check_all runs every check stage even when one fails; malformed dates are reported rather than aborting; accepted findings and closure evidence are shown; defer requires a valid future date. Adds SCOPE.md, the scope assessment, the open-findings source review and a unittest suite. Stops tracking __pycache__. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 6903@bnt-lap001 Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
5 KiB
| id | type | title | domain | repo | status | owner | topic_slug | created | updated | depends_on_workplans | state_hub_workstream_id | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| RISK-WP-0006 | workplan | Keep review obligations visible when the index or records are stale | infotech | risk-nexus | finished | the-custodian | risk-nexus | 2026-09-05 | 2026-09-05 |
|
900ba790-c5b8-523c-947f-5cd743fa1d58 |
RISK-WP-0006 — keep review obligations visible
Problem and priority
The scope assessment
found that make check stops before showing overdue work, all four full legal
policies are outside review discovery, and disclosure obligations disappear
from the work list. These are the first priorities: they hide known obligations
and can be corrected within this repository without a new service or mandate.
Malformed dates must not defeat the repaired reporting path.
Tasks and acceptance
T01 — Run every check stage even if another fails
id: RISK-WP-0006-T01
status: done
priority: high
state_hub_task_id: "44f58905-fc81-571f-b112-e37001b02ed9"
Run index, register and inbox checks independently, preserving a nonzero result if any stage fails. A stale index and a broken register stage must still allow the inbox stage to run. No regeneration or grading as a side effect.
T02 — Include full policies in the review workflow
id: RISK-WP-0006-T02
status: done
priority: high
state_hub_task_id: "4a9cd603-7722-5e3b-833e-b65109f33d8a"
Discover nested regulatory records, excluding README catalogues. Full policies
must appear when due and accept recorded outcomes. make due must expose these
obligations to existing scheduled sessions, not filter them out. Invalid dates
must be reported without aborting the report; invalid deferrals must not write.
T03 — Keep disclosure obligations visible after closure
id: RISK-WP-0006-T03
status: done
priority: high
state_hub_task_id: "3d250ebe-1d06-55f2-a4cc-8a716b12414f"
Report due or missing embargo review dates and pending publication handovers
across all findings, including fixed findings. Surface them through make due.
Do not publish, lift embargoes or change finding statuses automatically.
T04 — Correct the archived fix completion signal
id: RISK-WP-0006-T04
status: done
priority: medium
state_hub_task_id: "79b0c627-9fff-59e2-a400-8d3e9585504b"
An archived completed workplan must not be reported as an unchanged unfinished fix just because its display status carries an archive suffix. Preserve the archive label and the documented whole-file timestamp limitation.
T05 — Verify, document and reconcile registration
id: RISK-WP-0006-T05
status: done
priority: high
state_hub_task_id: "96d06e61-84e7-5c3a-9d79-b700408afaf7"
Add focused regression tests for the failures above using isolated files and mocked external reads. Run them and the live read-only reporting path. Update SCOPE, usage and the operational instructions, and reconcile the workplan and task records with State Hub. Record actual registration results and residuals.
Scope boundary and next priorities
This plan repairs visibility, not the overdue substantive reviews themselves. External intake delivery, urgent incident handling, scheduler-to-session delivery proof and the production declaration require separate operational decisions or cross-repository work. They remain open in the assessment. Missing fix records and the F-0011 notice require evidence reconciliation, not automatic closure. No legal conclusions, grades, acknowledgements or messages are generated here.
Verification and completion evidence
Implementation complete for T01–T04. Eight isolated regression tests pass via
make test, covering stage failures, nested policy discovery and recorded
reviews, invalid dates and deferrals, disclosure after closure, and archived
completed fixes. git diff --check passes.
Live validation first ran with a stale index: every report still executed and
Make returned nonzero. After make register, make check and make due both
returned zero while exposing all four overdue policies, eight pending handovers,
three overdue findings and the newer F-0011 inbox notice. No finding or policy
was stamped reviewed, re-graded or closed.
Registration: the normal CLI and an outside-sandbox retry timed out on State Hub
reads. A longer-timeout full reconciliation was stopped after prolonged API
reads without a completion result. Targeted registration succeeded
through the same workplan/task API and deterministic IDs used by the reconciler.
The workplan UUID is 900ba790-c5b8-523c-947f-5cd743fa1d58; all five task
UUIDs are recorded beside their source blocks. Completion and the file binding
are synchronized through the API; the local index uses the reconciler renderer.
Residuals: external contact delivery, incident clocks, independent execution assurance, substantive overdue reviews, method review scheduling and production transition decisions remain open. The updated activity definition is local source; deployment/synchronization to activity-core was not performed.