Preserving Institutional Memory
When a senior expert retires, the judgment that gave their files meaning leaves with them. Most of it was never recorded. One Horizon records it before it goes, attributes every insight to the expert who stated it, and delivers it on demand: a direct line to the experts themselves, decision support grounded in their casework, and a course library distilled from the same material.
01
Lived, not published
One Horizon captures lived experience through structured interviews: the cases the experts worked, the frameworks they use to decide, the signals they learned to trust, and what they do first when a crisis is live.
02
Signed off by the named expert
Every insight carries the name of the expert who stated it, and deliverables are reviewed and signed off by that expert before they go out. Advice that carries a name can be questioned, defended, and acted upon.
03
Attributed answers, on demand
Ask in your own words. Visor answers from recorded expert statements, names the experts, and states any coverage gaps rather than inventing an answer. When a question needs a person, the named expert can be contacted directly.
Former Senior Leaders
Police chiefs & intelligence directors
Military & Security Leaders
Cyber, corporate & operational resilience
Diplomats & Journalists
Crisis & disinformation response
Legal Specialists
Counsel, financial crime & compliance
Thirty-second glimpse, listen, then go deep.
How Professionals Actually Detect Deception
The Science of Catching Trusted Insiders
Carrying Uncertainty, The Ottawa Terrorist Attack
The Project Big Rig Cargo Heist
The Three Million Dollar Stolen Cargo Hub
I'm Visor, the AI guide in One Horizon. Ask a work-related question and I search the platform’s expert knowledge base for relevant guidance and sources.
Answers draw from the One Horizon knowledge base and identify the contributing expert or course. When the question needs judgment beyond the available material, you can contact the relevant expert.
Organizations can discuss private deployment and governance requirements separately. One Horizon can also help capture and organize an organization’s own expert knowledge under an agreed scope.
Protecting people is always the first operational priority, regardless of incident type, and in the hours immediately after an incident, follow-on threats are assessed by tasking human source networks and technical coverage in parallel.
A key adversary tactic is to provoke democratic governments into restrictive responses, then weaponize those very restrictions as censorship narratives to further erode institutional trust. The overreaction is not a side effect of the operation; it is the objective.
Public safety incidents follow a four-phase model, Background/Assessment → Engagement → Enforcement → After-Action, with distinct posture and authority for each phase. Confusing the phase boundaries (running enforcement reflexes inside engagement) is the structural failure that ends most major incidents badly.
When more than half of recorded crime carries a cyber element, it is no longer cybercrime, it is core crime, and a specialist unit staffed with half a percent of the service will be overwhelmed on contact. The structural answer is capability at the edge: every frontline officer and every civilian member carrying some level of cyber capability.
When a GPS tracker shows no alerts but more than four hours have passed, immediately ping the device on-demand, to retrieve real-time location before any other action. The breadcrumb history is what gives police reasonable and probable grounds for the search warrant, and that window closes fast.
In a workplace investigation, redirect conversations about cultural beliefs to conduct, actions, and impact, on others. The investigation can assess what happened and who was affected; it cannot referee competing value systems, and trying to is how interviews become endless debates.
Critical Incident Stress Management and psychosocial hazard identification are two fundamentally separate processes, so CISM by design will never surface or identify psychosocial hazards, no matter how well the debriefs are run. Hazard identification needs its own machinery.
Quantify breach scope early, it calibrates the proportionality of the entire organisational response, over-spend on low-impact incidents, or under-resource the ones that actually carry insider-fraud or regulatory exposure. Scope assessment is the input, not a downstream documentation step.
In a hardship posting the operative question is not "is this environment dangerous?", many are. It is whether the country is approaching a tipping point, where conditions can change faster than protective action can be taken. Consequence-severity alone can justify almost any restriction anywhere; trajectory is the variable that separates prudence from reflex.
A common name is an investigative risk before it is anything else, so every subject runs as deliberate parallel passes, base name, name variants with proximity operators, middle names, corporate affiliations, and geographic anchors, replicated across every database. Confirmation must come from independent search dimensions, never a single lucky hit.
