Summary

  • On 28 November 2012, AFRINIC-17 heard Jean Robert Hountomey present AFPUB-2012-GEN-001 remotely, then discussed it alongside a separate proposal concerning reverse DNS.
  • Adiel Akplogan told the meeting that a WHOIS data-integrity activity was already under way inside AFRINIC, sharpening the question of what policy would add to work staff could already perform.
  • A policy could have made staff maintenance recurring, measurable and reviewable. The draft also contemplated consequences affecting members, however, and those required a separate contractual and procedural basis.
  • The chair found no consensus after a show of hands and returned both proposals to the RPD mailing list. The published record gives no per-proposal tally, denominator or reasoned finding.
  • That result left the proposed member consequences unadopted. It did not cancel AFRINIC’s duty to keep its own database accurate, and it did not give staff permission to impose those consequences without policy.

A maintenance question arrives in the policy room

On the morning of 28 November 2012 in Khartoum, the sixth item in the AFRINIC-17 policy session looked, at first, like housekeeping. The registry’s public contact records needed attention. Jean Robert Hountomey, appearing remotely, presented a proposal called WHOIS Database Clean-up. Its premise was easy to recognise: contact information loses value when it is no longer accurate, and a registry that publishes such information cannot treat decay as somebody else’s problem. Yet the discussion soon revealed that the label “clean-up” covered two different institutional acts. One was maintenance of a database AFRINIC already operated.

The other was the use of contact-validation results to change how a member would be treated.

The difference was not semantic. If staff checked an email address, documented the result, accepted an authenticated correction and preserved a history of the change, AFRINIC would be performing the ordinary work of a private registry. That work supports people trying to reach the responsible network during an outage, an abuse report, a due-diligence review or an operational handoff. If, by contrast, the organisation used a failed contact test to attach public stigma, restrict service, declare breach or threaten a resource position, it would be doing something to the member, not merely something to its own record.

The evidence, authority and remedy needed for the second act could not be borrowed from the first.

AFRINIC-17 confronted that split directly because Adiel Akplogan stated that an activity concerning WHOIS data integrity was already under way inside AFRINIC. Some participants thought a policy remained important because policy would hold the organisation accountable for delivery. Alain Aina argued that not every operational problem required policy and that the CEO could record recommendations and expectations for AFRINIC’s activities. Douglas Onyango suggested improving the existing activity toward the proposal’s requirements, leaving open the possibility of withdrawal once AFRINIC marked the work complete.

These positions did not amount to a simple contest between people who cared about accurate data and people who did not. They were competing accounts of how to turn an accepted maintenance responsibility into dependable performance.

The chair eventually declared no consensus after a show of hands and returned the proposal to the RPD list. That disposition matters because it preserved, whether deliberately or not, the boundary exposed in the debate. Staff did not need a new public mandate to maintain the accuracy of the registry they ran. A community policy could still have specified frequency, coverage, correction service, measurement and reporting, making staff answerable for that maintenance. But the absence of consensus did not allow the proposed effects on members to migrate into an internal project. A private process had failed to adopt them.

Staff practice could not quietly supply what the policy process had not conferred—and the policy process itself could not create sovereign power that AFRINIC never possessed.

For operators, that distinction is a continuity safeguard. A registry error or overbroad label can affect the ability to coordinate around number resources even when the underlying network is functioning and its customers depend on it. For AFRINIC, the distinction is a legitimacy safeguard. The organisation’s strongest ground is accurate, auditable administration. The further a response moves from qualifying a field toward judging a member or disturbing a resource position, the more exact the contractual footing and the more independent the route of review must become. The meeting did not settle every detail.

It did make it impossible to say honestly that all of this was merely database clean-up.

What the minutes can—and cannot—carry

The official minutes are the centre of this event, but they are a summary rather than a transcript. They identify the agenda, the remote presentation, several named interventions and the final disposition. They do not reproduce Hountomey’s full oral case. They do not record every speaker behind every concern. They do not give a line-by-line account of the exchange. Any analysis that fills those gaps with imagined motives would turn a short institutional record into a drama the evidence cannot sustain.

This limitation is especially important because the chair grouped the floor discussion of WHOIS Database Clean-up with another proposal, No Reverse Unless Assigned. Haitham El Nakhal suggested combining the two because both concerned cleaning the WHOIS database. The minutes then record interventions across that combined discussion and dispose of both proposals in one paragraph. The proposals nevertheless kept separate identifiers and raised distinct questions. A remark expressly attributed by the minutes can be reported. An unattributed remark cannot safely be assigned to the clean-up draft merely because it would fit the story.

