Adaptive check cadence: the interval is earned, not assigned

Operator ruling 2026-08-20. Severity no longer sets the review interval.
A check that comes back clean climbs one rung — instant, 1h, 8h, 24h,
48h, 96h, 7d, 14d, 1mo, 1q — and anything wrong drops straight back to
instant. A quarter is the ceiling. The operator may defer an instant
finding to a stated date; that is the only other way off the bottom rung.

The rung is the point: it says how stable the estate has been on that
matter, which is information severity does not carry. Volatile things get
attention automatically; quiet things stop consuming it; neither
judgement has to be made by a person who might be busy.

Escalation trigger 5 rebased onto the ladder — fourteen days at the
bottom rung, whether that is failing checks or no checks.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-20 07:43:51 +02:00
parent 8b204d0411
commit 42bbf5d2dc
17 changed files with 429 additions and 148 deletions

View file

@ -10,21 +10,24 @@ date_reported: "2026-08-19"
system: ops-warden
environment: production
fix_owner: ops-warden
fix_tracking: WARDEN-WP-0032-T05
fix_tracking: WARDEN-WP-0032-T05 (done) / T06 (structural)
# Graded by risk-nexus 2026-08-19 — docs/rulings/2026-08-19-first-grading.md
severity: high
severity_at_production: high
severity: medium
severity_at_production: medium
severity_superseded: "high (2026-08-19) — the CLI-layer gap is mitigated"
impact: I4
likelihood: L2
fidelity_modifier: false
production_rescore: false
disclosure: embargoed
embargo_condition: "the five exec_capable lanes graded under WARDEN-WP-0032-T05"
embargo_condition: "RISK-F-0009 resolved — the OpenBao deny set covers every high-risk lane with a KV path"
embargo_since: "2026-08-19"
embargo_review: "2026-09-18"
escalation: none
last_reviewed: "2026-08-19"
review_by: "2026-09-18"
last_checked: "2026-08-20T05:40:00Z"
next_check: "2026-08-20T05:40:00Z" # due now: the ladder starts at instant
cadence: instant
clean_streak: 0
graded_by: risk-nexus
ruling: RISK-RULING-2026-08-19
---
@ -190,3 +193,35 @@ Reasoning: `docs/rulings/2026-08-19-first-grading.md`.
Open at review: OpenBao policy coverage of the five paths; whether
`WARDEN-WP-0032-T05` has landed; whether any compliance evidence cites
`ADR-0004` as implemented.
## Check — 2026-08-20: mitigated on one layer, `high` → `medium`
`ops-warden` reports all 17 high-risk lanes now exiting 7 on
`warden access --fetch` with `WARDEN_AGENT_ID` set, verified under
`WARDEN-WP-0032-T05`/`T06`. The 14 ungraded lanes are graded; the boundary
fires. The live gap this finding described is closed on the CLI layer.
**Not clean, so the cadence stays at `instant`.** Something moved, and under
the ladder that resets the clock rather than earning a longer one. The next
check is the one that can start climbing.
**`high` → `medium`.** What remains is the omission shape rather than the
instance: whether a future lane can still be added without a grade. That is
`WARDEN-WP-0032-T06`, and the durable form of the operator's maturity-context
rule is `zone-engine`'s (`RISK-N-0004`). Not `low`, because "graded by hand
once" is not the same as "cannot be ungraded again".
**The embargo condition changed rather than being met.** The original condition
— the five `exec_capable` lanes graded — is satisfied. But `RISK-F-0009` shows
the *second* layer, the OpenBao deny set that protects the direct `bao kv get`
path, covers 6 of 17 high-risk lanes. Publishing this finding now would name
lanes that are still reachable by the path this control exists to close. The
condition is therefore re-pointed at `RISK-F-0009`.
That is the disclosure rule working across two findings rather than one: what
matters is whether the text shortens a path, not whether this particular
finding's own fix has landed.
**Verification limit, recorded rather than assumed:** the mitigation is
`ops-warden`'s report and this register has not probed it. Their operator token
is expired, which is also why `RISK-F-0009` rests on a file comparison.