Summary

  • AFPUB-2026-GEN-002-DRAFT01 proposes a substantially automated member dashboard, immediate notices, reminders and staff notification for persistent discrepancies. Those administrative functions can improve registry accuracy, but the proposal also points toward staff-written rules for withholding, revocation or closure. That second function is not a permissible extension of bookkeeping.
  • AFRINIC may show evidence, identify the exact record or policy at issue, invite correction, preserve an audit trail and cooperate with lawful public authorities. It may not decide guilt or use registry dependency as punishment. Contract language, community process and procedural safeguards may organise voluntary administration; none grants AFRINIC sovereign coercive power.

The most revealing word in AFRINIC’s proposed workflow is not “compliant”. It is “Escalated”. A network operator who sees that word beside an account needs to know whether it means that a hostmaster will inspect an inconsistent record or that the organisation is being moved towards the loss of a service, a resource or membership. Those are categorically different events. One is administration. The other is punishment.

AFPUB-2026-GEN-002-DRAFT01 does not preserve that distinction. It begins with a potentially useful idea: give every Resource Member a private view of possible discrepancies against applicable resource policies. Review the records periodically. Automate checks where a machine can reliably compare data. Notify a member promptly. Send reminders. Let the member correct an error and let staff see where assistance is needed. A registry that maintains an address book should want the address book to be accurate, and the people named in it should be able to see and repair the evidence on which it relies.

The draft then crosses the line. If a matter remains unresolved for a period that staff will define, staff would be notified. AFRINIC could undertake a more exhaustive investigation and take further action. Staff would define and publish rules concerning the withholding of services, revocation of resources or closure of membership. The system therefore does not merely offer a better view of the ledger. It creates a route by which a ledger entry can be made to carry a punitive consequence.

That route is illegitimate in principle. AFRINIC exists to maintain unique and accurate number-resource records and to perform the narrow coordination necessary for networks to interoperate. It did not receive police power from a state. It was not constituted as a regulator. Its Policy Development Working Group is not a legislature, its mailing list is not a demos, its Board is not a sovereign cabinet and its staff are not prosecutors or judges. AFRINIC can administer its records. It cannot use control of those records as economic force against the networks that depend on them.

This conclusion does not depend on whether the dashboard is accurate, private, transparent, phased or reviewed by a human being. Those qualities matter inside a legitimate administrative function. They cannot turn an illegitimate punitive function into a legitimate one. Due process governs how a holder of authority should exercise power; due process does not create authority where none exists. A beautifully documented procedure for an institution to do what it has no mandate to do remains an overreach.

What the draft actually proposes

At the evidence cutoff of 9 August 2026, AFRINIC’s current-proposals index listed AFPUB-2026-GEN-002-DRAFT01 as “Under Discussion”. It was not adopted policy, and the reviewed evidence does not show that it had altered any member’s services. The proposal is dated 30 April 2026, AFRINIC reports that it was first posted to the RPD list on 26 May, and the staff impact assessment is dated 23 June.

The document’s own version labels are inconsistent. Its identifier says DRAFT01 and its revision history describes Version 1, while a header says 3.0 and the proposals index says Version 1.0. That discrepancy should remain visible. It is not evidence of punishment or implementation, but it illustrates why a consequential system cannot treat a single institutional label as self-explanatory. If AFRINIC cannot present the version identity of the proposal consistently, members are entitled to insist that every future dashboard result identify the exact policy text, version, record, timestamp and test that produced it.

The operative notice sequence contains four steps before any separate investigation. First, the dashboard would be reviewed periodically as resource policies change. Second, detected non-compliance would produce an automatic notice to the member. Third, an open issue would generate reminders. Fourth, an unresolved issue that has persisted for a staff-defined period would be brought to staff attention. The proposal specifies neither the review interval nor the reminder cadence, the number of reminders, the length of persistence, the severity categories or the point at which a person must verify a machine result.

