00:01:00.000hey good morning everybody uh welcome to special edition of shadow at night
00:01:14.340it's 8 30 a.m central standard time we have sorry yeah it is central standard time i almost thought
00:01:20.700daylight savings news came out in manitoba over the weekend that we might just go to daylight
00:01:25.360savings time permanently but that rumor has been flying around for 15 or so years anyway
00:01:31.080we we have a big week at the public order emergency commission in ottawa this is going
00:01:38.160to be the last week of testimony and i'm going to tell you who the witness list is in just a second
00:01:42.840but first i would like to go back to last week you guys uh this is a very important testimony
00:01:49.260that happened on friday afternoon not a lot of people saw it because it was friday afternoon
00:01:53.540And of course, you know, when when you're heading into a weekend, you tend to go, I'll catch up later.
00:01:59.940And you never do. So this is the attorney representing the Canadian Constitution Foundation.
00:02:06.460His name is Sujit Choudhury. And he is questioning the clerk of the Privy Council.
00:02:11.340This is the highest ranking bureaucrat in the country.
00:02:14.760Her name is Janice Charette and also Natalie Druin, who is with the Privy Council.
00:02:21.620And he's asking one question. The question is, did David Vigneault's report, and David Vigneault is testifying today, he's also the head of CSIS, did David Vigneault's report regarding no threat found within the convoy to national security ever make it to cabinet?
00:02:41.620Watch them squirm. This is four minutes of squirming.
00:02:44.860Ms. Charette, was the services assessment that required that there was no threat to national security, was that shared with the cabinet?
00:08:27.120Now, a lot of people are talking about this commission saying it's nothing but a bunch of BS. It's not going to mean anything in the long run. Okay, so here is the answer to that. And it is simply, yeah, you're right. It's not going to have any impact on Trudeau legally.
00:08:43.860However, however, public opinion is at stake here.
00:08:49.200So when we see these ministers lying their asses off in front of the entire country this week, we will know.
00:08:59.120And the country will know exactly what happened.
00:13:38.220Good morning, and this is now our third opportunity to see each other and go through the evidence that you'll be giving to the Commission this morning.
00:13:51.440and what i'd like to do is begin with a little bit of housekeeping i'll remind
00:13:58.260mr commissioner i'll remind parties through you that we have already had the interview summary
00:14:08.320of these three witnesses adopted during the closed session which took place on november 5th
00:14:13.780uh we also had the uh instantly uh confidential and public versions of the institutional report
00:14:22.740we might not have to suffer through this guy for two hours one item that has not yet been adopted
00:14:28.200is the uh summary that was posted yesterday of the closed session and so witnesses i would
00:14:34.880ask you each in turn to confirm that you reviewed that summary for accuracy and
00:14:43.380adopted as part of the evidence of CSIS and ITAC before the Commission today.
00:14:48.520Can you each confirm that? Yes. Yes. Yes. Thank you. And now to begin to for those
00:14:59.200to whom each of you is not already familiar to the public if I could ask
00:15:04.380you Mr. Vignon to begin by describing your role and function within the within CSIS yes so I've
00:15:18.140been appointed the director of CSIS in June 2017 in those functions I have the full responsibility
00:15:26.860authority over the organization and I am supported by a group of senior
00:15:33.620executives including Madam Tissi here with me today and I can go into further
00:15:39.580details about the mandate of the organization now or later.
00:15:42.900Let me if I could ask the clerk to call up just on that point because you've set
00:15:50.360out your mandate in your institutional report. Mr. Clerk could you pull up
00:15:54.820doj.ir 701. I'm inferring from the number of this document that CSIS was
00:16:08.080the first federal government institution to get its institutional
00:16:11.500report filed and witnesses if we go to the second page Mr. Clerk if you could
00:16:19.580Scroll down just to the top, exactly there, thank you.
00:16:23.820And we see in the second sentence there,
00:16:27.760and I'll read it and you can follow along with me,
00:16:30.160Mr. Vignon, CSIS's core mandate is to investigate threats
00:16:34.700to the security of Canada and advise the government
00:17:18.880Thank you. Ms. Cheye, you're with ITAC. Could you tell us what your role is there and in general terms what ITAC is? We'll go into a little more detail later, but just for introductory purposes.
00:17:32.380Yes, certainly. I am the executive director of ITAC. I've been in that position since September 2021. ITAC is an organization that was created in 2004 out of the national security policy to independently produce threat assessment using a broad range of intelligence and information both at the unclassified and classified level.
00:17:56.100We have three main lines of operations.
00:17:59.380The first one is to assess and recommend the national terrorism threat level for Canada.
00:18:05.060The second one is to report and assess terrorism-related event trends and threats.
00:18:14.580And the last one is to assess and set terrorism threat level for a Canadian threat worldwide.
00:18:21.860Thank you. And can you describe, in general terms, the relationship between ITAC and CSIS?
00:18:30.860Yes, so ITAC is co-located with CSIS headquarters, and we operate under the CSIS Act.
00:18:38.860And so I do have a reporting relationship to the director of the service.
00:18:43.860And my organization works very closely with CSIS partners.
00:18:51.800We have access to the intelligence that is collected by the service, and we assess it independently.
00:18:59.100Thank you. You used a phrase there, and I'll just take you to the words that are used in your materials,
00:19:10.320which is that ITAC operates under the authorities of the CSIS Act.
00:19:15.920Now, we don't see ITAC mentioned in the CSIS Act, am I correct, Sarah?
00:20:24.740When you say ITAC is responsible for determining the national terrorism threat level, can you explain how those determinations are made?
00:20:37.220Yes, actually, ITAC is responsible to recommend the national terrorism threat level.
00:20:42.820The director of the service sets the level.
00:20:45.420Thank you. Why don't you describe exactly that, the input you have and then the role that the director plays in that?
00:20:51.500Yes. So we use a very rigorous methodology to do that.
00:20:56.840So our analysts are trained to look at a number of indicators to come up with a recommendation.
00:21:03.160So the methodology uses both qualitative indicators and quantitative indicators.
00:21:07.980We look at all available intelligence, we consult with many security partners, and we specifically do an assessment of threat actors' intent, capabilities, and opportunities to conduct an act of terrorism.
00:21:23.200It's very important to point out that the assessment is specifically on the likelihood of an act of terrorism occurring in Canada.
00:21:35.020So once we've done all this work, those consultations, this analysis, we do it at least three times a year or more often is required.
00:21:44.240When I'm satisfied with the assessment, we present it to the director who then decides whether or not he takes a recommendation on the proposed level.
00:21:53.200And just before we go over to you, Mr. Vigneault, as to your role in this, perhaps, Madam Shaya, you could explain whether there is any relationship between the definition we've seen a lot of in this hearing, that is the two sub C definition of threat to the security of Canada, and the conclusion you and your organization reach on the national terrorism threat level.
00:22:22.740Yes, of course. So as you very well know, the 2C and all the ADAC unlocks investigative powers for the service, right?
00:22:35.800ITAC is not a collecting agency. We do not collect intelligence. We assess already collected intelligence.
00:22:43.180And so the intelligence that the service collects under 2C, this is the intelligence that we assess along with other informations or consultations with partners to come up with the recommendation of threat level.
00:22:58.000If I understand what you're saying, the recommendation that you make as to a threat level isn't a recommendation that a 2C threat has been found.
00:23:11.760Now, over to you, Mr. Vigneault, when you receive the recommendation from ITAC, what's your role?
00:23:19.560So, of course, after reviewing carefully the material, I need to satisfy myself that I concur with the analysis.
00:23:28.700And I can, you know, agree or disagree with the recommendation to set the threat level.
00:23:35.900And so, I do that, as Madame Chahy described, regularly during the year.
00:23:41.760or as required if there is a specific incident that you know happens
00:23:49.440in between those set time periods and tell me is this is this sometimes a subject of dialogue
00:23:58.720between CSIS and ITAC where you receive a threat level recommendation and perhaps
00:24:04.800ask for more information or query the conclusion or give other feedback
00:24:10.240the way it works is that uh it could be a combination of you know uh regular dialogue
00:24:16.560and so while the assessment is being made you know madame chey and i would have part of different
00:24:21.520meetings we discussed uh the terrorism issues in canada and abroad and so uh our common
00:24:27.520understanding will be formed through those discussions and it happens also that you know
00:24:31.920when i received the formal material i will ask to sit down with the executive director of itac
00:24:37.440to formally question some elements to make sure that i understand exactly what's the basis of the
00:24:43.280analysis and make sure that i'm comfortable with with such analysis and then i'm uh the position
00:24:49.520to make the determination of the threat level thank you uh now uh witnesses we are going to
00:24:58.400go through a an exercise that we've colloquially we commission council of colloquially called csis
00:25:04.240101 uh similar to some of the questions you got asked in your interview and in the closed session
00:25:10.960uh probably uh madam tessier these are mostly for you uh this is your you're working the the
00:25:20.640concepts you work with every day uh but other witnesses please feel free to add uh or qualify
00:25:29.120as you think appropriate um and and and these questions uh witnesses will be about your core
00:25:37.980mandate so your your sec well soon we will come to call your section 12 mandate but your mandate
00:25:43.520to investigate threats to the security of canada and so let's start with section 12 and mr clerk
00:25:51.920if you could call uh well we uh might you might already have it on hand it's the same document the
00:25:58.740doj.ir.701 and and page two uh you have uh in the second paragraph that begins pursuant
00:26:10.980uh an extract from section 12 uh which i'll just read uh for the transcript
00:26:17.520pursuant and the first part uh is is a lead-in and i'll mention when the quotation starts
00:26:27.040pursuant to section 12 of the CSIS Act, CSIS, until the extract from the Act begins,
00:26:34.660shall collect by investigation or otherwise to the extent that it is strictly necessary
00:26:40.080and analyze and retain information and intelligence respecting activities that may on reasonable
00:26:47.760grounds be suspected of constituting threats to the security of Canada and in relation thereto
00:26:54.380shall report to and advise the Government of Canada.
00:26:59.360Now, perhaps I'll put it over to you, Ms. Tessier,
00:27:04.700to describe the function that Section 12 serves in the core mandate work of CSIS.
00:27:11.440Certainly. Thank you for the question.
00:27:13.360It is really what defines what our mandate is, as you mentioned,
00:27:17.920in terms of opening investigation, collecting information,
00:27:21.460and reporting to the Government of Canada.
00:27:23.080The intelligence cycle is such that the Government of Canada issues intelligence requirements to the security and intelligence community, of which thesis, of course, is a part.
00:27:34.140And we then issue direction to our regional offices to collect the information that can fulfill that intelligence requirement.
00:27:40.960We analyze it in our headquarters and we subsequently disseminate our assessments to the Government of Canada.
00:32:12.180to be able to investigate leads that may come out as a result of that event being held
00:32:17.920and any potential threat to that event, to spectators, to the individuals attending,
00:32:22.820high-profile personalities, that type of issue.
00:32:26.180And do you have an example of when an issue might be something that is constituting a threat?
