Governance charter: shared part
The governance machinery every product of the family shares: Tier 0, standing, the councils, global motions, majorities, vetoes, the Joint Council and its election, sponsor votes, the community pool, visibility, and how the charter changes.
1. This charter and whom it binds
- There is one charter for the products of the family: this shared part, published by GOpenCSR, and a rider for each product. The shared part holds the machinery every product uses alike. A rider holds what is particular to its product: the seats of its councils, who elects them and their terms of office, who counts as its operators, what gives standing in it, and the matters only it decides.
- The shared part binds every product of the family: GOpenCDR, GOpenCNR and GOpenCSR. GOpenCDR's governance charter is GOpenCDR's rider, and the GOpenCNR charter rider is GOpenCNR's. The shared part and a product's rider together are that product's charter.
- A rider adds to the shared part and does not change it. Where the two speak to the same point, the shared part applies.
- GOpenCSR has no councils of its own. The shared services it runs are governed through the councils of the products, and its shared policies are global policies, changed by global motion.
- Tier 0 is the root operator role, held by Gelhaus Solutions. "We" in this charter is Gelhaus Solutions.
- Nothing in this charter overrides the law, a court order, or the rights holders have under their own terms. Every version is kept in the document archive.
2. Tier 0
- Role. Tier 0's root roles are shared across GOpenCDR, GOpenCNR and GOpenCSR. Tier 0 runs the services, carries out the decisions of the councils, and carries out global motions under the Joint Council's direction, answering to the Joint Council for them.
- A reserved seat in every council, and in the Joint Council. No council can remove it or change its class.
- Holding seats until people are elected. Tier 0 holds every seat of each product's elected councils, and of the Joint Council, as a block until people are elected to them. Each person elected takes one seat from the block, and a seat that stays unfilled stays with Tier 0.
- The block votes as one. A result carried by Tier 0's seats is flagged as such, whatever the motion's visibility. Tier 0 does not recuse until a majority of a council's seats is elected. From then on, on matters about Gelhaus Solutions' own resources, its block seats in that council abstain, as the council conduct code sets out.
- Four-eyes. Every change Tier 0 makes needs a passkey, and a second Tier 0 person approves it. While Tier 0 is one person, an approval made alone is flagged "decided alone", and the flag stays on the record.
- The veto. Tier 0 keeps a veto on grounds of security or law. A veto is never a vote. It applies only to motions that have been adopted, and every veto is published with its reasons, redacted only as law or security requires. It stays apart from the vetoes of councils, and Tier 0 does not decide those: the Joint Council does.
- Emergencies. Only in the cases where the general terms of service let us act first, such as an attack on our systems or on others, malware or phishing, or a binding order of a court or an authority, Tier 0 may act at once, and then it may only suspend or tighten, never loosen. An emergency measure applies at once; whoever it affects receives a statement of reasons no later than when it takes effect, unless the law forbids telling them, and is heard afterwards. It is published in the transparency log, lapses after 90 days unless it is reaffirmed and after one year at the latest, and is reviewed afterwards.
3. Standing
- Standing is what an account earns in a product by holding resources or roles there, as the product's rider defines it. It decides who may elect, stand, support a community motion and count toward a petition in that product.
- Standing never crosses products. Nothing earned in one product counts toward another product's seats, votes, candidacies, support or petitions. A GOpenCNR member's free
<member>.gnetname, and every name under it, counts toward no standing in GOpenCDR.
4. Councils
- Every product has its own councils, and each council belongs to exactly one product. Every product has the same three kinds:
- the Registry Council, for policies and directives;
- the Community Council, for new namespace, such as new TLDs and new pools;
- the Operators Council, for what is already operated, such as existing TLDs, hubs and transit, with ex officio seats for the product's operators.
- A kind of matter goes to the same kind of council in every product. Which matter goes to which council is kept as data and published with the councils.
- A council's name is always shown with its product, as in "GOpenCNR Registry Council". Two councils with the same name in two products are two councils.
- Rank. The Registry Council ranks above the Community Council, and the Community Council above the Operators Council. Rank decides how a veto climbs inside a product, and a higher council may veto any motion of a council below it.
