Operator decisions on RISK-F-0006 and RISK-F-0007
F-0006: backup spend approved, no ceiling stated. Permission is no longer the blocker; the embargo still needs a demonstrated restore. F-0007: pragmatic default before production — accepted (not closed, keeps its severity, review interval and production re-score, stays visible in the register), with a written on-request path so a named consumer boundary can be verified when someone asks. The acceptance expires at the production transition, which is an event and not a date. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
f2b38163ff
commit
00106ffcdd
3 changed files with 94 additions and 11 deletions
|
|
@ -11,7 +11,7 @@ date_filed: "2026-08-19"
|
|||
system: railiance-platform
|
||||
environment: production
|
||||
fix_owner: railiance-platform
|
||||
fix_tracking: unset
|
||||
fix_tracking: unset (railiance-platform to open)
|
||||
related: [RISK-F-0001]
|
||||
# Graded by risk-nexus 2026-08-19 — docs/rulings/2026-08-19-second-grading.md
|
||||
severity: high
|
||||
|
|
@ -24,9 +24,13 @@ disclosure: embargoed
|
|||
embargo_condition: "a backup exists and a restore has been demonstrated once"
|
||||
embargo_since: "2026-08-19"
|
||||
embargo_review: "2026-09-18"
|
||||
escalation: required
|
||||
escalation: answered
|
||||
escalation_trigger: 3
|
||||
escalation_status: pending-operator
|
||||
escalation_status: approved
|
||||
escalation_answered: "2026-08-19"
|
||||
escalation_answered_by: the-custodian
|
||||
escalation_act: approve
|
||||
decision: "spend for apps-pg backup storage approved; no ceiling stated"
|
||||
last_reviewed: "2026-08-19"
|
||||
review_by: "2026-09-18"
|
||||
graded_by: risk-nexus
|
||||
|
|
@ -86,3 +90,26 @@ error as the gate in `RISK-F-0002`.
|
|||
- **2026-08-19** — filed and graded from `RISK-F-0001`'s unfiled list.
|
||||
Open at review: has the spend been ruled on; is a backup configured; has a
|
||||
restore been demonstrated; does `railiance-platform` track it anywhere.
|
||||
|
||||
## Operator decision — 2026-08-19: approved
|
||||
|
||||
The spend is approved. `railiance-platform` may provision backup storage for
|
||||
`apps-pg` without returning for authorisation.
|
||||
|
||||
No ceiling was stated, so none is recorded. The register asks
|
||||
`railiance-platform` to report the actual target and its monthly cost once
|
||||
chosen; a figure materially above the trigger-3 band (recurring €50/month)
|
||||
comes back for confirmation rather than being assumed covered. That is the
|
||||
register being careful with an open approval, not a condition on it.
|
||||
|
||||
**What is now blocking is work, not permission.** The finding stays `open` at
|
||||
`high`, and the embargo condition is unchanged: a backup exists **and** a
|
||||
restore has been demonstrated once. A backup nobody has restored from is a
|
||||
claim, not a control.
|
||||
|
||||
`fix_tracking` is still `unset` and is now `railiance-platform`'s to open.
|
||||
|
||||
## Reviews
|
||||
|
||||
- **2026-08-19** — escalation answered, spend approved. Open at review: is a
|
||||
backup configured; has a restore been demonstrated; what does it cost.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue