risk-nexus/STATE.md
tegwick 81e31b379c Close RISK-F-0010 on RPF-WP-0029 evidence (RISK-RULING-2026-09-22-A)
Source default removed, governed upload and restore have receipts, and the
predecessor share is invalidated by owner attestation (no probe, by design).
Fixed, embargo lifted, publication handover pending. Age-key taint referred
to railiance-platform as a possible separate finding.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
2026-09-22 08:01:39 +02:00

7.7 KiB

STATE — risk-nexus

Updated: 2026-09-05 Domain: infotech · Repo: risk-nexus · Owner: the-custodian

One-line posture

The register decides. Eleven findings graded, three notes below the floor, one regulatory determination and a thirteen-entry legal policy set; every open question carries a default and a date. Today's live set is three: an open medium on qonto-assistant deny-stream completeness, an open low embargoed backup credential, and an accepted medium on audit retention.

Workplans

ID Status Notes
RISK-WP-0001 finished The four instruments, the index, the first grading. Still waiting on canon kinds until 2026-09-17.
RISK-WP-0002 finished Two findings and five public method instruments handed to policy-nexus
RISK-WP-0003 finished Regulatory intake; the legal policy set
RISK-WP-0004 finished Running the register: cadence, verification, inbox-before-grading
RISK-WP-0005 finished The seven gaps from history/2026-08-21-intent-gap-analysis.md
RISK-WP-0006 finished Reporting survives a stale index; full policies, embargo deadlines and closed-finding handovers stay visible; regression coverage and State Hub registration.
RISK-WP-0007 finished Owner evidence reconciled, runtime/provider closure conditions recorded, and accepted obligations distinguished from missing engineering fixes.

Scope correction and reporting repair — 2026-09-05

SCOPE.md now describes the checked-in capability. The timestamped assessment in history/2026-09-05-014333-scope-intent-assessment.md records the remaining gaps behind the earlier claim that WP-0005 closed them all.

WP-0006 repairs the reporting path: make check runs every stage even after failure; make due exposes regulatory policies and disclosure obligations; malformed date strings no longer abort reporting; invalid deferrals cannot write; archived completed workplans no longer trigger false inactivity alarms. Eight regression tests pass. The live report now exposes four overdue policies, eight pending publication handovers, and the existing overdue findings. These are visibility repairs, not substantive reviews or evidence of closure.

The daily activity source includes those obligations. Its live synchronization and end-to-end delivery remain unverified. External intake, incident clocks, production-transition decisions and estate assessment coverage remain open.

WP-0007 then reconciled the owner evidence in RISK-V-0003. Qonto's source cadence/reconciliation exists; KG-WP-0005-T03 waits for deployed acceptance. RPF-WP-0029 removed the backup fallback; T02 waits for provider invalidation and recovery receipts. Both findings were recorded as moved and remain open at instant; F-0010 was closed 2026-09-22 (RISK-RULING-2026-09-22-A), embargo lifted. F-0008's substantive review remains overdue and its existing acceptance terms are displayed explicitly. Ten tests pass. WP-0007 and four tasks are registered in State Hub.

The register

ID Sev Status Disclosure Cadence System
RISK-F-0011 medium open public instant qonto-assistant
RISK-F-0010 low fixed public (handover pending) 1h railiance-platform
RISK-F-0009 high fixed public instant railiance-platform
RISK-F-0008 medium accepted public 1h audit-core
RISK-F-0007 high fixed public instant estate
RISK-F-0006 high fixed public instant railiance-platform
RISK-F-0005 medium fixed public instant audit-core
RISK-F-0004 medium fixed public instant tenant-engine
RISK-F-0003 medium fixed public instant ops-warden
RISK-F-0002 medium fixed public instant ops-warden
RISK-F-0001 high fixed public instant flex-auth

Notes below the floor: RISK-N-0001 noisy neighbours · RISK-N-0003 found by reading not watching (first observation-sourced finding arrived 2026-09-02, still a note) · RISK-N-0004 zone lookup.

Not one field reads unset.

How it works

findings/*.md            source of truth; reporter fields + this repo's grade
  ↓ tools/register_index.py
REGISTER.md              generated, one screen, never hand-edited

docs/method/             severity · disclosure · escalation · review
                         verification · dependencies · check-procedure
docs/rulings/            why each grade is what it is, dated
docs/regulatory/         RISK-REG-0001 + policies/ (13, keyed by activation)
docs/verifications/      RISK-V-000N — what this repo checked itself

make due                 the work list
make fixes               state of every tracked fix, from the owner's file
make coverage            what the register has never heard from
make checked ARGS=...    record an outcome; moves the cadence rung
make check               index + malformed + waits + inbox + escalations

Cadence: instant → 1h → 8h → 24h → 48h → 96h → 7d → 14d → 1mo → 1q. Clean climbs one rung; anything moving resets to instant. The rung is the stability signal. Operator ruling, 2026-08-20.

Scheduled on activity-core: hourly-register-inbox-watch (fires only on an unread message) and daily-register-check-sweep (07:15, unconditional). Both instruct a session that exercises judgement; neither may record an outcome.

Waiting on other people

Who On Defaults
qonto-assistant deployed-instance capture and King's Guard acceptance under KG-WP-0005-T03; source cadence/reconciliation now exist (F-0011) 2026-09-16
railiance-platform whether the age recovery-key taint named in RPF-WP-0029 is a separate exposure to file (raised 2026-09-22 after F-0010 closed)
the-custodian canon kinds packet 2026-09-17
audit-core keyed commitment; platform-pg co-residency horizon 2026-11-17

Verify

make check                       # everything, including the inbox
python3 tools/register_check.py  # just the register
statehub fix-consistency --repo risk-nexus

What the gap analysis changed

history/2026-08-21-intent-gap-analysis.md graded this repo against its own INTENT.md and RISK-WP-0005 closed all seven gaps the same day.

  • Fix state is read, not remembered. make fixes resolves every fix_tracking against the owning repo's workplan file. Its first run found RISK-F-0005's fix already landed three days earlier, and both of RISK-F-0002's tracked records closed before that finding was filed.
  • Incident intake exists, with first_observed starting the 72-hour clock in RISK-POL-0005 and escalation that is not batched.
  • Public records have permanent addresses — two findings and five method instruments publish through policy-nexus; this repo remains their source.
  • Coverage has a number: make coverage — 7 of 117 registered repos have ever appeared in a finding. The other 110 are unknown, not clean.

Known conditions

  • Earlier workplans were not indexed in the hub. C-06 on the earlier set: this instance was not the identifier registrar. Needs a run with STATEHUB_REGISTRAR=1 on the production instance. WP-0006 now has a registered Hub workplan and five task UUIDs; this implementation did not repair historical workplan registration.
  • C-31 fires on RISK-F- ids until canon registers the kinds. Packet sent. Defaults 2026-09-17.
  • OpenBao is unverifiable from here (403). Every grade touching an OpenBao policy is a grade on a document, and says so.
  • RISK-F-0011 is due at instant. Graded this sitting; not clean-checked in the same sitting. The next pass climbs it if nothing moved.