RISK-WP-0005 T02, T03, T04: intake, the transition, and an honest README

T02: docs/method/intake.md names all four sources INTENT claims and
builds the two that had none. An incident files first and grades within
the hour, carries first_observed because obligations run from it, sits at
instant until it is over, and escalates immediately rather than batched —
a 72-hour notification clock outranks the rule that protects the
operator's attention. External report has no address anywhere in the
estate, and where one lives is policy-nexus's and the custodian's, so it
is routed with a proposal rather than invented here.

T03: the production transition defined by what is held rather than what
was announced — the first moment any system holds real external data,
which can happen by accident and cannot be reversed. Declared by the
custodian; noticed and asked about by this register. Lists what fires:
five re-scores, two acceptances ending, six policies activating.

T04: the README no longer claims a surface this repo does not have.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-21 08:31:44 +02:00
parent ba3b3f686d
commit 449307bea2
4 changed files with 204 additions and 2 deletions

View file

@ -1,7 +1,12 @@
# risk-nexus
Risk register and regulatory intake for the estate. Serves
`risk.coulomb.social`. Owned by `the-custodian`.
Risk register and regulatory intake for the estate. Owned by `the-custodian`.
**It does not serve anything yet.** `INTENT.md` names `risk.coulomb.social` as
the eventual surface; today publication runs through `policy-nexus` and three
documents are waiting for an address. Recorded here rather than left as a
claim, because a stated surface that does not exist is the class of thing this
register grades other repos down for.
Holds findings — security, architecture, operational, compliance — with a
severity, an owner and a date; decides whether and when each is published; and