Skip to main content

Governance / Case File

CASE FILE

Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institutional BreakdownLegal and Policy ConflictElection and Control Risk
CASE FILE signal visual
Governance / Case FileCASE FILE
Active Dossiers1 Live Case

AFRINIC saga currently tracked end-to-end.

Primary DomainGovernance

Institution legitimacy and continuity risk mapping.

MethodSignal + Timeline + Failure Paths

Primary-source based timeline and risk analysis.

Decision ValueHigh

Used for continuity and policy exposure planning.

Latest Coverage

Latest from CASE FILE

758 articles

Editorial illustration of sixty domain-name nodes converging on a court docket across a jurisdiction boundary.

CASE FILE

Sixty Names Were Defendants; the Statute Still Defined the Claim: Harrods v Sixty Internet Domain Names

The caption did something unusual: it named sixty domain names as defendants. That procedural choice made a dispute over the Harrods name look, for a moment, like a dispute over things rather than people. The Fourth Circuit’s answer was narrower. The names could be before the…

Sep 3, 2026
CIRA and 20 cards at a stone threshold, with a separate glass screen on the route beyond

CASE FILE

CIRA’s 20-Endorsement Threshold Has a Separate Conflict Test

CIRA’s September endorsement window gives members a route onto the election ballot. The twenty-supporter threshold works alongside conflict-of-interest rules that treat the two nomination routes differently.

Sep 3, 2026
Four separate text-free stations show a proposal sheet, a decision token, an abstract source branch and a sealed release package, linked only by thin handoff lines.

CASE FILE

At Python, an Accepted PEP Is Neither a Release Commitment Nor an Implementation Receipt

Python’s public process deliberately separates the decision on a proposal from the work of making it real. A PEP may be discussed by contributors, resolved by the Steering Council or an approved PEP-Delegate, implemented in CPython, merged to a particular branch and eventually…

Sep 3, 2026
A separate source-code slab, amber interruption gate, sealed package on three supports, project council ring and elevated corporate ring linked only by a thin reporting line.

CASE FILE

At Apache, a Release Vote Is Neither a Code Veto Nor a Board Technical Decision

At the Apache Software Foundation, a person can commit code, a qualified voter can stop a code change, a PMC can issue a formal release, and the Board can oversee the Foundation. Those acts sit in one institution, but they do not carry the same authority. Treating them as one…

Sep 3, 2026
Three separate circular review stations connected by one flowing paper path: public comments, technical decision and organizational consent.

CASE FILE

At OASIS, a Public Review Is Neither the Final Vote Nor a Suggestion

An OASIS standards document can collect comments, pass a Technical Committee ballot and still not be an OASIS Standard. Those are not redundant ceremonies. They are separate decisions with different records, constituencies and thresholds.

Sep 3, 2026
Three distinct revision cassettes ride one continuous identity rail while one server-side selector exposes feature, deviation and datastore layers.

CASE FILE

The Name Stayed the Same. The Module Did Not: RFC 9890

RFC 9890 makes a small registry correction with a large evidentiary consequence: a YANG module keeps its name and XML namespace across revisions, so identity alone can never tell an operator which definitions a system actually uses.

Sep 3, 2026
Four separate governance workspaces connected by bounded paths: foundation, technical coordination, open collaboration and independent project maintenance.

CASE FILE

OpenSSF Member Seats Stop at the Project Boundary

OpenSSF publishes a membership table with real fees, real representation routes and real Foundation-level benefits. It also publishes an unusually direct limit: a membership or sponsorship level does not decide a project matter, because project maintainers define that project's…

Sep 3, 2026
Abstract glass governance chamber receiving two separate entry paths, with a distinct oversight plane and independent project nodes.

CASE FILE

OpenJS CPC's New Community Vote Needs a Transition Receipt

This autumn, OpenJS Foundation’s Cross Project Council will replace two separate non-Impact voting paths with one Community Voting Member class. The Charter is unusually clear about the planned change: it names the effective election cycle, caps the new class at five seats and…

Sep 3, 2026
Two separate circular work surfaces joined by a transparent segmented bridge, with distinct abstract materials on each level

CASE FILE

CNCF's TAG-to-TOC Move Needs an Exit-and-Continuity Receipt

Three former Technical Advisory Group leaders entered the Cloud Native Computing Foundation's 2026 Technical Oversight Committee cohort. CNCF says they stepped down from TAG leadership because TOC members may not hold TAG lead positions at the same time. That is a useful public…

Sep 3, 2026
A violet identity prism stops at a transparent boundary; three local selectors pass through control modules and converge into a shared transit bank observed by separate probes.

CASE FILE

The Slice Identifier Reached the Transport Edge. The Guarantee Still Had to Be Built: RFC 9889

RFC 9889 turns 5G network slicing into a chain of accountable translations: the mobile domain can name a slice, but the transport domain must still classify traffic, allocate resources, install state and prove the resulting service.