00:32:35.700It's not, to be clear, it's not the actual event or issue that is the threat.
00:32:40.620It's the ability to investigate activities that because that event is being held, there could be a threat that comes as a result of that.
00:32:49.720So it's not the issue or event itself.
00:32:51.620Thank you. I got lazy there in my description.
00:32:55.980What you're talking about is an issue or an event in relation to which there could be activities that themselves constitute the threat, correct?
00:33:08.640And so if I can take you back to the question, is there an example that comes to mind of where an issue might give rise to activities that constitute a threat?
00:33:17.100As I mentioned, several high-profile issues where there's a gathering of personalities such as a G7, G20 event, the Olympic Games, significant events that could attract threat actors to target that event.
00:33:34.240could it in this context could an issue be an ideology like islamic terrorism
00:33:41.440that would be uh if that falls within the activities of a threat threat to terrorism
00:33:49.060does of course under 2c then that would be its own it wouldn't necessarily be um a more general
00:33:55.880issue-based event that that would fall squarely under 2c of the thesis act okay and uh
00:34:04.160so we've got uh if i if i follow this correctly looking at these uh at the listings in in paragraph
00:34:16.480two we could have an individual a group of persons or an organization who could any of those could
00:34:24.200be involved in activities or the target could be issues or events that allow for an investigation
00:34:31.340of activities that are suspected of constituting a threat because of or related to the issue or
00:34:37.480event. So it can be a permutation of those three categories of targets on their own or in
00:34:45.640conjunction with an issue or event. That's correct. Now let's get to that more refined level of
00:34:58.220description of the threat activities and a good place to find that Mr. Clerk if you can go back
00:35:06.780to page two we'll see in the footnote to page two the extract of section two of the CSIS Act
00:35:17.460and just Mr. Essay to help put this in context section two of the CSIS Act is the section that
00:35:27.020contains a long list of definitions, one of which is threats to the security of Canada, correct?
00:35:57.020And is it fair to say that for the purposes we are talking about in relation to the convoy, the blockades, the protests that in January and February of this year, that certainly the concentration and ultimately, I think, the exclusive area of interest for potential threats or for investigation of threats would be 2C.
00:36:27.020And I'll just read that out again, so it appears in the transcript.
00:36:33.240Activities within or relating to Canada directed toward or in support of the threat or use of acts of serious violence against persons or property for the purpose of achieving a political, religious, or ideological objective within Canada or a foreign state.
00:36:49.060and so that we don't have to keep repeating that uh in your community you often refer to
00:36:59.260threat related activities as a compact way of describing 2c we often refer to it as terrorism
00:37:07.240uh but yeah threat related activities related to terrorism other phrases i've seen are threats of
00:37:14.200serious violence and we all built into that we know it has to be all of those other words including
00:37:22.680ideologically motivated etc but if you hear me use that expression threats of serious violence or0.98
00:37:28.080activities directed towards serious violence you'll know that i'm talking about a 2c threat
00:37:33.920we agree on that i i would be careful on that because there could be a criminal activity that
00:37:40.100is serious violence, a murder, a homicide, that is not related to the security of Canada.
00:37:44.020So, I would just want to be clear that it has to relate to, as you pointed out, the
00:46:49.320They really believe in this extreme vision of changing society.
00:46:53.800And then, of course, serious violence, death, they are looking to kill.
00:46:57.860Right. And so I understand you're referring to the four criteria that are set out in this placemat there. So we see willingness to kill, attempting to affect societal change, ideological influence, and serious violence. So these are the criteria that would lead the service to determine that there is a threat under 2C in particular. Is that right?
00:47:21.540That's right. It's not an exact science. And I think it's important to realize that given the nature of this type of threat, we do try to develop this criteria. And as a matter of fact, many of our international allies have adopted the same vocabulary, because we know it's challenging. So we try to narrow it to those criteria in order for CSIS to begin its investigations.
00:47:44.180um okay so perhaps perhaps we can walk through through the criteria uh in turn so i'll i'll just
00:47:52.820note um actually before we go there uh a threat actor in this scenario um is not is not something
00:48:01.620somebody that the that the targets uh that the service is investigating is that correct
00:48:06.260sorry i don't think i understand your question so in order for somebody to move from being an actor
00:48:12.820into a target, they would have to meet these three criteria, is that correct?
00:48:47.820So perhaps let's go to the first criteria, willingness to kill or inspire others to kill.
00:48:53.880So what would be sufficient to meet that criteria?
00:48:59.180Our information indicating that somebody has communicated that they want to commit murder, that they're requiring arms, but it could also mean damaging property in such a way that could lead to somebody being killed, even if that wasn't the initial intent.
00:49:18.980It could also be inciting individuals to violence, because oftentimes it is the consumers of that type of propaganda who could be the ones to become radicalized and commit the act.
00:49:30.920Right. So I want to pick up on something you just said there.
00:49:33.460You said it could be destruction to property as well if it leads to loss of life.
00:49:44.040So if we zoom into this placemat onto scenario three there, this is a scenario in which presumably there's a threat to one of Canada's 10 critical infrastructure sectors, and loss of life isn't an objective per se, but it's a possible outcome, and that's what would trigger this criteria.
00:50:07.000So if we just scroll to the next page, please, Mr. Clerk.
00:50:14.040So, I think there's a definition up there about serious violence, and if we just zoom in a little bit more, and scroll to the right.
00:50:27.520Serious violence in relation to the 10 Government of Canada critical infrastructure sectors is defined as a threat actor who willfully destroys or damages property if such actions could endanger a person's life.
00:50:39.240And that's what we were just referring to, correct?
00:50:41.440So, for example, a willingness to engage in just pure destruction of property, if all the other criteria are met, wouldn't be sufficient to bring somebody up to the level of being a target. Is that correct?
00:50:58.580Yes. Okay. And so would an example of this be somebody, for instance, who might want to tear down a statue for an ideological purpose and for a desire to affect societal change, but because the potential of loss of life isn't made out, they wouldn't rise to the level of being a threat. Is that correct?
00:52:09.980Okay. So we'll turn to the next criteria, which is the desire to attempt societal change. If we can just zoom out, Mr. Clerk. And just go back up to the top page, please.
00:52:29.040So can you expand on what might meet this criteria, attempting to affect societal change?
00:52:36.140Absolutely. When we look at the IMV movement, because that's what it is, it's composition of movements, many members believe in what they call accelerationalism, which is a belief that society needs to change.
00:52:52.700if we'll take white supremacists as an example,
00:53:21.300So that's an example of societal change, where they really adhere to this accelerationist mindset, if you will.
00:53:28.760And so would somebody who's protesting meet the criteria for attempting to affect societal change?
00:53:38.100Not necessarily. I would just want to highlight that CSIS cannot, by its law, investigate lawful protest or dissent, unless it's related to one of the threats, the security of Canada.
00:53:49.660Right. And so protest alone, protest alone wouldn't be sufficient to meet this criteria.
00:54:22.240Certainly. There's xenophobic violence, as I mentioned earlier, anti-authority violence, so anti-government, gender-driven violence,
00:54:30.440and what we call other grievance that could be extreme environmental groups or animal rights type anti-abortion.
00:54:41.440I mean, the extreme violence. None of those existed during the convoy or at any other area of the country.
00:54:49.800So why does the service use the lens of movements and not discrete groups?
00:54:56.420If we look at terrorism as we're traditionally used to looking at it, we've very much been focused on groups.
00:55:03.820and those groups i'll use al-qaeda as an example very much a command and control structure where
00:55:12.140you had to be vetted and you had to really be accepted as a member of the group and very tightly
00:55:18.080held and you have to go to training camps and they like to be considered a member of al-qaeda
00:55:22.120while there are groups in the imbe space they're not as defined in the same way they don't
00:55:29.080necessarily have command and control. And it's really a movement of individuals of sometimes
00:55:34.620various elements of these ideologies and networks of individuals is a better way of describing it
00:55:41.320than actual strict groups as what we've seen in the past. Right. And so these are broad,
00:55:46.480broad categories, broad networks, and participation in any one of them, of course,
00:55:51.640isn't alone on its own because you've got the other criteria there. Yes, that's right. And we've
00:55:56.760We've seen, I've given a couple of examples, but we've seen cases where individuals, they don't belong to any group, but they adhere or they're influenced by these movements and they decide to act and commit terrorist attacks.
00:56:08.700So can you just explain to the Commission what the anti-public health measures movement is?
00:56:15.100Anti-public health came out, of course, as a result of the pandemic and individuals who felt that government was overreaching by their health regulations in terms of wearing a mask or vaccinations or what have you.
00:56:28.380And that would fall under which of these categories?
00:56:31.260Well, it's not an issue or a movement that the service investigated.
00:56:38.020However, we have seen some of our subjects of interest, subjects of investigation in the IMVE space, exploit that type of a movement.
00:56:46.240If they're anti-authority, if that's the ideology that they subscribe to, and they see government intervention, then they can exploit that to justify their ideology and say, you know, yet again, government is overreaching, that type of an example.
00:57:01.400In and of itself, anti-public health is not of concern to ceases.
00:57:04.440Right. And so what would be what would be that anchor that brings it into the purview of this of the service?
00:57:11.080Again, it would be more the individuals who exploit that type of a movement to recruit individuals, to bring them more towards the extreme view of anti-authority.
00:57:22.220Yeah, sorry, sweetheart. You're fishing and you got nothing.
00:57:26.080Serious violence to kill, to bring changes.
00:57:29.040Right. And so that that reference to serious violence is effectively what brings you back to 2C.
00:57:34.440And you mentioned another word there, Ms. Tessie, accelerationism. Can you expand on what that is?
00:57:43.680As I mentioned, and I'm not the security expert on this, but as I mentioned, it is a view that they have to accelerate the change of society because they're not satisfied with how society is right now.
00:57:56.880as I mentioned, they could be xenophobic, they could be anti-authority, and they feel the only
00:58:01.280way to make a change is not using the democratic process and voting, but rather to use serious
00:58:07.480violence to kill to bring about that change, because it's not happening in the current state
00:58:13.340of affairs. Right, and so I understand from your institutional report and from your witness
00:58:19.940summaries that the service has seen a rise in anti-public health measures content online. Is
00:58:26.240that pair? I'd say what we've seen a rise of is anti-authority rhetoric, violent rhetoric and
00:58:33.660threats against public officials. Certainly there was a rise when the public health measures were
00:58:41.360put into place, but when those were loosened, then of course the rhetoric towards that particular
00:58:47.020issue went down. But what has increased is threats against public officials, politicians.
00:58:52.860And has that posed a challenge at all for the service?
00:58:57.300It's certainly of concern to the service.
00:58:59.200So how does the service go about distinguishing between credible threats of violence and something that might just be a social media post that expresses anti-authority views?
00:59:14.160We take various measures. First of all, the service doesn't monitor all social media.
00:59:19.340I don't think we'd want our intelligence services to be monitoring everybody's social media.
00:59:22.520So it's very focused where we believe there are threats being communicated, if you will.
00:59:32.040So what kind of algorithmic flags do you have on social media then?