Licensing and enforcement must sit in separate entities, not for organisational tidiness, but because conflating issuer and regulator builds in the incentive to conceal defects. When the authority with exclusive visibility of a credential failure also owns that credential, quiet partial recalls replace industry disclosure.
A threat brief is ready for a decision-maker when it answers three things, the current situation, the resources and intelligence already held, and the consultation chain that preceded escalation. What the reviewer is listening for is completeness of the information ecosystem, not just the facts.
The duty to consult cannot be reduced to a checklist, it is different every time, and that is exactly why proponents get it wrong: they treat it as procedural notification when the obligation demands meaningful, good-faith engagement. Searching for a standard recipe is itself the misreading.
Underlying motivations, recognition, grievance, legacy, hold stronger under operational pressure than financial incentives. Reframing engagement from a transactional focus on money to one about access shifts the asset's self-perception from informant to partner, and that single reframing survives the long-cycle handler turnover.
Disinformation influence is driven by reach and narrative stickiness, not raw content volume, Telegram and YouTube deliver higher impact per post than high-volume platforms like X, which is why monitoring optimised for tweet counts misses the actual operations every time.
During engagement, build relationships and gather intelligence, but never debate rights with rights holders. Debating rights is the single most reliable way to collapse de-escalation; the discipline is to consult and pivot to a peaceful-resolution architecture instead of arguing the constitutional ground.
At the community-hub table, only one seat belongs to a police officer, public health, education, and local not-for-profits jointly review high-risk individuals before they ever enter the criminal justice system. The data behind the model: eighty percent of referrals turn out to be about mental health, not criminality.
A GPS device pinging at an unscheduled industrial area or warehouse is the signature that a stolen load has reached a stash location, not a routing anomaly. That detection moment is the operational pivot: the window to deploy recovery and coordinate the right jurisdictional response closes within hours, sometimes minutes.
Credible CQ learning pairs peer-reviewed academic sources with direct links to Indigenous-led organisations, scholarly material without community voice produces fluency without competence, and community voice without scholarly grounding produces empathy without epistemology. The combination is the discipline.
Resilience is not "bouncing back" but "bouncing forward", recovery should advance capability beyond the pre-incident baseline, not restore the status quo. Any after-action that returns the system to its prior state has missed the actual lesson encoded in the event.
Effective insider-risk response begins with securing buy-in from senior executives across all functional areas, not just security, without multi-stakeholder executive alignment, downstream investigative and remediation work stalls or fragments at the first organisational friction point, which is where insider matters actually unravel.
Data measures known risk. Leadership operates in the gap where emerging risk lives, the gradual erosion of stability that no single indicator captures yet. Organisations put people in leadership precisely to assess what the dashboard cannot yet show, and that gap widens as the stakes rise.
When a record can neither be confirmed nor eliminated as your subject, the rule is to pull the primary documents, the certificates themselves carry the identifying detail that dispositions the match. An ambiguous hit left unresolved contaminates the file; a hit ruled out with documented reasoning strengthens it.
In a credentialing failure, the clerical error is never the real story, the disclosure failure layered on top of it is, because a defect known to the issuer but hidden from the industry silently transfers operational, legal, and reputational risk onto the parties least able to see it coming.
The intake cascade that triangulates consensus is the same machinery that hides its blind spots, each compression node between analyst and decision-maker strips out the uncertainty and dissent that would most change the final assessment. The thoroughness of the chain is what makes what it filtered invisible.
When people stop speaking honestly, the organization has not become healthier, it has become quieter. No single indicator justifies action on its own, but taken together they signal an environment becoming more fragile and less predictable.
Opinion and evidence-based assessment can coexist in one intelligence report, as long as they are physically and rhetorically separated. The discipline is separation and labelling, not exclusion.
Decision authority must be pre-defined before the incident: who commands, who can spend money, who can shut down operations, who speaks publicly, and which regulators must be notified. Settling authority inside the incident consumes the hours that matter most.
