Operator decisions on RISK-F-0006 and RISK-F-0007
F-0006: backup spend approved, no ceiling stated. Permission is no longer the blocker; the embargo still needs a demonstrated restore. F-0007: pragmatic default before production — accepted (not closed, keeps its severity, review interval and production re-score, stays visible in the register), with a written on-request path so a named consumer boundary can be verified when someone asks. The acceptance expires at the production transition, which is an event and not a date. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
f2b38163ff
commit
00106ffcdd
3 changed files with 94 additions and 11 deletions
|
|
@ -2,18 +2,18 @@
|
||||||
|
|
||||||
Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-08-19.
|
Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-08-19.
|
||||||
|
|
||||||
7 open of 8 findings; 2 notes below the floor.
|
5 open of 8 findings; 2 notes below the floor.
|
||||||
|
|
||||||
## Findings
|
## Findings
|
||||||
|
|
||||||
| ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Review by |
|
| ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Review by |
|
||||||
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
|
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
|
||||||
| [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **required** (t2, pending-operator) | risk-nexus | open | 2026-11-17 |
|
| [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **required** (t2, pending-operator) | risk-nexus | open | 2026-11-17 |
|
||||||
| [RISK-F-0007](findings/RISK-F-0007-unverified-tenant-boundary.md) | No consumer's tenant boundary is verified anywhere | estate | **high** | embargoed | **required** (t4, pending-operator) | unset | open | 2026-09-18 |
|
| [RISK-F-0007](findings/RISK-F-0007-unverified-tenant-boundary.md) | No consumer's tenant boundary is verified anywhere | estate | **high** | embargoed | **answered** (t4, assigned) | per-consumer, on request | accepted | 2026-09-18 |
|
||||||
| [RISK-F-0006](findings/RISK-F-0006-apps-pg-no-backup-configured.md) | apps-pg has no backup configured at all: R0 means no recovery | railiance-platform | **high** | embargoed | **required** (t3, pending-operator) | railiance-platform | open | 2026-09-18 |
|
| [RISK-F-0006](findings/RISK-F-0006-apps-pg-no-backup-configured.md) | apps-pg has no backup configured at all: R0 means no recovery | railiance-platform | **high** | embargoed | **answered** (t3, approved) | railiance-platform | open | 2026-09-18 |
|
||||||
| [RISK-F-0005](findings/RISK-F-0005-audit-core-unfiltered-read-path.md) | audit-core read path applies no tenant filter; the bound is deployment, not code | audit-core | medium | embargoed | none | audit-core | open | 2026-11-17 |
|
| [RISK-F-0005](findings/RISK-F-0005-audit-core-unfiltered-read-path.md) | audit-core read path applies no tenant filter; the bound is deployment, not code | audit-core | medium | embargoed | none | audit-core | open | 2026-11-17 |
|
||||||
| [RISK-F-0004](findings/RISK-F-0004-tenant-engine-unfiltered-event-read.md) | tenant-engine events() returns the entire event log unfiltered | tenant-engine | **high** | embargoed | none | tenant-engine | open | 2026-09-18 |
|
| [RISK-F-0004](findings/RISK-F-0004-tenant-engine-unfiltered-event-read.md) | tenant-engine events() returns the entire event log unfiltered | tenant-engine | **high** | embargoed | none | tenant-engine | open | 2026-09-18 |
|
||||||
| [RISK-F-0003](findings/RISK-F-0003-ops-warden-read-boundary-ungraded-lanes.md) | ops-warden agent read-boundary does not fire on ungraded catalog lanes | ops-warden | **high** | embargoed | none | ops-warden | open | 2026-09-18 |
|
| [RISK-F-0003](findings/RISK-F-0003-ops-warden-read-boundary-ungraded-lanes.md) | ops-warden agent read-boundary does not fire on ungraded catalog lanes | ops-warden | **high** | embargoed | none | ops-warden | mitigated | 2026-09-18 |
|
||||||
| [RISK-F-0002](findings/RISK-F-0002-ops-warden-sign-ungated.md) | ops-warden signs SSH certificates with no authorization decision, and its unblock is now unsafe | ops-warden | medium | embargoed | **withdrawn** (t6, withdrawn-hazard-window-closed) | ops-warden | open | 2026-11-17 |
