From a13d954f8597fd92201746e2d52f031a5a88d969 Mon Sep 17 00:00:00 2001 From: tegwick Date: Tue, 1 Sep 2026 01:54:09 +0200 Subject: [PATCH] risk: complete Policy Nexus publication handover Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663 --- README.md | 9 ++++----- REGISTER.md | 3 +-- STATE.md | 9 ++++----- ...SK-F-0001-flex-auth-unauthenticated-check.md | 14 +++++--------- ...-0008-audit-retention-legal-basis-assumed.md | 7 +++++-- workplans/RISK-WP-0002-publication-handover.md | 17 ++++++++++++----- 6 files changed, 31 insertions(+), 28 deletions(-) diff --git a/README.md b/README.md index 3231d2e..4219409 100644 --- a/README.md +++ b/README.md @@ -2,11 +2,10 @@ Risk register and regulatory intake for the estate. Owned by `the-custodian`. -**It does not serve anything yet.** `INTENT.md` names `risk.coulomb.social` as -the eventual surface; today publication runs through `policy-nexus` and three -documents are waiting for an address. Recorded here rather than left as a -claim, because a stated surface that does not exist is the class of thing this -register grades other repos down for. +**It does not serve its own site.** `INTENT.md` names `risk.coulomb.social` as +the eventual surface; today public findings and method instruments have +permanent addresses through `policy-nexus`. The source stays here and the +published page records its exact source revision. Holds findings — security, architecture, operational, compliance — with a severity, an owner and a date; decides whether and when each is published; and diff --git a/REGISTER.md b/REGISTER.md index 71d622d..8fddd4d 100644 --- a/REGISTER.md +++ b/REGISTER.md @@ -1,6 +1,6 @@ # Register -Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-08-23. +Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-01. 8 live of 10 findings; 3 notes below the floor. @@ -38,7 +38,6 @@ Silence never buys a softer grade — see `docs/method/dependencies.md`. | RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 | | RISK-F-0007 | user-engine | likelihood falls for user-engine if a verification exists; a defect becomes its own finding if not | the on-request path is recorded as having produced no answer, which makes the acceptance itself unsupported and is escalated | 2026-09-03 | | RISK-F-0005 | audit-core | likelihood rises to L3 if any other production credential carries may_read | graded on the sender alone, as stated; the wider question is recorded as unanswered | 2026-09-19 | -| RISK-F-0001 | policy-nexus | publication: published plus the permanent URL comes back onto each record | the findings stay disclosure: public with no address, which the register records as a claim rather than a publication | 2026-09-17 | ## Embargoes diff --git a/STATE.md b/STATE.md index 921d690..9f5a2f3 100644 --- a/STATE.md +++ b/STATE.md @@ -1,6 +1,6 @@ # STATE — risk-nexus -**Updated:** 2026-08-21 (second pass) +**Updated:** 2026-09-01 **Domain:** infotech · **Repo:** risk-nexus · **Owner:** the-custodian ## One-line posture @@ -15,7 +15,7 @@ question carries a default and a date, and the check cadence is scheduled on | ID | Status | Notes | | --- | --- | --- | | `RISK-WP-0001` | **finished** | The four instruments, the index, the first grading | -| `RISK-WP-0002` | active | Publication handover — T01 with `policy-nexus` | +| `RISK-WP-0002` | **finished** | Two findings and five public method instruments handed to `policy-nexus` | | `RISK-WP-0003` | **finished** | Regulatory intake; the legal policy set | | `RISK-WP-0004` | **finished** | Running the register: cadence, verification, inbox-before-grading | | `RISK-WP-0005` | **finished** | The seven gaps from `history/2026-08-21-intent-gap-analysis.md` | @@ -76,7 +76,6 @@ outcome. | railiance-platform | deny-set coverage report (`F-0009`) | 2026-09-03 | | tenant-engine | confirm/correct `events()`; fix tracking | 2026-09-03 | | user-engine | tenant-boundary verification (`RISK-V-0002`) | 2026-09-03 | -| policy-nexus | publication entries for two findings + five method docs | 2026-09-17 | | the-custodian | canon kinds packet | 2026-09-17 | | railiance-platform | backup target, cost, demonstrated restore | 2026-09-18 | | audit-core | is `may_read` false on every production credential | 2026-09-19 | @@ -101,8 +100,8 @@ statehub fix-consistency --repo risk-nexus `RISK-F-0002`'s tracked records closed *before that finding was filed*. - **Incident intake exists**, with `first_observed` starting the 72-hour clock in `RISK-POL-0005` and escalation that is not batched. -- **External report still has no address** — proposed to `policy-nexus` and the - custodian, since a published surface is not this repo's to create. +- **Public records have permanent addresses** — two findings and five method + instruments publish through `policy-nexus`; this repo remains their source. - **Coverage has a number:** `make coverage` — 7 of 117 registered repos have ever appeared in a finding. The other 110 are unknown, not clean. diff --git a/findings/RISK-F-0001-flex-auth-unauthenticated-check.md b/findings/RISK-F-0001-flex-auth-unauthenticated-check.md index fd8e94b..308b814 100644 --- a/findings/RISK-F-0001-flex-auth-unauthenticated-check.md +++ b/findings/RISK-F-0001-flex-auth-unauthenticated-check.md @@ -3,6 +3,7 @@ id: RISK-F-0001 type: finding title: "flex-auth /v1/check authenticates no caller" status: fixed +owner: risk-nexus reported_by: flex-auth reported_via: rapp-postgres routed_by: rapp-postgres @@ -20,11 +21,13 @@ likelihood: L2 fidelity_modifier: false production_rescore: false disclosure: public -publication: requested +publication: published publication_id: risk-f-0001-flex-auth-unauthenticated-check publication_path: "findings/flex-auth-unauthenticated-check/v1/index.html" +publication_url: "https://policy.coulomb.social/findings/flex-auth-unauthenticated-check/v1/" +published_on: "2026-09-01" publication_subtitle: "The estate's authorization oracle authenticated no caller for as long as the endpoint existed. Found by reading, not by monitoring; fixed in two days." -revision: "graded-1" +revision: "published-1" last_reviewed: "2026-08-20" review_interval: 6m embargo_lifted: "2026-08-19 — FLEX-WP-0015 finished, live probes return 401" @@ -38,13 +41,6 @@ last_checked: "2026-08-20T20:44:46Z" next_check: "2026-08-20T20:44:46Z" cadence: instant clean_streak: 0 -waiting_on: - - who: policy-nexus - what: "publication.json entries for RISK-F-0001, RISK-F-0008 and the five public method documents" - since: "2026-08-20" - would_change: "publication: published plus the permanent URL comes back onto each record" - default: "the findings stay disclosure: public with no address, which the register records as a claim rather than a publication" - default_at: "2026-09-17" graded_by: risk-nexus ruling: RISK-RULING-2026-08-19 --- diff --git a/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md b/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md index a56ff68..eef8247 100644 --- a/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md +++ b/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md @@ -3,6 +3,7 @@ id: RISK-F-0008 type: finding title: "The legal basis for retaining audit facts against an erasure request has been assumed, never established" status: accepted +owner: risk-nexus reported_by: audit-core reported_via: audit-core routed_by: audit-core @@ -22,11 +23,13 @@ likelihood: L2 fidelity_modifier: false production_rescore: true disclosure: public -publication: requested +publication: published publication_id: risk-f-0008-audit-retention-legal-basis publication_path: "findings/audit-retention-legal-basis/v1/index.html" +publication_url: "https://policy.coulomb.social/findings/audit-retention-legal-basis/v1/" +published_on: "2026-09-01" publication_subtitle: "The estate retains personal data in audit records on grounds nobody had actually established. Published as a question, because it is one." -revision: "graded-1" +revision: "published-1" last_reviewed: "2026-08-20" review_interval: 6m escalation: answered diff --git a/workplans/RISK-WP-0002-publication-handover.md b/workplans/RISK-WP-0002-publication-handover.md index f31a7ac..a66550c 100644 --- a/workplans/RISK-WP-0002-publication-handover.md +++ b/workplans/RISK-WP-0002-publication-handover.md @@ -4,11 +4,11 @@ type: workplan title: "Hand the publishable findings to policy-nexus, and decide what else is a public document" domain: infotech repo: risk-nexus -status: active +status: finished owner: the-custodian topic_slug: risk-nexus created: "2026-08-20" -updated: "2026-08-20" +updated: "2026-09-01" depends_on_workplans: - RISK-WP-0001 state_hub_workstream_id: "b79af69c-5b08-55df-8caa-258eed3e397e" @@ -16,8 +16,8 @@ state_hub_workstream_id: "b79af69c-5b08-55df-8caa-258eed3e397e" # RISK-WP-0002 — publication handover -**Draft.** Sized deliberately small: two documents are ready and the rest is a -decision, not a project. +Finished 2026-09-01. Sized deliberately small: two documents were ready and +the rest was a decision, not a project. ## Goal @@ -44,7 +44,7 @@ batch — so the route wants to exist before it is needed, not during. ```task id: RISK-WP-0002-T01 -status: progress +status: done priority: high state_hub_task_id: "9ac32008-76b6-591c-82a1-ad6e2f8368b7" ``` @@ -60,6 +60,13 @@ work product. Decide once, here, and apply it to every later publication. In progress 2026-08-20. Operator ruled: findings publish **whole**. Publication front-matter applied to `RISK-F-0001` and `RISK-F-0008` (`revision`, `last_reviewed`, `review_interval: 6m`) with proposed ids, paths and subtitles; both now read `publication: requested`. Handover request sent to `policy-nexus`. The open question the task named is answered and recorded in `docs/rulings/2026-08-20-publication.md` — including that `RISK-F-0001` publishes with the paragraph about this register grading it wrong. +Completed 2026-09-01. `policy-nexus` admitted findings and public risk methods +as explicit publication kinds. The two findings publish whole at permanent +addresses and record those addresses back in their source files. The five +public method instruments — severity, disclosure, review, verification and +dependencies — publish beside them. Escalation and check-procedure remain +internal as ruled in T02. + ### T02 — Rule on the method documents ```task