policy-nexus/build/methods/risk-severity/v1/index.html
tegwick c1b60f322e
All checks were successful
Build and publish policy-nexus image / build-and-push (push) Successful in 1m10s
feat: publish Risk Nexus findings and methods
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 01:56:46 +02:00

256 lines
26 KiB
HTML

<!doctype html>
<html lang="en"><meta charset="utf-8">
<meta name="policy-source-revision" content="c5517c754bd84b0ebf47878ba0f26df0ecb3b4a4">
<meta name="policy-source-digest" content="f064c591aeef9425bbfbd5fa2aae659abb0ef83b8586848300077f41dd4ffaab">
<title>Severity</title>
<style>
:root{
--paper:#EDEEF0; --surface:#F6F7F8; --surface-2:#E4E6E9;
--ink:#171D24; --ink-2:#4A5561; --ink-3:#737E8A;
--rule:#D3D7DC; --rule-strong:#B6BCC3;
--brass:#8A6A2E; --brass-soft:#EFE5CD; --brass-line:#C9AE74;
--clay:#8A3A2C; --clay-soft:#F2DFDA;
--l0:#DCE0E2; --l1:#B9C4C7; --l2:#8CA1A6; --l3:#567D84; --l4:#23555E;
--chip-fg:#F6F7F8;
--font-display:ui-sans-serif,system-ui,-apple-system,"Segoe UI",Roboto,"Helvetica Neue",sans-serif;
--font-body:"Iowan Old Style","Palatino Linotype",Palatino,Georgia,serif;
--font-mono:ui-monospace,"SF Mono","Cascadia Code",Menlo,Consolas,monospace;
--measure:66ch;
}
@media (prefers-color-scheme:dark){
:root:not([data-theme="light"]){
--paper:#12161A; --surface:#191E24; --surface-2:#222831;
--ink:#E6E9EC; --ink-2:#A3ADB7; --ink-3:#78838E;
--rule:#2A3138; --rule-strong:#3B444D;
--brass:#C9A45C; --brass-soft:#33290F; --brass-line:#6B5426;
--clay:#D08A76; --clay-soft:#3A211B;
--l0:#262C32; --l1:#35424A; --l2:#4A626B; --l3:#6A939D; --l4:#97C4CD;
--chip-fg:#12161A;
}
}
:root[data-theme="dark"]{
--paper:#12161A; --surface:#191E24; --surface-2:#222831;
--ink:#E6E9EC; --ink-2:#A3ADB7; --ink-3:#78838E;
--rule:#2A3138; --rule-strong:#3B444D;
--brass:#C9A45C; --brass-soft:#33290F; --brass-line:#6B5426;
--clay:#D08A76; --clay-soft:#3A211B;
--l0:#262C32; --l1:#35424A; --l2:#4A626B; --l3:#6A939D; --l4:#97C4CD;
--chip-fg:#12161A;
}
*{box-sizing:border-box}
body{
margin:0; background:var(--paper); color:var(--ink);
font-family:var(--font-body); font-size:17px; line-height:1.62;
-webkit-font-smoothing:antialiased;
}
.wrap{max-width:1180px;margin:0 auto;padding:0 24px 96px}
.layout{display:grid;grid-template-columns:180px minmax(0,1fr);gap:56px;align-items:start}
@media (max-width:960px){.layout{grid-template-columns:1fr;gap:0}.rail{display:none}}
/* ---------- rail ---------- */
.rail{position:sticky;top:28px;padding-top:8px;font-family:var(--font-display);font-size:12px;line-height:1.5}
.rail ol{list-style:none;margin:0;padding:0;display:flex;flex-direction:column;gap:7px}
.rail a{color:var(--ink-3);text-decoration:none;display:flex;gap:9px}
.rail a:hover,.rail a:focus-visible{color:var(--brass)}
.rail .n{font-family:var(--font-mono);font-size:10px;color:var(--rule-strong);min-width:16px;padding-top:1px}
.rail .grp{margin-top:14px;font-size:9.5px;letter-spacing:.14em;text-transform:uppercase;color:var(--rule-strong)}
/* ---------- header ---------- */
header{padding:64px 0 40px;border-bottom:2px solid var(--ink);margin-bottom:44px}
.eyebrow{font-family:var(--font-mono);font-size:11.5px;letter-spacing:.13em;text-transform:uppercase;color:var(--ink-3);display:flex;flex-wrap:wrap;gap:14px;margin-bottom:22px}
.eyebrow .stat{color:var(--clay)}
h1{font-family:var(--font-display);font-weight:800;letter-spacing:-.035em;line-height:.94;font-size:clamp(46px,9vw,92px);margin:0 0 6px;text-wrap:balance}
.sub{font-family:var(--font-display);font-weight:500;font-size:clamp(16px,2.4vw,21px);letter-spacing:-.01em;color:var(--ink-2);margin:0 0 30px;max-width:34ch;line-height:1.3}
.metagrid{display:grid;grid-template-columns:repeat(auto-fit,minmax(180px,1fr));gap:20px 28px;border-top:1px solid var(--rule);padding-top:20px}
.metagrid dt{font-family:var(--font-mono);font-size:10px;letter-spacing:.13em;text-transform:uppercase;color:var(--ink-3);margin-bottom:5px}
