Summary

  • NRS's role in this subject is advocacy, research, campaigning, convening and authorized member representation. The operational acts belong to RIRs, IANA numbering services, courts, qualified successor operators and resource holders; citing an NRS position is neither evidence that NRS performs them nor an endorsement by BTW.
  • The registry operator should measure legitimacy by whether a resource holder can leave safely, not by retention figures that may conceal switching costs, data dependence or monopoly recognition.
  • A valid exit preserves the holder and the resources while changing the appointed registration provider. It is different from surrender, sale, a routing change, a corporate transfer or abandonment of recognized authority.
  • The losing provider must deliver complete portable records, disclose dependencies, cooperate with a bounded cutover and then lose every present power that arose solely from the service appointment.
  • Security, debt, fraud concerns and court orders require narrow, evidenced and reviewable treatment. They should travel as structured restrictions where appropriate rather than freezing an entire portfolio indefinitely.
  • Competition continues after departure only if receiving providers can qualify under open, objective rules and if common interfaces prevent the incumbent institution from turning interoperability into a closed club.
  • Exit improves voice rather than replacing it: boards and staff must persuade members when members can change providers without risking the integrity of their number-resource records.
  • The registry operator deserves positive institutional consideration precisely because it can make itself contestable. Its strongest claim would be a verified ability to surrender customers, data custody and service authority while the shared record remains accurate and continuous.

The role boundary is part of the evidence

NRS's own stated positioning supplies the first boundary for this analysis. It is a membership and advocacy organization pressing for decentralization, exit, portability, redundancy and fewer discretionary choke points. Heng Lu's note on why NRS exists says directly that NRS does not sell products or implement commercial solutions; its role is to change the direction of governance. NRS may therefore publish research, organize campaigns, convene affected operators, support members and represent an organization that has granted it authority. It may not turn that representation into registry authority over anyone else.

The implementation layer is separate. RIRs, IANA numbering services, courts, qualified successor operators and resource holders remain responsible for any authoritative registry record, allocation, transfer recognition, RPKI or RDAP operation, technical failover, binding review, insolvency act or legally compelled remedy relevant to this article. The NRO coordinates the five RIRs; it is not another name for NRS. IANA numbering services perform their defined coordination role; they are not an NRS department. Courts and lawful public authorities retain the powers their legal systems actually give them.

BTW's role is separate again. BTW reports the observable structure, checks primary sources and labels proposals as proposals. It does not convert NRS advocacy into fact, campaign on NRS's behalf or infer authority from alignment. That reality-not-advocacy discipline is why the institutional nouns in this article matter: a recommendation from NRS, an act by an RIR and an order from a court are three different things.

The institution proves itself at the moment of departure

The easy test of a registry is whether it can accept a customer. The harder test is whether it can release one. Entry brings fees, information and institutional reach. Exit removes them. Entry aligns the interests of the provider and applicant; exit exposes the point at which those interests separate. That is why departure reveals more about the limits of power than a membership brochure or satisfaction survey.

An incumbent may sincerely believe that retention demonstrates quality. It may also benefit from technical and procedural dependencies that make comparison impossible. If account history cannot be exported, if contact evidence is intelligible only to incumbent staff, if hosted security services cannot move, or if no receiving provider can gain recognition, the holder's continued presence says little about preference. The institution is measuring endurance under dependence.

Exit-based governance changes the burden of proof. The registry does not ask the customer to establish institutional failure before leaving. It asks the provider to show that any restriction is necessary, specific, temporary and reviewable. The default is that a competent holder may appoint a different qualified custodian while the common authority record remains coherent.

The decisive event is not cancellation. It is controlled loss of power. The former provider ceases to authenticate current instructions, charge for ended services, alter the live record, hold active credentials, represent itself as appointed custodian or use retained data for unrelated leverage. If those powers survive, the customer has not fully left.

For the registry operator, a clean departure would demonstrate that the common institution is more durable than any one service relationship. It would show that uniqueness, evidence and continuity belong to the shared settlement rather than to an incumbent's customer captivity. That is a more credible foundation for trust than a claim that nobody has chosen, or managed, to leave.

