← Stewardship & RFCs

APRF-RFC-0002 · accepted · MINOR · APRF v0.11.0

Demote incident-readiness INC-M3 and INC-M4 to recommended

Demotes INC-M3→INC-R2 and INC-M4→INC-R4; documents pre-release exception for removing IDs without deprecated stubs before the first tagged version.

Created 2026-08-01

FieldValue
Statusaccepted
Author(s)StackRail (working-draft publisher)
Created2026-08-01
SemVer impactMINOR
Index summaryDemotes INC-M3→INC-R2 and INC-M4→INC-R4; documents pre-release exception for removing IDs without deprecated stubs before the first tagged version.
ImplementsPR #14 (feat/incident-readiness-hybrid)

Problem

Two incident-readiness Checks were published as mandatory while the framework is still a pre-release working draft (0.10.0, no tagged release versions yet):

Former IDTitle (obligation)Why mandatory was too strong
INC-M3Post-incident reviews must produce tracked actions against APRF pillarsValuable learning loop, but not a production-blocking gate for Core/Regulated (was never in those profiles). Treating 100% SEV coverage as mandatory over-weights process maturity vs containment.
INC-M4Regular tabletop exercises must cover AI-specific incidentsTabletop cadence is important for Regulated maturity, but forcing it as a Tier-3 mandatory before adopters have stable playbooks/containment (INC-M1/M2) creates false fails.

Assessors and profile consumers need a clear, citable rationale for the gate change and for how IDs were remapped.

Proposal

  1. Demote the obligations from mandatory (must) to recommended (should):
  • INC-M3 → INC-R2 — post-incident reviews should produce tracked APRF-pillar actions (or explicit no-action rationale); hybrid detection via repo-post-incident-aprf-actions.
  • INC-M4 → INC-R4 — production systems should run AI-focused tabletops ≤180 days with retained owned actions; hybrid detection via repo-ai-incident-tabletop.
  1. Keep INC-M1 (playbooks) and INC-M2 (containment drill) as the incident-readiness mandatory Core gates.
  2. Update the Regulated profile: remove INC-M4 from mandatoryCheckIds (56→55; tier3-only 17→16). INC-M3 was never on Core/Regulated, so demotion does not change those counts.
  3. Rewrite sibling recommended Checks INC-R1 / INC-R3 from stubs to hybrid collectors in the same change set (editorial + measurable, not gate demotions).

Normative pass conditions remain measurable (coverage %, ages, owners, measuredAt ≤90d attest freshness).

Alternatives considered

  • Keep mandatory; soften passCondition — rejected; still fails Regulated assessments for teams with strong containment but immature tabletops/PIR process.
  • Demote in place (same IDs, change gate only) — rejected for M→R semantics clarity; recommended Checks use the *-R* namespace by convention.
  • Deprecate INC-M3/M4 stubs with replacedBy and retain files — preferred after first tagged release; see Compatibility for the intentional pre-release exception.

Compatibility

Gate / profile impact

ChangeImpact
INC-M3 removed; INC-R2 addedAdditive recommended Check; no Core/Regulated mandatory delta
INC-M4 removed; INC-R4 addedRegulated mandatories −1; recommended surface +1
Catalog sizeNet same incident-readiness Check count (M3/M4 → R2/R4)

SemVer: MINOR — profile gate set and Check IDs changed while still on working-draft 0.10.x before any tagged release.

Intentional exception — no deprecated stubs for INC-M3 / INC-M4

Per ARCHITECTURE.md / CONTRIBUTING.md, published Check IDs are normally retained as status: deprecated with replacedBy for an N−1 MINOR window.

Exception (pre-release only): APRF has not shipped any tagged release versions yet. Retaining empty deprecated mandatories would create noise for early adopters without protecting a published baseline. Therefore INC-M3 and INC-M4 YAML were removed and replaced by INC-R2 / INC-R4 rather than left as deprecated stubs.

This exception is recorded in `packages/aprf-engine/rules/_index/id-gaps.md`. After the first tagged release, future mandatory→recommended moves must use deprecate+replacedBy (or an explicit new RFC amending this exception).

Security considerations

No weakening of containment or playbook mandatories (INC-M1/M2). Demoting tabletops and post-incident APRF-action mapping reduces false Regulated fails; residual risk is delayed learning loops, mitigated by keeping both as high-severity recommended Checks with hybrid collectors.

Open questions

  • Should Regulated re-include an AI tabletop Check as mandatory once Level-5 maturity guidance is ratified?
  • After v1.0.0, should a one-time migration note in release notes list INC-M3/M4 → INC-R2/R4 for any private forks that copied pre-release IDs?

Checklist

  • Problem and affected parties
  • Proposed change stated
  • SemVer impact justified
  • Compatibility / deprecation plan (incl. intentional pre-release exception)
  • Checks remain measurable
  • Crosswalk impact noted (N/A — informative crosswalks unchanged)
  • Security / safety considered
  • Open questions listed

Comment window: 14 days from Created (working-draft quorum applies). Interim contact: see /aprf/rfc/.

Source markdown: /aprf/rfc/0002-incident-readiness-mandatory-to-recommended.md