The Army Lawyer | Issue 5 2020

Administrative Actions with a Counterintelligence Twist

When there is a military justice action—whether court-martial, Article 15, or reprimand—our Corps is well-versed in the follow-on actions required. From post-trial procedures to administrative separations, judge advocates (JAs) can smoothly guide our commands through the sometimes-intricate processes to maintain good order and discipline.

Despite these well-exercised muscle movements, the process often grinds to a halt when elements of counterintelligence (CI) investigations and non-Army agency equities become intertwined with the well-rehearsed administrative processes. While CI investigations are not as routine as their Criminal Investigation Division (CID) counterparts, JAs should understand how to leverage these robust investigations as well as the multi-agency input supporting them. This article will assist JAs in coordinating within the interagency space to deliver the right evidence to the right actor in a usable format while leveraging the capabilities of other agencies to address the commander’s concerns.

Counterintelligence Investigations

Executive Order (EO) 12333 directs the Secretary of Defense to “protect the security of Department of Defense [(DoD)] installations, activities, information, property, and employees by appropriate means, including such investigations of applicants, employees, contractors, and other persons with similar associations with the [DoD] as are necessary.”1 This authority is further delegated through Army channels to the Commander of U.S. Army Intelligence and Security Command (INSCOM); it is formalized, in part, in Army Regulation (AR) 381-12, Threat Awareness and Reporting Program.2 In AR 381-12, Tables 3-1 through 3-4 set forth a series of indicators that Soldiers should report to 1-800-CALL-SPY or a number of other resources described.3

Through authorities from INSCOM—and as described in AR 381-20, Army Counterintelligence Program—CI agents examine these tips and generate CI reports that could serve as the basis for additional investigation.4 These investigations are designed to: identify activities that may constitute national security crimes; substantiate or refute allegations or indications of spying; protect Army personnel, installations, and property; and acquire evidence to assist in the prosecution by competent authorities.5

The collection of information about a subject of an investigation is further limited by the procedures outlined in DoD Manual 5240.01.6 During a CI investigation, generally, non-public information about a U.S. person7 can only be intentionally collected without consent when the individual is believed: to be engaged in intelligence activities on behalf of a foreign power or their agent; be engaged in international terrorist activities; or be acting on behalf of an international terrorist.8 Given the subject matter and predicate for CI investigations, it is common for the investigations to include information, classified at various levels, from a number of other agencies.

Using CI Evidence for Separation

With the robust quality of CI investigations, it is tempting to simply use the CI investigation for a traditional administrative action.9 While the CI investigation may resemble—or in some cases parallel—a CID investigation, the CI investigation is intelligence driven and governed by intelligence oversight procedures;10 on the other hand, the CID investigation is for an express law enforcement purpose.11 This distinction most commonly manifests as a JA’s inability to use all the evidence in the CI file for the separation process due to intelligence considerations such as the incidental disclosure of sources and methods.12

In originally classifying a piece of information, the agency head—whether DoD, Army, or other agency—is making a determination about the potential harm the release of that information could have on the national security of the United States. These published classification guides13 extend to the derivative classification of subsequent reports that restate, paraphrase, or incorporate the protected information.14 Stated another way, the classification protects the information—including specific words—rather than the form the information takes. Since intelligence from non-Army agencies may carry additional caveats or limitations on its distribution or use, derivative classification can make it difficult to include a summary of classified material in a separation packet.15

With the difficulty in sharing intelligence with the target of that intelligence, it is often necessary to find alternate methods for separation. One available option is to use the CI investigation as a starting point for a more traditional CID or administrative investigation.16 Although the CI investigation provides a highly reliable roadmap to misconduct, when considering this path, the JA should work closely with the CI agent to prevent the inadvertent exposure of a source who contributed to the initial CI investigation.

Alternatively, the command could base the separation on information the subject is legally entitled to. For example, when a subject fills out their Standard Form 86,17 or conducts an interview with the Office of Personnel Management, those files are accessible by the individual through the Privacy Act.18 Additionally, if there is inconsistent data between these sources and other available sources, such as Federal Bureau of Investigation or U.S. Customs and Immigration Service (USCIS) interviews, it is possible to justify separation without referencing sensitive materials.19

Finally, when a separation authority is reviewing the separation action, consider reading that commander into the CI investigation. In presenting the CI investigation in this manner, the purpose is to give context to assist the command in choosing from the range of options available under the Uniform Code of Military Justice and regulation, not as a reason for separation.

Sharing Evidence for Action by Other Agencies

In addition to screening the evidence from a CI investigation for use in a separation, other government agencies may use the information only as background rather than a basis for action. For example, in separating a non-U.S. citizen with identified CI risks, CI agents and their servicing JAs may need to work with USCIS to fully neutralize the threat through post-separation deportation. As CI investigations derive their authority from a component of the intelligence community, and in addition to the limitations of dissemination above, Procedure 4 limits how U.S. person information may be disseminated.20

In some cases, CI agents may uncover evidence of non-national security crimes—like threats against an investigator, theft, or the unauthorized use of a government information system.21 In these situations, with proper intelligence oversight, CI agents can share this information with the appropriate federal entity—generally CID. Through CID’s existing relationships with other law enforcement agencies—both federal and local—CID can share evidence of crimes with other interested agencies. In a hypothetical situation, CI and CID agents can compare interview notes on a subject with interviewers from USCIS so that all federal agencies are operating from a common set of facts during the various interviews of a subject. By including DoD law enforcement in the investigation of CI matters, where appropriate, investigators and their servicing JAs can leverage the law enforcement sharing agreements to address both the unit’s discipline issues and larger national security concerns.

Leveraging Outside Capabilities to Address Commander Concerns

In addition to the utility of using CI information in the administrative process and communicating relevant information to other federal authorities, JAs can coordinate with outside agencies to address the commander’s concerns. For example, if the subject of a CI investigation makes comments about going absent without leave, this information can be shared with other interested federal agencies. In some circumstances, these agencies have the authority to flag the subject’s passport when they attempt to travel with the document. While the majority of these flags will not stop travel, they will trigger a notification to the requiring agency of the travel—hopefully with time to act.

Another concern of commanders separating Soldiers with CI concerns is the ability of the soon-to-be former Soldier returning as a federal employee or contractor. With credible derogatory information that falls within one of the thirteen adjudicative guidelines,22 the special security officer (SSO) or security manager should report the information through the Joint Personnel Adjudication System to the DoD central adjudication facility.23 In future national records checks, correct reporting of derogatory information ensures future investigators will have access to the information before government employment.24


Separations with a CI twist can be more difficult to move through the process—not for a dearth of evidence, but due to the nature of the evidence. As such, these separations require JAs to work with non-traditional partners both inside and outside the DoD. In working through professional CI agents, the SSO/security manager, CID, and other federal agencies, JAs can support their commands with the maintenance of good order and discipline. These separations also safeguard the national security of the United States by removing people of questionable loyalty from having placement and access to sensitive information—or those with the sensitive information. TAL

MAJ McCullough is a command judge advocate at 500th Military Intelligence Brigade-Theater at Schofield Barracks, Hawaii.

A special thank you is owed to the truly professional Counterintelligence Agents of the 500th Military Intelligence Brigade-Theater, specifically the Hawaii Resident Office for talking me through their investigative procedures so that we could find ways for the brigade legal team to assist in their mission to protect national security.


