Source: c79 finding-lifecycle — the rubric as org config · 2026-08-25
The frameworks are agnostic — every risk program must have an SLA rubric, but each org defines its own targets (Mark M, 2026-08-20). So the rubric is the one genuinely new config surface the lifecycle needs. Edit a target and the consequence panel re-judges the live world: SLA data = f(findings, rubric, period), with the rubric as the knob.
c78 placeholder 7 / 30 / 90 / 180 — superseded by Mark M's actual program (2026-08-20 call): 14 / 30 / 90 / advisory.
Clock starts at detection · exception pauses with mandatory expiry · expiry re-opens mechanically · reclassify re-baselines from original detection · accepted risk never counts as resolved. These are the semantics of the machine, ruled on the anatomy page — making them configurable is the first step toward the workflow tooling this cycle deliberately doesn't build.
Composition notes
- The consequence panel is the argument — editing a number visibly moves breach counts and the within-SLA verdict because deriveWorld takes the rubric as an argument. Nothing is stored; the page is the function.
- Presets demonstrate program variance — Mark M's own numbers, the superseded c78 placeholder, and the 48-hour-criticals program he described ("HIPAA HITRUST… criticals in 48 hours, no negotiate"). Same findings, three different judgments.
- "Advisory" is a first-class target value — days: null, per Mark M's low severity ("when we can get to it"). Advisory findings age informationally and can never breach.
- Changing a rubric after a quarterly export silently rewrites submitted history — target days become a contract at first submission. Product needs rubric versioning eventually; out of mock scope, recorded as an open thread.