The staff assessment supplies six example labels: “Policy compliant”, “First notice sent”, “2nd notice sent”, “Remediation in Progress”, “Escalated” and “Closed”. These are implementation examples, not enacted definitions and not normative states written into the proposal. No criteria specify how an account enters a state, which transitions are allowed, what “Closed” means or what consequence follows “Escalated”. Closed might mean corrected, dismissed, completed or subjected to an adverse measure. Escalated might mean a request for a hostmaster to look at the evidence.

It might also become the institutional precondition for a sanction process. A user interface cannot be allowed to conceal that difference.

AFRINIC staff identifies five possible families of automated checks. The system could inspect WHOIS contact accuracy, the validity of abuse-c information, consistency involving route objects, relevant RPKI Route Origin Authorisation coverage and reverse-DNS requirements. The assessment anticipates timestamped transitions and email notifications. A member would see only its own dashboard, while authorised AFRINIC staff could see dashboards across the membership. Hostmasters would work with members to remedy findings and minimise revocations, and AFRINIC expects recruitment and associated financial cost, also connected to MyAFRINICv2.

Each check can contribute to better records. None should be permitted to pronounce guilt. A contact field can be unreachable because a record is stale, a message failed or the test is poorly specified. A route object can differ from an observation because several registries, time windows or operational designs are involved. A network may intentionally make no route announcement. ROA coverage can be measured, but the ability to measure something does not make that thing universally mandatory. Reverse DNS may be tested, yet the legal and operational meaning still depends on the exact adopted obligation.

The more diverse the inputs, the more dangerous it is to compress them into a single moral-looking status.

An accurate dashboard should therefore speak the language of evidence: “this source reported this value at this time; this adopted rule requires this record; here is the discrepancy; here is how to correct either the source or the registry record.” It should not speak the language of verdict: “the member is non-compliant”, “the member is escalated”, “the member is closed”. The former describes what the bookkeeper knows. The latter suggests a power to judge the subject of the record.

The sacred boundary: record-keeping is not punishment

The registry layer is justified by a narrow technical need. Internet number resources must remain unique. Records must be sufficiently accurate for coordination. Control information, security assertions, transfer records and an audit history can help networks rely on the shared system. The record describes operational and legal reality; it does not create that reality. AFRINIC keeps the ledger because the ledger is useful to networks. Networks do not acquire legitimacy because AFRINIC has chosen to recognise them.

This ordering is the heart of the matter. Once the keeper of a ledger begins to believe that the record is the source of the rights it records, administrative dependence is transformed into imagined sovereignty. The institution starts with the practical ability to change a database and mistakes that capability for the authority to decide who deserves to remain in it. Scarcity, habit, technical complexity and years of deference can make the mistake feel normal. They cannot make it lawful or legitimate.

A house-address registry does not gain the power to punish a resident because removing the address would cause serious harm. The capacity to cause harm is evidence of dependency, not a mandate. In the same way, AFRINIC’s ability to withhold a registry service or revoke a record does not prove its authority to use that ability as punishment. The more essential the record is to a running network, the more strictly the registry must refrain from turning clerical control into coercion.

Rules still matter. A registry may define the information needed to keep unique and accurate records. It may ask for evidence that a transfer, contact or technical assertion can be recorded correctly. It may explain that a record is incomplete. It may refuse to place a false statement in the ledger. It may preserve a disputed notation while the competent authority resolves the underlying matter. It may report suspected illegality to the appropriate public authority and comply with a valid order from a court, regulator or government. Those are compatible with record-keeping.

Punishment is different. Deciding that conduct deserves a penalty, withholding an unrelated essential service to compel behaviour, revoking operational resources as a sanction, closing a member to express institutional disapproval or using a registry status as a substitute for adjudication are exercises of coercive public power. They belong exclusively to sovereign legal systems. Courts can hear evidence and issue binding orders. Regulators can exercise authority granted by law. Governments act through public mandates and remain subject to constitutional and judicial constraints.

