RISK-WP-0001 T01-T06,T08: the four instruments, the index, and the first grading
Severity (impact x likelihood, fidelity modifier for controls that lie,
headline-vs-constraint, build-mode double grade, the floor), disclosure
(publish/embargoed/restricted, and the build-mode deferral re-taken and
narrowed with RISK-F-0001 in hand), escalation (the five INTENT triggers
settled plus an ordering-hazard trigger the RISK-F-0002 case forced;
proposed, awaiting the custodian), review (intervals, what a review is,
what missing one produces, the production re-score).
Then applied: RISK-F-0001 critical/embargoed/escalated, RISK-F-0002
medium with a high constraint on RISK-F-0001's remediation, filed as a
peer and escalated only on the ordering, RISK-F-0003 high/embargoed/no
escalation. No unset field remains.
REGISTER.md is generated; make check reports overdue, stalled, ungraded
and unanswered escalations without changing anything.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 23:29:39 +02:00
|
|
|
# Filing a finding
|
|
|
|
|
|
|
|
|
|
One file per finding: `findings/RISK-F-NNNN-<slug>.md`, YAML front-matter,
|
Adaptive check cadence: the interval is earned, not assigned
Operator ruling 2026-08-20. Severity no longer sets the review interval.
A check that comes back clean climbs one rung — instant, 1h, 8h, 24h,
48h, 96h, 7d, 14d, 1mo, 1q — and anything wrong drops straight back to
instant. A quarter is the ceiling. The operator may defer an instant
finding to a stated date; that is the only other way off the bottom rung.
The rung is the point: it says how stable the estate has been on that
matter, which is information severity does not carry. Volatile things get
attention automatically; quiet things stop consuming it; neither
judgement has to be made by a person who might be busy.
Escalation trigger 5 rebased onto the ladder — fourteen days at the
bottom rung, whether that is failing checks or no checks.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 07:43:51 +02:00
|
|
|
then prose.
|
|
|
|
|
|
|
|
|
|
**Ids are allocated by `risk-nexus`.** Take the next id past the highest you
|
|
|
|
|
can see and file — that is the right thing to do — but if two reporters take
|
|
|
|
|
the same one, the earlier commit keeps it and the newcomer is renumbered here,
|
|
|
|
|
with the original id recorded as `filed_as`. This happened on 2026-08-20
|
|
|
|
|
(`RISK-F-0009`, filed as `RISK-F-0004`), which is why it is written down. Do
|
|
|
|
|
not renumber your own finding after filing; the register does it and tells you.
|
RISK-WP-0001 T01-T06,T08: the four instruments, the index, and the first grading
Severity (impact x likelihood, fidelity modifier for controls that lie,
headline-vs-constraint, build-mode double grade, the floor), disclosure
(publish/embargoed/restricted, and the build-mode deferral re-taken and
narrowed with RISK-F-0001 in hand), escalation (the five INTENT triggers
settled plus an ordering-hazard trigger the RISK-F-0002 case forced;
proposed, awaiting the custodian), review (intervals, what a review is,
what missing one produces, the production re-score).
Then applied: RISK-F-0001 critical/embargoed/escalated, RISK-F-0002
medium with a high constraint on RISK-F-0001's remediation, filed as a
peer and escalated only on the ordering, RISK-F-0003 high/embargoed/no
escalation. No unset field remains.
REGISTER.md is generated; make check reports overdue, stalled, ungraded
and unanswered escalations without changing anything.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 23:29:39 +02:00
|
|
|
|
|
|
|
|
## What the reporter fills in
|
|
|
|
|
|
|
|
|
|
```yaml
|
|
|
|
|
id: RISK-F-0004
|
|
|
|
|
type: finding
|
|
|
|
|
title: "one line, what is true — not what should be done"
|
|
|
|
|
status: open # open | fixed | accepted | withdrawn
|
|
|
|
|
reported_by: <repo> # who found it
|
|
|
|
|
reported_via: <repo> # who routed it here, if different
|
|
|
|
|
date_reported: "YYYY-MM-DD"
|
|
|
|
|
system: <repo> # the system the defect is in
|
|
|
|
|
environment: production # production | build | both
|
|
|
|
|
fix_owner: <repo> # who owns the fix — never risk-nexus
|
|
|
|
|
fix_tracking: <WP-ID or unset>
|
|
|
|
|
related: [RISK-F-0001] # optional
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
## What risk-nexus fills in — leave these out
|
|
|
|
|
|
|
|
|
|
`severity`, `severity_at_production`, `impact`, `likelihood`,
|
|
|
|
|
`fidelity_modifier`, `production_rescore`, `disclosure`, `embargo_*`,
|
Adaptive check cadence: the interval is earned, not assigned
Operator ruling 2026-08-20. Severity no longer sets the review interval.
A check that comes back clean climbs one rung — instant, 1h, 8h, 24h,
48h, 96h, 7d, 14d, 1mo, 1q — and anything wrong drops straight back to
instant. A quarter is the ceiling. The operator may defer an instant
finding to a stated date; that is the only other way off the bottom rung.
