Security Intelligence

How We Build an Africa OSINT Collection Architecture — Six Layers, One Standard

Open-source coverage of Africa has improved sharply; the constraint is now structure. The six collection layers we run, and the failure mode each one prevents.

By Mowlid Ali 27 Aug 2026 9 min Security Intelligence
Source

Originally reported by ACLED (Armed Conflict Location & Event Data Project). INGO ADVISORY analysis is attributable to our intelligence desk; the underlying reporting remains the property of the publisher.

Read the original publication View all 4 citations
Author
Mowlid Ali
Source
ACLED (Armed Conflict Location & Event Data Project)
Publication date
27 Aug 2026
Location
Africa — continental
Country
Africa (continental)
Category
Security Intelligence
Threat level
SUBSTANTIAL — An attack is likely.
Analytic confidence
High
Verification status
Verified
Listen · 3 minReady to play · about 3 min

Most organisations operating in Africa do not have an intelligence problem. They have a collection problem. Information arrives from partners, WhatsApp groups, national media and a government advisory page, and nobody can say which of those sources was first, which was verified, and which is simply the same claim travelling in a circle.

What happened

Open-source coverage of the continent has improved sharply. Conflict event data, humanitarian situation reporting, satellite imagery and flight and vessel tracking are now available to any analyst with time and discipline. The constraint has moved from access to structure: a desk that pulls from twenty places without a defined architecture produces volume, not judgement.

What is changing

Three shifts matter. Conflict event reporting has become granular enough to support district-level movement decisions rather than country-level advisories. Imagery revisit rates now allow damage and displacement to be checked within days. And the volume of manipulated or recycled content has risen far enough that verification has to be a named step in the workflow, not an instinct.

Why it matters

Decisions taken on unstructured collection fail in a predictable way. A single vivid report drives a suspension that was not warranted, or a genuine deterioration is missed because it arrived in a language the desk does not monitor. Both outcomes cost programme delivery, and both are avoidable.

Where the exposure sits

The exposure is concentrated where reporting is thinnest and consequence is highest: contested rural districts in Sudan, Mali, Burkina Faso, eastern DRC and central Somalia, where national media has withdrawn and local reporting is partisan by necessity. In those areas, absence of reporting is routinely misread as absence of incident.

How we structure collection

INGO Advisory organises collection into six layers, each with a defined purpose and a defined failure mode:

  • Conflict and armed-group reporting — event data and incident records establishing what happened, where, and to whom.
  • Early warning — hazard, displacement and food-security signals that lead incidents rather than describe them.
  • Geospatial — imagery and mapping used to confirm damage, access, infrastructure status and movement corridors.
  • Cyber and digital — intrusion reporting, infrastructure outages and information operations affecting operations and staff.
  • Strategic and political risk — governance, electoral, regulatory and economic reporting that shapes the operating environment.
  • Verification — reverse image and geolocation checks, source grading and corroboration before anything is published.
A record with one source is a claim. A record with three independent sources is a finding. The difference should be visible on the page, not held in an analyst's head.

What organisations should watch

  • Whether your reporting names its originating publisher, or only the aggregator that forwarded it.
  • Whether repeated reporting of the same event is being counted as corroboration.
  • Whether local-language reporting is monitored in the districts where you actually operate.
  • Whether your desk records what it does not know, alongside what it does.

What organisations should do

Write down the six layers, name the sources you use in each, and grade them. Require every record that reaches a decision-maker to carry a source, a date, a location and a confidence statement. Then review, quarterly, the decisions that were taken on low-confidence reporting — that review, more than any new feed, is what improves a desk.

Africa Risk Brief

Get the weekly Africa Risk Brief

Analysis like this — on security intelligence and Africa's highest-risk operating environments — delivered every Monday. Free.

No spam. Unsubscribe anytime. We never share your email.