00:59:35.480But we take, we use all our methodologies.
00:59:38.300If, again, if we feel that we have sufficient information to begin investigation, then we'll use the techniques and our methodologies, such as surveillance or what have you, that enable us to investigate that threat further.
00:59:49.280but it is always a challenge to know when somebody's going to move from the
00:59:54.260online space to the physical space that's obviously a great concern and as I
00:59:59.720mentioned earlier it's often not necessarily the person posting the
01:00:03.600rhetoric but the person consuming it who can decide become radicalized and then
01:00:07.580act right and so please no I was just also just to reinforce something that
01:00:15.260Ms. Tissier mentioned. So it's not always the people making a threat that we're most concerned
01:00:21.060about. It's the people who will consume that rhetoric and be triggered and mobilized to
01:00:26.640violence. And to also answer another of your questions to how we evaluate the threats.
01:00:32.500At ITAC, we look at this fairly closely and we apply the same type of methodology that we use
01:00:38.660for the terrorism threat level, which is to look at the threat actors, their intent, their capability
01:00:44.040and their opportunities and so our analysts are trained they have very detailed tradecraft
01:00:49.560to learn to evaluate the intent the intent based on the message a message that says i wish that
01:00:57.160person would get killed is really not the same as a message that says i really dislike this person
01:01:02.760i just acquired a gun and i'm going to shoot the person so our i'm i'm exaggerating but it's just
01:01:11.080to give you the idea of how we actually look at those threats and and and look at them very closely
01:01:16.280with that tradecraft and that methodology in mind right and this tradecraft that itac applies would
01:01:21.480be or the methodology is is distinct from these uh three or four criteria that the service is
01:01:27.000applying is that correct uh no not entirely because we uh when we we fall on the ccs act so
01:01:34.040we we look at the potential for terrorism and so in that in that case we don't look at just any
01:01:39.400serious violence and so it needs to be motivated by our ideology it needs to be done in the purpose
01:01:45.480of leading to societal change so in that sense it's not it's not completely different it's just
01:01:50.680that we use it differently we don't use it to determine whether or not we can collect on people
01:01:55.000since we don't collect intelligence okay thank you um so i'm going to ask you to define two
01:02:02.920big concepts and so i'll pose this question to the whole panel um one uh one thing that the services
01:02:10.760is struggling with as i understand is dealing with misinformation and disinformation as it navigates
01:02:17.720um the challenges of determining between assessing credible threats online and online rhetoric so can
01:02:23.880you explain to the commission what misinformation and disinformation might mean and how that impacts
01:02:30.360your work in determining threats under section 2c certainly i can i can answer that my colleagues
01:02:36.520can certainly uh add any comments they like uh misinformation tends to be erroneous information
01:02:42.840that is proper that continues to be sent online communicate online not necessarily knowing that
01:02:51.160the information is erroneous disinformation is purposely spreading false information
01:02:57.800if that if that helps at all i think that's the purpose here is i think it's the best definition
01:03:05.380unless you want to elaborate more but totally agree with what was said so engaging where would
01:03:11.840engaging with misinformation or disinformation fall on these on these criteria so can we just
01:03:17.360zoom out a little bit more mr clerk maybe i will uh essential on this one i think it's not just a
01:03:26.040question of misinformation disinformation because that is in and of itself not something that you
01:03:31.240know we need to be aware of it conscious of it but it's not something that we we need to determine
01:03:36.440ourselves the it's more looking back to the intent and the capabilities of the individual so
01:03:42.600uh unfortunately uh uh social media internet is full of of information that is uh misleading
01:03:51.240that could be a misinformation as miss stacy described could be also purposefully misleading
01:03:56.680this so that would be disinformation so i think you know we're more interested in understanding
01:04:01.240that dynamic and then apply that understanding to our analysis of specific activities specific
01:04:07.720individuals so i think that will be more a better description of how we the service would be
01:04:15.000conscious and aware and apply those those principles right so you're aware of the fact
01:04:21.000that there are things circulating online that might not be violent rhetoric or that might not
01:04:25.720reflect a desire to engage in violence, but you've got to keep a general awareness of that. Is that
01:04:30.600fair to say? Yeah, because what we have seen, unfortunately, a number of the individuals that
01:04:35.800have perpetrated the act of terrorism in Canada, we've had, you know, since 2014, we have 25 people
01:04:43.880who have been killed in terrorist activities by people who were motivated by violent extremist
01:04:52.160ideologies. And so when you dissect, deconstruct their motivation, often because they left manifestos
01:05:01.680or writings behind and so on, you see a conflation of different issues. It could be an xenophobic
01:05:08.040ideology and then when you when you start to look at the material and the understanding
01:05:15.160you realize that there is a lot of misinformation disinformation that is weaved into their um their
01:05:21.560their their writings or their understanding that creates that belief for these individuals that
01:05:26.500they must act so that's why we see cis uh will need to have that kind of awareness he's talking
01:05:32.400about the media right interested uh you know in every misinformation disinformation that exists
01:05:38.120but that reality informs uh the uh the threat related activity of uh that is exactly what the
01:05:45.580media does thank you and the government um i'd like to shift gears now so we can just take that
01:05:51.480document down mr click thank you um and and talk to you about the uh services activities and in
01:05:59.040respect of the convoy in particular. So as I understand it, the service was aware or had
01:06:05.860pre-existing targets and came to learn of the convoy through that activity. Is that fair?
01:06:11.720Sorry, we became aware of the convoy. Yes, of course.
01:06:17.900Right. And so the service had pre-existing targets who might have been involved?
01:06:22.220Yes, we had pre-existing targets in the IMV space, to be clear.
01:08:06.580So we started to engage our regional offices in Canada
01:08:09.400and some stations abroad to better understand the dynamic.
01:08:12.620and uh so we um that that evolution you know uh of our uh or the intensity of our work you know
01:08:20.800followed the uh the events of uh of january and february right but the service was was not
01:08:28.460investigating the anti-public health measures movement broadly for example and it certainly
01:08:33.520wasn't investigating the the uh the convoy itself as a discrete topic no right as was mentioned
01:08:42.140earlier uh we are prevented by a lot to investigate uh protests and lawful dissent uh we have we're
01:08:48.660not investigating the convoy itself uh our our interest is to understand all that dynamic
01:08:55.200is potentially influencing individuals who may individuals that were known already to cesis
01:09:00.800and others potentially to uh to radicalize further and engage in potential uh
01:09:07.820threat related activity so we were not investigating the convoy right and so the
01:09:12.620services focus remained at all times on its targets and their their participation
01:09:18.680or their involvement as it may be in in those protests I would maybe clarify a
01:09:25.020Commissioner I would say that you know we were of course you know focusing on
01:09:28.020our on our subject of investigations but also the dynamic of such events is
01:09:34.500that you have people uh sometimes it can refer to alarm wolves or individuals who might be further
01:09:40.060radicalized by the protest and so our work was to engage uh with uh with our federal partners
01:09:47.920with law enforcement at the federal provincial municipal level uh in ottawa and across the
01:09:54.440country to understand how potentially what was happening in in the protest world if i can put
01:10:00.720this way could have an influence if there was any threat of violence at all involved in any
01:10:06.660of the convoy activities it was from the government themselves others who could be
01:10:10.480based upon police which was essentially a two-fold analysis provocateurs making sure we
01:10:14.820sent in there purposely either by antifa or the government to cause and so on but also
01:10:21.020understanding who were others who could potentially radicalize who could potentially start to recruit
01:10:26.140and meet others to further threat-related activity.
01:10:32.360And so that focus is one that we maintain to the end.
01:10:39.840And to a large extent, that's what we continue to do.
01:10:42.420If this is our national intelligence agency, oh my God, we're in trouble.
01:10:47.320Is that we challenge ourselves on an ongoing basis to make sure that our perspective of
01:10:52.060threat-related activity is not just linear and doesn't change.
01:10:55.500We were on an ongoing basis because of that exchange of information with other organizations, challenging ourselves to make sure do we really understand well the dynamic here and how does this apply to the CSIS Act and how our intelligence professionals are executing.
01:11:13.320Right. So looking, so would it be fair to say CSIS was looking at the protests in conjunction with its targets as the Section 2C definition allows?
01:11:23.780our yes our targets but also looking at the broader perspective to see if others would
01:11:29.980eventually engage in such activity that they could become subject of investigations so looking for
01:11:36.260potential threats yes okay um i would like to pull up a document tsnsc can 50165
01:11:46.540so i'll just i'll take you through a few briefs that the service prepared in the course of the
01:11:54.660the protests and we can we can discuss them so do you recognize this document mr vigno yes
01:12:01.120can you explain to us what it is um as per the title these are notes that were prepared for
01:12:08.480senior executive in the organization, Ms. Desir, myself, to brief outside partners in this case
01:12:18.060would be Minister Mendicino, Minister of Public Safety, who I report to as Director of CISIS.
01:12:26.080So this would have been a ministerial briefing that you would have provided, is that right?
01:12:43.580Okay. So I just want to go through the content. If we can scroll down a bit.
01:12:50.200We have sort of the very first assessment prepared by the service, I think, of the Freedom Convoy.
01:12:56.720And so there's a bullet there that says CSIS is investigating IMVE activities and monitoring IMVE social media content. There has been online commentary calling for violence and storming parliament hill buildings.
01:13:11.340buildings. And then the next bullet, CSIS is tracking engagement of its targets in relation
01:13:17.500to the convoy. Over the coming days, CSIS will be monitoring the involvement of these targets
01:13:22.140and other persons of interest, in particular for any indications of mobilization to violence.
01:13:27.660So what do those two bullets mean there? What does CSIS will be monitoring the involvement of
01:13:33.820these targets and other persons of interest, in particular for indications of mobilization to
01:13:38.780violence mean so i think as we were just uh describing in the previous exchange is that
01:13:45.180we had already an awareness of a number of individuals in canada were engaged in activities
01:13:51.420that met our threshold for for 2c investigations and so we were aware we that some of these
01:13:59.340individuals were interested in the paying a lot of close interest to the convoy and trying to
01:14:05.500understand you know what it meant saw potential opportunities and so we were
01:14:12.220looking at those individuals so these are the knowns known actors if you want
01:14:17.620our work as well is to make sure as I mentioned that we don't have tunnel
01:14:21.820vision that we just don't look at what we know but also in this context of other
01:14:26.380people who might be influenced by the the events by some specific decision by
01:14:33.700government some specific radical rhetoric online to say it is my time I
01:14:39.940need to do something so our professionals thesis and in ITAC are
01:14:46.000trained to really understand well the the distinctions we're talking about
01:14:50.740about to see and so on about what is lawful dissent and protest versus what
01:14:55.660are activities that could be potentially you don't threat related activity on the
01:14:59.260the thesis act so this is a description of that at high level of that type of work that was ongoing
01:15:05.460during that period so is the assessment there that there's a possibility of a lone actor
01:15:10.820threat is that it yes essentially at that point you know late january we're looking at
01:15:17.200at such an activity because based on again experience of our professionals we have seen
01:15:24.000individuals who seize opportunities to to engage in those acts either because they had previous
01:15:30.640beliefs or by because they are um they are in uh events or activities or or or what they might they
01:15:39.760might read uh consume in terms of information is is radicalizing them extremely quickly so a person
01:15:45.680that's not known to the service but that could be localized um so at the bottom there we see the
01:15:50.640the bullet, CSIS is unaware at this time of any tangible plots or plans of serious violence.
