risk-nexus/REGISTER.md
tegwick e482423523 Five owner replies worked through: one fix closed, two grades corrected, one control retired
RISK-F-0006 fixed and public — railiance-platform's restore evidence was
read, not taken: 56s restore, all 13 coulomb_social row counts matching,
plus the BestEffort QoS this register had graded on, plus a failed first
WAL attempt recorded alongside the successful one.

RISK-F-0004 high -> medium. tenant-engine corrected in both directions:
payloads are returned (worse than graded) but there is no HTTP event-read
route, so the live network-reachable read this register wrote down does
not exist. L3 was a reachability claim inherited from a summary and never
tested.

RISK-F-0002: reading (c) confirmed — nothing blocks policy.enabled, it is
off by decision. ADR-0006 retires it in favour of zone-scoped
enforcement. Ruled: the framing is superseded, the risk is not. A control
retired before its replacement exists is still an absent control. The
successor's blocker is 26 of 27 lanes having no identifiable workload,
which is RISK-N-0004 with a number on it.

RISK-F-0009: uncovered count 8 -> 6, corrected by the reporter against
themselves; the token was never expired; and the deployed policy differs
from the file, which moves 'a file is not a safe proxy for the server'
from suspicion to evidence and amends verification.md — including the
admission that fix_tracker.py reads records, and a record can be stale.

RISK-V-0001 reconciled: ops-warden reaches the pin from the node through
a tunnel, so a podSelector ingress rule does not constrain it. The
observation was right and the inference was not.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 09:32:32 +02:00

6.6 KiB

Register

Generated by tools/register_index.py from findings/. Do not edit by hand. Last built 2026-08-21.

7 live of 9 findings; 3 notes below the floor.

Findings

ID Finding System Severity Disclosure Escalation Fix owner Status Cadence Next check
RISK-F-0009 agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest railiance-platform high embargoed none railiance-platform open instant (0) due
RISK-F-0008 The legal basis for retaining audit facts against an erasure request has been assumed, never established audit-core medium public answered (t2, answered) risk-nexus accepted instant (0) due
RISK-F-0007 No consumer's tenant boundary is verified anywhere estate high embargoed answered (t4, assigned) per-consumer, on request accepted 1h (1) 2026-08-21 08:32Z
RISK-F-0006 apps-pg has no backup configured at all: R0 means no recovery railiance-platform high public answered (t3, answered) railiance-platform fixed instant (0) due
RISK-F-0005 audit-core read path applies no tenant filter; the bound is deployment, not code audit-core medium public none audit-core mitigated instant (0) due
RISK-F-0004 tenant-engine events() returns the entire event log unfiltered tenant-engine medium embargoed none tenant-engine open instant (0) due
RISK-F-0003 ops-warden agent read-boundary does not fire on ungraded catalog lanes ops-warden medium embargoed none ops-warden mitigated 8h (2) 2026-08-21 14:32Z
RISK-F-0002 ops-warden signs SSH certificates with no authorization decision, and its unblock is now unsafe ops-warden medium embargoed withdrawn (t6, withdrawn-hazard-window-closed) ops-warden open instant (0) due
RISK-F-0001 flex-auth /v1/check authenticates no caller flex-auth high public withdrawn (t1, withdrawn-before-sending) flex-auth fixed instant (0) due

Constraints

Hazards created by acting in the wrong order. Each binds another finding's remediation.

From Binds Severity Constraint
RISK-F-0002 RISK-F-0001 lifted LIFTED 2026-08-19 — flex-auth /v1/check now authenticates callers (RISK-F-0001 fixed). Enabling policy.enabled is now an availability question for ops-warden, no longer an attestation hazard.

Waiting on someone

Every wait resolves on its default date whether or not anyone answers. Silence never buys a softer grade — see docs/method/dependencies.md.

Finding Who What would change Default if silent On
RISK-F-0009 railiance-platform embargo lifts on coverage; live verification would refine the grade but is not required for it the eight uncovered paths stand as recorded and the finding is re-raised 2026-09-03
RISK-F-0008 audit-core a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable 2026-11-17
RISK-F-0007 user-engine likelihood falls for user-engine if a verification exists; a defect becomes its own finding if not the on-request path is recorded as having produced no answer, which makes the acceptance itself unsupported and is escalated 2026-09-03
RISK-F-0005 audit-core likelihood rises to L3 if any other production credential carries may_read graded on the sender alone, as stated; the wider question is recorded as unanswered 2026-09-19
RISK-F-0001 policy-nexus publication: published plus the permanent URL comes back onto each record the findings stay disclosure: public with no address, which the register records as a claim rather than a publication 2026-09-17

Embargoes

Held from publication with a stated condition. A hold with no moving condition is a stall.

Finding Since Lifts when Re-decided
RISK-F-0009 2026-08-20 railiance-platform reports the deny set covers every high-risk lane with a KV path (live verification refines the grade, it is not the condition)
RISK-F-0007 2026-08-19 a verification exists for at least one consumer boundary 2026-09-18
RISK-F-0004 2026-08-19 the read path filters by tenant in code 2026-09-18
RISK-F-0003 2026-08-19 RISK-F-0009 resolved — the OpenBao deny set covers every high-risk lane with a KV path 2026-09-18
RISK-F-0002 2026-08-19 FLEX-WP-0015-T02 shipped and ops-warden policy.enabled true in production 2026-11-17

Notes (below the floor)

Seen, deliberately not findings. Not graded, not reviewed, not published.

ID Note Why below the floor
RISK-N-0004 No facility answers which zone a workload is in, or what applies there missing capability, not a defect — there is nothing to route to a fix owner, and the register does not file undone work
RISK-N-0003 Every defect in this register was found by reading, none by monitoring no owner and no defect — it is an argument about where to invest detection, and the register cannot route an argument
RISK-N-0001 Noisy-neighbour behaviour is uncharacterised no decision changes today — no tenant shares a saturating workload, and what is missing is measurement work, not a defect to route

How to read this

Severity is docs/method/severity.md; disclosure docs/method/disclosure.md; escalation docs/method/escalation.md; the check cadence docs/method/review.md. Cadence is the ladder rung and the count of consecutive clean checks — a finding at 1q (9) has held still for a long time; one at instant (0) moved recently. Anything wrong resets it. A constraint may be graded higher than the finding that carries it — read both.