Increasing the latitude of a junior leader's decision-making is simultaneously the best test of their fortitude, and the best mentoring environment for developing it. Development and assessment are the same act, run at the same moment, on the same file.
In an internal loss investigation, follow the facts and evidence wherever they lead, and refuse to let outside senior-management influence bend or soften the findings, whoever they implicate.
Protecting people is always the first operational priority, regardless of incident type, and in the hours immediately after an incident, follow-on threats are assessed by tasking human source networks and technical coverage in parallel.
A key adversary tactic is to provoke democratic governments into restrictive responses, then weaponize those very restrictions as censorship narratives to further erode institutional trust. The overreaction is not a side effect of the operation; it is the objective.
Public safety incidents follow a four-phase model, Background/Assessment → Engagement → Enforcement → After-Action, with distinct posture and authority for each phase. Confusing the phase boundaries (running enforcement reflexes inside engagement) is the structural failure that ends most major incidents badly.
When more than half of recorded crime carries a cyber element, it is no longer cybercrime, it is core crime, and a specialist unit staffed with half a percent of the service will be overwhelmed on contact. The structural answer is capability at the edge: every frontline officer and every civilian member carrying some level of cyber capability.
When a GPS tracker shows no alerts but more than four hours have passed, immediately ping the device on-demand, to retrieve real-time location before any other action. The breadcrumb history is what gives police reasonable and probable grounds for the search warrant, and that window closes fast.
In a workplace investigation, redirect conversations about cultural beliefs to conduct, actions, and impact, on others. The investigation can assess what happened and who was affected; it cannot referee competing value systems, and trying to is how interviews become endless debates.
Critical Incident Stress Management and psychosocial hazard identification are two fundamentally separate processes, so CISM by design will never surface or identify psychosocial hazards, no matter how well the debriefs are run. Hazard identification needs its own machinery.
Quantify breach scope early, it calibrates the proportionality of the entire organisational response, over-spend on low-impact incidents, or under-resource the ones that actually carry insider-fraud or regulatory exposure. Scope assessment is the input, not a downstream documentation step.
In a hardship posting the operative question is not "is this environment dangerous?", many are. It is whether the country is approaching a tipping point, where conditions can change faster than protective action can be taken. Consequence-severity alone can justify almost any restriction anywhere; trajectory is the variable that separates prudence from reflex.
A common name is an investigative risk before it is anything else, so every subject runs as deliberate parallel passes, base name, name variants with proximity operators, middle names, corporate affiliations, and geographic anchors, replicated across every database. Confirmation must come from independent search dimensions, never a single lucky hit.
Licensing and enforcement must sit in separate entities, not for organisational tidiness, but because conflating issuer and regulator builds in the incentive to conceal defects. When the authority with exclusive visibility of a credential failure also owns that credential, quiet partial recalls replace industry disclosure.
A threat brief is ready for a decision-maker when it answers three things, the current situation, the resources and intelligence already held, and the consultation chain that preceded escalation. What the reviewer is listening for is completeness of the information ecosystem, not just the facts.
The duty to consult cannot be reduced to a checklist, it is different every time, and that is exactly why proponents get it wrong: they treat it as procedural notification when the obligation demands meaningful, good-faith engagement. Searching for a standard recipe is itself the misreading.
Underlying motivations, recognition, grievance, legacy, hold stronger under operational pressure than financial incentives. Reframing engagement from a transactional focus on money to one about access shifts the asset's self-perception from informant to partner, and that single reframing survives the long-cycle handler turnover.
Disinformation influence is driven by reach and narrative stickiness, not raw content volume, Telegram and YouTube deliver higher impact per post than high-volume platforms like X, which is why monitoring optimised for tweet counts misses the actual operations every time.
During engagement, build relationships and gather intelligence, but never debate rights with rights holders. Debating rights is the single most reliable way to collapse de-escalation; the discipline is to consult and pivot to a peaceful-resolution architecture instead of arguing the constitutional ground.
At the community-hub table, only one seat belongs to a police officer, public health, education, and local not-for-profits jointly review high-risk individuals before they ever enter the criminal justice system. The data behind the model: eighty percent of referrals turn out to be about mental health, not criminality.
