risk-nexus/workplans/RISK-WP-0006-keep-review-obligations-visible.md
tegwick bbbede5f47 Keep review obligations visible and reconcile owner evidence (RISK-WP-0006, RISK-WP-0007)
check_all runs every check stage even when one fails; malformed dates are
reported rather than aborting; accepted findings and closure evidence are
shown; defer requires a valid future date. Adds SCOPE.md, the scope
assessment, the open-findings source review and a unittest suite. Stops
tracking __pycache__.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
2026-09-22 07:56:58 +02:00

5 KiB
Raw Blame History

id type title domain repo status owner topic_slug created updated depends_on_workplans state_hub_workstream_id
RISK-WP-0006 workplan Keep review obligations visible when the index or records are stale infotech risk-nexus finished the-custodian risk-nexus 2026-09-05 2026-09-05
RISK-WP-0005
900ba790-c5b8-523c-947f-5cd743fa1d58

RISK-WP-0006 — keep review obligations visible

Problem and priority

The scope assessment found that make check stops before showing overdue work, all four full legal policies are outside review discovery, and disclosure obligations disappear from the work list. These are the first priorities: they hide known obligations and can be corrected within this repository without a new service or mandate. Malformed dates must not defeat the repaired reporting path.

Tasks and acceptance

T01 — Run every check stage even if another fails

id: RISK-WP-0006-T01
status: done
priority: high
state_hub_task_id: "44f58905-fc81-571f-b112-e37001b02ed9"

Run index, register and inbox checks independently, preserving a nonzero result if any stage fails. A stale index and a broken register stage must still allow the inbox stage to run. No regeneration or grading as a side effect.

T02 — Include full policies in the review workflow

id: RISK-WP-0006-T02
status: done
priority: high
state_hub_task_id: "4a9cd603-7722-5e3b-833e-b65109f33d8a"

Discover nested regulatory records, excluding README catalogues. Full policies must appear when due and accept recorded outcomes. make due must expose these obligations to existing scheduled sessions, not filter them out. Invalid dates must be reported without aborting the report; invalid deferrals must not write.

T03 — Keep disclosure obligations visible after closure

id: RISK-WP-0006-T03
status: done
priority: high
state_hub_task_id: "3d250ebe-1d06-55f2-a4cc-8a716b12414f"

Report due or missing embargo review dates and pending publication handovers across all findings, including fixed findings. Surface them through make due. Do not publish, lift embargoes or change finding statuses automatically.

T04 — Correct the archived fix completion signal

id: RISK-WP-0006-T04
status: done
priority: medium
state_hub_task_id: "79b0c627-9fff-59e2-a400-8d3e9585504b"

An archived completed workplan must not be reported as an unchanged unfinished fix just because its display status carries an archive suffix. Preserve the archive label and the documented whole-file timestamp limitation.

T05 — Verify, document and reconcile registration

id: RISK-WP-0006-T05
status: done
priority: high
state_hub_task_id: "96d06e61-84e7-5c3a-9d79-b700408afaf7"

Add focused regression tests for the failures above using isolated files and mocked external reads. Run them and the live read-only reporting path. Update SCOPE, usage and the operational instructions, and reconcile the workplan and task records with State Hub. Record actual registration results and residuals.

Scope boundary and next priorities

This plan repairs visibility, not the overdue substantive reviews themselves. External intake delivery, urgent incident handling, scheduler-to-session delivery proof and the production declaration require separate operational decisions or cross-repository work. They remain open in the assessment. Missing fix records and the F-0011 notice require evidence reconciliation, not automatic closure. No legal conclusions, grades, acknowledgements or messages are generated here.

Verification and completion evidence

Implementation complete for T01T04. Eight isolated regression tests pass via make test, covering stage failures, nested policy discovery and recorded reviews, invalid dates and deferrals, disclosure after closure, and archived completed fixes. git diff --check passes.

Live validation first ran with a stale index: every report still executed and Make returned nonzero. After make register, make check and make due both returned zero while exposing all four overdue policies, eight pending handovers, three overdue findings and the newer F-0011 inbox notice. No finding or policy was stamped reviewed, re-graded or closed.

Registration: the normal CLI and an outside-sandbox retry timed out on State Hub reads. A longer-timeout full reconciliation was stopped after prolonged API reads without a completion result. Targeted registration succeeded through the same workplan/task API and deterministic IDs used by the reconciler. The workplan UUID is 900ba790-c5b8-523c-947f-5cd743fa1d58; all five task UUIDs are recorded beside their source blocks. Completion and the file binding are synchronized through the API; the local index uses the reconciler renderer.

Residuals: external contact delivery, incident clocks, independent execution assurance, substantive overdue reviews, method review scheduling and production transition decisions remain open. The updated activity definition is local source; deployment/synchronization to activity-core was not performed.