--- id: RISK-WP-0007 type: workplan title: "Reconcile owner evidence and keep runtime closure obligations visible" domain: infotech repo: risk-nexus status: finished owner: the-custodian topic_slug: custodian created: "2026-09-05" updated: "2026-09-05" depends_on_workplans: - RISK-WP-0006 state_hub_workstream_id: "ac12733f-3f4b-5c7b-aee7-7115b9c4db72" --- # RISK-WP-0007 — reconcile owner evidence The repaired reports expose work the register had not read. Reconcile it before building another mechanism. Source remediation is progress; deployed acceptance and credential invalidation require their own evidence. ## T01 — Reconcile the qonto return ```task id: RISK-WP-0007-T01 status: done priority: high state_hub_task_id: "d3f0a9b7-4374-5350-b0b4-d7ac4f782acb" ``` Read the newer inbox notice, source cadence/logger/endpoint and observer workplan. Link QONTO-WP-0005 and KG-WP-0005-T03 to F-0011; replace the stale missing-source claim with the concrete runtime acceptance obligation. Keep the medium grade and open status until that obligation is demonstrated. Record a moved check. ## T02 — Reconcile backup source remediation ```task id: RISK-WP-0007-T02 status: done priority: high state_hub_task_id: "215b8b0b-aef0-5575-bf12-b08dc2941cbe" ``` Read RPF-WP-0029 and verify source fallback removal without displaying, testing or copying credential material. Link provider invalidation/recovery tracking; keep the low grade, open status and embargo until the original conditions hold. Record a moved check, retaining the existing deadline. ## T03 — Distinguish accepted obligations from missing fixes ```task id: RISK-WP-0007-T03 status: done priority: high state_hub_task_id: "a17feb05-2c2c-5372-adbb-9d2c095f55fd" ``` Report an accepted record's accepter, expiry condition, determination and review date when those fields resolve to a real record. Do not invent a fix workplan for F-0008 or suppress incomplete acceptance records. Surface closure conditions even when the source workplan is completed. Cover both paths with regression tests. Inspect F-0008's technical evidence without renewing legal conclusions or certifying that its real-data trigger remains false. ## T04 — Record verification boundaries and register the result ```task id: RISK-WP-0007-T04 status: done priority: medium state_hub_task_id: "ebf1edad-6e0e-5fdc-9781-5e79cff8b117" ``` Retain dated source evidence, explicit next evidence and owners. Inspect local external-intake/publication and activity evidence; state exactly what remains unverified. Update scope/state/index, run tests and reports, register this workplan and its tasks, and verify completion in State Hub. ## Boundaries No messages, acknowledgements, deployments, credential actions, publication, new spending or automatic finding closure. Existing source-owner workplans remain authoritative. This plan closes the register's reconciliation work, not the owners' unresolved runtime obligations or the substantive legal reviews. ## Completion evidence Completed 2026-09-05. RISK-V-0003 retains the inspected source evidence, provenance and runtime/provider acceptance requirements. F-0011 now tracks QONTO-WP-0005 and KG-WP-0005-T03; F-0010 tracks RPF-WP-0029-T02. Both received `moved` outcomes and remain at `instant`; no same-sitting clean check was made. Grades, open statuses, the credential embargo and original default dates remain. F-0008's technical inspection is explicitly not a completed substantive review. Its existing acceptance is now reported with its determination and due date; invalid/incomplete acceptances still produce missing-tracking warnings. The closure-evidence section survives completed source workplans. Ten isolated tests pass via `make test`; document links and `git diff --check` pass. The generated register and live checker expose the two waiting owner tasks, recorded acceptance, four overdue full policies and eight publication handovers. State Hub registration succeeded for workplan `ac12733f-3f4b-5c7b-aee7-7115b9c4db72` and all four tasks (UUIDs in source). Completion status and backing-file binding are reconciled through the same API; the local WORK-RECORDS index is regenerated with the State Hub renderer. Still external or unverified: runtime capture/observer acceptance, provider invalidation/recovery receipts, acceptance-trigger facts and legal reviews, external contact delivery and scheduled-session completion. Source searches establish no stronger conclusion. No messages or acknowledgements were sent.