Exit is an accountability mechanism, not a mood

Albert Hirschman's distinction among exit, voice and loyalty remains useful because it treats departure and participation as different responses to institutional decline. The lesson is not that every dissatisfied member should leave. It is that the possibility of exit changes how an institution hears voice. A complaint backed only by patience can be absorbed. A complaint backed by a safe alternative changes the cost of indifference.

In Internet number registration, the alternative must be carefully bounded. A resource holder cannot create a second conflicting authority simply because it dislikes a decision. Nor can a registry service operator provider erase a lawful restriction at the border of its service. The exit mechanism must preserve the facts that other networks, registries and relying parties need to interpret the holder's authority.

That constraint makes exit harder but also more valuable. The registry operator has to separate the portable customer relationship from the common rules needed to prevent duplicate claims. It must identify which services are provider-specific, which facts are shared, which restrictions survive a provider change and which powers disappear with appointment. These distinctions force an institution to explain itself.

Exit therefore becomes an accountability mechanism only when it is executable. A declaration of freedom without a receiving provider, common data format, cutover rule, clock or remedy is symbolic. It may improve legal argument after a failure, but it does not discipline ordinary service decisions before failure.

The registry operator should treat exit capability as infrastructure. It belongs beside identity assurance, record integrity, security and continuity. The registry operator should publish its performance, test difficult cases and impose consequences when a provider obstructs departure. Exit then becomes neither threat nor sentiment. It becomes a routine constraint on concentrated administrative power.

A real exit changes the provider, not the holder or the resource

The word "exit" is dangerously elastic. A holder may leave an association by resigning, leave a market by selling, leave a service by surrendering resources or leave a network by ceasing to announce routes. None necessarily proves registration-service portability.

A valid registry-operator exit holds three elements constant. The recognized holder remains the same legal or natural person. The number resources remain within the portfolio except where the holder separately authorizes a transfer. The authoritative public history remains continuous. The changed element is the provider appointed to administer current registration service and selected dependencies.

This definition excludes false substitutes. Surrender returns authority and destroys the customer's continuing interest. A sale changes the holder. A merger may change legal identity. A sponsorship arrangement may insert an intermediary without giving the holder an independent right to choose. A routing change affects reachability but does not necessarily alter registration. An internal account migration may change software while leaving institutional control untouched.

The distinction protects both sides. Holders cannot use provider exit to evade a verified court restriction, erase history or manufacture title. Providers cannot say that a customer is free to leave because it may abandon the resources that made the service valuable. The right concerns continuity of recognized authority under a different custodian.

Every exit record should therefore answer four questions: who is the continuing holder, which resources remain in scope, what provider appointment ends, and what provider appointment begins? Additional events may occur at the same time, but they should be separately authorized and evidenced. Combining them into one ambiguous departure creates opportunity for both fraud and obstruction.

Safe exit requires one current authority

Portability is sometimes criticized as a threat to registry uniqueness. That objection is valid if portability means simultaneous competing records. It is not valid if the registry operator defines a single cutover event and a common chronology.

Before cutover, the losing provider remains responsible for current service within strict limits. The receiving provider prepares but cannot issue effective instructions as if appointment were complete. At cutover, the common coordination layer records one atomic change in provider authority. After cutover, the receiving provider becomes current, while the former provider retains only the historic and protective duties expressly assigned to it.

The shared record should expose current appointment and preserve prior appointments as history. It should also distinguish the event's effective time from later distribution through caches, mirrors or relying systems. A delayed observer may temporarily see older information, but it should never receive two equally valid current answers from the registry operator.

If one resource in a portfolio cannot move, clean resources should not be trapped automatically. The holder can authorize batches, each with its own atomic change. A disputed resource remains with its existing provider and restriction while undisputed resources proceed. This reduces the value of strategic objections and limits operational blast radius.

The one-authority rule is what makes exit compatible with coordination. The registry operator is not licensing private forks. It is providing a neutral method for changing the service custodian reflected in a common record. The incumbent's loss is real, but public certainty remains intact.

Data export is the first surrender of institutional advantage

The losing provider normally knows more than the customer can see. It holds account events, earlier contact evidence, service dependencies, support decisions, restrictions, billing states, signatures and staff interpretations. If the export contains only the current public record, the receiving provider inherits a shell while the incumbent retains the information needed to operate safely.