01:15:55.160And so at this stage, there's no risk of a threat materializing.
01:16:01.120I would not necessarily say there's no risk, it's just that we're not aware of it.
01:16:06.400And so I think, you know, it is a, I think Ms. Tessier used the expression earlier, it's
01:22:01.080and that's TSNSC CAN 001-50-211, please.
01:22:22.880Okay, so if we can just zoom out a bit
01:22:25.180so that we can see the entire page, please.
01:22:28.340so i believe this brief is dated february 10th are you familiar with this document
01:22:36.080yes i don't see the date on it i think it's just at the bottom of the page there
01:22:42.820okay um so this is this is a brief uh again on the on the protest if we just look at the title
01:22:53.000says anti-public health measures movement grievances and the freedom convoy 2022
01:22:59.480so if we scroll to the bottom of page two
01:23:05.080we have the outlook prepared by the service
01:23:12.360um sorry if we if we scroll up a bit as as well so we see there just before the redaction no
01:23:21.400formal organized plot of violence has been identified cesis assesses that the freedom
01:23:26.120convoy 2022 is of interest to various subjects of investigation especially those who hold anti-mandate
01:23:32.520or broader anti-government views um and then just just underneath outlook there cesis will continue
01:23:39.080to monitor the involvement of imves within the freedom convoy 2022 uh in order to better understand
01:23:45.080the public health measures movement so what is what is the assessment being shared here
01:23:48.680So essentially, the first line above the outlook you mentioned is that at that point, CSIS assessment was that we did not see specific actions being taken that would characterize a threat to the security of Canada associated with the events.
01:24:14.160Okay. And so the last question that I'll pose to you before I turn it back over to Mr. Cameron is, you know, we've heard, the commission has heard evidence about the distinction between lawful and unlawful protests.
01:24:28.100So in this period between January 27th up to February 10th, you might have even formed the view, just as a personal opinion, that the protests might have gone from being a lawful one to an unlawful one.
01:24:40.340Would that have had any bearing on your assessments or on your work?
01:24:45.520No, because it's not the criteria we'd be looking at per se.
01:24:50.940it has again related to uh violence so we're very again going back very closely to the 2c
01:24:57.420definition we've talked about earlier so a declaration of an event that is unlawful
01:25:02.940for example you know you can have a permit for demonstration and then you know there's too many
01:25:07.740people therefore your your demonstration is outside the bounds of the permit it could be
01:25:12.060unlawful but that would not engage us so the unlawfulness in and of itself alone is not just
01:25:17.820a criteria that would be determinative for CSIS. Can I add something, and it's the last line
01:25:24.060on page two here, if I can read it. Further, CSIS will also continue to follow the evolving
01:25:30.620and dynamic situation surrounding the convoy to identify any national security concerns.
01:25:36.140That is really important to underline, is that this was a very fluid,
01:25:39.820volatile environment, and we were constantly doing our assessments. We were
01:25:47.820they were every day we were re looking at our information our investigations to ensure that
01:25:53.940we were up to our assessments so I just want to underline that it's sometimes a snapshot in time
01:25:58.880that that date when that particular brief was written but that we were also very aware that
01:26:31.780And what I'm going to do is pick up now with following on that helpful information you were able to give us about the IMVE space and how it fit in with your observations of the convoy and protest and blockade activities.
01:26:53.460I just want to run through, and this will all sound familiar, and indeed to parties who've had a chance to read the summary of the closed session, this will be similar to a series of questions that you answered there, leading up to some context that I want to bring to the questions that follow.
01:27:17.160So what I'm going to do is just ask you about your involvement in the government, in the law enforcement and other intelligence communities as you were all watching the protests and the blockades, etc. evolve.
01:27:38.220So, first of all, as the materials indicate, I think you'll agree that CSIS attended, had a representative attending and participating in the ADM NS Ops meetings, and I think we know that acronym now, so I won't bother spelling it out.
01:28:08.220and you had regular interaction with the nsia about the convoy and blockade events yes and you
01:28:15.260were a member when it was formed of the combined intelligence group that was set up so that all the
01:28:20.540intelligence collected by the various law enforcement and intelligence agencies could be
01:28:26.460shared among the parties involved in the convoy and blockade events yes and uh cesus was a member
01:28:35.660or at least had a representative at intersect meetings that a broader group of law enforcement
01:28:42.220and first responder personnel involved in major events such as the convoy posed for ottawa yes
01:28:51.820um and indeed if we if we step back to before the uh the actual formation of the combined
01:28:59.020intelligence group uh it looks from the documentation that cesus was receiving
01:29:04.220intelligence such as the Hendon reports that were generated by the OPP and other information that
01:29:13.700once they became involved the OPS was also generating with respect to intelligence on the
01:29:18.900convoy yes okay and if we could call up the again Mr. Clerk please the information sorry the
01:29:28.620the Institutional Report, all seven zeros one, and go to page 13 at about halfway down.
01:29:43.560Now, here's, I think, exactly where we were picking up, Ms. Tessier, with your comment
01:29:52.640about the dynamic nature of the events that were unfolding in front of you and putting
01:30:02.600it in context of what I was just describing about your many-faceted interrelations with
01:30:09.680the intelligence and law enforcement community.
01:30:11.540It says here, CSIS continually monitored streams of intelligence and shared information with
01:30:18.000domestic and foreign partners including through the one vision processes with the rcmp and police
01:30:24.480of jurisdiction to assess threats of serious violence in relation to the convoy and here i'm
01:30:32.080going to ask you to remember and see if you can provide for me in this open forum that your
01:30:39.520Your classified institutional report contained an actual itemization of all of the agencies, and I don't need you to be more specific than you want to be, but it was tens or dozens of agencies that you were collecting and sharing information with, correct?
01:30:57.920Yes, that's correct. We have, as was mentioned earlier, we have offices throughout Canada, and we deal with police of jurisdiction at all levels.
01:31:06.700Right. So to the extent that there was intelligence or information available in relation to potential threats to the security of Canada, as defined in the CSIS Act, it was received and considered by the service.
01:31:21.300Thank you. Now, if we can look at where you were giving input, we looked at where you were getting and sharing intelligence, where you were giving input to government.
01:31:38.180if we go to page 13 again just a little bit higher or i guess immediately above where we
01:31:43.220just were cabinet meetings uh you and was that mr vigno you were attending mostly to the sse
01:31:52.180and the irg meetings both of them mr c attended a couple as well thank you and where your role was
01:31:59.220and i uh am uh quoting here too at the end of the paragraph to provide updates on national
01:32:08.340security threats that may arise and answer questions so that was your role at those uh
01:32:43.220These commission lawyers are given way too much time
01:32:46.940for just nonsensical, extraneous questioning.
01:32:57.700Thank you. If you can go to page five, about two-thirds of the way down.
01:33:08.080And this is, just to situate you, this is a paragraph from the summary of the interview we had when we were meeting with you earlier in the year.
01:33:19.680And it reads in the first paragraph under the word, under the heading Intelligence,
01:33:23.460Mr. Vignon stated that at no point did the service assess that the protests in Ottawa or elsewhere, and there's a parenthetical definition of what that refers to, constituted a threat to the security of Canada as defined by Section 2 of the CESIS Act and that CESIS cannot investigate activity constituting lawful protest.
01:33:45.140um and i'm going to ask you to hold these uh thoughts in your in your mind but i'll just
01:33:54.800on that point you you recollect telling us that during the interview mr pignon yes i do yes and
01:34:01.020uh if we go to eight page eight of the same document about halfway down
01:35:25.520I don't think we need to call it up because you can probably recite it from
01:35:30.700heart and thus recognize it when I put it to you,
01:35:33.540that legal mandate that you're describing when you say as defined by the services legal mandate
01:35:38.980is to investigate threats to the security of canada and advise and advise the government
01:35:44.420of canada on such threats correct yes if we can go now to mr clerk wts 6079 this is the
01:35:58.900the public summary of the closed session we had on November 5th and the bottom of page
01:36:09.020five of that. And I'll read there, Mr. Vigneault explained that the advice and the assessments
01:36:25.320they would be giving to government is taken in conjunction by the decision maker with all of the
01:36:31.800other different pieces of analysis for the decision mr clerk if you can scroll down to
01:36:37.360follow with me different pieces of analysis for the decision maker to make a determination in
01:36:43.660the end if this is a threat to national security or not when cesus looks at national security in
01:36:50.220this case their assessment was that this was not a threat to national security within the
01:36:55.140confines of the CSIS Act and you remember saying that Mr. Vigneault? Yes. And then
01:37:01.380if we sticking with you Mr. Vigneault for one more over at the top of page six
01:37:08.620sorry the bottom of page six over to the top of seven Mr. Vigneault confirmed a statement from
01:37:18.800the commission's interview with CSIS and you might recognize this as the one we started out with
01:37:24.300And the interview with CSIS and ITAC to the effect that at no point did the service assess that the protests in Ottawa or elsewhere, defined as the Freedom Convoy, constituted a threat to the security of Canada under Section 2 of the CSIS Act, and that CSIS cannot, sorry, cannot investigate activity constituting lawful protest unless conducted in conjunction with a threat-related activity.
01:37:47.680And then you conclude that paragraph, Mr. Vigneault confirmed that to the extent that he was able to give input on this topic at Cabinet and IRG meetings, this was the view he expressed.
01:38:00.960And again, do you recall making those statements?
01:40:51.780And if I can just break that out a bit, if I understand what you're saying there, you have an understanding, and we might find out later in the week where you got that understanding, but I'll let you keep that as a mystery for now.
01:41:13.180You had an understanding that the Emergencies Act definition of threats to security of Canada was broader than the CSIS Act definition, correct?
01:41:21.200yes and maybe if you allow me commissioner just just don't want to um go back to the first uh
01:41:28.320first element that you uh you took me through uh mr cameron which was the uh that you know when i
01:41:34.000learned that the uh emergencies act was to be invoked uh uh you know informed myself so um this
01:41:40.880is i think is the crux of the issue so as director of cesus we are very familiar you know uh my
01:41:46.720My colleague and I, you know, we know the Act fairly well,
01:42:13.720And that's when I was assured that, you know, there was a separate understanding, you know, the confines of the CSIS Act, the same words based on legal interpretation, jurisprudence, federal court rulings, and so on.
01:42:28.020There was a very clear understanding of what those words meant in the confines of the CSIS Act.
01:42:33.500And what I was reassured by is that there was, you know, in the context of the Emergencies Act, there was to be a separate interpretation.
