top of page

My Personal Playbook for Designing Stealth

Writer: karthi keyan
karthi keyan
Aug 15
21 min read

Systems, levels, enemies. In roughly the order I do them.


I trained as an architect before I started making games, which for a long time I treated as a slightly embarrassing detour. Four years learning to draw buildings nobody was going to let me build. It stopped being embarrassing the first time I had to explain to my fellow level designer why his room didn't work(career risking move, i know) . He'd built a beautiful arena. It had four entrances, a mezzanine that saw everything, and a floor that made no sound anywhere. He'd designed a stage. we needed a building.


That's the difference the whole playbook turns on. An architect designs for people who will do things you didn't anticipate, in a structure that has to hold up regardless. A stage designer designs for the show. Stealth is architecture. Almost everything else in games is stagecraft.


What follows is what I actually do, in the order I actually do it, with the mistakes marked.


---

First, the thing the whole playbook is for

You can't tune a system until you know what it's producing. So before any of the rules, here's my theory of what a stealth game is actually selling, because I think most of the genre's decline comes from getting this wrong.


The reward in stealth is not the clean run. It's the margin.


Watch enough footage and it's obvious. Nobody clips the perfect ghost. Nobody has ever posted a fifteen-minute video captioned "he never saw me once." What gets clipped is the guard turning around half a second after you break line of sight. The body you dragged behind a crate while his mate walked past the crate. The moment the search timer ran out with you standing in a cupboard listening to two men decide it was nothing.


The product is the near miss. Everything in the playbook exists to manufacture near misses and then let the player survive them.


---

Why the perfect run feels flat

This is the part designers resist because it sounds like an argument against their own game.


Action pays constantly and legibly. Enemy dies, room clears, meter fills, hundred percent, ding. Stealth's reward for a flawless run is that nothing happened. No debris. No counter. No clearance. You walk out of a building you walked into and the building is identical.


Asad Anjum's diagnosis is the sharpest version of this and it's the argument I've never won in a room containing a monetisation lead: stealth's central pleasure is structurally invisible to positive reinforcement loops. There's nothing to reward because success is defined as absence.


So teams bolt rewards on. Score screens. Ghost bonuses. Achievement stickers for no-kill runs. It half-works, and it half-works in a way that makes the underlying problem worse, because now the player is optimising for the scoreboard, and the scoreboard pays for the flawless run, and the flawless run is the version with no near misses in it. You have paid the player to have a worse time.


The fix isn't a better scoreboard. It's accepting that the reward has to come from the middle of the spectrum, not the top of it.


---

The edge is where the game is

Here's the shape of it, and it's why the staircase matters so much more than the cone.

At full concealment there's no tension, you're safe, you're just walking. At full detection there's no stealth, you're in a firefight or a loading screen. Everything worth having happens in the narrow band between: the moment he's unsure.


That unsure step is the single most valuable state in the genre and most implementations rush through it. It's where the player is being looked at and hasn't been seen. It's where the plan is still alive but dying. It's the only state that produces the specific, unmistakable feeling that people play these games for not fear exactly, something more like being caught out in a lie and talking your way through it.


Design consequence: stretch step two. Give the "he's investigating, he hasn't confirmed" state real duration and real legibility. Let the player watch him decide. Most of my tuning time on any stealth project goes into that one window, and it's always the window producers want to shorten because it looks like the player standing still. And a stretched step two is worthless if the player can't perceive it, half of that tuning is feedback work, not AI work.


Follow and this is the one that changes level design to "you should be seen constantly and confirmed rarely." A player who has never triggered step two hasn't played your game. If your telemetry shows a level where most players complete without a single investigation, that level is too easy in the specific sense that it never sold anyone the product.


---

Failure is content, and reloading destroys it

The second half of the theory follows from the first. If the reward is the near miss, then the near miss has to be survivable, or players will refuse to have one.


This is the real function of the spectrum of failure. It isn't a difficulty accommodation. It's the delivery mechanism for the entire reward, because a near miss you can't survive isn't a near miss and it's just a death with better timing.


And this is why save-scumming is a design failure rather than a player failure. Nobody quickloads for fun. Players quickload when the game has told them that the interesting state is a mistake. If detection means failure, then the only rational play is to erase every detection, and the player will dutifully erase precisely the moments you built the game to produce.