AFRINIC possesses none of those foundations merely because networks use its database.

The difference cannot be cured by consent theatre. Resource Members sign an RSA because interacting with the established registry is often the practical way to obtain and maintain number-resource records. That contract can organise the exchange of services and information. It can set administrative conditions for accurate performance. But a private contract does not turn AFRINIC into a sovereign. A contract clause drafted by the service provider cannot grant that provider the general power to punish.

Where a genuine contractual dispute arises, AFRINIC can communicate its position, preserve the evidence and seek enforcement through the competent legal forum. It cannot be claimant, adjudicator and executioner merely because it controls a critical administrative switch.

Community consensus cannot cure the defect either. The PDWG is an open coordination forum, not a legislature representing every resource holder, every affected customer or every African state. Attendance is not citizenship. Participation on a mailing list is not a delegation of sovereignty. Rough consensus can help a voluntary technical system identify workable common practices. It cannot vote coercive authority into existence. Even unanimous approval among participants would not transform a private registry into a court or regulator.

Nor can the Board manufacture the missing mandate. AFRINIC’s Bylaws put the company’s affairs under Board direction and supervision, allow delegation and give the CEO responsibility for day-to-day management. Those provisions distribute authority within a company. They do not expand the company beyond its lawful nature. A board can direct the registry’s administrative work; it cannot declare itself the source of public punitive power. Delegating such a claim to staff makes it no stronger.

The draft’s provision for Board “special measures” may be intended to protect essential infrastructure during exceptional circumstances, but an internal exception to an illegitimate punishment system does not legitimise the system.

This is why human review, notice, cure and appeal—although useful for correcting records—cannot answer the foundational objection. Suppose the dashboard cites every source, a hostmaster confirms every discrepancy, the member receives 30 days, an internal panel hears a challenge, the Board records reasons and the software preserves a perfect audit log. AFRINIC would still be a registry, not a sovereign authority. The process might reduce factual error. It would not create jurisdiction to punish.

The question must therefore be asked in the right order. Not: what safeguards would make AFRINIC’s sanctions fair? First: does AFRINIC possess authority to punish at all? The answer is no. Once that answer is fixed, the role of safeguards becomes clear. They should make the bookkeeping accurate, contestable and reversible. They must never be treated as the ingredients from which punitive power can be assembled.

The RSA does not confer sovereignty

The strongest contrary argument begins with the Registration Service Agreement. Resource Members undertake to comply with adopted policies. AFRINIC has existing review functions. The RSA discusses cooperation, breach, termination, liability and appeal. Clause 4(b)(iii), according to the reviewed text, links noncooperation with a utilisation review to listed consequences that include revocation, withholding of services, effects on future requests and closure.

The termination sequence includes written notice of intention, an invitation to show cause or take remedial measures, a 30-day period in which the member may state grounds against termination, and AFRINIC’s assessment of those grounds or remediation.

That language is evidence of what AFRINIC’s contract claims and how the organisation has tried to structure its dealings. It is not proof that AFRINIC possesses the authority claimed. The distinction is essential. A private party cannot acquire sovereign power by inserting a punitive remedy into its own standard agreement. The existence of words such as “revocation” and “termination” may explain how an institutional workflow could cause harm; it does not settle whether the registry is entitled to impose that harm as punishment.

Even on its own terms, the RSA does not allow a dashboard flag to perform every step. A machine-reported mismatch is not the same as refusal to cooperate with a review. An automatic notice is not necessarily the particular written intention to terminate. A staff-defined persistence period is not the RSA’s 30-day response period. A red state does not prove a breach. Those textual limits expose the immediate drafting problem, but the deeper doctrine goes further: satisfying the contract’s internal sequence still would not transform AFRINIC into a sovereign enforcer.

