In progress GHub Creator and maintainer Open core 2026 - present

GOpenCSR / Gelhaus Open Community Services Registry

One account, one log and one place to govern, for every G Open registry.

The services the G Open registries share: one passkey account for GOpenCDR and GOpenCNR, organisations and roles, four-eyes approval at the root, councils and motions, one case system for abuse, and one public transparency log for every change.

What it is

GOpenCSR, the Gelhaus Open Community Services Registry, is the layer the G Open registries share. GOpenCDR runs a namespace and GOpenCNR runs a network. Everything both of them need to know about people, decisions and accountability lives once, here, at csr.gplatform.org.

One account

One G Open account signs you in to GOpenCDR, GOpenCNR and GOpenCSR. Sign-in uses passkeys, with a fresh passkey confirmation before anything sensitive, and GOpenCSR is the OpenID Connect provider both registries trust. People and verified organisations hold resources, with roles (owner, admin, tech, abuse and read-only) that apply to everything a holder has.

You see what you sign

A change to a name or an address is signed by its holder: in the browser with a passkey, in a signing step that shows exactly what is being signed, or from automation with an Ed25519 key registered under a passkey. The receipt for a signed change is its entry in the transparency log, with a proof that it is there.

Two people at the root

Every change by Tier 0, the root operator, needs a passkey and a second person's approval. While Tier 0 is one person, an approval made alone is flagged as decided alone.

Councils that decide

Each product has its own Registry, Community and Operators Councils, and standing earned in one product never counts in another. GOpenCSR runs the machinery they share: elections, sponsored motions, a community pool anyone signed in can suggest to, vetoes that climb from council to council, and a Joint Council that settles conflicts between products.

One case system, one log

Abuse reports about names and addresses go into one case system: the holder acts first, and Tier 0 steps in when it does not. Every registry change, every root and operator event and every governance decision goes into one append-only transparency log at csr.gplatform.org/tlog, with signed checkpoints and witnesses. The log holds identifiers and hashes, never a name, an email address or an IP address.

Privacy by default

An account needs a verified email address and nothing more. GOpenCSR sets one strictly necessary session cookie and carries no trackers, analytics or advertising.