Search RPD Archives
[rpd] Updated Proposal - AfriNIC Policy Compliance Dashboard AFPUB-2026-GEN-002-DRAFT02
jordi.palet at theipv6company.com
jordi.palet at theipv6company.com
Fri Oct 2 16:09:06 UTC 2026
Hi Tshepo,
Even if the proposal requires staff verification, automatic possible lack of compliance detection will in the end, release human resources for initial verification and simplify the process.
We decided to not describe the details of the recovery decisions, because it was one of the concerns in the previous version. So the proposal is now more a simpler “framework”. We want:
As automated as possible monitoring.
Display the status of each monitored item.
Notifications.
The thresholds for manual investigation aren’t changed from what today is already doing the staff. Policy should not change that to avoid being considered to intrusive in the legal aspects for the bylaws/RSA. This version avoids precisely the complains from the analysis impact in the previous version. This is also the reason we don’t create a procedure, because it is staff/board decision, which they already must have today, even if this policy would not exist.
While I agree with the changes that you are proposing for section 4, most of them were (not exact same wording but same meaning) in the original proposal 3 years ago (as we have them in a policy proposal in LACNIC that reached consensus and was implemented several years ago) …. and they were rejected by the impacts assesement. Anyway, we will check back depending on the inputs from the new impacts assessment.
Regards,
Jordi
@jordipalet
> El 2 oct 2026, a las 14:29, Tshepo Masuku <TshepoMasuku26 at hotmail.com> escribió:
>
> Dear PDWG,
>
> Thank you for the revised proposal. DRAFT02 acknowledges the limitations of automated assessment, requires staff verification and removes the former Board-exception clause. Those changes address parts of the earlier discussion. My comment therefore does not assume that the proposal requires automatic revocation or retains the deleted exception.
>
> The remaining question is what paragraph 4 of section 3 actually changes: does it merely describe existing authority, or establish an additional policy basis for exercising enforcement powers?
>
> This distinction was already raised in the DRAFT01 legal assessment, which asked whether the proposal operationalised existing contractual rights or created additional remedies. The June meeting also recorded the contrary interpretation that the proposal operated entirely within the existing framework. Neither interpretation should simply be assumed to settle the meaning of the revised text.
>
> Paragraph 4 combines investigation and potential service withholding, revocation or membership closure in a sentence linked to evidence indicating possible non-compliance. It refers to the RSA/bylaws, but does not expressly distinguish the threshold for investigating a concern from the conditions necessary for an adverse decision.
>
> There are two separate questions here. Staff verification asks whether the information is reliable. It does not, by itself, answer whether a particular obligation applies, whether a breach has been established, or which remedy is authorised. For example, confirming that a record is incorrect does not alone determine which consequences may follow from that error.
>
> The scope question also needs an explicit answer. CPM section 3.1 distinguishes number-resource policy from general business practices and procedures, which fall outside the PDP. This does not establish that every provision affecting enforcement is outside scope. It does mean that the authors should identify which new resource-policy obligation paragraph 4 creates and which matters remain governed by separate contractual procedures.
>
> There is a related change between versions. DRAFT01 expressly required staff to define and publish a procedure; that requirement is not retained in DRAFT02’s operative wording. However, CPM section 3.2.2 already requires implementation procedures to be documented and publicly available. I am therefore not claiming that publication obligations disappear. The unanswered question is which procedure will govern dashboard-derived findings, and when members will be able to inspect it.
>
> The response that “existing instruments continue to apply” is relevant, but it should lead to an identifiable provision and procedure. Where no additional enforcement authority is intended, an explicit non-expansion clause would clarify that intention without prescribing staff workflows.
>
> I propose replacing paragraph 4 with the following:
>
> > 4. Verification and use of dashboard information
>
> The dashboard provides information for member assistance and staff verification. This section does not introduce additional substantive obligations, create new sanctions, or alter the conditions for exercising an existing remedy.
>
> An unverified dashboard indication shall not itself establish a breach. Any adverse decision relying on dashboard information shall identify the applicable obligation, the facts established, the authority for the decision and the procedure followed.
>
> Before dashboard information is used to support adverse decisions, AFRINIC shall publish the applicable notification, evidence-disclosure, response, correction and review arrangements. Existing contractual and legal protections remain applicable.
>
>
>
> This wording separates useful monitoring from the authority to impose consequences. It does not prevent legitimate investigation or excuse an established breach.
>
> Please could the authors explain whether this reflects their intended scope? Where it does not, please identify precisely which additional obligation, authority or consequence the current wording is intended to establish. A DRAFT02-specific staff explanation of that interaction would also help the community assess the revised text, rather than treating the earlier impact assessment as a determination on this version.
>
> I ask that the discussion record distinguish this question from the automation concerns already addressed, and document the response and any resulting amendment. The issue is not whether a dashboard can be useful. It is whether members and the community can determine, from the text, what legal or operational consequence the new section adds.
>
> Kind regards,
> Tshepo
>
> _______________________________________________
> RPD mailing list
> RPD at afrinic.net
> https://lists.afrinic.net/mailman/listinfo/rpd
**********************************************
IPv4 is over
Are you ready for the new Internet ?
http://www.theipv6company.com
The IPv6 Company
This electronic message contains information which may be privileged or confidential. The information is intended to be for the exclusive use of the individual(s) named above and further non-explicilty authorized disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited and will be considered a criminal offense. If you are not the intended recipient be aware that any disclosure, copying, distribution or use of the contents of this information, even if partially, including attached files, is strictly prohibited, will be considered a criminal offense, so you must reply to the original sender to inform about this communication and delete it.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.afrinic.net/pipermail/rpd/attachments/20261002/0acc4ed6/attachment-0001.html>
More information about the RPD
mailing list