RISK-WP-0005 T02, T03, T04: intake, the transition, and an honest README

T02: docs/method/intake.md names all four sources INTENT claims and
builds the two that had none. An incident files first and grades within
the hour, carries first_observed because obligations run from it, sits at
instant until it is over, and escalates immediately rather than batched —
a 72-hour notification clock outranks the rule that protects the
operator's attention. External report has no address anywhere in the
estate, and where one lives is policy-nexus's and the custodian's, so it
is routed with a proposal rather than invented here.

T03: the production transition defined by what is held rather than what
was announced — the first moment any system holds real external data,
which can happen by accident and cannot be reversed. Declared by the
custodian; noticed and asked about by this register. Lists what fires:
five re-scores, two acceptances ending, six policies activating.

T04: the README no longer claims a surface this repo does not have.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-21 08:31:44 +02:00
parent ba3b3f686d
commit 449307bea2
4 changed files with 204 additions and 2 deletions

View file

@ -1,7 +1,12 @@
# risk-nexus
Risk register and regulatory intake for the estate. Serves
`risk.coulomb.social`. Owned by `the-custodian`.
Risk register and regulatory intake for the estate. Owned by `the-custodian`.
**It does not serve anything yet.** `INTENT.md` names `risk.coulomb.social` as
the eventual surface; today publication runs through `policy-nexus` and three
documents are waiting for an address. Recorded here rather than left as a
claim, because a stated surface that does not exist is the class of thing this
register grades other repos down for.
Holds findings — security, architecture, operational, compliance — with a
severity, an owner and a date; decides whether and when each is published; and

93
docs/method/intake.md Normal file
View file

@ -0,0 +1,93 @@
---
id: RISK-METHOD-INTAKE
type: method
title: "Intake: the four sources, including the two that had no path"
status: adopted
owner: risk-nexus
adopted: "2026-08-21"
workplan: RISK-WP-0005-T02
review_interval: 6m
---
# Intake
`INTENT.md` claims intake "from any source: research, review, incident,
external report". Until 2026-08-21 two of those four had no path at all, and
every finding in the register had arrived from a repo reading its own code.
A register that only receives self-assessments is a self-assessment aggregator.
That is a respectable thing to be and it is not what the intent says.
## The four sources
| Source | Path | State |
| --- | --- | --- |
| Research | a repo or agent files against `findings/README.md` | working, nine findings |
| Review | same, usually against a ladder or standard | working, most of the nine |
| **Incident** | below | new |
| **External report** | below — and the address is not this repo's to create | routed |
## Incident
An incident is a finding about something happening **now** rather than a latent
defect. The difference is not severity; it is that someone is exercising it, or
the loss is occurring, while the record is being written.
### What is different
- **File first, grade later.** The normal order is reversed: get the record
into `findings/` with what is known, and grade it in the same hour rather
than in the same sitting. An ungraded incident is still a record; an unwritten
one is nothing.
- **`incident: true` and a `first_observed` timestamp**, both in front-matter.
The timestamp matters more than the grade, because obligations run from it.
- **Cadence starts at `instant` and stays there** until the incident is over.
That is the ladder's existing behaviour and needs no special case: something
that keeps moving keeps resetting.
- **The 72-hour clock.** If personal data is or may be involved,
`RISK-POL-0005` (GDPR Arts 3334) requires notification within 72 hours of
becoming aware. **`first_observed` is what starts that clock**, and this is
the one place the register puts a hard deadline on itself. Escalation is
immediate under trigger 1 or 2 — not batched, notwithstanding the batching
rule, because batching exists to protect the operator's attention and a
72-hour clock outranks that.
- **Severity is scored on what is happening, not what could.** The `L4`
likelihood band — "already happening" — exists for exactly this and is
otherwise almost unused.
### What is not different
Ownership, routing, and the boundary. The repo that owns the system owns the
response; this register records, grades, escalates and keeps the clock. A risk
register that runs incident response is a second engineering team with a
stopwatch.
## External report
Someone outside the estate finding something and having somewhere to send it.
**No such place exists.** There is no `security.txt` anywhere in the estate, no
published address, and no route from an outsider to this register. If someone
found a flaw in a coulomb.social surface tomorrow, their options would be to
guess an email address or say nothing.
**Where that address lives is not this repo's decision.** It is a published
surface, which makes it `policy-nexus`'s to serve and the custodian's to
approve. Routed on 2026-08-21 with a proposal:
- a `security.txt` (RFC 9116) at `policy.coulomb.social/.well-known/`, naming
a contact and a preferred language, with an expiry date as the RFC requires;
- reports arriving there routed to `risk-nexus` and filed like any other
finding, with `reported_by: external`;
- **no promise of a bounty, a timeline, or safe harbour.** The ask is a route
in, not a commitment out. A published disclosure policy is a later decision
and a heavier one.
Until that exists, this register's claim to accept external reports is
aspirational and `STATE.md` says so.
## What all four share
The reporter says what is true and how they know. This register says how bad it
is and who hears about it. Nothing in this document changes that boundary —
including for incidents, where the temptation to take over is strongest.

