Summary

  • ICANN’s Redaction Register landing page says the register will be updated as new Board materials are posted, but its linked workbook contains only FY17 through FY24. It has no item-level FY25 or FY26 record and its FY24 review-outcome fields were blank at the evidence cutoff.
  • This is not proof that annual review stopped. The Redacted Board Materials Archive reaches FY2026, and a 2025 version chain shows a meeting location released while a contract amount remained protected. The problem is that the archive, annual aggregates and individual pages do not replace a synchronized master index.
  • ICANN should publish a versioned redaction custody register in both machine-readable and human-readable form, generated with every Board publication and review. It can expose classification, authority, trigger, outcome and version lineage without exposing the confidential text.

Two live records tell different years

Open ICANN’s Redacted Board Materials Archive and the first fiscal-year heading is FY2026. The page then reaches back through FY2025 and earlier years, preserving originally published material that was later updated after annual review. It is evidence of a living process.

Open the Board Materials Redaction Register and follow its only workbook link. The tabs run from FY17 to FY24. There is no FY25 tab and no FY26 tab. The last fiscal-year sheet contains 29 records, ending with a 5 May 2024 IT outsourcing contract-extension item. Twenty-four of those records are marked as subject to annual review, yet the FY24 cells for removal, annual-review rationale, completion date, updated publication date and updated-material link were blank when the file was captured.

Both observations can be true without contradiction inside ICANN. The organization may maintain a current internal database. A newer workbook may exist but not be linked. Publication of the public matrix may simply have fallen behind. The archive itself shows that annual review did not vanish.

For an outsider, however, the contradiction is operational. The landing page says ICANN will update the register whenever it posts a new set of Board resolutions, minutes and briefing materials. The linked public object does not contain the later years that other public objects plainly contain. The observer cannot use an unseen internal record. Governance is measured at the interface it gives the governed.

The failure is not secrecy. It is synchronization.

The workbook was designed to be the join

The linked file is not a decorative transparency report. Across FY17 through FY24, it contains 399 rows. Its columns identify the meeting date, type of meeting, redacted document, subject, source link, redaction reason and code, annual-review eligibility, whether the redaction was removed, the annual-review rationale, review completion date, publication date of updated material, updated-material link and additional notes.

That schema performs a precise governance function. A redacted page alone tells the reader that something is missing. A register row says what institutional claim justifies the gap, whether the claim should expire, and where the record goes when it changes. It converts absence into a reviewable state.

The distinction matters because ICANN’s own guidelines do not treat every withheld fact alike. Draft or premature material, sensitive delegation information, confidential negotiation or business information and legal privilege are generally subject to annual review. Employment information, personal contact details, superseded drafts and material not considered by the Board generally are not. After 15 years, the guidelines call for publication at the next annual review unless a significant reason supports continued withholding.

That is a more mature design than a binary “secret/public” flag. Negotiation sensitivity may expire when the transaction is complete. A premature draft may become harmless once the decision is final. Personal data and privilege can remain protected. The register is where those different clocks are supposed to become visible.

Without current rows, the policy still exists but the public cannot follow its execution at item level. A rule that says “review annually” and a page that shows one later release are not the same as a maintained ledger showing the entire population, each classification and every outcome.

The archive proves the mechanism works—and why it is not enough

The strongest argument against an alarmist reading is on ICANN’s own archive page. ICANN says it completed the first annual-review cycle in December 2021 and created the archive to preserve the original versions of materials subsequently updated. It also says the archive will be updated after each annual review.

The 8 June 2025 Board resolutions provide the cleanest example. The archived original says a later document now discloses information in sections 1.a and 1.b. The current version names Seville, Spain, as the location of the ICANN84 Annual General Meeting. A contract amount remains redacted as confidential negotiation information.

That is not a failed transparency process. It is a discriminating one. The sensitivity of the location expired; the organization released it. ICANN concluded that the commercial figure still warranted protection. The public can compare the two versions and see that annual review did more than mechanically preserve the original black boxes.

But the example also demonstrates why the archive cannot take over the register’s job. The archive contains originals that later changed. It does not purport to be the denominator of all redactions. An item retained in full after review has no reason to enter an archive of updated originals. An item awaiting review may not appear there either. Nor does the archive give a common row for classification, next review, retained rationale and partial-release result.

An archive is a provenance store. A register is a state store. Asking one to perform the other’s job produces a biased picture: the successes that generated new versions become visible, while retained and pending items disappear from the comparative field.

