risk-nexus/notes/RISK-N-0003-defects-found-by-reading-not-monitoring.md
tegwick 7d6ded5743 The inbox round: two grades corrected, one note promoted
Read the repo inbox after grading, which is the wrong order and is now
recorded as such. flex-auth had answered the NetworkPolicy question on
2026-08-18 (narrow ingress, not default-deny — L3 becomes L2, critical
becomes high) and reported RISK-F-0001 fixed at 12:35 today with live 401
probes. F-0001 closes fixed and public; its escalation is withdrawn
before it was ever sent. RISK-F-0002's ordering constraint lifts with it
and its trigger-6 escalation is withdrawn.

audit-core had routed the erasure-versus-audit legal question here on
2026-08-18 asking for an owner. RISK-N-0002 was wrong to call it a note:
the remedy is not retrofittable, so the decision can only be taken early.
Promoted to RISK-F-0008, owned by this repo as regulatory intake,
escalated on trigger 2.

Accepted rapp-postgres's record format and ops-warden's typed-act
escalation vocabulary. Reading the inbox is now question zero of every
review.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 23:38:07 +02:00

1.7 KiB

id type title date source floor_reason revisit ruling
RISK-N-0003 note Every defect in this register was found by reading, none by monitoring 2026-08-19 rapp-postgres, routing RISK-F-0001; restated in RISK-F-0002 no owner and no defect — it is an argument about where to invest detection, and the register cannot route an argument when a finding arrives that monitoring plausibly should have caught and did not RISK-RULING-2026-08-19-C

RISK-N-0003 — found by reading, not by watching

rapp-postgres raised it when routing RISK-F-0001 and left the call here: all four defects in that round were found by repos reading their own code against a ladder, within a day of each other, and none by monitoring. RISK-F-0002 is a fifth, found by re-reading an answer this estate had just given. RISK-F-0003 is a sixth, found while counting fields for a zone model.

Ruled a note, not a finding, on 2026-08-19.

It is true, it is worth knowing, and it clears neither floor test cleanly. No repo owns "the estate's ability to notice its own defects", and there is no defect to route — the observation is an argument for investing in detection, and the register that files arguments as findings stops being readable.

There is also a reading of it that is not alarming. Reading code against a ladder is a detection method, it worked six times in a week, and the estate has been doing it deliberately. What is unproven is whether it would find anything nobody thought to look at.

It comes back the first time a finding arrives that monitoring plausibly should have caught and did not. That is the evidence this note is missing, and until then filing it would be the register asserting a conclusion it cannot support.