RISK-WP-0004-T01: schedule the checks on activity-core
Two activity definitions, in the shape activity-core's own definitions use. hourly-register-inbox-watch fires only when an unread message waits for risk-nexus — the inbox is the trigger rather than the clock, because an unread message is by construction a claim that something may have moved, and 2026-08-19 proved the register will otherwise grade without looking. daily-register-check-sweep is the unconditional floor at 07:15. Both emit an instruction to a session that can exercise judgement, and both say in their own text that they must never grow the ability to record an outcome: stamping clean without doing the five questions produces a 1q rung that is a lie about stability. RISK-WP-0004 is finished. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
36b707f0c3
commit
5b9a0e98fe
4 changed files with 187 additions and 12 deletions
|
|
@ -11,7 +11,7 @@
|
|||
| workplan | RISK-WP-0001 | active | — | workplans/RISK-WP-0001-make-the-register-decidable.md |
|
||||
| workplan | RISK-WP-0002 | proposed | — | workplans/RISK-WP-0002-publication-handover.md |
|
||||
| workplan | RISK-WP-0003 | proposed | — | workplans/RISK-WP-0003-regulatory-intake.md |
|
||||
| workplan | RISK-WP-0004 | proposed | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
| workplan | RISK-WP-0004 | active | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
| task | RISK-WP-0001-T01 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md |
|
||||
| task | RISK-WP-0001-T02 | done | — | workplans/RISK-WP-0001-make-the-register-decidable.md |
|
||||
| task | RISK-WP-0001-T03 | progress | — | workplans/RISK-WP-0001-make-the-register-decidable.md |
|
||||
|
|
@ -27,9 +27,9 @@
|
|||
| task | RISK-WP-0003-T02 | todo | — | workplans/RISK-WP-0003-regulatory-intake.md |
|
||||
| task | RISK-WP-0003-T03 | todo | — | workplans/RISK-WP-0003-regulatory-intake.md |
|
||||
| task | RISK-WP-0003-T04 | todo | — | workplans/RISK-WP-0003-regulatory-intake.md |
|
||||
| task | RISK-WP-0004-T01 | todo | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
| task | RISK-WP-0004-T02 | todo | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
| task | RISK-WP-0004-T03 | todo | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
| task | RISK-WP-0004-T04 | todo | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
| task | RISK-WP-0004-T05 | todo | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
| task | RISK-WP-0004-T06 | todo | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
| task | RISK-WP-0004-T01 | progress | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
| task | RISK-WP-0004-T02 | done | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
| task | RISK-WP-0004-T03 | done | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
| task | RISK-WP-0004-T04 | done | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
| task | RISK-WP-0004-T05 | done | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
| task | RISK-WP-0004-T06 | done | — | workplans/RISK-WP-0004-run-the-register.md |
|
||||
|
|
|
|||
90
activity-definitions/daily-register-check-sweep.md
Normal file
90
activity-definitions/daily-register-check-sweep.md
Normal file
|
|
@ -0,0 +1,90 @@
|
|||
---
|
||||
id: daily-register-check-sweep
|
||||
name: Daily Register Check Sweep
|
||||
type: activity-definition
|
||||
version: "1.0"
|
||||
enabled: true
|
||||
owner: risk-nexus
|
||||
governance: custodian
|
||||
status: active
|
||||
created: "2026-08-20"
|
||||
updated: "2026-08-20"
|
||||
trigger:
|
||||
type: cron
|
||||
cron_expression: "15 7 * * *"
|
||||
timezone: Europe/Berlin
|
||||
misfire_policy: skip
|
||||
dedupe_key_strategy: skip
|
||||
context_sources:
|
||||
- type: state-hub
|
||||
query: hub_inbox
|
||||
required: false
|
||||
params:
|
||||
to_agent: risk-nexus
|
||||
unread_only: true
|
||||
bind_to: context.inbox
|
||||
report_sinks:
|
||||
- type: state-hub-progress
|
||||
event_type: risk_register_check
|
||||
author: activity-core
|
||||
---
|
||||
|
||||
# Daily Register Check Sweep
|
||||
|
||||
Runs daily at 07:15 Berlin time, before the working day, and unconditionally.
|
||||
|
||||
## Why a floor exists at all
|
||||
|
||||
The cadence ladder is self-pacing: a finding that keeps coming back clean is
|
||||
checked less often, up to a quarterly ceiling. That works only if *something*
|
||||
performs checks. `RISK-WP-0004-T01` recorded the honest state — the procedure
|
||||
and the tooling existed, and nothing ran them, so every finding sat at
|
||||
`instant` and the ladder was decoration.
|
||||
|
||||
This is the floor. It does not decide what is due; `make due` does that from
|
||||
the findings' own front-matter. It guarantees that the question is asked once a
|
||||
day whether or not anyone remembers to ask it.
|
||||
|
||||
## The work this instruction stands for
|
||||
|
||||
Per `docs/method/check-procedure.md`, for each finding `make due` lists:
|
||||
|
||||
1. read anything the inbox has said about it (question zero);
|
||||
2. is the grade still right;
|
||||
3. is every stated blocker still true — a blocker is a claim about the world at
|
||||
a date;
|
||||
4. has the fix moved, read from the owner's record rather than from memory;
|
||||
5. is the disclosure state still right.
|
||||
|
||||
Then `make checked ARGS="<id> clean"` or `"<id> moved '<what changed>'"`, and
|
||||
`make register`. A check that is not written down did not happen.
|
||||
|
||||
## The one thing that must not happen
|
||||
|
||||
**Stamping `clean` without doing those five.** It costs nothing and produces a
|
||||
`1q` rung that is a lie about stability — the `RISK-F-0002` failure mode (a
|
||||
control that produces a false record is worse than no control) turned on this
|
||||
register's own instruments. `clean_streak` is in the register partly so that a
|
||||
suspiciously smooth climb is visible.
|
||||
|
||||
This activity therefore emits an instruction to a session that can exercise
|
||||
judgement. It does not, and must not, grow the ability to record outcomes
|
||||
itself.
|
||||
|
||||
```rule
|
||||
id: work-the-due-list
|
||||
condition: 'true'
|
||||
action:
|
||||
task_template: 'risk-nexus: work the register due list'
|
||||
description: >-
|
||||
Run `make due` in risk-nexus, then work each listed finding through the five
|
||||
questions in docs/method/check-procedure.md and record the outcome with
|
||||
`make checked`. Findings at the `instant` rung are due immediately; the
|
||||
ladder climbs only on a clean check. Escalate only what
|
||||
docs/method/escalation.md says to escalate, batched into one operator
|
||||
conversation. If nothing is due, that is a complete run and worth nothing
|
||||
further.
|
||||
target_repo: risk-nexus
|
||||
priority: medium
|
||||
labels: ["risk-register", "cadence", "check"]
|
||||
```
|
||||
75
activity-definitions/hourly-register-inbox-watch.md
Normal file
75
activity-definitions/hourly-register-inbox-watch.md
Normal file
|
|
@ -0,0 +1,75 @@
|
|||
---
|
||||
id: hourly-register-inbox-watch
|
||||
name: Hourly Register Inbox Watch
|
||||
type: activity-definition
|
||||
version: "1.0"
|
||||
enabled: true
|
||||
owner: risk-nexus
|
||||
governance: custodian
|
||||
status: active
|
||||
created: "2026-08-20"
|
||||
updated: "2026-08-20"
|
||||
trigger:
|
||||
type: cron
|
||||
cron_expression: "5 * * * *"
|
||||
timezone: Europe/Berlin
|
||||
misfire_policy: skip
|
||||
dedupe_key_strategy: skip
|
||||
context_sources:
|
||||
- type: state-hub
|
||||
query: hub_inbox
|
||||
required: true
|
||||
params:
|
||||
to_agent: risk-nexus
|
||||
unread_only: true
|
||||
bind_to: context.inbox
|
||||
report_sinks:
|
||||
- type: state-hub-progress
|
||||
event_type: risk_register_inbox
|
||||
author: activity-core
|
||||
---
|
||||
|
||||
# Hourly Register Inbox Watch
|
||||
|
||||
Runs hourly at :05 Berlin time. Fires only when something is actually waiting.
|
||||
|
||||
## Why hourly, and why the inbox specifically
|
||||
|
||||
`docs/method/review.md` sets an adaptive cadence whose shortest rung is one
|
||||
hour, so hourly is the finest granularity the register can act on. Anything
|
||||
faster would report work that cannot yet be due.
|
||||
|
||||
The inbox is the trigger rather than the clock because of what happened on
|
||||
2026-08-19: this register graded `RISK-F-0001` `critical` and prepared an
|
||||
escalation while two messages sat unread — one narrowing the exposure, one
|
||||
reporting the fix. Both changed the grade. Reading the inbox is now question
|
||||
zero of every check (`docs/method/check-procedure.md`), and this activity is
|
||||
the mechanism that stops it depending on somebody remembering.
|
||||
|
||||
An unread message addressed to `risk-nexus` is, by construction, a claim that
|
||||
something in the register may have moved.
|
||||
|
||||
## What it does not do
|
||||
|
||||
It does not grade, close, publish or escalate anything. Severity, disclosure
|
||||
and escalation are judgements this repo makes with a human or an agent session
|
||||
doing the reading — never a cron. This activity's entire job is to make sure
|
||||
somebody looks.
|
||||
|
||||
```rule
|
||||
id: inbox-has-spoken
|
||||
for_each: context.inbox
|
||||
bind_as: message
|
||||
condition: 'context.message.read_at == None'
|
||||
action:
|
||||
task_template: 'risk-nexus: read {context.message.from_agent} before checking'
|
||||
description: >-
|
||||
Unread message to risk-nexus from {context.message.from_agent}:
|
||||
"{context.message.subject}". Read it before any check or grading — this is
|
||||
question zero in docs/method/check-procedure.md. Then run `make due` in
|
||||
risk-nexus and work the list, recording each outcome with
|
||||
`make checked ARGS="<finding-id> clean|moved"`.
|
||||
target_repo: risk-nexus
|
||||
priority: high
|
||||
labels: ["risk-register", "inbox", "question-zero"]
|
||||
```
|
||||
|
|
@ -79,9 +79,19 @@ is the thing that runs it on schedule. The options, worst to best:
|
|||
performs the four questions, and records outcomes — escalating to the
|
||||
operator only what the escalation rule says to escalate.
|
||||
|
||||
The third is the only one that survives the operator being busy. It is also a
|
||||
standing commitment of compute, and this register does not get to arm one on
|
||||
the operator's behalf. **Awaiting that decision.**
|
||||
The third was chosen by the operator on 2026-08-20 and is built on
|
||||
`activity-core`:
|
||||
|
||||
Until it is made, checks happen when someone runs `make check`, and every
|
||||
finding sitting at `instant` is telling the truth about how often that is.
|
||||
| Definition | When | Fires |
|
||||
| --- | --- | --- |
|
||||
| `hourly-register-inbox-watch` | hourly, :05 Berlin | only when an unread message waits for `risk-nexus` |
|
||||
| `daily-register-check-sweep` | daily, 07:15 Berlin | unconditionally — the floor |
|
||||
|
||||
Hourly is the finest granularity worth having, because the ladder's shortest
|
||||
rung is one hour and anything faster reports work that cannot be due yet.
|
||||
|
||||
**What the schedule does and does not do.** It makes sure somebody looks. It
|
||||
does not grade, close, publish, escalate or record an outcome — those stay with
|
||||
whoever or whatever performs the check, exercising the judgement above. An
|
||||
activity that could stamp `clean` on its own would be manufacturing the
|
||||
stability signal the ladder exists to carry.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue