Skip to content

Risk Register

Обновлено: 2026-07-05 Owner: Founder / You Статус: v0.1, стартовый реестр рисков

Назначение

Risk Register фиксирует основные риски Design Corporation, их владельцев, текущий контроль и следующий шаг. Это не incident log; реальные инциденты остаются в runbooks и операционных журналах.

Severity Model

SeverityMeaningResponse
P0Риск денег, безопасности, доступа или production continuityСрочно, отдельный owner focus
P1Риск revenue flow, compliance, delivery или повторяемой операцииВ текущем рабочем цикле
P2Риск качества, порядка, документации или будущей масштабируемостиПланово

Risk Register

RiskSeverityAreaOwnerCurrent controlGapNext action
Personal and company account mixingP0ownership / accountingFounder / YouAccount boundaries documented in Company RegisterNo full migration/accounting plan for future company-owned publishingKeep personal KDP separate; create migration plan only by explicit decision
Unknown current cash positionP0financeFounder / YouFinance Ledger structure existsReal bank/payment data not filledFill current-month cash in/out and subscriptions
Unknown monthly burnP0financeFounder / YouExpense categories definedSubscription and hosting costs not reconciledBuild subscription ledger
P0 revenue KPI missingP0revenueAgent Book / Agent Hub / Agent PrintRevenue priorities documentedBook/Hub/Print baseline metrics not filledAdd weekly KPI snapshot for Book, Hub and Print
Secrets exposure in docs/repoP0securityAgent Platform / Agent DocsDocs explicitly ban secretsNeed periodic scan disciplineAdd secret scan checklist to docs change process
Production deploy confusion with git pushP0operationsFounder / You / Agent PlatformDocs distinguish push from deployFuture agents may over-apply standing push approvalKeep production deploy approval separate in governance
GitHub token expiry blocking operationsP1operationsFounder / YouToken renewed on 2026-07-03No reminder/rotation cadenceAdd credential rotation schedule without storing token
Payment processor setup unknownP1finance / Book / Print / HubAgent Accounting / Agent Book / Agent Print / Agent HubPlaceholder in Finance LedgerFees, invoice flow and settlement timing unknownInventory active processors, invoice flow and fees
Tax filing cadence unknownP1complianceFounder / You / accountantPlaceholder in Company RegisterVAT/CIT/PIT reserve rules not documentedConfirm accountant cadence and reserve rule
Domain renewal ownership incompleteP1infrastructureAgent PlatformDomains listed in TopologyRenewal provider/cost/expiry not centralizedAdd domain expiry/cost owner to topology or finance ledger
Backup coverage unknown across all projectsP1continuityAgent PlatformSome runbooks contain backup notesNo global backup matrixCreate backup coverage matrix by project
Legacy/paused monitors causing false P0 alertsP1operationsAgent PlatformServeradmin runbook has cleanup patternsProject register still has statuses needing verificationClassify active vs paused vs legacy monitors
Project owner gapsP1governanceFounder / You / Agent DocsOwners doc covers core agentsSeveral register rows need owner assignmentConfirm owners for GMG, Agent Gateway, Orchestrator, BuildOS, Beauty, Movie
Client data retention unknownP1complianceFounder / YouCompany Register marks missingNo retention policyDefine retention/access policy per app
Brand asset source unclearP2brand / deliveryAgent Docs / Agent UIDesign doctrine existsCanonical assets not fully indexedIdentify logo/font/color sources

Immediate P0 Queue

  1. Fill Finance Ledger with current-month cash in/out.
  2. Build subscription ledger and monthly burn.
  3. Add Book/Hub/Print KPI baseline.
  4. Confirm tax/accounting cadence with accountant.
  5. Add backup/domain expiry matrix.

Controls

ControlApplies toStatus
No secrets in docsdocs repo, company docs, runbooksactive
Explicit production deploy approvalall prod domainsactive
Separate personal vs company KDP/accountingBook/KDP flowsactive policy, partial data
MCP/docs index rebuild after docs changesdocs knowledge systemactive
Finance Ledger source/period/formula requirementall money answersactive framework
Project Register status modelall project portfolio decisionsactive framework

Update Rule

Update this register after:

  1. A production or finance-impacting incident.
  2. Any payout, billing, tax, Ads write-mode or third-party account change.
  3. Any new project/domain/runtime added to topology.
  4. Any confirmed change in revenue priority.
  5. Any security, secret or backup process change.