Close out RISK-WP-0001: task notes, README, repo classification
T01, T02, T04-T08 done. T03 stays in progress: the escalation rule is written and proposed, and it is not adopted until the custodian rules on it — an unadopted rule is worse than an unwritten one because it looks like coverage. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
4daff5503f
commit
37906c3a22
3 changed files with 68 additions and 8 deletions
19
.repo-classification.yaml
Normal file
19
.repo-classification.yaml
Normal file
|
|
@ -0,0 +1,19 @@
|
|||
repo_classification:
|
||||
standard: Repo Classification Standard
|
||||
version: "1.0"
|
||||
classified_at: "2026-08-19"
|
||||
classified_by: agent
|
||||
category: project
|
||||
domain: infotech
|
||||
secondary_domains:
|
||||
- government
|
||||
capability_tags:
|
||||
- governance
|
||||
- security
|
||||
- knowledge
|
||||
business_stake:
|
||||
- technology
|
||||
- operations
|
||||
business_mechanics:
|
||||
- coordination
|
||||
- operation
|
||||
25
README.md
25
README.md
|
|
@ -11,4 +11,29 @@ register.
|
|||
It does not fix things: findings route to the repo that owns the defect. It
|
||||
does not host: `policy-nexus` is the publication surface.
|
||||
|
||||
## Where things are
|
||||
|
||||
- **`REGISTER.md`** — the whole register, one screen. Generated; do not edit.
|
||||
- **`findings/`** — one file per finding. `findings/README.md` is the filing
|
||||
contract for reporting repos.
|
||||
- **`notes/`** — seen, deliberately below the floor. Not graded, not reviewed.
|
||||
- **`docs/method/`** — how this repo decides:
|
||||
[severity](docs/method/severity.md),
|
||||
[disclosure](docs/method/disclosure.md),
|
||||
[escalation](docs/method/escalation.md),
|
||||
[review and expiry](docs/method/review.md).
|
||||
- **`docs/rulings/`** — the reasoning behind each grading, dated.
|
||||
- **`workplans/`** — the work.
|
||||
|
||||
## Using it
|
||||
|
||||
```
|
||||
make register # rebuild REGISTER.md from findings/
|
||||
make check # verify the index, then report what is going quiet
|
||||
```
|
||||
|
||||
`make check` reports ungraded findings, overdue reviews, stalled remediation,
|
||||
embargoes due for re-decision, escalations awaiting the operator, and what is
|
||||
owed at the production transition. It changes nothing.
|
||||
|
||||
- Intent: `INTENT.md`
|
||||
|
|
|
|||
|
|
@ -93,7 +93,7 @@ publishable through `policy-nexus` later; this workplan does not publish it.
|
|||
|
||||
```task
|
||||
id: RISK-WP-0001-T01
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
|
|
@ -114,11 +114,13 @@ Constraints it has to satisfy, taken from the findings already here:
|
|||
|
||||
**Output:** `docs/method/severity.md`.
|
||||
|
||||
Completed 2026-08-19. `docs/method/severity.md`: impact `I1`-`I4` x likelihood `L1`-`L4` on a grid, the fidelity modifier (+1 impact band where the failure produces a false record rather than none), the headline-versus-constraint split, the build-mode double grade, and the floor. Amended the same day by T07 — build mode lowers impact as well as likelihood, and non-adversarial findings read likelihood as event probability.
|
||||
|
||||
### T02 — Disclosure states
|
||||
|
||||
```task
|
||||
id: RISK-WP-0001-T02
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
|
|
@ -138,11 +140,13 @@ Whichever way it goes is a recorded decision, not a habit.
|
|||
|
||||
**Output:** `docs/method/disclosure.md`, including the re-taken deferral.
|
||||
|
||||
Completed 2026-08-19. `docs/method/disclosure.md`. The deferral was re-taken and **narrowed**: build-mode default stays publish, the live-and-reachable exception exists now and costs one front-matter field, the *mechanism* stays deferred as originally reasoned. All seven findings sit at `embargoed` with observable lift conditions.
|
||||
|
||||
### T03 — The escalation rule
|
||||
|
||||
```task
|
||||
id: RISK-WP-0001-T03
|
||||
status: todo
|
||||
status: progress
|
||||
priority: high
|
||||
```
|
||||
|
||||
|
|
@ -168,11 +172,13 @@ The custodian adopts the rule. Ask, do not assume.
