# Risk Tiers

Risk tiers control planning depth and QA breadth. They do not change Authorizing User authority,
portable packet shape, optional-review policy, or QA reuse.

## Tiers

- **Tier 1 — no runtime surface.** Documentation, comments, skill prose, README content, and
  non-routing Markdown that is not itself an executable or published behavior contract.
- **Tier 2 — contained runtime surface.** Package or application code, tests, and configuration
  whose effect is contained within the repository and can be established through repository QA.
- **Tier 3 — external or durable blast radius.** Published or distributed behavior, schemas,
  migrations, security/privacy/data boundaries, licensing, registry state, or production/member
  behavior.

Classify the highest-risk touched surface, not the line count or expected ease. A public package bin
is Tier 3 even when its implementation is small. Record one tier and a short rationale in Risks /
Rules.

## Proportionate Depth

| Tier | Post depth                                                    | Typical final QA breadth                                                 |
| ---- | ------------------------------------------------------------- | ------------------------------------------------------------------------ |
| 1    | objective, proof, boundaries, repository rules                | changed-artifact validation and `git diff --check`                       |
| 2    | repository facts, runtime impacts, failure modes              | affected package checks plus warranted workspace checks                  |
| 3    | public contracts, consumers, rollback/release/data boundaries | complete relevant package baseline plus broader proof justified by reach |

The table is a selection guide, not a command list. `quality-assurance.md` remains the authority for
manifest choice, reuse, and invalidation.

## Tier Change

Any participant may raise the tier when the diff reveals a higher-risk surface. Only the Product
Owner may approve a lower tier when doing so changes the accepted risk envelope. A tier change is
material drift and returns to Post; merely choosing broader QA inside the existing tier does not.

Previously passing QA remains reusable only where it still covers the raised tier's final manifest.
Peer-review state is irrelevant to tier classification and cannot raise or lower it by itself.