Bethesda spent a paragraph of the Daggerfall manual begging people not to reload, telling them straight out that they'd never see the best parts of the game if they undid every mistake. Completely futile, and it was always going to be, because you cannot ask for this in a manual. You have to build somewhere for it to happen and then make that place more attractive than the reload.


Three things actually discourage save-scumming, and none of them is scolding:


  • A recoverable middle. If losing position is survivable, the reload is no longer the obviously correct move. This is most of the work.


  • Legible fairness. People reload when they feel cheated. Deterministic facings, fair warning, no blind lethal choices, no spawns behind cleared ground, every one of those rules from later in this playbook is really a save-scum prevention measure. A player who believes the game is honest will accept a bad outcome as their own. A player who suspects the dice will reload until the dice agree.


  • Momentum. Make the recovery more interesting than the retry. The MGSV chain works partly because each step is more exciting than the step before it. Reloading takes you back to the boring part.


I'd add a fourth if you can get it past your team - make the reload cost something. Not punitively. Just enough friction that the player has to notice they're choosing it.


---

The proof is that no two testers play it the same way

The last piece of the theory is the one I use to tell whether any of the above landed, and it's the only metric I fully trust.


Sit ten testers down. If you get ten meaningfully different routes, the level works. If you get ten of the same route, it doesn't and importantly, it doesn't matter how much they enjoyed it, because what they enjoyed was executing your solution rather than authoring their own.


The reason this is the right test: ownership is where the reward actually lands. The near miss only means something if the plan that nearly failed was yours. Nobody tells a story about executing an intended solution correctly. They tell stories about the thing they improvised when the intended solution fell apart, which is why the two most common sentences in a good stealth playtest are "I didn't know if that would work" and "oh, that's not what I meant to do."


So the loop of the whole theory, in one line:

"Legible space and honest enemies let the player form a plan; a wide middle band lets the plan half-fail; surviving the half-failure is the reward; and the reason it's a reward is that the plan was theirs."

Everything below is in service of that sentence.


---x---

Part One: Systems


1. Write the sentence before you write anything else


One line, on the first page of the doc, and everything gets checked against it:


The player knows where the enemies are. The enemies don't know where the player is. Losing that is costly and recoverable.


That's the engine. Everything else, the cones, the vents, the gadget tree, the crouch button is furniture. Furniture is cheap and you can buy it in a sprint. The engine you have to build, and if you don't build it you ship something that looks like stealth in a trailer and evaporates in the hand.


I keep the sentence visible because feature requests arrive constantly and most of them are furniture. "Can we add a takedown animation" sure, that's furniture, low risk. "Can we add see-through-walls" that's an attack on the engine and we need a different conversation.


---

2. The spectrum of failure is the system. Design it first.


Tom Francis's term, and the most useful single concept in the genre. The failure spectrum is the range of states between total success and total failure, and its width is the most consequential number in your game. It's the pipe the entire reward comes down.


Too narrow and you get the reload loop. Alarm sounds, mission fails, quickload. Early Splinter Cell did this deliberately and it produces a real tension, but it's tension of the fingers, not the mind, and you can watch it kill a session live: the moment a player starts quicksaving every four seconds, your stealth is dead and they're playing a different game using your assets.


Too wide and success stops being distinguishable from failure, and then there's no reason to hide. This is the modern disease. Widen it far enough smoke bomb, vent, reset, no cost and you've built a game where being caught is a minor scheduling inconvenience.


The reference implementation is Metal Gear Solid V, and I make people walk the chain link by link because every link is a decision somebody had to argue for:


- Guard sees something. Doesn't shoot. Comes to look.

- Confirms you. Game drops into a slow-motion window, one chance to remove him.

- You miss. He now has to physically call it in and you can stop him doing that.

- Call goes out. You can still run, still break line of sight, still get back to black.

- Or fight. Or call a helicopter and stop pretending it's espionage.


None of that is forgiveness. Every link costs you position. The point is that none of them ends the sentence.


How I set the width: I write out the chain in the doc as an explicit ladder, one line per step, before any of it exists. Then for each step I write what it costs the player. If a step has no cost, delete it that's slack, and slack is what makes stealth toothless. If a step has no exit, that's a wall, and walls are what make people quickload.


