RISK-F-0008 accepted: no external determination, policy set instead
The triggers survive as what ends the acceptance rather than as what starts a purchase. Accepted is not closed — it keeps its cadence, and audit-core's two questions stay open under it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
7f135f9e0f
commit
674bd41635
2 changed files with 43 additions and 13 deletions
|
|
@ -9,7 +9,7 @@ Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. La
|
|||
| ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Cadence | Next check |
|
||||
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
|
||||
| [RISK-F-0009](findings/RISK-F-0009-openbao-deny-set-covers-a-third-of-high-risk-lanes.md) | agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest | railiance-platform | **high** | embargoed | none | railiance-platform | open | 1h (1) | **due** |
|
||||
| [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **required** (t2, partially-answered) | risk-nexus | open | instant (0) | **due** |
|
||||
| [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **answered** (t2, answered) | risk-nexus | accepted | instant (0) | **due** |
|
||||
| [RISK-F-0007](findings/RISK-F-0007-unverified-tenant-boundary.md) | No consumer's tenant boundary is verified anywhere | estate | **high** | embargoed | **answered** (t4, assigned) | per-consumer, on request | accepted | instant (0) | **due** |
|
||||
| [RISK-F-0006](findings/RISK-F-0006-apps-pg-no-backup-configured.md) | apps-pg has no backup configured at all: R0 means no recovery | railiance-platform | **high** | embargoed | **answered** (t3, approved) | railiance-platform | open | 1h (1) | **due** |
|
||||
| [RISK-F-0005](findings/RISK-F-0005-audit-core-unfiltered-read-path.md) | audit-core read path applies no tenant filter; the bound is deployment, not code | audit-core | medium | embargoed | none | audit-core | open | 1h (1) | **due** |
|
||||
|
|
@ -35,7 +35,6 @@ Silence never buys a softer grade — see `docs/method/dependencies.md`.
|
|||
| --- | --- | --- | --- | --- |
|
||||
| RISK-F-0009 | railiance-platform | embargo lifts on coverage; live verification would refine the grade but is not required for it | the eight uncovered paths stand as recorded and the finding is re-raised | 2026-09-03 |
|
||||
| RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 |
|
||||
| RISK-F-0008 | the-custodian | fixes when the estate stops running on an assumption | the assumption is recorded in the register as an assumption | 2026-11-17 |
|
||||
| RISK-F-0007 | user-engine | likelihood falls for user-engine if a verification exists; a defect becomes its own finding if not | the on-request path is recorded as having produced no answer, which makes the acceptance itself unsupported and is escalated | 2026-09-03 |
|
||||
| RISK-F-0006 | railiance-platform | embargo lifts on a demonstrated restore; the approved spend becomes a real figure | recorded as stalled with approval already granted, which is the worst kind of stall | 2026-09-18 |
|
||||
| RISK-F-0005 | audit-core | likelihood rises to L3 if any other production credential carries may_read | graded on the sender alone, as stated; the wider question is recorded as unanswered | 2026-09-19 |
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
id: RISK-F-0008
|
||||
type: finding
|
||||
title: "The legal basis for retaining audit facts against an erasure request has been assumed, never established"
|
||||
status: open
|
||||
status: accepted
|
||||
reported_by: audit-core
|
||||
reported_via: audit-core
|
||||
routed_by: audit-core
|
||||
|
|
@ -29,17 +29,20 @@ publication_subtitle: "The estate retains personal data in audit records on grou
|
|||
revision: "graded-1"
|
||||
last_reviewed: "2026-08-20"
|
||||
review_interval: 6m
|
||||
escalation: required
|
||||
escalation: answered
|
||||
escalation_trigger: 2
|
||||
escalation_status: partially-answered
|
||||
escalation_status: answered
|
||||
accepted_by: the-custodian
|
||||
accepted_on: "2026-08-20"
|
||||
accepted_until: "the estate holds a real person's data, or a counterparty requires a stated position"
|
||||
escalation_answered: "2026-08-20"
|
||||
escalation_answered_by: the-custodian
|
||||
escalation_act: rule
|
||||
decision: "identity in audit records: opaque subject ids preferred, agent identifiers where possible, operator credentials only where necessary, policy decisions tracked to the responsible party; zone-level privacy guarantees may raise the floor"
|
||||
outstanding: "a defensible retention period per category (waits on audit-core's co-residency horizon), and the trigger list for buying an external answer"
|
||||
determination: RISK-REG-0001
|
||||
last_checked: "2026-08-20T10:02:41Z"
|
||||
next_check: "2026-08-20T10:02:41Z"
|
||||
last_checked: "2026-08-20T21:36:44Z"
|
||||
next_check: "2026-08-20T21:36:44Z"
|
||||
cadence: instant
|
||||
clean_streak: 0
|
||||
waiting_on:
|
||||
|
|
@ -49,12 +52,6 @@ waiting_on:
|
|||
would_change: "a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only"
|
||||
default: "encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable"
|
||||
default_at: "2026-11-17"
|
||||
- who: the-custodian
|
||||
what: "rule the trigger list for buying an external determination"
|
||||
since: "2026-08-19"
|
||||
would_change: "fixes when the estate stops running on an assumption"
|
||||
default: "the assumption is recorded in the register as an assumption"
|
||||
default_at: "2026-11-17"
|
||||
graded_by: risk-nexus
|
||||
ruling: RISK-RULING-2026-08-19-C
|
||||
---
|
||||
|
|
@ -328,3 +325,37 @@ waits on the co-residency horizon, and the trigger list for buying an external
|
|||
determination. The record is reviewed every 90 days with this finding, or
|
||||
immediately on any trigger.
|
||||
- **2026-08-20** — not clean: The determination now exists: RISK-REG-0001 states the grounds per category and names duration as the weak point. Cadence instant → instant; checked again immediately.
|
||||
|
||||
## Operator decision — 2026-08-20: no external determination, and a policy set instead
|
||||
|
||||
Ruled: **the estate will not buy an external determination while it is
|
||||
building.** The internal determination (`RISK-REG-0001`) stands as the recorded
|
||||
position, and the finding moves to `accepted` — deliberately carried, with a
|
||||
named accepter and a condition that ends it.
|
||||
|
||||
That is not the same as the trigger list being rejected. The triggers survive
|
||||
as what ends the acceptance: a real person's data, or a counterparty requiring
|
||||
a stated position. What was declined is spending money in advance of either.
|
||||
|
||||
**The compensating control is the thing that makes this defensible.** Rather
|
||||
than defer the question, the operator directed that the estate **define and
|
||||
keep a set of legal policies for reuse**, because future work contexts will
|
||||
need specific positions in place and should retrieve them rather than research
|
||||
them.
|
||||
|
||||
`docs/regulatory/policies/` now catalogues thirteen, keyed by activation
|
||||
condition. Two of them turned out to be **already active and unowned**:
|
||||
commercial and tax retention (`RISK-POL-0009`), and the e-invoicing receiving
|
||||
obligation (`RISK-POL-0012`), live since 2025 with no system in the estate
|
||||
named as the receiving point.
|
||||
|
||||
Finding an unnoticed live obligation in the first hour of building the
|
||||
catalogue is the argument for having built it. The reason this repo exists is
|
||||
that regulation was previously "consulted and discarded"; a set that answers
|
||||
"what applies if we do X" before anyone does X is the opposite of that.
|
||||
|
||||
**Still open under the acceptance**, and unchanged by this ruling: `audit-core`
|
||||
on whether a keyed commitment restores erasability, and the `platform-pg`
|
||||
co-residency horizon that decides whether the stated retention periods are
|
||||
achievable. An accepted risk still gets checked.
|
||||
- **2026-08-20** — not clean: Trigger list ruled: no external determination in build mode; accepted with the legal policy set as the compensating control. Cadence instant → instant; checked again immediately.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue