Commit graph

2 commits

Author SHA1 Message Date
0ff87c22d8 Persist the gap analysis to history/, open RISK-WP-0005
history/2026-08-21-intent-gap-analysis.md follows the estate's history
convention. RISK-WP-0005 carries the seven gaps, ordered so the one place
the register misreports goes first: fix_tracking is a string nobody
reads, so a stalled fix and a silent owner are currently the same thing.

The two INTENT claims with no implementation at all — incident intake and
external report — are T02. STATE.md now says both of those out loud
rather than leaving them to the assessment.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 08:19:57 +02:00
ace941ef05 Assess STATE against INTENT: seven gaps, one sharp failure
The 'a regulation that applies was found before it was needed' test is
not met and cannot be retro-fitted: the policy set found two obligations
already live, the e-invoicing one by about nineteen months. The catalogue
makes the test passable going forward; it does not make that instance a
pass.

Also: remediation tracking does not track — fix_tracking is a string
nobody reads, so an owner who goes quiet and a fix that goes quiet look
identical; there is no intake path for incidents or external reports, so
the register is a self-assessment aggregator rather than what INTENT
claims; and no coverage model, so a system with zero findings is
indistinguishable from one nobody assessed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 08:16:43 +02:00