Work in progress · updated 8 Oct 2026 · a hypothesis, not a finding
An incident you can walk through
Does playing an incident, and making the people's calls yourself, build understanding faster than reading the same story?
One afternoon · about two minutes · two calls are yours
37 emails arrive. Agents act in seconds. Twice, the run stops for a person to decide. That person is you.
The evidence on screen
How it went
Now try it another way
When each step happened
The record (empty until you start)
What this can't show yet: your own incident or response steps, a team playing it together, a headset or a room, and whether it helps at all. That's what the test below is for.
Why a marble run?Two earlier sketches I threw away, and the twenty ideas it was scored against, with the reasons.Why 3D here, and when not
Most security data should stay flat: tables and charts read faster, and depth hides things (Tamara Munzner's rule of thumb is "no unjustified 3D"). Here the 3D carries no numbers. It does one job: it makes cause and effect physical, so a pearl falling through gates needs no legend. Everything you have to read, the screens, the evidence and the times, stays flat beside it.
Three claims, one test
"3D helps" is three different claims. A: it speeds up one person's triage. The weakest: in my NSX study (43 people), the grid beat a flat world map. B: a shared view helps a team hold one picture. Some support: 22 cyber cadets in pairs did better with 3D mixed reality than with 2D (Ask and colleagues, 2023). C: rehearsing it builds understanding faster. Untested; the nearest evidence is a memory study of 40 people (Krokos and colleagues, 2019). This page tests C only.
Why it matters
Teams rehearse incidents as tabletop exercises: a document and some discussion questions (CISA publishes free packages; the EU's DORA rules list scenario-based tests). Buyers of AI security tools ask a related question every week: which actions may the agent take alone? Both are questions about gates: who holds each one, and what happens when nobody does.
What I'm trying
- The home page's afternoon, with its cast: porcelain figures for people, lit beads for agents.
- Gravity is time: seconds at the top, minutes in the middle, hours at the bottom.
- You make the people's two calls, with the evidence they'd see. Then you can hand either gate to the agent and run it again.
- One visual per job: the run for cause and effect, the panel beside it for what a person sees, the clocks strip for when, the record for the audit trail.
What would show it works
Ten people get the same afternoon: five as the home page's storyboard, five as this run. Four questions, timed: which steps the agent took alone, whose call kept the data inside, what a no at +19 minutes would have led to, and how long the law gave. The next day, the same four from memory. C holds only if the run group gets at least one more right the next day without taking longer. It's a convenience sample, and n gets printed.
Next step
Run the test. If C holds, let a team load its own response steps as gates: the version a buyer could use in a trial.