The combined format created compression at precisely the point where differentiation was most valuable. Douglas Onyango’s call for clean-up without time-limit exclusions, along with mandatory and continuously available reporting of invalid points of contact, clearly illuminates the desired breadth and visibility of maintenance. Mark Elkins’s suggestion of a public shame list shows how quickly a conversation about record quality could move toward reputational leverage. His stated support for both proposals establishes his recorded position, not the breadth of support in the room.

Haitham’s combination suggestion establishes a procedural intervention, not a merger of the drafts. Adiel’s account of an internal activity establishes that AFRINIC said work was under way, not what the work covered or whether it succeeded.

The minutes’ final paragraph is similarly precise in one respect and thin in others. It records discussion, a show of hands, the chair’s declaration of no consensus on both proposals, and a return to the RPD mailing list. It does not publish the number of hands, the number eligible to participate, a separate result for each draft, an objection ledger or a reasoned explanation of why consensus was absent. AFRINIC’s annual report later supplies an aggregate confirmation: five policies were discussed in 2012 and none gained consensus at the AFRINIC-17 public policy meeting in Khartoum.

That summary corroborates the outcome but adds no proposal-specific count or rationale; its policy-list formatting is imperfect as well.

These are not minor documentary complaints. They define what the event can support. The record proves that an internal-activity-versus-policy-accountability disagreement occurred and that the chair returned the proposals to the list. It does not prove that the room rejected database accuracy, rejected every clause, endorsed an alternative staff plan or determined that any consequence was lawful or unlawful under a particular member’s contract. No consensus is a bounded procedural disposition. Treating it as a detailed merits judgment would give the record more resolution than it has.

Nor can the grouped show of hands establish representative public authority. AFRINIC is a private coordination body operating registry services. The people in the room could participate in its policy process; they could not, through attendance or a raised hand, transform the meeting into a legislature for Africa’s networks, governments or public. The minutes do not claim a population denominator, and a service region is not an electorate. The relevant achievement of the record is narrower: it shows how AFRINIC’s own process handled two pending proposals on that date.

That is enough to analyse the authority split without inflating the meeting into something it was not.

The work that did not need to wait

Adiel’s statement that data-integrity work was already happening changed the burden of the discussion. If AFRINIC already had an activity, proponents of policy needed to explain not simply why accurate data mattered, but why an internal project was insufficient. Opponents of new policy, meanwhile, could not answer merely by pointing at the existence of work. An activity can exist without a published scope, an owner, a calendar, performance measures, a secure correction path or evidence of completion. “Under way” describes motion. It does not establish coverage or quality.

The underlying staff duty was nonetheless real and immediate. AFRINIC chose to operate the registry and expose contact fields as a coordination interface. That choice carried a responsibility to keep the interface as accurate as reasonably possible: test contact channels, distinguish confirmed results from assumptions, correct fields after appropriate authentication, preserve changes, and describe uncertainty at the field level. None of those acts requires AFRINIC to decide who is morally deserving, who owns an address block in a public-law sense, or who should be punished.

They are the disciplined acts of a bookkeeper maintaining the instrument it controls.

Waiting for a new policy before doing such work would have inverted responsibility. A registry cannot publish a field, invite reliance on it and then claim it lacks authority to check whether the field still functions. It can investigate the quality of its own data because data stewardship is part of operating the service. The relevant constraints are accuracy, security, auditability and candour. A failed test should be recorded as the result of that test, not enlarged into a finding about the member’s intentions or entitlement. A verified correction should be traceable. Where evidence is incomplete, the record should say so.

This is also why the operational case for maintenance does not need exaggerated claims. Accurate WHOIS and RDAP records can reduce the time and cost involved in troubleshooting, incident response, due diligence and finding a responsible contact. They can help an operator decide where to send a technically urgent message. They can support a lender, counterparty or network partner assessing whether the published details correspond to a reachable organisation. But the database remains limited public evidence. A field is not a title deed.

A successful reply does not prove every operational right, and a failed reply does not prove abandonment, misconduct or invalid control of number resources.

Good maintenance respects that evidential scale. Imagine a contact address that rejects mail during a temporary system migration. Staff can accurately record that a test at a stated time failed and invite authenticated correction through a secure channel. They cannot infer from that single result that the member has disappeared, broken every contractual duty or forfeited its resource position. The narrow record helps downstream users without pretending to resolve a dispute it cannot resolve. Precision is not weakness here; it is what makes the database trustworthy.

