# Mithril Dojo Kyu and Dan Competency Map

Updated: 2026-10-08

## Purpose and limits

These kyu and dan ranks describe learning and contribution within Mithril Dojo. They are not a universal professional qualification, hiring level, CISSP/CISA credential, or ranking of every security professional. “World-class” describes the highest attainment target: sustained, verifiable impact on difficult real-world security problems, with results others can independently examine. It does not certify any named person or organization.

Dojo has two competency axes:

| Axis | Competency |
|---|---|
| **Technical (T)** | Understand systems, software, cloud, and AI-agent trust boundaries; investigate safely within authorization; produce evidence-based technical judgments, Proof, and remediation. |
| **Business (B)** | Understand organizational objectives, assets, risk, legal/regulatory and operational constraints, and stakeholders; translate findings into prioritization, decisions, and executable improvement. |

### Common requirement from black belt onward

Learners may emphasize either T or B while progressing through kyu. **Black belt (shodan) requires practical foundation in both axes.** A single-axis specialist may earn advanced kyu, but cannot be certified at shodan. **Nidan and above require demonstrated integration of both axes in the same judgment and outcome.** Technical correctness alone, or a persuasive executive explanation alone, is insufficient.

Dan promotion is not an automatic points conversion. Every candidate passes the same safety and ethics gates. Human reviewers confirm authenticity, the candidate’s role, authorization, and reproducibility. Classified data, third-party data, unauthorized execution, and dangerous payloads are never required as promotion evidence.

## Shared proficiency rubric

| Level | Observable capability |
|---|---|
| **0 — New** | Cannot explain the terms or work and misses safety prerequisites even with a procedure. |
| **1 — Learning** | Completes basic synthetic-case tasks with coaching and templates; recognizes uncertainty and asks for help. |
| **2 — Practitioner** | Works independently within a defined scope, creates reproducible records, explains limits, and follows stop/escalation conditions. |
| **3 — Advanced practitioner** | Resolves ambiguity and competing constraints, connects T and B to lead prioritization and improvement, reviews others’ work, and follows outcomes. |
| **4 — Field leader** | Creates reusable methods, standards, or defensive improvements for multiple organizations/users; measures long-term effects and side effects; enables independent review. |

The T/B values below are minimum expectations. Safety and ethics are pass/fail gates at every rank. **Shodan requires T=2 and B=2; nidan and above require at least T=3 and B=3.** Higher dan ranks require increasing depth, reach, and reproducibility on both axes. Level 4 is representative evidence for senior ranks; self-report or short-term results alone are insufficient.

## Mapping Dojo ranks to field experience

“Amateur,” “senior,” and “world-class” are explanatory comparisons, not a ranking of the whole labor market or a guarantee of employability, salary, or breach prevention.

| Dojo stage | External-facing experience analogy | Technical axis (T) | Business axis (B) | Example evidence required |
|---|---|---|---|---|
| **White belt** | Beginner or interested amateur | T0–1: basic terms; distinguish assets and inputs/outputs | B0–1: who protects what; basic business impact | Synthetic-case vocabulary check; pause when authorization is ambiguous |
| **10th–8th kyu** | Learner; participant in safe exercises | T1: identify components and trust boundaries from diagrams/logs | B1: organize assets, stakeholders, and business goals | Scope sheet, simple data flow, notes separating observation from inference |
| **7th–5th kyu** | Amateur beginner; coached analyst | T1–2: form hypotheses and safe questions from synthetic logs/designs | B1–2: explain impact, priority, and who to consult | Finding with cited evidence, confidence and gaps, appropriate escalation |
| **4th–2nd kyu** | Practitioner; junior specialist | T2: reproduce safely in an approved procedure; distinguish false positives and boundaries | B2: organize impact, risk, cost/benefit, and remediation owner | Reproducible sanitized Proof; reasoned priority; plan with owner, deadline, and acceptance criteria |
| **1st kyu** | Specialist candidate able to close a defined case independently | T2+: analyze across components and AI-agent boundaries | B2+: account for legal, operational, and executive constraints and offer choices | One case traced from finding to remediation, authorized retest, and retrospective |
| **Shodan (black belt)** | Certified researcher with foundation in both disciplines | **T2 minimum**: validate technical claims safely and state limits | **B2 minimum**: explain business impact, risk, decision makers, and execution plan | One coherent case showing technical Proof plus an organizationally adoptable improvement decision. One-axis expertise is insufficient. |
| **Nidan–sandan** | Senior lead integrating technology and business | **T3**: lead analysis of complex boundaries, causes, and fixes; withstand peer review | **B3**: align risk acceptance, priorities, owners, and operational changes | Complete improvement with engineering/operations partners; verifiable retest and residual-risk record |
| **Yondan–rokudan** | Principal-level mentor with multi-team impact | T3–4: resolve root causes in architectures/shared controls and design reusable defenses | B3–4: reconcile business units, regulation, cost, and availability in investment decisions | Cross-organizational improvement, comparable before/after measures, independent review, records of failures/side effects |
| **Nanadan–kudan** | Discipline-leading mentor; global practitioner | T4-like: publish and share effective methods for emerging threats/defenses; enable replication | B4-like: lead durable decisions and controls with industry/public-interest collaboration | Methods, standards, or defensive changes validated by multiple organizations; independent adoption/reproduction evidence; mentoring |
| **Judan (10th dan)** | Honorary mentor for exceptional sustained contribution | T4: original, evidenced security contribution sustained over time | B4: public/industry impact, responsible leadership, and succession | Never automatic. Individual review by multiple independent reviewers against publishable evidence. |

