RISK-WP-0002: findings publish whole; method docs public except escalation

Operator ruled both. Findings publish as the file a reader gets —
including RISK-F-0001's record that this register graded it critical
while its fix notice sat unread. A summary would be a second document per
finding kept in sync by hand, and drift is the failure this repo most
distrusts; and a published register containing only other repos' defects
reads as an accusation, while one containing its own reads as a record.

Method docs public except escalation, which is restricted because it
names spend thresholds and describes when the operator personally is
interrupted — a map of where attention is scarce, needed by nobody
judging a finding.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
tegwick 2026-08-20 22:43:48 +02:00
parent 7dc8d01a63
commit f0db7c83ca
10 changed files with 112 additions and 10 deletions

View file

@ -6,7 +6,10 @@ status: adopted
owner: risk-nexus owner: risk-nexus
adopted: "2026-08-20" adopted: "2026-08-20"
workplan: RISK-WP-0001 workplan: RISK-WP-0001
review_interval: 180d review_interval: 6m
disclosure: public
revision: "adopted-1"
last_reviewed: "2026-08-20"
--- ---
# Waiting # Waiting

View file

@ -6,7 +6,10 @@ status: adopted
owner: risk-nexus owner: risk-nexus
adopted: "2026-08-19" adopted: "2026-08-19"
workplan: RISK-WP-0001-T02 workplan: RISK-WP-0001-T02
review_interval: 180d review_interval: 6m
disclosure: public
revision: "adopted-1"
last_reviewed: "2026-08-20"
--- ---
# Disclosure # Disclosure

View file

@ -7,7 +7,9 @@ owner: the-custodian
drafted_by: risk-nexus drafted_by: risk-nexus
drafted: "2026-08-19" drafted: "2026-08-19"
workplan: RISK-WP-0001-T03 workplan: RISK-WP-0001-T03
review_interval: 90d review_interval: 3m
disclosure: restricted
restricted_reason: "names the operator's spend thresholds and describes when the operator personally is interrupted"
--- ---
# Escalation # Escalation

View file

@ -6,7 +6,10 @@ status: adopted
owner: risk-nexus owner: risk-nexus
adopted: "2026-08-19" adopted: "2026-08-19"
workplan: RISK-WP-0001-T04 workplan: RISK-WP-0001-T04
review_interval: 180d review_interval: 6m
disclosure: public
revision: "adopted-1"
last_reviewed: "2026-08-20"
--- ---
# Review and expiry # Review and expiry

View file

@ -6,7 +6,10 @@ status: adopted
owner: risk-nexus owner: risk-nexus
adopted: "2026-08-19" adopted: "2026-08-19"
workplan: RISK-WP-0001-T01 workplan: RISK-WP-0001-T01
review_interval: 180d review_interval: 6m
disclosure: public
revision: "adopted-1"
last_reviewed: "2026-08-20"
--- ---
# Severity # Severity

View file

@ -6,7 +6,10 @@ status: adopted
owner: risk-nexus owner: risk-nexus
adopted: "2026-08-20" adopted: "2026-08-20"
workplan: RISK-WP-0004-T05 workplan: RISK-WP-0004-T05
review_interval: 180d review_interval: 6m
disclosure: public
revision: "adopted-1"
last_reviewed: "2026-08-20"
--- ---
# Verification # Verification

View file

@ -0,0 +1,69 @@
---
id: RISK-RULING-2026-08-20-B
type: ruling
title: "What the estate publishes about its own risk"
status: recorded
owner: risk-nexus
date: "2026-08-20"
workplan: RISK-WP-0002
---
# Publication — 2026-08-20
Two operator decisions, and what they commit this register to.
## Findings publish whole
A reader gets the finding file: the claim, the grade with its reasoning, the
review log, and **the register's own corrections**.
`RISK-F-0001` is the first, and it publishes with the paragraph recording that
this register graded it `critical` and prepared an escalation while its fix
notice sat unread in the inbox — including the sentence "only luck put the fix
on the same day".
That was the decision worth taking deliberately, and the reasoning is worth
keeping:
- **The contract publishes a file.** A summary would be a second document per
finding, kept in sync by hand, and drift is the failure this register most
distrusts — it is why `REGISTER.md` is generated rather than maintained.
- **The self-criticism is the credible part.** A published register that only
contains other repos' defects reads as an accusation. One that contains its
own reads as a record. The estate has nothing to gain from a risk register
that appears to have never been wrong.
- **It is the same standard applied inward.** This repo asks every owner to
state exposure only as far as they can support it, and to say when they could
not verify something. Publishing a cleaned-up version of our own work while
holding others to that would be indefensible.
The cost is real and accepted: criticism of other repos is public, and so is
every misgrade this register makes. The second is the price of the first being
believable.
## Method documents: public, except escalation
Public: `severity`, `disclosure`, `review`, `verification`, `dependencies`.
Together they let an outside reader judge whether a published finding means
anything — what `high` is, why something was held, how often it is re-checked,
what the register may verify itself, and what happens when someone does not
answer.
**`escalation` is `restricted`**, and not because it is embarrassing. It names
the operator's spend thresholds and describes the conditions under which the
operator personally is interrupted. That is a map of where attention is scarce
and what triggers it, which is useful to exactly one kind of reader and is not
needed by anyone judging a finding.
`check-procedure` stays internal by omission rather than by ruling: it is an
operating manual, not an instrument, and nothing about a published finding
depends on it.
## What this does not decide
- **Timing.** Publication follows the embargo conditions already recorded.
Six findings remain held.
- **Address scheme.** `policy-nexus` owns addressing and permanence
(`POLICY-NEXUS-WP-0001`). Paths proposed here are proposals.
- **Whether anything else ever publishes.** Rulings, verifications and
regulatory records are unaddressed and stay internal until someone asks.

