diff --git a/workplans/RISK-WP-0001-make-the-register-decidable.md b/workplans/RISK-WP-0001-make-the-register-decidable.md index 8f3b7c8..e5f0552 100644 --- a/workplans/RISK-WP-0001-make-the-register-decidable.md +++ b/workplans/RISK-WP-0001-make-the-register-decidable.md @@ -250,7 +250,9 @@ message to that repo, not as an edit in it. **Acceptance:** no `unset` field remains in `findings/`. -Completed 2026-08-19. `docs/rulings/2026-08-19-first-grading.md`. `RISK-F-0001` critical, embargoed, escalated on trigger 1 — the INTENT question about whether governing access counts as exposure is answered yes. `RISK-F-0002` medium today with a `high` constraint on `RISK-F-0001`'s remediation, filed as a **peer**, and escalated only on the ordering, against the reporter's own reading. `RISK-F-0003` high, embargoed, no escalation. No `unset` field remains. +Completed 2026-08-19, in three rounds — the third after reading the inbox, which is recorded in `docs/rulings/2026-08-19-third-grading.md` as this repo's own defect: `RISK-F-0001` was graded `critical` and escalated while two messages that changed the grade sat unread. Corrected to `high` and closed `fixed` the same day; both escalations withdrawn. + +`docs/rulings/2026-08-19-first-grading.md`. `RISK-F-0001` critical, embargoed, escalated on trigger 1 — the INTENT question about whether governing access counts as exposure is answered yes. `RISK-F-0002` medium today with a `high` constraint on `RISK-F-0001`'s remediation, filed as a **peer**, and escalated only on the ordering, against the reporter's own reading. `RISK-F-0003` high, embargoed, no escalation. No `unset` field remains. ### T07 — Rule on what is waiting outside the register @@ -336,6 +338,17 @@ notes out. ## Residuals +- **Publication handover.** `RISK-F-0001` (fixed) and `RISK-F-0008` (a + question, published as a question) are `disclosure: public` with + `publication: pending-handover`. Handing them to `policy-nexus` under its + publication contract is the first item of the next workplan; nothing in this + one publishes. +- **Inbox before grading.** Added to `docs/method/review.md` as question zero + after this workplan graded `RISK-F-0001` `critical` while its fix notice sat + unread. The mechanism is a habit, not a check — if it slips again, the answer + is a check in `make check` against message timestamps, and that is a task, + not a residual. + - Publication of these instruments through `policy-nexus` is a later workplan, and only if T02 concludes anything here should be public. - Regulatory intake — the second half of this repo's remit — is untouched here.