How Coordination Scoring Works: Detecting Coordinated Narrative Attacks
Coordinated narrative attacks are detected by analysing how accounts behave, not what they say. Coordination scoring measures timing synchronisation, posting cadence, account age clustering and cross-platform repetition to identify when apparently independent accounts are operating as a single campaign. Signal by AI Uniti applies this behavioural method across five platforms simultaneously and typically surfaces coordination 6 to 12 hours before conventional monitoring flags it.
What is a coordinated narrative attack?
A coordinated narrative attack is a deliberate campaign in which networks of accounts, often a blend of automated and human-operated, push the same storyline about a company, institution or individual across multiple platforms in a compressed timeframe. The objective is to make a manufactured narrative look like organic public opinion.
For an ASX200 or FTSE100 company the consequences are financial: share price pressure, customer churn, regulatory attention and reputational damage that outlasts the campaign itself. This is why we frame the problem as financial protection through behavioural intelligence rather than as a communications issue.
Why content analysis misses coordination
Most monitoring tools read content. They track mentions, classify sentiment and flag keywords. Coordinated campaigns are engineered to pass exactly those checks. Each individual post looks plausible. The wording varies. The sentiment is mixed by design.
The giveaway is never the message. It is the behaviour around the message. Five hundred accounts do not organically discover the same storyline within the same 40 minutes, on platforms with no shared audience, using accounts created in the same fortnight. Content analysis cannot see that pattern. Behavioural analysis can. This is the core of coordinated inauthentic behaviour detection: the campaign gives itself away through how its accounts behave together, not through what any one of them says.
Behavioural detection carries a second advantage: it is language-agnostic. Because the signals are temporal and structural rather than linguistic, the same method works whether a campaign runs in English, Mandarin or Bahasa.
The behavioural signals that expose coordination
Temporal synchronisation: clusters of accounts posting on the same theme within abnormally tight windows.
Cadence anomalies: posting frequencies that do not match human patterns, including uniform intervals and round-the-clock activity.
Account age clustering: batches of accounts created within the same short period activating together.
Engagement distortion: follower-to-engagement ratios and amplification patterns inconsistent with organic reach.
Cross-platform correlation: the same keywords appearing in the same timeframe across different channels with no shared audience.
No single signal is conclusive. Coordination scoring works by measuring the convergence of these signals across an account cluster.
How coordination scoring works
Coordination scoring is deterministic. Every account is placed on a bot-to-human spectrum using timing patterns, posting frequency, account age, engagement ratios and behavioural anomalies. Scores are then aggregated at cluster level: when a group of accounts shows convergent behavioural signals around the same narrative, the cluster is flagged as coordinated, and the verdict carries an explainable chain of behavioural evidence.
This is not black-box machine learning. A risk officer, general counsel or regulator can trace any flag back to the specific behaviours that produced it. Why that traceability decides whether intelligence turns into action is the subject of explainable verdicts in narrative risk detection.
The method is built on scale. AI Uniti has analysed 793,000 coordinated campaign videos, and every account analysed enriches a shared profile layer that sharpens detection for every customer.
Why the first 12 hours matter
A narrative campaign is most vulnerable before it crosses into mainstream visibility. Once journalists, recommendation algorithms and genuine users begin amplifying a manufactured storyline, the distinction between inauthentic origin and organic spread stops mattering to the outcome.
Behavioural signals appear at the seeding stage, before volume builds. That is what produces Signal’s 6 to 12 hour detection window ahead of conventional monitoring: coordination is visible in behaviour long before it is visible in trending volume. Those hours are the difference between preparing a response and running damage control.
Coordinated narrative manipulation is becoming a standard instrument of market and reputational interference. The organisations that weather it will be the ones that can see coordination while it is still forming. Book a 15-minute demo to see coordination scoring on a live campaign.
Frequently Asked Questions
What is coordination scoring?
Coordination scoring is a deterministic method for detecting coordinated narrative manipulation. It measures behavioural convergence across account clusters (timing, cadence, account age, engagement patterns and cross-platform repetition) and produces explainable verdicts rather than black-box classifications.
How is coordination scoring different from social listening?
Social listening tools such as Brandwatch and Meltwater monitor what is being said and how people feel about it. Coordination scoring identifies who is saying it, and whether those voices are acting independently or as a coordinated network. The two are complementary, not interchangeable.
Does coordination scoring work across languages?
Yes. Because the signals are behavioural rather than linguistic, detection performance does not depend on the language of the campaign.
Which platforms does Signal cover?
Signal currently correlates activity across X, Bluesky, Mastodon, YouTube and RSS sources simultaneously.