risk-nexus/workplans/RISK-WP-0007-reconcile-owner-evidence.md
tegwick bbbede5f47 Keep review obligations visible and reconcile owner evidence (RISK-WP-0006, RISK-WP-0007)
check_all runs every check stage even when one fails; malformed dates are
reported rather than aborting; accepted findings and closure evidence are
shown; defer requires a valid future date. Adds SCOPE.md, the scope
assessment, the open-findings source review and a unittest suite. Stops
tracking __pycache__.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 6903@bnt-lap001
Assistant-Session: 8319e8a8-ffa6-4eb3-b8bf-b29945628f89
2026-09-22 07:56:58 +02:00

4.4 KiB

id type title domain repo status owner topic_slug created updated depends_on_workplans state_hub_workstream_id
RISK-WP-0007 workplan Reconcile owner evidence and keep runtime closure obligations visible infotech risk-nexus finished the-custodian custodian 2026-09-05 2026-09-05
RISK-WP-0006
ac12733f-3f4b-5c7b-aee7-7115b9c4db72

RISK-WP-0007 — reconcile owner evidence

The repaired reports expose work the register had not read. Reconcile it before building another mechanism. Source remediation is progress; deployed acceptance and credential invalidation require their own evidence.

T01 — Reconcile the qonto return

id: RISK-WP-0007-T01
status: done
priority: high
state_hub_task_id: "d3f0a9b7-4374-5350-b0b4-d7ac4f782acb"

Read the newer inbox notice, source cadence/logger/endpoint and observer workplan. Link QONTO-WP-0005 and KG-WP-0005-T03 to F-0011; replace the stale missing-source claim with the concrete runtime acceptance obligation. Keep the medium grade and open status until that obligation is demonstrated. Record a moved check.

T02 — Reconcile backup source remediation

id: RISK-WP-0007-T02
status: done
priority: high
state_hub_task_id: "215b8b0b-aef0-5575-bf12-b08dc2941cbe"

Read RPF-WP-0029 and verify source fallback removal without displaying, testing or copying credential material. Link provider invalidation/recovery tracking; keep the low grade, open status and embargo until the original conditions hold. Record a moved check, retaining the existing deadline.

T03 — Distinguish accepted obligations from missing fixes

id: RISK-WP-0007-T03
status: done
priority: high
state_hub_task_id: "a17feb05-2c2c-5372-adbb-9d2c095f55fd"

Report an accepted record's accepter, expiry condition, determination and review date when those fields resolve to a real record. Do not invent a fix workplan for F-0008 or suppress incomplete acceptance records. Surface closure conditions even when the source workplan is completed. Cover both paths with regression tests. Inspect F-0008's technical evidence without renewing legal conclusions or certifying that its real-data trigger remains false.

T04 — Record verification boundaries and register the result

id: RISK-WP-0007-T04
status: done
priority: medium
state_hub_task_id: "ebf1edad-6e0e-5fdc-9781-5e79cff8b117"

Retain dated source evidence, explicit next evidence and owners. Inspect local external-intake/publication and activity evidence; state exactly what remains unverified. Update scope/state/index, run tests and reports, register this workplan and its tasks, and verify completion in State Hub.

Boundaries

No messages, acknowledgements, deployments, credential actions, publication, new spending or automatic finding closure. Existing source-owner workplans remain authoritative. This plan closes the register's reconciliation work, not the owners' unresolved runtime obligations or the substantive legal reviews.

Completion evidence

Completed 2026-09-05. RISK-V-0003 retains the inspected source evidence, provenance and runtime/provider acceptance requirements. F-0011 now tracks QONTO-WP-0005 and KG-WP-0005-T03; F-0010 tracks RPF-WP-0029-T02. Both received moved outcomes and remain at instant; no same-sitting clean check was made. Grades, open statuses, the credential embargo and original default dates remain.

F-0008's technical inspection is explicitly not a completed substantive review. Its existing acceptance is now reported with its determination and due date; invalid/incomplete acceptances still produce missing-tracking warnings. The closure-evidence section survives completed source workplans.

Ten isolated tests pass via make test; document links and git diff --check pass. The generated register and live checker expose the two waiting owner tasks, recorded acceptance, four overdue full policies and eight publication handovers.

State Hub registration succeeded for workplan ac12733f-3f4b-5c7b-aee7-7115b9c4db72 and all four tasks (UUIDs in source). Completion status and backing-file binding are reconciled through the same API; the local WORK-RECORDS index is regenerated with the State Hub renderer.

Still external or unverified: runtime capture/observer acceptance, provider invalidation/recovery receipts, acceptance-trigger facts and legal reviews, external contact delivery and scheduled-session completion. Source searches establish no stronger conclusion. No messages or acknowledgements were sent.