If a member supplies false information that makes accurate registration impossible, AFRINIC can state the discrepancy and seek correction. If the parties disagree about their contractual rights, they can use lawful dispute-resolution mechanisms and courts. If conduct violates legislation or regulation, the competent public authority can act. AFRINIC can then update records to reflect the lawful result. That sequence preserves the difference between evidence, adjudication and administration. The dashboard proposal instead risks collapsing them inside the institution that controls the ledger.

The RSA’s liability language makes that collapse more troubling. The reviewed agreement limits each party’s liability to the greater of USD 100 or the member’s payments in the preceding six months, subject to the contract’s qualifications. This statement does not predict damages in any particular case. It does reveal an asymmetry: a registry-side decision affecting an operational resource can impose losses far beyond the contractual exposure of the institution making the decision. The ability to cause large harm while carrying limited responsibility is a reason to narrow the registry’s role, not to elaborate its punishment procedure.

It is tempting to answer the asymmetry with stronger review and compensation. Those may be valuable where AFRINIC makes an administrative error. They do not purchase punitive authority. Power and liability should never detach, but symmetry alone is not enough: even an institution willing to pay full damages does not thereby become entitled to punish. The correct design prevents the registry from using its core function as a sanction in the first place.

The strongest defence—and why it fails

The proposal’s administrative case is substantial. Manual reviews can be slow, uneven and hard to audit. Different members may receive different levels of attention. A private dashboard can inspect everyone on a common schedule, reveal a discrepancy early, send reminders, preserve timestamps and give the member and hostmaster a shared remediation history. Automation can reduce ordinary transcription mistakes and help staff focus on records that genuinely need human attention. Member-only access can reduce reputational exposure. Additional Hostmasters can answer questions and assist with corrections.

A phased implementation can begin with reporting while the institution learns which checks are reliable.

The history also provides an operational comparator. LACNIC’s policy record describes automated checks where possible, confirmation before recovery steps, opportunities for contact and cure, a maximum three-month public period and later deletion of NS records. That record demonstrates that automated checks and staged workflows can be built. It does not establish legal or institutional authority for AFRINIC. Different contracts, jurisdictions, organisations and histories matter, and repetition by another registry cannot turn a category error into a mandate.

The best version of the defence says that the dashboard would constrain power rather than create it. AFRINIC already performs reviews, so a visible and logged system would make existing practice less surprising. A machine output could remain a prompt for human inspection. Written procedures could replace scattered discretion. A record of notice, evidence, correction and reversal could protect a member when memories differ. These are genuine advantages.

They support an assistance dashboard. They do not support enforcement. The defence fails at the precise moment it moves from “the dashboard can make records and communication better” to “the dashboard can help AFRINIC punish more consistently”. Consistent overreach is still overreach. Transparent coercion by an institution without sovereign authority is still coercion without authority. A human being pressing the button does not change the institutional nature of the button.

The claim that the dashboard merely disciplines power AFRINIC already has also assumes the answer. AFRINIC has practical control over records and contractual influence because operators depend on coordination. Practical control is not sovereign authority. Existing exercise does not establish legitimate origin. Long habit does not convert convenience into jurisdiction. If the supposed power consists of exploiting a member’s dependence on the address book, the dashboard should not discipline that power; it should separate the address book from it.

This rebuttal does not require abandoning the useful system. It requires a binding architectural rule: every automated output is evidence for record maintenance and member assistance only. No dashboard state may itself open a punishment track, withhold a service, alter eligibility, revoke resources, close membership or weaken the operational standing of a network. A disputed matter that genuinely requires legal enforcement must leave the registry workflow and enter the competent sovereign process.

How a proper bookkeeper’s dashboard would work

A lawful, useful design begins with a modest vocabulary. It shows an “observation” or “record discrepancy”, not a verdict of non-compliance. It identifies the exact source and the time at which the source was checked. It cites the adopted policy or record requirement that makes the data relevant. It explains whether the machine compared two fields, tested reachability or detected an absence. It distinguishes what the software observed from what a person has verified.

The member can then correct the underlying record, explain why the observation does not reflect an applicable obligation, or submit evidence. AFRINIC logs the submission, assigns it to an identified administrative role and records the resolution. A reversal is not hidden; it appears with the same clarity as the original notice. Historical information is retained only for a defined administrative purpose, with access and accuracy controls. Aggregate reporting can show how many observations were generated, how many were confirmed as record errors, how many were corrected, how many were reversed and how long each stage took.

The status vocabulary should stop at the condition of the record. “Check pending”, “member notified”, “correction received”, “record updated”, “observation unresolved” and “administrative review complete” can describe work without pretending to adjudicate misconduct. The word “Escalated” should not be used unless it means only that another bookkeeper or supervisor will inspect the record. “Closed” should describe closure of the administrative ticket, never closure of the member.

Most important, every link to punishment must be removed. The dashboard must not feed service withholding, resource revocation, membership closure, future-request eligibility or any comparable penalty. Staff instructions must prevent the use of its states as shortcuts in unrelated decisions. The Board’s role should be to enforce this boundary and protect continuity, not to grant discretionary exceptions from sanctions the registry should not impose.

Where a record cannot truthfully be changed because the underlying facts remain disputed, AFRINIC can preserve the present entry, add a neutral notation and identify the route for lawful resolution. Where a court, regulator or government with jurisdiction issues a valid order, the registry can implement the administrative consequence of that order. This is not passivity. It is disciplined coordination: the body qualified to decide acts, and the record-keeper accurately reflects the result.

Such a dashboard would also clarify the relationship between objective and qualitative questions. A machine can report that a value differs, a field is absent or a message was not delivered. It should not decide whether a business has sufficiently justified need, whether an operational choice is morally acceptable or whether a member deserves to retain critical resources. Qualitative disputes belong to human institutions with lawful authority, and punitive disputes belong to sovereign legal systems.

The history shows why the line must be explicit

AFRINIC’s dashboard idea has evolved across several attempts. In March 2019, the organisation advertised a student or internship project to identify compliance issues, design metrics and develop a dashboard and API for Hostmasters. That was exploratory work, not an adopted sanction mechanism. A proposal entered the record in July 2020. At AFRINIC-32 on 17 September, the co-chairs found no rough consensus. Jordi Palet appealed on 1 October, arguing in part that automation could improve consistency and notice and that implementation details could remain operational.

AFRINIC’s appeal index records publication of a report on 18 February 2021, but the exact disposition is not asserted because the reviewed indexed material did not independently establish it.

The 2021 predecessor draft was more explicit about consequences. Submitted on 9 November, it contemplated a path from public listing to removal of reverse-DNS NS records after two months and resource recovery with removal of the holder’s records after three months. AFRINIC staff assessed the draft on 15 November and recommended limiting the system to visibility while leaving RSA contract management to the Board acting through management. At AFRINIC-34 on 18 November, discussion addressed privacy, PDP scope, staff discretion, assistance to members and public versus private status. The meeting record says rough consensus was reached.

Last Call ran from December 2021 into January 2022. Consensus was announced on 14 January 2022 and a ratification report was sent to the Board. An appeal was later set aside on 9 August 2022 as inadmissible because the appellant had not shown a failed attempt to resolve the matter with the chairs or working group. The committee did not reach the merits. AFRINIC’s proposal history then recorded on 4 February 2026 that the proposal was not ratified by the Board and had expired. The page gives no reason, so none should be invented.

The 2026 text improves some details. It removes the predecessor’s fixed two- and three-month milestones. The implementation described in the assessment is private to each member and authorised staff rather than a public compliance list. Both changes reduce obvious risks. But the current proposal does not sever punishment from the dashboard. It replaces fixed timing with a persistence period chosen by staff and leaves staff to define withholding, revocation and closure procedures. The form of discretion changes; the prohibited function remains.

The lesson of the history is not that a more careful draft might eventually make registry punishment acceptable. It is that repeated drafting has failed to respect the category boundary. Visibility and correction belong in a registry policy. Punishment does not. The right revision is not a longer sanction section. It is deletion of the sanction connection.

Data protection is a floor, not the source of the boundary

AFRINIC’s legal assessment raises important questions about the data behind the dashboard: what member and personal data will be collected, whether third-party sources will be used, how determinations will be made, how long information will be retained, how accuracy will be checked and how a member can challenge an input. The proposal publishes no complete data inventory, retention schedule, algorithm catalogue, provenance design, accuracy standard or processor list.

Mauritius’s Data Protection Act 2017 and the Data Protection Office’s guidance discuss rights for natural-person data subjects involving access, correction or restriction, objection and solely automated decisions with legal or similarly significant effects. A Resource Member is a legal entity, so the application of those protections depends on which personal data, which natural person and which consequence are involved. The evidence does not establish that every company-level dashboard state would violate that law. It does establish the need for precise data design.

But data-protection compliance cannot supply the authority AFRINIC lacks. A registry might collect data lawfully, retain it proportionately, explain the logic, offer human intervention and correct every error promptly. It still would not become a sovereign enforcer. Privacy law can constrain the processing of evidence. It does not convert the processor into a court.

The same distinction applies to an internal appeal. An appeal route can help a member correct an AFRINIC record. The PDWG Appeal Committee, however, deals with disputes about the co-chairs’ process under the CPM. It is not a tribunal deciding the merits of a dashboard accusation or a registry sanction. RSA clause 13, as reviewed, is framed around an organisation appealing an assigning registry to a parent registry, and its fit for an AFRINIC dashboard dispute is unclear. Creating a new internal merits panel would improve error correction but would not confer public jurisdiction.

The economic cost of confusing a record with a verdict

A bad status can impose cost before any formal action. Engineers may have to reconstruct route data. Registry staff may have to trace policy versions. Managers may have to assess whether a notice threatens services. Lawyers may have to determine whether an automated message is merely informational or the first step in an asserted contractual process. An exact, evidence-rich request to correct a record can reduce those burdens. A vague “Escalated” state multiplies them.

Smaller operators bear a larger relative cost because legal and remediation work is partly fixed. A new entrant may not have dedicated registry or compliance staff. A large multinational has more expertise but also more routing arrangements, records and business contexts capable of producing misleading comparisons. Customers and public-interest networks benefit from accurate data, but they also bear the external cost when an administrative dispute reaches a live service. AFRINIC itself must pay for engineering, Hostmaster capacity and communication, and it assumes litigation and reputational risk if its system overreaches.

The proposed private access model limits public disclosure, which is sensible. It does not eliminate the risk that an institutional label travels. A leaked or informally repeated “Escalated” status could be treated by a customer, lender, insurer or transaction counterparty as proof that a neutral authority had found wrongdoing. That is a risk inference, not a claim that leakage has happened or will happen. It is another reason not to give an administrative state the vocabulary or consequence of a verdict.

There is also a behavioural cost. An assistance dashboard invites a member to repair records quickly because correction is the purpose. A punishment-linked dashboard tells the member that every ordinary reply may become evidence in a case controlled by the same institution. Engineers call counsel before answering. Informal cooperation becomes defensive correspondence. Staff queues lengthen, provisional labels last longer and a system intended to reduce friction creates a new layer of adversarial expense.

The distortion can reach the institution itself. Metrics make some work legible to management. Staff may begin to optimise counts of notices, escalations or closures because those are easy to report, even when the underlying obligation requires context. An example state becomes a performance category; a performance category becomes a budget justification; a budget justification becomes an entrenched function. Once staff, software and incentives are built around punishment, restoring a thin registry becomes harder.

The correct response is not a more sophisticated enforcement score. It is purpose limitation at the institutional level. The dashboard exists to improve record accuracy and member communication. Data collected for that purpose must not acquire a second life as a penalty trigger, eligibility screen or reputational credential. A new use requires more than notice; punitive use is outside AFRINIC’s role altogether.

