LetsData

How we define narrative, sub-narrative, and narrative trigger

How we define narrative, sub-narrative, and narrative trigger

|

5 min read

Drafted by Erica Peterson

Ask five analysts what a "narrative" is and you will get five answers, most of them reasonable and none of them quite compatible. One means a broad framing that has circulated for years. Another means the specific false claim that surfaced on Telegram this morning. A third means the news event that set the whole thing off.

That is not anyone's fault. The field grew quickly, borrowed vocabulary from several disciplines at once, and never really stopped to agree on terms. But the imprecision has a cost. If you cannot say which of those three things you are looking at, you cannot say what changed, you cannot say whether a response worked, and you cannot compare this week's monitoring to last week's. A single count that mixes all three will rise and fall for reasons nobody can explain afterward.

So we made a decision internally: three distinct objects, three distinct definitions, used consistently in everything we produce. What follows is how we define them, and why each distinction earns its place. These are our working definitions rather than a universal standard — but they are the ones we hold ourselves to, and they are what our terminology means whenever you encounter it in our analysis.

The narrative

We define a narrative as a high-level, recurring pattern of meaning that frames how people interpret events and what they do in response. It builds the cognitive ground on which decisions get made, and it is the central object of intelligence work.

We structure every narrative the same way: agent | operator | target. Who is being cast in a role, what mechanism the framing relies on, and whose interpretation is being shaped. A narrative that frames a government as corrupt (agent) by drawing on existing public distrust (operator) among voters (target) is a complete object in that grammar. If you cannot fill all three slots, you are probably looking at something else — often a sub-narrative that hasn't been traced back to its parent yet.

One property matters more than the rest, and it explains a great deal of frustration in this work. Narratives are composite and over-determined: they are held up by many smaller claims, not one. Refute any single claim and the narrative usually stands, because it was never resting on that claim alone. This is the most common reason a debunk lands cleanly, is factually unimpeachable, and changes nothing at all.

Figure 1. A narrative sits above multiple sub-narratives, each carrying part of its weight. A trigger enters from outside and determines when the structure activates.

The sub-narrative

A sub-narrative is a specific instantiation of a narrative — a case of it. It inherits the parent's agent, operator, and target, and adds one element: a specifier. The specifier is the operational "how" or "what" — a named policy, a named event, a named mechanism.

Stay with the corruption example. The parent narrative frames a government as corrupt. A sub-narrative might hold that a particular disaster relief fund is being mishandled. Same agent, same operator, same target, plus one specific fund.

We treat sub-narratives as the load-bearing components: the claims that actually carry the parent narrative's weight in circulation. They also happen to be where the observable material lives, which makes them where most useful analytical work gets done. You can establish whether a relief fund was mishandled. You cannot establish, in any tractable sense, whether a government is corrupt in the abstract. That asymmetry is the reason we insist on the distinction rather than treating sub-narratives as small narratives.

Figure 2. The structural difference between the three objects. A sub-narrative inherits the full agent, operator, and target grammar and adds a specifier; a trigger has no such grammar at all.

The narrative trigger

A narrative trigger is a cluster of trending real-world discussion that activates or reactivates a narrative or sub-narrative. It is the on-ramp into discourse, and it answers the one question the other two objects cannot: why now.

Here is the distinction we are most careful about, because it is the easiest to lose. A trigger is not the real-world event. It is the discussion cluster forming around that event. A gas price spike is an event; the wave of argument that forms around it is the trigger. We hold that line for two reasons. Events happen constantly without activating anything, so the event alone has little predictive value. And the shape of the discussion — who joins, how quickly, in what register — is the part you can actually observe and measure.

Triggers are how we account for timing. A narrative can lie dormant for years and then resurface within hours. Nothing about the narrative changed in the interval. What changed was the availability of an on-ramp.

Figure 3. A worked example. The event produces a discussion cluster, that cluster acts as the trigger, the trigger reactivates a sub-narrative, and the sub-narrative carries a long-standing parent narrative.

The same three objects, two very different rooms

The grammar holds regardless of who is being targeted. What changes is what the specifiers are made of, and how quickly the chain runs.

In a national security context, the parent narrative is usually old. That a defensive alliance is really an aggressor is a framing with decades behind it; nobody needs to build it, and nobody is going to argue it away. What arrives fresh is the specifier. A multinational exercise gets announced, local-language debate about that exercise spikes, and a sub-narrative attaches: this particular exercise is a rehearsal for occupation. The exercise is checkable. Its schedule, its participants, its published scope are all matters of record. The parent narrative is not checkable in the same way, which is exactly why the specifier is where the work goes.

Figure 4. A national security chain. The announced exercise is the event; the local-language debate forming around it is the trigger; the occupation-rehearsal claim is the sub-narrative that carries a long-standing parent narrative.

The corporate version runs on a much shorter clock, and often the parent narrative barely predates the incident. A payment outage during a scheduled upgrade is an ordinary operational event that becomes a trigger only once complaints trend and get amplified. The sub-narrative that forms — deposits are frozen and unrecoverable — is specific enough to be answered directly, and answering it quickly is usually the whole intervention. Leave it unanswered through a second incident and the specifiers begin to accumulate into something more durable: the institution itself is unstable. At that point you are no longer managing an incident. You are managing a narrative, with all the over-determination that implies.

Figure 5. A corporate chain. The same structure, compressed into days rather than years, and with a parent narrative still forming rather than already established.

Both examples make the same point about triggers. The event is not the trigger. Exercises are announced routinely and outages happen constantly, and most of them activate nothing at all. What made these two consequential was the discussion that gathered around them.

Why we keep them separate

Definitions are only worth the discipline they impose. Ours pay for themselves in three places.

Measurement. The three objects move on different clocks. Narratives change over months or years. Sub-narratives appear and fade in weeks. Triggers spike and decay in days. A single blended volume metric is measuring three signals at once, and when it moves you will not be able to say which one moved.

Response. Each level invites a different intervention. Refuting a sub-narrative is tractable, because a specifier is checkable. Refuting a narrative usually is not. Responding to a trigger is a timing judgment rather than a content one — the question is whether to engage a discussion at all while it is still forming.

Attribution. Coordination tends to be visible at the sub-narrative and trigger levels. Organic and coordinated actors often converge on the same parent narrative, precisely because parent narratives are broad enough to be sincerely and widely held. What separates them is the pattern underneath: which specifiers appear, in what order, and how fast they attach themselves to a new trigger.

Figure 6. Quick reference. The three objects differ in level, in what they answer, in structure, and in the role they play.

The short version

A narrative is why and who. A sub-narrative is how and what. A trigger is when.

Keep them apart and a monitoring program produces findings you can compare week over week, hand to a colleague, and defend in a review. Collapse them and it produces a number. We would rather have the findings — which is why, whenever you see these terms in our work, this is what they mean.

Nobody debates whether a building needs a fire alarm system.

Nobody debates whether a building needs a fire alarm system.

Most tools tell you there's smoke. Vantage tells you which floor, who started it, whether it's spreading, and what conditions made your landscape fire-prone in the first place.

Most tools tell you there's smoke. Vantage tells you which floor, who started it, whether it's spreading, and what conditions made your landscape fire-prone in the first place.