Skip to main content

Risk Classification

Every mutating operation MUST declare a risk level. Risk classification drives safety requirements.

LevelDescriptionRequired Safety
noneNo risk (reads, navigation)None
lowEasily reversible (cart operations)None required, logging recommended
mediumState changes requiring attentionConfirmation recommended
highFinancial or significant data impactConfirmation MUST be required
criticalIrreversible, high-impact operationsConfirmation AND approval MUST be required

Classification Guidelines

  • Payment processinghigh
  • Account deletioncritical
  • Profile updatemedium
  • Adding bookmarklow
  • Searching productsnone

Implementations MUST NOT classify a delete action as none risk unless the deletion is trivially reversible (e.g., removing an unsaved draft).