The registry operator should define a minimum portable record that allows independent reconstruction. It should include resource scope, holder identity and authority evidence, current and historic contacts, provider appointments, relevant event history, active restrictions, pending requests, service dependencies, billing obligations that lawfully survive, review outcomes, integrity proofs and the provenance needed to assess each assertion. Protected information can move through controlled custody, but its sensitivity cannot justify omission from the handoff.

The export must be semantic, not merely voluminous. A machine-readable archive with undocumented local codes is not portable. Every field needs a stable meaning, issuer, time, version and permitted use. The receiving provider should be able to determine what is current, what is disputed, what has expired and what requires independent verification without calling the incumbent for oral interpretation.

The European Union's Data Act supplies a useful adjacent principle for data-processing services: customer switching depends on identifying exportable data and preventing contractual, commercial, technical and organisational obstacles. Internet number registration is a different service and needs stricter authority controls, but the governance lesson travels. Data held to serve a customer should not become a proprietary barrier to changing the custodian.

Export also needs deletion and retention rules. The former provider may retain evidence required by law, audit, security or dispute preservation. It should not retain active operational copies indefinitely or repurpose protected records because the customer has left. A retention schedule, legal basis and destruction evidence turn loss of data custody into a verifiable event.

The losing provider must actually lose authority

An institution can deliver an export while preserving practical control. It may keep active account credentials, remain listed as the point of contact, continue signing dependent entities, receive notices before the new provider or retain an exclusive ability to correct historical records. The customer appears to have moved while the old centre of power remains.

The registry operator should maintain a provider-authority inventory for every service. At cutover, each power is transferred, terminated or deliberately retained under a named legal basis. The list includes the ability to submit current changes, authenticate representatives, manage selected reverse-DNS delegations, operate hosted RPKI functions, receive security notices, view protected evidence, charge recurring fees, raise objections and represent the holder to other coordinating institutions.

Retained power should be exceptional. Historic evidence custody does not authorize current instructions. A surviving debt claim does not authorize record control. A preservation duty does not permit customer profiling. A narrow court hold on one resource does not preserve authority over an entire portfolio. The registry operator's default should be that service powers end with the appointment from which they arose.

The holder needs a closure statement listing ended powers and surviving duties. The receiving provider and common coordination service should receive the same version. If the former provider later acts under a surviving duty, the event must cite that duty and be visible to authorized reviewers.

This is where institutional seriousness becomes measurable. Many organisations favour customer choice in principle but resist the concrete loss of credentials, data, revenue and discretion. The registry operator becomes credible only when it engineers that loss deliberately and can prove it occurred.

Competition must continue after the first successful exit

One demonstration does not create a competitive environment. A future registry operator could advertise portability while allowing only one receiving provider, setting qualification costs that exclude challengers or letting incumbents vote on competitors. Exit would become a managed exception rather than a standing market constraint.

Receiving-provider qualification should be open, objective and proportionate. Applicants need to show identity assurance, security, record integrity, financial resilience, continuity capacity, independent audit and the ability to exchange common records. They should not need political sponsorship from an incumbent or conformity with business choices unrelated to safe registration.

Testing criteria and failure evidence should be public enough for a competent applicant to prepare. Multiple assessors can reduce dependence on one gatekeeper. Rejected applicants need reasons, cure paths and independent review. Qualification decisions should disclose conflicts when existing providers have commercial interests in the outcome.

Competition also requires comparable service information. Customers should see prices, support commitments, export performance, security incidents, continuity tests, complaints, compensation and prior obstruction findings. A provider should be free to offer better service around a common authoritative core, but it should not obscure the boundary between mandatory coordination and optional products.

The registry operator must remain contestable too. If the registry operator controls qualification, common standards and dispute review, its own scope needs limits and challenge. Providers should be able to propose compatible alternatives, appeal discriminatory conformance decisions and leave the common service under a safe succession arrangement. An exit institution that cannot itself be succeeded eventually recreates the power it was designed to discipline.

Switching examples show that continuity can travel

Internet number registration has distinctive security and uniqueness requirements, so analogies should not be mistaken for direct precedents. They are still useful evidence that service continuity and provider loss can be designed together.

Ofcom's mobile switching guidance describes a customer keeping a telephone number while moving service, with an authorization code, a normal one-working-day target and compensation where the switch is delayed or abused. The telephone number is not an IP address, and the legal setting is different. The useful point is institutional: a provider can lose a customer while the customer's operational identifier continues.

The EU Data Act requires contractual switching terms for covered data-processing services, identifies exportable data and imposes a maximum transitional period subject to stated conditions. Again, cloud service is not number registration. The comparison demonstrates that lawmakers increasingly treat data extraction, service continuity and reduction of switching barriers as enforceable parts of competition rather than optional courtesy.

ICANN's Emergency Back-End Registry Operator programme provides another bounded lesson. It preserves five critical domain-registry functions when a generic top-level domain operator is at risk of failure, using prepared providers and registry data escrow. It does not offer the customer-level registry-operator exit proposed here, but it shows that continuity can be separated from the survival of one operator.

These examples do not prove that registry-service portability will be simple. They refute a weaker claim: that critical identifiers, protected records or complex technical services inherently require permanent dependence on one provider. Design, law and tested transition can preserve continuity while institutional control changes.

Exit and voice reinforce each other

Critics sometimes frame exit as a market substitute for democratic participation. That would be a mistake. A registry operator governing authoritative records still needs member voice, transparent rulemaking, accountable boards, reasoned decisions and public-interest safeguards. Exit does not decide every collective question.

Its value is that it changes the conditions under which voice operates. A board hearing complaints about service delay knows members can move. Staff proposing a proprietary extension must explain how records will travel. A provider seeking higher fees must compete on visible performance. Members who lose a vote do not automatically lose their ability to choose the custodian administering their records.

Exit also protects dissent from becoming existential. In a captive institution, every disputed election or policy may feel like a struggle for total control because the losing side must continue under the winner. Provider choice reduces the prize attached to office. Common rules still bind where uniqueness requires them, but optional service choices remain contestable.

The relationship runs both ways. Voice protects exit from abuse. Members must set common qualification criteria, define the portable record, oversee continuity reserves and prevent dominant providers from weakening competitors. Public deliberation identifies discrimination or security risks that individual switching decisions may not reveal.

A healthy registry operator therefore avoids a false choice. Voice governs the narrow common layer; exit disciplines service providers and the expansion of that layer. Loyalty can then become meaningful because staying reflects preference and shared purpose rather than fear of losing recognized authority.

Membership statistics need an exit denominator

An institution can publish membership growth while concealing how many customers attempted to leave, how long departure took or how many abandoned their requests. Gross retention is a weak legitimacy measure when switching is difficult.

The registry reporting should show entry, voluntary exit, forced exit, completed provider changes, withdrawn requests and unresolved cases. It should distinguish a customer who chose another provider from one that surrendered resources, merged, ceased operation or was removed for cause. Median and maximum completion time should be accompanied by the distribution of pauses and objections.

The most revealing ratio is not churn alone. It is successful exit among valid requests, adjusted for security and legal complications. A low departure rate with fast, clean tests may show satisfaction. A low rate with no tested pathway may show lock-in. A high rate may reveal poor service, successful competition or a new provider with a better offer. Numbers require reasons.

Post-exit evidence matters too. The registry operator should track record defects, dependent-service interruption, duplicate authority, unauthorized residual access, complaints and compensation during a defined aftercare period. A migration counted as complete on cutover day may fail the following week when a notice goes to the former provider or a retained credential is used.

Publication should protect customer security and commercial confidentiality. Aggregation can still expose provider performance, recurring failure categories and institutional trends. A registry willing to be judged by departures gains evidence that retention alone cannot provide.

Price can turn formal freedom into captivity

A customer may possess a legal right to leave and still face an exit bill larger than the value of changing providers. Termination fees, export charges, manual review costs, forfeited reserves and mandatory professional services can make a nominal right unusable.

The registry operator should separate legitimate transition costs from lost future revenue. A provider may charge a transparent, cost-based amount for exceptional customer-specific work not already covered by ordinary fees. It should not charge for producing the standard portable record, ending credentials, issuing routine closure evidence or cooperating with the common cutover. Those capabilities are part of qualified service.

