2026-08-19 23:20:31 +02:00
|
|
|
# Work Records — risk-nexus
|
|
|
|
|
|
|
|
|
|
> Generated by `statehub fix-consistency` (CUST-WP-0061-T04, work-record
|
|
|
|
|
> stage 3). Do not edit by hand — edit the source file/block listed for
|
|
|
|
|
> each record and re-run fix-consistency to refresh this index. Archived
|
|
|
|
|
> workplans are omitted; closed decisions/intakes/engagements stay listed
|
|
|
|
|
> so recently-resolved work is still visible. [auto]
|
|
|
|
|
|
|
|
|
|
| Kind | ID | Status | Lane | Source |
|
|
|
|
|
| --- | --- | --- | --- | --- |
|
2026-08-20 23:37:45 +02:00
|
|
|
| workplan | RISK-WP-0001 | finished | — | workplans/RISK-WP-0001-make-the-register-decidable.md |
|
2026-08-20 22:44:46 +02:00
|
|
|
| workplan | RISK-WP-0002 | active | — | workplans/RISK-WP-0002-publication-handover.md |
|
RISK-F-0009: live verification, and a correction to my own count
ops-warden filed this static, saying its OpenBao token was expired. It was not --
bao policy read succeeded, so the deployed policy has now been compared directly.
Coverage confirmed at 6 of 17. But the uncovered count was wrong: eight included
a path pattern and a broker grant, neither of which a policy can deny, and the
finding's own prose already said so about the first. Six stand.
New: the deployed policy differs from the file in railiance-platform -- the file
denies core-hub/runtime, the server does not. No ops-warden lane maps there, so
the numbers are unchanged. It matters because this finding named "the deployed
policy may differ from the file" as unconfirmed, and it does.
Severity, disclosure and embargo left untouched -- risk-nexus's to set. The
embargo condition is a coverage report from railiance-platform, which this does
not satisfy.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 00:50:25 +02:00
|
|
|
| workplan | RISK-WP-0003 | finished | — | workplans/RISK-WP-0003-regulatory-intake.md |
|
2026-08-20 12:02:14 +02:00
|
|
|
| workplan | RISK-WP-0004 | finished | — | workplans/RISK-WP-0004-run-the-register.md |
|
RISK-WP-0005-T01: read the fix records, and two findings moved
fix_tracker.py resolves fix_tracking against the owning repo's workplan
file — the ADR-001 source of truth — and uses the file's last commit date
as the honest answer to 'has this moved', independent of whether the
register looked. Archived workplans are searched too, so a finished fix
that was filed away does not read as missing.
First run, three findings it should have known about:
RISK-F-0005 — AUDIT-WP-0008-T04 has read done since 2026-08-18. The fix
this finding asked for has landed and the register spent three days not
knowing. Now mitigated, embargo lifted, disclosure public. Not fixed:
that needs a probe, and T05's adversarial evidence artifact still reads
wait.
RISK-F-0002 — both tracked records were closed before the finding was
filed: WARDEN-WP-0007 archived 2026-07-08, FLEX-WP-0007 finished
2026-06-29, against a finding of 2026-08-18 that names FLEX-WP-0007 as
the blocker. Routed as a question, not a conclusion.
Four findings carry no fix tracking at all, which the report now says out
loud rather than leaving as an empty field.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 08:29:38 +02:00
|
|
|
| workplan | RISK-WP-0005 | active | — | workplans/RISK-WP-0005-close-the-intent-gaps.md |
|
2026-08-19 23:38:07 +02:00
|
|
|
| task | RISK-WP-0001-T01 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md |
|
|
|
|
|
| task | RISK-WP-0001-T02 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md |
|
2026-08-20 23:37:45 +02:00
|
|
|
| task | RISK-WP-0001-T03 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md |
|
2026-08-19 23:38:07 +02:00
|
|
|
| task | RISK-WP-0001-T04 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md |
|
|
|
|
|
| task | RISK-WP-0001-T05 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md |
|
|
|
|
|
| task | RISK-WP-0001-T06 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md |
|
|
|
|
|
| task | RISK-WP-0001-T07 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md |
|
|
|
|
|
| task | RISK-WP-0001-T08 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md |
|
2026-08-20 22:44:46 +02:00
|
|
|
| task | RISK-WP-0002-T01 | progress | — | workplans/RISK-WP-0002-publication-handover.md |
|
|
|
|
|
| task | RISK-WP-0002-T02 | done | — | workplans/RISK-WP-0002-publication-handover.md |
|
|
|
|
|
| task | RISK-WP-0002-T03 | done | — | workplans/RISK-WP-0002-publication-handover.md |
|
RISK-F-0009: live verification, and a correction to my own count
ops-warden filed this static, saying its OpenBao token was expired. It was not --
bao policy read succeeded, so the deployed policy has now been compared directly.
