A risk management service.
Find a file
tegwick e482423523 Five owner replies worked through: one fix closed, two grades corrected, one control retired
RISK-F-0006 fixed and public — railiance-platform's restore evidence was
read, not taken: 56s restore, all 13 coulomb_social row counts matching,
plus the BestEffort QoS this register had graded on, plus a failed first
WAL attempt recorded alongside the successful one.

RISK-F-0004 high -> medium. tenant-engine corrected in both directions:
payloads are returned (worse than graded) but there is no HTTP event-read
route, so the live network-reachable read this register wrote down does
not exist. L3 was a reachability claim inherited from a summary and never
tested.

RISK-F-0002: reading (c) confirmed — nothing blocks policy.enabled, it is
off by decision. ADR-0006 retires it in favour of zone-scoped
enforcement. Ruled: the framing is superseded, the risk is not. A control
retired before its replacement exists is still an absent control. The
successor's blocker is 26 of 27 lanes having no identifiable workload,
which is RISK-N-0004 with a number on it.

RISK-F-0009: uncovered count 8 -> 6, corrected by the reporter against
themselves; the token was never expired; and the deployed policy differs
from the file, which moves 'a file is not a safe proxy for the server'
from suspicion to evidence and amends verification.md — including the
admission that fix_tracker.py reads records, and a record can be stale.

RISK-V-0001 reconciled: ops-warden reaches the pin from the node through
a tunnel, so a podSelector ingress rule does not constrain it. The
observation was right and the inference was not.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 09:32:32 +02:00
activity-definitions Drop dedupe_key_strategy from the inbox watch and say what actually happens 2026-08-20 12:02:14 +02:00
docs Five owner replies worked through: one fix closed, two grades corrected, one control retired 2026-08-21 09:32:32 +02:00
findings Five owner replies worked through: one fix closed, two grades corrected, one control retired 2026-08-21 09:32:32 +02:00
history Persist the gap analysis to history/, open RISK-WP-0005 2026-08-21 08:19:57 +02:00
notes RISK-WP-0005 finished: the seven gaps closed 2026-08-21 08:34:30 +02:00
tools RISK-WP-0005 finished: the seven gaps closed 2026-08-21 08:34:30 +02:00
workplans RISK-WP-0005 finished: the seven gaps closed 2026-08-21 08:34:30 +02:00
.custodian-brief.md chore(consistency): sync task status from DB [auto] 2026-08-19 23:41:18 +02:00
.repo-classification.yaml Classify with the canon governance_and_control tags 2026-08-20 08:08:07 +02:00
INTENT.md INTENT: the register is no longer empty, and the first finding tested the deferral 2026-08-17 22:52:37 +02:00
Makefile RISK-WP-0005 finished: the seven gaps closed 2026-08-21 08:34:30 +02:00
README.md RISK-WP-0005 T02, T03, T04: intake, the transition, and an honest README 2026-08-21 08:31:44 +02:00
REGISTER.md Five owner replies worked through: one fix closed, two grades corrected, one control retired 2026-08-21 09:32:32 +02:00
STATE.md STATE.md: what the gap analysis changed 2026-08-21 08:35:13 +02:00
WORK-RECORDS.md STATE.md: what the gap analysis changed 2026-08-21 08:35:13 +02:00

risk-nexus

Risk register and regulatory intake for the estate. Owned by the-custodian.

It does not serve anything yet. INTENT.md names risk.coulomb.social as the eventual surface; today publication runs through policy-nexus and three documents are waiting for an address. Recorded here rather than left as a claim, because a stated surface that does not exist is the class of thing this register grades other repos down for.

Holds findings — security, architecture, operational, compliance — with a severity, an owner and a date; decides whether and when each is published; and decides which must reach the operator personally rather than sitting in a register.

It does not fix things: findings route to the repo that owns the defect. It does not host: policy-nexus is the publication surface.

Where things are

  • REGISTER.md — the whole register, one screen. Generated; do not edit.
  • findings/ — one file per finding. findings/README.md is the filing contract for reporting repos.
  • notes/ — seen, deliberately below the floor. Not graded, not reviewed.
  • docs/method/ — how this repo decides: severity, disclosure, escalation, review and expiry.
  • docs/rulings/ — the reasoning behind each grading, dated.
  • workplans/ — the work.

Using it

make register   # rebuild REGISTER.md from findings/
make check      # verify the index, then report what is going quiet

make check reports ungraded findings, overdue reviews, stalled remediation, embargoes due for re-decision, escalations awaiting the operator, and what is owed at the production transition. It changes nothing.

  • Intent: INTENT.md