Charges should be disclosed before entry and comparable across providers. Any amount above a published threshold needs an itemized estimate, the customer's approval and an appeal route. The provider cannot suspend a safe handoff merely because a customer disputes the excess portion; undisputed accrued fees and the challenged exit charge should be treated separately.

Small holders need special attention. A fixed compliance cost can be trivial for a global carrier and prohibitive for a community network or small Internet service provider. Standard automation and pooled assistance can lower cost without reducing identity or security assurance. Proportionality should change the complexity of the evidence, not whether the right exists.

Registry financing should also avoid dependence on captive revenue. Continuity reserves, qualification fees and common-service dues need transparent purposes. If the registry operator can fund itself only when customers cannot leave, its governance incentives are already misaligned.

Security must constrain the method, not erase the right

Portability creates a valuable attack surface. A criminal who captures a holder's identity could move registration service, alter contacts and gain access to dependent functions. Strong authentication and staged confirmation are essential.

Security should define the assurance needed for a given portfolio. High-impact resources may require multiple authorized representatives, protected-channel confirmation, corporate authority evidence, cooling periods for recent credential changes and independent review. Lower-risk portfolios may use simpler controls. Every factor should support a stated proposition rather than accumulate as unexplained friction.

A failed check must lead to a cure path. The holder should learn whether the problem concerns identity, representative authority, resource scope, signature, contact integrity or a specific inconsistency, subject to limits needed to avoid teaching an attacker. The provider should continue separable work while the affected check is resolved.

The losing provider should not control the final security judgment alone. It has information, but also a commercial conflict. A neutral reviewer can examine protected evidence and decide whether the assurance threshold is met. The receiving provider has duties as well: it must not accept weak evidence merely to win the customer.

Security events after a request need precise timing. A late contact change, suspicious login or newly discovered compromise may justify a pause. The evidence should show why it affects the requested move and when review will end. Security becomes credible when it is narrow and auditable, not when the word itself stops all clocks.

Debt and commercial disputes should not control the record

Providers need effective ways to collect lawful fees. Holders should not be able to consume service and escape payment by changing providers. But using authoritative record control as general debt security gives the registrar power far beyond the value of the disputed service.

The registry operator should distinguish undisputed current charges, disputed charges, exit-specific costs and unrelated contractual claims. The holder can be required to pay or secure an undisputed amount. A disputed amount can move to ordinary adjudication, escrow or a bounded review. The provider should not retain the entire resource portfolio unless the service contract and applicable law clearly create that remedy and an independent decision confirms it.

This separation protects the integrity of the record. Public registration should state current authority, not serve as a pressure device in a disagreement about consulting fees or an optional product. If the provider can keep control until every commercial claim is resolved, it can manufacture captivity through broad invoices.

The same principle applies to data. A provider may retain evidence needed to pursue a claim. It should not withhold the standard export or active credentials that must move. The receiving provider can be informed of a surviving obligation without inheriting the role of debt collector.

The test is proportionality. Does the asserted claim justify the exact registration restriction imposed, for the exact resources affected, during a defined period? If not, ordinary legal remedies should carry the dispute while the customer leaves.

Court orders must travel with their limits intact

A provider change cannot nullify a lawful court order. If a competent court freezes a resource, preserves evidence or restricts changes, the receiving provider must know and comply to the extent legally required. Otherwise, exit could become a route around public authority.

The opposite risk is equally serious. An incumbent may describe a broad dispute or legal letter as a complete bar to departure, even when the order concerns one resource, one transaction or one jurisdiction. The customer remains trapped because no one tests scope.

The registry operator should encode restrictions as structured, reviewable records. The handoff package should identify the issuing authority, operative requirement, affected resources, effective period, review status and disclosure limits. Protected documents can move through sealed custody. The common public view need reveal only that a restriction exists where publication is lawful and necessary.

The receiving provider should accept the restriction without accepting the incumbent's private interpretation as final. If scope is contested, a neutral legal reviewer or the issuing court should decide. Clean resources proceed. The former provider retains evidence but loses unrelated service authority.

