Risks
Owner: Project Manager
Reviewers: Engineering, QA, Security
Status: Draft
Version: 0.1
Last Updated: 2026-09-16
Review Cycle: Per release
| Risk | Impact | Likelihood | Mitigation | Status |
|---|---|---|---|---|
| Temporary auth scope bypasses allow data exposure if shipped. | High | Medium | Remove bypasses and add permission regression tests. | OPEN |
| PRD features marked planned may be mistaken for shipped. | Medium | Medium | Keep status labels in PRD and requirements docs. | OPEN |
| IoT command timeout alerting is incomplete. | Medium | Medium | Add alert creation and operational tests. | OPEN |
| Scheduled report automation is planned but not implemented. | Medium | Medium | Gate release notes and UAT around actual report behavior. | OPEN |
| Production monitoring/backup targets are not confirmed. | High | Medium | Define SLO, RPO, RTO and provider choices. | OPEN |
| AI features lack implementation and safety/citation criteria. | Medium | Medium | Complete handbook reference design before AI release. | OPEN |