.metagrid dd{margin:0;font-family:var(--font-display);font-size:13.5px;line-height:1.45;color:var(--ink)}
/* ---------- typography ---------- */
section{margin-bottom:60px;scroll-margin-top:24px}
h2{font-family:var(--font-display);font-weight:750;letter-spacing:-.022em;font-size:clamp(24px,3.4vw,31px);line-height:1.12;margin:0 0 18px;text-wrap:balance;display:flex;gap:14px;align-items:baseline}
h2 .sn{font-family:var(--font-mono);font-size:12px;font-weight:400;color:var(--brass);letter-spacing:.06em;flex:none;padding-top:2px}
h3{font-family:var(--font-display);font-weight:700;font-size:16px;letter-spacing:-.008em;margin:34px 0 10px;color:var(--ink)}
p{margin:0 0 15px;max-width:var(--measure)}
ul,ol{max-width:var(--measure);margin:0 0 15px;padding-left:20px}
li{margin-bottom:7px}
strong{font-weight:600}
em{font-style:italic}
code{font-family:var(--font-mono);font-size:.855em;background:var(--surface-2);padding:1px 5px;border-radius:2px}
a{color:var(--brass)}
.lede{font-size:19px;line-height:1.55;color:var(--ink-2);max-width:60ch}
/* ---------- devices ---------- */
.callout{border-left:3px solid var(--brass);background:var(--brass-soft);padding:18px 22px;margin:0 0 24px;max-width:var(--measure)}
.callout p:last-child{margin-bottom:0}
.callout .lbl{font-family:var(--font-mono);font-size:10px;letter-spacing:.13em;text-transform:uppercase;color:var(--brass);display:block;margin-bottom:8px}
.rule-quote{border-top:2px solid var(--ink);border-bottom:2px solid var(--ink);padding:26px 0;margin:28px 0;max-width:var(--measure)}
.rule-quote p{font-family:var(--font-display);font-weight:600;font-size:19px;line-height:1.38;letter-spacing:-.014em;margin:0;text-wrap:balance}
.hard{border-left:3px solid var(--clay);background:var(--clay-soft);padding:18px 22px;margin:0 0 24px;max-width:var(--measure)}
.hard .lbl{font-family:var(--font-mono);font-size:10px;letter-spacing:.13em;text-transform:uppercase;color:var(--clay);display:block;margin-bottom:8px}
.hard p:last-child{margin-bottom:0}
.dec{font-family:var(--font-mono);font-size:10.5px;letter-spacing:.08em;color:var(--brass);text-transform:uppercase}
.vec{font-family:var(--font-mono);font-size:.9em;font-weight:600;background:var(--surface-2);padding:2px 7px;border-radius:2px;white-space:nowrap;letter-spacing:.04em}
/* ---------- tables ---------- */
.scroll{overflow-x:auto;margin:0 0 24px;-webkit-overflow-scrolling:touch}
table{border-collapse:collapse;width:100%;min-width:520px;font-family:var(--font-display);font-size:13.5px;line-height:1.45}
th{text-align:left;font-family:var(--font-mono);font-size:9.5px;letter-spacing:.13em;text-transform:uppercase;color:var(--ink-3);font-weight:400;padding:0 16px 8px 0;border-bottom:1px solid var(--rule-strong);vertical-align:bottom}
td{padding:11px 16px 11px 0;border-bottom:1px solid var(--rule);vertical-align:top;color:var(--ink-2)}
td:first-child{color:var(--ink);font-weight:600}
tbody tr:last-child td{border-bottom:none}
.lvl{font-family:var(--font-mono);font-weight:600;font-size:12px;letter-spacing:.04em;color:var(--ink)}
/* ---------- ladders ---------- */
.breakout{margin:34px 0 40px}
.bhead{display:flex;justify-content:space-between;align-items:baseline;gap:20px;border-bottom:1px solid var(--rule-strong);padding-bottom:9px;margin-bottom:22px;flex-wrap:wrap}
.bhead h3{margin:0;font-size:13px;letter-spacing:.1em;text-transform:uppercase;font-family:var(--font-mono);font-weight:400;color:var(--ink-3)}
.bhead .note{font-family:var(--font-display);font-size:12.5px;color:var(--ink-3)}
.ladders{display:grid;gap:26px}
.ladder{display:grid;grid-template-columns:126px minmax(0,1fr);gap:18px;align-items:start}
@media (max-width:700px){.ladder{grid-template-columns:1fr;gap:10px}}
.ladder .pname{font-family:var(--font-display);font-weight:700;font-size:14px;letter-spacing:-.01em;padding-top:2px}
.ladder .pname span{display:block;font-family:var(--font-mono);font-size:10px;font-weight:400;letter-spacing:.1em;text-transform:uppercase;color:var(--ink-3);margin-top:3px}
.rungs{display:grid;gap:3px;grid-template-columns:repeat(5,minmax(0,1fr))}
@media (max-width:700px){.rungs{grid-template-columns:repeat(2,minmax(0,1fr))}}
.rung{padding:9px 10px 11px;background:var(--surface);border-top:4px solid var(--l0);min-width:0}
.rung.r1{border-top-color:var(--l1)} .rung.r2{border-top-color:var(--l2)}
.rung.r3{border-top-color:var(--l3)} .rung.r4{border-top-color:var(--l4)}
.rung .code{font-family:var(--font-mono);font-size:11px;font-weight:600;letter-spacing:.06em;color:var(--ink);display:block;margin-bottom:4px}
.rung .txt{font-family:var(--font-display);font-size:11.5px;line-height:1.34;color:var(--ink-2);display:block}
.rung.na{opacity:.42}
/* ---------- matrix ---------- */
.matrix-shell{display:grid;grid-template-columns:auto minmax(0,1fr);gap:12px;align-items:stretch;margin-bottom:14px}
.ylab{writing-mode:vertical-rl;transform:rotate(180deg);font-family:var(--font-mono);font-size:9.5px;letter-spacing:.14em;text-transform:uppercase;color:var(--ink-3);text-align:center;padding-bottom:22px}
.mgrid{display:grid;grid-template-columns:34px repeat(5,minmax(0,1fr));gap:3px}
.mcell{background:var(--surface);min-height:60px;padding:6px;display:flex;flex-direction:column;justify-content:flex-end;gap:4px;min-width:0}
.mcell.tint1{background:color-mix(in srgb,var(--l1) 26%,var(--surface))}
.mcell.tint2{background:color-mix(in srgb,var(--l2) 26%,var(--surface))}
.mcell.tint3{background:color-mix(in srgb,var(--l3) 24%,var(--surface))}
.mcell.tint4{background:color-mix(in srgb,var(--l4) 22%,var(--surface))}
.mcell.void{background:repeating-linear-gradient(135deg,transparent,transparent 5px,var(--rule) 5px,var(--rule) 6px);opacity:.55}
.rlab,.clab{font-family:var(--font-mono);font-size:10px;font-weight:600;letter-spacing:.05em;color:var(--ink-3);display:flex;align-items:center;justify-content:center}
.rlab{min-height:60px}
.clab{padding-top:7px;min-height:22px}
.pin{font-family:var(--font-mono);font-size:9.5px;font-weight:600;letter-spacing:.02em;background:var(--ink);color:var(--paper);padding:2px 5px;border-radius:2px;line-height:1.3;display:block;overflow:hidden;text-overflow:ellipsis;white-space:nowrap}
.pin.ghost{background:transparent;color:var(--ink-2);border:1px dashed var(--rule-strong)}
.mnote{display:flex;gap:22px;flex-wrap:wrap;font-family:var(--font-display);font-size:12px;color:var(--ink-3);padding-top:6px}
.mnote .k{display:flex;align-items:center;gap:7px}
.sw{width:13px;height:13px;flex:none;background:var(--ink)}
.sw.g{background:transparent;border:1px dashed var(--rule-strong)}
.sw.v{background:repeating-linear-gradient(135deg,transparent,transparent 4px,var(--rule) 4px,var(--rule) 5px);border:1px solid var(--rule)}
@media (max-width:640px){
.mgrid{grid-template-columns:28px repeat(5,minmax(0,1fr))}
.mcell{min-height:52px;padding:4px}
.pin{font-size:8px;padding:1px 3px}
.rlab{min-height:52px}
}
/* ---------- methodology ---------- */
.verbs{display:grid;grid-template-columns:repeat(auto-fit,minmax(210px,1fr));gap:2px;background:var(--rule);border:1px solid var(--rule)}
.verb{background:var(--surface);padding:18px 18px 20px}
.verb h4{font-family:var(--font-display);font-weight:750;font-size:15px;margin:0 0 7px;letter-spacing:-.01em}
.verb p{font-family:var(--font-display);font-size:12.5px;line-height:1.46;color:var(--ink-2);margin:0;max-width:none}
.verb .step{font-family:var(--font-mono);font-size:9.5px;letter-spacing:.13em;color:var(--brass);display:block;margin-bottom:9px}
/* ---------- questions ---------- */
.qs{display:flex;flex-direction:column;gap:0;border-top:1px solid var(--rule-strong)}
.q{display:grid;grid-template-columns:34px minmax(0,1fr) 170px;gap:18px;padding:16px 0;border-bottom:1px solid var(--rule);align-items:start}