Coverage confirmed at 6 of 17. But the uncovered count was wrong: eight included
a path pattern and a broker grant, neither of which a policy can deny, and the
finding's own prose already said so about the first. Six stand.
New: the deployed policy differs from the file in railiance-platform -- the file
denies core-hub/runtime, the server does not. No ops-warden lane maps there, so
the numbers are unchanged. It matters because this finding named "the deployed
policy may differ from the file" as unconfirmed, and it does.
Severity, disclosure and embargo left untouched -- risk-nexus's to set. The
embargo condition is a coverage report from railiance-platform, which this does
not satisfy.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 00:50:25 +02:00
|
|
|
| task | RISK-WP-0003-T01 | done | — | workplans/RISK-WP-0003-regulatory-intake.md |
|
2026-08-20 23:18:52 +02:00
|
|
|
| task | RISK-WP-0003-T02 | done | — | workplans/RISK-WP-0003-regulatory-intake.md |
|
|
|
|
|
| task | RISK-WP-0003-T03 | done | — | workplans/RISK-WP-0003-regulatory-intake.md |
|
|
|
|
|
| task | RISK-WP-0003-T04 | done | — | workplans/RISK-WP-0003-regulatory-intake.md |
|
2026-08-20 12:02:14 +02:00
|
|
|
| task | RISK-WP-0004-T01 | done | — | workplans/RISK-WP-0004-run-the-register.md |
|
2026-08-20 08:55:48 +02:00
|
|
|
| task | RISK-WP-0004-T02 | done | — | workplans/RISK-WP-0004-run-the-register.md |
|
|
|
|
|
| task | RISK-WP-0004-T03 | done | — | workplans/RISK-WP-0004-run-the-register.md |
|
|
|
|
|
| task | RISK-WP-0004-T04 | done | — | workplans/RISK-WP-0004-run-the-register.md |
|
|
|
|
|
| task | RISK-WP-0004-T05 | done | — | workplans/RISK-WP-0004-run-the-register.md |
|
|
|
|
|
| task | RISK-WP-0004-T06 | done | — | workplans/RISK-WP-0004-run-the-register.md |
|
RISK-WP-0005-T01: read the fix records, and two findings moved
fix_tracker.py resolves fix_tracking against the owning repo's workplan
file — the ADR-001 source of truth — and uses the file's last commit date
as the honest answer to 'has this moved', independent of whether the
register looked. Archived workplans are searched too, so a finished fix
that was filed away does not read as missing.
First run, three findings it should have known about:
RISK-F-0005 — AUDIT-WP-0008-T04 has read done since 2026-08-18. The fix
this finding asked for has landed and the register spent three days not
knowing. Now mitigated, embargo lifted, disclosure public. Not fixed:
that needs a probe, and T05's adversarial evidence artifact still reads
wait.
RISK-F-0002 — both tracked records were closed before the finding was
filed: WARDEN-WP-0007 archived 2026-07-08, FLEX-WP-0007 finished
2026-06-29, against a finding of 2026-08-18 that names FLEX-WP-0007 as
the blocker. Routed as a question, not a conclusion.
Four findings carry no fix tracking at all, which the report now says out
loud rather than leaving as an empty field.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 08:29:38 +02:00
|
|
|
| task | RISK-WP-0005-T01 | todo | — | workplans/RISK-WP-0005-close-the-intent-gaps.md |
|
|
|
|
|
| task | RISK-WP-0005-T02 | todo | — | workplans/RISK-WP-0005-close-the-intent-gaps.md |
|
|
|
|
|
| task | RISK-WP-0005-T03 | todo | — | workplans/RISK-WP-0005-close-the-intent-gaps.md |
|
|
|
|
|
| task | RISK-WP-0005-T04 | todo | — | workplans/RISK-WP-0005-close-the-intent-gaps.md |
|
|
|
|
|
| task | RISK-WP-0005-T05 | todo | — | workplans/RISK-WP-0005-close-the-intent-gaps.md |
|
|
|
|
|
| task | RISK-WP-0005-T06 | todo | — | workplans/RISK-WP-0005-close-the-intent-gaps.md |
|
|
|
|
|
| task | RISK-WP-0005-T07 | todo | — | workplans/RISK-WP-0005-close-the-intent-gaps.md |
|