risk: complete Policy Nexus publication handover

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
This commit is contained in:
tegwick 2026-09-01 01:54:09 +02:00
parent 96d06e320a
commit a13d954f85
6 changed files with 31 additions and 28 deletions

View file

@ -2,11 +2,10 @@
Risk register and regulatory intake for the estate. Owned by `the-custodian`. Risk register and regulatory intake for the estate. Owned by `the-custodian`.
**It does not serve anything yet.** `INTENT.md` names `risk.coulomb.social` as **It does not serve its own site.** `INTENT.md` names `risk.coulomb.social` as
the eventual surface; today publication runs through `policy-nexus` and three the eventual surface; today public findings and method instruments have
documents are waiting for an address. Recorded here rather than left as a permanent addresses through `policy-nexus`. The source stays here and the
claim, because a stated surface that does not exist is the class of thing this published page records its exact source revision.
register grades other repos down for.
Holds findings — security, architecture, operational, compliance — with a Holds findings — security, architecture, operational, compliance — with a
severity, an owner and a date; decides whether and when each is published; and severity, an owner and a date; decides whether and when each is published; and

View file

@ -1,6 +1,6 @@
# Register # Register
Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-08-23. Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-01.
8 live of 10 findings; 3 notes below the floor. 8 live of 10 findings; 3 notes below the floor.
@ -38,7 +38,6 @@ Silence never buys a softer grade — see `docs/method/dependencies.md`.
| RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 | | RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 |
| RISK-F-0007 | user-engine | likelihood falls for user-engine if a verification exists; a defect becomes its own finding if not | the on-request path is recorded as having produced no answer, which makes the acceptance itself unsupported and is escalated | 2026-09-03 | | RISK-F-0007 | user-engine | likelihood falls for user-engine if a verification exists; a defect becomes its own finding if not | the on-request path is recorded as having produced no answer, which makes the acceptance itself unsupported and is escalated | 2026-09-03 |
| RISK-F-0005 | audit-core | likelihood rises to L3 if any other production credential carries may_read | graded on the sender alone, as stated; the wider question is recorded as unanswered | 2026-09-19 | | RISK-F-0005 | audit-core | likelihood rises to L3 if any other production credential carries may_read | graded on the sender alone, as stated; the wider question is recorded as unanswered | 2026-09-19 |
| RISK-F-0001 | policy-nexus | publication: published plus the permanent URL comes back onto each record | the findings stay disclosure: public with no address, which the register records as a claim rather than a publication | 2026-09-17 |
## Embargoes ## Embargoes

View file

@ -1,6 +1,6 @@
# STATE — risk-nexus # STATE — risk-nexus
**Updated:** 2026-08-21 (second pass) **Updated:** 2026-09-01
**Domain:** infotech · **Repo:** risk-nexus · **Owner:** the-custodian **Domain:** infotech · **Repo:** risk-nexus · **Owner:** the-custodian
## One-line posture ## One-line posture
@ -15,7 +15,7 @@ question carries a default and a date, and the check cadence is scheduled on
| ID | Status | Notes | | ID | Status | Notes |
| --- | --- | --- | | --- | --- | --- |
| `RISK-WP-0001` | **finished** | The four instruments, the index, the first grading | | `RISK-WP-0001` | **finished** | The four instruments, the index, the first grading |
| `RISK-WP-0002` | active | Publication handover — T01 with `policy-nexus` | | `RISK-WP-0002` | **finished** | Two findings and five public method instruments handed to `policy-nexus` |
| `RISK-WP-0003` | **finished** | Regulatory intake; the legal policy set | | `RISK-WP-0003` | **finished** | Regulatory intake; the legal policy set |
| `RISK-WP-0004` | **finished** | Running the register: cadence, verification, inbox-before-grading | | `RISK-WP-0004` | **finished** | Running the register: cadence, verification, inbox-before-grading |
| `RISK-WP-0005` | **finished** | The seven gaps from `history/2026-08-21-intent-gap-analysis.md` | | `RISK-WP-0005` | **finished** | The seven gaps from `history/2026-08-21-intent-gap-analysis.md` |
@ -76,7 +76,6 @@ outcome.
| railiance-platform | deny-set coverage report (`F-0009`) | 2026-09-03 | | railiance-platform | deny-set coverage report (`F-0009`) | 2026-09-03 |
| tenant-engine | confirm/correct `events()`; fix tracking | 2026-09-03 | | tenant-engine | confirm/correct `events()`; fix tracking | 2026-09-03 |
| user-engine | tenant-boundary verification (`RISK-V-0002`) | 2026-09-03 | | user-engine | tenant-boundary verification (`RISK-V-0002`) | 2026-09-03 |
| policy-nexus | publication entries for two findings + five method docs | 2026-09-17 |
| the-custodian | canon kinds packet | 2026-09-17 | | the-custodian | canon kinds packet | 2026-09-17 |
| railiance-platform | backup target, cost, demonstrated restore | 2026-09-18 | | railiance-platform | backup target, cost, demonstrated restore | 2026-09-18 |
| audit-core | is `may_read` false on every production credential | 2026-09-19 | | audit-core | is `may_read` false on every production credential | 2026-09-19 |
@ -101,8 +100,8 @@ statehub fix-consistency --repo risk-nexus
`RISK-F-0002`'s tracked records closed *before that finding was filed*. `RISK-F-0002`'s tracked records closed *before that finding was filed*.
- **Incident intake exists**, with `first_observed` starting the 72-hour clock - **Incident intake exists**, with `first_observed` starting the 72-hour clock
in `RISK-POL-0005` and escalation that is not batched. in `RISK-POL-0005` and escalation that is not batched.
- **External report still has no address** — proposed to `policy-nexus` and the - **Public records have permanent addresses** — two findings and five method
custodian, since a published surface is not this repo's to create. instruments publish through `policy-nexus`; this repo remains their source.
- **Coverage has a number:** `make coverage` — 7 of 117 registered repos have - **Coverage has a number:** `make coverage` — 7 of 117 registered repos have
ever appeared in a finding. The other 110 are unknown, not clean. ever appeared in a finding. The other 110 are unknown, not clean.

