What qualifies as a Control
Not everything that sounds like good advice becomes a Control. Each one has to be:
A real requirement
Not advice or a category — something specific enough to actually do.
One clear job
It owns a single responsibility, not already covered by something else.
Contributes to an outcome
It materially advances at least one Capability.
Actually doable
It can be put in place within a defined scope — your accounts, your devices.
Checkable
You (or someone helping you) can verify whether it's actually been done.
Built to last
It stays meaningful across different technologies and providers over time.
How Controls apply
Directly, per Domain
A Control applies wherever it's relevant — directly to each Digital Life Domain it covers, not just inherited automatically because it happens to serve the same Capability as something else. The same Control can show up in more than one place (your email, your banking, your social accounts) while staying the exact same requirement underneath.
See it in practice
Controls, worked end to end
Rather than a raw list, the clearest way to see Controls in action is the starter journey — every control on that page (MFA, unique passwords, aliases, breach monitoring, and more) is a real, fully-specified Control run through all six Pillars on one account.
Grow with you
Three tiers, adopted at your pace
Controls are graded by the effort and skill they assume, so you can adopt progressively instead of facing the whole catalog at once.
Citizen
Everyday individuals seeking sound baseline protection. Start here.
Pro
For those accepting more effort for materially stronger protection.
Ghost
For elevated or targeted risk — journalists, activists, exposed people.
Tiers are cumulative in intent, not mandatory in sequence — you can be more advanced in one area of your life and simpler in another.