A risk management service.
Find a file
tegwick 7d6ded5743 The inbox round: two grades corrected, one note promoted
Read the repo inbox after grading, which is the wrong order and is now
recorded as such. flex-auth had answered the NetworkPolicy question on
2026-08-18 (narrow ingress, not default-deny — L3 becomes L2, critical
becomes high) and reported RISK-F-0001 fixed at 12:35 today with live 401
probes. F-0001 closes fixed and public; its escalation is withdrawn
before it was ever sent. RISK-F-0002's ordering constraint lifts with it
and its trigger-6 escalation is withdrawn.

audit-core had routed the erasure-versus-audit legal question here on
2026-08-18 asking for an owner. RISK-N-0002 was wrong to call it a note:
the remedy is not retrofittable, so the decision can only be taken early.
Promoted to RISK-F-0008, owned by this repo as regulatory intake,
escalated on trigger 2.

Accepted rapp-postgres's record format and ops-warden's typed-act
escalation vocabulary. Reading the inbox is now question zero of every
review.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 23:38:07 +02:00
docs The inbox round: two grades corrected, one note promoted 2026-08-19 23:38:07 +02:00
findings The inbox round: two grades corrected, one note promoted 2026-08-19 23:38:07 +02:00
notes The inbox round: two grades corrected, one note promoted 2026-08-19 23:38:07 +02:00
tools RISK-WP-0001 T01-T06,T08: the four instruments, the index, and the first grading 2026-08-19 23:29:39 +02:00
workplans Close out RISK-WP-0001: task notes, README, repo classification 2026-08-19 23:34:34 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-19 23:19:40 +02:00
.repo-classification.yaml Close out RISK-WP-0001: task notes, README, repo classification 2026-08-19 23:34:34 +02:00
INTENT.md INTENT: the register is no longer empty, and the first finding tested the deferral 2026-08-17 22:52:37 +02:00
Makefile RISK-WP-0001 T01-T06,T08: the four instruments, the index, and the first grading 2026-08-19 23:29:39 +02:00
README.md Close out RISK-WP-0001: task notes, README, repo classification 2026-08-19 23:34:34 +02:00
REGISTER.md The inbox round: two grades corrected, one note promoted 2026-08-19 23:38:07 +02:00
WORK-RECORDS.md The inbox round: two grades corrected, one note promoted 2026-08-19 23:38:07 +02:00

risk-nexus

Risk register and regulatory intake for the estate. Serves risk.coulomb.social. Owned by the-custodian.

Holds findings — security, architecture, operational, compliance — with a severity, an owner and a date; decides whether and when each is published; and decides which must reach the operator personally rather than sitting in a register.

It does not fix things: findings route to the repo that owns the defect. It does not host: policy-nexus is the publication surface.

Where things are

  • REGISTER.md — the whole register, one screen. Generated; do not edit.
  • findings/ — one file per finding. findings/README.md is the filing contract for reporting repos.
  • notes/ — seen, deliberately below the floor. Not graded, not reviewed.
  • docs/method/ — how this repo decides: severity, disclosure, escalation, review and expiry.
  • docs/rulings/ — the reasoning behind each grading, dated.
  • workplans/ — the work.

Using it

make register   # rebuild REGISTER.md from findings/
make check      # verify the index, then report what is going quiet

make check reports ungraded findings, overdue reviews, stalled remediation, embargoes due for re-decision, escalations awaiting the operator, and what is owed at the production transition. It changes nothing.

  • Intent: INTENT.md