A GPS device pinging at an unscheduled industrial area or warehouse is the signature that a stolen load has reached a stash location, not a routing anomaly. That detection moment is the operational pivot: the window to deploy recovery and coordinate the right jurisdictional response closes within hours, sometimes minutes.
Credible CQ learning pairs peer-reviewed academic sources with direct links to Indigenous-led organisations, scholarly material without community voice produces fluency without competence, and community voice without scholarly grounding produces empathy without epistemology. The combination is the discipline.
Resilience is not "bouncing back" but "bouncing forward", recovery should advance capability beyond the pre-incident baseline, not restore the status quo. Any after-action that returns the system to its prior state has missed the actual lesson encoded in the event.
Effective insider-risk response begins with securing buy-in from senior executives across all functional areas, not just security, without multi-stakeholder executive alignment, downstream investigative and remediation work stalls or fragments at the first organisational friction point, which is where insider matters actually unravel.
Data measures known risk. Leadership operates in the gap where emerging risk lives, the gradual erosion of stability that no single indicator captures yet. Organisations put people in leadership precisely to assess what the dashboard cannot yet show, and that gap widens as the stakes rise.
When a record can neither be confirmed nor eliminated as your subject, the rule is to pull the primary documents, the certificates themselves carry the identifying detail that dispositions the match. An ambiguous hit left unresolved contaminates the file; a hit ruled out with documented reasoning strengthens it.
In a credentialing failure, the clerical error is never the real story, the disclosure failure layered on top of it is, because a defect known to the issuer but hidden from the industry silently transfers operational, legal, and reputational risk onto the parties least able to see it coming.
The intake cascade that triangulates consensus is the same machinery that hides its blind spots, each compression node between analyst and decision-maker strips out the uncertainty and dissent that would most change the final assessment. The thoroughness of the chain is what makes what it filtered invisible.
When people stop speaking honestly, the organization has not become healthier, it has become quieter. No single indicator justifies action on its own, but taken together they signal an environment becoming more fragile and less predictable.
Opinion and evidence-based assessment can coexist in one intelligence report, as long as they are physically and rhetorically separated. The discipline is separation and labelling, not exclusion.
Decision authority must be pre-defined before the incident: who commands, who can spend money, who can shut down operations, who speaks publicly, and which regulators must be notified. Settling authority inside the incident consumes the hours that matter most.
Increasing the latitude of a junior leader's decision-making is simultaneously the best test of their fortitude, and the best mentoring environment for developing it. Development and assessment are the same act, run at the same moment, on the same file.
In an internal loss investigation, follow the facts and evidence wherever they lead, and refuse to let outside senior-management influence bend or soften the findings, whoever they implicate.
Decades of operational judgement, distilled into one intelligent system.
5,264 insights, captured from former senior law enforcement and intelligence leaders, security and risk specialists, academics, and legal experts. Each category below is a distinct way they think under pressure, and Visor weighs all of them, in real time, in every answer it gives your team.
Hover a category to see how that mode of thinking shapes the answers Visor returns to your team.
Membership Options
An annual membership gives each seat holder the expert-access features included in the plan, Visor decision support and the full course library. Pricing is an organization platform fee plus per-seat fees, billed by invoice.
Public Service Membership
Built for government teams. Pressure-test a position before it goes upward, every module and deliverable is signed off by an expert who has held the mandate, so your department gets an in-house reference it can stand behind on the record.
platform fee per year, plus $2,450 per executive seat.
Corporate Membership
Built for industry leaders. From insider threat to crisis leadership, your team gets decision-grade frameworks verified by the people who have actually done the job, ready to put to work the very next morning.
platform fee per year, plus $3,500 per executive seat.
Security Guard Course - Province of Ontario
Ministry‑approved security guard licensing course for the Province of Ontario.
$99.99 CAD
Private Investigator Course - Province of Ontario
Ministry‑approved private investigator licensing course for the Province of Ontario.
$119.99 CAD
Expert Directory
Get in touch with one of our team members.
