A risk management service.
Find a file
tegwick aeb56e3711 RISK-WP-0003 T02/T03: state the retention periods, and write the intake route
T02 applies the dependency rule to this repo's own work: rather than wait
on audit-core's co-residency horizon, RISK-REG-0001 now states target
periods per category with the reasoning — 12 months for operator and
agent security records, 3 years to year-end for counterparty transaction
evidence, 8 years for accounting vouchers (shortened by BEG IV, flagged
as worth confirming), 10 years for books, 6 for commercial letters,
delete for anything with no ground. Targets, not achievements: the estate
cannot demonstrate any of them while the real horizon is the maximum
across every co-resident on platform-pg, and that gap is stated so the
table cannot be read as a compliance claim.

T03 writes the intake route from what audit-core did correctly without
one: the question as a question, what already depends on it, what becomes
expensive if the answer is no, and what you are not asking for.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 23:16:51 +02:00
activity-definitions Drop dedupe_key_strategy from the inbox watch and say what actually happens 2026-08-20 12:02:14 +02:00
docs RISK-WP-0003 T02/T03: state the retention periods, and write the intake route 2026-08-20 23:16:51 +02:00
findings Type the publication handover as a wait like any other 2026-08-20 22:44:46 +02:00
notes RISK-N-0004: route the zone-lookup requirement to zone-engine as a note 2026-08-20 07:24:33 +02:00
tools Waits outlive statuses 2026-08-20 22:45:36 +02:00
workplans RISK-WP-0003 T02/T03: state the retention periods, and write the intake route 2026-08-20 23:16:51 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-19 23:41:18 +02:00
.repo-classification.yaml Classify with the canon governance_and_control tags 2026-08-20 08:08:07 +02:00
INTENT.md INTENT: the register is no longer empty, and the first finding tested the deferral 2026-08-17 22:52:37 +02:00
Makefile RISK-WP-0004: five of six tasks done; the executor is the operator's call 2026-08-20 08:49:23 +02:00
README.md Close out RISK-WP-0001: task notes, README, repo classification 2026-08-19 23:34:34 +02:00
REGISTER.md Type the publication handover as a wait like any other 2026-08-20 22:44:46 +02:00
WORK-RECORDS.md Type the publication handover as a wait like any other 2026-08-20 22:44:46 +02:00

risk-nexus

Risk register and regulatory intake for the estate. Serves risk.coulomb.social. Owned by the-custodian.

Holds findings — security, architecture, operational, compliance — with a severity, an owner and a date; decides whether and when each is published; and decides which must reach the operator personally rather than sitting in a register.

It does not fix things: findings route to the repo that owns the defect. It does not host: policy-nexus is the publication surface.

Where things are

  • REGISTER.md — the whole register, one screen. Generated; do not edit.
  • findings/ — one file per finding. findings/README.md is the filing contract for reporting repos.
  • notes/ — seen, deliberately below the floor. Not graded, not reviewed.
  • docs/method/ — how this repo decides: severity, disclosure, escalation, review and expiry.
  • docs/rulings/ — the reasoning behind each grading, dated.
  • workplans/ — the work.

Using it

make register   # rebuild REGISTER.md from findings/
make check      # verify the index, then report what is going quiet

make check reports ungraded findings, overdue reviews, stalled remediation, embargoes due for re-decision, escalations awaiting the operator, and what is owed at the production transition. It changes nothing.

  • Intent: INTENT.md