risk-nexus/notes/RISK-N-0003-defects-found-by-reading-not-monitoring.md
tegwick 29f50d5143 Intake RISK-F-0011 and climb the due checks
Gate House routed a King's Guard observation that qonto-assistant's
audit.deny stream has no completeness evidence. Filed and graded medium,
public, open. Clean-checked F-0010, F-0008, and REG-0001 after confirming
nothing moved. Raised the inbox timeout so question-zero does not false-fail
on the tunneled hub.

Assistant: grok
Assistant-Session: 01a060e9-e363-7521-bf11-df5fa31b7156
2026-09-02 10:14:43 +02:00

3.2 KiB

id type title date source floor_reason revisit ruling
RISK-N-0003 note Every defect in this register was found by reading, none by monitoring 2026-08-19 rapp-postgres, routing RISK-F-0001; restated in RISK-F-0002 no owner and no defect — it is an argument about where to invest detection, and the register cannot route an argument when a finding arrives that monitoring plausibly should have caught and did not RISK-RULING-2026-08-19-C

RISK-N-0003 — found by reading, not by watching

rapp-postgres raised it when routing RISK-F-0001 and left the call here: all four defects in that round were found by repos reading their own code against a ladder, within a day of each other, and none by monitoring. RISK-F-0002 is a fifth, found by re-reading an answer this estate had just given. RISK-F-0003 is a sixth, found while counting fields for a zone model.

Ruled a note, not a finding, on 2026-08-19.

It is true, it is worth knowing, and it clears neither floor test cleanly. No repo owns "the estate's ability to notice its own defects", and there is no defect to route — the observation is an argument for investing in detection, and the register that files arguments as findings stops being readable.

There is also a reading of it that is not alarming. Reading code against a ladder is a detection method, it worked six times in a week, and the estate has been doing it deliberately. What is unproven is whether it would find anything nobody thought to look at.

It comes back the first time a finding arrives that monitoring plausibly should have caught and did not. That is the evidence this note is missing, and until then filing it would be the register asserting a conclusion it cannot support.

Update — 2026-08-21: the denominator

RISK-WP-0005-T07 built the smallest possible coverage report, and it puts a number on what this note could previously only gesture at:

7 of 117 registered repos have ever appeared in a finding. 110 never have.

That is not 110 clean repos and this note does not claim it is. It is 110 repos about which the register knows nothing, and the estate's own evidence — two for two on tenant boundaries, four defects in one review round — says that looking tends to find something.

The note stays a note. There is still no owner for "the estate's ability to notice its own defects", and nothing here is a defect to route. What changed is that the gap now has a size, and make coverage prints it, which is the difference between an argument and a measurement.

It comes back as a finding the first time something is found in one of the 110 that a reasonable sweep would have caught earlier.

Update — 2026-09-02: the first observation-sourced finding

RISK-F-0011 arrived from King's Guard live observation, routed by Gate House. That breaks the original "none by monitoring" half of the sentence. It does not trip the revisit: the finding is the observer reporting that a load-bearing deny stream has no completeness evidence, not a defect monitoring should have caught and did not.

The note stays a note. There is still no owner for estate-wide detection, and one observation-sourced finding does not convert an argument into a defect.