Sep 3, 2026
A signed violet token reaches a four-gate evidence chamber while a separate cyan call capsule is still approaching and the result ring remains dark.

CASE FILE

The Token Arrived Before the Call. Verification Still Had to Wait: RFC 9888

The signed identity token reached the destination service first. The telephone call was still crossing a path that could not carry that token with it. RFC 9888 makes this split useful for legacy networks, but it also leaves an operational obligation: two arrivals on two channels…

Sep 3, 2026
Separate cyan secure and amber legacy TACACS+ corridors remain isolated after the protected path stops, with no fallback bridge.

CASE FILE

The Secure Channel Failed. The Client Was Not Allowed to Fall Back: RFC 9887

RFC 9887 turns a secure-transport upgrade into a rule about authority: when the protected TACACS+ path fails, reachability of the older path does not authorize the client to use it.

Sep 3, 2026
Envelopes in a glass cloud stand beside a separate DMARC console with three brass knobs and a DNS cable

CASE FILE

Outsourcing Email Does Not Assign the DMARC Work

A survey of 99,300 domains puts an old procurement assumption under pressure: a hosted mailbox and a working domain-authentication programme are not the same purchase.

Sep 3, 2026
A verified identity hierarchy and separate certificate and endorsement artifacts stop at a boundary before an empty sensor-scanned airspace.

CASE FILE

The Tag Resolved. The Aircraft Was Not Located: RFC 9886

The reverse-DNS answer arrived in milliseconds: a public key, a registration certificate and a static Remote ID record. The airspace display was still empty. RFC 9886 explains why both screens can be correct — it makes an aircraft-related identifier resolvable without turning…

Sep 3, 2026
A single amber capability beacon shines over uneven receiver paths while complete geometric data modules travel separately toward a closed change-authority gate.

CASE FILE

The Capability Was Advertised. The Protocol Was Not Authorized: RFC 9885

A zero-length IS-IS capability can be visible on every change-board screen and still be limited public evidence to authorize one configuration command. RFC 9885 makes that limit explicit: the advertisement is management information, not a protocol trigger, while safe MP-TLV…

Sep 3, 2026
A faceted core inside a glass test enclosure connects to three sockets beyond the enclosure

CASE FILE

ITU’s Agent-Security Agenda Makes Deployment Part of the Test

A draft programme for ITU’s 7 September workshop asks what evidence integrators should demand from suppliers of agents, tools and models. That puts the security claim where the system acquires its powers—and raises a question about how far a supplier’s earlier test can travel.

Sep 3, 2026
An amber diagnostic packet and label stack cross several obscured branching transit planes before only the egress aperture confirms the endpoint in green.

CASE FILE

The Path Label Reached the Egress. The Transit Route Stayed Unseen: RFC 9884

One green LSP Ping result can answer a narrow and valuable question: the egress processed a Path Segment Identifier in the control-plane context named by the probe. It cannot reveal the transit route that delivered it. RFC 9884 makes that boundary operationally useful—provided…

Sep 3, 2026
A cyan signing chamber marks blank request plates while a separate violet key-establishment core remains untouched beyond an amber policy gate and issued tiles retain return conduits to the signer.

CASE FILE

The Request Was Signed. The Other Private Key Was Still Only Asserted: RFC 9883

A certificate request can carry a valid signature and still offer no technical proof that the requester holds the private key named by its new public key. RFC 9883 does this deliberately. It turns the gap into an explicit policy choice—and a revocation dependency that operators…

Sep 3, 2026
An amber message splits into a direct lattice-signing path and a digest-and-attribute path while an isolated blue token sits above the computation and a violet intermediate crosses into a separate custody chamber.

CASE FILE

RFC 9882 Put SHA-512 in the Field. It Did Not Always Use It

A CMS record can truthfully name SHA-512 while that algorithm contributes nothing to the signature being checked. RFC 9882 requires exactly that combination on one of its two ML-DSA paths. The apparent contradiction disappears only when an auditor follows the bytes rather than…

Sep 3, 2026
Four abstract evidence lanes pass through a central provenance matrix before reaching a blank standards folio

CASE FILE

WebAuthn's Report Has Four Browser Columns. Independence Needs a Key.

W3C's new WebAuthn Level 3 Recommendation links a fixed test report with four browser columns. The transition record adds that part of Chrome's implementation differs from Edge's. That caveat is important—and incomplete. Product names show where tests ran; they do not tell a…

Sep 3, 2026

Member Unlock

Restricted Profile Intelligence

Login is required to unlock full profile briefings and deep-dive sections.

Only for Strategic Circle

Strategic Circle Briefing

Join to unlock strategic briefings after signing in.

Join Strategic Circle
Only for Leadership Alliance

Leadership Alliance Briefing

For qualified IP-asset owners and management; sign in to unlock alliance briefings.

Join Leadership Alliance

Session Map

Active Dossiers

AFRINIC Saga

Multi-year governance and legal crisis with implications for RIR accountability worldwide.

Open AFRINIC Saga