View file

@ -0,0 +1,91 @@
---
id: RISK-METHOD-PRODUCTION
type: method
title: "The production transition: what expires, and who says when"
status: proposed
owner: the-custodian
drafted_by: risk-nexus
drafted: "2026-08-21"
workplan: RISK-WP-0005-T03
review_interval: 6m
---
# The production transition
Five findings owe a re-score here. One acceptance **expires** here. Several
dormant legal policies activate here. And until 2026-08-21 nobody had defined
the event, named who declares it, or told the repos that carry the obligations.
An acceptance that expires on an undefined event expires on nobody's calendar.
**Status: `proposed`.** The definition is the custodian's; the plumbing is
this repo's.
## Proposed definition
> **The production transition is the first moment any system in the estate
> holds, processes or decides about the data of a real external person or
> tenant.**
Deliberately not: a launch announcement, a version number, a deployment to a
cluster named production, or a declaration made in advance. All four can be
true while nothing real is at stake, and all four can be false on the day
something is.
Two consequences worth stating, because they are what make the definition
usable:
- **It can happen by accident.** A single real signup, a migrated contact list,
one counterparty's document sent through a pipeline for testing. Which is
why it is defined by what is held rather than by what was announced.
- **It is not reversible.** Deleting the data afterwards does not un-transition
the estate; it changes the exposure and not the fact that the estate is now
the kind of thing that holds real data.
## Who declares it
The operator, through `the-custodian`. Not this register: `INTENT.md` keeps
"deciding what canon says" and estate-level facts with the custodian, and a
risk register that unilaterally declares the estate to be in production has
appointed itself.
What this register does is **notice and ask**. Any finding, verification or
policy check that turns up real external data in a system triggers one question
to the custodian: *has the transition happened?* The answer is theirs; the
record is ours.
## What fires on the day
| Obligation | Carried by | Count today |
| --- | --- | --- |
| Re-score every finding with `production_rescore: true` | this register | 5 |
| `RISK-F-0007`'s acceptance expires — the unverified tenant boundary stops being carried | this register, escalating | 1 |
| `RISK-POL-0001`, `0003`, `0004`, `0005`, `0008` activate; `0002` fully | owning repos | 6 policies |
| `RISK-F-0008`'s acceptance ends — the retention basis stops being an internal determination | this register | 1 |
`make check` lists the first two under "owed at the production transition"
today, so the size of the obligation is visible before the day rather than
discovered on it.
## How the register hears about it
Three routes, in order of reliability:
1. **The custodian says so**, in a message. Preferred, and the only one that is
also a decision.
2. **A finding or verification turns up real external data**, and this register
asks. This is the route that works when nobody remembered to declare.
3. **A legal policy activates on its own condition** — the accessibility or
data-subject-rights entries in `docs/regulatory/policies/` fire on facts
about the world, not on a declaration, and a repo consulting one is evidence
the transition may have happened.
Route 2 exists because route 1 is exactly the kind of announcement that gets
skipped in a busy week, and the estate has already demonstrated (`RISK-POL-0012`)
that an obligation can be live for nineteen months without anyone noticing.
## What this document does not do
It does not schedule the transition, gate it, or require anything before it. In
build mode a finding is information — that is unchanged. This says only what
becomes true on a day that will arrive whether or not it is planned.

View file

@ -142,6 +142,19 @@ comes back.
> *Added 2026-08-19 (`RISK-WP-0001-T07`).* Forced by `RISK-F-0006`, where the
> defect is an absent backup and the reach reading produced nonsense.
## Live incidents
Everything above assumes a latent defect — something reachable that nobody is
currently reaching. When someone is, three things change:
- **Likelihood is `L4`.** The band means "already happening" and this is what
it is for.
- **Impact is scored on what has occurred plus what is still reachable**, not
on the worst case. An incident in progress has facts; use them.
- **The grade is provisional and expected to move.** File first, grade within
the hour, re-grade as facts arrive. `docs/method/intake.md` has the rest,
including the 72-hour clock that `first_observed` starts.
## The floor
`INTENT.md`: if a finding would not change anyone's decision, it is a note,