risk-nexus/workplans/RISK-WP-0002-publication-handover.md
tegwick f0db7c83ca RISK-WP-0002: findings publish whole; method docs public except escalation
Operator ruled both. Findings publish as the file a reader gets —
including RISK-F-0001's record that this register graded it critical
while its fix notice sat unread. A summary would be a second document per
finding kept in sync by hand, and drift is the failure this repo most
distrusts; and a published register containing only other repos' defects
reads as an accusation, while one containing its own reads as a record.

Method docs public except escalation, which is restricted because it
names spend thresholds and describes when the operator personally is
interrupted — a map of where attention is scarce, needed by nobody
judging a finding.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 22:43:48 +02:00

5.3 KiB

id type title domain repo status owner topic_slug created updated depends_on_workplans
RISK-WP-0002 workplan Hand the publishable findings to policy-nexus, and decide what else is a public document infotech risk-nexus active the-custodian risk-nexus 2026-08-20 2026-08-20
RISK-WP-0001

RISK-WP-0002 — publication handover

Draft. Sized deliberately small: two documents are ready and the rest is a decision, not a project.

Goal

RISK-F-0001 and RISK-F-0008 carry disclosure: public and publication: pending-handover. Get them onto policy.coulomb.social under policy-nexus's existing contract, and settle whether this repo's method documents are public too.

Done means: both findings have a permanent address, publication: published, and a recorded answer on the method documents.

Why now

Six findings are embargoed with lift conditions, and RISK-F-0009 has already demonstrated that a condition can be met and the embargo still hold. When those conditions start clearing, publication will happen in a trickle rather than a batch — so the route wants to exist before it is needed, not during.

policy-nexus has been told this is coming (2026-08-20) and asked for nothing.

Tasks

T01 — Publish the two ready findings

id: RISK-WP-0002-T01
status: progress
priority: high

Follow policy-nexus's publication contract as it stands. Do not invent an address scheme: POLICY-NEXUS-WP-0001 settled addressing and permanence, and this repo is a consumer of that decision.

Open question for T01 rather than an assumption: is a finding published whole, or as a summary? RISK-F-0001 contains a full ruling, a re-grade, a review log and this register's own process defect. Some of that is register-internal work product. Decide once, here, and apply it to every later publication.

In progress 2026-08-20. Operator ruled: findings publish whole. Publication front-matter applied to RISK-F-0001 and RISK-F-0008 (revision, last_reviewed, review_interval: 6m) with proposed ids, paths and subtitles; both now read publication: requested. Handover request sent to policy-nexus. The open question the task named is answered and recorded in docs/rulings/2026-08-20-publication.md — including that RISK-F-0001 publishes with the paragraph about this register grading it wrong.

T02 — Rule on the method documents

id: RISK-WP-0002-T02
status: done
priority: medium

docs/method/severity.md, disclosure.md, escalation.md, review.md.

The case for publishing: they say how the estate grades and holds risk, which is exactly what an outside reader needs to judge whether a published finding means anything.

The case against: the escalation rule names the operator's own thresholds, and the severity scale is a judgement instrument this repo revises freely. A published instrument invites argument about the instrument.

Suggested split, to be ruled on rather than assumed: severity and disclosure public, escalation and review internal. Escalation in particular describes when the operator is interrupted, which is not the estate's business to advertise.

Completed 2026-08-20. Public: severity, disclosure, review, verification, dependencies — the instruments a reader needs to judge whether a published finding means anything. Restricted: escalation, because it names the operator's spend thresholds and describes when the operator personally is interrupted, which is a map of where attention is scarce and is needed by nobody judging a finding. check-procedure stays internal by omission: an operating manual, not an instrument.

T03 — The standing route

id: RISK-WP-0002-T03
status: done
priority: medium

Write down what happens when an embargo lifts: who hands over, in what shape, and how publication: published gets recorded back on the finding.

Small. It is a paragraph in docs/method/disclosure.md plus whatever policy-nexus needs on their side, not a mechanism.

Completed 2026-08-20. The route is in docs/method/disclosure.md: the check that lifts the embargo records it, the finding gets publication front-matter in the shape policy-nexus already requires (owner, revision, last_reviewed, review_interval), this repo asks for an entry with source_repo/source_path/proposed canonical_path, and publication: published plus the URL comes back onto the finding — because a finding that says public with no address is a claim, not a publication.

One thing the contract settled for T01: publication.json publishes a file from the source repo, so a reader gets exactly what is handed over. Whole-versus-summary is therefore a decision about what a finding file contains, not about rendering.

Non-goals

  • No publication surface here. policy-nexus hosts; this repo hands over.
  • No timed release, no coordinated disclosure, no notification tiers. Those stay deferred (docs/method/disclosure.md) until there are real users.
  • No re-grading of anything to make it publishable.

Risks

A finding is published with an internal ruling attached. Mitigation: T01 decides whole-versus-summary before anything ships.

The handover becomes a project. Mitigation: three tasks, one of which is a paragraph. If it grows, that is a signal the publication contract does not fit findings, and that is a conversation with policy-nexus rather than more tasks here.