The annual report supplies scale, not custody

ICANN’s FY25 annual report adds a different part of the picture. It reports that 1,188 pages of Board Briefing Materials were published during the fiscal year and 205 pages, or 17.25 percent, contained redactions. It also records 21 instances in which Board information was withheld under Bylaw 3.5(b), and four confidential executive sessions followed by public reporting of adopted resolutions.

Those numbers establish that post-FY24 redaction activity was material. They cannot be converted into a missing row count. A page, a withholding instance and a register entry are different units. One document may span many pages or carry several redactions. The aggregate tells the public how much publication and withholding occurred; it does not say which item carried which code, whether it was reviewable, when it was reviewed or what later changed.

The individual Board pages supply still another layer. On 3 May 2026, the Board said that all or part of the FY27 organization and chief executive objectives would remain confidential under Bylaw 3.5(b) until the President and CEO or a designee determined they could be released. The rationale separates organization objectives from individual objectives and explains their use in evaluating the chief executive. On 7 June 2026, a preliminary report concerning the Singapore office lease contained confidential-negotiation redactions and an express release condition.

Neither item proves improper conduct. Employment, bargaining and evaluation material can carry real confidentiality interests. Nor does naming a release authority prove that the named official personally conducts every review. These pages matter because they expose the metadata questions a register should answer: What is the review class? Who holds the institutional release authority? Is there a milestone or date? Who records a retention decision? Where will the original and updated versions be joined?

A search result can find an individual clause. It cannot provide a comparable lifecycle across hundreds of items.

Maximum feasible openness needs an executable state

ICANN’s current Bylaws, amended in July 2026, frame the duty as maximum feasible openness and transparency. Board resolutions are to be made public rapidly. The Bylaws also permit withholding for personnel and employment matters, necessary legal matters, information whose disclosure is prohibited by law or contract, and other matters the Board votes to keep confidential. Preliminary reports and minutes generally must describe the basis for nondisclosure.

The Board publication practices carry the same balance into operations: publish as much as feasible, redact the smallest necessary portion, state the reason, and review whether the reason still holds. This is not a promise that every deliberation will become public. It is a promise that the boundary between disclosure and withholding is governed.

That boundary cannot be evaluated from policy prose alone. It needs executable public state. For every gap in a document, the reader should be able to find the classification, controlling basis, review track, latest decision and current version without possessing institutional memory.

Heng Lu’s distinction between symbolic and operational reality is useful here. “Maximum feasible openness” is a symbolic commitment until the procedures, records and state transitions make it testable. The workbook’s schema was capable of doing that work. Its public time horizon now stops before the archive and source pages do.

The same point applies to multi-stakeholder legitimacy. Community participation can raise questions and discover inconsistencies, but participation is not a substitute for a denominator. If only the organization knows the complete population of redactions, outsiders cannot distinguish a representative sample from a convenient set of visible cases. A comparable ledger turns scrutiny from anecdote into governance.

What the missing join costs

The first cost is a lost denominator. The archive makes successful releases easy to see but says nothing comprehensive about items retained, pending or classified as nonreviewable. The annual report counts pages and withholding instances, not redaction rows. Without the register, no public object joins the population.

The second cost is the collapse of eligibility into outcome. Marking a redaction “subject to annual review” does not reveal whether review occurred. A completed review may retain, narrow, partially release, fully release or correct the material. Those are different decisions with different next states.

The third cost is hidden partial success. The Seville decision is exactly the kind of calibrated release ICANN should want observers to notice. Yet the public must compare an archived original with a current page to understand it. A register row could state: location released; contract amount retained; review completed on this date; next trigger recorded. That makes restraint and disclosure equally auditable.

The fourth cost is dependence on search craft. A person must know that a redaction archive exists, understand ICANN’s fiscal years, find the exact meeting page and compare versions. Openness becomes a skill test rather than a property of the record.

The fifth cost is weaker institutional learning. Without a common row and stable identifiers, it becomes hard to compare which classifications are most often retained, which release triggers work, how long partial release takes, and where reviews repeatedly produce no public explanation. That analysis can improve the policy without exposing a single protected sentence.

The strongest defence deserves to be preserved

ICANN can reasonably resist a system that treats confidentiality as presumptively suspect.

