risk-nexus/docs/rulings/2026-08-20-publication.md
tegwick 02a17e601d Record all three rulings; RISK-WP-0003 finished
Escalation rule adopted as written. RISK-F-0008 accepted with the legal
policy set as the compensating control. Canon kinds packet sent to
the-custodian, with note offered lifecycle-free and verifications
deliberately withheld as an unsettled species.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 23:37:45 +02:00

5.3 KiB

id type title status owner date workplan
RISK-RULING-2026-08-20-B ruling What the estate publishes about its own risk recorded risk-nexus 2026-08-20 RISK-WP-0002

Publication — 2026-08-20

Two operator decisions, and what they commit this register to.

Findings publish whole

A reader gets the finding file: the claim, the grade with its reasoning, the review log, and the register's own corrections.

RISK-F-0001 is the first, and it publishes with the paragraph recording that this register graded it critical and prepared an escalation while its fix notice sat unread in the inbox — including the sentence "only luck put the fix on the same day".

That was the decision worth taking deliberately, and the reasoning is worth keeping:

  • The contract publishes a file. A summary would be a second document per finding, kept in sync by hand, and drift is the failure this register most distrusts — it is why REGISTER.md is generated rather than maintained.
  • The self-criticism is the credible part. A published register that only contains other repos' defects reads as an accusation. One that contains its own reads as a record. The estate has nothing to gain from a risk register that appears to have never been wrong.
  • It is the same standard applied inward. This repo asks every owner to state exposure only as far as they can support it, and to say when they could not verify something. Publishing a cleaned-up version of our own work while holding others to that would be indefensible.

The cost is real and accepted: criticism of other repos is public, and so is every misgrade this register makes. The second is the price of the first being believable.

Method documents: public, except escalation

Public: severity, disclosure, review, verification, dependencies. Together they let an outside reader judge whether a published finding means anything — what high is, why something was held, how often it is re-checked, what the register may verify itself, and what happens when someone does not answer.

escalation is restricted, and not because it is embarrassing. It names the operator's spend thresholds and describes the conditions under which the operator personally is interrupted. That is a map of where attention is scarce and what triggers it, which is useful to exactly one kind of reader and is not needed by anyone judging a finding.

check-procedure stays internal by omission rather than by ruling: it is an operating manual, not an instrument, and nothing about a published finding depends on it.

What this does not decide

  • Timing. Publication follows the embargo conditions already recorded. Six findings remain held.
  • Address scheme. policy-nexus owns addressing and permanence (POLICY-NEXUS-WP-0001). Paths proposed here are proposals.
  • Whether anything else ever publishes. Rulings, verifications and regulatory records are unaddressed and stay internal until someone asks.

Later the same day — three more rulings

The escalation rule is adopted, as written

docs/method/escalation.md, status: adopted, thresholds included. €50/month recurring and €500 one-off are now the operator's numbers.

It had governed four escalations while still a draft. That was the state RISK-WP-0001-T03 refused to leave open, and the wait carried the register's most uncomfortable default — unadopted by 2026-09-17 would have meant recording it as de facto in force but unratified, said on the face of every escalation sent under it.

RISK-F-0008 moves to accepted. The estate will not buy advice in build mode; RISK-REG-0001 stands as the recorded position. The three triggers survive as what ends the acceptance rather than what starts a purchase.

The direction that came with it is the substantive part: define and keep a set of legal policies for reuse, because work contexts will need specific positions in place and should retrieve them rather than research them.

docs/regulatory/policies/ holds thirteen, keyed by activation condition rather than by regime, so a context pulls a slice — a first real user account pulls six; a consumer product in Germany pulls those plus accessibility.

Two turned out to be already active and unowned: commercial and tax retention, and the e-invoicing receiving obligation live since 2025 with no named receiving point in the estate. That is the catalogue justifying itself in its first hour, and it is exactly the failure INTENT.md describes — regulation consulted once and discarded, with nobody noticing what had quietly become true.

Register the canon kinds

finding, regulatory-record and note go to canon as work-record kinds. The packet is with the-custodian; canon is theirs and this repo does not edit it.

The reason is not the C-31 warning. No repo can currently ask the hub what findings are open against it, and that capability gap was simply showing up as a warning. note is offered with no lifecycle at all — a note is not work and does not progress — and with an explicit invitation to reject it rather than give it a fake one. Verifications were deliberately left out: two records and a week-old shape is not a settled species.