Evidence from prior disputes does not enlarge AFRINIC’s role

Materials from the Number Resource Society, LARUS and BTW provide important context for the consequences of registry action. The NRS POA Start Pack raises questions about suspension, termination, derecognition and member remedies. An AFRINIC letter hosted by NRS reproduces RSA review and revocation language from a disputed setting. LARUS published a statement supporting Cloud Innovation, contesting AFRINIC’s conduct and alleging harm to customers. BTW has separately analysed sanctions-screening continuity and cross-border compliance costs.

Those materials are part of the evidence record, but the principle here does not depend on treating every disputed allegation as an adjudicated finding. They show why the institutional boundary matters in practice: registry actions can reach networks, customers and economic activity. They do not need to be balanced against AFRINIC’s self-description as though “stewardship” and “community” were independent sources of authority. AFRINIC’s official sources prove what it proposed, what its instruments say and what its staff assessed. They cannot prove a sovereign mandate the institution never received.

NRS’s role must remain bounded as well. It advocates, researches, convenes and represents members who expressly authorise it. It does not operate AFRINIC’s registry, RPKI, WHOIS or RDAP, administer appeals or elections, hold custody or guarantee continuity. That boundary reinforces rather than weakens the central doctrine: institutions must not claim functions merely because they care about the outcome. AFRINIC remains the subject because the proposed status and sanction connection would operate through AFRINIC’s administrative control.

This article likewise does not claim that the 2026 draft has already harmed a member. It remains under discussion. No final metric catalogue, persistence period, severity scheme, human-review rule, correction workflow, launch date or dashboard-specific challenge route is fixed. The six states are examples. The prior Board non-ratification has no published reason in the reviewed record. The exact result of the 2020 appeal is not asserted. These uncertainties restrict factual claims about implementation. They do not make the normative boundary uncertain.

The only defensible counterfactual

There are two legitimate choices. AFRINIC can decide not to build the dashboard, accepting the continued cost of fragmented notices and manual checks. Or it can build a visibility-and-correction dashboard that is technically and institutionally incapable of punishment. There is no third legitimate option in which enough procedure turns the record-keeper into an enforcer.

The visibility design preserves almost every serious benefit offered by supporters. Members receive earlier notice. Checks run on a common schedule. Records and obligations appear together. Staff can see where assistance is required. The system logs notices, submissions, corrections and reversals. Aggregate performance data can reveal whether a test generates excessive false positives or whether staff capacity is adequate. The interface becomes a shared maintenance surface rather than a hidden scoring system.

Its bright-line constraints are equally important. No machine output is dispositive. No state declares misconduct. No status affects a service, resource, membership, standing or future request. No persistence clock turns an observation into a sanction case. No Board exception is needed to rescue essential infrastructure from an AFRINIC punishment because AFRINIC imposes no such punishment. If a legal dispute arises, the competent court, regulator or government decides it, and AFRINIC performs the narrow administrative act required by the lawful result.

This design does not weaken compliance. It locates compliance where it belongs. The registry verifies facts relevant to its records. Members correct inaccuracies and explain operational context. Public authorities enforce public law. Courts resolve disputes. Each institution does its own job, and none borrows the registry’s technical choke point to imitate another.

The draft’s own legal assessment already recognises the danger of blurring policy and contract enforcement, delegating essential terms, omitting due-process safeguards, leaving data governance undefined and presenting qualitative judgments as objective metrics. The right response is not to cure each omission and proceed with sanctions. It is to take the warning to its logical conclusion: the sanction layer must be removed.

AFRINIC may know that a record is inconsistent. It may tell the member. It may ask for correction. It may preserve evidence and assist. It may maintain an accurate ledger after a competent authority has acted. It may not transform knowledge into a punishment of its own. The dashboard should end where sovereignty begins.

Sources