Negotiation figures can weaken the organization in later procurement. Privileged advice can lose protection through disclosure. Personal and employment information can create lasting harm. Draft analysis can be misunderstood as a final institutional position. Security-sensitive material can create operational danger. Candid Board advice may deteriorate if every tentative view is published immediately.

There is also an operating-cost defence. A manual spreadsheet spanning meetings, attachments, classifications and later reviews is easy to let drift. Making it current requires disciplined ownership across publication, legal review and record management.

These are reasons to design the register carefully, not reasons to abandon it. The remedy should not ask reviewers to summarize privileged advice or reproduce a confidential price. It should allow a compact retention rationale such as “negotiation remains active” or “privilege continues,” with a private evidence field inaccessible to the public. Personal names need not identify the custodian; an institutional role is sufficient.

Most importantly, the register should not be a second manual system. The same transaction that posts a redacted Board page should create the relevant rows. The same annual-review workflow that updates a page should record the outcome, archive the prior version and publish the next review state. If the public workbook is stale because it is maintained separately, automation of the metadata handoff is the proportional repair.

Publish a versioned redaction custody register

ICANN should replace the periodic public workbook with one versioned redaction custody register available as a web table and machine-readable dataset. The familiar spreadsheet can remain as an export. The source record should update with every Board-material publication and every review decision.

Each redaction needs an immutable identifier. The identifier should survive a changed URL, a partial release, a correction and a superseding document. It should connect:

  • meeting, artifact and permanent section locator;
  • redaction code and Bylaw, DIDP, legal or contractual basis;
  • scope, such as page, paragraph, attachment, field or amount;
  • annual, milestone, 15-year or ordinarily nonreviewable classification;
  • creation date and institutional custodian;
  • release-decision authority and an oversight or escalation path where appropriate;
  • next review date or named event that will trigger review;
  • latest review date and outcome;
  • a compact rationale for retention;
  • what was released and what remained protected after a partial release;
  • links to the archived original and current public version;
  • every correction and supersession; and
  • a public/private boundary explaining why deeper evidence cannot be shown.

The register should distinguish no review yet from review completed and retained. It should distinguish partial release from full release. It should distinguish a scheduled annual check from a trigger controlled by the end of a negotiation. Those distinctions already exist in the policy. The public data should preserve them.

A consistency validator can make the system reliable. A new redacted Board page should not publish unless it has a register identifier, code and review class. A review that changes the page should not complete unless the old version is archived and both directions link correctly. A retention decision should update the last-review date and next state without exposing the private material. Corrections should append to the lineage rather than silently overwrite it.

None of this creates a public veto over Board confidentiality. It does not turn a requester into the release authority. It does not invalidate a resolution if metadata is late. It simply makes ICANN’s own distinction between justified, reviewable, retained and released material visible over time.

Evidence limits

The evidence reviewed here does not establish that ICANN lacks a current internal register. It does not establish that FY24, FY25 or FY26 annual reviews were skipped. The archive and the Seville update point the other way: review and release continued.

The archive is not a complete list of redactions. The FY25 annual-report figures cannot be translated into exact register entries. Blank FY24 outcome fields in the linked workbook do not prove blank internal outcomes. The 2026 objectives and lease items do not establish self-dealing, excessive secrecy or improper delay. No reviewed fact shows that a Board decision was invalid.

The demonstrated condition is public and bounded: the Redaction Register landing page points to an item-level workbook ending at FY24, while later archive entries, annual reporting and Board pages show that the lifecycle continued. The proposed response is a synchronized custody record, not a demand for the protected contents.

Sources

  1. ICANN — Board Materials Redaction Register
  2. ICANN — Redaction Register workbook, 15 June 2024
  3. ICANN — Redacted Board Materials Archive
  4. ICANN — Guidelines for the Posting of Board Briefing Materials
  5. ICANN — Board Publication Practices
  6. ICANN Bylaws, as amended 3 July 2026
  7. ICANN FY25 Annual Report
  8. ICANN — Improving ICANN’s Transparency, 24 June 2024
  9. ICANN Board — Approved Resolutions, 8 June 2025, original redacted version
  10. ICANN Board — Approved Resolutions, 8 June 2025, updated version
  11. ICANN Board — Approved Resolutions, 3 May 2026
  12. ICANN Board — Preliminary Report, 7 June 2026
  13. Heng Lu — The Multi-Stakeholder Mirage
  14. Heng Lu — On Reality Layers, Symbolic Power, and Why Clarity Feels So Hostile