The register had nine waits in four days, one four hops deep: F-0003's embargo waited on F-0009, which waited on railiance-platform, which waited on live OpenBao verification, which waited on a credential nobody has. No single link was wrong, which is why it needed a rule. docs/method/dependencies.md: the register never waits to decide, it decides and revises. Every wait carries who, what, since, what it would change, what happens if nobody answers, and the date that default applies. Depth one — a record never waits on a record that is itself waiting. Defaults are dates and are pessimistic: silence costs the grade the evidence supports rather than buying a softer one, and owners are told the default in advance because a default nobody was warned about is an ambush. Applied: F-0009's embargo now lifts on railiance-platform reporting coverage, with live verification as a refinement rather than a condition, cutting the F-0003 chain from four hops to two. All eight open waits are typed with defaults. make check reports them with age, owner and default date, flags defaults come due, and catches depth-two violations. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
7.4 KiB
Register
Generated by tools/register_index.py from findings/. Do not edit by hand. Last built 2026-08-20.
8 live of 9 findings; 3 notes below the floor.
Findings
| ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Cadence | Next check |
|---|---|---|---|---|---|---|---|---|---|
| RISK-F-0009 | agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest | railiance-platform | high | embargoed | none | railiance-platform | open | 1h (1) | due |
| RISK-F-0008 | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | required (t2, partially-answered) | risk-nexus | open | instant (0) | due |
| RISK-F-0007 | No consumer's tenant boundary is verified anywhere | estate | high | embargoed | answered (t4, assigned) | per-consumer, on request | accepted | instant (0) | due |
| RISK-F-0006 | apps-pg has no backup configured at all: R0 means no recovery | railiance-platform | high | embargoed | answered (t3, approved) | railiance-platform | open | 1h (1) | due |
| RISK-F-0005 | audit-core read path applies no tenant filter; the bound is deployment, not code | audit-core | medium | embargoed | none | audit-core | open | 1h (1) | due |
| RISK-F-0004 | tenant-engine events() returns the entire event log unfiltered | tenant-engine | high | embargoed | none | tenant-engine | open | 1h (1) | due |
| RISK-F-0003 | ops-warden agent read-boundary does not fire on ungraded catalog lanes | ops-warden | medium | embargoed | none | ops-warden | mitigated | 1h (1) | due |
| RISK-F-0002 | ops-warden signs SSH certificates with no authorization decision, and its unblock is now unsafe | ops-warden | medium | embargoed | withdrawn (t6, withdrawn-hazard-window-closed) | ops-warden | open | instant (0) | due |
| RISK-F-0001 | flex-auth /v1/check authenticates no caller | flex-auth | high | public | withdrawn (t1, withdrawn-before-sending) | flex-auth | fixed | instant (0) | due |
Constraints
Hazards created by acting in the wrong order. Each binds another finding's remediation.
| From | Binds | Severity | Constraint |
|---|---|---|---|
| RISK-F-0002 | RISK-F-0001 | lifted | LIFTED 2026-08-19 — flex-auth /v1/check now authenticates callers (RISK-F-0001 fixed). Enabling policy.enabled is now an availability question for ops-warden, no longer an attestation hazard. |
Waiting on someone
Every wait resolves on its default date whether or not anyone answers.
Silence never buys a softer grade — see docs/method/dependencies.md.
| Finding | Who | What would change | Default if silent | On |
|---|---|---|---|---|
| RISK-F-0009 | railiance-platform | embargo lifts on coverage; live verification would refine the grade but is not required for it | the eight uncovered paths stand as recorded and the finding is re-raised | 2026-09-03 |
| RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 |
| RISK-F-0008 | the-custodian | fixes when the estate stops running on an assumption | the assumption is recorded in the register as an assumption | 2026-11-17 |
| RISK-F-0007 | user-engine | likelihood falls for user-engine if a verification exists; a defect becomes its own finding if not | the on-request path is recorded as having produced no answer, which makes the acceptance itself unsupported and is escalated | 2026-09-03 |
| RISK-F-0006 | railiance-platform | embargo lifts on a demonstrated restore; the approved spend becomes a real figure | recorded as stalled with approval already granted, which is the worst kind of stall | 2026-09-18 |
| RISK-F-0005 | audit-core | likelihood rises to L3 if any other production credential carries may_read | graded on the sender alone, as stated; the wider question is recorded as unanswered | 2026-09-19 |
| RISK-F-0004 | tenant-engine | grade rises if the log carries tenant payload rather than metadata | grade stands as recorded; absent fix tracking is recorded as a stall | 2026-09-03 |
| RISK-F-0002 | ops-warden | if it admits no ingress, enabling the gate stops all signing — an availability blocker, not a risk one | the register records the ordering as unverified and re-raises it; the finding stands at medium | 2026-08-27 |
Embargoes
Held from publication with a stated condition. A hold with no moving condition is a stall.
| Finding | Since | Lifts when | Re-decided |
|---|---|---|---|
| RISK-F-0009 | 2026-08-20 | railiance-platform reports the deny set covers every high-risk lane with a KV path (live verification refines the grade, it is not the condition) | — |
| RISK-F-0007 | 2026-08-19 | a verification exists for at least one consumer boundary | 2026-09-18 |
| RISK-F-0006 | 2026-08-19 | a backup exists and a restore has been demonstrated once | 2026-09-18 |
| RISK-F-0005 | 2026-08-19 | AUDIT-WP-0008-T04 lands a tenant filter in the read path | 2026-11-17 |
| RISK-F-0004 | 2026-08-19 | the read path filters by tenant in code | 2026-09-18 |
| RISK-F-0003 | 2026-08-19 | RISK-F-0009 resolved — the OpenBao deny set covers every high-risk lane with a KV path | 2026-09-18 |
| RISK-F-0002 | 2026-08-19 | FLEX-WP-0015-T02 shipped and ops-warden policy.enabled true in production | 2026-11-17 |
Notes (below the floor)
Seen, deliberately not findings. Not graded, not reviewed, not published.
| ID | Note | Why below the floor |
|---|---|---|
| RISK-N-0004 | No facility answers which zone a workload is in, or what applies there | missing capability, not a defect — there is nothing to route to a fix owner, and the register does not file undone work |
| RISK-N-0003 | Every defect in this register was found by reading, none by monitoring | no owner and no defect — it is an argument about where to invest detection, and the register cannot route an argument |
| RISK-N-0001 | Noisy-neighbour behaviour is uncharacterised | no decision changes today — no tenant shares a saturating workload, and what is missing is measurement work, not a defect to route |
How to read this
Severity is docs/method/severity.md; disclosure docs/method/disclosure.md;
escalation docs/method/escalation.md; the check cadence docs/method/review.md.
Cadence is the ladder rung and the count of consecutive clean checks — a finding at 1q (9)
has held still for a long time; one at instant (0) moved recently. Anything wrong resets it.
A constraint may be graded higher than the finding that carries it — read both.