The same discipline protects AFRINIC from an impossible role. If every uncertain contact becomes an occasion for adjudication, staff must decide facts and remedies far beyond database operations. If every field remains unqualified because consequences would be risky, the public interface becomes less useful. Separating evidence from consequence avoids both failures. Staff can maintain and qualify the record vigorously while leaving contract disputes and any coercive remedy to an exact instrument and an independent legal path appropriate to the stakes.

Adiel’s intervention therefore supports neither institutional complacency nor discretionary enforcement. It supports a narrower conclusion: there was already an operational lane in which AFRINIC could act. The meeting still had to decide whether policy should structure that lane and whether any separate member-facing effect belonged in the proposal. The first question was about the performance of the registry. The second was about a member’s position. Conflating them would make the existence of staff work a blank cheque, when it was actually evidence that maintenance and consequence could be separated in practice.

Why policy still had serious work to do

The strongest case for policy came from the weakness of the phrase “internal activity.” A project inside an organisation may depend on current priorities, staff availability or a manager’s continuing interest. It may cover some records and not others without publishing the rule. It may generate no aggregate metrics by which members or downstream users can judge performance. It may stop without a formal decision. If stale registry data shifts troubleshooting and coordination costs to the rest of the network, an undocumented project is an unsatisfying answer even when its staff are diligent.

The concern recorded in the minutes—that policy and internal activity were not equivalent because policy would make AFRINIC accountable for delivery—deserves its full force. A staff-facing policy could set a recurring calendar, define the population of records covered, specify how tests are authenticated, establish correction deadlines, require an audit trail and publish aggregate results. It could distinguish a test failure from a verified inaccuracy. It could require secure cure channels and a review when a member says the record or test is wrong. These are not decorative procedural details.

They determine whether maintenance is consistent, observable and correctable.

Douglas’s response to the announcement of the internal activity points toward that possibility. He suggested improving the work toward the proposal’s requirements, with possible withdrawal after AFRINIC flagged completion. The minutes do not say the meeting adopted this path, and they contain no evidence that completion occurred. Still, the intervention reveals a practical bridge between policy advocates and operationalists: identify what the existing activity lacks, improve it against explicit requirements, and make completion visible. That bridge does not depend on treating staff as powerless before policy.

It depends on treating internal work as something that must be evidenced.

Alain’s argument supplied the other side. He said the problem did not necessarily need policy and that the CEO could record community recommendations and expectations for AFRINIC activities rather than draft policy for every problem. That is a serious governance economy argument. Policy is costly and can become unwieldy when used to specify every operational task. A capable management team should be able to translate clear expectations into service work without turning the policy room into a procedures manual.

Yet recommendation is not the same as proof of performance. If AFRINIC chose the operational route, it still needed ownership, scope, evidence and reporting. A recorded expectation could be effective if it produced a calendar, metrics and transparent results. It could be ineffective if it amounted only to an instruction that data quality should improve. The meeting record does not tell us which would have happened. The point is not that policy is always superior. It is that accountability must be concrete regardless of the instrument used.

This is where the authority split resolves an apparent contradiction. Policy can add real value without being the source of staff’s basic permission to maintain records. Its value lies in constraint and observability: binding the maintainer to perform its existing responsibility in a defined way. The policy room may specify what AFRINIC must measure and disclose about its own service. It does not need to pretend that it has created the underlying duty from nothing. And because the obligation runs toward staff performance, the policy can be ambitious without taking a member’s position as its enforcement object.

Such a policy would also allocate error risk more fairly. AFRINIC controls the test design, the public field and the correction interface. If a test is faulty or a correction stalls, the registry is best placed to document and fix the problem. Aggregate reporting can show whether errors cluster in the registry’s method rather than in member behaviour. A policy that measures only member response while hiding registry performance would tell half the story. The minutes’ accountability concern is most persuasive when applied to both the maintenance duty and the institution that performs it.

Stale records impose costs, and members may ignore requests. Those facts strengthen the case for clear notice and an exact member obligation where one exists. They do not make every endpoint legitimate. A credible maintenance regime can repeat authenticated notices, offer secure correction, record the status precisely and report aggregate trends. If AFRINIC then seeks a service restriction or other material remedy, it must leave the maintenance lane and identify the binding instrument that permits that step. Policy accountability solves discretion in staff work.

It cannot solve a missing authority chain by relabelling consequence as maintenance.

