diff --git a/docs/method/dependencies.md b/docs/method/dependencies.md index ca56560..df34a7b 100644 --- a/docs/method/dependencies.md +++ b/docs/method/dependencies.md @@ -6,7 +6,10 @@ status: adopted owner: risk-nexus adopted: "2026-08-20" workplan: RISK-WP-0001 -review_interval: 180d +review_interval: 6m +disclosure: public +revision: "adopted-1" +last_reviewed: "2026-08-20" --- # Waiting diff --git a/docs/method/disclosure.md b/docs/method/disclosure.md index 364da78..2ae7eb6 100644 --- a/docs/method/disclosure.md +++ b/docs/method/disclosure.md @@ -6,7 +6,10 @@ status: adopted owner: risk-nexus adopted: "2026-08-19" workplan: RISK-WP-0001-T02 -review_interval: 180d +review_interval: 6m +disclosure: public +revision: "adopted-1" +last_reviewed: "2026-08-20" --- # Disclosure diff --git a/docs/method/escalation.md b/docs/method/escalation.md index aef32ae..c13f32f 100644 --- a/docs/method/escalation.md +++ b/docs/method/escalation.md @@ -7,7 +7,9 @@ owner: the-custodian drafted_by: risk-nexus drafted: "2026-08-19" workplan: RISK-WP-0001-T03 -review_interval: 90d +review_interval: 3m +disclosure: restricted +restricted_reason: "names the operator's spend thresholds and describes when the operator personally is interrupted" --- # Escalation diff --git a/docs/method/review.md b/docs/method/review.md index 22d7ca1..015efd0 100644 --- a/docs/method/review.md +++ b/docs/method/review.md @@ -6,7 +6,10 @@ status: adopted owner: risk-nexus adopted: "2026-08-19" workplan: RISK-WP-0001-T04 -review_interval: 180d +review_interval: 6m +disclosure: public +revision: "adopted-1" +last_reviewed: "2026-08-20" --- # Review and expiry diff --git a/docs/method/severity.md b/docs/method/severity.md index f67a5f4..9bcdc94 100644 --- a/docs/method/severity.md +++ b/docs/method/severity.md @@ -6,7 +6,10 @@ status: adopted owner: risk-nexus adopted: "2026-08-19" workplan: RISK-WP-0001-T01 -review_interval: 180d +review_interval: 6m +disclosure: public +revision: "adopted-1" +last_reviewed: "2026-08-20" --- # Severity diff --git a/docs/method/verification.md b/docs/method/verification.md index 67d5ce1..312b8bb 100644 --- a/docs/method/verification.md +++ b/docs/method/verification.md @@ -6,7 +6,10 @@ status: adopted owner: risk-nexus adopted: "2026-08-20" workplan: RISK-WP-0004-T05 -review_interval: 180d +review_interval: 6m +disclosure: public +revision: "adopted-1" +last_reviewed: "2026-08-20" --- # Verification diff --git a/docs/rulings/2026-08-20-publication.md b/docs/rulings/2026-08-20-publication.md new file mode 100644 index 0000000..ec5f3ae --- /dev/null +++ b/docs/rulings/2026-08-20-publication.md @@ -0,0 +1,69 @@ +--- +id: RISK-RULING-2026-08-20-B +type: ruling +title: "What the estate publishes about its own risk" +status: recorded +owner: risk-nexus +date: "2026-08-20" +workplan: RISK-WP-0002 +--- + +# Publication — 2026-08-20 + +Two operator decisions, and what they commit this register to. + +## Findings publish whole + +A reader gets the finding file: the claim, the grade with its reasoning, the +review log, and **the register's own corrections**. + +`RISK-F-0001` is the first, and it publishes with the paragraph recording that +this register graded it `critical` and prepared an escalation while its fix +notice sat unread in the inbox — including the sentence "only luck put the fix +on the same day". + +That was the decision worth taking deliberately, and the reasoning is worth +keeping: + +- **The contract publishes a file.** A summary would be a second document per + finding, kept in sync by hand, and drift is the failure this register most + distrusts — it is why `REGISTER.md` is generated rather than maintained. +- **The self-criticism is the credible part.** A published register that only + contains other repos' defects reads as an accusation. One that contains its + own reads as a record. The estate has nothing to gain from a risk register + that appears to have never been wrong. +- **It is the same standard applied inward.** This repo asks every owner to + state exposure only as far as they can support it, and to say when they could + not verify something. Publishing a cleaned-up version of our own work while + holding others to that would be indefensible. + +The cost is real and accepted: criticism of other repos is public, and so is +every misgrade this register makes. The second is the price of the first being +believable. + +## Method documents: public, except escalation + +Public: `severity`, `disclosure`, `review`, `verification`, `dependencies`. +Together they let an outside reader judge whether a published finding means +anything — what `high` is, why something was held, how often it is re-checked, +what the register may verify itself, and what happens when someone does not +answer. + +**`escalation` is `restricted`**, and not because it is embarrassing. It names +the operator's spend thresholds and describes the conditions under which the +operator personally is interrupted. That is a map of where attention is scarce +and what triggers it, which is useful to exactly one kind of reader and is not +needed by anyone judging a finding. + +`check-procedure` stays internal by omission rather than by ruling: it is an +operating manual, not an instrument, and nothing about a published finding +depends on it. + +## What this does not decide + +- **Timing.