ops-warden filed this static, saying its OpenBao token was expired. It was not --
bao policy read succeeded, so the deployed policy has now been compared directly.
Coverage confirmed at 6 of 17. But the uncovered count was wrong: eight included
a path pattern and a broker grant, neither of which a policy can deny, and the
finding's own prose already said so about the first. Six stand.
New: the deployed policy differs from the file in railiance-platform -- the file
denies core-hub/runtime, the server does not. No ops-warden lane maps there, so
the numbers are unchanged. It matters because this finding named "the deployed
policy may differ from the file" as unconfirmed, and it does.
Severity, disclosure and embargo left untouched -- risk-nexus's to set. The
embargo condition is a coverage report from railiance-platform, which this does
not satisfy.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The register had nine waits in four days, one four hops deep: F-0003's
embargo waited on F-0009, which waited on railiance-platform, which
waited on live OpenBao verification, which waited on a credential nobody
has. No single link was wrong, which is why it needed a rule.
docs/method/dependencies.md: the register never waits to decide, it
decides and revises. Every wait carries who, what, since, what it would
change, what happens if nobody answers, and the date that default
applies. Depth one — a record never waits on a record that is itself
waiting. Defaults are dates and are pessimistic: silence costs the grade
the evidence supports rather than buying a softer one, and owners are
told the default in advance because a default nobody was warned about is
an ambush.
Applied: F-0009's embargo now lifts on railiance-platform reporting
coverage, with live verification as a refinement rather than a condition,
cutting the F-0003 chain from four hops to two. All eight open waits are
typed with defaults. make check reports them with age, owner and default
date, flags defaults come due, and catches depth-two violations.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Nine records checked. Five clean and climbed to 1h: RISK-F-0003, 0004,
0005, 0006, 0009 and RISK-REG-0001. Three moved and stay at instant —
RISK-F-0002 (RISK-V-0001 found the flex-auth-ops-warden policy admits no
ingress, so the live question there is now availability rather than
attestation), RISK-F-0007 (the on-request path walked for the first time
as RISK-V-0002), RISK-F-0008 (the determination now exists).
The rule: a finding recorded as moved is not clean-checked in the same
sitting. Re-reading your own keystrokes and climbing produces a rung that
says the world held still when what held still was the last five minutes.
The rung carries stability information or it carries nothing.
record_check.py now handles regulatory records as well as findings.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Operator ruling 2026-08-20. Severity no longer sets the review interval.
A check that comes back clean climbs one rung — instant, 1h, 8h, 24h,
48h, 96h, 7d, 14d, 1mo, 1q — and anything wrong drops straight back to
instant. A quarter is the ceiling. The operator may defer an instant
finding to a stated date; that is the only other way off the bottom rung.
The rung is the point: it says how stable the estate has been on that
matter, which is information severity does not carry. Volatile things get
attention automatically; quiet things stop consuming it; neither
judgement has to be made by a person who might be busy.
Escalation trigger 5 rebased onto the ladder — fourteen days at the
bottom rung, whether that is failing checks or no checks.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 07:43:51 +02:00
Renamed from findings/RISK-F-0004-agent-boundary-policy-covers-a-third-of-high-risk-lanes.md (Browse further)