View file

@ -3,6 +3,7 @@ id: RISK-F-0001
type: finding type: finding
title: "flex-auth /v1/check authenticates no caller" title: "flex-auth /v1/check authenticates no caller"
status: fixed status: fixed
owner: risk-nexus
reported_by: flex-auth reported_by: flex-auth
reported_via: rapp-postgres reported_via: rapp-postgres
routed_by: rapp-postgres routed_by: rapp-postgres
@ -20,11 +21,13 @@ likelihood: L2
fidelity_modifier: false fidelity_modifier: false
production_rescore: false production_rescore: false
disclosure: public disclosure: public
publication: requested publication: published
publication_id: risk-f-0001-flex-auth-unauthenticated-check publication_id: risk-f-0001-flex-auth-unauthenticated-check
publication_path: "findings/flex-auth-unauthenticated-check/v1/index.html" publication_path: "findings/flex-auth-unauthenticated-check/v1/index.html"
publication_url: "https://policy.coulomb.social/findings/flex-auth-unauthenticated-check/v1/"
published_on: "2026-09-01"
publication_subtitle: "The estate's authorization oracle authenticated no caller for as long as the endpoint existed. Found by reading, not by monitoring; fixed in two days." publication_subtitle: "The estate's authorization oracle authenticated no caller for as long as the endpoint existed. Found by reading, not by monitoring; fixed in two days."
revision: "graded-1" revision: "published-1"
last_reviewed: "2026-08-20" last_reviewed: "2026-08-20"
review_interval: 6m review_interval: 6m
embargo_lifted: "2026-08-19 — FLEX-WP-0015 finished, live probes return 401" embargo_lifted: "2026-08-19 — FLEX-WP-0015 finished, live probes return 401"
@ -38,13 +41,6 @@ last_checked: "2026-08-20T20:44:46Z"
next_check: "2026-08-20T20:44:46Z" next_check: "2026-08-20T20:44:46Z"
cadence: instant cadence: instant
clean_streak: 0 clean_streak: 0
waiting_on:
- who: policy-nexus
what: "publication.json entries for RISK-F-0001, RISK-F-0008 and the five public method documents"
since: "2026-08-20"
would_change: "publication: published plus the permanent URL comes back onto each record"
default: "the findings stay disclosure: public with no address, which the register records as a claim rather than a publication"
default_at: "2026-09-17"
graded_by: risk-nexus graded_by: risk-nexus
ruling: RISK-RULING-2026-08-19 ruling: RISK-RULING-2026-08-19
--- ---