- Seats. Every seat has a class: reserved, Tier 0 block, appointed, elected or ex officio. Its holder is a person or a verified organisation. A seat is voted by its holder or, for an organisation, by its representative, and an alternate votes it when marked to. A seat may give its proxy to another member of the council. How many seats each council has, who elects them, their terms of office, vacancies and attendance are set by the product's rider.
- Chair. Tier 0 chairs each council unless the council elects its own chair. The chair calls the council's sessions.
- Each council keeps rules of procedure, which it adopts and changes by motion within this charter.
5. Committees
- A committee belongs to one council. That council sets its mandate, its members, its chair, and a date by which it is reviewed or ends.
- A committee decides only within its mandate. Outside it, it recommends. The council remains answerable for what its committees decide.
- Conflicts between councils, and between products, go to the Joint Council, never to a committee.
6. Majorities
- Every motion, global or not, states its majority before voting, as a threshold over a base:
- the threshold: more than half, two thirds, or all;
- the base: full, meaning all seats or, for a global motion, all affected councils; or simple, meaning those taking part, which are the seats that voted or the councils that reached a decision.
- The rules set a floor for each kind of matter. A motion may ask for more than its floor, never less:
| Kind of matter | Floor | Visibility | |---|---|---| | Policy, pools, TLDs | More than half, simple | Public only | | Directive | More than half, simple | Any | | Global policy | More than half of the councils that reach a decision | Public only | | Council veto | More than half of all the council's seats | Public | | Charter | Two thirds of the votes cast in the product's Registry Council and in its Community Council, each with at least half of its seats present, after at least 30 days of public comment | Public only |
- Quorum. A council reaches a decision on a motion only if at least half of its seats able to vote take part. Without that quorum, or when its voting closes without a result, the council has reached no decision.
7. Global motions
- A global motion is one that binds more than one product. It goes to the same kind of council in every affected product, and each council decides it under its own rules. It carries a text for each product, or one text where it is a global policy.
- Sponsoring. A global motion is sponsored in any one of its deciding councils. It is fixed at that council's next session and goes on the agenda of every other deciding council's next session.
- Chairing and enacting. The Joint Council chairs every global motion from tabling to result: the agendas in every deciding council, the voting windows and the combined result. It proclaims the motion in force and directs its execution, with deadlines and instructions for each product. Tier 0 carries the motion out and answers to the Joint Council for it.
- Passing. By default a global motion passes with more than half of the councils that reached a decision; a council that reached no decision is left out of the count. A motion may open with a stricter rule: more than half of all affected councils, two thirds, or all.
- Binding. A global motion that stands, because it passed and no veto against it holds, binds every affected product, including one whose council voted no.
- After a failure. When a global motion fails or falls to a veto, any council that voted yes may table a motion for its own product alone. The Joint Council may instead propose one reconciled text for a single further vote in the same councils.
8. Vetoes
- Who may veto. Every council that decided a motion together with other councils, whatever it voted. Inside a product, also any higher council, over any motion of a council below it: the Registry Council over the Community and Operators Councils, the Community Council over the Operators Council.
- How. A veto is a motion of the council, passed by more than half of all its seats, within 7 days of the result. A motion takes effect only when every veto window on it has closed.
- Vetoes of global motions go straight to the Joint Council, which decides whether the veto holds.
- Vetoes inside a product climb the product's ladder, from the Operators Council to the Community Council to the Registry Council. Each higher council may, within 7 days of the step below it, back the veto or overturn it. A veto that a higher council backs and nobody overturns holds, and the motion falls. Nothing goes to the Joint Council until the Registry Council's stage is over. Then the Joint Council takes a veto the Registry Council cast itself, a veto that was overturned, and a veto that no higher council backed.
- The Joint Council's decision on a veto is final, unless more than half of the councils that decided the motion veto that decision within 7 days. That veto is final.
- Tier 0's veto is separate from all of these, as Article 2 sets out.
9. The Joint Council
- Purpose. The Joint Council deals only with conflicts and global motions, and passes no policy of its own. It decides:
- every veto of a global motion, and the vetoes a product's ladder hands up to it;
- disputes over whether a motion is global, which products it affects, and which kind of council decides it;
- contradicting motions of different products: which one gives way, or whether both go back;
- after a failed global motion, whether to propose one reconciled text for a single further vote.