|
| [RISK-F-0002](findings/RISK-F-0002-ops-warden-sign-ungated.md) | ops-warden signs SSH certificates with no authorization decision, and its unblock is now unsafe | ops-warden | medium | embargoed | **withdrawn** (t6, withdrawn-hazard-window-closed) | ops-warden | open | 2026-11-17 |
|
||||||
| [RISK-F-0001](findings/RISK-F-0001-flex-auth-unauthenticated-check.md) | flex-auth /v1/check authenticates no caller | flex-auth | **high** | public | **withdrawn** (t1, withdrawn-before-sending) | flex-auth | fixed | 2026-08-26 |
|
| [RISK-F-0001](findings/RISK-F-0001-flex-auth-unauthenticated-check.md) | flex-auth /v1/check authenticates no caller | flex-auth | **high** | public | **withdrawn** (t1, withdrawn-before-sending) | flex-auth | fixed | 2026-08-26 |
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -11,7 +11,7 @@ date_filed: "2026-08-19"
|
||||||
system: railiance-platform
|
system: railiance-platform
|
||||||
environment: production
|
environment: production
|
||||||
fix_owner: railiance-platform
|
fix_owner: railiance-platform
|
||||||
fix_tracking: unset
|
fix_tracking: unset (railiance-platform to open)
|
||||||
related: [RISK-F-0001]
|
related: [RISK-F-0001]
|
||||||
# Graded by risk-nexus 2026-08-19 — docs/rulings/2026-08-19-second-grading.md
|
# Graded by risk-nexus 2026-08-19 — docs/rulings/2026-08-19-second-grading.md
|
||||||
severity: high
|
severity: high
|
||||||
|
|
@ -24,9 +24,13 @@ disclosure: embargoed
|
||||||
embargo_condition: "a backup exists and a restore has been demonstrated once"
|
embargo_condition: "a backup exists and a restore has been demonstrated once"
|
||||||
embargo_since: "2026-08-19"
|
embargo_since: "2026-08-19"
|
||||||
embargo_review: "2026-09-18"
|
embargo_review: "2026-09-18"
|
||||||
escalation: required
|
escalation: answered
|
||||||
escalation_trigger: 3
|
escalation_trigger: 3
|
||||||
escalation_status: pending-operator
|
escalation_status: approved
|
||||||
|
escalation_answered: "2026-08-19"
|
||||||
|
escalation_answered_by: the-custodian
|
||||||
|
escalation_act: approve
|
||||||
|
decision: "spend for apps-pg backup storage approved; no ceiling stated"
|
||||||
last_reviewed: "2026-08-19"
|
last_reviewed: "2026-08-19"
|
||||||
review_by: "2026-09-18"
|
review_by: "2026-09-18"
|
||||||
graded_by: risk-nexus
|
graded_by: risk-nexus
|
||||||
|
|
@ -86,3 +90,26 @@ error as the gate in `RISK-F-0002`.
|
||||||
- **2026-08-19** — filed and graded from `RISK-F-0001`'s unfiled list.
|
- **2026-08-19** — filed and graded from `RISK-F-0001`'s unfiled list.
|
||||||
Open at review: has the spend been ruled on; is a backup configured; has a
|
Open at review: has the spend been ruled on; is a backup configured; has a
|
||||||
restore been demonstrated; does `railiance-platform` track it anywhere.
|
restore been demonstrated; does `railiance-platform` track it anywhere.
|
||||||
|
|
||||||
|
## Operator decision — 2026-08-19: approved
|
||||||
|
|
||||||
|
The spend is approved. `railiance-platform` may provision backup storage for
|
||||||
|
`apps-pg` without returning for authorisation.
|
||||||
|
|
||||||
|
No ceiling was stated, so none is recorded. The register asks
|
||||||
|
`railiance-platform` to report the actual target and its monthly cost once
|
||||||
|
chosen; a figure materially above the trigger-3 band (recurring €50/month)
|
||||||
|
comes back for confirmation rather than being assumed covered. That is the
|
||||||
|
register being careful with an open approval, not a condition on it.
|
||||||
|
|
||||||
|
**What is now blocking is work, not permission.** The finding stays `open` at
|
||||||
|
`high`, and the embargo condition is unchanged: a backup exists **and** a
|
||||||
|
restore has been demonstrated once. A backup nobody has restored from is a
|
||||||
|
claim, not a control.
|
||||||
|
|
||||||
|
`fix_tracking` is still `unset` and is now `railiance-platform`'s to open.
|
||||||
|
|
||||||
|
## Reviews
|
||||||
|
|
||||||
|
- **2026-08-19** — escalation answered, spend approved. Open at review: is a
|
||||||
|
backup configured; has a restore been demonstrated; what does it cost.
