Summary
- AFPUB-2012-GEN-001-DRAFT-02 proposed a scheduled WHOIS contact-validation programme, an invalid-record marker, public reporting and, after one year, a step in which AFRINIC would “claim the number resources back”; the draft never gained consensus.
- Contacting members, checking whether published fields still work, recording confirmation and correcting demonstrated errors are ordinary duties of a private registry bookkeeper. They did not require a new sovereign mandate.
- A policy could still have served a valuable purpose by binding staff to recurrence, notice, measurement, audit trails, correction routes and public reporting. That is accountability for administration, not a transfer of coercive power.
- A bounced email or continued silence is evidence about a contact channel, not a verdict about entitlement, control, misconduct or abandonment. An evidential marker must therefore be kept separate from any consequence against number resources.
- The 2013 meeting sharpened the distinction: staff reported that an existing project had already obtained updates from about 80% of contacted members, while participants disputed whether policy was needed and whether reclamation was too harsh. No consensus was found, and a 2014 record says the earlier proposal was withdrawn after AFRINIC cited its existing process.
Picture the small indignity at the start of a large institutional mistake. An engineer at an abuse desk sends a message to the address in a public registration record. The message returns. The mailbox may have been retired after a staff change; a domain may have been reconfigured; the responsible team may now use another address. The engineer still needs a human being who can act. A stale record has imposed a real cost.
Now picture the registry employee on the other side of that record. There is an obvious clerical job to do: ask the member to confirm the field, record the attempt, accept a documented correction and make clear to users what has and has not been verified. But there is also a sealed drawer that the clerk has no right to open. Inside it sits a different question: whether the organisation associated with the record may continue to use its number resources. A returned message supplies no key to that drawer.
AFRINIC’s WHOIS Database Clean-up proposal, published as Draft 02 in October 2012, put both activities on one escalation ladder. It proposed an initial cleanup, annual validation, confirmation when members sought additional resources or services, a first one-month email period, further communication after continued silence, an invalid-record mark, reporting and, one year after first contact, a step at which AFRINIC said it would claim the number resources back. The conflict was not over whether accurate contacts mattered.
It was over whether a private bookkeeper needed policy to do its existing accuracy work, and whether weak evidence about a mailbox could be converted into a consequence against network resources. The stakes ran from slower incident response at one end to disrupted operator continuity at the other.
A practical defect, correctly seen
The proposal identified an ordinary source of decay in public records. People change jobs. Organisations reorganise. Telephone numbers and email addresses change. Companies merge or are acquired. A field that was correct when entered can become useless without anyone staging an act of defiance. The draft’s account of these causes was persuasive precisely because it was mundane. Administrative data deteriorate when reality moves and the ledger does not.
That deterioration matters. Registration records are part of the Internet’s reliance surface. Network operators, abuse teams, counterparties and customers use them to find a responsible contact, route a question, assess a transaction or make sense of a disputed record. A bad address increases search time. An unqualified record can give false confidence. Repeated failures spread cost outward: the registry saves the effort of maintaining a field while many users each pay a small price trying to work around it.
None of this turns WHOIS into a deed registry, a court file or a licence. A registration entry is published evidence maintained by a private coordinator. It can be helpful evidence, poor evidence, current evidence or stale evidence. Its accuracy should be improved because accurate evidence makes coordination cheaper. But even an immaculate entry does not itself confer title, and an inaccurate one does not itself extinguish entitlement. The value of the ledger lies in disciplined description, not in a power to make the world conform to whatever its cells imply.
Seen in that light, most of Draft 02’s proposed work was uncontroversial bookkeeping. AFRINIC could contact members. It could ask them to confirm or update contact details. It could retain a history of attempts and changes. It could distinguish fields recently supplied from fields due for review. It could ask for confirmation when a member requested another service. It could measure the response to a maintenance exercise and report aggregate results. These activities fit the registry’s legitimate function: keeping a useful, qualified account of the information entrusted to it.
They did not require a new sovereign mandate because no sovereign act was involved. AFRINIC is a private company performing a narrow coordinating and recordkeeping function. It is not a state, legislature, regulator, police force, prosecutor, punishment body, confiscator or adjudicator. Contact validation remains clerical even when it is systematic, inconvenient or written into a policy. A meeting cannot enlarge it into public power by applause, and an institutional label cannot do so by assertion.
The draft’s three different propositions
The central analytical error in the 2012 proposal was not its desire for clean data. It was the failure to keep three propositions apart.
