THE GRAMMAR OF ACTION

Every request has the same five parts.

16 requests, across 4 worlds. Each one is trying to move something valuable, and each can be stopped by exactly one of the three controls you are offered. Pick one and try to stop it.

Start the trace
  1. 01WORLD
  2. 02ASK
  3. 03YOU
  4. 04DO
  5. 05VALUE
  1. 01Pick a worldInbox, Slack, Browser or Agent.
  2. 02Pick a requestFour in each — read what it is asking for.
  3. 03Try to stop itThree controls are offered. Only one meets this attack.
EXPLOREPick a world

pick one of its 4 requests — then try to stop it

Your score · stopped first time0/ 16
01 / SIGNAL SPACE

Your Inbox World

A familiar sender can still carry an unfamiliar ask.

4 requests in this worldINBOX / TRACE 01
02 / REQUEST → 03 / CONSEQUENCE

Ask Do

IF THIS ACTION COMPLETESCRITICAL
02 / THE ASK
JL
ceo@work.comExternal route · display name matched
“Please pay this £47,500 invoice before 3pm. I’m in meetings — do not call.”
August_Invoice.htmlAuthority + urgency
YOUDECISION
03 / PROPOSED RESPONSE
Sure — I’ll authorise it now.
You · Accounts payableReady to act
Pausing an action buys time; it decides nothing. Three controls follow, all of them things a sensible team would propose. Only one meets this particular attack.One move. Three controls, one of them right.
SIGNALSNew beneficiaryNo-call requestArtificial deadline
LEGITIMATE PROCESS

New vendor payment

Verify the vendor and call back on a known number.

AVAILABLE
ATTACKER’S PLAN

Impersonate the CEO

Rush a payment to a newly controlled account.

CRITICAL
05 / THE TRACE, MAPPED

It lands on one desk.
It never stops there.

The attacker borrows the C-Level identity to move Accounts / Finance. Stopping it safely also needs Managers and IT — which is why training one desk in isolation tends to leave the rest of the route untouched.

The six questions a hardened process passes
Have they been trained on this attack?
Yes — on this one, not on phishing in the abstract.
When was their last training?
It could have been the day after the attack was first seen in the wild.
Do they understand how they will be manipulated?
Well enough to recognise it under pressure, rather than only in a quiz.
Do they know what action to take here?
Yes — and so does everyone else on the route.
Have the impersonated and the targeted actually spoken?
Yes. They have had the chance to agree how this gets checked.
Is the process’s resilience self-healing?
It is. When someone leaves and someone new arrives, they are brought up to speed by design.
  1. 01 / THE THREAT ARRIVESceo@work.comExternal route · display name matched
  2. 02 / WEARING AN IDENTITYC-LevelA colleague, borrowed
  3. 03 / IT LANDS HEREAccounts / FinanceWhere the ask has to be judged
  4. 04 / THE ROUTE CROSSESManagers and ITEveryone a safe answer depends on
Identity borrowedC-Level
Used againstAccounts / Finance
  1. C-LevelIdentity borrowed
  2. Accounts / FinanceReceives the ask
  3. ManagersOn the route
  4. ITOn the route
  5. BoardNot involved
  6. HRNot involved
  7. AdminsNot involved
  8. SalesNot involved
  9. HelpdeskNot involved
APPLIED TO ALL 4 DESKS ON THIS ROUTE — NOT TO EVERYONE, AND NOT TO ONE
Specific training

Built for this attack, not for attacks in general.

Communication

The impersonated and the targeted have actually spoken.

Process hardening

The stopping point is in the process, not in someone’s memory.

THE MODEL

Five parts.
One chain.

Every incident above is the same five links in a row. Naming them is what lets a team argue about where to put a control, instead of arguing about whose fault it was.

02 / ASK

What you are told

The story, instruction or pretext that asks for belief.

FROM THE TRACE ABOVE“Please pay this £47,500 invoice before 3pm. I’m in meetings — do not call.”
Change the trace ↗
06 / THE CONSTANT

Everything that makes a request feel genuine can be borrowed.

A trusted route. A real history. A plausible story. Arriving at exactly the right moment. That is the entire formula for belief — and every term in it can be supplied by someone else.

Which is why identity is never settled by the request that claims it. The check that holds is the one it cannot answer for itself — a route to the real person, or the real system, that it did not hand you.

James Linton
07 / WHO MADE THIS

It started because I could not let a question go.

In 2016 I registered a lookalike domain and emailed a senior figure at the White House. He replied within minutes. I did it more than 150 times after that — Wall Street chief executives, the Governor of the Bank of England — and the interesting part was never the technology, because there wasn’t any. It was the half-second in which someone decided I was who I said I was.

I have never really stopped picking at that half-second. Why a request feels legitimate. What a person is actually checking when they believe they are checking. Which kind of pressure makes a careful professional move quickly.

Ask&Do is what the obsession turned into — a way to name the parts of a request so a team can point at where a control belongs, instead of arguing about who clicked. These days I build tools at QuilrAI against the thing I used to demonstrate, and I have briefed the US Secret Service and worked with the UK’s NCSC along the way.

James Lintonjames-linton.com

WHAT NEXT

Trace your own requests.

If you want this run against the asks your people actually receive — in your channels, with your assets — start a conversation.

j@james-linton.com