check_all runs every check stage even when one fails; malformed dates are reported rather than aborting; accepted findings and closure evidence are shown; defer requires a valid future date. Adds SCOPE.md, the scope assessment, the open-findings source review and a unittest suite. Stops tracking __pycache__. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 6903@bnt-lap001 Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
147 lines
7.6 KiB
Markdown
147 lines
7.6 KiB
Markdown
# STATE — risk-nexus
|
|
|
|
**Updated:** 2026-09-05
|
|
**Domain:** infotech · **Repo:** risk-nexus · **Owner:** the-custodian
|
|
|
|
## One-line posture
|
|
|
|
**The register decides.** Eleven findings graded, three notes below the floor,
|
|
one regulatory determination and a thirteen-entry legal policy set; every open
|
|
question carries a default and a date. Today's live set is three: an open
|
|
medium on qonto-assistant deny-stream completeness, an open low embargoed
|
|
backup credential, and an accepted medium on audit retention.
|
|
|
|
## Workplans
|
|
|
|
| ID | Status | Notes |
|
|
| --- | --- | --- |
|
|
| `RISK-WP-0001` | **finished** | The four instruments, the index, the first grading. Still waiting on canon kinds until 2026-09-17. |
|
|
| `RISK-WP-0002` | **finished** | Two findings and five public method instruments handed to `policy-nexus` |
|
|
| `RISK-WP-0003` | **finished** | Regulatory intake; the legal policy set |
|
|
| `RISK-WP-0004` | **finished** | Running the register: cadence, verification, inbox-before-grading |
|
|
| `RISK-WP-0005` | **finished** | The seven gaps from `history/2026-08-21-intent-gap-analysis.md` |
|
|
| `RISK-WP-0006` | **finished** | Reporting survives a stale index; full policies, embargo deadlines and closed-finding handovers stay visible; regression coverage and State Hub registration. |
|
|
| `RISK-WP-0007` | **finished** | Owner evidence reconciled, runtime/provider closure conditions recorded, and accepted obligations distinguished from missing engineering fixes. |
|
|
|
|
## Scope correction and reporting repair — 2026-09-05
|
|
|
|
`SCOPE.md` now describes the checked-in capability. The timestamped assessment
|
|
in `history/2026-09-05-014333-scope-intent-assessment.md` records the remaining
|
|
gaps behind the earlier claim that WP-0005 closed them all.
|
|
|
|
WP-0006 repairs the reporting path: `make check` runs every stage even after
|
|
failure; `make due` exposes regulatory policies and disclosure obligations;
|
|
malformed date strings no longer abort reporting; invalid deferrals cannot
|
|
write; archived completed workplans no longer trigger false inactivity alarms.
|
|
Eight regression tests pass. The live report now exposes four overdue policies,
|
|
eight pending publication handovers, and the existing overdue findings.
|
|
These are visibility repairs, not substantive reviews or evidence of closure.
|
|
|
|
The daily activity source includes those obligations. Its live synchronization
|
|
and end-to-end delivery remain unverified. External intake, incident clocks,
|
|
production-transition decisions and estate assessment coverage remain open.
|
|
|
|
WP-0007 then reconciled the owner evidence in RISK-V-0003. Qonto's source
|
|
cadence/reconciliation exists; KG-WP-0005-T03 waits for deployed acceptance.
|
|
RPF-WP-0029 removed the backup fallback; T02 waits for provider invalidation
|
|
and recovery receipts. Both findings were recorded as moved and remain open
|
|
at `instant`; F-0010 remains embargoed. F-0008's substantive review remains
|
|
overdue and its existing acceptance terms are displayed explicitly. Ten tests
|
|
pass. WP-0007 and four tasks are registered in State Hub.
|
|
|
|
## The register
|
|
|
|
| ID | Sev | Status | Disclosure | Cadence | System |
|
|
| --- | --- | --- | --- | --- | --- |
|
|
| `RISK-F-0011` | medium | open | public | instant | qonto-assistant |
|
|
| `RISK-F-0010` | low | open | embargoed | instant | railiance-platform |
|
|
| `RISK-F-0009` | high | fixed | public | instant | railiance-platform |
|
|
| `RISK-F-0008` | medium | accepted | public | 1h | audit-core |
|
|
| `RISK-F-0007` | high | fixed | public | instant | estate |
|
|
| `RISK-F-0006` | high | fixed | public | instant | railiance-platform |
|
|
| `RISK-F-0005` | medium | fixed | public | instant | audit-core |
|
|
| `RISK-F-0004` | medium | fixed | public | instant | tenant-engine |
|
|
| `RISK-F-0003` | medium | fixed | public | instant | ops-warden |
|
|
| `RISK-F-0002` | medium | fixed | public | instant | ops-warden |
|
|
| `RISK-F-0001` | high | fixed | public | instant | flex-auth |
|
|
|
|
Notes below the floor: `RISK-N-0001` noisy neighbours · `RISK-N-0003` found by
|
|
reading not watching (first observation-sourced finding arrived 2026-09-02,
|
|
still a note) · `RISK-N-0004` zone lookup.