The rung is the point: it says how stable the estate has been on that
matter, which is information severity does not carry. Volatile things get
attention automatically; quiet things stop consuming it; neither
judgement has to be made by a person who might be busy.
Escalation trigger 5 rebased onto the ladder — fourteen days at the
bottom rung, whether that is failing checks or no checks.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 07:43:51 +02:00
|
|
|
`escalation*`, `constraint*`, `last_checked`, `next_check`, `cadence`,
|
|
|
|
|
`clean_streak`, `graded_by`, `ruling`.
|
|
|
|
|
|
|
|
|
|
`cadence` is the check-frequency rung, and it is earned rather than assigned:
|
|
|
|
|
a clean check climbs one rung (`instant` → `1h` → `8h` → `24h` → `48h` → `96h`
|
|
|
|
|
→ `7d` → `14d` → `1mo` → `1q`), and anything moving drops it straight back to
|
|
|
|
|
`instant`. So the rung on your finding is a public statement about how settled
|
|
|
|
|
the matter has been — which is why it is not yours to set.
|
RISK-WP-0001 T01-T06,T08: the four instruments, the index, and the first grading
Severity (impact x likelihood, fidelity modifier for controls that lie,
headline-vs-constraint, build-mode double grade, the floor), disclosure
(publish/embargoed/restricted, and the build-mode deferral re-taken and
narrowed with RISK-F-0001 in hand), escalation (the five INTENT triggers
settled plus an ordering-hazard trigger the RISK-F-0002 case forced;
proposed, awaiting the custodian), review (intervals, what a review is,
what missing one produces, the production re-score).
Then applied: RISK-F-0001 critical/embargoed/escalated, RISK-F-0002
medium with a high constraint on RISK-F-0001's remediation, filed as a
peer and escalated only on the ordering, RISK-F-0003 high/embargoed/no
escalation. No unset field remains.
REGISTER.md is generated; make check reports overdue, stalled, ungraded
and unanswered escalations without changing anything.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 23:29:39 +02:00
|
|
|
|
|
|
|
|
Setting them yourself is not an error to be corrected — it is a boundary this
|
|
|
|
|
repo would rather keep. The reporter says what is true; this repo says how bad
|
|
|
|
|
it is and who hears about it (`INTENT.md`). Leaving them out, or writing
|
|
|
|
|
`unset`, both work; the nag reports either way until they are graded.
|
|
|
|
|
|
|
|
|
|
## What makes a good finding here
|
|
|
|
|
|
|
|
|
|
- **State exposure only as far as you can support it.** "Not established" is a
|
|
|
|
|
complete answer and grades better than a guess. `RISK-F-0001` declining to
|
|
|
|
|
assume a NetworkPolicy is the model.
|
|
|
|
|
- **Say how it was found.** Provenance is a grading input.
|
|
|
|
|
- **Suggest a direction if you have one, marked as a suggestion.** The fix is
|
|
|
|
|
yours; the grade is ours.
|
|
|
|
|
- **A note is fine.** If it would not change anyone's decision, it belongs in
|
|
|
|
|
`notes/` — see the floor in `docs/method/severity.md`.
|
|
|
|
|
|
2026-08-20 01:12:31 +02:00
|
|
|
## Asking for a tenant-boundary verification
|
|
|
|
|
|
|
|
|
|
Separate from filing. The estate carries `RISK-F-0007` — no consumer's tenant
|
|
|
|
|
boundary is verified anywhere — as an accepted risk until production, on the
|
|
|
|
|
operator's ruling of 2026-08-19, with verification available **on request**.
|
|
|
|
|
|
|
|
|
|
Message `risk-nexus` naming one consumer boundary and what would have to be
|
|
|
|
|
true of it. The owning repo of that consumer does the verification; this repo
|
|
|
|
|
scopes and records it and verifies nothing itself. A boundary that holds is
|
|
|
|
|
evidence; one that does not is a finding with its own owner.
|
|
|
|
|
|
RISK-WP-0001 T01-T06,T08: the four instruments, the index, and the first grading
Severity (impact x likelihood, fidelity modifier for controls that lie,
headline-vs-constraint, build-mode double grade, the floor), disclosure
(publish/embargoed/restricted, and the build-mode deferral re-taken and
narrowed with RISK-F-0001 in hand), escalation (the five INTENT triggers
settled plus an ordering-hazard trigger the RISK-F-0002 case forced;
proposed, awaiting the custodian), review (intervals, what a review is,
what missing one produces, the production re-score).
Then applied: RISK-F-0001 critical/embargoed/escalated, RISK-F-0002
medium with a high constraint on RISK-F-0001's remediation, filed as a
peer and escalated only on the ordering, RISK-F-0003 high/embargoed/no
escalation. No unset field remains.
REGISTER.md is generated; make check reports overdue, stalled, ungraded
and unanswered escalations without changing anything.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 23:29:39 +02:00
|
|
|
After filing: `make check`. Then this repo grades it.
|