@media (max-width:760px){.q{grid-template-columns:28px minmax(0,1fr);gap:12px}.q .owner{grid-column:2}}
.q .qn{font-family:var(--font-mono);font-size:11px;color:var(--brass);padding-top:3px}
.q .qt{font-family:var(--font-display);font-size:14px;line-height:1.48;color:var(--ink-2)}
.q .qt b{color:var(--ink);font-weight:700;display:block;margin-bottom:2px;font-size:14.5px}
.owner{font-family:var(--font-mono);font-size:10px;letter-spacing:.05em;color:var(--ink-3);padding-top:4px}
.owner .tag{display:inline-block;border:1px solid var(--rule-strong);padding:2px 7px;border-radius:2px}
.owner .tag.need{border-color:var(--clay);color:var(--clay)}
/* ---------- misc ---------- */
.numbers{font-family:var(--font-mono);font-size:12.5px;line-height:1.85;background:var(--surface);border-left:3px solid var(--l3);padding:16px 20px;margin:0 0 22px;overflow-x:auto;max-width:var(--measure)}
.numbers .v{color:var(--ink);font-weight:600}
.numbers .k{color:var(--ink-3)}
pre{font-family:var(--font-mono);font-size:12.5px;line-height:1.68;background:var(--surface);border-left:3px solid var(--rule-strong);padding:16px 20px;overflow-x:auto;margin:0 0 22px;max-width:var(--measure);color:var(--ink-2)}
.alt{border-bottom:1px solid var(--rule);padding:14px 0;max-width:var(--measure)}
.alt:last-of-type{border-bottom:none}
.alt b{font-family:var(--font-display);font-size:14px;display:block;margin-bottom:3px}
.alt p{font-size:14.5px;margin:0;color:var(--ink-2)}
.alt .verdict{font-family:var(--font-mono);font-size:10px;letter-spacing:.1em;text-transform:uppercase;color:var(--clay)}
footer{border-top:2px solid var(--ink);margin-top:20px;padding-top:22px;font-family:var(--font-mono);font-size:11px;letter-spacing:.06em;color:var(--ink-3);display:flex;justify-content:space-between;gap:20px;flex-wrap:wrap}
.tm td,.tm th{text-align:center}
.tm td:first-child,.tm th:first-child{text-align:left}
.yes{color:var(--l4);font-weight:700}
.no{color:var(--clay);font-weight:700}
.kind{font-family:var(--font-mono);font-size:9px;letter-spacing:.09em;text-transform:uppercase;padding:2px 6px;border-radius:2px;white-space:nowrap;border:1px solid var(--rule-strong);color:var(--ink-3)}
.kind.adv{border-color:var(--clay);color:var(--clay)}
.routes{display:grid;grid-template-columns:repeat(auto-fit,minmax(240px,1fr));gap:2px;background:var(--rule);border:1px solid var(--rule);margin:0 0 22px}
.route{background:var(--surface);padding:16px 18px}
.route h4{font-family:var(--font-display);font-weight:750;font-size:14px;margin:0 0 6px}
.route p{font-family:var(--font-display);font-size:12.5px;line-height:1.45;color:var(--ink-2);margin:0;max-width:none}
.route .tag{font-family:var(--font-mono);font-size:9px;letter-spacing:.1em;text-transform:uppercase;color:var(--brass);display:block;margin-bottom:8px}
a:focus-visible,.rail a:focus-visible{outline:2px solid var(--brass);outline-offset:3px}
@media (prefers-reduced-motion:reduce){*{animation:none!important;transition:none!important}}
</style>
<div class="wrap"><header><div class="eyebrow"><span>RISK-METHOD-SEVERITY</span> <span class="stat">adopted · adopted-1</span> <span>risk-nexus</span> <span>reviewed 2026-08-20</span><span>generated from canonical source — do not edit</span></div><h1>Severity</h1><p class="sub">Source: <code>risk-nexus · docs/method/severity.md · c5517c754bd84b0ebf47878ba0f26df0ecb3b4a4</code></p><p class="sub">Review due: 2027-02-20</p></header><div class="layout"><nav class="rail" aria-label="Sections"><ol><li><a href="#the-two-axes"><span class="n">·</span>The two axes</a></li><li><a href="#the-grid"><span class="n">·</span>The grid</a></li><li><a href="#the-fidelity-modifier"><span class="n">·</span>The fidelity modifier</a></li><li><a href="#which-state-is-scored"><span class="n">·</span>Which state is scored</a></li><li><a href="#build-mode"><span class="n">·</span>Build mode</a></li><li><a href="#non-adversarial-findings"><span