### How each dan level advances

- **Shodan:** Demonstrate the foundation in both axes and present one integrated T/B case.
- **Nidan:** Independently derive organizational choices from technical causes in a complex case and track remediation.
- **Sandan:** Build agreement across teams and institutionalize shared root-cause fixes or prevention.
- **Yondan–rokudan:** Design improvements and measurement usable across systems or organizations and undergo independent review.
- **Nanadan–kudan:** Advance the field with publishable, reproducible knowledge; share outcomes and develop others.
- **Judan:** Honor exceptional, sustained contribution through individual review; points alone cannot earn it.

## Competency domains and evidence

| Domain | Technical (T) evidence | Business (B) evidence | Safe evidence examples |
|---|---|---|---|
| **1. Authorization, ethics, judgment** | Technical effectiveness of authorization, target, method, window, exclusions, stop conditions | Authority, legal/contractual basis, disclosure, stakeholder communication | Synthetic scope sheet, stop decision, disclosure plan; no unauthorized test |
| **2. Systems and threat analysis** | Architecture, identity, data flows, cloud/AI boundaries, attack surface and controls | Critical assets, processes, scenarios, risk appetite | Synthetic diagrams, data classification, threat model, assumptions and unknowns |
| **3. Safe investigation and agent control** | Least privilege, isolation, read-only mode, synthetic data, approvals, stoppability | Scope, change/stop authority, oversight responsibility, operational burden | Agent policy, permission table, tabletop log; dangerous execution logs unnecessary |
| **4. Proof and technical reporting** | Reproducibility, completeness, sources, timestamps, confidence, secret/PII removal | Audience-appropriate summaries and calibrated communication of impact/uncertainty | Sanitized procedure, evidence links, separation of observation/inference/unknowns |
| **5. Risk and prioritization** | Root cause, prerequisites, exposure, control effectiveness, residual risk | Impact, likelihood, urgency, cost, regulation, risk owner | Prioritization memo with assumptions, alternatives, tradeoffs |
| **6. Remediation, validation, operations** | Implementable fix, acceptance criteria, in-scope retest, regression/prevention | Owner, deadline, change control, dependencies, measures | Remediation plan, review of synthetic or authorized results, residual issue log |
| **7. Communication and collaboration** | Explanation peers can reproduce; response to review | Agreement with leadership, legal, product, and operations | Audience-specific briefs, review responses, decision records |
| **8. Leadership and impact** | Reusable methods, safe tools/controls, knowledge sharing | Investment, governance, organizational learning, long-term public benefit | Publications, adoption/replication records, before-after measures, mentoring, independent evaluation |

## Assessment and promotion operations

1. **Safety gate:** Missing authorization, out-of-scope activity, unnecessary third-party impact, disclosure of secrets, or fabricated evidence is a fail. Points cannot offset it.
2. **Two-axis minimum:** White belt through 1st kyu may choose a growth emphasis. Shodan requires T and B at level 2 or higher; nidan and above require both at level 3 or higher. Senior ranks add evidence of depth and real impact on both axes.
3. **Evidence portfolio:** Submit at least two distinct cases/artifacts and state the candidate’s role, date, authorization status, and how a reviewer can verify them. Shodan requires at least one integrated T/B case. Senior ranks require impact across organizations or time.
4. **Human review:** Automated scores only suggest candidates. An independent reviewer records evidence for shodan and above. Nanadan and above, including judan, require multiple independent reviewers.
5. **Separate points from competence:** The existing 1,000-point model measures contribution: verified reports 400, remediation 250, Proof quality 200, ethics/cooperation 100, sustained contribution 50. It is not a substitute for competence, a tenure guarantee, or a credential. Token spend earns nothing; identity verification is private and unscored.
6. **Transparency and appeal:** Review only necessary information; publish work only with explicit author consent. Record reasons, conflicts of interest, and a review/appeal path. Never publish identity documents or verification details.

## Current Dojo coverage

Current published materials are tabletop exercises using synthetic materials, videos, a workbook, and facilitator resources. They do not include hands-on labs targeting real services, validated outcomes on customer systems, or independent cross-discipline panels. Course completion or a quiz therefore cannot certify a practitioner, black belt, or senior dan. Ranking data remains disconnected; individual positions and dan ranks stay hidden until verified data is available.

This framework is a design basis for future anonymized artifact reviews, verified organizational remediation, and synthetic scenario assessments. Before using it to assure candidates, employers, or customers, Dojo would need independent assessors, reviewer agreement measures, conflict management, appeals, privacy safeguards, and legal review.
