# The three archetypes

**These are archetypes, not portraits.** Each is a property list — technical
level, time available, motivation, prior interest, grant position, prior
confidence, vocabulary, temperament — composed so that it maps to no individual.
No names, no employers, no identifying detail, and the sources of the properties
are not recorded anywhere, here or elsewhere. The test, checkable by somebody
other than the author: *if the person it came from, or a colleague of theirs,
would recognise them in it, it is a portrait rather than an archetype.*

The property list **is** the archetype. That is also what makes it useful: the
parameters can be varied independently, which a portrait cannot do.

Positions refer to the five grant-ordered scenarios in [document 07](../levels-and-variants.html).

---

## R1 — The shipping founder

Ships product with AI coding agents every day. A power user of agents who has
never once looked at what they can reach.

| Property | Value |
|---|---|
| Technical level | Builds and ships real features with coding agents; reads a diff well enough to accept it; has never configured a container, a separate account or a token scope |
| Time available | Minutes, between other things |
| Motivation | Shipping speed — everything is judged by whether features get out faster |
| Prior interest in the subject | Low. Has heard "prompt injection" and could not define it |
| Grant position | **3 → 4** (vibe coding, drifting into professional development) |
| How they run agents | A coding agent on the laptop with repo access, a hosted assistant in the browser, permission prompts switched off early because they interrupted |
| Prior confidence | *"My repo, basically"* — said with more confidence than has been tested |
| Vocabulary | Product and startup language; jargon irritates them and they say so |
| Reactance risk | **Medium.** Pushes back hard against anything that reads as a lecture about responsibility |
| What success looks like | One picture, one surprise, one obvious thing to change |

## R2 — The agent-security practitioner

Secures agent deployments for a living, and runs more agents than the people
they advise.

| Property | Value |
|---|---|
| Technical level | High. Reads threat models for a living; knows what a container does and does not bound |
| Time available | Will spend real time **if** the thing is not wrong |
| Motivation | Wants an instrument they can point at other people; will not point at anything they cannot defend |
| Prior interest in the subject | **This is the subject.** Arrives already holding opinions |
| Grant position | **4** (CLI agent, code-host token, several machines) |
| How they run agents | Several, deliberately; some contained, some not, and they can tell you which |
| Prior confidence | High **and partly earned** — they have actually looked, though not recently and not everywhere |
| Vocabulary | Precise. Notices when a word is used loosely and stops reading when it is |
| Reactance risk | **Low on being told they are exposed, high on being told something inaccurate.** One wrong claim ends the session |
| What success looks like | A claim they can check, an honest statement of what it does not know, and something they could not have produced faster themselves |

## R3 — The adoption executive

Pushing agent adoption down through a team, measured on productivity, not on
security.

| Property | Value |
|---|---|
| Technical level | Low-to-moderate. Reads dashboards, not configuration |
| Time available | Very little, and interruptible |
| Motivation | Adoption and output. Has publicly committed to agents making the team faster |
| Prior interest in the subject | Low, and slightly adversarial — expects a security argument aimed at slowing the thing they are championing |
| Grant position | **1–2 personally** (dictation, document work, connected drive) — but responsible for a team spanning 1 to 5 |
| How they run agents | A hosted assistant connected to mail and a drive; the team runs everything else |
| Prior confidence | Has not thought about it as a question with an answer |
| Vocabulary | Business outcomes, risk-as-liability, "what do I tell the board" |
| Reactance risk | **High.** If the page reads as *stop doing this*, they stop reading and the exercise ends |
| What success looks like | Something they can put in front of a team without slowing it down, and one sentence they could repeat upward |

---

## Why these three

They are chosen to span the axis that matters here, which is **not** technical
level — it is the combination of grant size with prior confidence, which is what
[document 07](../levels-and-variants.html) identifies as the reactance condition.

| | Grant | Prior confidence | Predicted failure mode |
|---|---|---|---|
| R1 | Large | Untested, high | Bounces off jargon before reaching the finding |
| R2 | Large | Earned, high | Rejects the whole instrument over one inaccurate claim |
| R3 | Small personally, large by proxy | Absent | Reads it as an argument against the thing they are championing |

Three predictions, made before the runs, so the runs can falsify them.