The failure I made: on one project I designed a lovely five-step chain and then let the encounter designers tune the guards independently, and by ship the whole ladder collapsed into steps one and five. Seen, then dead. The spectrum isn't a feature you build once. It's a thing you defend in every review for two years.


---

3. Determinism, with one exception


Bauer's rule and I've come round to it entirely: randomise idle animations, randomise barks, randomise what he's grumbling about. Never randomise where he's facing.


The argument is that randomisation in a stealth setup makes skill irrelevant in both directions at once. Good players eat unlucky dice, bad players sail through on lucky ones, and nobody feels anything either way. His secondary rule is the one people forget: if you must randomise, give the player enough reaction time to respond to the outcome. Randomisation without reaction time is a low blow.


The exception I allow: randomising timing within a fixed route, in small amounts, late in the game. Same path, same facings, ±10% on the pause durations. It stops stopwatch play without breaking the mental model. Anything more and people start save-scumming, and the moment they save-scum you've lost the observe-plan-execute loop entirely.


---

4. Gadgets edit the room. They don't resolve it.


The test I use, and it's caught bad tools three times:


Can you describe what the gadget does to the room, without mentioning the enemy?


Water arrow: removes light from a space. Whistle: relocates a person. Blink: relocates you. Drone: extends your sightline past a wall. All of those edit the architecture and hand it back to you still unsolved. That's what a stealth tool is.


If you can only describe it in terms of what it does to a guard "it kills him quietly," "it stuns him for eight seconds" it's a weapon with a silencer on it, and it will resolve encounters rather than reshape them.


Two failure modes, both Bauer's, both real:


Gadget-dependency. A section that requires the drone. If the player can arrive without it, the section is either impossible or it detonates. My rule in every feature doc now: every stealth setup completable with the tools the player can never not have. Gadgets are an extra layer of pleasure, never a key.


Vanilla stealth. The inverse, and it's got the better name. You build a game full of toys and then design levels that refuse them. If your game has drones and your maps are carpeted in no-fly zones, why did you build drones. The fix is administrative and boring: a support sheet, maintained from pre-production, tracking which levels exercise which tools, so that across the whole game everything gets a stage. Not every level. The set.


---

5. Scarcity is what makes a gadget a decision


A kit doesn't create tension by existing. It creates tension by running out.


This is the whole gap between Styx and Dishonored, and I say that as someone who'd rather play Dishonored. Both are a man with powers sneaking around a building. One straps your resources so hard that spending anything is a genuine choice; the other gives you enough that the kit stops being an economy and becomes a menu. Dishonored is a better game and a worse stealth game, and both of those things are true because of the same decision.


Set your resource economy at the same time as the failure spectrum. They're the same dial viewed from two angles: how much can this cost me, and how much can I afford.


---

6. The prosthetics, and why I fight them


Listening mode, tagging, scanning tools that change what you know rather than what's true.


These attack the engine rather than serving it. They exist because players want control, and stealth is built on withholding information, so the two are structurally at war. Listening mode ends the war by surrendering: hear through walls, see everyone, get a god's-eye view you did nothing to earn, and the section plays itself.


Tagging is the least-bad compromise, because at minimum you have to scout to earn the intel, and earning it is itself a stealth activity. If I have to ship a prosthetic, it's tagging, with a range limit and a decay timer.


But be clear-eyed about the trap: the prosthetic creates the demand for the prosthetic. Once a generation expects to see enemies through concrete, a game that withholds it doesn't read as tense it reads as broken. You end up shipping it not because it's good but because its absence is a review score.


---

Part Two: Enemies


7. Build the staircase, not the switch


Detection is a staircase. He glimpses something. He's unsure. He's sure. Each step buys the player a window, and the windows are the game. Metal Gear had this in 1987 and it is still the correct answer.


Metal Gear 2 added the back half in 1990 and people still skip it: guards who stay alert after losing you, keep searching, and eventually stand down. Alarm as a process with a duration, not a flag. The stand-down is not a mercy it's the mechanism that makes the recovery half of the spectrum legible. If the player can't perceive the search ending, they can't plan around it, so they just wait, and waiting isn't play.


---

8. Make the AI predictable, legible, and slightly stupid on purpose


Three properties, in priority order:


  • Predictable. The player must be able to build a mental model that holds. This is more important than sophistication. A crude cone in a good room outperforms a beautiful perception model in a bad one, every time.


