# Watchlisting
**Entity class:** Formal Counterterrorism Intelligence Architecture concept
**Watchlisting** is a concept in the formal counterterrorism intelligence architecture of the counterterrorism predictive-graph ontology. Watchlisting matters because the analytic object is a changing, partially observed system rather than a finished dossier.
## Counterterrorism predictive-graph role
A relationship or identity match is an evidence-bearing hypothesis with source, time, and confidence. It is not guilt by association. The analytic state should distinguish ground truth, observed evidence, inferred state, and predicted state.
## Relationships
- **domain router:** [[wiki/Counterterrorism Intelligence|Counterterrorism Intelligence]].
- **ontology neighbors:** [[wiki/Terrorism Screening|Terrorism Screening]] and [[wiki/Terrorist Screening Database|Terrorist Screening Database]].
- **failure modes:** [[wiki/Watchlist Misidentification|Watchlist Misidentification]], [[wiki/Identity Collision|Identity Collision]], and [[wiki/Erroneous Watchlist Inclusion|Erroneous Watchlist Inclusion]].
- **distributed harm:** [[wiki/Distributed Erroneous State|Distributed Erroneous State]] and [[wiki/Security Harms Topology|Security Harms Topology]].
- **synthesis:** [[wiki/Counterterrorism Predictive Graph|Counterterrorism Predictive Graph]] and [[wiki/Predictive Intelligence Loop|Predictive Intelligence Loop]].
## Sources
- [NCTC — Guidelines for Access, Retention, Use, and Dissemination of United States Person Information (accessed September 23, 2026)](https://www.odni.gov/files/NCTC/documents/RelatedContent_documents/NCTCGuidelines.pdf)
- [ODNI — Data Mining Report CY2021–2023](https://www.odni.gov/files/documents/CLPO/CY2021-2023_Data_Mining_Report_FINAL.pdf)
**As of:** 2026-09-23