zone-engine/workplans
tegwick 158efab24a ZONE-WP-0001-T03: maturity-derived risk defaults, and what they can attach to
Operator direction: an ungraded lane inherits the default its maturity context
implies — accepted in experimental context, high or critical in production.

M0-M3 is the right ladder and already carries rank, phase, max_dataclass and
promotion gates; what it lacks is a join to lanes, which is T02's gap.
.repo-classification.yaml category cannot carry it: railiance-platform, which
runs production OpenBao and owns three of RISK-F-0003's five exposed lanes, is
category tooling, while net-kingdom, a canon docs repo, is product. It orders
work mode, not blast radius.

Also records that maturity must come from the lane's owner, not the repo holding
the catalog, and that 'accepted' is an acceptance rather than a grade — it needs
an owner and an expiry, so it is a second field, not a rung.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 23:23:49 +02:00
..
ZONE-WP-0001-security-zone-model.md ZONE-WP-0001-T03: maturity-derived risk defaults, and what they can attach to 2026-08-19 23:23:49 +02:00