Severity (impact x likelihood, fidelity modifier for controls that lie, headline-vs-constraint, build-mode double grade, the floor), disclosure (publish/embargoed/restricted, and the build-mode deferral re-taken and narrowed with RISK-F-0001 in hand), escalation (the five INTENT triggers settled plus an ordering-hazard trigger the RISK-F-0002 case forced; proposed, awaiting the custodian), review (intervals, what a review is, what missing one produces, the production re-score). Then applied: RISK-F-0001 critical/embargoed/escalated, RISK-F-0002 medium with a high constraint on RISK-F-0001's remediation, filed as a peer and escalated only on the ordering, RISK-F-0003 high/embargoed/no escalation. No unset field remains. REGISTER.md is generated; make check reports overdue, stalled, ungraded and unanswered escalations without changing anything. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
116 lines
5.2 KiB
Markdown
116 lines
5.2 KiB
Markdown
---
|
|
id: RISK-METHOD-DISCLOSURE
|
|
type: method
|
|
title: "Disclosure: publish now, hold, or restrict"
|
|
status: adopted
|
|
owner: risk-nexus
|
|
adopted: "2026-08-19"
|
|
workplan: RISK-WP-0001-T02
|
|
review_interval: 180d
|
|
---
|
|
|
|
# Disclosure
|
|
|
|
Whether and when a finding is published. `policy-nexus` is the surface; this
|
|
document decides what it is handed.
|
|
|
|
## What disclosure is not
|
|
|
|
**A finding file in this repo is not a publication.** This repo is a private
|
|
checkout on a private forge. Holding a finding means not routing it to
|
|
`policy-nexus`; it does not mean hiding it from the estate, from the owning
|
|
repo, or from the operator. Every state below is fully visible internally.
|
|
|
|
## The states
|
|
|
|
| State | Meaning | Entry condition |
|
|
| --- | --- | --- |
|
|
| `public` | Published through `policy-nexus` now. | The finding is fixed, or reading it gives no one an advantage they do not already have. |
|
|
| `embargoed` | Held, with a stated condition that lifts it. | Live, unfixed, and the text would help someone reach the defect faster than they could without it. |
|
|
| `restricted` | Held with no expected lift. | Publication would remain harmful after the fix — third-party material, a named person, or a credential-shaped detail that survives remediation. |
|
|
|
|
There is no fourth state and no `unset` after grading. A finding whose
|
|
disclosure has not been decided is an ungraded finding.
|
|
|
|
## Embargo is a record, not a silence
|
|
|
|
`INTENT.md` requires the record that a delay was deliberate rather than a
|
|
document quietly going missing. An `embargoed` finding therefore carries:
|
|
|
|
```yaml
|
|
disclosure: embargoed
|
|
embargo_condition: "FLEX-WP-0015-T02 ships to production"
|
|
embargo_since: "2026-08-19"
|
|
embargo_review: "2026-08-26"
|
|
```
|
|
|
|
`embargo_condition` must be an event someone can observe, not a mood. "Until
|
|
it is safer" is not a condition. `embargo_review` follows the finding's
|
|
severity interval from `docs/method/review.md`; when it passes, the embargo is
|
|
re-decided, not extended by default.
|
|
|
|
An embargo that has outlived two consecutive reviews without its condition
|
|
moving is itself a finding — the remediation has stalled, and the hold is now
|
|
doing the work the fix was supposed to do.
|
|
|
|
## The build-mode deferral, re-taken
|
|
|
|
`INTENT.md` recorded controlled disclosure as deferred to production, reasoning
|
|
that build mode has no users to expose. `RISK-F-0001` arrived and tested it: a
|
|
live authorization bypass in the service every other service trusts, with
|
|
publish-or-forget as the only available choice.
|
|
|
|
**The deferral is narrowed, not kept and not abandoned.**
|
|
|
|
What was right about it: build mode does have no consumers to protect, and
|
|
building an embargo *mechanism* — timed release, staged notification,
|
|
coordinated disclosure with third parties — before there is anyone to
|
|
coordinate with would be machinery for its own sake.
|
|
|
|
What was wrong about it: it conflated the mechanism with the decision. The
|
|
argument for publishing in build mode is that there are no users to expose.
|
|
That argument says nothing about attackers, and `RISK-F-0001` is exactly the
|
|
class where the two come apart — the finding names an unauthenticated
|
|
decision surface and the service that carries it. Publishing that while it is
|
|
live helps precisely one kind of reader.
|
|
|
|
So the ruling is:
|
|
|
|
1. **Build-mode default stays publish.** Architecture, method, fixed findings,
|
|
and findings whose exposure is already bounded go out. The estate publishing
|
|
what it knows is wrong remains the norm and does not need a case made for it
|
|
each time.
|
|
2. **Live-and-reachable is the exception, and it exists now.** A finding that
|
|
is unfixed *and* whose text shortens the path to the defect is `embargoed`
|
|
until the fix lands. That is the missing middle `INTENT.md` said did not
|
|
exist. It costs one front-matter field and a line in `REGISTER.md`.
|
|
3. **The mechanism stays deferred.** No timed release, no coordinated
|
|
disclosure protocol, no notification tiers. Those wait for real users, as
|
|
originally reasoned. What is not deferred is the *decision*, because
|
|
`RISK-F-0001` demonstrated the decision is needed before the machinery is.
|
|
|
|
This is a decision of this repo, taken 2026-08-19 with `RISK-F-0001`,
|
|
`RISK-F-0002` and `RISK-F-0003` in hand rather than hypothetically. It is
|
|
revisable, and the production transition is the scheduled moment to revisit it.
|
|
|
|
## Test for "shortens the path"
|
|
|
|
Ask: does the finding tell a reader something that materially reduces the work
|
|
of reaching the defect, beyond what reading the repo would give them?
|
|
|
|
- A file path and line number in a private repo — no, that is already there.
|
|
- "This surface authenticates nobody, here is its cluster address" — yes.
|
|
- "These five named lanes vend real secret values without the boundary firing"
|
|
— yes.
|
|
- "This system had no backups configured" — no, once backups exist; yes, while
|
|
they do not, because it names when destruction is unrecoverable.
|
|
|
|
When the answer is genuinely unclear, embargo and re-decide at the review. The
|
|
cost of a wrong embargo is a delayed publication; the cost of a wrong publish
|
|
is not recoverable.
|
|
|
|
## Publication happens elsewhere
|
|
|
|
A `public` finding is handed to `policy-nexus` under its publication contract
|
|
and gets a permanent address there. This repo never serves it and never
|
|
edits it after handover; corrections go through the same route as the original.
|