A risk management service.
ops-warden filed this static, saying its OpenBao token was expired. It was not -- bao policy read succeeded, so the deployed policy has now been compared directly. Coverage confirmed at 6 of 17. But the uncovered count was wrong: eight included a path pattern and a broker grant, neither of which a policy can deny, and the finding's own prose already said so about the first. Six stand. New: the deployed policy differs from the file in railiance-platform -- the file denies core-hub/runtime, the server does not. No ops-warden lane maps there, so the numbers are unchanged. It matters because this finding named "the deployed policy may differ from the file" as unconfirmed, and it does. Severity, disclosure and embargo left untouched -- risk-nexus's to set. The embargo condition is a coverage report from railiance-platform, which this does not satisfy. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| activity-definitions | ||
| docs | ||
| findings | ||
| notes | ||
| tools | ||
| workplans | ||
| .custodian-brief.md | ||
| .repo-classification.yaml | ||
| INTENT.md | ||
| Makefile | ||
| README.md | ||
| REGISTER.md | ||
| WORK-RECORDS.md | ||
risk-nexus
Risk register and regulatory intake for the estate. Serves
risk.coulomb.social. Owned by the-custodian.
Holds findings — security, architecture, operational, compliance — with a severity, an owner and a date; decides whether and when each is published; and decides which must reach the operator personally rather than sitting in a register.
It does not fix things: findings route to the repo that owns the defect. It
does not host: policy-nexus is the publication surface.
Where things are
REGISTER.md— the whole register, one screen. Generated; do not edit.findings/— one file per finding.findings/README.mdis the filing contract for reporting repos.notes/— seen, deliberately below the floor. Not graded, not reviewed.docs/method/— how this repo decides: severity, disclosure, escalation, review and expiry.docs/rulings/— the reasoning behind each grading, dated.workplans/— the work.
Using it
make register # rebuild REGISTER.md from findings/
make check # verify the index, then report what is going quiet
make check reports ungraded findings, overdue reviews, stalled remediation,
embargoes due for re-decision, escalations awaiting the operator, and what is
owed at the production transition. It changes nothing.
- Intent:
INTENT.md