|
|
|
|
Not one field reads `unset`.
|
|
|
|
## How it works
|
|
|
|
```
|
|
findings/*.md source of truth; reporter fields + this repo's grade
|
|
↓ tools/register_index.py
|
|
REGISTER.md generated, one screen, never hand-edited
|
|
|
|
docs/method/ severity · disclosure · escalation · review
|
|
verification · dependencies · check-procedure
|
|
docs/rulings/ why each grade is what it is, dated
|
|
docs/regulatory/ RISK-REG-0001 + policies/ (13, keyed by activation)
|
|
docs/verifications/ RISK-V-000N — what this repo checked itself
|
|
|
|
make due the work list
|
|
make fixes state of every tracked fix, from the owner's file
|
|
make coverage what the register has never heard from
|
|
make checked ARGS=... record an outcome; moves the cadence rung
|
|
make check index + malformed + waits + inbox + escalations
|
|
```
|
|
|
|
**Cadence:** `instant → 1h → 8h → 24h → 48h → 96h → 7d → 14d → 1mo → 1q`.
|
|
Clean climbs one rung; anything moving resets to `instant`. The rung is the
|
|
stability signal. Operator ruling, 2026-08-20.
|
|
|
|
**Scheduled on `activity-core`:** `hourly-register-inbox-watch` (fires only on
|
|
an unread message) and `daily-register-check-sweep` (07:15, unconditional).
|
|
Both instruct a session that exercises judgement; neither may record an
|
|
outcome.
|
|
|
|
## Waiting on other people
|
|
|
|
| Who | On | Defaults |
|
|
| --- | --- | --- |
|
|
| qonto-assistant | deployed-instance capture and King's Guard acceptance under `KG-WP-0005-T03`; source cadence/reconciliation now exist (`F-0011`) | 2026-09-16 |
|
|
| railiance-platform | provider invalidation and recovery receipts under `RPF-WP-0029-T02`; source fallback removed (`F-0010`) | 2026-09-15 |
|
|
| the-custodian | canon kinds packet | 2026-09-17 |
|
|
| audit-core | keyed commitment; `platform-pg` co-residency horizon | 2026-11-17 |
|
|
|
|
## Verify
|
|
|
|
```
|
|
make check # everything, including the inbox
|
|
python3 tools/register_check.py # just the register
|
|
statehub fix-consistency --repo risk-nexus
|
|
```
|
|
|
|
## What the gap analysis changed
|
|
|
|
`history/2026-08-21-intent-gap-analysis.md` graded this repo against its own
|
|
`INTENT.md` and `RISK-WP-0005` closed all seven gaps the same day.
|
|
|
|
- **Fix state is read, not remembered.** `make fixes` resolves every
|
|
`fix_tracking` against the owning repo's workplan file. Its first run found
|
|
`RISK-F-0005`'s fix already landed three days earlier, and both of
|
|
`RISK-F-0002`'s tracked records closed *before that finding was filed*.
|
|
- **Incident intake exists**, with `first_observed` starting the 72-hour clock
|
|
in `RISK-POL-0005` and escalation that is not batched.
|
|
- **Public records have permanent addresses** — two findings and five method
|
|
instruments publish through `policy-nexus`; this repo remains their source.
|
|
- **Coverage has a number:** `make coverage` — 7 of 117 registered repos have
|
|
ever appeared in a finding. The other 110 are unknown, not clean.
|
|
|
|
## Known conditions
|
|
|
|
- **Earlier workplans were not indexed in the hub.** C-06 on the earlier set: this instance was
|
|
not the identifier registrar. Needs a run with `STATEHUB_REGISTRAR=1` on the
|
|
production instance. WP-0006 now has a registered Hub workplan and five task
|
|
UUIDs; this implementation did not repair historical workplan registration.
|
|
- **C-31** fires on `RISK-F-` ids until canon registers the kinds. Packet sent.
|
|
Defaults 2026-09-17.
|
|
- **OpenBao is unverifiable from here** (403). Every grade touching an OpenBao
|
|
policy is a grade on a document, and says so.
|
|
- **`RISK-F-0011` is due at `instant`.** Graded this sitting; not clean-checked
|
|
in the same sitting. The next pass climbs it if nothing moved.
|