Operator ruled both. Findings publish as the file a reader gets —
including RISK-F-0001's record that this register graded it critical
while its fix notice sat unread. A summary would be a second document per
finding kept in sync by hand, and drift is the failure this repo most
distrusts; and a published register containing only other repos' defects
reads as an accusation, while one containing its own reads as a record.
Method docs public except escalation, which is restricted because it
names spend thresholds and describes when the operator personally is
interrupted — a map of where attention is scarce, needed by nobody
judging a finding.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Written now rather than at the first lift, because publication arrives in
a trickle and a route improvised each time is one that eventually is not
taken. Also settles a T01 input: policy-nexus publishes a file from the
source repo, so whole-versus-summary is a question about what a finding
file contains, not about rendering.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The previous commit shipped the activity definitions but a script error
left the workplan file unedited, so the task states are recorded here.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
T02 inbox check, wired into make check and verified against the actual
2026-08-19 failure — replayed at that moment it surfaces all three
messages that were already waiting. T03 sweeps the rest of the
quietly-tolerated class: bad dates, cadence off the ladder, undefined
disclosure states, dangling constraint_on and related refs, embargoes
without conditions, escalations without triggers. T04 requests
verification of user-engine's tenant boundary — the first walk down the
on-request path, chosen as a consumer not already known to fail it. T05
established by trying what this register can verify: cluster yes, OpenBao
403. T06 puts regulatory records on the findings ladder.
T01 stays in progress: the procedure, make due and make checked exist,
but arming something that runs them on schedule is a standing compute
commitment and the operator's to make.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Cluster reads work from this host; OpenBao returns 403, the same wall
ops-warden hit. So the register can check what the cluster admits and
cannot check what the secret store permits, and every grade touching an
OpenBao policy is a grade on a document. That asymmetry is recorded
rather than closed: a risk register holding production secret-store
access would have traded a verification problem for a worse one.
RISK-V-0001 is the first verification. It confirms RISK-F-0001's ingress
claim against the live cluster — the first grade here standing on
evidence this repo gathered — contradicts the 'egress: []' claim, which
live shows as 443/6443 to anywhere, and surfaces a third policy created
the day of the fix whose Ingress policyType carries no rules, which bears
on whether enabling ops-warden's gate would fail closed.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Publication handover (two findings ready, three tasks, one of which is a
paragraph); regulatory intake as a working remit rather than one record,
carrying RISK-REG-0001's open items; and running the register, where
every task traces to something that actually went wrong in week one —
grading before reading the inbox, a status the tooling did not know, an
id collision, two gradings resting on file comparison because a token
expired, and an on-request path nobody has walked.
All three are status: proposed. The custodian decides which become active
and in what order.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
T01, T02, T04-T08 done. T03 stays in progress: the escalation rule is
written and proposed, and it is not adopted until the custodian rules on
it — an unadopted rule is worse than an unwritten one because it looks
like coverage.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
work-record-types_v0.1 pins workplan ids to ^[A-Z]+-WP-[0-9]{4}$ and tasks
to that plus -TNN; a hyphenated RISK-NEXUS prefix trips the sidetrack
detector. RISK-WP also matches the register's existing RISK-F finding
prefix. Renamed before the workplan was indexed anywhere.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The three open findings all leave severity, disclosure and escalation
unset, correctly: those are this repo's to set and the instruments to set
them with do not exist yet. The workplan writes the severity scale, the
disclosure states (re-taking the deferral with RISK-F-0001 in hand), the
escalation rule INTENT.md says is unwritten, and the review/expiry rule —
then grades the three findings and rules on what is waiting outside the
register.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>