A risk management service.
ADR-0004 reads as a categorical rule; the implementation is an opt-in list. is_high_risk is risk == "high", and risk is optional — 14 of 27 catalog lanes carry no value, so the boundary never fires for them. Five are exec_capable, so warden access --fetch can stream a real value to an agent session. Reported by ops-warden about ops-warden, found while partitioning the estate for zone-engine's ZONE-WP-0001-T02. Severity, disclosure and escalation left unset — those are risk-nexus's to set. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| findings | ||
| INTENT.md | ||
| README.md | ||
risk-nexus
Risk register and regulatory intake for the estate. Serves
risk.coulomb.social. Owned by the-custodian.
Holds findings — security, architecture, operational, compliance — with a severity, an owner and a date; decides whether and when each is published; and decides which must reach the operator personally rather than sitting in a register.
It does not fix things: findings route to the repo that owns the defect. It
does not host: policy-nexus is the publication surface.
- Intent:
INTENT.md