A risk management service.
Find a file
tegwick d5147bfaea Typed, dated, defaulted waits — and cut the four-hop chain
The register had nine waits in four days, one four hops deep: F-0003's
embargo waited on F-0009, which waited on railiance-platform, which
waited on live OpenBao verification, which waited on a credential nobody
has. No single link was wrong, which is why it needed a rule.

docs/method/dependencies.md: the register never waits to decide, it
decides and revises. Every wait carries who, what, since, what it would
change, what happens if nobody answers, and the date that default
applies. Depth one — a record never waits on a record that is itself
waiting. Defaults are dates and are pessimistic: silence costs the grade
the evidence supports rather than buying a softer one, and owners are
told the default in advance because a default nobody was warned about is
an ambush.

Applied: F-0009's embargo now lifts on railiance-platform reporting
coverage, with live verification as a refinement rather than a condition,
cutting the F-0003 chain from four hops to two. All eight open waits are
typed with defaults. make check reports them with age, owner and default
date, flags defaults come due, and catches depth-two violations.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 22:34:56 +02:00
activity-definitions Drop dedupe_key_strategy from the inbox watch and say what actually happens 2026-08-20 12:02:14 +02:00
docs Typed, dated, defaulted waits — and cut the four-hop chain 2026-08-20 22:34:56 +02:00
findings Typed, dated, defaulted waits — and cut the four-hop chain 2026-08-20 22:34:56 +02:00
notes RISK-N-0004: route the zone-lookup requirement to zone-engine as a note 2026-08-20 07:24:33 +02:00
tools Typed, dated, defaulted waits — and cut the four-hop chain 2026-08-20 22:34:56 +02:00
workplans Close RISK-WP-0004: all six tasks done 2026-08-20 08:56:17 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-19 23:41:18 +02:00
.repo-classification.yaml Classify with the canon governance_and_control tags 2026-08-20 08:08:07 +02:00
INTENT.md INTENT: the register is no longer empty, and the first finding tested the deferral 2026-08-17 22:52:37 +02:00
Makefile RISK-WP-0004: five of six tasks done; the executor is the operator's call 2026-08-20 08:49:23 +02:00
README.md Close out RISK-WP-0001: task notes, README, repo classification 2026-08-19 23:34:34 +02:00
REGISTER.md Typed, dated, defaulted waits — and cut the four-hop chain 2026-08-20 22:34:56 +02:00
WORK-RECORDS.md Drop dedupe_key_strategy from the inbox watch and say what actually happens 2026-08-20 12:02:14 +02:00

risk-nexus

Risk register and regulatory intake for the estate. Serves risk.coulomb.social. Owned by the-custodian.

Holds findings — security, architecture, operational, compliance — with a severity, an owner and a date; decides whether and when each is published; and decides which must reach the operator personally rather than sitting in a register.

It does not fix things: findings route to the repo that owns the defect. It does not host: policy-nexus is the publication surface.

Where things are

  • REGISTER.md — the whole register, one screen. Generated; do not edit.
  • findings/ — one file per finding. findings/README.md is the filing contract for reporting repos.
  • notes/ — seen, deliberately below the floor. Not graded, not reviewed.
  • docs/method/ — how this repo decides: severity, disclosure, escalation, review and expiry.
  • docs/rulings/ — the reasoning behind each grading, dated.
  • workplans/ — the work.

Using it

make register   # rebuild REGISTER.md from findings/
make check      # verify the index, then report what is going quiet

make check reports ungraded findings, overdue reviews, stalled remediation, embargoes due for re-decision, escalations awaiting the operator, and what is owed at the production transition. It changes nothing.

  • Intent: INTENT.md