|
||||||
|
|
|
||||||
|
|
@ -2,7 +2,7 @@
|
||||||
id: RISK-F-0007
|
id: RISK-F-0007
|
||||||
type: finding
|
type: finding
|
||||||
title: "No consumer's tenant boundary is verified anywhere"
|
title: "No consumer's tenant boundary is verified anywhere"
|
||||||
status: open
|
status: accepted
|
||||||
reported_by: net-kingdom
|
reported_by: net-kingdom
|
||||||
reported_via: risk-nexus
|
reported_via: risk-nexus
|
||||||
routed_by: risk-nexus
|
routed_by: risk-nexus
|
||||||
|
|
@ -10,7 +10,7 @@ date_reported: "2026-08-19"
|
||||||
date_filed: "2026-08-19"
|
date_filed: "2026-08-19"
|
||||||
system: estate
|
system: estate
|
||||||
environment: build
|
environment: build
|
||||||
fix_owner: unset
|
fix_owner: per-consumer, on request
|
||||||
fix_tracking: unset
|
fix_tracking: unset
|
||||||
related: [RISK-F-0004, RISK-F-0005]
|
related: [RISK-F-0004, RISK-F-0005]
|
||||||
# Graded by risk-nexus 2026-08-19 — docs/rulings/2026-08-19-second-grading.md
|
# Graded by risk-nexus 2026-08-19 — docs/rulings/2026-08-19-second-grading.md
|
||||||
|
|
@ -24,9 +24,16 @@ disclosure: embargoed
|
||||||
embargo_condition: "a verification exists for at least one consumer boundary"
|
embargo_condition: "a verification exists for at least one consumer boundary"
|
||||||
embargo_since: "2026-08-19"
|
embargo_since: "2026-08-19"
|
||||||
embargo_review: "2026-09-18"
|
embargo_review: "2026-09-18"
|
||||||
escalation: required
|
escalation: answered
|
||||||
escalation_trigger: 4
|
escalation_trigger: 4
|
||||||
escalation_status: pending-operator
|
escalation_status: assigned
|
||||||
|
escalation_answered: "2026-08-19"
|
||||||
|
escalation_answered_by: the-custodian
|
||||||
|
escalation_act: assign
|
||||||
|
accepted_by: the-custodian
|
||||||
|
accepted_on: "2026-08-19"
|
||||||
|
accepted_until: "production transition (hard expiry, not a date)"
|
||||||
|
decision: "pragmatic default before production — carried unverified; verification of a named consumer boundary on request"
|
||||||
last_reviewed: "2026-08-19"
|
last_reviewed: "2026-08-19"
|
||||||
review_by: "2026-09-18"
|
review_by: "2026-09-18"
|
||||||
graded_by: risk-nexus
|
graded_by: risk-nexus
|
||||||
|
|
@ -97,3 +104,52 @@ better than a routed one nobody agreed to.
|
||||||
- **2026-08-19** — filed and graded. Open at review: has an owner been named;
|
- **2026-08-19** — filed and graded. Open at review: has an owner been named;
|
||||||
have any further instances been found; is the Tenancy Posture question still
|
have any further instances been found; is the Tenancy Posture question still
|
||||||
open.
|
open.
|
||||||
|
|
||||||
|
## Operator decision — 2026-08-19: pragmatic default, tighter control on request
|
||||||
|
|
||||||
|
The custodian ruled: **before production, carry it.** Verifying every
|
||||||
|
consumer's tenant boundary is not attempted as a programme now; a named
|
||||||
|
boundary is verified when someone asks for it.
|
||||||
|
|
||||||
|
The finding moves to `accepted` — which in this register is not `closed`. It
|
||||||
|
keeps its severity, its review interval and its production re-score, and it
|
||||||
|
stays in `REGISTER.md` where an accepted risk is supposed to be visible while
|
||||||
|
it is being carried.
|
||||||
|
|
||||||
|
**The acceptance expires at the production transition, and that is an event,
|
||||||
|
not a date.** `production_rescore` is `true`: at production the same defect is
|
||||||
|
`I4` × `L3` — `critical` — and the acceptance does not survive it. Nobody has
|
||||||
|
to remember; `make check` lists it under what is owed at that transition.
|
||||||
|
|
||||||
|
### The on-request path
|
||||||
|
|
||||||
|
So that "on request" is a mechanism and not a sentiment:
|
||||||
|
|
||||||
|
- **Who may ask** — any repo that consumes or is consumed by another, the
|
||||||
|
operator, or an outside counterparty through the operator.
|
||||||
|
- **What they get** — verification scoped to one named consumer boundary, not
|
||||||
|
a general audit. The request names the consumer and what would have to be
|
||||||
|
true.
|
||||||
|
- **Who does it** — the owning repo of that consumer. This register scopes and
|
||||||
|
records; it does not verify, and it does not fix.
|
||||||
|
- **What it produces** — a dated verification record here. If the boundary
|
||||||
|
holds, that is evidence and this finding's likelihood falls for that
|
||||||
|
consumer. If it does not, that is a finding of its own with its own owner,
|
||||||
|
filed normally.
|
||||||
|
|
||||||
|
Requests arrive as a message to `risk-nexus` and appear in the register within
|
||||||
|
one review cycle.
|
||||||
|
|
||||||
|
### What the register keeps saying while this is carried
|
||||||
|
|
||||||
|
The two-for-two record stands: every repo that has looked at its own boundary
|
||||||
|
this month found a defect (`RISK-F-0004`, `RISK-F-0005`). The acceptance does
|
||||||
|
not make that less true, and this finding is the place it stays visible. If a
|
||||||
|
third instance arrives, the pragmatic default is worth re-taking before
|
||||||
|
production rather than at it.
|
||||||
|
|
||||||
|
## Reviews
|
||||||
|
|
||||||
|
- **2026-08-19** — escalation answered, accepted until production with
|
||||||
|
verification on request. Open at review: any request received; any further
|
||||||
|
instances found; whether production is close enough to re-take the default.
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue