In an Admiralty Code rating like B2, what do the letter and the number each grade?
answer
- two characters, two separate judgements
- one about the sender, one about the claim
- letters A to F, numbers 1 to 6
- B6 is honest, not contradictory
- grade 1 demands independence
basics
~20 sThe letter grades the source's track record (A completely reliable, down to F cannot be judged). The number grades that one report's credibility (1 confirmed by other sources, down to 6 cannot be judged). They are graded independently.
solid answer
~50 sThe Admiralty Code, also called the NATO system, rates every incoming report with two characters that are deliberately assessed apart. The letter is **source reliability** across everything that source has ever given you: `A` completely reliable, `B` usually reliable, `C` fairly reliable, `D` not usually reliable, `E` unreliable, `F` reliability cannot be judged. The number is **information credibility** for this specific claim, judged against everything else you hold: `1` confirmed by other sources, `2` probably true, `3` possibly true, `4` doubtful, `5` improbable, `6` truth cannot be judged. The split exists because a good source can still pass on an unverifiable claim, so `B6` is a normal and honest grade, not a contradiction. Collapsing the two is the classic error: "it came from a top-tier vendor, so it is true" imports the letter into the number and gives a brand-new claim a corroboration it never earned.
go deeper
Be ready to recite both scales and say in one sentence why they are separate. Give an example of a usually-reliable source carrying an unverifiable claim.
Explain what grade 1 actually requires, namely a corroborator with its own first-hand observation, and show how you would record the reason for a grade so it can be reviewed later.
An interviewer expects you to grade per source per domain, catching the case where a trusted vendor has no visibility into the environment being asked about, and to connect the grades to the confidence you publish.
Own the question of what the grading scheme is for in your organisation: whether it stays a lightweight intake note or hardens into a score that automated decisions consume, and what that would cost you when a C3 is wrong.
## Two characters, two different jobs The Admiralty Code (the NATO system, also reproduced in US Army FM 2-22.3) is the oldest and still the most widely borrowed way of tagging incoming reporting in an intelligence function. Every item gets two characters, and the whole value of the scheme is that they are assessed **separately**. **The letter — source reliability.** A property of the *source*, accumulated over everything it has ever sent you: | Grade | Meaning | |---|---| | A | Completely reliable | | B | Usually reliable | | C | Fairly reliable | | D | Not usually reliable | | E | Unreliable | | F | Reliability cannot be judged | **The number — information credibility.** A property of *this particular report*, judged against the rest of what you know: | Grade | Meaning | |---|---| | 1 | Confirmed by other sources | | 2 | Probably true | | 3 | Possibly true | | 4 | Doubtful | | 5 | Improbable | | 6 | Truth cannot be judged | ## Why they must not be merged Reliability is a bet on a track record. Credibility is a bet on a claim. They move for different reasons, and a single blended "trust score" destroys the information you most need at 07:00 when someone asks what you actually know. - `B6` — a vendor you rely on has published something genuinely new that nothing else you hold speaks to. Honest, common, and not a criticism of the vendor. - `F1` — an anonymous tip, sender unknown and unassessable, whose *content* you then independently confirmed in your own telemetry. The claim stands even though the source does not. - `A4` — a source that has never been wrong is, this time, saying something your own logs contradict. The letter does not rescue the number. The failure this prevents is reputational laundering: a well-regarded name attached to a claim it did not verify. A vendor writing up an intrusion it responded to is reporting first-hand observation; the same vendor summarising somebody else's blog is repeating, and repetition is not confirmation. ## Reliability is access and competence, not just honesty A source can be entirely honest and still unreliable *for your question*. A telemetry-rich endpoint vendor may have excellent visibility into a Windows estate and none at all into the SaaS tenants and identity provider that are the whole of your environment. Grade the source for the domain you are asking about, and be prepared to give the same organisation different letters for different subjects. ## The number's top grade has a hidden requirement `1 — confirmed by other sources` only means anything if those other sources are **independent**. Three write-ups that all trace back to one original blog are one source wearing three hats, and a credibility grade of `1` awarded on that basis is simply wrong. Before you award corroboration, ask of each supporting report: what did *this* author observe first-hand, and would they have written it had the first report never existed? ## How the grade is actually used The two characters are inputs to the judgement you publish, not the judgement itself. A stack of `C3` and `B6` material supports a low-confidence assessment and an explicit statement of what would change it; it does not support telling an executive "we are fine" or "we are breached". The grade is also how you keep your own reasoning auditable later: when an assessment is overturned, you can see whether you over-trusted a source, over-read a claim, or both. Keep it lightweight. In a small team a two-character tag in the intake note, plus one line on *why*, is enough. Two habits ruin it: grading the **feed** rather than each report inside it, and letting a letter become a permanent label nobody ever revisits after the source is wrong twice.
- Is a grade of B6 a criticism of the source?No. It says the source is usually reliable and that this specific claim is something nothing else in your holdings speaks to yet. Brand-new first-hand reporting from a good vendor lands at B6 by definition, because corroboration has not had time to exist. Treating B6 as a smear pushes analysts to inflate the number instead, which is the real harm.
- Would you ever grade the same organisation with two different letters?Yes, per subject. Reliability folds in access and competence, not just honesty. A vendor with deep endpoint telemetry may be an A on Windows intrusion tradecraft and a D on SaaS identity abuse where it has no sensors. Grading per source per domain keeps you from importing authority into a question the source cannot actually see.
- What stops the letter from silently doing the number's job?Recording a one-line reason next to the number: what corroborates this claim, from where, and whether that corroborator observed anything itself. If the only reason you can write is 'came from a good vendor', the number is 6 and you have caught yourself. The written reason is what makes the grade reviewable after the assessment is overturned.
It is the difference between how much you trust a friend and how much you believe one particular story they told you. A reliable friend can still repeat a rumour they have not checked.
saying these in an interview costs you the question
- Treats the two characters as one blended trust score
- Says a reputable source makes a claim credible
- Thinks the number counts how many sources agreed
- Confuses 6, cannot be judged, with 5, improbable
- Grades the feed once instead of each report
- Awards grade 1 to reports that cite each other