The moment “clean-up” stopped being clerical

The proposal archive matters here only for the minimum needed to understand the meeting. AFPUB-2012-GEN-001-DRAFT-02 assigned recurring validation work to staff and asserted duties concerning accurate data. It also contemplated adverse effects following non-response, including effects that could reach a member’s record or resource position. That mixture explains why the debate could not be settled by agreeing that WHOIS quality was desirable. The proposal coupled a service standard for the maintainer with a response mechanism capable of changing the position of the maintained party.

The proposed cadence included recurring elements—a monthly interval, twice-yearly activity and an eventual one-year point appear in the archived text—but those parameters should not distract from the institutional question. The important fact is not the choreography of every step. It is that a contact-validation result could travel from a database observation into an adverse member consequence. At that crossing, the organisation would need more than confidence in its operational aim.

It would need to show what obligation bound the particular member, what evidence established breach, what notice and cure were provided, who made the reasoned decision, and where the member could obtain genuinely independent review.

The proposal said members were committed through the RSA to maintain accurate data. That statement records the draft’s premise; it is not an independent ruling about any contract. The exact 2012 RSA version binding a particular member is not present in the meeting record considered here. Neither are the operative suspension or termination clauses, the available remedies, or evidence that any named member failed a duty. A responsible authority analysis therefore starts with the precise instrument, not with the general label “RSA” and not with the fact that the proposal used it.

This exactness protects both sides. If a binding contract clearly requires a member to maintain specified contact data and supplies a defined remedy after notice, AFRINIC can point to the clause and follow its terms. The member can test whether the evidence meets the clause and whether the procedure was observed. If the instrument does not support the proposed consequence, a policy-room vote cannot rewrite that deficiency into public power. Private parties can agree contractual terms, but a contract remains a private instrument. It does not make AFRINIC a regulator, prosecutor or court.

The need for proportional evidence rises with the consequence. Correcting a typographical error after authenticated confirmation requires evidence that the new field is correct. Marking a channel as unconfirmed requires evidence about the test and honest limits on what the mark means. Publishing an adverse label about a named company requires confidence that readers will not interpret the label more broadly than the evidence warrants. Restricting service or disturbing resource continuity requires a much stronger foundation because the loss can reach customers and counterparties who had no part in the contact failure.

That escalation in evidence is not a recommendation for gentler punishment. It is a categorical warning that some acts are outside registry administration altogether. AFRINIC can keep accurate books. It can carry out contractually specified service processes. It cannot become a sovereign, police force, punishment body, confiscator or adjudicator because participants agree that a consequence would motivate replies. Community agreement is internal cooperation, not a transfer of state power. A database field cannot pronounce on ultimate entitlement.

The no-consensus outcome is crucial at this boundary. Because the proposed consequence did not gain the recorded approval sought by the draft, it remained unadopted in that process. It would be perverse to say that this failure left staff freer than adoption would have done. An internal project could continue checking and correcting records; it could not absorb the draft’s rejected member-facing consequences simply because the maintenance goal remained valid. Otherwise, bringing a consequential rule to the policy room and failing would become a route around the policy room.

Nor did the chair’s decision transfer power to the CEO. Alain’s suggestion concerned recording recommendations and expectations for operational activity. It did not establish that management could declare breach, stigmatise a member or alter resource status without a separate authority chain. Management may organise the registry’s work. It cannot manufacture jurisdiction through an instruction. The clean line is not between “community” and “CEO,” as though one of them must possess unlimited power.

It is between tasks AFRINIC legitimately performs as administrator and consequences that require exact private footing and independent legal process.

A public status is not a public shaming

Mark Elkins’s suggestion of a public shame list captures the temptation to turn visibility into leverage. If private reminders do not produce replies, naming companies may appear to create an incentive. But a shame device is different from precise evidential disclosure. Its purpose and likely effect are reputational: it invites an audience to infer blame. The underlying contact test may establish only that a message failed or went unanswered under particular conditions. It does not establish why, whether other verified channels worked, whether the member received proper notice, or whether the member’s resource position is invalid.

A carefully designed public status, by contrast, limits itself to what the registry knows. It can identify the field tested, the date, the method, the observed result and whether an authenticated correction is pending. It can avoid moral language and make clear that the status does not determine ownership, entitlement or misconduct. Such a status serves users of the database because it qualifies evidence. It does not recruit those users to punish the subject.

The difference matters economically. A named adverse list can affect due diligence, commercial relationships and perceptions of reliability. Readers may treat the registry’s institutional voice as authoritative even where its evidence is narrow. False suspicion creates transaction costs that are difficult to reverse. The member may correct the contact quickly yet continue to carry the reputational residue of the label. Meanwhile, customers and network partners may face continuity concerns disproportionate to a temporary communication failure.

