Work the register due list, and add the one-check-per-sitting rule

Nine records checked. Five clean and climbed to 1h: RISK-F-0003, 0004,
0005, 0006, 0009 and RISK-REG-0001. Three moved and stay at instant —
RISK-F-0002 (RISK-V-0001 found the flex-auth-ops-warden policy admits no
ingress, so the live question there is now availability rather than
attestation), RISK-F-0007 (the on-request path walked for the first time
as RISK-V-0002), RISK-F-0008 (the determination now exists).

The rule: a finding recorded as moved is not clean-checked in the same
sitting. Re-reading your own keystrokes and climbing produces a rung that
says the world held still when what held still was the last five minutes.
The rung carries stability information or it carries nothing.

record_check.py now handles regulatory records as well as findings.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-20 12:03:12 +02:00
parent 2ebdc133bc
commit 56b8d61583
12 changed files with 116 additions and 36 deletions

View file

@ -8,10 +8,10 @@ determined: "2026-08-20"
finding: RISK-F-0008
sources_read: "GDPR Arts 5, 6, 17, 21, 32; Recitals 49, 65; HGB §257; AO §147"
external_review: none
last_checked: "2026-08-20T05:25:00Z"
next_check: "2026-08-20T05:25:00Z"
cadence: instant
clean_streak: 0
last_checked: "2026-08-20T10:02:42Z"
next_check: "2026-08-20T11:02:42Z"
cadence: 1h
clean_streak: 1
---
# RISK-REG-0001 — the retention basis, written down
@ -113,3 +113,7 @@ argument avoided by holding less data is better than a strong one relied upon.
happened.
Reviewed every 90 days with `RISK-F-0008`, or immediately on any trigger.
## Reviews
- **2026-08-20** — clean check: grounds unchanged; still waiting on audit-core's co-residency horizon. Cadence instant → 1h (1 clean in a row); next check 2026-08-20 11:02Z.