01:42:43.420based on the confines of that act he is trying to change his testimony starting on on the uh on
01:42:51.080that the tent i believe when we discuss that to make sure that we understand you know and how we
01:42:56.340would be um not informing but you know using the words very carefully and and very much specified
01:43:03.780you know when we were providing advice and information it was based on the csis act
01:43:08.280definition so i just wanted to maybe contextualize this a little bit so thanks for that
01:43:14.780Now, if we can go back to that sentence at the bottom of page eight, I understand.
01:43:19.960I think the words do speak for themselves, but I want to make sure I understand your sense of them, that based on your understanding that the Emergencies Act definition of that to the Security of Canada was broader than the CSIS Act.
01:43:34.920And then it says, as well as based on his opinion of everything he had seen to that point.
01:43:39.480So, if I'm understanding the way you've put those two together, that if you take a broader definition and then look more broadly, you come up with the advice you gave to the Prime Minister of your belief that it was required to invoke the Act.
01:44:00.860Now, I want to sort of insert a parenthesis or come back to an observation.
01:44:07.240Mr. Clerk, can you call up SSM NSC CAN 50216?
01:44:17.440These are IRG meeting minutes for the February 13th meeting.
01:44:24.000And at page 12, we'll find the report to government that you commissioned, Mr. Vigneault,
01:44:32.920when you learned that the government was considering the invocation of the act.
01:44:36.600Sally, I am patient, but I'm also very interested in this. It's very important that we absorb this as many of us as we can.
01:44:44.140I think it's now well understood by the commission and the parties that as you learned that the government was considering the invocation of the Emergencies Act, a concern that you had because of your understanding of the IMVE space, and feel free to join in, Ms. Tessier, if you want to add here.
01:45:03.860The concern was that the invocation of the act actually had the potential to, I think the word inflame is used, but to raise the temperature and actually increase the risk of a threat of serious violence. Is that right?
01:45:18.480Yes, it is. And this is really when, you know, we feel that it is our responsibility. A little bit like when Ms. Khan walked me through another assessment in relation to the flags. It is, we have experts, we have people inside the organizations that, you know, really well understand those dynamics.
01:45:39.880and in this context was to make sure that the government,
01:45:45.360yes, within the confine of the reflection on the vocation of the Emergencies Act,
01:45:51.060but also more broadly about what is happening in the country
01:45:57.140We felt it was important that we took that expertise within the service
01:46:00.960and we shared that more broadly with partners, with the government
01:46:07.040so that everybody had that understanding that we had at the service.
01:46:13.140So it is within that spirit, both in the context of the Emergencies Act,
01:46:17.500but also in the context of what we see, what we potentially see in Canada.
01:46:22.700Right. So if I understand the purpose of this report,
01:46:27.420it was to alert the government to a potential movement in the threat environment.
01:46:34.500And by that, I'll tell you what I'm trying to get at.
01:46:37.680You weren't by offering this assessment or deciding to do the assessment concluding that the government itself was, by invoking the Act, engaging in activities that posed a threat to the security of Canada.
01:46:52.760It was really much, you know, again, based on the expertise and understanding of the IMV milieu, is to see how some of these elements can be interpreted.
01:47:05.620And Ms. Konya asked us earlier about disinformation, misinformation, and that would be a good example of how some objective decision could be misconstrued deliberately or not.
01:47:20.960and what is the impact on potential threat activity in Canada.
01:47:24.840So that really was the spirit in which we produced that document.
01:47:28.780Right. And this document, perhaps also in the spirit of things we see in your annual reports
01:47:33.580or some of your reports to Parliament,
01:47:36.080CSIS sometimes prepares reports to government related to threats to the security of Canada
01:47:42.100that aren't actually premised on the commencement of an investigation
01:47:45.440based on reasonable grounds that the activity poses a threat,
01:47:49.400but it's simply advice to the government, a report to the government on threat-related issues, correct?
01:47:56.060Yes, essentially it's to use the expertise, the knowledge, and to try to bring a level of understanding
01:48:04.380or bring a light into very complex dynamic issues that are, in the case of IMVE, fast evolving in our country.
01:48:13.660So we try to bring that level of understanding, yes.
01:48:18.520Okay, if we can go back then, Mr. Clerk, to the public summary, that's WTS 6079, and just wrap up the chronology and indeed this examination by going to page seven of that summary.
01:48:37.660we're now at the stage where uh the act has been invoked and the the point i understand you to be
01:48:55.740making in the paragraph that begins uh mr vignon explained uh the point being that after revocation
01:49:03.500you continued to provide input both to partner agencies and to cabinet through the IRG
01:49:10.900about the evolution of the protests, the blockades, etc., the convoy.
01:49:19.840So you're continuing to give input proactively, but you weren't actually asked the question,
02:15:24.680I have some questions and I may be asking all of you at some point for your thoughts.
02:15:28.680The area that I'd like to start with is about information flow.
02:15:31.680So, Mr. Vigneault, maybe I'll start with you as the head of CSIS because you can speak to your role in advising kind of up the line.
02:15:38.680But as I understand it, and my friend is taking you through the definition of CSIS,
02:15:43.680but the mandate of CSIS is to investigate threats to the security of Canada. Is that correct?
02:15:49.680is your mic on can you try again okay yes sorry i didn't hear you that's all
02:15:57.200and part of your role is to share the appropriate information with senior decision makers in the
02:16:04.160federal public service including the national security advisor and minister of public safety
02:16:09.680is that correct that's accurate but it's also broader than that we also share information with
02:16:15.360with many other uh partners but don't we from the on the federal level that would be accurate
02:16:21.440yes and so and that's how it works we know in the federal sphere there are a number of law
02:16:26.640enforcement type relationships that would work in a similar way and that they'll collect information
02:16:32.000and they'll share it with senior level decision makers is that correct yes so such as cbsa rcmp
02:16:39.360there are a number of others yes and obviously you would agree that it's crucial that those
02:16:47.040senior level decision makers have all the information they need to make informed decisions
02:16:53.920yes i would say that that's what we endeavor to do to make sure all relevant information
02:16:58.000is available to decision makers and so when we're thinking about information flow and we think about
02:17:04.720things that can go wrong in that process there are a couple of things
02:17:08.640or a number of things but a couple of kind of main things that can go wrong
02:17:12.400in terms of what you do in advising decision makers
02:17:16.480the first may be that cesus may fail to identify certain information
02:17:22.720on potential national security threats in other words you that might just miss
02:17:26.320on the intelligence side yes i believe i testified earlier to say
02:17:30.480that we uh you know what we advise on is what we're
02:17:33.360aware of and we endeavor to make sure that we are fulfilling our investigations to the extreme
02:17:38.480degrees but we will never have the uh um the uh the hubris to say that we know everything right
02:17:44.960and of course if you don't know you can't advise right yes the second the information may be
02:17:53.040available but it may not be properly communicated up the chain that's that could happen right
02:17:57.920I think it's maybe taking a second to speak to that is that you know there is there are different
02:18:05.800levels you know Ms. Tessier's role my role are somewhat different and we have you know people
02:18:09.980involved you know at the operational level and at the regional level so I think you know there is
02:18:15.180it's clear there is a lot of information that is accumulated and there is a process of analysis
02:18:20.180and distillation of that information when it comes to our level right and it's a human process so
02:18:26.100might have some information that may come into certain offices regional offices and then it has
02:18:30.740to go up and then to be reviewed and go up again from your level to senior decision maker and
02:18:37.220whether it be by inadvertence or maybe not realizing its significance there's always a
02:18:41.700possibility that something important may be missed correct i would say it as a general statement it
02:18:47.940is a possibility everywhere not more specifically at thesis or in intelligence but i would say yes
02:18:54.420it's an accurate reality when human beings are involved that's right and that's for
02:18:58.100kind of all law federal law enforcement type agencies right i would say i would not want
02:19:04.900to speak to other law enforcement agencies but you know from from the thesis point of view we'd say
02:19:08.740that's a an accurate description of a theoretical uh issue yes and obviously sometimes you may not
02:19:15.060be aware when i say you it could be ceases it could be another law enforcement agency
02:19:19.780may not be aware of the potential significance of a certain fact and and it may just be missed
02:19:24.420I think it's again, you know, in the same vein, I would say that's accurate, yes.
02:19:29.120Okay, I would like to ask about Project Hendon briefly, and maybe Ms. Tessier, because you were kind of the lead on the actual intelligence side, as I understand, at the operational side.
02:19:39.260We do have evidence, of course, that CSIS did receive Hendon reports that went to a number of recipients, that's correct?
02:23:03.060i would say that uh to a broad this dissemination of the information to uh to people who need to
02:23:11.840know because when you have uh and the complex context and the concept of need to know is
02:23:17.580important but it's in a case like this and i think you know as we've seen in uh and we'll uh
02:23:24.280we may we may speak to that later uh cesus took a uh very um uh open approach to share a lot of
02:23:32.120our information with the maximum people possible so those who need to know
02:23:36.800specific details we endeavor to share those details with them and but the same
02:23:42.940thing with criminal investigations and national security investigations you
02:23:46.580just need to make sure to maintain the the integrity of those investigations
02:23:51.320that you know you sometimes you know will you know you'll take the the two
02:23:55.040concept of sharing as much information possible while making sure that those
02:23:59.600who need to know have the same information and that's what our experts are doing on a day-to-day
02:24:04.960basis on an ongoing basis because we don't want the third party rule to kind of get in the way of
02:24:11.440broad information sharing correct well in the case specifically of when we talk about intelligence
02:24:16.560there is a a concept called intelligence and evidence which means that if you were to use
02:24:24.000information collected by CSIS, for example, on intelligence basis, share with law enforcement,
02:24:30.240there is a process of inerring complexity for law enforcement and eventually
02:24:38.160Crown prosecutors to use that information in open court. So there are a number of rules that have
02:24:43.200been put in place, having learned over time what the pitfalls were, and Ms. Stacie referred to
02:24:49.440earlier as the One Vision process, which is an elaborate process that has been put in place
02:24:55.180between the RCMP and CSIS to make sure that we are sharing all of the information, you know,
02:25:02.520relevant in the right way to enable law enforcement. If I could address third-party
02:25:08.000rule, this service respects third-party rule, and the procedure is to request of that third-party
02:25:14.500any sharing that we think would be useful so we don't just share third-party information we always
02:25:20.760ask for permission to do so right and so as far as project tendon is concerned and you may not be
02:25:24.760aware but it had a very broad distribution list that went to all federal law enforcement related
02:25:29.600agencies and that works to break down silos fair um i don't have personal knowledge of that
02:25:37.420so uh speak to that all right and final topic is on social media we've heard a lot in this inquiry
02:25:43.620about social media anyone can go on fire up the twitter machine and you can find lots of vile
02:25:49.060content and threats and things of that nature on social media fair yes and i believe it was
02:25:55.700mentioned in your witness summary that it's very difficult to assess the intent and impact of
02:26:00.740violent online rhetoric that's fair that's fair you would agree that useful intelligence requires
02:26:08.180a lot more than simply scrolling through twitter right yes it's a much more complex than that
02:26:14.820and miss chair you spoke about this in your evidence not that long ago that it really
02:26:20.740requires a trained analyst to review what's there and on social media and pass it through an
02:26:27.780appropriate intelligent lens tradecraft as you put it before you can have a useful product is that
02:26:33.780fair? Yes. When it falls within our mandate to look at a specific threat on social media,
02:26:40.900our analysts, who are especially trained, will take a look with that tradecraft in mind.
