Commit graph

10 commits

Author SHA1 Message Date
f0db7c83ca RISK-WP-0002: findings publish whole; method docs public except escalation
Operator ruled both. Findings publish as the file a reader gets —
including RISK-F-0001's record that this register graded it critical
while its fix notice sat unread. A summary would be a second document per
finding kept in sync by hand, and drift is the failure this repo most
distrusts; and a published register containing only other repos' defects
reads as an accusation, while one containing its own reads as a record.

Method docs public except escalation, which is restricted because it
names spend thresholds and describes when the operator personally is
interrupted — a map of where attention is scarce, needed by nobody
judging a finding.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 22:43:48 +02:00
7dc8d01a63 RISK-WP-0002-T03: the standing handover route
Written now rather than at the first lift, because publication arrives in
a trickle and a route improvised each time is one that eventually is not
taken. Also settles a T01 input: policy-nexus publishes a file from the
source repo, so whole-versus-summary is a question about what a finding
file contains, not about rendering.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 22:41:18 +02:00
54606c883e Close RISK-WP-0004: all six tasks done
The previous commit shipped the activity definitions but a script error
left the workplan file unedited, so the task states are recorded here.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 08:56:17 +02:00
36b707f0c3 RISK-WP-0004: five of six tasks done; the executor is the operator's call
T02 inbox check, wired into make check and verified against the actual
2026-08-19 failure — replayed at that moment it surfaces all three
messages that were already waiting. T03 sweeps the rest of the
quietly-tolerated class: bad dates, cadence off the ladder, undefined
disclosure states, dangling constraint_on and related refs, embargoes
without conditions, escalations without triggers. T04 requests
verification of user-engine's tenant boundary — the first walk down the
on-request path, chosen as a consumer not already known to fail it. T05
established by trying what this register can verify: cluster yes, OpenBao
403. T06 puts regulatory records on the findings ladder.

T01 stays in progress: the procedure, make due and make checked exist,
but arming something that runs them on schedule is a standing compute
commitment and the operator's to make.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 08:49:23 +02:00
97fcc56a4d RISK-WP-0004-T05: establish what this register can verify, by trying it
Cluster reads work from this host; OpenBao returns 403, the same wall
ops-warden hit. So the register can check what the cluster admits and
cannot check what the secret store permits, and every grade touching an
OpenBao policy is a grade on a document. That asymmetry is recorded
rather than closed: a risk register holding production secret-store
access would have traded a verification problem for a worse one.

RISK-V-0001 is the first verification. It confirms RISK-F-0001's ingress
claim against the live cluster — the first grade here standing on
evidence this repo gathered — contradicts the 'egress: []' claim, which
live shows as 443/6443 to anywhere, and surfaces a third policy created
the day of the fix whose Ingress policyType carries no rules, which bears
on whether enabling ops-warden's gate would fail closed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 08:46:06 +02:00
a798a4c771 Draft RISK-WP-0002, RISK-WP-0003, RISK-WP-0004
Publication handover (two findings ready, three tasks, one of which is a
paragraph); regulatory intake as a working remit rather than one record,
carrying RISK-REG-0001's open items; and running the register, where
every task traces to something that actually went wrong in week one —
grading before reading the inbox, a status the tooling did not know, an
id collision, two gradings resting on file comparison because a token
expired, and an on-request path nobody has walked.

All three are status: proposed. The custodian decides which become active
and in what order.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 08:07:06 +02:00
76a96fcf44 Publication handover and inbox-first as residuals of RISK-WP-0001
Also records in T06 that the first grading ran before the inbox was read.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 23:41:07 +02:00
37906c3a22 Close out RISK-WP-0001: task notes, README, repo classification
T01, T02, T04-T08 done. T03 stays in progress: the escalation rule is
written and proposed, and it is not adopted until the custodian rules on
it — an unadopted rule is worse than an unwritten one because it looks
like coverage.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 23:34:34 +02:00
e8ee138ad2 Use the canon-registered id scheme for the workplan prefix
work-record-types_v0.1 pins workplan ids to ^[A-Z]+-WP-[0-9]{4}$ and tasks
to that plus -TNN; a hyphenated RISK-NEXUS prefix trips the sidetrack
detector. RISK-WP also matches the register's existing RISK-F finding
prefix. Renamed before the workplan was indexed anywhere.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 23:20:31 +02:00
63dde5fa38 RISK-NEXUS-WP-0001 — make the register decidable
The three open findings all leave severity, disclosure and escalation
unset, correctly: those are this repo's to set and the instruments to set
them with do not exist yet. The workplan writes the severity scale, the
disclosure states (re-taking the deferral with RISK-F-0001 in hand), the
escalation rule INTENT.md says is unwritten, and the review/expiry rule —
then grades the three findings and rules on what is waiting outside the
register.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 23:19:16 +02:00