--- id: RISK-RULING-2026-09-02-A type: ruling title: "Inbox intake: qonto-assistant audit.deny stream completeness" status: adopted owner: risk-nexus adopted: "2026-09-02" review_interval: 6m disclosure: public revision: "adopted-1" last_reviewed: "2026-09-02" --- # Inbox intake — 2026-09-02 One unread finding-intake from Gate House. The two findings already due were read against it first; it does not speak about them. ## Decision | Finding | Prior state | Ruling | Evidence that changes it | | --- | --- | --- | --- | | `RISK-F-0011` | unfiled | medium, public, open | live deny observed; no heartbeat, cadence, or reconciliation view; local lockout does not consume the stream | The reporter asked for a finding, a note, or an explicit rejection. It is a finding. Both floor tests hold: qonto-assistant can publish or reject a cadence, and recording this changes whether anyone may treat the deny stream as complete. It is not a note. `RISK-N-0004` is the missing-capability shape with no owner and nothing to route. Here the owner is named, the residual is already routed, and observation is already staffed on a claim it cannot finish. ## Why medium, and why not the reporter's "load-bearing" reading unmodified Gate House said the `audit.deny` class is load-bearing because qonto-assistant's escalation loop branches on it. Current source narrows that. `DenyEscalationTracker` is in-process on the decision path; `AuditLogger.emit` is a parallel record. A missing audit line would not, today, turn the Fast Local Loop off. The stream is still load-bearing for **estate observation**. King's Guard already consumes it. Without a cadence or a reconciliation view, that observation can preserve a received deny and cannot vouch for the stream. That is the defect. `I2` not `I3`: one lane's observation, not a crossed authorization or tenant boundary. Access remains denied in the observed case; the local lockout is independent of the stream. `L3` not `L4`: completeness unknown is not "denies are being dropped". The reporter said so, and this register follows it. `L3` not `L2` because the working set already reads the stream. No fidelity modifier: the observer did not claim completeness. ## What is not decided here Taxonomy ownership of an emission-cadence declaration (net-kingdom / info-tech-canon) stays their residual. Depth-one: this finding waits on qonto-assistant, defaults on 2026-09-16, and does not wait on a canon debate that has not yet failed one routing exchange. ## Same sitting, already-due findings `RISK-F-0010` and `RISK-F-0008` / `RISK-REG-0001` were due from 2026-09-01. The intake does not mention them. Owner records have not moved since that check. Their outcomes are recorded with `make checked`, not re-graded here. `RISK-F-0011` is not clean-checked in this sitting.