The first proposition concerned the bookkeeper’s existing duty. If AFRINIC publishes contact information as part of its registry, it should maintain the quality of that publication. Maintenance includes testing a channel, seeking correction and describing uncertainty accurately. The relevant question is whether staff did the work carefully: which field was tested, when, by what method, with what result and with what opportunity to correct a mistake.
The second proposition concerned institutional accountability. An internal activity can be intermittent, opaque or quietly abandoned. A policy can require annual recurrence, set notice periods, define evidence, require aggregate reporting and make staff answerable for performance. That is a real difference. It does not create the underlying clerical function, but it can make execution less dependent on managerial preference. It can also protect members by specifying what staff may infer, how quickly a disputed label must be cured and what records must be kept.
The third proposition concerned a consequence against the resource holder. Draft 02 said that persistent inaccuracy and failure to respond would, one year after first contact, lead AFRINIC to claim the number resources back. That was not merely a stronger version of correction. It was a change of category. The premise concerned evidence about contactability; the proposed endpoint concerned operational continuity and asserted entitlement. No number of intermediate reminders could supply the missing logical and institutional bridge.
Treating those propositions as stages of one process makes escalation look natural. First an email is sent, then another method is tried, then the record is marked invalid, then time passes, then the resources are claimed. The neatness of the sequence disguises the discontinuity. Steps one through three concern the quality of the ledger. The last step reaches beyond the ledger and purports to determine what may be done to the holder. Time does not transform the first kind of question into the second.
This distinction also explains why “cleanup” must be used carefully. Correction is legitimate bookkeeping. Removing duplicate characters, updating a proven contact detail, appending a date of confirmation or qualifying an unverified field improves the fidelity of the record. None of those acts punishes anyone. Resource-taking, by contrast, cannot be smuggled into the word “cleanup” as though it were merely deleting an obsolete row. A network resource is not dirt in a database, and a holder is not an error to be purged.
What an invalid marker can honestly mean
Draft 02 proposed marking a record invalid after continued non-response and further communication attempts. A carefully defined marker could have been useful. Public users need to know when the registry has recent evidence that an address is not working, or when it has been unable to obtain confirmation. Without a qualification, an old field may invite reliance it no longer deserves.
But “invalid” is dangerously broad. Does it mean the syntax is malformed? That a test email bounced? That no reply arrived within a period? That the named person left? That the whole object is untrustworthy? Or that the associated organisation has lost some claim? These meanings are not interchangeable. A responsible registry would label the evidential fact as precisely as the evidence allows: “email delivery failed on this date”, “contact not confirmed since this date” or “member response pending”, rather than issuing a general verdict.
A returned email proves only that a message did not reach that mailbox at that time. It may provide good reason to test another channel and ask for an update. Silence after several approaches may justify a stronger qualification of the contact field. Neither fact proves that the organisation abandoned the resources, ceased operating the network, lost control, used the resources improperly or committed misconduct. It does not show who holds contractual rights, what another contact channel would reveal or whether a contested consequence is lawful.
The burden of language matters because labels travel. An operator may treat “invalid” as a warning about fraud. A commercial counterparty may pause a transaction. A security team may infer that nobody controls the network. An automated system may collapse a field-level warning into an organisation-level score. If the registry has observed only a failed channel, its public notation must resist those larger inferences. Accuracy is not served by replacing an overconfident old field with an overconfident new label.
Draft 02 did not specify the exact fields of a public invalid label, its reliance meaning, privacy limits, appeal mechanism or rapid correction path. Nor did it establish how staff would distinguish a non-answer from a failure of the registry’s own message, an outdated object from an unreachable organisation, or a temporary outage from durable staleness. These omissions did not make validation impossible. They showed why policy, if used, should have concentrated on evidential discipline rather than on an endpoint against resources.
The clean design is simple in principle. Status follows evidence; it does not exceed it. The record preserves the date and method of a test. A member can see and correct the evidence. Users are told whether a field, not an entitlement, is unconfirmed. History is retained so that correction does not erase accountability. A dispute about the resource holder’s rights leaves the clerical lane and proceeds, if it must proceed at all, through applicable contract, law, due process and an independent competent forum. The database cell is never allowed to act as a verdict.
Khartoum: maintenance or policy?
When the proposal was discussed at AFRINIC-17 in Khartoum in November 2012, the meeting record showed that the most interesting disagreement was already visible. AFRINIC said that an activity concerning WHOIS data integrity was under way. Participants then asked whether policy was necessary when staff were already doing the work. One view held that policy would compel performance and make AFRINIC accountable. Another held that not every operational problem required a policy.