  • Legible.The guard has to broadcast his state. Posture, barks, pace, head movement. If the player can't tell step two from step three, the staircase might as well be a switch.


  • Slightly stupid on purpose, but never visibly. Good AI cheats and hides it. Bad AI cheats and you can see the seams the man studying a wall, the corpse forgotten in thirty seconds, the patrol that stops existing when you're not looking. The cheat should always be in the player's favour and always be deniable.


The one I add:

  • enemies with somewhere to be. A guard whose only purpose is to catch you is a turret with legs. A guard who's walking to a post, having a smoke, complaining about his shift that guard is a person with a schedule you can learn, and learning it is the game.


---

9. Ban the linear patrol


Specific and unglamorous and it fixes more sessions than anything else on this list.


The quick-turner: guard walks a straight line back and forth, player follows for the takedown, guard hits the end of his path, snaps 180, and lights him up. The player did nothing wrong. He read the room correctly and got punished for it.


Fix: no linear paths. Circuits with at least three or four points, so that when the guard turns he isn't already looking at you and there's a beat to disengage. If the geometry forces a linear path, slow the turn down. That's the entire fix, it costs nothing, and I have watched it ship broken in games with eight-figure budgets.


---

10. Fair warning, always


If there's a dog behind the right-hand door, the player hears it barking.


Then, if they open it anyway, that's on them and crucially, they know it's on them, and they'll laugh instead of reloading in disgust. A blind choice where one option is death isn't difficulty, it's just mean, and worse than mean, it teaches the player to stop choosing. A player who has stopped choosing is a player running the safe route with the sound off.


---

11. Spawns are a promise


Never spawn an enemy where the player has already cleared, unless the fiction has explained the reinforcement route and the player could have seen it coming. Reinforcements arriving through a door you established two minutes ago: fine, good, tense. Reinforcements materialising in a room you swept: you've just told the player that observation doesn't pay, and observation is the only thing you were selling.


---

Part Three: Levels


12. Lock the metrics before you draw a line


Architecture is calibrated to a body. Door heights, stair risers, ceiling clearances the whole discipline is sized to a person, and you only notice when it's violated.


Same for us, and the mistake I see most in junior work is drawing the space before locking the numbers. How high can they jump. How far can they see. How fast do they walk crouched. How wide is the cone, how long is the investigation, how far does sound carry through a wall.


Every one of those is a dimension in your building. Change crouch speed by fifteen percent in month eight and every room you've built has silently retuned, and nobody will tell you, and the levels will just start feeling slightly wrong.


Styx is the instructive case because they changed the body. The goblin is half a man's height, deliberately, so the weakness reads in silhouette. But the second-order effect is what it does to the architecture: a pot becomes a room, a grate becomes a door, and all the void space a human-scaled building doesn't consider habitable turns into circulation the guards can't follow. One decision about a character model rewrote every level in the game for free.


---

13. Design where they stand to think


I used to think about cover. Now I think about where the player stands to think, which is a completely different question and a much better one.


The loop is observe, plan, execute, react. The observation phase needs somewhere safe to stand. No refuge, no observation; no observation, no plan, only reaction which is a shooter with a slower walk speed.


But refuge with too much prospect is worse. The vantage point problem: elevation, cover, and clean lines into the space, all in one position. Give a player that and they'll disassemble the encounter from a chair, and you'll watch the recording and see the exact second your level died it's when their mouse stops moving.


Bauer's fixes are all architectural, which is why I like them. Glass in front, so they can look but not shoot. Strip the cover so standing there is expensive. Restrict which enemies are reachable from it, if the geometry has an honest reason. And the one I actually use: break the space so no single position reads the whole floor. Four small prospects instead of one big one means the player runs the loop four times instead of once. Four times the game out of the same square footage and you get to stage your spawns for free, because the player can never audit your population.


---

14. Count your routes on paper


Before I open the editor. Top-down, trace every viable line, count them.


Three to five main routes. Two or three at ground level, roughly the same again above and below where the geometry allows, plus small connectors so people can hop between mains that's where the improvisation lives.


Two routes means it's a corridor with a detour. Eleven means I've built a park.


