Specira sample artefact. Rendered from the governed default template on a fictional company. Names, figures and dates are illustrative.All artefacts →
SAMPLE
seeded demo data · specira.ai
Specira Risk Register: Governed Template Rendering
Governed template rendering reference: Risk Register default v2 (draft) definition 06f85204…94fb
Risk Register · Project artifact SPECIRA

Risk Register: Dispatch Modernization

Meridian Field Services: instructional example, not project evidence

Draft · watermark policy: draft_only template risk_register v2 · pack: specira_default_delivery track here, analyze there; one scale, one owner per row
§1

Scales, Floor & Cadence

mandatory 1 decision1 evidence rule validators: scores_cite_the_one_corporate_anchored_scale · no_second_scale_minted · export_opens_with_scope_header_and_register_pointer

One corporate scale (the threat model's anchors, cited never restated), so a threat rating and a delivery risk score compare directly. The floor decides what earns a row; the cadence scales with severity.

Scope: full register, as of 2026-09-15 · live register at workspace registers[1]. Scale: the threat model's anchored likelihood and impact scales (risk ratings[2]); TM-01's likely-high and an adoption risk's score are the same currency. Floor: possible-moderate and above earns a row (E. Sandoval with the sponsor, July 14; aligns with the threat model's acceptance floor). Cadence: high band weekly at steering; moderate biweekly with the delivery lead; escalation fires on any trigger or indicator breach immediately. Scale changes are governance decisions (decision log[3]).

§2

Technical Risks

mandatory 1 decision1 evidence rule validators: every_risk_statement_matches_cause_event_impact_pattern · threat_model_sourced_risk_has_backreference_id · every_open_risk_has_single_named_owner

Cause → event → impact, every row; a bare noun is unscoreable. Material threat findings graduate here by id; the analysis stays in the threat model.

IdStatement (cause → event → impact)InherentProximity / velocityLeading indicatorOwnerSource
RSK-01 Because vendor webhooks are the sole position path (per ADR-6[3]), a replayed or forged webhook could poison positions and steer assignments, costing dispatch integrity at the pilot hub likely · high imminent · fast Signature-verification failure rate E. Sandoval TM-01[2]
RSK-02 Because the board exposes assignment actions to authenticated staff, a read-only account crafting direct calls could write assignments without authority possible · high imminent · fast Server-side denial count for read-only roles E. Sandoval TM-03[2]
RSK-04 Because a single vendor push path now carries all positions, a vendor outage would stale the board and block proximity assignment beyond the feed-loss window possible · moderate within pilot · fast Feed gap length trend (INT-1 failure semantics[4]) E. Sandoval ADR-6[3]
RSK-05 Because Calgary runs an exception intake process discovered at journey mapping, the one-process rollout plan would misfit Calgary, costing rollout rework in phase two possible · moderate phase two · slow n/a (none identified; noted) M. Chen ASM-04[5] broken
§3

Business Risks

mandatory 1 decision1 evidence rule validators: escalate_rows_record_handoff_target · leading_indicator_present_or_explicit_none_note
IdStatementInherentLeading indicatorOwnerNote
RSK-06 Because suggestion-first dispatch changes a habit dispatchers have held for years (future state[6]), sustained bypass-by-override could erode the pilot's value case before the week-6 review possible · high Override rate above 40% after week 2 (US-3 telemetry[7]) M. Chen plan §4
RSK-07 Because the monitoring-notice question is unresolved (open questions[8]), a union grievance over location tracking could pause the pilot at the represented hub possible · high Union response to the notice review N. Duval ESCALATED to the steering group July 21 (beyond this register's authority); received by the sponsor; handoff recorded, row kept
§4

Response Plans

mandatory 1 decision1 evidence rule validators: every_row_above_floor_has_response_plan · accept_rows_name_owner_and_revisit_event · residual_not_exceeding_inherent_without_justification

The row carries the summary; the plan carries the funded actions: split, never duplicated. Responses come from the closed set: avoid, mitigate, transfer, accept, escalate.

RiskResponseActions (citing their rows)TriggerResidual
RSK-01mitigate Signature hardening + replay-window rejection (SR-021[8]); quarterly key rotation (machine identity[9]) Indicator breach opens an incident possible · moderate
RSK-02mitigate Server-side authority denial (SR-004[8]), instantiated at US-1 row AT-5[7] Denial-count anomaly rare · moderate
RSK-04mitigate Degradation posture + feed-loss resilience scenario (quality scenarios[4]), verified by DV-5[10] Feed gap beyond 10 min activates the manual-assignment contingency possible · low
RSK-05mitigate Calgary exception-path journey mapping added to phase two (portfolio[6]) Phase-two planning start rare · moderate
RSK-06mitigate + accept residual Suggestion-quality tuning + override-reason review loop (FR-013[11], US-3[7]) The 40% indicator possible · moderate; accepted by M. Chen, revisit at the week-6 value review
RSK-07escalate Steering owns the response; contingency: notice text pre-cleared with the union representative before pilot start n/a held at steering
§5

Closed Risks

mandatory 1 decision1 evidence rule validators: closed_risk_has_disposition_and_rationale · realized_rows_link_their_issue

A register is only living if it retires rows as routinely as it opens them. Realized links its issue; retired states its evidence; nothing vanishes.

IdDispositionRationale & evidenceDate
RSK-03retired Adapter fan-in capacity was unproven; the breakpoint run measured failure onset at 2,150 positions/min against the 400 needed, a fivefold margin (PS-3 results[12]); signed E. Sandoval Sep 13
RSK-08realized → issue The transitional INT-3 nightly drop loaded a truncated file one morning; converted to ISS-2[13] (resolved by checksum-and-rerun, INT-3[4]); the row closed the day the issue opened: one fact, one tracker Aug 2
§6

Open Questions

mandatory1 decision
QuestionOwnerAnswer byBlocks
Does the week-6 value review need a pre-agreed override-rate threshold distinct from RSK-06's indicator (a review gate versus a risk trigger)? M. ChenSep 26, 2026 The RSK-06 acceptance wording only
Refs

References & Package Contents

In the Specira workspace

specira [1] Workspace risk register: the live source of truth app.specira.ai/projects/dispatch-modernization/registers/risks
specira [2] Threat model: anchored scales, TM-01, TM-03 app.specira.ai/projects/dispatch-modernization/artifacts/threat-model
specira [3] Decision log: ADR-6 and its monitored consequence app.specira.ai/projects/dispatch-modernization/artifacts/decision-log#adr-6
specira [4] Architecture: INT-1/INT-3 semantics, quality scenarios app.specira.ai/projects/dispatch-modernization/artifacts/architecture
specira [5] Assumption register: ASM-04 (broken; spawned RSK-05) app.specira.ai/projects/dispatch-modernization/artifacts/assumption-register#asm-04
specira [6] Journey maps: future state, portfolio app.specira.ai/projects/dispatch-modernization/artifacts/journey-maps
specira [7] User stories: US-1 row AT-5, US-3 telemetry app.specira.ai/projects/dispatch-modernization/artifacts/user-stories
specira [8] Security requirements: SR-004, SR-021; open questions app.specira.ai/projects/dispatch-modernization/artifacts/security-requirements
specira [9] Auth & authz policy: machine identity rotation app.specira.ai/projects/dispatch-modernization/artifacts/auth-authz-policy#machine
specira [10] Deployment verification: DV-5 app.specira.ai/projects/dispatch-modernization/artifacts/deployment-verification#dv-5
specira [11] FRD: FR-013 app.specira.ai/projects/dispatch-modernization/artifacts/frd#fr-013
specira [12] Performance test scenarios: PS-3 results app.specira.ai/projects/dispatch-modernization/artifacts/performance-test-scenarios#results
specira [13] Issues: ISS-2 (RSK-08 realized) app.specira.ai/projects/dispatch-modernization/issues/iss-2
Generated by Specira · template risk_register v2 (draft) · pack specira_default_delivery lineage 06f85204…94fb · page 1 of 6