class="n">·</span>Non-adversarial findings</a></li><li><a href="#live-incidents"><span class="n">·</span>Live incidents</a></li><li><a href="#the-floor"><span class="n">·</span>The floor</a></li><li><a href="#provenance-is-a-grading-input"><span class="n">·</span>Provenance is a grading input</a></li><li><a href="#recording-a-grade"><span class="n">·</span>Recording a grade</a></li></ol></nav><main><p>This is <code>risk-nexus</code>'s judgement instrument. It is not canon, it is not a standard, and it binds nobody else. It exists so that two findings graded a month apart are graded the same way, and so that a grade can be argued with.</p>
<p>It was written against three real findings (<code>RISK-F-0001</code>, <code>RISK-F-0002</code>, <code>RISK-F-0003</code>) and it must keep grading those three sensibly or it is wrong.</p>
<section id="the-two-axes"><h2>The two axes</h2>
<h3>Impact — what happens if it goes wrong once</h3>
<div class="scroll"><table><thead><tr><th>Band</th><th>Name</th><th>Test</th></tr></thead><tbody><tr><td><code>I1</code></td><td>negligible</td><td>Confined to one component. No data leaves it, no record is falsified, no recovery is lost.</td></tr><tr><td><code>I2</code></td><td>limited</td><td>One system's data or availability. Recoverable. Confined to a single tenant, actor or lane.</td></tr><tr><td><code>I3</code></td><td>serious</td><td>Crosses a boundary — tenant, system, or trust — or removes recoverability for one system.</td></tr><tr><td><code>I4</code></td><td>severe</td><td>Crosses the estate. What is compromised here propagates to everything that trusts it, or the data loss is unbounded.</td></tr></tbody></table></div>
<p>Impact is scored at <strong>one occurrence</strong>, not at the worst imaginable campaign. "An attacker who already owns the cluster could do this too" is not an impact argument.</p>
<h3>Likelihood — how far anyone has to reach</h3>
<div class="scroll"><table><thead><tr><th>Band</th><th>Name</th><th>Test</th></tr></thead><tbody><tr><td><code>L1</code></td><td>remote</td><td>Requires access nobody currently holds and no ordinary process grants.</td></tr><tr><td><code>L2</code></td><td>possible</td><td>Requires a foothold the estate does grant somewhere — an in-cluster workload, an agent session, a scoped token.</td></tr><tr><td><code>L3</code></td><td>likely</td><td>Reachable from inside the normal working set with no additional step.</td></tr><tr><td><code>L4</code></td><td>present</td><td>No barrier at all, or it is already happening.</td></tr></tbody></table></div>
<p>Likelihood is about <strong>reach</strong>, not about intent or about whether anyone has bothered. <code>risk-nexus</code> does not model attackers; it models what the system permits.</p>
<p>Where the reporter has not established exposure, the finding says so and the grade uses the band the <em>stated</em> facts support — not the worst case, and not zero. <code>RISK-F-0001</code> explicitly declines to assume a default-deny NetworkPolicy exists; the grade must decline with it, and the unverified fact becomes a review item rather than a silent assumption in either direction.</p>
</section>
<section id="the-grid"><h2>The grid</h2>
<div class="scroll"><table><thead><tr><th></th><th><code>L1</code></th><th><code>L2</code></th><th><code>L3</code></th><th><code>L4</code></th></tr></thead><tbody><tr><td><code>I4</code></td><td>medium</td><td>high</td><td><strong>critical</strong></td><td><strong>critical</strong></td></tr><tr><td><code>I3</code></td><td>low</td><td>medium</td><td>high</td><td><strong>critical</strong></td></tr><tr><td><code>I2</code></td><td>low</td><td>low</td><td>medium</td><td>high</td></tr><tr><td><code>I1</code></td><td>note</td><td>low</td><td>low</td><td>medium</td></tr></tbody></table></div>
<p>Four severities: <code>low</code>, <code>medium</code>, <code>high</code>, <code>critical</code>. <code>note</code> is not a severity; see the floor.</p>
