risk-nexus/REGISTER.md
tegwick d5147bfaea Typed, dated, defaulted waits — and cut the four-hop chain
The register had nine waits in four days, one four hops deep: F-0003's
embargo waited on F-0009, which waited on railiance-platform, which
waited on live OpenBao verification, which waited on a credential nobody
has. No single link was wrong, which is why it needed a rule.

docs/method/dependencies.md: the register never waits to decide, it
decides and revises. Every wait carries who, what, since, what it would
change, what happens if nobody answers, and the date that default
applies. Depth one — a record never waits on a record that is itself
waiting. Defaults are dates and are pessimistic: silence costs the grade
the evidence supports rather than buying a softer one, and owners are
told the default in advance because a default nobody was warned about is
an ambush.

Applied: F-0009's embargo now lifts on railiance-platform reporting
coverage, with live verification as a refinement rather than a condition,
cutting the F-0003 chain from four hops to two. All eight open waits are
typed with defaults. make check reports them with age, owner and default
date, flags defaults come due, and catches depth-two violations.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-20 22:34:56 +02:00

7.4 KiB

Register

Generated by tools/register_index.py from findings/. Do not edit by hand. Last built 2026-08-20.

8 live of 9 findings; 3 notes below the floor.

Findings

ID Finding System Severity Disclosure Escalation Fix owner Status Cadence Next check
RISK-F-0009 agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest railiance-platform high embargoed none railiance-platform open 1h (1) due
RISK-F-0008 The legal basis for retaining audit facts against an erasure request has been assumed, never established audit-core medium public required (t2, partially-answered) risk-nexus open instant (0) due
RISK-F-0007 No consumer's tenant boundary is verified anywhere estate high embargoed answered (t4, assigned) per-consumer, on request accepted instant (0) due
RISK-F-0006 apps-pg has no backup configured at all: R0 means no recovery railiance-platform high embargoed answered (t3, approved) railiance-platform open 1h (1) due
RISK-F-0005 audit-core read path applies no tenant filter; the bound is deployment, not code audit-core medium embargoed none audit-core open 1h (1) due
RISK-F-0004 tenant-engine events() returns the entire event log unfiltered tenant-engine high embargoed none tenant-engine open 1h (1) due
RISK-F-0003 ops-warden agent read-boundary does not fire on ungraded catalog lanes ops-warden medium embargoed none ops-warden mitigated 1h (1) due
RISK-F-0002 ops-warden signs SSH certificates with no authorization decision, and its unblock is now unsafe ops-warden medium embargoed withdrawn (t6, withdrawn-hazard-window-closed) ops-warden open instant (0) due
RISK-F-0001 flex-auth /v1/check authenticates no caller flex-auth high public withdrawn (t1, withdrawn-before-sending) flex-auth fixed instant (0) due

Constraints

Hazards created by acting in the wrong order. Each binds another finding's remediation.

From Binds Severity Constraint
RISK-F-0002 RISK-F-0001 lifted LIFTED 2026-08-19 — flex-auth /v1/check now authenticates callers (RISK-F-0001 fixed). Enabling policy.enabled is now an availability question for ops-warden, no longer an attestation hazard.

Waiting on someone

Every wait resolves on its default date whether or not anyone answers. Silence never buys a softer grade — see docs/method/dependencies.md.

Finding Who What would change Default if silent On
RISK-F-0009 railiance-platform embargo lifts on coverage; live verification would refine the grade but is not required for it the eight uncovered paths stand as recorded and the finding is re-raised 2026-09-03
RISK-F-0008 audit-core a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable 2026-11-17
RISK-F-0008 the-custodian fixes when the estate stops running on an assumption the assumption is recorded in the register as an assumption 2026-11-17
RISK-F-0007 user-engine likelihood falls for user-engine if a verification exists; a defect becomes its own finding if not the on-request path is recorded as having produced no answer, which makes the acceptance itself unsupported and is escalated 2026-09-03
RISK-F-0006 railiance-platform embargo lifts on a demonstrated restore; the approved spend becomes a real figure recorded as stalled with approval already granted, which is the worst kind of stall 2026-09-18
RISK-F-0005 audit-core likelihood rises to L3 if any other production credential carries may_read graded on the sender alone, as stated; the wider question is recorded as unanswered 2026-09-19
RISK-F-0004 tenant-engine grade rises if the log carries tenant payload rather than metadata grade stands as recorded; absent fix tracking is recorded as a stall 2026-09-03
RISK-F-0002 ops-warden if it admits no ingress, enabling the gate stops all signing — an availability blocker, not a risk one the register records the ordering as unverified and re-raises it; the finding stands at medium 2026-08-27

Embargoes

Held from publication with a stated condition. A hold with no moving condition is a stall.

Finding Since Lifts when Re-decided
RISK-F-0009 2026-08-20 railiance-platform reports the deny set covers every high-risk lane with a KV path (live verification refines the grade, it is not the condition)
RISK-F-0007 2026-08-19 a verification exists for at least one consumer boundary 2026-09-18
RISK-F-0006 2026-08-19 a backup exists and a restore has been demonstrated once 2026-09-18
RISK-F-0005 2026-08-19 AUDIT-WP-0008-T04 lands a tenant filter in the read path 2026-11-17
RISK-F-0004 2026-08-19 the read path filters by tenant in code 2026-09-18
RISK-F-0003 2026-08-19 RISK-F-0009 resolved — the OpenBao deny set covers every high-risk lane with a KV path 2026-09-18
RISK-F-0002 2026-08-19 FLEX-WP-0015-T02 shipped and ops-warden policy.enabled true in production 2026-11-17

Notes (below the floor)

Seen, deliberately not findings. Not graded, not reviewed, not published.

ID Note Why below the floor
RISK-N-0004 No facility answers which zone a workload is in, or what applies there missing capability, not a defect — there is nothing to route to a fix owner, and the register does not file undone work
RISK-N-0003 Every defect in this register was found by reading, none by monitoring no owner and no defect — it is an argument about where to invest detection, and the register cannot route an argument
RISK-N-0001 Noisy-neighbour behaviour is uncharacterised no decision changes today — no tenant shares a saturating workload, and what is missing is measurement work, not a defect to route

How to read this

Severity is docs/method/severity.md; disclosure docs/method/disclosure.md; escalation docs/method/escalation.md; the check cadence docs/method/review.md. Cadence is the ladder rung and the count of consecutive clean checks — a finding at 1q (9) has held still for a long time; one at instant (0) moved recently. Anything wrong resets it. A constraint may be graded higher than the finding that carries it — read both.