02:26:45.260Right. And that is, in fact, what OPP did with Project Hendon, correct? They took information
02:26:49.740and they passed it through their lens and then produced it out to its partner agencies.
02:26:55.280I don't recall the exact reports. I wouldn't be able to say yes or no to that question.
02:27:00.940Okay. My last question, Commissioner, I know I'm probably up against the clock.
02:27:03.780And the point I'm trying to make here is that analyzing social media to identify risks is something that should be done by subject matter experts or those trained to do so. Is that fair?
02:27:15.480I would say that depending on what the purpose of looking at social media is, but if the purpose is to enlighten CSIS, for example, in our mandate, absolutely.
02:27:27.220and they are another level of complexity of who should have the authority,
02:27:34.140who should have the mandate to look more broadly at social media.
02:27:37.980I think it's something that we testified in our ex-parte hearing
02:29:07.800I apologize, maybe it was Mr. Guignol, the director.
02:29:09.620That was the advice you provided to Cabinet, was it not, sir?
02:29:12.180Yeah, I believe that the statement I made
02:29:14.680was related to that the analysis continued to be
02:29:19.700that there was no threat to the security of Canada.
02:29:23.020That's the concept that we'll be normally using in our vernacular.
02:29:26.500Yeah, by security of Canada, we're talking about 2C,
02:29:29.420violence associated with ideologically motivated objectives, right?
02:29:33.600Yes, very much within the confines of the CSIS Act.
02:29:36.000But Mr. Avigno, if there was a concern that,
02:29:39.660and it was also your advice that invoking the Emergencies Act
02:29:42.680could further inflame that kind of rhetoric, correct?
02:29:45.000It was our advice, our assessment, I would say more than our advice, our assessment was that given everything that we know about the dynamic nature of IMV milieu, but yes, some individuals might, you know, seize on such a government measure to further inflame the rhetoric and potentially, you know, push them to act violently.
02:30:10.280yes so there was a concern that's what I was kind of getting at is that if the if the situation or
02:30:15.280some of the rhetoric was so volatile and extreme that invoking the emergencies that could lead
02:30:19.820to some kind of violent reaction was that not a concern it's absolute concern and um and if I
02:30:26.720may add Mr. Champ I would say that the uh uh the fact that from from early in January to throughout
02:30:33.400the period in question, we mobilized our headquarters
02:30:38.920and our regional offices because we were concerned
02:31:24.720and we also know that um there were many violent uh threats against public officials
02:31:33.180in ottawa uh you cesus was aware of that yes not only federal officials but also municipal officials
02:31:41.680i don't recall who exactly but i do know overall there were threats and there continue to be
02:31:47.960increasing threats as i mentioned earlier today against elected officials right the mayor testified
02:31:53.300that there was an individual coming from New Brunswick who was arrested
02:31:56.240who had apparently firearms in his truck.
02:31:58.700We also heard evidence from a city councillor, Mathieu Fleury,
02:32:01.160who had to leave with his family from his home
02:32:03.620because people were coming to his house.
02:32:06.760Was CSIS following those kinds of threats against municipal officials?
02:32:11.060As I mentioned earlier, we maintained,
02:32:13.380our focus was on our subjects of investigation, of course,
02:32:15.820but naturally we worked very closely with our law enforcement partners,
02:32:20.380shared information and continue to assess the situation as it related to our mandate and as i
02:32:26.420described earlier in terms of how we assess the situation in order to open investigation but miss
02:32:32.400tessier just to be clear like if someone's making a threat against a public government official
02:32:36.720whether it's federal or municipal or provincial isn't that inherently falling under 2c if someone's
02:32:42.360threatening a public official because they want some type of different political uh decision or
02:32:47.100policy choice, isn't that inherently falling under 2C?
02:32:50.200As I mentioned earlier today, we've developed criteria in order to invoke 2C under the IMVE
02:32:56.600threat, because there are criminal investigations that take place, there are public order
02:33:02.100incidents that take place that are not CSIS's mandate to investigate.
02:33:06.420If I may add, Mr. Commissioner, I would just say that, as was described by Ms. Stacey and
02:33:10.660myself earlier, we're participating in all of these different groups, including Intersect
02:33:16.440and the combined intelligence group where we would be sharing information ourselves our information
02:33:21.240but also receiving information from other law enforcement in this specific case this is where
02:33:25.880you may have public safety issues versus you know a threat to the security of canada that you know
02:33:31.240might be in the same kind of dynamic environment and that this is where you know by being at the
02:33:36.120same table and exchanging that information we inform ourselves the second point is that this
02:33:41.640was a very dynamic uh threat assessment that we're going doing or throughout the this period so by
02:33:47.800all means if we had seen specific information about you know individuals wanting to engage in a way
02:33:54.440often that you know the the that flash will be more of a police investigation because of the
02:33:59.160specific threat that will be criminal nature as opposed to an individual that might want to engage
02:34:03.720in a terrorist activity these are not perfectly you know uh black and white issues and this is
02:34:09.720why we are working to exchange information very dynamically but mr vigno let's just be clear that
02:34:14.680if someone's making a threat against a public official because they're trying to influence
02:34:17.960that public official that inherently falls under 2c does it not now it may be that you don't view
02:34:22.840the threat as credible but if it was a credible threat it would inherently fall under 2c would it
02:34:28.040not i think that if you uh that's why we we've took a lot of uh of of pain to uh in uh inside
02:34:35.720the service and working with partners to better understand how the imv phenomenon was interacting
02:34:41.880with the uh with the css champ is trying to tell you know a description of how we go through the
02:34:49.320process of understanding this what will be the sphere of css responsibility what would be the
02:34:54.280sphere of the law enforcement responsibility and that's why i'm the i'm saying is that this is not
02:35:00.200black and white it's dynamic and this is why people talk to each other on an ongoing basis
02:35:04.840Sir, please, I'd like to give you lots of, normally I'd like to give witnesses full-time to answer, but I only have a limited time.
02:35:10.160I'm just trying to get an answer because I believe I've asked it a few times here.
02:35:13.040So you waste time by badgering like that?
02:35:14.820If someone is threatening a public official because they want to influence that public official to take some policy choice, does that not inherently fall under 2C, yes or no?
02:35:22.800Each case is looked on a case-by-case basis, and it would not be, you know, a default proposition.
02:35:27.680so someone's threatening to kill a mayor or a premier because they want them to drop a public
02:35:34.340health measure that's not trying to get rid of all context whatsoever that's what he's doing
02:35:40.180and um and his arrogance i can just add i think as we've walked through there are a number of
02:35:48.000other criteria that look at him what an ass to be the ceases act there is you know uh the the
02:35:53.620The testimony that Ms. Stacey gave, responding to Ms. Khan's questions about that placement earlier,
02:36:00.900I think is how we are understanding and how we are exercising our authority.
02:36:05.940So I understand, Mr. Champ, you're looking for something specific,
02:36:09.220but this is, we've described very well, I think, the process by which we're looking at these issues.
02:36:14.260And it's not because someone would only write online that they want to kill someone,
02:36:19.420that it would automatically be a threat.
02:36:23.000yes sir i understand that and we're reading a lot of time just to get an easy answer to what
02:36:27.240i thought was an easy question i thought your response was going to be with all due respect
02:36:30.220that yes a threat to a public official to influence that public official would fall
02:36:34.380under 2c but in most cases we have not used these uh threats as credible or valid because
02:36:40.100you know it's just online i think in one of the cc's documents i saw shit posting or something
02:36:44.320like that um but if you viewed a threat to a public official as credible would it not fall
02:36:49.320under 2c if we have and we have done that in the past we have no answers please sir
02:36:55.260okay well fine i'll move on thank you so um now did cesus look into any of those threats
02:37:02.700in the context of the convoy protest any nexus to the convoy protest
02:37:07.060since uh probably since the the mid-january until you know and we continue to today we continue to
02:40:54.280So Section 12 requires that CSIS investigate
02:40:57.720wherever there are reasonable grounds to suspect there's a threat to the security of canada as
02:41:02.520defined in section two right yes okay and so that just require it doesn't require certainty it
02:41:08.360doesn't require reasonable grounds to believe it's reasonable it's just reasonable suspicion right
02:41:13.000to initiate investigations yes yeah okay uh and that's an assessment that ccist does day in and
02:41:19.080day out yes okay uh now as someone whose father was monitored by your organization for over 10
02:41:27.160years until it was determined an investigation wasn't actually necessary my personal experience
02:41:32.360is that it seems that your organization is very thorough is that a fair assessment that CSIS is
02:41:37.480rigorous in executing its duties um i'm not sure uh the context of your uh the the previous uh
02:41:47.720the premise of your question but i would say that we try to be thorough in what we do yes
02:41:53.080Right, because, I mean, a big reason that your agency's members have to be thorough
02:41:58.640is that if CSIS incorrectly determines something is not a threat
02:42:02.160and then chooses not to investigate, that could lead to harms down the road, right?
02:42:07.140I would say that investigating threats to the security of Canada is a very complex issue.
02:42:15.060Missing, you know, signs, missing information and having incorrect assessment
02:42:20.120is indeed something that we are very careful about.
02:42:23.760And as a learning organization, we try to make sure that we learn from the past
02:42:28.280and that we are trying to come with the best possible assessment on an ongoing basis.
02:42:33.740Right. So you said something earlier, and I was just trying to write it down as you said it,
02:42:37.900but something to the effect that CSIS mobilized whatever resources it could
02:42:42.500in order to try and understand the Freedom Convoy protest. Is that right?
02:42:47.000Something similar to that, I would say. It's accurate, yes.
02:42:50.120Okay. So you've talked a bit about the potential for a lone wolf threat. Now, am I correct in thinking that that's not based off of particular intelligence? It's more of a conclusion from general principles about this kind of an event?
02:43:03.900This is based on expert analysis by CSIS, by ITAC and other organizations, that to understand the dynamic environment in where violent rhetoric can push individuals to act.
02:43:21.100And unfortunately, we've seen a number of people who were not on the radar of anyone who were consuming this type of information and indeed, you know, a committed act of terrorism or extreme violence.
02:43:34.960So we are, unfortunately, it is a very complex, dynamic environment, and we have to be careful about people who would be very quickly moved from just being a recipient and consumer of information to someone who would radicalize to violence.
02:43:53.180Okay, so you were just asked questions about the potential that people were present at the protests that CSIS was already monitoring.
02:44:04.960But basically, your organization was keeping tabs on them, right?
02:44:11.040So, as we've said in our public testimony, we were aware of, we already had subject of investigations who we assessed were interested in the protest.
02:44:22.020We used different techniques to assure ourselves of their activities.
02:44:27.340And we also continue to look for other individuals that might be recruited or might be approached or might want to radicalize throughout the events in question, obviously respecting the mandate of CSIS.
02:44:43.460Okay, now, but just to go back to the general point, the idea is that this is a large gathering.
02:44:48.460It could be used as an opportunity by someone to commit to engage in some sort of a threat.
02:44:56.080But that kind of threat is present at other big events like a G7 protest, right?
02:45:04.640Actually, unfortunately, with the dynamic of what we see IMVE, the threat is persistent.
02:45:10.500This is why the national terrorism threat level is set at medium.
02:45:14.160It means that, you know, today here in Canada, there are individuals with the capability and intention to engage in an act of terrorism.
02:45:21.460And so I would say, yes, those larger events, but also more broadly, it is a dynamic that exists throughout our society, irrespective of those large events as well.
02:45:31.500And what I would add to that is, as I testified earlier today, part of the ideology in IMVE is anti-authority.
02:45:39.480So they exploit that type of feeling amongst people for their own to try to recruit people to a more extremist ideology, their own more extreme ideology.
02:46:48.580We've heard a bit about how the definition for threats to the security of Canada doesn't include, it doesn't include protests.
02:46:58.540Am I right in thinking that the basic idea here is that if there's a protest where one of the four factors aren't present, you don't investigate.
02:47:06.240And if there's a protest where the four factors are present, you would investigate, right?
02:47:12.540If we look at the document, the paragraph under D, under 2D, does not include lawful advocacy, protest, or dissent unless carried on in conjunction with any of the activities cited above.
02:47:24.120Right. So the fact that it's a protest isn't a barrier to an investigation if one of these things is present.
02:47:30.800I would say, generally speaking, the service stays away from investigating protests.
02:47:35.580We recognize it's a democratic right in Canada, so we don't investigate protests.
02:47:39.660What this means is if, an example perhaps I can give, if we had information that a terrorist group was going to pretend to use an event in order to conduct a terrorist activity, well, of course, that would be of interest to ceases.
02:47:56.800But we are very, very conscious and aware of balancing the rights of individuals in a democracy like Canada with our own mandate and our more intrusive techniques.
02:48:06.540okay uh mr vinho um so looking uh let's look at uh we can look at a first uh based on the
02:48:15.000services assessment there was no espionage or sabotage associated with the protest correct
02:48:19.360that's correct so uh this 2a definition wasn't met
02:48:25.280no okay and uh there was no foreign interference
02:48:31.040um we have uh i think it's in our uh our uh testimony that we have said that we investigated
02:48:40.720for interference in relation to the event including foreign funding and we do not see
02:48:45.520these activities amounting to a threat to secretive canada so 2b wasn't that yeah thank you
02:48:52.640uh and uh there wasn't any serious violence associated with the protests
02:48:57.240um i would not say that or a credible threat of serious violence um that's not what we're
02:49:05.420looking at we're looking at you know how these events the or individuals you know might engage
02:49:10.540in activities that meet our threshold uh that um this is where i was answering questions earlier
02:49:16.000about you know distinction between what what law enforcement would be doing in terms of serious
02:49:19.860violence versus what we would do uh as a css under the confine of the css act okay i'll be
02:49:25.520more specific then there were no activities within or relating to Canada directed toward
02:49:29.520or in support of the threat or use of acts of serious violence against persons or property
02:49:33.620for the purpose of achieving a political religious or ideological objective within Canada correct
02:49:38.640yes and we've testified to that earlier uh I figure so so t2c was you see was not met okay
02:49:44.800and um just quickly there was no uh there's no credible threat to overthrowing our established
02:49:50.880system of government i can say that we have not investigated under 2d okay thank you because
02:49:57.840there's not only was there no section 2 threat present but there wasn't even reasonable grounds
02:50:01.680to suspect a section 2 threat was present well i we uh we are on the record to say that we already
02:50:08.880had individuals who had met the the 2c threshold you know that's where subjective investigation
02:50:14.160that were uh involved and that so we had legitimate grounds to be uh to be looking at
02:50:21.440what was happening as we've said based on our expertise we have seen unfortunately events like
02:50:27.200that where individuals were radicalized and mobilized to violence extremely quickly so that's
02:50:33.200why uh we continue to expand those resources throughout the uh those events to make sure that
02:50:39.040we again did not miss something if i could just have an indulgence to sort of hit the last point
02:50:44.000i've been working up to i'll try to be very quick yeah although you could have skipped a b c d it's
02:50:50.800been testified too many times that it wasn't met but go ahead okay thank you you got the commissioner
02:50:56.400even saying it so that's awesome somebody clip that out clip it respect individuals but there
02:51:02.400the protest itself did not pose a section two threat to the security of canada what we've
02:51:07.120testified to is that we did not uh made a determination at the event itself uh we uh
02:51:13.040and i think it's it's part of our uh testimony yes okay and yet you still advised the prime
02:51:18.160minister to invoke the emergencies act yes i did and you did that not because you thought that there
02:51:25.040was the the protest posed a threat to the security of canada as defined in section two of the cses
02:51:29.920act but because you were reassured that threat to the security of canada had a different meaning
02:51:34.800under the in the context of the emergencies act i think uh my testimony was uh was in part that but
02:51:40.800it was also based on all of the other information that you know i became aware of during uh all of
02:51:46.480the interdepartmental meetings and cabinet meetings i participated in so it was i was
02:51:51.440provided uh that opinion was provided if you want as a national security advisor as opposed to a the
02:51:59.280director of CSIS specifically. Okay, and when you say that information
02:52:03.200that you had received, you're referring to your earlier comment that you were
02:52:07.360reassured that that definition had a broader
02:52:10.800meaning under the Emergencies Act? I was referring to that but also more
02:52:14.240specifically to other events in Canada, events you know in
02:52:18.320Ottawa that you know convinced me to say that you know the
02:52:23.440powers under the Act would be necessary. Okay, so just my final question.
02:52:27.680better get out the very last question uh the um this determination then that the emergencies act
02:52:36.560standard is a the definition is broader under the emergencies act than with respect to under the
02:52:41.840cses act uh that was not the product of you reading the emergencies act and developing
02:52:46.880your own assessment that was something that was advice that you had received that's correct
02:52:51.040okay thank you very much and thank you for the indulgence mr commissioner thank you
02:56:50.520So you said in your initial witness statement that you felt it was important to communicate at the IRG and to Cabinet that under CSIS's analysis, there wasn't a Section 2 threat.
02:57:05.680What I wanted to be very clear, Mr. Commissioner, is that because it was a very dynamic environment, a lot of moving parts, as we say,
02:57:15.280and I wanted people to be clear about how CSIS we were analyzing the situation and so people
02:57:22.960were talking about using different words in the media everywhere and we just wanted to bring a
02:57:28.260level of clarity so that's why we said our assessment was very dynamic and we continued
02:57:33.720to assess but throughout that period we wanted to make sure that people did not misinterpret
02:57:39.260based on everything that you know was being mentioned that CSIS we saw a threat to national
02:57:43.500security based on our act so that was the purpose of us being very deliberate about that approach
02:57:48.620okay i guess i i mean you understand that the purpose of one of the purposes of this commission
02:57:54.260is to assess whether uh the act was properly invoked um sorry can you just answer audibly yes
02:58:01.420thank you um and i guess i'm wondering why you didn't think it was relevant when you met with
02:58:07.500commission council in august to note that you had in fact advised the prime minister that you
02:58:12.780believed the act should be invoked? I think there's probably two reasons. I would say one is that
02:58:20.020very simply the question was not asked and so just you know when you go through the
02:58:24.620the dynamic you know process of the of the interview so it did not was not specifically
02:58:30.680asked but there was also at that point you know a lack of clarity in my head about what was still
02:58:36.080cabinet confidence and what would be what i was able to to say as a part as a participant in
02:58:42.400cabinet meetings so uh that was further clarified uh throughout that uh that period and that's why
02:58:49.840i think again you you um you mentioned you know the the the nature of this commission um um as a
02:58:58.480senior official in government you know we're never allowed to speak about cabinet confidences
02:59:02.880We're never allowed in the case of CSIS to produce, you know, a number of the information that has been, you know, put in front of the, in public for commission and for Canadians to see normally that will not be public.
02:59:14.540So, it just needed to ascertain, you know, what were the limits of what we're able to do.
02:59:18.920And when I was, it was clarified with me that indeed I was able to speak to that, I did.
02:59:23.740okay but when you met with commission council in august you you felt that you didn't feel that
02:59:31.500cabinet confidence prevented you from advising that you had advised cabinet and the irg that
02:59:37.560you did not believe there was a threat within the meaning of the cesus act that had been
02:59:42.700clarified with me yes okay because i would put to you that those two pieces of information are
02:59:49.000really two sides of the same coin that if one is not subject to cabinet confidentiality the other
02:59:54.360one also would not be um i understand uh that that analysis but i would say that the uh just
03:00:02.620refer back to what i said uh we never discussed cabinet confidences and you know the the information
03:00:08.460the way that the um uh the information was communicated to witnesses in terms of what
03:00:14.500would be possible to disclose and not in terms of candid confidences just became clearer
03:00:20.120with the passage of time, you know, between, you know, August and our ex-party interview.
03:00:27.460Okay, thank you. I don't know if you had an opportunity to review the testimony given by
03:00:33.040Ms. Thomas, the National Security and Intelligence Advisor.
03:00:36.580I briefly saw some of the key extract, yes.
03:00:40.040Okay. So one of the things that Ms. Thomas said was that the CSIS definition of threats to the security of Canada is quite narrow. Do you agree with that, that it's a narrow definition?
03:00:51.980I would say that the CESIS Act was enacted in 1984, and I think that the world has evolved considerably since then.
03:01:04.460And that looking at the threat environment today is indeed, you know, requires probably a new look, modernizing, you know, a view of this.
03:01:15.160And the second thing is that we also, through jurisprudence, through federal court rulings,
03:01:23.240commission of inquiries, and review bodies who have access to all of our information,
03:01:28.320that understanding of the act was very much more clarified and so very, with a lot of
03:01:37.780specificity, if you want, in many aspects.
03:01:40.360And so between, you know, experts at CSIS and the OJ Council, I think, you know, there is a very specific interpretation of the Act, which is, in this specific case of the Commission, different than the Emergencies Act.
03:01:53.840okay so um and and i mean you understand of course why and i think you've alluded to this
03:02:00.560in other statements that you've made here today and in your witness statement that um there should
03:02:05.740be a high threshold before our intelligence services start uh surveilling or targeting
03:02:10.880canadians would you agree with that yes i do agree okay um the holding or expressing of unpopular
03:02:18.880political views should not be enough to engage CSIS's mandate?
03:02:48.880And do you understand why? Now, I know you take the view that the definition and the Emergencies Act is broader, but would you agree that the threshold to invoke the use of the Emergencies Act should also be a high one?
03:03:06.940I would say that with anything, any exercise of power by the state, you know, there is a high threshold.
03:03:13.280I'm not a legal expert to say, you know, what should be the threshold of the Emergencies Act.
03:03:19.400Okay, but you understand that the Emergencies Act allows the government to rule by executive order for a period of time?
03:03:28.280And that the public order emergency section of the Emergencies Act allows those orders to let the government assume control of public utilities, for example?
03:19:48.600So in this email, and again, it's January 27th, 2022 at 4.21 p.m., you're aware that the protesters in Ottawa hadn't really even arrived at that time, right?
03:20:04.120Sorry, on the 27th specifically, I do not have those specific chronological details with me. I'm sorry.
03:20:14.040So there it says to ML, that's Mary Liz, I wanted to reach out on the current issue-led situation for the convoy.
03:20:24.080Given how this is transitioning to a whole of government coordination response, I feel like emergency preparedness.
03:20:29.100We are a well-positioned office to provide more of a high-level messaging going forward.
03:20:34.060Public safety, of course, has a major role to play when it comes to the RCMP, CSIS, and IMVE threats.
03:20:41.500but we have a helpful perspective on the whole government coordination and collaboration
03:20:46.280with other levels of government these are the lines we worked up earlier today any thoughts
03:20:52.640on if this is a helpful approach convoy emergency preparedness and it says our government recognizes
03:20:58.320and respects that everyone in canada has the right to safe and peaceful protest
03:21:02.060threatening acts of violence and inciting hatred as we have seen from a select few in recent days
03:21:08.400is unacceptable. It does not reflect the views of the majority of Canadians. We condemn all such
03:21:13.600hateful and violent rhetoric in the strongest terms. As is common with any significant gathering
03:21:20.440with potential impacts of government operations, such as the annual Canada Day celebration,
03:21:25.760law enforcement and security agencies across all levels of government are engaged in coordinating
03:21:29.840to ensure a safe event. Now, do you recognize the phrases and the sentences in the first
03:21:38.500three bullet points? Have you heard them somewhere before? I do not have a specific
03:21:44.060recollection of these words. You guys know why he's doing this, right?
03:21:47.740Do you recall the Prime Minister's speech on January 31st? Do you recall him when he was
03:21:54.720in isolation he came out and gave a speech on january 31st about the protest do you remember
03:22:01.960that i do not remember the specific date i remember having the prime minister speaking you
03:22:07.000know to these this has nothing to do with thesis isolation that's what he said okay so he said
03:22:12.680can you agree with me that writing out a narrative like this prior to the protest even arriving
03:22:21.060And then on the January 31st, despite the fact, and this is in evidence, there had been no real actual violence in Ottawa.
03:22:42.000As an intelligence officer, as an intelligence agency, that there's a narrative being built for an emergency before the purported thing creating the emergency has even taken place.
03:22:58.680Mr. Commissioner, what I can say is that, as we've testified, you know, the interdepartmental community got together to understand what was happening, share information, make sure that each of the organization would be able to discharge their mandate appropriately.
03:23:14.400And so at that point, you know, of course we are, as I testified, you know, we're keeping aware of what's happening around us, but we are very much focused on making sure that we are discharging our investigative responsibilities and not opine on other issues.
03:23:33.420Okay, and let me ask you this. The biggest concern, it appeared, was over the first weekend of the protest, there was the appearances of Confederate flags and Nazi flags and Nazi symbols, right? Did you investigate those issues at all?
03:23:54.600mr commissioner we testified earlier that we have written a an intelligence assessment about
03:24:02.360the presence of flags and some of the meaning of those flags and so i can go back to our analysis
03:24:09.320what we've described then i'd be happy to if you want to refer me back to the document speak to
03:24:14.280that okay if mr cook if you could just go back to my examination aid this shouldn't be an issue
03:24:20.520uh it's a paragraph 16 just scroll right down to it
03:24:26.360sorry mr commissioner just for your information this is the document that the doj has an outstanding
03:24:31.000objection over and if we can go to paragraph 16. before putting it up on the screen so uh mr
03:24:38.920commissioner we've already objected to this document being put up i understand but i'm going
03:24:44.520to ask for a ruling on the commissioner to put put this page to them so let's deal with that
03:24:48.680if we can so if we can put up uh page 16 again and what is page 16 or paragraph 16 is just the
03:24:56.560two pictures of the first um post in time at 10 13 a.m on january 28 2022 of the spotting of a
03:25:06.540confederate flag and so and there's also a license plate number if you'd like me to go through and
03:25:12.120bring up all of the documents i'm just trying to get this done quicker sir if i but you're way over
03:25:17.280time already i understand but i'm not this is so important sir that i need more time to get through
03:25:23.920this area it is extraordinarily important well so far asking a bunch of questions
03:25:30.060right to people who have no knowledge of the documents i understand i understand so it's not
03:25:35.780i'm trying to explain something and i know you're frustrated and but that's not good use of your
03:25:43.260time if you and reading into the record that exchange of of texts was done days ago and again
03:25:52.800that's not a good use so i'm i'm just i i'm trying to be patient and i understand you want to get
03:26:01.640something done so let's try and work together to figure out how we can navigate this in a
03:26:09.380appropriate way just do it so you want to put up a picture of a license plate
03:26:15.680that's in relativity yes okay and i think your co-counsel has the number for that the relativity
03:26:24.740number so we can i'm guessing yes mr commissioner from my understanding my my uh mr mr miller would
03:26:33.300like to first put up a tweet of Aerial Truster that shows the image of the license and then
03:26:42.080the license. We'll call up the number HRF. So PoE dot HRF six zeros two one. Okay. So I think
03:26:53.000that's okay, Mr. McKinnon. We're just putting up the picture for what it's worth. We'll see what it
03:26:57.420what it is we we've gone to page 16 uh with respect and it's not just a picture but we've
03:27:05.480moved on mr mckinnon so so if it's just the picture that's fine okay so that's that's what
03:27:12.020i think we're doing so i'm just just let's try and get through this do it then so sir this is
03:27:18.200my first understanding that uh this was the first post in time that i can find uh with respect to
03:27:27.040when a confederate flag or a nazi flag appeared and it's at 10 13 a.m on january 28th of 2022
03:27:36.100and it's posted by ariel troaster do you know who she is i do not she's you're not aware that she's
03:27:42.900the new counselor that replaced counselor mckinney i do not know who the individual is all right and
03:27:50.820And so then if I could just bring up the closer photo with respect to the license plate, please.
03:27:58.120And that actually is at page 43 of the examination book of authorities.
03:28:03.000That'll just be easier for you, Mr. Clerk.
03:28:07.340So your co-counsel, I think, has the reference.
03:28:10.600Yes, Mr. Commissioner, the reference is poe.hrf6029.
03:28:20.820Sheila Gunn-Reed from Rebel News there.
03:28:30.260So, and it's been clear, so online, that license plate number is BL, then it's got a crown in the middle, is three, and I can literally tell you what it is, and people were trying to look it up.
03:35:04.300And so I'd ask you to take my word for it that it was part of the same legislative package to get those two statutes in alignment.
03:35:14.380And then in 2019, there is a major initiative on the part of CSIS is the development of a definition and framework for ideologically motivated violent extremism.
03:35:31.560i believe that the work started before that but i think it was it was maybe put in uh in higher
03:35:39.000gear i had uh in my first public uh speech that i had made after becoming director in 2018
03:35:47.400that speech spoke to to the rise of of this and i believe i used the word the the concept of imv
03:35:53.400then but i could it's around 2018 2019 indeed that it was that work was uh solidify and and
03:36:00.920And the concepts were developed to try to understand, characterize better this new phenomenon dynamic we were seeing in society.
03:36:08.920Good. And, sir, and just so we're clear, I believe that the first time CSIS reported out on this development and its thinking was in the 2019 annual report.
03:36:24.480OK, good. And and it's and is it true in your in your interview summary, you stated that the that IMVE does not mirror the criminal code definition of terrorism?
03:36:40.460I don't recall seeing that. You'd have to show me the document.
03:36:43.160Sure. So could we pull up witness summary 60, please? And could we go to the bottom of page three?
03:37:50.660And so is it reasonable to infer from your evidence there that the definition of IMVE is broader than their criminal code definition of terrorism?
03:38:06.120I'm not sure I would say it's broader, but it's for different purposes for sure.
03:38:10.580And I think I am, I'm familiar, very familiar with the attack at the Quebec City mosque.
03:38:18.620And this example and other unfortunate examples is what foresees us to say, this dynamic, we need to better understand what is happening.
03:38:28.900So that work to define, better define IMV, the four quadrants and so on, was in relation to that.
03:38:35.720But it's also very important in this comment when I say that it was different than the criminal code,
03:38:42.200is that you could meet a definition of threat to security of Canada under the CISA sector.
03:38:48.300You could meet the sociological definition of terrorist activity, which I believe that Alexandre Bissonnette was indeed engaged in terrorist activity, but that may not transfer the crown charging someone for a terrorist defense.
03:39:05.080And I think it is a very important notion that indeed has been, you know, very troubling for many in the country, including in this specific case, the Muslim community in Canada.
03:39:15.580So does it follow, sir, from what you've just said, that IMVE or the notion of IMVE gives CSIS broader tools to assess and respond to extremism than might be available under the criminal code?
03:39:31.800I think by statute, CSIS has been built to be separate and distinct from law enforcement and from the criminal code in the sense that our threshold for investigations would be different than the police.
03:39:44.340our techniques might be also different so i think you know it is uh clearly uh separate the two
03:39:50.640and and and and sorry ma'am did you no no i i think that's a very uh accurate okay and and
03:39:58.920would you say that it's um that CSIS over the last number of years has developed a lot of expertise
03:40:04.820on imve i would i would say yes uh you know because unfortunately there there are more
03:40:12.900cases in Canada. There are more cases internationally. And we have worked very closely with a number
03:40:19.440of partners at the federal, provincial, municipal level and international partners. And as my
03:40:25.000colleague testified, that conceptual framework has been adopted by a couple of international
03:40:29.740partners as well. And the analysis is done in the first instance by skilled intelligence
03:40:34.140professionals? Yes, that would be accurate. And you're a learning organization, so you're always
03:40:39.520trying to improve how you analyze IMV? That would be accurate, yes. Okay, and so would it be fair to
03:40:46.960say if you can now look back to 2018 or 2019 and think about the world before then and the world
03:40:55.340after in terms of CSIS's function, do you think that the adoption of IMV has broadened
03:41:01.500the scope of the activity CSIS investigates under 2C? I would not say they broaden. I would
03:41:09.500say that to help our our investigators or analysts to better understand of how
03:41:16.040the CSIS Act applied what would be the because again we make a very significant
03:41:22.120distinction in what we call awful but lawful speech and protected you know by
03:41:27.740the Charter versus activities that would be that would be you know
03:41:32.960defined under the CSIS Act and so I think it's more it's not a broadening
03:41:37.900It's more a fine-tuning of the understanding, developing analytical tools to make sure that not only do we not go over the law,
03:41:46.780but that we are indeed investigating the threats to Canada as mandated by Parliament.
03:41:53.860But you would agree that IMVE now occupies 50% or more of CSIS resources?