Each agent that reaches the decision gate (a suspicious attachment / link prompt) makes a binary choice — open it (risky) or decline (safe) — sampled from a logistic behavioral model driven by four security-UX "nudges" from behavioral-economics decision architecture (Thaler & Sunstein):
p(risky) = σ( b0
− wF · friction
− wS · salience
+ wD · default_risky
+ wP · social_proof )
σ(z) = 1 / (1 + e^(−z))
- Friction — an extra confirmation step before opening reduces risky uptake (loss of momentum / System-2 engagement).
- Warning salience — a visually prominent warning (color, icon, size) suppresses risky choices via attention capture.
- Default option — whichever action requires zero clicks (open vs decline) is disproportionately chosen — the well-documented default effect.
- Social-proof pressure — a claim like "94% of colleagues opened this" pushes choices toward the risky action, illustrating how attacker-side social engineering can hijack the same lever defenders use.
Decision latency is modeled as increasing with friction (more steps = more time) plus gate-vs-decision travel time. Every agent is an independent Bernoulli trial with probability p computed live from the current slider state — this is the same class of model security-UX teams use to A/B test phishing-warning and consent-dialog designs before shipping them.
This 2D build is a genuine top-down reimplementation of the same x/z flow field the 3D original uses (agents only ever move in a ground plane; the 3D version's vertical axis is a cosmetic bob) — drag to pan the flow view and scroll/pinch to zoom, exactly like orbiting the 3D camera. Two extra analytics panels — a live logistic response-curve plot and a decision-latency histogram — make the same math legible without a 3D renderer.