Summary
- AFRINIC-3 recorded meeting consensus in December 2005 on a proposal allowing qualifying end-user organisations to seek direct, provider-independent IPv4 assignments, generally no smaller than a /24. That act moved the proposal to a separate 15-day last call; it was not a vote, Board ratification, implementation, an assignment to any named applicant, or a grant of sovereign authority.
- The policy addressed a genuine operational bargain: a direct assignment could reduce dependence on one upstream and the disruption of later renumbering, while utilisation tests, routing-table growth, filtering risk, direct registry obligations and hostmaster discretion imposed costs of their own. Later AFRINIC records label the policy Implemented, but the checked record does not disclose the exact Board act, effective date, final-text chain or historical routing outcomes.
Analysis
The decision hidden inside a prefix length
The sharpest argument at AFRINIC-3 was compressed into three characters: /24. For an organisation that wanted public IPv4 space independent of its access provider, that prefix could mean a stable network identity capable of surviving a change of upstream. For other networks, every separately announced prefix could mean another route to store, process, accept or filter. And for AFRINIC, the proposed minimum was the point at which a request might move out of an upstream provider’s address space and into a direct relationship with the regional registry.
That is why the Cairo/Giza meeting’s act deserves precision. AFRINIC’s official report says the listed policy proposals, including the proposal for direct or provider-independent assignments to end-user organisations, received consensus at AFRINIC-3. The same record says they would return to the policy mailing list for 15 further days before being sent to the Board for final approval. Meeting consensus was therefore real and institutionally consequential, but deliberately incomplete. It advanced a proposal. It did not finish the process.
Four states must remain separate. First came meeting consensus: AFRINIC’s internal finding that general agreement existed among the participating policy community at the open meeting. Second came last call: a distinct 15-day mailing-list interval for final changes and amendments. Third came Board ratification and adoption, which the operative 2004 policy-development process reserved to the Board. Fourth came implementation, later evidenced by AFRINIC’s own publication of AFPUB-2006-GEN-001 as Implemented and by the policy’s appearance in consolidated manuals.
The first, second and fourth states have public documentary support. The precise bridge through the third does not. No checked contemporaneous Board agenda, minutes, resolution, ratification notice, final submitted text or effective-date record was located for this policy. That absence does not prove the Board never acted; a later institutional implementation state is visible.
It does mean that the AFRINIC-3 meeting itself cannot be described as final approval, and that a March 2006 notice saying the proposal would be forwarded to the Board cannot be silently converted into proof that forwarding, ratification and implementation had already occurred.
This distinction is not pedantry. A network-resource policy operates through text, sequence and institutional custody. If the public record cannot show which version crossed each threshold, a later reader cannot tell whether a criterion was approved at the meeting, introduced during last call, added by the Board, or inserted during later consolidation. The policy may still have been sensible. Its administrative history may still be incomplete.
What the April proposal offered
Mark Tinka’s proposal body was dated 16 April 2005 and appeared in the policy-list archive on 17 April. Its stated problem was concrete: AFRINIC did not yet have criteria for assigning IPv4 addresses directly to end users. The proposal built such a path for organisations using the addresses within their own networks. It did not authorise recipients to sub-delegate or reassign the block outside the organisation.
The general minimum was a /24. In binary prefix arithmetic, that is 256 total IPv4 addresses. A smaller request was to be handled through the applicant’s upstream provider rather than by a direct AFRINIC assignment. For a first direct assignment, the applicant had to demonstrate either efficient use of at least a /25 from an upstream or an immediate need for at least 50 per cent of the requested block based on its network infrastructure. A /25 contains 128 addresses, exactly half the address count of a /24.
The first-assignment pathways therefore converged, in the minimum-size example, on a need or prior-use signal equivalent to 128 addresses.
Additional assignments carried a separate evidentiary burden. The organisation had to document its previous assignments and forecast one year of growth. The stated thresholds were 25 per cent immediate utilisation and 50 per cent utilisation within one year, with the possibility of higher requirements where individual network circumstances justified them. For a /24 illustration, 25 per cent is 64 addresses, the numerical size of a /26, while 50 per cent is 128.