|
|||
|
||||
**Output:** `docs/method/escalation.md`.
|
||||
|
||||
In progress 2026-08-19. `docs/method/escalation.md` is written and `status: proposed`. All five INTENT triggers settled — 1 adopted and bounded, 2 adopted unbounded, 3 bounded at EUR 50/month or EUR 500 one-off, 4 bounded by one failed routing exchange, 5 bounded at twice the review interval — plus trigger 6 (ordering hazard producing a false attestation), added because `RISK-F-0002` produced the case. Tested against all seven findings before proposing. **Not done until the custodian adopts it**, and the spend numbers are the operator's to overwrite.
|
||||
|
||||
### T04 — Review dates and expiry
|
||||
|
||||
```task
|
||||
id: RISK-WP-0001-T04
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
|
|
@ -190,11 +196,13 @@ picks which.
|
|||
**Output:** `docs/method/review.md`; the finding front-matter contract extended
|
||||
with `review_by` and `last_reviewed`.
|
||||
|
||||
Completed 2026-08-19. `docs/method/review.md`: 7/30/90/180-day intervals by severity, the four questions a review answers — including `RISK-F-0002`'s "a blocker is a claim about the world at a date" as question 2 — what a missed review produces, the production re-score as an event rather than a date, and the three ways a finding may close.
|
||||
|
||||
### T05 — Register index
|
||||
|
||||
```task
|
||||
id: RISK-WP-0001-T05
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
|
|
@ -210,11 +218,13 @@ arriving, and it is worth a note in the residuals rather than a wider table.
|
|||
**Output:** `REGISTER.md`, its generator, and the front-matter contract the
|
||||
generator relies on written down where a reporter will see it.
|
||||
|
||||
Completed 2026-08-19. `REGISTER.md`, generated by `tools/register_index.py` from the finding front-matter, with separate Constraints, Embargoes and Notes sections so a lower headline cannot hide a higher constraint. The filing contract is in `findings/README.md`, where a reporter will meet it. `make check` fails if the index is stale.
|
||||
|
||||
### T06 — Grade the three open findings
|
||||
|
||||
```task
|
||||
id: RISK-WP-0001-T06
|
||||
status: todo
|
||||
status: done
|
||||
priority: high
|
||||
```
|
||||
|
||||
|
|
@ -240,11 +250,13 @@ message to that repo, not as an edit in it.
|
|||
|
||||
**Acceptance:** no `unset` field remains in `findings/`.
|
||||
|
||||
Completed 2026-08-19. `docs/rulings/2026-08-19-first-grading.md`. `RISK-F-0001` critical, embargoed, escalated on trigger 1 — the INTENT question about whether governing access counts as exposure is answered yes. `RISK-F-0002` medium today with a `high` constraint on `RISK-F-0001`'s remediation, filed as a **peer**, and escalated only on the ordering, against the reporter's own reading. `RISK-F-0003` high, embargoed, no escalation. No `unset` field remains.
|
||||
|
||||
### T07 — Rule on what is waiting outside the register
|
||||
|
||||
```task
|
||||
id: RISK-WP-0001-T07
|
||||
status: todo
|
||||
status: done
|
||||
priority: medium
|
||||
```
|
||||
|
||||
|
|
@ -267,11 +279,13 @@ The last three live in NetKingdom's *Tenancy Posture*, a draft, and filing them
|
|||
here does not amend it. A finding may say a standard is wrong; it cannot change
|
||||
one.
|
||||
|
||||
Completed 2026-08-19. `docs/rulings/2026-08-19-second-grading.md`. Four filed — `RISK-F-0004` (tenant-engine), `RISK-F-0005` (audit-core), `RISK-F-0006` (apps-pg, escalated on spend), `RISK-F-0007` (the unverified tenant boundary, escalated on ownership, `fix_owner` deliberately `unset`). Two ruled notes — `RISK-N-0001` noisy neighbours, `RISK-N-0002` erasure-versus-audit — each with an event to be re-read at rather than a date. Filing `RISK-F-0007` does not amend *Tenancy Posture*.
|
||||
|
||||
### T08 — Nag
|
||||
|
||||
```task
|
||||
id: RISK-WP-0001-T08
|
||||
status: todo
|
||||
status: done
|
||||
priority: low
|
||||
```
|
||||
|
||||
|
|
@ -285,6 +299,8 @@ nothing. A human or the custodian acts on the output.
|
|||
Runs from a `Makefile` target in this repo, in the same shape as the sibling
|
||||
`policy-nexus` `make check`.
|
||||
|
||||
Completed 2026-08-19. `tools/register_check.py` behind `make check`: ungraded fields, overdue reviews, stalls at twice the interval, embargoes overdue for re-decision, escalations awaiting the operator, and what is owed at the production transition. Report only — it writes nothing and changes no field.
|
||||
|
||||
## Sequencing
|
||||
|
||||
T01 first — the floor it sets is what T02, T04, T05 and T07 lean on.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue