Legal policy set: written before needed, dormant until a context activates

Operator ruling: no external determination in build mode, but keep the
set of legal policies for reuse when a work context needs one in place.

docs/regulatory/policies/ catalogues thirteen, keyed by activation
condition rather than by regime, with a retrieval table so a context
pulls a slice: first real user account pulls six of them; a
consumer-facing product in Germany pulls those plus accessibility. Two
are already active and nobody had noticed — commercial and tax retention,
and the e-invoicing receiving obligation that has been live since 2025
with no named owner in the estate. Four written in full; the rest carry
their trigger now and get their text when a context approaches, which is
the point.

RISK-POL-0011 is the argument for the whole catalogue: accessibility
cannot be retrofitted cheaply, so a policy retrieved at launch is a
rebuild while one read at design time is just a constraint.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-20 23:36:22 +02:00
parent 3a0ba5d427
commit 7f135f9e0f
7 changed files with 332 additions and 13 deletions

View file

@ -2,10 +2,12 @@
id: RISK-METHOD-ESCALATION
type: method
title: "Escalation: what reaches the operator personally"
status: proposed
status: adopted
owner: the-custodian
drafted_by: risk-nexus
drafted: "2026-08-19"
adopted: "2026-08-20"
adopted_by: the-custodian
workplan: RISK-WP-0001-T03
review_interval: 3m
disclosure: restricted
@ -18,9 +20,15 @@ restricted_reason: "names the operator's spend thresholds and describes when the
operator personally rather than sitting in a register, and says the rule is not
yet written. This is the rule, drafted by `risk-nexus`.
**Status: `proposed`.** The custodian adopts it. It is not in force until the
front-matter says `adopted`, and an unadopted rule is worse than an unwritten
one because it looks like coverage.
**Status: `adopted`, 2026-08-20, as written.** The thresholds in trigger 3 —
€50/month recurring, €500 one-off — were this repo's proposal and are now the
operator's numbers. They bound nothing yet: the one spend decision taken so far
(`RISK-F-0006`) was approved without a figure being named.
The rule governed four escalations before it was adopted, which is the state
`RISK-WP-0001-T03` refused to leave open — a draft that quietly governs is
worse than either an adopted rule or no rule, because it looks like coverage
while nobody has agreed to it.
Getting this wrong in either direction is a failure: escalating everything
makes the operator the queue, escalating nothing makes the register a place