Summary

  • Revision 07 of draft-carpenter-gendispatch-anachronisms, uploaded on 9 September 2026, adds a section saying that the IETF lacks a generally agreed definition and general policy for conflicts of interest. It remains an individual Informational Internet-Draft posted to open discussion, not an adopted rule.
  • IESG, IAB, LLC and Trust/IPMC policies already govern different populations and decisions. The missing control is therefore not a universal dossier on every contributor, but a decision-scope record that says which rule applies when a person exercises authority, how the interest was treated and who acts if that person steps aside.

The most consequential change in revision 07 occupies five lines of plain text. It says that allegations of conflict of interest occasionally appear on IETF mailing lists, that the IETF has no generally agreed definition or general policy, and that policies do exist for IETF LLC staff, IESG members and the IETF Trust/IPMC.

That is a gap statement, not a finding against anyone. It names no disputed decision and no person. It also does not say that the institution has no safeguards. The important word is “general”.

The previous revision had no conflict section. The official comparison shows the new Section 11 and a related change to the title: “and Gaps” now follows “Some Anachronisms”. The change log is equally restrained—“Added conflict of interest”.

The process status matters. The Datatracker record calls this an active individual Internet-Draft with intended Informational status. It cautions that individual filing records neither IETF endorsement nor a formal step in the standards process. The history records Brian Carpenter's upload on 9 September; the API entry has no stream or responsible Area Director. The draft says it is posted only to open discussion and that issues attracting interest should probably become separate focused drafts.

Its discussion home does not change that state. GenDispatch's charter gives the working group a routing function: it can direct work to an existing group, develop a charter or BoF proposal, recommend another body, defer, or reject. It is not chartered to perform the proposed work itself. Revision 07 therefore creates a live governance question, not a policy.

The policies are islands with explicit shores

The shortest way to misunderstand the new paragraph would be to read “no general policy” as “no rules”. The official documents show something more precise.

The IESG conflict-of-interest policy covers NomCom-selected and ex-officio IESG members and expects liaisons to follow it. It recognises that technical and procedural choices can affect employers and other interests. It nevertheless says employer involvement in IETF activity is not by itself a conflict. It requires public disclosure of employment, sponsorship, consulting customers and other likely sources, with additional potential conflicts disclosed internally. A clear conflict normally leads an Area Director to recuse and leave the action to other ADs.

That policy also names the decisions that make the interest operationally relevant: judging consensus, approving documents, appointing designated experts, handling charters and BoFs, deciding appeals, responding to liaison statements and making appointments. Its logic is not “affiliation equals fault”. Its logic is that a covered role is about to use a defined power.

The IAB policy has another perimeter. It covers selected and ex-officio IAB members, expressly not liaisons or IAB program participants. It identifies confirmations, standards appeals, RFC Series questions, liaison roles, advice and appointments. Other potential interests are disclosed internally; the IAB can request recusal; a recusal is recorded in public minutes.

The IETF LLC policy draws an even sharper institutional line. Its Covered Individuals are Board Directors and the LLC's workforce, including contractors, plus people given formal authority to represent it in a stated capacity. The exclusion is broad: ordinary IETF or IRTF contributors sit outside this definition, as do technical leadership bodies, group chairs, directorates, named editorial or volunteer functions, the Ombudsteam and Trust trustees, unless a separate LLC role brings them inside.

The Trust and IPMC policy index and the IPMC policy add distinct board-governance surfaces. RFC 9680, the antitrust guidance for participants, accurately preserves the patchwork: it points to established IESG, IAB and LLC conflict policies “if and when applicable”. Applicability is doing real work in that phrase.

These boundaries are not necessarily defects. A corporate procurement decision, an IAB appeal, an IESG document approval and a working-group consensus call are different acts. They can require different disclosure recipients, confidentiality rules, substitutes and public records. The gap appears when a consequential act falls between the named perimeters—or when the public record does not say which perimeter governed it.

Participation is too broad; authority is observable

RFC 3935 places individual participation, openness to technically competent input and rough consensus among the IETF's basic values. RFC 7282 makes the institutional fact more bluntly: the IETF does not really have members. People participate as engineers, authors, implementers, reviewers, employees, customers and citizens, often at the same time.

A rule triggered by mere participation would therefore begin at the wrong boundary. It could demand public financial or organisational dossiers from everyone who sends a message, files an issue or comments on a draft. It would collect large amounts of personal data while saying little about which decision could actually be affected. It could also turn ordinary technical disagreement into an invitation to classify the speaker rather than answer the objection.

Interests are common; discretionary authority is narrower. RFC 2418 gives Working Group chairs responsibility for process and for determining rough consensus. RFC 7282 explains why that is judgment rather than arithmetic: an objection must be genuinely considered before a chair can place it “in the rough”. Editors, review leaders, Area Directors, appointed experts and appeal bodies can hold different powers at different stages. A contributor may move into or out of one of those roles without changing employers.

The trigger should follow that transition. When a person is about to call consensus, approve or block advancement, select an expert, dispose of an appeal, award a contract or exercise another policy-defined discretion, the system should be able to answer: what decision is this; what role does the person hold for this act; which conflict rule applies; and who can act if participation is limited?

This approach also separates prevention from remedy. RFC 2026's conflict-resolution and appeals path allows review of standards-process actions. The 2025 IESG statement asks appellants to identify a specific action, grounds and requested remedy and warns against speculation or personal accusation. That is a valuable ex-post route. It is not the same as declaring an interest before a decision, assigning an unconflicted substitute or preserving the treatment applied at the time.

Record the decision scope, not a permanent verdict on a person

A minimum decision-scope conflict record can join the islands without forcing them into one policy. It needs a decision identifier and stage; the actor's role for that decision; the applicable policy and version, or an explicit no named policy; the disclosed interest class at the least sensitive useful level; the disclosure recipient; the independent role that assessed materiality; and the treatment—participation, abstention, recusal or another documented mitigation.

If the original decision-maker steps aside, the record should name the substitute role, not merely say “recused”. It should link the public reason or minutes where the applicable policy requires publication, identify the review or appeal route, and retain correction and supersession history. The record should never infer a conflict from an employer name, authorship or technical position. It should record an authorised determination, including the conclusion that no conflict exists or that participation is permitted.

The architecture can remain federated. IESG, IAB, LLC, Trust/IPMC and later role-specific policies can keep their own definitions and confidentiality boundaries. A shared minimum only makes the routing fields comparable. A reader can then distinguish not covered, not disclosed publicly, assessed and permitted, mitigated, recused and under review instead of compressing all six states into silence or suspicion.

That is the restraint in Heng Lu's Minimum Initial Specification: standardise the smallest coordination boundary and leave local policy local. The Policy Mirror supplies the companion test: a consequential result should be reconstructable from the rule, authority and evidence that produced it. The decision-scope record is my proposal, not language in revision 07.

Revision 07 has done something useful precisely because it does not pretend to finish the work. It has moved conflicts of interest from an occasional allegation to an explicit process-design question. The next step should not be a registry of people. It should be a map of power at the moment power is used.

Sources