Those calculations explain the thresholds; they do not establish how many host addresses any particular network could use, how AFRINIC measured deployment, or whether every historical request was for a /24.
The text also gave AFRINIC staff a substantive administrative role. Hostmasters would evaluate need, decide assignment size on CIDR boundaries, apply a slow-start approach and preserve registry records. Hard numerical tests did not eliminate discretion. They sat beside it. That pairing can be useful: networks do not all grow in the same shape, and exceptional infrastructure may not fit one occupancy ratio. It can also make predictability depend on whether reasons, comparable cases and the application of discretion are recorded.
The sealed evidence identifies that risk but does not establish that AFRINIC discriminated against any actual applicant.
A separate part of the draft addressed critical infrastructure, including public exchange points and core DNS providers. It contemplated end-user assignments with a /24 ceiling and reserved blocks for exchange points. The later last-call summary shows that this section was not a finished matter in Cairo. Entities asked for section 5 to become more specific and disagreed over which top-level-domain operators qualified as critical. That discussion is another reason not to treat the meeting’s consensus as authentication of every word on a later Implemented page.
Even a typographical detail illustrates the custody problem. The initial text contained the phrase “at less 50%,” which a list entity identified as an apparent error for “at least 50%.” The later Implemented text uses the corrected formulation. The correction is well supported, but the April post, the archived March 2006 draft and the later Implemented page are not byte-identical. A trustworthy history should show not just the sensible final reading but the authorised change path.
Eight months of argument, not a moment of acclamation
The proposal did not arrive in Cairo without prior exposure. The elapsed time from its 17 April list posting to AFRINIC’s later recorded consensus date of 13 December was at least 240 days, far beyond the policy-development process’s 30-day discussion minimum. That duration is evidence of opportunity. It is not evidence that discussion was continuous, broadly attended or representative of every affected organisation.
The April messages nevertheless reveal a serious technical-policy contest. Entities asked whether a /24 minimum would enlarge the global routing table, whether provider-aggregatable space already solved the applicant’s problem, what reasons would justify independence, whether upstream providers would actually carry the route, and how much discretion hostmasters should possess. A suggestion to cap the programme at 250 or 500 /24 assignments offered one way to bound the routing exposure. Those figures would correspond to 64,000 or 128,000 addresses respectively; 512 /24 blocks have the address count of one contiguous /15.
But the suggestion was not adopted in the published proposal, and another entity warned that a fixed cap could generate a land rush.
The debate therefore resisted a simple story. Provider independence was not free. Aggregation was not costless to the end user. A registry could issue a prefix but could not make autonomous networks accept it. Quantitative eligibility rules could ration a finite pool but could also favour organisations whose plans fit the chosen metrics. A cap could constrain the number of new routes while accelerating applications before the ceiling closed. Staff discretion could accommodate unusual networks while making outcomes harder to predict.
The proposal also pointed non-public networks toward private address space, but that technical alternative did not answer the problem posed by an organisation needing stable public reachability. On 3 December, Mouhamet Diop announced that this proposal and three others would be discussed in Cairo for a final time before being passed to the Board. The notice established meeting readiness and an intended sequence; it did not establish consensus, approval or implementation in advance.
The meeting summary preserved two of those tensions: the routing-table consequences of direct /24 assignments and the need to narrow the critical-infrastructure wording. What it did not preserve is equally important. The checked record contains no entity denominator for the policy item, no exact question on which consensus was called, no identification of the person who made the call, no show-of-hands or humming record, no objection count, no speaking sequence, no audio or video record, and no contemporaneous signed certification explaining how material objections were resolved.
The report identifies Alan Barrett and Ernest Byaruhanga as leaders or moderators of the afternoon policy discussion. That role attribution is useful but does not answer which person, if either, uttered the consensus call or by what observable method.
