risk-nexus/workplans/RISK-WP-0002-publication-handover.md
tegwick a13d954f85 risk: complete Policy Nexus publication handover
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a058f3-8ba0-7692-a042-9a870fc3d663
2026-09-01 01:54:09 +02:00

6 KiB

id type title domain repo status owner topic_slug created updated depends_on_workplans state_hub_workstream_id
RISK-WP-0002 workplan Hand the publishable findings to policy-nexus, and decide what else is a public document infotech risk-nexus finished the-custodian risk-nexus 2026-08-20 2026-09-01
RISK-WP-0001
b79af69c-5b08-55df-8caa-258eed3e397e

RISK-WP-0002 — publication handover

Finished 2026-09-01. Sized deliberately small: two documents were ready and the rest was a decision, not a project.

Goal

RISK-F-0001 and RISK-F-0008 carry disclosure: public and publication: pending-handover. Get them onto policy.coulomb.social under policy-nexus's existing contract, and settle whether this repo's method documents are public too.

Done means: both findings have a permanent address, publication: published, and a recorded answer on the method documents.

Why now

Six findings are embargoed with lift conditions, and RISK-F-0009 has already demonstrated that a condition can be met and the embargo still hold. When those conditions start clearing, publication will happen in a trickle rather than a batch — so the route wants to exist before it is needed, not during.

policy-nexus has been told this is coming (2026-08-20) and asked for nothing.

Tasks

T01 — Publish the two ready findings

id: RISK-WP-0002-T01
status: done
priority: high
state_hub_task_id: "9ac32008-76b6-591c-82a1-ad6e2f8368b7"

Follow policy-nexus's publication contract as it stands. Do not invent an address scheme: POLICY-NEXUS-WP-0001 settled addressing and permanence, and this repo is a consumer of that decision.

Open question for T01 rather than an assumption: is a finding published whole, or as a summary? RISK-F-0001 contains a full ruling, a re-grade, a review log and this register's own process defect. Some of that is register-internal work product. Decide once, here, and apply it to every later publication.

In progress 2026-08-20. Operator ruled: findings publish whole. Publication front-matter applied to RISK-F-0001 and RISK-F-0008 (revision, last_reviewed, review_interval: 6m) with proposed ids, paths and subtitles; both now read publication: requested. Handover request sent to policy-nexus. The open question the task named is answered and recorded in docs/rulings/2026-08-20-publication.md — including that RISK-F-0001 publishes with the paragraph about this register grading it wrong.

Completed 2026-09-01. policy-nexus admitted findings and public risk methods as explicit publication kinds. The two findings publish whole at permanent addresses and record those addresses back in their source files. The five public method instruments — severity, disclosure, review, verification and dependencies — publish beside them. Escalation and check-procedure remain internal as ruled in T02.

T02 — Rule on the method documents

id: RISK-WP-0002-T02
status: done
priority: medium
state_hub_task_id: "ce61806e-02c8-594f-a7b6-88f21d0ee371"

docs/method/severity.md, disclosure.md, escalation.md, review.md.

The case for publishing: they say how the estate grades and holds risk, which is exactly what an outside reader needs to judge whether a published finding means anything.

The case against: the escalation rule names the operator's own thresholds, and the severity scale is a judgement instrument this repo revises freely. A published instrument invites argument about the instrument.

Suggested split, to be ruled on rather than assumed: severity and disclosure public, escalation and review internal. Escalation in particular describes when the operator is interrupted, which is not the estate's business to advertise.

Completed 2026-08-20. Public: severity, disclosure, review, verification, dependencies — the instruments a reader needs to judge whether a published finding means anything. Restricted: escalation, because it names the operator's spend thresholds and describes when the operator personally is interrupted, which is a map of where attention is scarce and is needed by nobody judging a finding. check-procedure stays internal by omission: an operating manual, not an instrument.

T03 — The standing route

id: RISK-WP-0002-T03
status: done
priority: medium
state_hub_task_id: "595737b7-19f3-5c39-b208-958c57775bc2"

Write down what happens when an embargo lifts: who hands over, in what shape, and how publication: published gets recorded back on the finding.

Small. It is a paragraph in docs/method/disclosure.md plus whatever policy-nexus needs on their side, not a mechanism.

Completed 2026-08-20. The route is in docs/method/disclosure.md: the check that lifts the embargo records it, the finding gets publication front-matter in the shape policy-nexus already requires (owner, revision, last_reviewed, review_interval), this repo asks for an entry with source_repo/source_path/proposed canonical_path, and publication: published plus the URL comes back onto the finding — because a finding that says public with no address is a claim, not a publication.

One thing the contract settled for T01: publication.json publishes a file from the source repo, so a reader gets exactly what is handed over. Whole-versus-summary is therefore a decision about what a finding file contains, not about rendering.

Non-goals

  • No publication surface here. policy-nexus hosts; this repo hands over.
  • No timed release, no coordinated disclosure, no notification tiers. Those stay deferred (docs/method/disclosure.md) until there are real users.
  • No re-grading of anything to make it publishable.

Risks

A finding is published with an internal ruling attached. Mitigation: T01 decides whole-versus-summary before anything ships.

The handover becomes a project. Mitigation: three tasks, one of which is a paragraph. If it grows, that is a signal the publication contract does not fit findings, and that is a conversation with policy-nexus rather than more tasks here.