Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
6 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | depends_on_workplans | state_hub_workstream_id | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| RISK-WP-0002 | workplan | Hand the publishable findings to policy-nexus, and decide what else is a public document | infotech | risk-nexus | finished | the-custodian | risk-nexus | 2026-08-20 | 2026-09-01 |
|
b79af69c-5b08-55df-8caa-258eed3e397e |
RISK-WP-0002 — publication handover
Finished 2026-09-01. Sized deliberately small: two documents were ready and the rest was a decision, not a project.
Goal
RISK-F-0001 and RISK-F-0008 carry disclosure: public and
publication: pending-handover. Get them onto policy.coulomb.social under
policy-nexus's existing contract, and settle whether this repo's method
documents are public too.
Done means: both findings have a permanent address, publication: published,
and a recorded answer on the method documents.
Why now
Six findings are embargoed with lift conditions, and RISK-F-0009 has already
demonstrated that a condition can be met and the embargo still hold. When those
conditions start clearing, publication will happen in a trickle rather than a
batch — so the route wants to exist before it is needed, not during.
policy-nexus has been told this is coming (2026-08-20) and asked for nothing.
Tasks
T01 — Publish the two ready findings
id: RISK-WP-0002-T01
status: done
priority: high
state_hub_task_id: "9ac32008-76b6-591c-82a1-ad6e2f8368b7"
Follow policy-nexus's publication contract as it stands. Do not invent an
address scheme: POLICY-NEXUS-WP-0001 settled addressing and permanence, and
this repo is a consumer of that decision.
Open question for T01 rather than an assumption: is a finding published whole,
or as a summary? RISK-F-0001 contains a full ruling, a re-grade, a review
log and this register's own process defect. Some of that is register-internal
work product. Decide once, here, and apply it to every later publication.
In progress 2026-08-20. Operator ruled: findings publish whole. Publication front-matter applied to RISK-F-0001 and RISK-F-0008 (revision, last_reviewed, review_interval: 6m) with proposed ids, paths and subtitles; both now read publication: requested. Handover request sent to policy-nexus. The open question the task named is answered and recorded in docs/rulings/2026-08-20-publication.md — including that RISK-F-0001 publishes with the paragraph about this register grading it wrong.
Completed 2026-09-01. policy-nexus admitted findings and public risk methods
as explicit publication kinds. The two findings publish whole at permanent
addresses and record those addresses back in their source files. The five
public method instruments — severity, disclosure, review, verification and
dependencies — publish beside them. Escalation and check-procedure remain
internal as ruled in T02.
T02 — Rule on the method documents
id: RISK-WP-0002-T02
status: done
priority: medium
state_hub_task_id: "ce61806e-02c8-594f-a7b6-88f21d0ee371"
docs/method/severity.md, disclosure.md, escalation.md, review.md.
The case for publishing: they say how the estate grades and holds risk, which is exactly what an outside reader needs to judge whether a published finding means anything.
The case against: the escalation rule names the operator's own thresholds, and the severity scale is a judgement instrument this repo revises freely. A published instrument invites argument about the instrument.
Suggested split, to be ruled on rather than assumed: severity and disclosure public, escalation and review internal. Escalation in particular describes when the operator is interrupted, which is not the estate's business to advertise.
Completed 2026-08-20. Public: severity, disclosure, review, verification, dependencies — the instruments a reader needs to judge whether a published finding means anything. Restricted: escalation, because it names the operator's spend thresholds and describes when the operator personally is interrupted, which is a map of where attention is scarce and is needed by nobody judging a finding. check-procedure stays internal by omission: an operating manual, not an instrument.
T03 — The standing route
id: RISK-WP-0002-T03
status: done
priority: medium
state_hub_task_id: "595737b7-19f3-5c39-b208-958c57775bc2"
Write down what happens when an embargo lifts: who hands over, in what shape,
and how publication: published gets recorded back on the finding.
Small. It is a paragraph in docs/method/disclosure.md plus whatever
policy-nexus needs on their side, not a mechanism.
Completed 2026-08-20. The route is in docs/method/disclosure.md: the check that lifts the embargo records it, the finding gets publication front-matter in the shape policy-nexus already requires (owner, revision, last_reviewed, review_interval), this repo asks for an entry with source_repo/source_path/proposed canonical_path, and publication: published plus the URL comes back onto the finding — because a finding that says public with no address is a claim, not a publication.
One thing the contract settled for T01: publication.json publishes a file from the source repo, so a reader gets exactly what is handed over. Whole-versus-summary is therefore a decision about what a finding file contains, not about rendering.
Non-goals
- No publication surface here.
policy-nexushosts; this repo hands over. - No timed release, no coordinated disclosure, no notification tiers. Those stay
deferred (
docs/method/disclosure.md) until there are real users. - No re-grading of anything to make it publishable.
Risks
A finding is published with an internal ruling attached. Mitigation: T01 decides whole-versus-summary before anything ships.
The handover becomes a project. Mitigation: three tasks, one of which is a
paragraph. If it grows, that is a signal the publication contract does not fit
findings, and that is a conversation with policy-nexus rather than more tasks
here.