mirror of
https://github.com/Tria-plc/edr-platform.git
synced 2026-08-26 18:42:49 +00:00
RiskStep returned early to a badge as soon as a risk level existed, so the control was unreachable and a mis-assigned level could never be corrected. Both the server and the sibling AssignRiskCard treat risk as correctable until duty is advised off it — completeWithMetadata has no already-completed guard and overwrites metadata.riskLevel. RiskStep was stricter than either. It now keeps the control mounted alongside the assigned badge, offers "Reassign risk", and locks to badge-only once DUTY_TAXES_ADVISED completes. The control also reads the persisted level (it was hardcoded to GREEN, so unhiding it alone would have misreported the assignment), and the T1 gate is skipped once a level exists, since risk cannot be assigned without a closed T1 and stale T1 data must not hide the badge. Correcting a level previously left no record of the old value, who changed it, or when — thin ground for a customer-visible level that may be disputed. assignRisk now appends each decision to metadata.riskHistory: the level, the level it replaced, the timestamp, the user id, and a display name resolved at assignment time so the trail shows a person rather than a UUID. riskLevel still carries the current value and always equals the last entry, so existing consumers are unchanged. History lives on the existing metadata JSONB column, so no migration is needed, and the logic sits in assignRisk rather than the shared completeWithMetadata that adviseDuty and others also use. Re-picking the level already in force is not recorded — it changed nothing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>