</section>
<section id="the-fidelity-modifier"><h2>The fidelity modifier</h2>
<p><strong>A control that lies is one impact band worse than the same control absent.</strong></p>
<p>Apply <code>+1</code> impact band (capped at <code>I4</code>) when the failure mode produces a <em>false record</em> rather than <em>no record</em>: an attestation that a check passed when nothing checked, an audit line asserting an authorization that was never made, a green signal derived from an unreachable test.</p>
<p>The reasoning is <code>RISK-F-0002</code>'s and the register adopts it: an absent control is a gap you can find by looking; a lying control is a gap that survives looking, because the evidence you would look at is the thing that is wrong. Only one of the two states misleads the person investigating afterwards.</p>
<p>The modifier applies to the state being scored. A finding that describes both states — control absent today, control lying if switched on in the wrong order — gets <strong>two scores and one of them is the register's headline</strong>; see "Which state is scored".</p>
</section>
<section id="which-state-is-scored"><h2>Which state is scored</h2>
<p>The headline <code>severity</code> is the state of the world <strong>today</strong>. A hazard that would be created by a <em>future</em> action is not the headline, because a register that scores hypotheticals stops describing the estate.</p>
<p>The hazard is not lost. It is recorded on the finding as a named <strong>constraint</strong> with its own grade, and it attaches to whatever action would trigger it — usually another finding's remediation. <code>RISK-F-0002</code> is the worked example: the gate being off is today (headline), the gate being switched on while the oracle is forgeable is a constraint on <code>RISK-F-0001</code>'s fix, graded separately and higher.</p>
<p>If the constraint's grade is higher than the headline, the finding says so in its ruling. A reader must not be able to come away with the low number and miss the high one.</p>
</section>
<section id="build-mode"><h2>Build mode</h2>
<p>Every finding is graded twice:</p>
<ul><li><code>severity</code> — today, in build mode, with today's likelihood.</li><li><code>severity_at_production</code> — the same impact, with likelihood re-read for a system carrying real users and real tenant data.</li></ul>
<p>Build mode legitimately lowers <strong>both</strong> axes, for different reasons: likelihood, where the reach itself depends on a production deployment that has not happened; and impact, where the data that would be exposed does not exist yet. What it must never lower is <code>severity_at_production</code> — the defect does not improve because the calendar has not reached it.</p>
<div class="rule-quote"><p><em>Amended 2026-08-19 (<code>RISK-WP-0001-T07</code>).</em> This paragraph originally said build mode was a likelihood input and never an impact one. Grading the unverified tenant boundary broke that: what build mode changes there is the consequence of an occurrence, not the reach of it. The instrument was wrong on first hard use and is corrected rather than worked around.</p></div>
<p>Where the two grades differ, the production transition is a mandatory re-score. <code>docs/method/review.md</code> binds the review date to it, so the re-score is a scheduled event and not somebody's memory.</p>
</section>
<section id="non-adversarial-findings"><h2>Non-adversarial findings</h2>
<p>Likelihood is written as reach because most findings are about someone getting somewhere. Where a finding is about loss, corruption or outage — no backup, no recovery path, an eviction-prone deployment — there is no attacker to model.</p>