- It chairs and enacts global motions as Article 7 sets out. The Joint Council decides by recorded vote of its seats. Each of its motions sets its majority; by default, a motion passes with more than half of all its seats.
- Seats. The Joint Council has N seats, where N is the larger of 7 and 2P + 1, and P is the number of products that have councils. The Joint Council is formed by all the products this shared part binds, GOpenCDR included; GOpenCSR has no councils, so P is 2 today. N is therefore always odd, and with one or two products it is 7. One seat is Tier 0's reserved seat, which is not elected. The others are elected.
- Candidates must hold a seat in a council of a product. Tier 0 fields no nominees.
- Until the first election, Tier 0 holds every seat. Elections are held every year. An elected seat that nobody wins stays with Tier 0 until the next yearly election.
- The election. Every seat of every council of every product casts one ballot. Ballots are counted by weighted single transferable vote: a group of ballots holding more than 1 / (elected seats + 1) of the total weight elects one member.
- Ballot weight. Each council's ballots together carry a weight made of three equal thirds, and the council's weight is shared evenly by its seats:
- one third by product, split evenly between the products, and within a product evenly between its councils;
- one third by council, split evenly between councils, where a product counts at most 3 councils, shared between all of its councils if it has more;
- one third by seat, split by the number of seats, where a council counts at most 7 seats and a product's seats count at most 21 in all, scaled down evenly if they would add up to more.
As a formula, for council c of product p:
W(c) = (1/3)(1/P)(1/k_p)
+ (1/3)(min(k_p, 3) / k_p) / sum over all products q of min(k_q, 3)
+ (1/3)(m_c / sum of m over all councils)where P is the number of products, k_p the number of councils of product p, and m_c = min(seats of c, 7), with a product's m values scaled down evenly so that they add up to at most 21. A larger council or an extra council therefore weighs no more than a standard one.
- Worked example, as today. GOpenCDR and GOpenCNR, each with councils of 7, 7 and 2 seats:
- product third: 1/3 × 1/2 × 1/3 = 5.56% for each council;
- council third: 1/3 × 1/6 = 5.56% for each council;
- seat third: 1/3 × 7/32 = 7.29% for a council of 7 seats, 1/3 × 2/32 = 2.08% for a council of 2;
- in all: 18.4% for each council of 7 seats (2.63% per seat), 13.2% for each Operators Council of 2 seats (6.60% per seat), and 50% for each product.
With 6 elected seats, the quota is 1/7 = 14.3%, so the ballots of one 7-seat council alone can elect one member. With five products of three 7-seat councils each, every ballot weighs the same, each product 20% and each council 6.7%. A product with a fourth council of 74 seats still weighs 50% against a standard product, and that council 12.5%, like each of its siblings.
- Its decisions are final, unless more than half of the councils that decided the motion concerned veto the decision within 7 days. That veto is final.
10. Sponsor votes
- A motion is tabled on sponsor votes, counted per seat, not per person. One person or holder voting two seats gives two sponsor votes. A seat sponsors through whoever votes it: its representative, or its alternate when marked to. Proxies do not sponsor.
- The minimum is one sponsor vote unless a council raises it by motion in its rules of procedure. A change of the minimum applies to motions not yet fully sponsored.
- Secrecy. Who sponsored a motion stays confidential, at every minimum and from Tier 0 too, until the council's next session starts. Until then, any sponsor may withdraw, and a sponsor who withdraws is never revealed.
- Fixed at the session. A fully sponsored motion is fixed when the council's next session starts, however long that takes. It is then tabled, its sponsors are published and can no longer withdraw, and it goes on to public comment and voting as its kind of matter requires.
- Tier 0's block sponsors with every block seat, like any holder with several seats, under the same secrecy. It can meet any minimum alone.
- Revisions. A sponsor vote binds to the revision of the motion it was given for. A new revision keeps only the sponsor votes given for it; the others are released without notice. Once a motion is tabled, it changes only through amendments, which are motions of their own.