Cross-border cases require special care. A provider cannot promise that every order will be recognized everywhere, nor should it assume foreign orders are irrelevant. The registry operator needs conflict-of-law procedures, emergency preservation and a route to judicial clarification. Portability should preserve the problem accurately, not pretend it has solved the merits.

Critical networks need earlier exit, not permanent captivity

Public-sector, health, financial and essential-service networks may appear too important to move. Their dependency makes a failed transition dangerous. It also makes permanent reliance on one weakening provider dangerous.

Critical holders should maintain tested continuity profiles before distress. The profile identifies authorized representatives, essential contacts, RPKI and reverse-DNS choices, notification paths, maintenance constraints, public-law duties and acceptable cutover windows. A receiving provider can prepare against this record without gaining premature authority.

Higher assurance may justify longer preparation, independent observation and staged resource batches. It should not justify an undefined incumbent veto. If the current provider is failing, compromised or subject to disruptive litigation, delay may be the greater risk. The registry operator needs power to accelerate protected handoff under evidence-based emergency conditions.

ICANN's EBERO model illustrates the value of prequalified continuity providers for critical domain-registry functions. The registry operator should adapt the principle without copying the institutional form: prepare successors before failure, define the minimum service to preserve, maintain usable records and separate emergency custody from permanent ownership.

Public procurement can reinforce readiness. Governments and critical operators should require portable records, named dependencies, tested exit and continuity evidence when selecting a registry service operator provider. They should not assume institutional reputation will substitute for a departure plan.

Dependent services must be visible and separable

Registration service is often bundled with other capabilities. A provider may manage reverse DNS, host RPKI functions, maintain routing-registry entries, receive abuse contacts, monitor resources or administer delegated users. A customer can move the base appointment and still suffer interruption because nobody identified what else depended on the incumbent.

Every registry-service provider should maintain a customer-visible dependency inventory. For each service, it states whether the service must move with registration, may remain under a separate contract, can end safely or requires coordination with an external institution. The holder selects an outcome before cutover.

The inventory should distinguish authority from convenience. A monitoring dashboard may be useful but irrelevant to authoritative state. A hosted RPKI arrangement may require a carefully sequenced change. Reverse-DNS administration may remain temporarily with the former provider if the service is separately authorized. Abuse contacts need continuity even when other optional services end.

Bundling should never be invisible leverage. Providers can offer integrated products, but contracts and exports must make the components separable. Prices for continued optional services should be stated without penalizing the customer for moving registration.

After cutover, each dependency needs an observed result: moved, continued, ended or unaffected. Silence is not evidence. The holder and both providers should receive a closure record, while independent checks confirm selected public effects where possible.

Escrow is necessary evidence but not an exit system

Data escrow protects against loss of records. ICANN's Registrar Data Escrow Program requires covered registrars to deposit specified registration data with approved custodians. That is valuable continuity infrastructure.

An escrow deposit does not by itself authenticate a holder's departure request, resolve a disputed restriction, qualify a receiving provider, identify dependent services or execute a cutover. A backup can be complete while no institution has authority to use it for routine switching. It can also be syntactically valid while difficult for a successor to interpret.

The registry operator should connect escrow to tested release conditions and semantic reconstruction. Deposits need validation, versioning and periodic exercises in which an independent party rebuilds the state needed for service. Release authority should be separated from the incumbent, with safeguards against premature access.

Routine exit should normally use a current export rather than emergency escrow. The escrow copy exists when the provider cannot or will not cooperate. Differences between the two should be reconciled, and the event record should show which source supported each fact.

Treating escrow as one component prevents false confidence. The registry operator's credibility rests on the complete handoff: evidence, authority, provider qualification, dependency treatment, cutover and remedy. A stored archive is essential, but departure occurs only when power changes safely.

Exit performance should affect permission to serve

Compensation alone may turn obstruction into a priced business choice. A wealthy provider could pay small amounts while preserving the strategic value of captivity. Repeated exit failure must affect qualification.

The first material failure should trigger independent diagnosis, a funded correction plan and a retest within a short period. New-customer growth may be limited where the defect indicates that more customers would deepen continuity risk. Existing customers should receive notice that does not expose security details.