<p>For those, likelihood reads as <strong>the chance of the triggering event inside one review interval</strong>: <code>L1</code> would be surprising, <code>L2</code> is an ordinary failure the estate has seen before, <code>L3</code> is expected in the normal course of running, <code>L4</code> is already happening. Impact is unchanged: what is lost, and whether it comes back.</p>
<div class="rule-quote"><p><em>Added 2026-08-19 (<code>RISK-WP-0001-T07</code>).</em> Forced by <code>RISK-F-0006</code>, where the defect is an absent backup and the reach reading produced nonsense.</p></div>
</section>
<section id="live-incidents"><h2>Live incidents</h2>
<p>Everything above assumes a latent defect — something reachable that nobody is currently reaching. When someone is, three things change:</p>
<ul><li><strong>Likelihood is <code>L4</code>.</strong> The band means "already happening" and this is what it is for.</li><li><strong>Impact is scored on what has occurred plus what is still reachable</strong>, not on the worst case. An incident in progress has facts; use them.</li><li><strong>The grade is provisional and expected to move.</strong> File first, grade within the hour, re-grade as facts arrive. <code>docs/method/intake.md</code> has the rest, including the 72-hour clock that <code>first_observed</code> starts.</li></ul>
</section>
<section id="the-floor"><h2>The floor</h2>
<p><code>INTENT.md</code>: if a finding would not change anyone's decision, it is a note, not a risk. Concretely, a register entry requires <strong>both</strong>:</p>
<ol><li><strong>An owner who could act.</strong> Some repo, or the operator, can do something about it. No actor, no entry.</li><li><strong>A decision that changes.</strong> Recording it alters what someone does, when they do it, or what they must not do first.</li></ol>
<p>Fails either test → it is a note in <code>notes/</code>, not a finding in <code>findings/</code>. Notes are not graded, not reviewed, and not published. They exist so that "we saw it" survives without inflating the register.</p>
<p>An <code>I1</code>/<code>L1</code> cell is <code>note</code> in the grid for the same reason: something that is both negligible and unreachable is a thing we know, not a risk we carry.</p>
<p>Two things the floor does <strong>not</strong> exclude:</p>
<ul><li><strong>Known and deliberate.</strong> <code>RISK-F-0002</code> is a decision somebody made on purpose. It still passes the floor, because it changes what may be switched on and in what order. Deliberate is not the same as tracked.</li><li><strong>Omission-shaped.</strong> <code>RISK-F-0003</code> is a default that silently produces ungoverned lanes. The individual lane is small; the default is not.</li></ul>
</section>
<section id="provenance-is-a-grading-input"><h2>Provenance is a grading input</h2>
<p>All four defects known to this register were found by repos reading their own code against a ladder, within days of each other. None was found by monitoring.</p>
<p>Where a finding's provenance is "we happened to look", the register does not get to assume that similar defects would have been caught. That raises likelihood for the class, not for the instance, and it belongs in the ruling's reasoning rather than in a modifier — the register grades what is filed, and notes when the filing was luck.</p>
</section>
<section id="recording-a-grade"><h2>Recording a grade</h2>
<p>The finding's front-matter carries:</p>
<pre>severity: critical # headline, today
severity_at_production: critical
impact: I4 # band, before modifiers
likelihood: L3
fidelity_modifier: false # true if +1 applied, with the reason in the ruling</pre>
<p>and the ruling section states impact, likelihood, any modifier, and the one sentence that would have to become false for the grade to change.</p>
</section><footer><span>RISK-METHOD-SEVERITY · adopted-1 · adopted</span><span>risk-nexus · docs/method/severity.md · c5517c754bd84b0ebf47878ba0f26df0ecb3b4a4</span></footer></main></div></div></html>