Commit graph

2 commits

Author SHA1 Message Date
38e083ed3d INTENT: the register is no longer empty, and the first finding tested the deferral
Controlled disclosure was deferred to production on the reasoning that build
mode has no users to expose. The first finding to arrive is a live
authorization bypass in the service every other service trusts, where the
choice today is publish or hold with nothing between. The deferral may still be
right; it is now a decision with a real case in hand.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 22:52:37 +02:00
45db859942 Seed INTENT: risk register, regulatory intake, escalation duty
Owned by the-custodian alongside policy-nexus, with the duty of deciding what
must reach the operator personally.

Three things had nowhere to live. Findings landed in whichever document
discovered them - the estate's largest known gap is currently open question 3
in an unratified draft, with no owner, severity or date. Disclosure had no
mechanism, only publish-now or forget, which is fine in build mode and wrong at
production. And regulation was researched at the moment it was needed and never
retained.

Regulatory intake moves here from policy-nexus T06: deciding what a rule
demands of us is a judgement about risk, not an act of publishing. That also
leaves policy-nexus doing one thing, which was the point.

Two constraints written in deliberately. This repo does not fix - findings
route to the repo owning the defect, because a risk service that fixes becomes
a second engineering team with no boundary. And it does not block delivery in
build mode; if that changes it will be a decision recorded here, not a habit
that accretes.

The escalation rule is named as unwritten rather than invented. Getting it
wrong in either direction fails: escalate everything and the operator becomes
the queue, escalate nothing and the register is where serious things go quiet.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:55:30 +02:00