Those omissions constrain what can be claimed about the event. They do not, by themselves, erase the meeting state that AFRINIC recorded. The defensible statement is that AFRINIC’s official records say the proposal achieved meeting consensus. The indefensible additions would be that the result was unanimous, that a known majority voted for it, that all members or all African operators were represented, or that the room acquired political authority over absent end users and states.
Consensus was not a vote
The public record briefly became confused after the meeting. When Ernest Byaruhanga opened last call on 9 February 2006, his message said the community had consented and voted. Alan Barrett responded that no vote had occurred; there had been apparent consensus. Alan Levin recalled that there might have been a vote involving two voting members, but explicitly said his memory could be wrong. AFRINIC chief executive Adiel Akplogan then gave the institutional correction: policy was not decided by voting, and no vote had occurred.
That exchange resolves one point and leaves another open. It supports “consensus, not a ballot” as the controlling description of AFRINIC’s process. It does not reveal the entity population or consensus method. The remembered phrase about two voting members cannot be repurposed as the denominator for a vote that AFRINIC said did not happen. Nor can the lack of a recorded count be used to infer that everyone present agreed.
The governing policy-development process is consistent with the correction. AFRINIC’s transitional process, version 0.1 from March 2004, described a six-step route. Anyone could propose; the open policy list discussed; after at least 30 days an open meeting considered endorsement; a proposal without consensus returned for further work or ended; meeting consensus triggered a 15-day last call; only after those stages did the Board ratify and adopt the policy for use. The process expressly defined consensus as general agreement rather than a result measured by majority vote.
That internal definition gave the meeting a procedural function. It did not transform attendance into a public mandate. Under the controlling Heng Lu doctrine, a policy room is not a legislature, and presence is evidence rather than authority to speak for those who are absent. AFRINIC-3 entities could move an AFRINIC proposal through AFRINIC’s own process. They could not by that act represent every end-user organisation, every network operator, every member, every state or the African continent as a political whole.
This boundary does not make internal consensus meaningless. Institutions need decision mechanisms, and an open-list-plus-meeting model can surface objections before a registry adopts issuance criteria. The key is proportionality: the decision may govern AFRINIC’s own free-pool service and consenting relationships within lawful scope. It cannot bootstrap itself into ownership of operators’ network assets or into general coercive jurisdiction.
The 58-day handoff to last call
The later policy history assigns 13 December 2005 as the consensus date. The AFRINIC-3 report says the event ran on 13 and 14 December, while the HTML minutes are headed 14 December. The February last-call message refers instead to a meeting on 12 and 13 December. The evidence package uses 13 December for the recorded policy-history act and 13–14 December for the event, but it does not manufacture a single corrected chronology where AFRINIC’s records diverge.
Last call opened on 9 February 2006, 58 elapsed days after the recorded 13 December consensus date. The contemporary process specified a 15-day last-call duration, but the checked text did not set a deadline for how quickly that stage had to open after the meeting. The gap is therefore observable, not necessarily a process violation.
Byaruhanga’s opening notice instructed entities to send comments to the policy list and said the proposals would then go to the Board for review. A later exchange clarified AFRINIC’s chosen channel: the notice could be forwarded to another list, but policy debate was to take place on the policy working-group list so it could be followed and summarised. That design may have made the official record more manageable. It does not prove universal notice to every organisation affected by a new direct-assignment option.
Even the closing date has two official versions. A later history table says last call ended on 24 February. A 7 March mailing-list notice says it expired at noon SAST on 25 February and mistypes the year as 2005. The existence and completion of the 15-day stage are sufficiently supported, but the exact closing date is not clean enough to state without qualification. Measured from the history table’s 24 February date, the 7 March forwarding notice arrived 12 elapsed days later; using the 25 February date produces a shorter interval under ordinary date subtraction. Neither calculation turns the notice into a Board decision.
The 7 March message says the policy working group would now forward the proposals to the Board for approval. Its grammar matters. It is evidence that AFRINIC regarded last call as complete and intended the next handoff. It is not evidence of the Board’s receipt time, deliberation, quorum, method, resolution, approval date or effective date.