The meeting did not adopt the shame-list suggestion. Reporting it as an intervention preserves the record; treating it as authorised policy would falsify it. The suggestion also cannot be used to infer bad faith by Mark or anyone who supported a visible mechanism. Participants were confronting a genuine collective cost from stale data. The correct analytical response is to separate the useful aim—making record quality observable—from the unsupported leap to public blame.

This separation gives AFRINIC a stronger, not weaker, public interface. A field-level uncertainty status is valuable precisely because it refuses to perform legal or moral work. Downstream users learn what was tested and how much weight to place on the record. Members have a clear route to correct errors. AFRINIC’s reporting can expose whether its own maintenance programme is working. Nothing in that design requires a spectacle of culpability.

One paragraph for two unresolved proposals

The chair’s grouping decision and single no-consensus paragraph left an evidential scar. Two proposals could share a broad concern with database quality while still present different authority questions. A combined discussion can save time and reveal common operational issues. It can also blur which objections attach to which text and whether a raised hand reflects support for one proposal, both or neither. When the published account contains no separate tally or reasoning, later readers cannot reconstruct those distinctions responsibly.

That does not make the outcome invalid by itself; the record supplies too little information for such a claim. It does mean the outcome should be read modestly. The chair found no consensus in the private process and returned both drafts to the list. The decision says nothing reliable about how many participants accepted staff accountability but rejected member consequences, how many preferred operational action to policy, or how many opposed one of the proposals for reasons unrelated to WHOIS clean-up. Those possible alignments are analytically important but historically unknown.

The annual report’s aggregate sentence cannot repair the missing resolution. It confirms that none of five policies gained consensus at AFRINIC-17, but it does not disaggregate the hands or the reasons. Nor does the fact that the wider meeting ran from 24 to 29 November change the date of the relevant policy session shown in the minutes: 28 November. The event owned here is that day’s discussion and disposition, not the publication history of the draft or a later account of what became of it.

The thin disposition places a burden on anyone making claims from it. A policy opponent cannot say the meeting decided that an internal project was sufficient. A policy advocate cannot say the meeting endorsed every maintenance premise but stumbled on procedure. Staff cannot say no consensus authorised administrative implementation of the draft. A member cannot say the result erased any accurate-data duty contained in an actual binding contract. Each of those claims would require evidence beyond the recorded outcome.

The most defensible reading is both narrower and more useful. AFRINIC-17 surfaced a genuine design choice about institutional accountability, failed to settle the combined proposals, and sent the discussion back to the RPD list. Within that uncertainty, ordinary registry maintenance remained ordinary registry maintenance. The member consequences proposed alongside it remained unadopted. The unresolved space between those statements was not a licence; it was a reason to keep the lanes distinct.

Continuity depends on keeping the lanes distinct

Number-resource records sit at an administrative chokepoint. Operators, vendors, incident responders and commercial partners consult them because a registry provides a common reference. That practical influence can be beneficial when the record is accurate and its limitations are clear. It becomes dangerous when the institution controlling the record also treats a narrow test as authority to alter the subject’s operational position.

The distribution of risk is asymmetric. AFRINIC designs or selects the contact test, holds the historical record and controls the public interface. A member is expected to maintain reachable information and respond through appropriate channels. Downstream networks rely on continuity without participating in the test. If the registry makes a clerical error, the member and its customers can bear most of the immediate loss. If a member neglects a contact, responders and other networks bear coordination costs.

A sound system must therefore measure staff performance as seriously as member response and must not let the party controlling the administrative chokepoint decide an expansive remedy on its own evidence.

The Khartoum debate is valuable because it exposes this allocation before it hardens into practice. Adiel’s internal activity represented the maintenance lane. The accountability concern represented the value of binding the maintainer to deliver. The consequence-bearing portions of the draft represented a different lane in which the member’s position could change. The show of hands did not fuse them. It left the institution with the same basic responsibility it had when the session began: maintain accurate records and be honest about what they prove.

That responsibility is substantial. It demands competence, recurrence, security, audit trails and correction. It may demand a staff-facing policy if management commitments are too opaque. It does not include a power to punish, confiscate or adjudicate. AFRINIC’s legitimacy grows when it performs the narrow role well and shrinks when clerical influence is presented as public authority. The line drawn at the meeting table is therefore not an excuse for weak maintenance. It is the condition under which strong maintenance remains legitimate.