Sweep risk inbox and reconcile findings
Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
This commit is contained in:
parent
d65aaf7484
commit
7f1424dbcf
12 changed files with 363 additions and 96 deletions
|
|
@ -8,10 +8,11 @@ determined: "2026-08-20"
|
|||
finding: RISK-F-0008
|
||||
sources_read: "GDPR Arts 5, 6, 17, 21, 32; Recitals 49, 65; HGB §257; AO §147"
|
||||
external_review: none
|
||||
last_checked: "2026-08-20T10:02:42Z"
|
||||
next_check: "2026-08-20T11:02:42Z"
|
||||
cadence: 1h
|
||||
clean_streak: 1
|
||||
last_checked: "2026-09-01T00:38:53Z"
|
||||
next_check: "2026-09-01T00:38:53Z"
|
||||
cadence: instant
|
||||
clean_streak: 0
|
||||
checked_by: "codex/risk-nexus"
|
||||
---
|
||||
|
||||
# RISK-REG-0001 — the retention basis, written down
|
||||
|
|
@ -176,3 +177,5 @@ table as a compliance claim.
|
|||
Default if none of these arrives by 2026-11-17: this table stands as the
|
||||
estate's stated position, with the achieved-versus-target gap recorded as
|
||||
unresolved.
|
||||
|
||||
- **2026-09-01** — not clean: the dated review found that the 2026-08-20 target-period amendment had never advanced this record's check state. The targets now stand explicitly; achievement under the shared backup horizon and keyed-commitment feasibility remain open. Cadence 1h → instant; checked again immediately.
|
||||
|
|
|
|||
78
docs/rulings/2026-09-01-inbox-sweep.md
Normal file
78
docs/rulings/2026-09-01-inbox-sweep.md
Normal file
|
|
@ -0,0 +1,78 @@
|
|||
---
|
||||
id: RISK-RULING-2026-09-01-A
|
||||
type: ruling
|
||||
title: "Inbox sweep: tenant boundaries, the agent read boundary, and an embedded backup credential"
|
||||
status: adopted
|
||||
owner: risk-nexus
|
||||
adopted: "2026-09-01"
|
||||
review_interval: 6m
|
||||
disclosure: embargoed
|
||||
embargo_condition: "RISK-F-0010's provider credential is revoked or invalidated and the literal source default is removed"
|
||||
embargo_since: "2026-09-01"
|
||||
embargo_review: "2026-09-15"
|
||||
revision: "adopted-1"
|
||||
last_reviewed: "2026-09-01"
|
||||
---
|
||||
|
||||
# Inbox sweep — 2026-09-01
|
||||
|
||||
One unread owner reply triggered this review. Reading the dependent owner
|
||||
records then showed that six findings were being carried in states older than
|
||||
their evidence, while one filed finding had never been graded.
|
||||
|
||||
## Decisions
|
||||
|
||||
| Finding | Prior state | Ruling | Evidence that changes it |
|
||||
| --- | --- | --- | --- |
|
||||
| `RISK-F-0002` | open, embargoed | fixed, public | zone-aware signing gate complete; authenticated live decision; focused Warden suite passes |
|
||||
| `RISK-F-0003` | mitigated, embargoed | fixed, public | absent/unknown grade fails safe; explicit grade required in CI; dependent OpenBao layer fixed |
|
||||
| `RISK-F-0004` | open, embargoed | fixed, public | broad `events()` removed from production protocol; three tenant-scope tests pass |
|
||||
| `RISK-F-0005` | mitigated, public | fixed, public | bounded production E2 isolation run plus sixty current focused tests |
|
||||
| `RISK-F-0007` | accepted, embargoed | fixed, public | the zero-verification claim is disproved by Audit, Tenant, and User Engine evidence |
|
||||
| `RISK-F-0009` | open, embargoed | fixed, public | generated source/live deny coverage is total for concrete paths; dedicated identity proved deny-wins |
|
||||
| `RISK-F-0010` | open, ungraded | low, embargoed | embedded provider credential remains in source; endpoint evidence limits impact to the write-only backup lane |
|
||||
|
||||
The historical grades of fixed findings remain on their records. A fix changes
|
||||
the status and disclosure decision; it does not rewrite how serious the defect
|
||||
was while live.
|
||||
|
||||
## Cross-tenant boundary ruling
|
||||
|
||||
`RISK-F-0007` said **no** consumer boundary was verified anywhere. That exact
|
||||
claim is now false. Audit Core supplies the strongest evidence: a bounded
|
||||
production run against three calibrated cross-tenant attacks, with safe custody
|
||||
and cleanup. Tenant Engine supplies a dedicated scoped-store suite, and User
|
||||
Engine supplies negative unit and integrated scenarios. These records do not
|
||||
prove every consumer correct. They close the estate-wide absence; a future
|
||||
consumer-specific defect is filed under that owner rather than kept alive under
|
||||
a sentence no longer true.
|
||||
|
||||
The current focused checks run by Risk Nexus are:
|
||||
|
||||
- ops-warden: 137 passed;
|
||||
- audit-core: 60 passed;
|
||||
- tenant-engine: 3 passed;
|
||||
- user-engine: 18 passed;
|
||||
- railiance-platform high-risk boundary invariant: 19 lanes, 14 concrete
|
||||
entries, 5 non-concrete/non-KV, 0 uncovered, 0 errors.
|
||||
|
||||
## Embedded credential ruling
|
||||
|
||||
`RISK-F-0010` is `I2` because the observed endpoint is a write-only file drop,
|
||||
the stored material is ciphertext, and the recovery key is separate. It is
|
||||
`L2` because the literal is recoverable from granted repository or log access.
|
||||
That yields `low`. The current value is not probed: testing an exposed
|
||||
credential would expand the action beyond safe triage and is unnecessary to
|
||||
grade the stated facts.
|
||||
|
||||
The disclosure state is embargoed because announcing the recoverable credential
|
||||
while its validity is unknown and its literal remains in source shortens the
|
||||
route to the defect. The embargo lifts after two observable events: provider
|
||||
revocation or invalidation, and removal of the source default. Restore evidence
|
||||
is requested as closure evidence for the governed replacement, but its absence
|
||||
does not justify reproducing or testing the old value.
|
||||
|
||||
No escalation trigger fires today. Railiance Platform owns the fix; there is no
|
||||
known use, disclosure, legal duty, new spend, ownership dispute, or fourteen-day
|
||||
stall. The dated wait makes that last statement expire rather than persist as
|
||||
prose.
|
||||
Loading…
Add table
Add a link
Reference in a new issue