View file

@ -3,6 +3,7 @@ id: RISK-F-0008
type: finding type: finding
title: "The legal basis for retaining audit facts against an erasure request has been assumed, never established" title: "The legal basis for retaining audit facts against an erasure request has been assumed, never established"
status: accepted status: accepted
owner: risk-nexus
reported_by: audit-core reported_by: audit-core
reported_via: audit-core reported_via: audit-core
routed_by: audit-core routed_by: audit-core
@ -22,11 +23,13 @@ likelihood: L2
fidelity_modifier: false fidelity_modifier: false
production_rescore: true production_rescore: true
disclosure: public disclosure: public
publication: requested publication: published
publication_id: risk-f-0008-audit-retention-legal-basis publication_id: risk-f-0008-audit-retention-legal-basis
publication_path: "findings/audit-retention-legal-basis/v1/index.html" publication_path: "findings/audit-retention-legal-basis/v1/index.html"
publication_url: "https://policy.coulomb.social/findings/audit-retention-legal-basis/v1/"
published_on: "2026-09-01"
publication_subtitle: "The estate retains personal data in audit records on grounds nobody had actually established. Published as a question, because it is one." publication_subtitle: "The estate retains personal data in audit records on grounds nobody had actually established. Published as a question, because it is one."
revision: "graded-1" revision: "published-1"
last_reviewed: "2026-08-20" last_reviewed: "2026-08-20"
review_interval: 6m review_interval: 6m
escalation: answered escalation: answered

View file

@ -4,11 +4,11 @@ type: workplan
title: "Hand the publishable findings to policy-nexus, and decide what else is a public document" title: "Hand the publishable findings to policy-nexus, and decide what else is a public document"
domain: infotech domain: infotech
repo: risk-nexus repo: risk-nexus
status: active status: finished
owner: the-custodian owner: the-custodian
topic_slug: risk-nexus topic_slug: risk-nexus
created: "2026-08-20" created: "2026-08-20"
updated: "2026-08-20" updated: "2026-09-01"
depends_on_workplans: depends_on_workplans:
- RISK-WP-0001 - RISK-WP-0001
state_hub_workstream_id: "b79af69c-5b08-55df-8caa-258eed3e397e" state_hub_workstream_id: "b79af69c-5b08-55df-8caa-258eed3e397e"
@ -16,8 +16,8 @@ state_hub_workstream_id: "b79af69c-5b08-55df-8caa-258eed3e397e"
# RISK-WP-0002 — publication handover # RISK-WP-0002 — publication handover
**Draft.** Sized deliberately small: two documents are ready and the rest is a Finished 2026-09-01. Sized deliberately small: two documents were ready and
decision, not a project. the rest was a decision, not a project.
## Goal ## Goal
@ -44,7 +44,7 @@ batch — so the route wants to exist before it is needed, not during.
```task ```task
id: RISK-WP-0002-T01 id: RISK-WP-0002-T01
status: progress status: done
priority: high priority: high
state_hub_task_id: "9ac32008-76b6-591c-82a1-ad6e2f8368b7" state_hub_task_id: "9ac32008-76b6-591c-82a1-ad6e2f8368b7"
``` ```
@ -60,6 +60,13 @@ work product. Decide once, here, and apply it to every later publication.
In progress 2026-08-20. Operator ruled: findings publish **whole**. Publication front-matter applied to `RISK-F-0001` and `RISK-F-0008` (`revision`, `last_reviewed`, `review_interval: 6m`) with proposed ids, paths and subtitles; both now read `publication: requested`. Handover request sent to `policy-nexus`. The open question the task named is answered and recorded in `docs/rulings/2026-08-20-publication.md` — including that `RISK-F-0001` publishes with the paragraph about this register grading it wrong. In progress 2026-08-20. Operator ruled: findings publish **whole**. Publication front-matter applied to `RISK-F-0001` and `RISK-F-0008` (`revision`, `last_reviewed`, `review_interval: 6m`) with proposed ids, paths and subtitles; both now read `publication: requested`. Handover request sent to `policy-nexus`. The open question the task named is answered and recorded in `docs/rulings/2026-08-20-publication.md` — including that `RISK-F-0001` publishes with the paragraph about this register grading it wrong.
Completed 2026-09-01. `policy-nexus` admitted findings and public risk methods
as explicit publication kinds. The two findings publish whole at permanent
addresses and record those addresses back in their source files. The five
public method instruments — severity, disclosure, review, verification and
dependencies — publish beside them. Escalation and check-procedure remain
internal as ruled in T02.
### T02 — Rule on the method documents ### T02 — Rule on the method documents
```task ```task