Repeated or severe failure should escalate. The registry operator can require supervised departures, a larger continuity reserve, independent administration of exports or suspension of new appointments. Persistent inability or refusal to release customers should lead to loss of provider status through a controlled succession plan.

Consequences must distinguish provider fault from external events. A receiving provider may be unready; a court may issue a new order; a public repository may update late. The assessor should attribute each delay and publish the reasoning. Fair attribution protects providers while preventing vague references to complexity from excusing obstruction.

The central metric is holder outcome, not institutional activity. Meetings, tickets and document volume do not compensate for a customer that remains unable to leave. Permission to serve should depend partly on observed capacity to surrender service.

A routine departure should look deliberately uneventful

Consider a medium-sized network operator with IPv4, IPv6 and an autonomous system number under one registry-service provider. It chooses a competitor because support has declined and the competitor offers better dependency reporting. The holder is not selling resources, changing corporate identity or altering routing at the same time.

The request identifies the resources, receiving provider and desired window. The losing provider acknowledges it, verifies authority under published controls and returns a complete portfolio plus active restrictions and dependencies. One outdated contact requires a recovery check but does not stop export of unrelated history.

The holder decides to move registration and abuse contacts, keep reverse-DNS administration under a temporary separate contract and move hosted RPKI service after registration cutover. The receiving provider reconstructs the portfolio, identifies one semantic defect and receives a corrected delta. No valid debt or court restriction exists.

At the agreed event, the common record changes the provider appointment once. The losing provider's current credentials end. The receiving provider can act. The public state converges, notices reach the correct contacts and the planned dependent services behave as selected. Closure evidence identifies retained historic records and their destruction schedule.

Nothing dramatic happens to routing because the holder did not request a routing change. Users should not notice the institutional event. That uneventfulness is the achievement. A registry worth leaving makes the loss of one provider relationship ordinary enough that the wider network need not absorb the conflict.

The strongest objections improve the design

The first objection is fraud. Portability may create a path for resource theft. The answer is not captivity but stronger common authentication, independent review, staged authority and rapid reversal for proven compromise. An incumbent monopoly is also a security risk when its credentials fail.

The second objection is cost. Multiple providers, common interfaces, testing and continuity reserves are expensive. The relevant comparison is not with a costless present. It is with the expense of opaque delay, provider collapse, litigation, corrupted records and customer dependence. Standardization can reduce repeated bilateral work.

The third objection is fragmentation. Competing providers may produce inconsistent records. That risk justifies one common authority event, conformance testing and traceable history. It does not justify one permanent service provider.

The fourth objection is opportunism. Holders may switch to evade policy or shop for weak verification. Common minimum rules and portable restrictions answer this. Providers compete on service, not on manufacturing contradictory authority.

The fifth objection is institutional weakness. Easy departure could reduce registry-operator revenue and solidarity. If solidarity depends on the inability to leave, it is already weak. The registry operator should earn common funding through clearly valuable coordination and charge for it transparently, while optional service remains contestable.

An exit constitution needs explicit limits

The registry operator's foundational rules should state that a qualified holder may change registration provider without surrendering or transferring the resources. They should define the narrow grounds for pause, the maximum stages, the independent reviewer and the remedies for obstruction.

The rules should also prohibit several forms of self-protection. A provider may not condition export on the customer's reasons for leaving, impose unpublished termination charges, withhold clean resources because another is disputed, retain active credentials after cutover or use optional services to block the base appointment. The registry operator may not let incumbents exclude a qualified competitor without reasoned independent review.

Amendments that increase exit cost should face a higher threshold. Every proposal should state effects on data portability, provider choice, transition time, fees, continuity and successor access. Cumulative effects matter: several modest dependencies can create practical captivity.

Emergency powers need expiry and review. A security incident may justify temporarily slowing departures, but the registry operator must state scope, evidence and an end date. A crisis should not become the permanent basis for central control.

These constitutional limits are not anti-institutional. They identify the conditions under which members can trust a shared authority service without granting indefinite control to its current administrators.

A public exit ledger would change institutional incentives

The registry operator should publish a privacy-protective record of provider changes and performance. Each entry can show broad portfolio class, request and completion dates, pause categories, objections, dependent-service outcomes, compensation and review result without exposing resource identifiers or authentication evidence.