11. Stages, the community pool and petitions
- Every motion is at one of four stages: community (no sponsor vote), partially sponsored (at least one sponsor vote, below the minimum), fully sponsored (minimum reached, waiting for the session), and tabled.
- Community motions. Anyone signed in may suggest a motion to a council. A suggestion, and a motion that has lost its last sponsor, even its drafter's own, sits in that council's community pool.
- Support. Accounts may support a community motion, and support counts only from accounts with standing in the council's product. The number of supporters is public. Their names are not published.
- Petitions. A community motion whose support reaches the petition threshold, 25 accounts with standing or 3 operators of that product, gains one sponsor vote, never more. Where the council's minimum is higher, seats of the council must add the rest. The petition's sponsor vote can fall away, like any sponsor's, until the session fixes the motion.
- Partially sponsored motions are public by default, like every stage. A motion that loses its last sponsor goes back to the pool at once. A motion that stays short of the minimum for 90 days has its sponsor votes released without notice and goes back to the pool.
- A community motion with no sponsor and no new support for 6 months is archived. Nothing in the pool is ever deleted.
12. Visibility
- That a motion exists is always public, at every stage and in every state.
- Every motion has one of three states:
- Public: everything is public.
- Public with confidential votes: the text, the sponsors, the comments, the tallies and the result are public; each seat's vote is sealed for good, with its hash in the transparency log. A result carried by Tier 0's seats is still flagged.
- Confidential: the public sees that the motion exists, its council, its dates, and its result where that is allowed. Members of the council and Tier 0 see the rest.
- Sponsorship setting. Separately from its state, a motion shows the public its stage and its number of sponsor votes (the default), its stage only, or nothing beyond its existence. Sponsors' names never show before the session.
- Who chooses. The drafter chooses the state and the sponsorship setting, within the floor for the kind of matter in the table in Article 6. Policy, the charter, pools, TLDs and global policy are always public. A confidential motion names its reason (security, a legal matter, personal data, or a contract) and is reviewed for release every year.
- Once a motion is tabled, the council may make it more open by majority, never less open. Suggestions from the public are always public, and a motion that falls back to the pool keeps its state.
13. Policies and the fence
- A policy is one kind of document for every scope: numbered clauses, each binding or guidance, some of them enforced by the software.
- Scopes. Policies exist at these scopes: global, set by the councils; Tier 0's operations; and each organisation. Each rider adds the scopes particular to its product.
- Floors only. A lower scope may be stricter than a higher one, never looser.
- An exception to a policy is granted by motion of the council that owns the policy, is published, and lasts at most two years, renewable the same way.
- The fence. Global policy may never impose prices, removal terms or content rules on a product's operators. An operator, or a scope, may opt into more.
14. Sessions and records
- Agendas and minutes of sessions are published, within what each motion's state allows.
- Votes are recorded seat by seat. Each ballot records the seat, the person and the capacity in which they vote, including a ballot cast on a holder's instruction. Ballots are sealed until voting closes, the hash of each ballot is written to the transparency log, and a ballot may be changed until the close. Votes are published once voting closes, unless the motion's votes are confidential.
- Ballots in elections are secret.
- Public for good. Seats held, recorded votes, tabled motions, sponsors once published, and public comments stay public for good. A comment removed under the GOpenCSR terms stays removed, and votes sealed under a motion whose votes are confidential stay sealed.
- Everything is on the record. Motions, sponsors at the session, the hashes of ballots, results, vetoes, the Joint Council's decisions and directions, seat changes and emergency measures are recorded in the transparency log, which holds identifiers and hashes only and from which no entry can be removed.
15. Changing this charter
- The shared part changes only when every affected product adopts the change under its own charter-change rule. Under this shared part, that rule is: two thirds of the votes cast in the product's Registry Council and in its Community Council, each with at least half of its seats present, after at least 30 days of public comment.
- A rider changes by its product alone, under that same rule.
- Tier 0's reserved seat in each council and in the Joint Council cannot be removed.
16. Conduct
Every council member, alternate and committee member, and Tier 0, is bound by the council conduct code: its duties, its declarations of interest and its rules on recusal.