--- id: RISK-WP-0002 type: workplan title: "Hand the publishable findings to policy-nexus, and decide what else is a public document" domain: infotech repo: risk-nexus status: finished owner: the-custodian topic_slug: risk-nexus created: "2026-08-20" updated: "2026-09-01" depends_on_workplans: - RISK-WP-0001 state_hub_workstream_id: "b79af69c-5b08-55df-8caa-258eed3e397e" --- # RISK-WP-0002 — publication handover Finished 2026-09-01. Sized deliberately small: two documents were ready and the rest was a decision, not a project. ## Goal `RISK-F-0001` and `RISK-F-0008` carry `disclosure: public` and `publication: pending-handover`. Get them onto `policy.coulomb.social` under `policy-nexus`'s existing contract, and settle whether this repo's method documents are public too. Done means: both findings have a permanent address, `publication: published`, and a recorded answer on the method documents. ## Why now Six findings are embargoed with lift conditions, and `RISK-F-0009` has already demonstrated that a condition can be met and the embargo still hold. When those conditions start clearing, publication will happen in a trickle rather than a batch — so the route wants to exist before it is needed, not during. `policy-nexus` has been told this is coming (2026-08-20) and asked for nothing. ## Tasks ### T01 — Publish the two ready findings ```task id: RISK-WP-0002-T01 status: done priority: high state_hub_task_id: "9ac32008-76b6-591c-82a1-ad6e2f8368b7" ``` Follow `policy-nexus`'s publication contract as it stands. Do not invent an address scheme: `POLICY-NEXUS-WP-0001` settled addressing and permanence, and this repo is a consumer of that decision. Open question for T01 rather than an assumption: **is a finding published whole, or as a summary?** `RISK-F-0001` contains a full ruling, a re-grade, a review log and this register's own process defect. Some of that is register-internal work product. Decide once, here, and apply it to every later publication. In progress 2026-08-20. Operator ruled: findings publish **whole**. Publication front-matter applied to `RISK-F-0001` and `RISK-F-0008` (`revision`, `last_reviewed`, `review_interval: 6m`) with proposed ids, paths and subtitles; both now read `publication: requested`. Handover request sent to `policy-nexus`. The open question the task named is answered and recorded in `docs/rulings/2026-08-20-publication.md` — including that `RISK-F-0001` publishes with the paragraph about this register grading it wrong. Completed 2026-09-01. `policy-nexus` admitted findings and public risk methods as explicit publication kinds. The two findings publish whole at permanent addresses and record those addresses back in their source files. The five public method instruments — severity, disclosure, review, verification and dependencies — publish beside them. Escalation and check-procedure remain internal as ruled in T02. ### T02 — Rule on the method documents ```task id: RISK-WP-0002-T02 status: done priority: medium state_hub_task_id: "ce61806e-02c8-594f-a7b6-88f21d0ee371" ``` `docs/method/severity.md`, `disclosure.md`, `escalation.md`, `review.md`. The case for publishing: they say how the estate grades and holds risk, which is exactly what an outside reader needs to judge whether a published finding means anything. The case against: the escalation rule names the operator's own thresholds, and the severity scale is a judgement instrument this repo revises freely. A published instrument invites argument about the instrument. Suggested split, to be ruled on rather than assumed: severity and disclosure public, escalation and review internal. Escalation in particular describes when the operator is interrupted, which is not the estate's business to advertise. Completed 2026-08-20. Public: `severity`, `disclosure`, `review`, `verification`, `dependencies` — the instruments a reader needs to judge whether a published finding means anything. Restricted: `escalation`, because it names the operator's spend thresholds and describes when the operator personally is interrupted, which is a map of where attention is scarce and is needed by nobody judging a finding. `check-procedure` stays internal by omission: an operating manual, not an instrument. ### T03 — The standing route ```task id: RISK-WP-0002-T03 status: done priority: medium state_hub_task_id: "595737b7-19f3-5c39-b208-958c57775bc2" ``` Write down what happens when an embargo lifts: who hands over, in what shape, and how `publication: published` gets recorded back on the finding. Small. It is a paragraph in `docs/method/disclosure.md` plus whatever `policy-nexus` needs on their side, not a mechanism. Completed 2026-08-20. The route is in `docs/method/disclosure.md`: the check that lifts the embargo records it, the finding gets publication front-matter in the shape `policy-nexus` already requires (`owner`, `revision`, `last_reviewed`, `review_interval`), this repo asks for an entry with `source_repo`/`source_path`/proposed `canonical_path`, and `publication: published` plus the URL comes back onto the finding — because a finding that says `public` with no address is a claim, not a publication. One thing the contract settled for T01: `publication.json` publishes **a file from the source repo**, so a reader gets exactly what is handed over. Whole-versus-summary is therefore a decision about what a finding file contains, not about rendering. ## Non-goals - No publication surface here. `policy-nexus` hosts; this repo hands over. - No timed release, no coordinated disclosure, no notification tiers. Those stay deferred (`docs/method/disclosure.md`) until there are real users. - No re-grading of anything to make it publishable. ## Risks **A finding is published with an internal ruling attached.** Mitigation: T01 decides whole-versus-summary before anything ships. **The handover becomes a project.** Mitigation: three tasks, one of which is a paragraph. If it grows, that is a signal the publication contract does not fit findings, and that is a conversation with `policy-nexus` rather than more tasks here.