- [[wiki/Negative Identity Assertion|Negative Identity Assertion]] supplies a machine-readable way to prevent repeat collision, but requires the system to retain a record of the prior misidentification.
### Relational and collective harms
Security systems are graphs. Families, colleagues, congregants, clients, students, travel companions, devices, accounts, and shared places can acquire derivative attention around an erroneous root node. The harm may include delay, questioning, associated-person records, reputational suspicion, chilled association, family separation, and loss of collective trust.
### Institutional and mission harms
Bad security states also injure the protective mission. Analysts spend time resolving preventable collisions. Frontline personnel receive unreliable handling instructions. Resources move away from real threats. Repeated error reduces public cooperation. Inaccurate records can create both false positives and false negatives. Harm to the individual and harm to security effectiveness are therefore joined rather than opposed.
## Compounding downstream destruction
The central analytic unit is not the root error alone. It is the cascade:
**bad input → erroneous state → distribution → local decisions → human adaptation → new observations → reinforced state → delayed correction → residual records → altered life trajectory**
The system can distribute harm more efficiently than it distributes awareness of harm. Each component sees a lawful local task: resolve a match, deny boarding, review a visa, question a traveler, log an encounter, protect a source, or wait for authoritative correction. The affected person experiences the combined system as one continuing force.
[[wiki/Cumulative Downstream Burden|Cumulative Downstream Burden]] is the metric for this cascade. It counts encounters, institutions, derivative decisions, associated people, time, cost, lost opportunity, psychological load, behavioral adaptation, and residual effects per root error.
## Evidence tiers
- **Established:** documented adverse encounters, data-quality failures, correction delays, downstream propagation, litigation histories, purpose migration, measurable trust loss, and documented iatrogenic effects.
- **Strongly indicated:** compounding interaction among distributed records, adaptive behavior, institutional opacity, and opportunity loss when multiple documented mechanisms converge.
- **Plausible:** harms compatible with the architecture but lacking a case-specific causal record.
- **Unresolved:** named pathways requiring a deciding audit log, dissemination record, source record, causal study, or adjudicated case.
## Relationships
- **measurement layer:** [[wiki/The Second Error Function|The Second Error Function]], [[wiki/Cumulative Downstream Burden|Cumulative Downstream Burden]], and [[wiki/Correction Latency|Correction Latency]].
- **identity harms:** [[wiki/Watchlist Misidentification|Watchlist Misidentification]], [[wiki/Identity Collision|Identity Collision]], [[wiki/Erroneous Watchlist Inclusion|Erroneous Watchlist Inclusion]], and [[wiki/Identity-Rooted Error Amplification|Identity-Rooted Error Amplification]].
- **distributed harms:** [[wiki/Distributed Erroneous State|Distributed Erroneous State]], [[wiki/Graph Error Propagation|Graph Error Propagation]], and [[wiki/Surveillance Record Persistence|Surveillance Record Persistence]].
- **trajectory harms:** [[wiki/Life-Trajectory Harm|Life-Trajectory Harm]], [[wiki/Opportunity Foreclosure|Opportunity Foreclosure]], and [[wiki/Iatrogenic Security Intervention|Iatrogenic Security Intervention]].
- **redress layer:** [[wiki/Watchlist Redress|Watchlist Redress]], [[wiki/Negative Identity Assertion|Negative Identity Assertion]], [[wiki/Redress Opacity|Redress Opacity]], and [[wiki/Legibility-Gated Redress|Legibility-Gated Redress]].
- **canonical case:** [[wiki/Rahinah Ibrahim|Rahinah Ibrahim]] and [[wiki/Ibrahim v. Department of Homeland Security|Ibrahim v. Department of Homeland Security]].
- **principal analysis:** [[research/Harms Incurred While Bringing Preventive Systems Online|Harms Incurred While Bringing Preventive Systems Online]].
- **collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]].
## Sources / Provenance
- [GAO-06-1031 — Terrorist Watch List Screening](https://www.gao.gov/assets/gao-06-1031.pdf) (2006-09-29).
- [DOJ OIG — Follow-up Audit of the Terrorist Screening Center](https://oig.justice.gov/archives/reports/FBI/a0741/exec.htm) (2007-09).
- [GAO-25-108349 — Terrorist Watchlist: Nomination and Redress Processes for U.S. Persons](https://www.gao.gov/products/gao-25-108349) (2025-08-14).
- [GAO-26-108650 — Terrorist Watchlist: FBI Should Improve Outreach Efforts to Nonfederal Users](https://www.gao.gov/products/gao-26-108650) (2026-01-12).
- [*Ibrahim v. Department of Homeland Security*, 912 F.3d 1147](https://cdn.ca9.uscourts.gov/datastore/opinions/2019/01/02/14-16161.pdf) (9th Cir. 2019-01-02).
- [Ensign et al. — Runaway Feedback Loops in Predictive Policing](https://proceedings.mlr.press/v81/ensign18a.html) (2018).
- [WHO Guidelines on Ethical Issues in Public Health Surveillance](https://iris.who.int/bitstream/handle/10665/255721/9789241512657-eng.pdf) (2017).
**As of:** 2026-09-23