Updated by fix-consistency on 2026-09-22: - update .custodian-brief.md for risk-nexus Assistant: claude-code Assistant-Model: opus Assistant-Process: 6903@bnt-lap001 Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89 |
||
|---|---|---|
| activity-definitions | ||
| docs | ||
| findings | ||
| history | ||
| notes | ||
| tests | ||
| tools | ||
| workplans | ||
| .custodian-brief.md | ||
| .gitignore | ||
| .repo-classification.yaml | ||
| INTENT.md | ||
| Makefile | ||
| README.md | ||
| REGISTER.md | ||
| SCOPE.md | ||
| STATE.md | ||
| WORK-RECORDS.md | ||
risk-nexus
Risk register and regulatory intake for the estate. Owned by the-custodian.
It does not serve its own site. INTENT.md names risk.coulomb.social as
the eventual surface; today public findings and method instruments have
permanent addresses through policy-nexus. The source stays here and the
published page records its exact source revision.
Holds findings — security, architecture, operational, compliance — with a severity, an owner and a date; decides whether and when each is published; and decides which must reach the operator personally rather than sitting in a register.
It does not fix things: findings route to the repo that owns the defect. It
does not host: policy-nexus is the publication surface.
Where things are
REGISTER.md— the whole register, one screen. Generated; do not edit.findings/— one file per finding.findings/README.mdis the filing contract for reporting repos.notes/— seen, deliberately below the floor. Not graded, not reviewed.docs/method/— how this repo decides: severity, disclosure, escalation, review and expiry.docs/rulings/— the reasoning behind each grading, dated.workplans/— the work.
Using it
make register # rebuild REGISTER.md from findings/
make check # verify the index, then report what is going quiet
make check reports ungraded findings, overdue reviews, stalled remediation,
embargoes due for re-decision, escalations awaiting the operator, and what is
owed at the production transition. It changes nothing.
All check stages run even when the index is stale; the command still exits
nonzero for a failed stage. make due shows the full obligation report and
inbox freshness, including full regulatory policies, embargo review deadlines
and publication handovers that remain pending after a finding closes.
make checked accepts finding, regulatory determination and full policy IDs;
it records an actual review, not a repair for an overdue warning.
make fixes distinguishes owner workplans from recorded acceptance obligations.
make check and make due also show explicit closure_condition evidence still
owed by live findings, even when a source workplan has finished. Acceptance
terms and a finished workplan are not proof of runtime closure.
Run make test for isolated regression checks. Python 3 and PyYAML are required.
- Intent:
INTENT.md - Current capability: SCOPE.md