The failure to avoid is the avoidance path: one route nothing ever contests. It might be long, it might be clever, doesn't matter once anyone finds it the level is over, and someone always finds it, and then it's on YouTube. The minimum bar is that every path gets seen by somebody at some point. Not every corner swept. The mains contested, occasionally, enough that you have to stop and wait and think.


---

15. Three doors


Dana Nightingale's rule from the Clockwork Mansion, mentioned almost in passing: never more than three ways in and out of a room.


It sounds like fire code. It's the routing problem from the opposite side. A room with five exits is a room where a guard can't be cornered and a player can't be trapped, which means nothing that happens in it can carry weight. Space creates stakes by removing options but it has to remove the right number. One exit is a queue.


----

16. Design in section


Everyone works in plan because plan is what the editor shows you. Stealth lives in section the vertical cut that shows what's above and below.


Verticality isn't traversal flavour, it's the third axis of the sightline problem, and it's how players buy time. Vertical layout plus mobility gets them high; high gives perspective; perspective gives time; time is what makes deliberate play possible at all. Take the roof off and you've deleted the planning phase without touching a single guard.


It also means stealth levels can be small, which is the best news in the discipline. Steve Lee's Half-Life 2 map fifteen days, made to get hired at Arkane packs about ten minutes of play into a square you could sprint across in thirty seconds, because you cross it four times at three heights. Dense folded circulation beats sprawl, costs less, and screenshots better. I have never once regretted making a stealth space smaller.


---

17. Make the floor a system


The best purely architectural idea the genre ever had is from 1998 and almost nobody has copied it.


Thief made building materials into mechanics. Carpet swallows footsteps, run all you like. Tile is a permanent liability no matter how slowly Garrett moves, tile makes noise, always. The floor isn't scenery with a texture on it, it's a system with behaviour, and you route through a mansion partly by reading what it's built from. Then water arrows, which put out torches and let you pour darkness into a room. You don't find shadow. You manufacture it.


Set that against tall grass. Grass is a material with no properties. Nothing to exploit, nothing to ruin, nothing to read, and standing in it makes you invisible to a man eight feet away. Architecture reduced to a boolean.


The honest warning: material-as-system is an audio and materials dependency that has to be locked early, and it doesn't demo. You can't show it in a vertical slice. You can only feel it in hour three. Budget for it in pre-production or don't attempt it.


---

18. Show the door before the key


Older than the genre. Doom's coloured locks work because you meet the lock first, and the lock writes the objective.


Lee does it three times in that Half-Life map shows you the gravity gun through a doorway you can't reach in the first minute, and the memory is what turns a later route into a discovery instead of a corridor. It sounds obvious right up until you build a genuinely non-linear level, hand out the key on route B, and watch someone open the door on route A with no idea they'd solved anything.


---

Part Four: Feedback


None of the above matters if the player can't read it. A perfectly tuned staircase that the player can't perceive is a switch. A fair level that reads as unfair gets reloaded exactly as hard as an unfair one. Feedback isn't polish in this genre it's the layer that converts your systems into something a person can plan against, and it's where I've seen more good stealth die than anywhere else.



19. Tell them about themselves, not about the AI


The best feedback decision the genre ever made is Thie*'s light gem, and it's usually described wrongly. It doesn't tell you what the guards can see. It tells you how visible you are. Small difference, enormous consequence: it makes the player think of themselves as an object in the world with properties, rather than trying to reverse-engineer somebody's perception code.


The alternative lineage is the Metal Gear Solid radar, which is genuinely the most legible detection interface anyone has shipped and which the series then spent twenty years walking back out of embarrassment, because it tells you about *them*. Both work. But the self-directed version scales better, survives the removal of the HUD, and doesn't collapse into a prosthetic.


The rule I hold to: at any moment, the player should be able to answer "how exposed am I right now" without guessing. If they can't, they're not making decisions, they're gambling, and gamblers reload.


---

20. Sound is invisible and you have to fix that


The hardest feedback problem in stealth, and most teams never solve it.


The player can hear their own footsteps. What they cannot hear is how far those footsteps travelled. So they get caught by a noise they made and had no way to evaluate, and it feels like the game cheated even when it didn't. This is the number one source of the "that's bullshit" reaction in playtests, in my experience not vision, sound.


