RISK-WP-0001 T01-T06,T08: the four instruments, the index, and the first grading

Severity (impact x likelihood, fidelity modifier for controls that lie,
headline-vs-constraint, build-mode double grade, the floor), disclosure
(publish/embargoed/restricted, and the build-mode deferral re-taken and
narrowed with RISK-F-0001 in hand), escalation (the five INTENT triggers
settled plus an ordering-hazard trigger the RISK-F-0002 case forced;
proposed, awaiting the custodian), review (intervals, what a review is,
what missing one produces, the production re-score).

Then applied: RISK-F-0001 critical/embargoed/escalated, RISK-F-0002
medium with a high constraint on RISK-F-0001's remediation, filed as a
peer and escalated only on the ordering, RISK-F-0003 high/embargoed/no
escalation. No unset field remains.

REGISTER.md is generated; make check reports overdue, stalled, ungraded
and unanswered escalations without changing anything.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-19 23:29:39 +02:00
parent e268259f94
commit d5a3953f2e
15 changed files with 1334 additions and 14 deletions

View file

@ -12,10 +12,27 @@ environment: production
fix_owner: ops-warden
fix_tracking: WARDEN-WP-0007 (gate shipped, disabled) / FLEX-WP-0007 (runtime deploy)
related: [RISK-F-0001]
# risk-nexus's to set, not the reporter's (INTENT, "What it does not own").
severity: unset
disclosure: unset
escalation: unset
# Graded by risk-nexus 2026-08-19 — docs/rulings/2026-08-19-first-grading.md
severity: medium
severity_at_production: medium
impact: I3
likelihood: L2
fidelity_modifier: false
production_rescore: false
constraint_on: RISK-F-0001
constraint_severity: high
constraint: "policy.enabled must not be turned on while flex-auth /v1/check answers unauthenticated callers — the gate would sign a false attestation"
disclosure: embargoed
embargo_condition: "FLEX-WP-0015-T02 shipped and ops-warden policy.enabled true in production"
embargo_since: "2026-08-19"
embargo_review: "2026-11-17"
escalation: required
escalation_trigger: 6
escalation_status: pending-operator
last_reviewed: "2026-08-19"
review_by: "2026-11-17"
graded_by: risk-nexus
ruling: RISK-RULING-2026-08-19
---
# RISK-F-0002 — the SSH signing gate is off, and turning it on is now the more dangerous move
@ -120,3 +137,59 @@ the risk of a decision we had already made and filed away as merely blocked.
The estate's habit of recording a blocker once and not revisiting it is the
thing to watch. A blocker is a claim about the world at a date. `RISK-F-0001`
invalidated this one in a day, and nothing would have re-checked it.
## Register ruling — 2026-08-19
All three questions this finding put are answered.
**1. Severity — `medium` today, with a `high` constraint.** The headline
scores the state of the world now: the gate is off, a missing control honestly
represented. `I3` (SSH certificates into production hosts cross a trust
boundary) × `L2` (scoped `VAULT_TOKEN`, actor in `inventory.yaml`, TTLs, every
issuance logged — thin, but not nothing).
The argument that the two states are not equally bad is **accepted in full**,
and it is now written into the scale as the fidelity modifier: a control that
lies is one impact band worse than the same control absent
(`docs/method/severity.md`). It is recorded as a constraint rather than the
headline because the register describes the estate as it is, and the dangerous
state does not exist yet:
> **Constraint, severity `high`.** Enabling `policy.enabled` while `/v1/check`
> answers unauthenticated callers converts an absent control into a false
> attestation — a genuine `allow` obtained by anyone with ClusterIP reach, and
> a `policy_decision_id` in the signature log asserting the issuance was
> authorized. `I3 + fidelity → I4`, `L2` → `high`.
The constraint is attached to `RISK-F-0001`'s remediation and recorded on both
findings. A reader must not take away `medium` and miss it.
**2. Peer, not consequence.** Filed as `ops-warden` filed it. The fix owner
differs and the "off" state has standing regardless of how `RISK-F-0001`
resolves — if that finding were withdrawn tomorrow, production signing would
still carry no per-request judgement. What is not independent is the ordering,
and that travels as a constraint rather than by collapsing the two records.
**3. Escalation — the register disagrees, narrowly.** On triggers 1-5 it
agrees with `ops-warden`: no real tenant data, no obligation, no spend, no
ownership dispute, no stall. But "it is written down in both repos" is the one
argument the register cannot accept here, because this finding is itself the
evidence against it: its own blocker was written down, filed, and invalidated
in a day with nothing re-checking it.
So trigger 6 — ordering hazard producing a false attestation — fires **once**.
One acknowledgement that the operator holds the ordering, then the register
carries it. Not a standing supervision request. That trigger exists in
`docs/method/escalation.md` because of this finding.
**The general point is adopted.** "A blocker is a claim about the world at a
date" is now question 2 of every review in `docs/method/review.md`, and this
finding is cited there as the case that bought it.
Reasoning: `docs/rulings/2026-08-19-first-grading.md`.
## Reviews
- **2026-08-19** — graded. Next review 2026-11-17 (`medium` → 90 days).
Open at review: has `FLEX-WP-0007` or `WARDEN-WP-0007` moved; is the stated
blocker still true; does the ordering constraint still hold.