From 674bd416357cb3607ab1fb888cfc5ae41d55111f Mon Sep 17 00:00:00 2001 From: tegwick Date: Thu, 20 Aug 2026 23:36:44 +0200 Subject: [PATCH] RISK-F-0008 accepted: no external determination, policy set instead MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The triggers survive as what ends the acceptance rather than as what starts a purchase. Accepted is not closed — it keeps its cadence, and audit-core's two questions stay open under it. Co-Authored-By: Claude Opus 5 --- REGISTER.md | 3 +- ...008-audit-retention-legal-basis-assumed.md | 53 +++++++++++++++---- 2 files changed, 43 insertions(+), 13 deletions(-) diff --git a/REGISTER.md b/REGISTER.md index ffa23de..830d295 100644 --- a/REGISTER.md +++ b/REGISTER.md @@ -9,7 +9,7 @@ Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. La | ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Cadence | Next check | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | [RISK-F-0009](findings/RISK-F-0009-openbao-deny-set-covers-a-third-of-high-risk-lanes.md) | agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest | railiance-platform | **high** | embargoed | none | railiance-platform | open | 1h (1) | **due** | -| [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **required** (t2, partially-answered) | risk-nexus | open | instant (0) | **due** | +| [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **answered** (t2, answered) | risk-nexus | accepted | instant (0) | **due** | | [RISK-F-0007](findings/RISK-F-0007-unverified-tenant-boundary.md) | No consumer's tenant boundary is verified anywhere | estate | **high** | embargoed | **answered** (t4, assigned) | per-consumer, on request | accepted | instant (0) | **due** | | [RISK-F-0006](findings/RISK-F-0006-apps-pg-no-backup-configured.md) | apps-pg has no backup configured at all: R0 means no recovery | railiance-platform | **high** | embargoed | **answered** (t3, approved) | railiance-platform | open | 1h (1) | **due** | | [RISK-F-0005](findings/RISK-F-0005-audit-core-unfiltered-read-path.md) | audit-core read path applies no tenant filter; the bound is deployment, not code | audit-core | medium | embargoed | none | audit-core | open | 1h (1) | **due** | @@ -35,7 +35,6 @@ Silence never buys a softer grade — see `docs/method/dependencies.md`. | --- | --- | --- | --- | --- | | RISK-F-0009 | railiance-platform | embargo lifts on coverage; live verification would refine the grade but is not required for it | the eight uncovered paths stand as recorded and the finding is re-raised | 2026-09-03 | | RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 | -| RISK-F-0008 | the-custodian | fixes when the estate stops running on an assumption | the assumption is recorded in the register as an assumption | 2026-11-17 | | RISK-F-0007 | user-engine | likelihood falls for user-engine if a verification exists; a defect becomes its own finding if not | the on-request path is recorded as having produced no answer, which makes the acceptance itself unsupported and is escalated | 2026-09-03 | | RISK-F-0006 | railiance-platform | embargo lifts on a demonstrated restore; the approved spend becomes a real figure | recorded as stalled with approval already granted, which is the worst kind of stall | 2026-09-18 | | RISK-F-0005 | audit-core | likelihood rises to L3 if any other production credential carries may_read | graded on the sender alone, as stated; the wider question is recorded as unanswered | 2026-09-19 | diff --git a/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md b/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md index 9e6f725..a56ff68 100644 --- a/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md +++ b/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md @@ -2,7 +2,7 @@ id: RISK-F-0008 type: finding title: "The legal basis for retaining audit facts against an erasure request has been assumed, never established" -status: open +status: accepted reported_by: audit-core reported_via: audit-core routed_by: audit-core @@ -29,17 +29,20 @@ publication_subtitle: "The estate retains personal data in audit records on grou revision: "graded-1" last_reviewed: "2026-08-20" review_interval: 6m -escalation: required +escalation: answered escalation_trigger: 2 -escalation_status: partially-answered +escalation_status: answered +accepted_by: the-custodian +accepted_on: "2026-08-20" +accepted_until: "the estate holds a real person's data, or a counterparty requires a stated position" escalation_answered: "2026-08-20" escalation_answered_by: the-custodian escalation_act: rule decision: "identity in audit records: opaque subject ids preferred, agent identifiers where possible, operator credentials only where necessary, policy decisions tracked to the responsible party; zone-level privacy guarantees may raise the floor" outstanding: "a defensible retention period per category (waits on audit-core's co-residency horizon), and the trigger list for buying an external answer" determination: RISK-REG-0001 -last_checked: "2026-08-20T10:02:41Z" -next_check: "2026-08-20T10:02:41Z" +last_checked: "2026-08-20T21:36:44Z" +next_check: "2026-08-20T21:36:44Z" cadence: instant clean_streak: 0 waiting_on: @@ -49,12 +52,6 @@ waiting_on: would_change: "a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only" default: "encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable" default_at: "2026-11-17" - - who: the-custodian - what: "rule the trigger list for buying an external determination" - since: "2026-08-19" - would_change: "fixes when the estate stops running on an assumption" - default: "the assumption is recorded in the register as an assumption" - default_at: "2026-11-17" graded_by: risk-nexus ruling: RISK-RULING-2026-08-19-C --- @@ -328,3 +325,37 @@ waits on the co-residency horizon, and the trigger list for buying an external determination. The record is reviewed every 90 days with this finding, or immediately on any trigger. - **2026-08-20** — not clean: The determination now exists: RISK-REG-0001 states the grounds per category and names duration as the weak point. Cadence instant → instant; checked again immediately. + +## Operator decision — 2026-08-20: no external determination, and a policy set instead + +Ruled: **the estate will not buy an external determination while it is +building.** The internal determination (`RISK-REG-0001`) stands as the recorded +position, and the finding moves to `accepted` — deliberately carried, with a +named accepter and a condition that ends it. + +That is not the same as the trigger list being rejected. The triggers survive +as what ends the acceptance: a real person's data, or a counterparty requiring +a stated position. What was declined is spending money in advance of either. + +**The compensating control is the thing that makes this defensible.** Rather +than defer the question, the operator directed that the estate **define and +keep a set of legal policies for reuse**, because future work contexts will +need specific positions in place and should retrieve them rather than research +them. + +`docs/regulatory/policies/` now catalogues thirteen, keyed by activation +condition. Two of them turned out to be **already active and unowned**: +commercial and tax retention (`RISK-POL-0009`), and the e-invoicing receiving +obligation (`RISK-POL-0012`), live since 2025 with no system in the estate +named as the receiving point. + +Finding an unnoticed live obligation in the first hour of building the +catalogue is the argument for having built it. The reason this repo exists is +that regulation was previously "consulted and discarded"; a set that answers +"what applies if we do X" before anyone does X is the opposite of that. + +**Still open under the acceptance**, and unchanged by this ruling: `audit-core` +on whether a keyed commitment restores erasability, and the `platform-pg` +co-residency horizon that decides whether the stated retention periods are +achievable. An accepted risk still gets checked. +- **2026-08-20** — not clean: Trigger list ruled: no external determination in build mode; accepted with the legal policy set as the compensating control. Cadence instant → instant; checked again immediately.