From d723f2c0769115988d826d1f80c3e7bf6f75c50a Mon Sep 17 00:00:00 2001 From: tegwick Date: Thu, 20 Aug 2026 01:12:31 +0200 Subject: [PATCH] Tell reporters how to ask for a boundary verification The on-request path from the operator's RISK-F-0007 ruling is only useful if the repos that would use it can find it. Co-Authored-By: Claude Opus 5 --- findings/README.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/findings/README.md b/findings/README.md index 1c2cf67..5b556d0 100644 --- a/findings/README.md +++ b/findings/README.md @@ -43,4 +43,15 @@ it is and who hears about it (`INTENT.md`). Leaving them out, or writing - **A note is fine.** If it would not change anyone's decision, it belongs in `notes/` — see the floor in `docs/method/severity.md`. +## Asking for a tenant-boundary verification + +Separate from filing. The estate carries `RISK-F-0007` — no consumer's tenant +boundary is verified anywhere — as an accepted risk until production, on the +operator's ruling of 2026-08-19, with verification available **on request**. + +Message `risk-nexus` naming one consumer boundary and what would have to be +true of it. The owning repo of that consumer does the verification; this repo +scopes and records it and verifies nothing itself. A boundary that holds is +evidence; one that does not is a finding with its own owner. + After filing: `make check`. Then this repo grades it.