** Publication follows the embargo conditions already recorded. + Six findings remain held. +- **Address scheme.** `policy-nexus` owns addressing and permanence + (`POLICY-NEXUS-WP-0001`). Paths proposed here are proposals. +- **Whether anything else ever publishes.** Rulings, verifications and + regulatory records are unaddressed and stay internal until someone asks. diff --git a/findings/RISK-F-0001-flex-auth-unauthenticated-check.md b/findings/RISK-F-0001-flex-auth-unauthenticated-check.md index 157947a..a8c2de7 100644 --- a/findings/RISK-F-0001-flex-auth-unauthenticated-check.md +++ b/findings/RISK-F-0001-flex-auth-unauthenticated-check.md @@ -20,7 +20,13 @@ likelihood: L2 fidelity_modifier: false production_rescore: false disclosure: public -publication: pending-handover +publication: requested +publication_id: risk-f-0001-flex-auth-unauthenticated-check +publication_path: "findings/flex-auth-unauthenticated-check/v1/index.html" +publication_subtitle: "The estate's authorization oracle authenticated no caller for as long as the endpoint existed. Found by reading, not by monitoring; fixed in two days." +revision: "graded-1" +last_reviewed: "2026-08-20" +review_interval: 6m embargo_condition: "met 2026-08-19 — FLEX-WP-0015 finished, live probes return 401" embargo_since: "2026-08-19" embargo_review: "2026-08-19" diff --git a/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md b/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md index 7615865..9e6f725 100644 --- a/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md +++ b/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md @@ -22,7 +22,13 @@ likelihood: L2 fidelity_modifier: false production_rescore: true disclosure: public -publication: pending-handover +publication: requested +publication_id: risk-f-0008-audit-retention-legal-basis +publication_path: "findings/audit-retention-legal-basis/v1/index.html" +publication_subtitle: "The estate retains personal data in audit records on grounds nobody had actually established. Published as a question, because it is one." +revision: "graded-1" +last_reviewed: "2026-08-20" +review_interval: 6m escalation: required escalation_trigger: 2 escalation_status: partially-answered diff --git a/workplans/RISK-WP-0002-publication-handover.md b/workplans/RISK-WP-0002-publication-handover.md index 213e75c..ddbab95 100644 --- a/workplans/RISK-WP-0002-publication-handover.md +++ b/workplans/RISK-WP-0002-publication-handover.md @@ -43,7 +43,7 @@ batch — so the route wants to exist before it is needed, not during. ```task id: RISK-WP-0002-T01 -status: todo +status: progress priority: high ``` @@ -56,11 +56,13 @@ or as a summary?** `RISK-F-0001` contains a full ruling, a re-grade, a review log and this register's own process defect. Some of that is register-internal work product. Decide once, here, and apply it to every later publication. +In progress 2026-08-20. Operator ruled: findings publish **whole**. Publication front-matter applied to `RISK-F-0001` and `RISK-F-0008` (`revision`, `last_reviewed`, `review_interval: 6m`) with proposed ids, paths and subtitles; both now read `publication: requested`. Handover request sent to `policy-nexus`. The open question the task named is answered and recorded in `docs/rulings/2026-08-20-publication.md` — including that `RISK-F-0001` publishes with the paragraph about this register grading it wrong. + ### T02 — Rule on the method documents ```task id: RISK-WP-0002-T02 -status: todo +status: done priority: medium ``` @@ -78,6 +80,8 @@ Suggested split, to be ruled on rather than assumed: severity and disclosure public, escalation and review internal. Escalation in particular describes when the operator is interrupted, which is not the estate's business to advertise. +Completed 2026-08-20. Public: `severity`, `disclosure`, `review`, `verification`, `dependencies` — the instruments a reader needs to judge whether a published finding means anything. Restricted: `escalation`, because it names the operator's spend thresholds and describes when the operator personally is interrupted, which is a map of where attention is scarce and is needed by nobody judging a finding. `check-procedure` stays internal by omission: an operating manual, not an instrument. + ### T03 — The standing route ```task