Both sides grasped part of the institutional problem. Staff did not need permission from a new policy to ask whether the registry’s own contact fields still worked. Waiting for policy would have been an odd abdication: a bookkeeper does not require legislation to reconcile the book. A contemporaneous AFRICANN exchange made much the same practical point by treating accurate-data maintenance as ordinary professionalism and asking why improvement could not begin without further proposals. Another message viewed the proposal as a possible trigger for cleanup.
These were participant views, not a source of power, but they neatly captured the difference between duty and impetus.
The accountability argument was nevertheless more substantial than a demand for paperwork. An undocumented project can produce a headline number without revealing its scope. It can validate easy cases and postpone hard ones. It can fade when priorities change. If public-record accuracy is a continuing service, members and users have reason to ask for a schedule, a definition of success, field-level measurements and a record of correction times. Policy can bind the registry as well as the member.
The 2012 discussion also included calls for broader scope, continuous or mandatory reporting and a public “shame list”. The phrase reveals a temptation that a sound accuracy programme should reject. Publication may be justified to inform reliance; humiliation is not a registry function. A field status should communicate what is known, not mobilise social pressure as a substitute for proof. The bookkeeper’s credibility grows when its vocabulary is neutral and exact, not when its notices are designed to stigmatise.
The co-chairs found no consensus and returned the proposal to the mailing list. AFRINIC’s annual report later listed it among five proposals discussed in 2012 and said none gained consensus at AFRINIC-17. That outcome did not mean accuracy was unimportant, and it did not adjudicate every proposed measure. It established something narrower and important: the draft did not acquire an adopted status in the recorded process. Its words remain evidence of an attempted design, not proof that the design was implemented or legitimate.
Nor would consensus have solved the authority problem. A policy community can decide how a private coordinating service should operate within its proper sphere. It can set a validation calendar, reporting rules and correction standards. It cannot vote sovereign power into existence. Even unanimous approval would not make an unreachable mailbox equivalent to abandoned resources or turn AFRINIC into a confiscator. The source of a claimed power has to be traced through the exact applicable instrument and authorisation chain; the warmth of a room’s assent is not a substitute.
The strongest case for a rule
The strongest counterargument deserves to be stated without caricature. Persistent inaccurate contacts impose costs on people beyond the member whose data are stale. Operators cannot reliably deliver notices. Abuse desks waste time. Counterparties face uncertainty. Voluntary requests can be ignored, and an internal staff initiative is not a durable service obligation. Without clear recurrence, deadlines, reporting and some credible endpoint, both members and AFRINIC may avoid accountability. On this view, policy is what turns a worthy intention into a dependable system.
That case is convincing up to the point at which “credible endpoint” becomes a euphemism for taking resources. A narrow policy could require annual review. It could define secure channels, a reasonable notice sequence, field-specific status labels, change histories, staff response targets, aggregate statistics and an appeal route. It could require AFRINIC to disclose how many records it tested, what share it reached, which fields changed and how quickly valid corrections were published. It could make silence visible without pretending silence proves more than it does.
The policy could also recognise an attributed member duty to keep information accurate. Draft 02 said members were committed through the Registration Service Agreement to do so, and AFRINIC’s legal adviser was later recorded as saying accurate contacts were already required by that agreement. An agreement may allocate duties between private parties. If a member has promised to update a field, failure to do so can be addressed under the exact agreement, with its terms, notice requirements, remedies and dispute provisions examined rather than assumed.
But a contractual duty to maintain contact information and a power to claim resources are distinct propositions. The first does not establish the second. Still less does it create sovereignty. The registry cannot leap from “this party promised accurate data” to “this failed mailbox authorises us to take the resources” without proving the applicable chain and respecting an independent route for contest. A general reference to the agreement is not enough; neither a proposal nor a legal adviser’s meeting response is a judgment on enforceability.
Proportionality follows the nature of the defect. If the defect is an unconfirmed field, the proportionate remedy is to qualify the field, seek confirmation, preserve evidence and correct it when proof arrives. If a service request depends on current contact information, the registry may ask for that information to complete the administrative request. If a separate contractual dispute arises, it must be addressed as that dispute, not pre-decided by the visual state of a WHOIS object. The response should repair the evidence before it reaches for the operator.
