Operator ruled both. Findings publish as the file a reader gets — including RISK-F-0001's record that this register graded it critical while its fix notice sat unread. A summary would be a second document per finding kept in sync by hand, and drift is the failure this repo most distrusts; and a published register containing only other repos' defects reads as an accusation, while one containing its own reads as a record. Method docs public except escalation, which is restricted because it names spend thresholds and describes when the operator personally is interrupted — a map of where attention is scarce, needed by nobody judging a finding. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
3 KiB
| id | type | title | status | owner | date | workplan |
|---|---|---|---|---|---|---|
| RISK-RULING-2026-08-20-B | ruling | What the estate publishes about its own risk | recorded | risk-nexus | 2026-08-20 | RISK-WP-0002 |
Publication — 2026-08-20
Two operator decisions, and what they commit this register to.
Findings publish whole
A reader gets the finding file: the claim, the grade with its reasoning, the review log, and the register's own corrections.
RISK-F-0001 is the first, and it publishes with the paragraph recording that
this register graded it critical and prepared an escalation while its fix
notice sat unread in the inbox — including the sentence "only luck put the fix
on the same day".
That was the decision worth taking deliberately, and the reasoning is worth keeping:
- The contract publishes a file. A summary would be a second document per
finding, kept in sync by hand, and drift is the failure this register most
distrusts — it is why
REGISTER.mdis generated rather than maintained. - The self-criticism is the credible part. A published register that only contains other repos' defects reads as an accusation. One that contains its own reads as a record. The estate has nothing to gain from a risk register that appears to have never been wrong.
- It is the same standard applied inward. This repo asks every owner to state exposure only as far as they can support it, and to say when they could not verify something. Publishing a cleaned-up version of our own work while holding others to that would be indefensible.
The cost is real and accepted: criticism of other repos is public, and so is every misgrade this register makes. The second is the price of the first being believable.
Method documents: public, except escalation
Public: severity, disclosure, review, verification, dependencies.
Together they let an outside reader judge whether a published finding means
anything — what high is, why something was held, how often it is re-checked,
what the register may verify itself, and what happens when someone does not
answer.
escalation is restricted, and not because it is embarrassing. It names
the operator's spend thresholds and describes the conditions under which the
operator personally is interrupted. That is a map of where attention is scarce
and what triggers it, which is useful to exactly one kind of reader and is not
needed by anyone judging a finding.
check-procedure stays internal by omission rather than by ruling: it is an
operating manual, not an instrument, and nothing about a published finding
depends on it.
What this does not decide
- Timing. Publication follows the embargo conditions already recorded. Six findings remain held.
- Address scheme.
policy-nexusowns addressing and permanence (POLICY-NEXUS-WP-0001). Paths proposed here are proposals. - Whether anything else ever publishes. Rulings, verifications and regulatory records are unaddressed and stay internal until someone asks.