Operational identity separation: the OPSEC principle most people skip.
Short answer
Operational identity separation means keeping identities, devices, and activities compartmented so that a breach in one does not compromise the others. Most people implement privacy tools without implementing the principle that makes those tools coherent. Signal is secure. Signal used on a device that also holds your work email, your real name in the contact list, and your location history is not compartmented. Compartmentation is the discipline that gives a stack of tools any actual coverage.
What compartmentation actually means
Compartmentation is an intelligence concept applied to information security. The idea is that access to one compartment should not provide access to another. A breach in one compartment stays within that compartment, leaving the rest of the structure intact.
Applied to personal operational security, this means your source communications happen on a device that has no connection to your personal accounts, your personal accounts are not linked to your professional identity, and your professional identity is not linked to your location data. The structure is hierarchical: each layer is independently breakable, and the failure of one does not surface what the others contain.
This is different from privacy hygiene, which is about limiting what data you share. Compartmentation is about how you structure what you do keep, so that failure in one area does not cascade. A threat model built before you establish your compartments tells you which separations matter most for your specific situation.
The most common failure: identity overlap
Identity overlap is when two supposedly separate identities or contexts share a linkage that makes them traceable back to each other. The linkage can be technical: two accounts accessed from the same IP address, or two browser profiles that share a fingerprint. It can be behavioural: using the same writing style, the same username pattern, or the same operational hours across separate identities. Or it can be relational: a contact who appears in both contexts and who, when compromised or questioned, links them together.
The journalist who uses a pseudonymous email for source communications but accesses it from the same device as their personal email has not compartmented. The device logs both sessions, with the IP address, browser fingerprint, and connection timing all sitting in the same device context, so a forensic examination of that device compromises both identities at once.
The correct approach is physical separation where the stakes warrant it. Different devices for different contexts: A travel device prepared specifically for field work is compartmentation applied to geography, while a source communications device that never touches your personal accounts is compartmentation applied to identity.
Device compartmentation
The strongest form of device compartmentation is a separate physical device for each sensitive context. This is operationally demanding and often impractical. A workable intermediate is separate browser profiles with strict rules about what is accessed in each profile, combined with a separate device for the highest-risk activities.
The rules for browser profile compartmentation need to be followed consistently to be effective. Accessing a sensitive account once from the wrong profile creates a linkage that cannot be undone. The attacker does not need to catch you every time. They need to catch you once. Account creation discipline is the foundational practice that browser compartmentation rests on, and it has to be in place before any of this becomes meaningful.
Communication compartmentation
A source communication channel that also contains your personal conversations is not compartmented. The security of the channel matters less than the security of what surrounds it. Communicating safely with confidential sources begins with the assumption that the device used for source communications should contain nothing that identifies or implicates you beyond what is necessary for the communication.
Disappearing messages are a compartmentation tool. They limit how long a compromise of the device exposes historical communications. They do not protect against real-time compromise. Combined with a dedicated device and a dedicated identity, they reduce the historical exposure window while the other elements reduce the identity exposure.
The contact list on a source device should contain only the contacts relevant to that context. A contact list that includes both sources and colleagues creates a map of the journalist’s network. Metadata that connects people to each other is as valuable to an adversary as the content of the communications themselves.
Financial and account compartmentation
Every account linked to your real identity through a real payment method, a real phone number, or a real email address is a node in the identity graph. Adversaries with subpoena power or data broker access can traverse this graph from any known node to find unknown ones.
Virtual card numbers, alias email addresses, and VoIP phone numbers are the tools that break the identity graph at specific points. Used consistently, they prevent new accounts from extending the graph. They do not retroactively fix accounts that were already created with real identity markers. The protocol for creating online accounts without exposing your real identity is what closes the graph going forward. For existing accounts, audit which ones are linked to your real identity and whether those linkages are necessary.
Frequently asked questions
How much separation is enough?
Enough to address your actual threat model. For a journalist protecting sources, physical device separation for source communications is the minimum. For someone managing multiple professional identities, browser profile separation and alias email addresses may be sufficient. The answer is specific to what you are protecting and from whom.
Does using Tor provide compartmentation?
Tor provides network-level anonymity. It obscures your IP address and routes traffic through multiple nodes, but it does not provide identity compartmentation if you log into accounts tied to your real identity, or if your browser fingerprint stays consistent across sessions. Tor is one tool that can support compartmentation, not a substitute for it.
What is the most common mistake people make when starting compartmentation?
Treating it as a setup problem instead of a discipline problem. People configure two browser profiles, label one “work” and one “personal”, and then within a week they have logged into a personal account from the work profile because it was faster. The structure stays in place; the compartmentation collapses. The question is not whether you can build the separation, it is whether you can hold it under fatigue, time pressure, and minor convenience trade-offs over months. Build small, hold strictly, and expand only when the existing layer is operational without slips.
Is full compartmentation realistic for someone with a normal job and family?
Full compartmentation is rarely the right target outside of high-risk roles. The realistic goal for most people is partial separation aligned to the actual risk: a dedicated work device for sensitive professional matters, alias email for sign-ups that do not need a real identity, and a clean browser profile for activities where tracking is a concern. The principle scales down without losing its value, as long as each compartment has a clear purpose and the boundaries are not crossed for convenience. Trying to run six identities when two would cover the actual threat model usually collapses within weeks.
There’s no perfect setup. Anyone selling you perfect is selling fear. The goal is simple: make yourself a harder target than the person next to you.