The record would allow members to see whether providers release customers as readily as they accept them. Auditors could detect patterns: repeated late exports, broad debt holds, security pauses concentrated on departing high-value customers or a receiving provider with frequent reconstruction defects.

Public evidence would also protect good providers. A registrar accused of obstruction could show that the pause followed a verified authority anomaly and ended within the standard. A receiving provider could demonstrate consistent handoffs. Reputation would attach to observed conduct rather than marketing claims.

The registry operator should publish its own decisions in the same discipline. If it authorizes a pause, rejects a competitor or delays a cutover, the record should identify the rule, evidence category, reviewer and outcome. Oversight cannot stop at the service-provider layer.

Data retention for the public record should be long enough to reveal patterns and support later disputes. Protected evidence can follow shorter, purpose-based periods. The aim is durable accountability without creating a new collection of exploitable customer details.

What success would look like after five years

A successful registry operator would not boast that nobody left. It would show that departures occurred without duplicate authority, material service interruption or lost evidence. It would publish completion times, defect rates, valid pause reasons and remedies. Providers with poor results would improve or lose permission to take new customers.

Competition would be visible in service quality, prices, support, security and dependency management. New qualified providers could enter without incumbent sponsorship. Customers could compare offers knowing that another move remained possible. The common record would stay stable while provider market shares changed.

Voice would also improve. Member debates could focus on the necessary common layer because fewer service disputes would be treated as constitutional crises. Boards would know that expanding proprietary dependencies increases measured exit cost. Staff would maintain documentation for successors as part of ordinary duty.

Distress events would become less improvisational. Escrow, continuity providers, authority records and tested cutovers would exist before a provider failed. Courts and regulators would receive clearer evidence about which powers can move and which restrictions must remain.

Most importantly, staying would become informative. A holder that remains after seeing credible alternatives expresses a measure of preference. Loyalty begins to mean something when exit is safe.

Watchpoints for a future registry

The first watchpoint is silent incompleteness. An export may pass format checks while omitting dispute history, dependency states or the meaning of local codes. Reconstruction testing should determine whether a successor can actually operate.

The second is residual authority. Former providers may retain credentials, contact priority or informal influence after the formal change. Closure audits should examine powers, not only labels.

The third is qualification capture. Incumbents may make receiving-provider standards costly, subjective or politically controlled. Entry decisions need conflict disclosure, reasons and appeal.

The fourth is selective friction. High-value customers, critics or members leaving after a disputed vote may encounter more checks than comparable cases. The registry operator should compare pause and defect rates across customer classes while protecting privacy.

The fifth is security inflation. Real threats can become a vocabulary for delay. Every security hold needs a proposition, evidence, scope, owner and expiry.

The sixth is fee migration. When explicit termination charges are capped, providers may move the cost into mandatory advice, data preparation or continuing dependency contracts. Total departure cost should be measured.

The seventh is institutional self-exemption. The registry operator may demand portability from registrars while making its own coordination service impossible to replace. Continuity and succession testing must reach the common layer.

A future direction earns trust by accepting loss

The positive case for the registry operator is not that it promises wiser administrators, better slogans or permanent harmony. Those claims are fragile. People change, boards divide and institutions accumulate interests. The stronger case is structural: the registry operator can make authoritative registration compatible with a holder's ability to change the institution serving it.

That design accepts four losses. The provider may lose the customer. It must release usable data. It must surrender powers tied to the appointment. It must continue competing after the departure. Each loss is uncomfortable, and each is evidence that authority has boundaries.

The registry operator should not romanticize exit. Most holders should prefer reliable continuity to repeated switching. Complex portfolios need careful preparation. Fraud, court orders and genuine disputes require restraint. But these facts support disciplined portability rather than permanent captivity.

A registry worth leaving is one worth joining because its value does not depend on trapping the customer. Its common record survives competition. Its safeguards survive provider change. Its administrators know that service power can end. Its members can speak without wagering the continuity of their resources on every institutional dispute.

The most credible future registry will not ask the public to infer trust from those who remain. It will show, with evidence, what happened to those who chose to go.

Sources

NRS and BTW role sources