View file

@ -20,7 +20,13 @@ likelihood: L2
fidelity_modifier: false fidelity_modifier: false
production_rescore: false production_rescore: false
disclosure: public disclosure: public
publication: pending-handover publication: requested
publication_id: risk-f-0001-flex-auth-unauthenticated-check
publication_path: "findings/flex-auth-unauthenticated-check/v1/index.html"
publication_subtitle: "The estate's authorization oracle authenticated no caller for as long as the endpoint existed. Found by reading, not by monitoring; fixed in two days."
revision: "graded-1"
last_reviewed: "2026-08-20"
review_interval: 6m
embargo_condition: "met 2026-08-19 — FLEX-WP-0015 finished, live probes return 401" embargo_condition: "met 2026-08-19 — FLEX-WP-0015 finished, live probes return 401"
embargo_since: "2026-08-19" embargo_since: "2026-08-19"
embargo_review: "2026-08-19" embargo_review: "2026-08-19"

View file

@ -22,7 +22,13 @@ likelihood: L2
fidelity_modifier: false fidelity_modifier: false
production_rescore: true production_rescore: true
disclosure: public disclosure: public
publication: pending-handover publication: requested
publication_id: risk-f-0008-audit-retention-legal-basis
publication_path: "findings/audit-retention-legal-basis/v1/index.html"
publication_subtitle: "The estate retains personal data in audit records on grounds nobody had actually established. Published as a question, because it is one."
revision: "graded-1"
last_reviewed: "2026-08-20"
review_interval: 6m
escalation: required escalation: required
escalation_trigger: 2 escalation_trigger: 2
escalation_status: partially-answered escalation_status: partially-answered

View file

@ -43,7 +43,7 @@ batch — so the route wants to exist before it is needed, not during.
```task ```task
id: RISK-WP-0002-T01 id: RISK-WP-0002-T01
status: todo status: progress
priority: high priority: high
``` ```
@ -56,11 +56,13 @@ or as a summary?** `RISK-F-0001` contains a full ruling, a re-grade, a review
log and this register's own process defect. Some of that is register-internal log and this register's own process defect. Some of that is register-internal
work product. Decide once, here, and apply it to every later publication. work product. Decide once, here, and apply it to every later publication.
In progress 2026-08-20. Operator ruled: findings publish **whole**. Publication front-matter applied to `RISK-F-0001` and `RISK-F-0008` (`revision`, `last_reviewed`, `review_interval: 6m`) with proposed ids, paths and subtitles; both now read `publication: requested`. Handover request sent to `policy-nexus`. The open question the task named is answered and recorded in `docs/rulings/2026-08-20-publication.md` — including that `RISK-F-0001` publishes with the paragraph about this register grading it wrong.
### T02 — Rule on the method documents ### T02 — Rule on the method documents
```task ```task
id: RISK-WP-0002-T02 id: RISK-WP-0002-T02
status: todo status: done
priority: medium priority: medium
``` ```
@ -78,6 +80,8 @@ Suggested split, to be ruled on rather than assumed: severity and disclosure
public, escalation and review internal. Escalation in particular describes when public, escalation and review internal. Escalation in particular describes when
the operator is interrupted, which is not the estate's business to advertise. the operator is interrupted, which is not the estate's business to advertise.
Completed 2026-08-20. Public: `severity`, `disclosure`, `review`, `verification`, `dependencies` — the instruments a reader needs to judge whether a published finding means anything. Restricted: `escalation`, because it names the operator's spend thresholds and describes when the operator personally is interrupted, which is a map of where attention is scarce and is needed by nobody judging a finding. `check-procedure` stays internal by omission: an operating manual, not an instrument.
### T03 — The standing route ### T03 — The standing route
```task ```task