Appearance
Risk Register
Обновлено: 2026-07-05 Owner: Founder / You Статус: v0.1, стартовый реестр рисков
Назначение
Risk Register фиксирует основные риски Design Corporation, их владельцев, текущий контроль и следующий шаг. Это не incident log; реальные инциденты остаются в runbooks и операционных журналах.
Severity Model
| Severity | Meaning | Response |
|---|---|---|
P0 | Риск денег, безопасности, доступа или production continuity | Срочно, отдельный owner focus |
P1 | Риск revenue flow, compliance, delivery или повторяемой операции | В текущем рабочем цикле |
P2 | Риск качества, порядка, документации или будущей масштабируемости | Планово |
Risk Register
| Risk | Severity | Area | Owner | Current control | Gap | Next action |
|---|---|---|---|---|---|---|
| Personal and company account mixing | P0 | ownership / accounting | Founder / You | Account boundaries documented in Company Register | No full migration/accounting plan for future company-owned publishing | Keep personal KDP separate; create migration plan only by explicit decision |
| Unknown current cash position | P0 | finance | Founder / You | Finance Ledger structure exists | Real bank/payment data not filled | Fill current-month cash in/out and subscriptions |
| Unknown monthly burn | P0 | finance | Founder / You | Expense categories defined | Subscription and hosting costs not reconciled | Build subscription ledger |
| P0 revenue KPI missing | P0 | revenue | Agent Book / Agent Hub / Agent Print | Revenue priorities documented | Book/Hub/Print baseline metrics not filled | Add weekly KPI snapshot for Book, Hub and Print |
| Secrets exposure in docs/repo | P0 | security | Agent Platform / Agent Docs | Docs explicitly ban secrets | Need periodic scan discipline | Add secret scan checklist to docs change process |
| Production deploy confusion with git push | P0 | operations | Founder / You / Agent Platform | Docs distinguish push from deploy | Future agents may over-apply standing push approval | Keep production deploy approval separate in governance |
| GitHub token expiry blocking operations | P1 | operations | Founder / You | Token renewed on 2026-07-03 | No reminder/rotation cadence | Add credential rotation schedule without storing token |
| Payment processor setup unknown | P1 | finance / Book / Print / Hub | Agent Accounting / Agent Book / Agent Print / Agent Hub | Placeholder in Finance Ledger | Fees, invoice flow and settlement timing unknown | Inventory active processors, invoice flow and fees |
| Tax filing cadence unknown | P1 | compliance | Founder / You / accountant | Placeholder in Company Register | VAT/CIT/PIT reserve rules not documented | Confirm accountant cadence and reserve rule |
| Domain renewal ownership incomplete | P1 | infrastructure | Agent Platform | Domains listed in Topology | Renewal provider/cost/expiry not centralized | Add domain expiry/cost owner to topology or finance ledger |
| Backup coverage unknown across all projects | P1 | continuity | Agent Platform | Some runbooks contain backup notes | No global backup matrix | Create backup coverage matrix by project |
| Legacy/paused monitors causing false P0 alerts | P1 | operations | Agent Platform | Serveradmin runbook has cleanup patterns | Project register still has statuses needing verification | Classify active vs paused vs legacy monitors |
| Project owner gaps | P1 | governance | Founder / You / Agent Docs | Owners doc covers core agents | Several register rows need owner assignment | Confirm owners for GMG, Agent Gateway, Orchestrator, BuildOS, Beauty, Movie |
| Client data retention unknown | P1 | compliance | Founder / You | Company Register marks missing | No retention policy | Define retention/access policy per app |
| Brand asset source unclear | P2 | brand / delivery | Agent Docs / Agent UI | Design doctrine exists | Canonical assets not fully indexed | Identify logo/font/color sources |
Immediate P0 Queue
- Fill Finance Ledger with current-month cash in/out.
- Build subscription ledger and monthly burn.
- Add Book/Hub/Print KPI baseline.
- Confirm tax/accounting cadence with accountant.
- Add backup/domain expiry matrix.
Controls
| Control | Applies to | Status |
|---|---|---|
| No secrets in docs | docs repo, company docs, runbooks | active |
| Explicit production deploy approval | all prod domains | active |
| Separate personal vs company KDP/accounting | Book/KDP flows | active policy, partial data |
| MCP/docs index rebuild after docs changes | docs knowledge system | active |
| Finance Ledger source/period/formula requirement | all money answers | active framework |
| Project Register status model | all project portfolio decisions | active framework |
Update Rule
Update this register after:
- A production or finance-impacting incident.
- Any payout, billing, tax, Ads write-mode or third-party account change.
- Any new project/domain/runtime added to topology.
- Any confirmed change in revenue priority.
- Any security, secret or backup process change.