Mark of the Ninja solved it and everyone should have copied it: draw the sound. Expanding rings, visible radius, in the world. Suddenly noise is a spatial object with a shape, exactly like a vision cone, and the player can plan against it. It's cartoonish, it's completely unrealistic, and it's the single best piece of feedback design in the genre.


If you can't draw it, you have to compensate elsewhere: surface materials the player can see and predict (Thief's tile and carpet do double duty here they're a mechanic and they're the feedback for the mechanic), enemy barks that name the cause, and a much more generous investigation window.


---

21. Every detection must be explainable in one sentence


My hard test, applied to footage:


When the player gets caught, can they say why in one sentence, immediately, without checking?


"He heard me on the tile." "I broke cover too early." "I forgot about the second one on the balcony." Those are fine. That's a player learning.


"...I don't know?" That's the failure, and it's fatal, because a player who can't attribute a loss will attribute it to you. And once they've decided the game is arbitrary, they stop planning and start reloading, and your entire spectrum of failure becomes decorative.


Enemy barks are the cheapest fix and most games waste them on personality. Make them diagnostic: name the cause out loud. "Door's open." "Footprints." "Someone's been through here." That's not flavour, it's a receipt. It tells the player which of their decisions is being punished, which means the next attempt is a corrected plan rather than a coin flip.


### 22. Feedback the recovery, not just the loss


Almost every team builds excellent feedback for being detected stinger, music swell, the guard shouting and then nothing at all for the way back down.


This is backwards, given what the reward actually is. If the near miss survived is the product, then the moment the search ends is the moment you're selling, and it needs to be as loud and as clear as the moment it started. The player has to know they got away with it, or they'll sit in the cupboard for another ninety seconds, unsure, bored, and eventually they'll reload just to be certain.


Concretely: the music has to come back down, audibly. The guards have to say something that means "stand down" in plain language. The alert UI, if you have one, has to visibly drain rather than just vanish. And ideally the world shows a trace the body's still where you left it, the door's still open, the guard walks his route a bit more warily now. That's the receipt for the story that just happened.


Prefer diegetic wherever you can afford it. HUD feedback is precise and cheap and it works, but it also floats free of the fiction and it's one short step from becoming a prosthetic. A guard whose posture and pace tell you he's suspicious is doing the same job as an alert meter and costs you nothing in immersion. The light gem is the honest middle: an abstraction, but one attached to your own body rather than to the enemy's mind.


---

Part Five: Verification


23. Watch strangers play, and listen to what they say out loud


The most useful thing I do, and it isn't for the bugs.


You play your own level so many times that you go myopic, and then you defend a setup nobody outside the building can beat while insisting it's obvious. Bauer is blunt that you shouldn't let your team dismiss playtest results and call the testers idiots. I have been the person calling the testers idiots. I was wrong every time.


Streams beat telemetry here, and specifically because streamers talk. They narrate the plan before they execute it. That's free intentionality data and there's nothing else like it.


- "Right up the pipe, wait for the smoker to turn, in through the window." Your affordances landed.

- "I dunno, let's try this." They landed nothing.


And no heatmap will ever tell you which of those happened, because the path looks identical either way.


The other thing I take from a stream session is the divergence count. Ten testers, ten routes, and I'll ship it. Ten testers, one route, and it doesn't matter how much they smiled they executed my solution, they didn't author theirs, and the near miss they had wasn't really theirs to have.


---

24. The one question


When someone pitches me a stealth feature, I ask one thing, and it's never about the AI:


If the player is spotted, what do they do next?


"Reload." No engine. The genre isn't in the building.


"Kill everyone, it's fine." No engine either. The stealth is a costume.


A chain he investigates, you get a window, he calls it in, you can stop him, and if it all goes wrong you can still crawl back into the dark and start over then it's alive, and everything else on this list is just work.


---

Twenty-four items, and honestly most of them collapse into three: build the ladder, break the sightlines, watch someone else play it.

The rest is what you say in meetings to defend those three.And all three exist to manufacture one thing a man walking past the crate you're behind, and then walking on.


Architects have a phrase for the thing I'm circling that a building's plan is a hypothesis about how people will move, and the building is the test. Stealth levels are the only game spaces I've worked on where that's literally true. Everywhere else you're building a stage and the show is the point.


Here the building is the show. Which is why it's slow, and expensive, and why so few people are still doing it.

Comments


bottom of page