This answer does not make policy toothless. Quite the opposite: it gives policy a task it can legitimately perform and against which performance can be measured. Staff must run the schedule. Members must have workable ways to respond. Public users must be told what a status means. Corrections must be timely. Statistics must expose drift and delay. These obligations are more demanding than a dramatic threat written at the bottom of an escalation ladder, because they require the registry to do patient, inspectable work year after year.
Lusaka: the existing project comes into view
The directly connected discussion at AFRINIC-18 in Lusaka on June 19th 2013 clarified why the proposal had struggled to define its added value. Jean Robert Hountoumey again described unreachable person-object email addresses and the familiar causes: job rotation, organisational change, changed telecommunications details, mergers and acquisitions. He relied on the stated member obligation to keep information accurate and continued to seek periodic validation.
AFRINIC staff responded that an internal project already sought accurate member contact information. Staff said that about 80% of contacted members had responded and updated their information, and recommended that the policy might not be needed. The figure was encouraging as a report of activity, but it was not a performance audit. The meeting minutes did not provide the denominator, the dates, the fields tested, the sampling method, the evidence standard or an independent check. “About 80%” could not show whether the project covered the difficult residue or produced durable accuracy.
That informational gap strengthened the bounded accountability case. If staff were already performing the work, the question for a policy was not whether to confer authority but how to make the service legible. Which records entered the programme? How often did staff test them? What counted as a successful update? How were delivery failures distinguished from non-response? What happened to challenged labels? Aggregate answers would let members evaluate both the burden placed on them and the quality of AFRINIC’s administration.
The same meeting recorded the more fundamental objection. Participants criticised resource reclamation for bad contact information as too harsh. AFRINIC’s legal adviser replied that accurate contact details were already required by the Registration Service Agreement. Another view held that a policy would compel cleanup and make AFRINIC accountable. These interventions did not resolve the missing bridge. An asserted accuracy duty said nothing, by itself, about a lawful power to reclaim, while the appeal to accountability supported rules for staff performance rather than a coercive transformation of evidence.
The co-chairs again found no consensus and returned Draft 02 to the list. The record contains no later adoption, ratification or implementation of this draft. A May 2014 policy-list entry then said the earlier proposal had been withdrawn after AFRINIC advised that an internal process already handled WHOIS cleanup and general contact updates. That later statement closes the relevant procedural story. It does not establish that the internal process was comprehensive, continuously operated or sufficient; nor does it invite a backward reading of a different 2014 proposal into the 2012 draft.
The outcome leaves a useful institutional paradox. The proposal may have been unnecessary as permission for maintenance and valuable as a demand for accountability. Staff’s existing project answered “can the work begin?” but not “how will the work remain measurable?” Withdrawal removed the flawed escalation ladder, yet the official explanation did not prove that the remaining administrative programme contained the safeguards and disclosures that a narrow policy could have required.
Accuracy without dominion
Good registry governance begins with modesty about what a record can do. A registry can improve evidence. It can reduce uncertainty. It can make its own administrative conduct observable. It cannot turn the absence of evidence from one channel into evidence of absent rights, and it cannot treat its coordinating position as dominion over the networks that depend on the record.
That modesty serves practical interests. Overstated authority makes every maintenance error more dangerous. A misdirected notice, a broken mail system, a record attached to the wrong contact or a delay in processing a correction can become a threat to routing, customers, finance and business continuity if the validation system leads toward resource-taking. The registry bears only a fraction of those downstream losses. A bounded system reduces that asymmetry by ensuring that clerical judgments remain clerical.
It also improves data quality. Members are more likely to cooperate with a process whose statuses are exact, whose correction path is secure and whose consequences track the evidence. A theatrical process invites strategic behaviour: rushed confirmations, defensive correspondence and disputes over labels. A service-oriented process makes the easy action the honest one. It asks for the minimum proof needed to update the field and gives public users a clear account of freshness.
AFRINIC’s legitimate role in 2012 was therefore neither passive nor imperial. It was not required to leave stale fields untouched. It was entitled, as the maintainer of the ledger, to run disciplined accuracy work. But it had to stop at the boundary of the evidence. The returned envelope belonged on the evidence bench, beside the date, attempted channel and next request. The drawer marked resource control remained shut.
That is the enduring lesson of AFPUB-2012-GEN-001’s authority theory. The debate was not a choice between dirty records and harsh enforcement. It was a design problem with a better answer: maintain the ledger as a professional service, make the maintainer accountable, qualify uncertainty honestly and refuse to convert a stale contact into a private verdict. The proposal was strongest when it scheduled work the registry should already have been doing. It crossed the line when it made an evidential defect a bridge to taking resources.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
