A risk management service.
The three open findings all leave severity, disclosure and escalation unset, correctly: those are this repo's to set and the instruments to set them with do not exist yet. The workplan writes the severity scale, the disclosure states (re-taking the deferral with RISK-F-0001 in hand), the escalation rule INTENT.md says is unwritten, and the review/expiry rule — then grades the three findings and rules on what is waiting outside the register. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| findings | ||
| workplans | ||
| INTENT.md | ||
| README.md | ||
risk-nexus
Risk register and regulatory intake for the estate. Serves
risk.coulomb.social. Owned by the-custodian.
Holds findings — security, architecture, operational, compliance — with a severity, an owner and a date; decides whether and when each is published; and decides which must reach the operator personally rather than sitting in a register.
It does not fix things: findings route to the repo that owns the defect. It
does not host: policy-nexus is the publication surface.
- Intent:
INTENT.md