risk-nexus/findings/RISK-F-0004-tenant-engine-unfiltered-event-read.md
tegwick 42bbf5d2dc Adaptive check cadence: the interval is earned, not assigned
Operator ruling 2026-08-20. Severity no longer sets the review interval.
A check that comes back clean climbs one rung — instant, 1h, 8h, 24h,
48h, 96h, 7d, 14d, 1mo, 1q — and anything wrong drops straight back to
instant. A quarter is the ceiling. The operator may defer an instant
finding to a stated date; that is the only other way off the bottom rung.

The rung is the point: it says how stable the estate has been on that
matter, which is information severity does not carry. Volatile things get
attention automatically; quiet things stop consuming it; neither
judgement has to be made by a person who might be busy.

Escalation trigger 5 rebased onto the ladder — fourteen days at the
bottom rung, whether that is failing checks or no checks.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 07:43:51 +02:00

3.3 KiB
Raw Blame History

id type title status reported_by reported_via routed_by date_reported date_filed system environment fix_owner fix_tracking related severity severity_at_production impact likelihood fidelity_modifier production_rescore disclosure embargo_condition embargo_since embargo_review escalation last_checked next_check cadence clean_streak graded_by ruling
RISK-F-0004 finding tenant-engine events() returns the entire event log unfiltered open tenant-engine flex-auth risk-nexus 2026-08-17 2026-08-19 tenant-engine production tenant-engine unset
RISK-F-0001
high critical I3 L3 false true embargoed the read path filters by tenant in code 2026-08-19 2026-09-18 none 2026-08-19T21:20:00Z 2026-08-19T21:20:00Z instant 0 risk-nexus RISK-RULING-2026-08-19-B

RISK-F-0004 — the tenant event log is readable across tenants

What is true, as reported

tenant-engine's events() returns the entire event log with no tenant filter. Reported by tenant-engine as a live cross-tenant read at E2 on the Tenancy Posture E ladder, surfaced in the same review round as RISK-F-0001 and recorded inside that finding as visible-but-unfiled.

This repo has not verified it and does not own the code. It is filed on the owning repo's own self-report. tenant-engine confirms or corrects it.

Why it is being filed now

It was held back pending the precedent this register set for what warrants a record of its own. That precedent now exists (docs/method/severity.md), and "still waiting on the precedent" has stopped being an available answer. This finding clears the floor on both tests: tenant-engine can act, and recording it changes when they act.

What is not established

  • Whether any caller other than tenant-engine itself currently reaches events().
  • What the log contains — whether the rows are metadata or carry tenant payload. The grade assumes cross-tenant visibility, not payload disclosure, and would rise if it is the latter.
  • Whether a fix is tracked anywhere. fix_tracking is unset and this repo has asked.

Register ruling — 2026-08-19

high today (I3 × L3), critical at production, embargoed until the read path filters in code, no escalation.

I3: a cross-tenant read crosses a tenant boundary inside one system. L3: no additional step is needed by anything that can already call the method, and the authorization that would otherwise constrain the caller is RISK-F-0001, which authenticates nobody.

production_rescore: true. Today the log holds no real counterparty's events, which lowers what one occurrence costs; it does not lower what the defect is. At production the same read is I4 — real tenant data crossing a boundary that nothing verifies — and the re-score is owed before any production declaration completes.

No escalation: no real tenant data yet (trigger 1 reads real), owned, and not yet stalled. It becomes an escalation on the day the estate takes real tenant data, and that is what production_rescore is for.

Reviews

  • 2026-08-19 — filed and graded from RISK-F-0001's unfiled list. Open at review: does tenant-engine confirm; is a fix tracked; what does the log actually contain.