risk-nexus accepted the offer to match their convention rather than grow a second one, and published it: 14d critical/high, 30d medium, 60d low, nothing auto-closing on staleness alone. Their preference — point warden route gaps at those windows and the two registers agree without a shared mechanism — is better than a joint tool. blocker_stale_days() now maps lane risk onto those windows. A flat 14 would have been wrong in both directions: too aggressive for a low-risk pointer, and it treated an admin PAT lane the same as one. ungraded takes the shortest window, not the longest. ADR-0007 makes an absent grade a defect and ADR-0008 makes a grade cover the whole path, so a lane nobody graded is the one whose blocker deserves least trust. Encoding that as 60 days would have been the fail-open default this repo already fixed once. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| playbooks | ||
| AccessManagementDirective.md | ||
| AccessRouting.md | ||
| ActorInventoryPatterns.md | ||
| AuditTrail.md | ||
| CertCommandInterface.md | ||
| CredentialRouting.md | ||
| InterHubBootstrapAccessLane.md | ||
| NetKingdomSecurityMap.md | ||
| OpenBaoSshEngineChecklist.md | ||
| OperatorAccessAssist.md | ||
| OpsWardenConfig.md | ||
| OpsWardenMemory.md | ||
| PolicyGatedSigning.md | ||
| WorkloadSecurityPosture.md | ||