Contemporaneous materials alternated between “Board of Trustees” and “Board of Directors.” That naming difference does not displace the internal allocation of the ratification function to AFRINIC’s Board, but it reinforces why the missing agenda, resolution and final attachment should not be supplied by inference.
Implementation is visible; ratification custody is not
Later AFRINIC materials remove one possible overstatement while creating another temptation. An archived policy page identifies the proposal under the later reference AFPUB-2006-GEN-001 and labels it Implemented. Consolidated policy materials reproduce the rules for IPv4 end-user assignments. It would therefore be wrong to say that the proposal was never implemented merely because the checked contemporaneous Board record is missing.
It would be equally wrong to work backwards from the Implemented label and invent the missing details. The later page does not supply the exact Board resolution, ratification date, final submitted text, effective date or clause-by-clause change history. It also includes a requirement that an end user be an AFRINIC member in good standing. That criterion is not visible in the initial proposal or the archived March 2006 draft reviewed for the sealed package. It may have entered through an unlocated last-call or Board version, or through another authorised change. Without the relevant text and record, its insertion point remains unknown.
The distinction can be expressed without contradiction: AFRINIC’s later record shows that the institution treated the policy as implemented, while the checked public evidence does not reconstruct the complete route by which the Board ratified a particular final text on a particular date. Institutional outcome and documentary custody are related facts, not interchangeable ones.
A proportionate record would have made the chain easy to audit. It would preserve the exact version placed before the meeting, identify the consensus caller and proposition, record the main objections and their disposition, publish the version sent to last call, show amendments made there, preserve the final Board submission, and attach the Board resolution, final text and effective date. None of those requirements demands that a technical meeting resemble a national parliament. They simply match documentary precision to the operational consequences of allocating scarce, durable identifiers.
The operational bargain: continuity for route cost
Direct assignment changes the location of dependence. Under provider-aggregatable space, an organisation’s public addresses normally come through an upstream. Changing that provider can force renumbering. Public IP identity may be embedded in DNS, firewall rules, access-control lists, external allowlists, APIs, monitoring systems, customer configurations and reputation systems. Replacing an address can therefore be a distributed migration across parties the operator does not fully control.
A provider-independent assignment can reduce that exposure. If successive upstreams accept and carry the route, the organisation may preserve the same public network identity while changing providers. That can lower switching costs, reduce an incumbent provider’s bargaining leverage and make multihoming or continuity planning more practical for an organisation that does not operate as a local Internet registry.
But direct does not mean independent of everyone. The later policy’s membership-in-good-standing condition placed the organisation in a direct administrative relationship with AFRINIC. The holder gained distance from one upstream’s address block while accepting membership, documentation, utilisation review, fees and policy exposure at the registry layer. The checked evidence does not supply the contemporaneous end-user fee schedule, uptake counts or contract terms needed to price that shift for a 2006 applicant.
Nor did the assignment carry itself across the Internet. Registration answers a ledger question: which organisation has been issued the prefix under the registry’s policy? Routing answers an operational question: which autonomous networks originate, import, filter and propagate the route? AFRINIC could maintain the registry and issue a /24. It could not compel an upstream to announce that prefix or every network on the Internet to accept it. An assigned /24 might be useful, selectively reachable, filtered, or dependent on a particular routing arrangement.
No recipient-level BGP or filtering data in the sealed record establishes which outcome occurred.
The routing-table objection was therefore substantive. Each independently announced /24 can add a route, moving some of the cost of provider independence onto networks that maintain routing hardware and software. Entities differed over whether that marginal cost was acceptable or dangerous. The package contains no quantified 2005 route-impact study that settles the magnitude, so neither “negligible” nor “catastrophic” is defensible as a historical finding.
This is the running-code test required by the controlling doctrine. Policy has to be evaluated through both sides of the live network. Provider-independent identity can protect an operator from renumbering and lock-in. More-specific announcements can impose routing and filtering costs elsewhere. A registry entry is useful coordination but not a guarantee of reachability. The operator remains the party that finances infrastructure, negotiates transit, maintains contacts and bears service failure.
Scarcity discipline without a sovereignty claim
The strongest defence of the 2005 process begins with the free pool. AFRINIC had finite unallocated IPv4 space and needed criteria for deciding which requests justified direct issuance. A /24 was a practical boundary for many routing arrangements. Utilisation thresholds constrained waste. The proposal had been exposed on an open list for far longer than the minimum period, the meeting addressed the routing objection, last call gave people who were not in Cairo a further opportunity to respond, and Board ratification prevented a single staff member from holding unilateral formal power.
That defence should be admitted in full. The initial allocation of scarce free-pool space requires queue discipline. Verifying identity, need, uniqueness and accurate contacts is within a registry’s coordination function. Refusing a new request that fails to establish the published criteria is not automatically punitive confiscation of an operational asset. The stage of the decision, the applicant’s reliance and the available remedy all matter.
The limit is just as important. Under Heng Lu’s controlling doctrine, AFRINIC is a numbering ledger and voluntary coordinator, not a sovereign. It has no police, prosecutor, judicial or legislative authority. Its files can prove what AFRINIC proposed, recorded, announced and later labelled. They cannot self-prove that the registry owns the address resource in a political sense, that meeting entities spoke for a continent, or that an internal policy supplies public-law jurisdiction over an end user’s later commercial conduct.
Corporate policy and contract can still create obligations among consenting parties within lawful scope. A registry can maintain uniqueness, process requests, publish a holder relationship, correct records and coordinate continuity. If a later dispute requires coercive punishment, confiscation or adjudication of legal rights, the relevant authority must come from competent courts or public-law institutions with independent due process. Calling the underlying rule “consensus policy” cannot make AFRINIC police, prosecutor and judge.
This boundary is particularly important because the direct-assignment policy moved the registered-holder line closer to the operator. The organisation could not reassign the addresses outside itself under this policy, but that historical use condition does not erase the operator, provider, customer and routing layers that make the network real. NRS and BTW’s controlling operator-side record establishes that assignments and downstream use are ordinary Internet dependencies whose contacts and responsibilities should remain legible. Ledger clarity is valuable. It must not be inflated into sovereign permission over every operational use.
NRS’s role also stays bounded. It advocates, researches, convenes and represents members who explicitly authorise it. It does not operate AFRINIC’s registry, RPKI, WHOIS or RDAP services; it does not run AFRINIC elections, appeals, settlements, custody or continuity. Its operator-side analysis helps identify the stakes. It does not substitute for the institutional records needed to prove what AFRINIC did at each process stage.
What can responsibly be concluded
AFRINIC-3 established a bounded institutional innovation. The entities accepted, at meeting-consensus level, a route by which qualifying end-user organisations could seek direct IPv4 assignments under measurable need and utilisation criteria. That mechanism could reduce forced renumbering and upstream dependence. It could also add more-specific routes, expose holders to filtering, require a direct registry relationship and leave material judgment with hostmasters.
The consensus was not a vote. The record does not provide a reliable entity denominator, an exact consensus method or evidence of continental representation. It does provide AFRINIC’s own official statement that consensus occurred and that 15 further days on the mailing list would follow. Last call later opened and closed, though official records disagree by a day on the closing date. A March notice records the planned forwarding to the Board. Later AFRINIC publications show an Implemented status and persistent policy text.
What remains absent is the exact Board act and a complete version chain. The gap cannot be filled by treating meeting consensus as final implementation. It also cannot be used to erase the later implementation evidence. The honest account holds both facts at once.
The 2005 policy can therefore be defended as legitimate free-pool administration without granting AFRINIC a sovereign character it does not possess. Its authority was narrow: coordinate unique numbering, assess applications, maintain an accurate ledger and act within contractual and corporate scope. The operational result depended on end-user investment, upstream contracts and autonomous routing choices beyond the registry’s command.
That is the durable lesson of the /24 debated in Cairo: a registry can record an assignment, a meeting can advance a policy, a Board can own an internal ratification step, and networks can decide whether to route—but none of those acts should be mistaken for another.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
