Legal policy set: written before needed, dormant until a context activates

Operator ruling: no external determination in build mode, but keep the
set of legal policies for reuse when a work context needs one in place.

docs/regulatory/policies/ catalogues thirteen, keyed by activation
condition rather than by regime, with a retrieval table so a context
pulls a slice: first real user account pulls six of them; a
consumer-facing product in Germany pulls those plus accessibility. Two
are already active and nobody had noticed — commercial and tax retention,
and the e-invoicing receiving obligation that has been live since 2025
with no named owner in the estate. Four written in full; the rest carry
their trigger now and get their text when a context approaches, which is
the point.

RISK-POL-0011 is the argument for the whole catalogue: accessibility
cannot be retrofitted cheaply, so a policy retrieved at launch is a
rebuild while one read at design time is just a constraint.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-20 23:36:22 +02:00
parent 3a0ba5d427
commit 7f135f9e0f
7 changed files with 332 additions and 13 deletions

View file

@ -4,18 +4,12 @@ type: workplan
title: "Make the register decidable: severity, disclosure, escalation, expiry"
domain: infotech
repo: risk-nexus
status: active
status: finished
owner: the-custodian
topic_slug: risk-nexus
created: "2026-08-19"
updated: "2026-08-20"
waiting_on:
- who: the-custodian
what: "adopt docs/method/escalation.md, which is producing decisions while still status: proposed"
since: "2026-08-19"
would_change: "the rule stops being a draft that looks like coverage; the spend thresholds become the operator's numbers rather than ours"
default: "recorded as de facto in force but unratified, and every escalation sent under it says so on its face"
default_at: "2026-09-17"
- who: the-custodian
what: "register finding / note / regulatory-record as canon work-record kinds, or rule that the register is a different ontology"
since: "2026-08-20"
@ -159,7 +153,7 @@ Completed 2026-08-19. `docs/method/disclosure.md`. The deferral was re-taken and
```task
id: RISK-WP-0001-T03
status: progress
status: done
priority: high
```
@ -185,7 +179,7 @@ The custodian adopts the rule. Ask, do not assume.
**Output:** `docs/method/escalation.md`.
In progress 2026-08-19. `docs/method/escalation.md` is written and `status: proposed`. All five INTENT triggers settled — 1 adopted and bounded, 2 adopted unbounded, 3 bounded at EUR 50/month or EUR 500 one-off, 4 bounded by one failed routing exchange, 5 bounded at twice the review interval — plus trigger 6 (ordering hazard producing a false attestation), added because `RISK-F-0002` produced the case. Tested against all seven findings before proposing. **Not done until the custodian adopts it**, and the spend numbers are the operator's to overwrite.
In progress 2026-08-19. `docs/method/escalation.md` is written and `status: proposed`. All five INTENT triggers settled — 1 adopted and bounded, 2 adopted unbounded, 3 bounded at EUR 50/month or EUR 500 one-off, 4 bounded by one failed routing exchange, 5 bounded at twice the review interval — plus trigger 6 (ordering hazard producing a false attestation), added because `RISK-F-0002` produced the case. Tested against all seven findings before proposing, and against nine by the time it was adopted. The €50/month and €500 thresholds are now the operator's numbers rather than ours — they bound nothing so far, since the only spend decision taken (`RISK-F-0006`) was approved without a figure.
### T04 — Review dates and expiry