Summary

  • A new IETF Chairs Resources page says the LLC has secured Directors and Officers insurance for the IESG, IAB, IRSG, NomCom, LLC Board and several individual decision roles, including Working Group and Research Group Chairs.
  • It covers actions reasonably considered part of the listed work, continues to respond after a person leaves for acts taken while serving, and tells role holders to use the legal contact channel published on the page for role-related legal action.
  • The page does not pre-approve claims. It says the insurer determines coverage for a specific situation after a claim is submitted.
  • The separate LLC term Covered Individuals excludes many of the same IETF roles unless they are formally authorised to act for the LLC. The two lists serve different policies; neither is a master register of institutional authority.
  • A privacy-bounded receipt should join the insured role to its appointment source and governing instrument while stating that coverage is not appointment validity, procedural authority, consensus, immunity or a liability outcome.

A public map of the insurance perimeter

The page appeared quietly on the IETF Chairs Resources site. Its metadata records creation on 11 August 2026, an update the next day and Jay Daley as author. The Executive Director's public pre-read for the 1 September LLC Board meeting later described the page as a response to multiple people expressing heightened concern about legal action.

That sequence establishes a reason for publishing guidance. It does not establish that anyone has sued, threatened to sue or submitted an insurance claim. The Board meeting was scheduled for 19:00 UTC, after this article's evidence cutoff, so the pre-read cannot be turned into minutes from a discussion that had not yet happened.

The perimeter itself is broad and specific. The page names the Internet Engineering Steering Group, Internet Architecture Board, Internet Research Steering Group, Nominating Committee and IETF Administration LLC Board. It then adds the Independent Series Editor, Ombudsteam, Moderation Team, Working Group Chairs and Research Group Chairs. Leadership groups receive notice during annual orientations.

This is useful public information. A volunteer considering a contentious chair or review role should not have to discover the existence of organisational protection only after a lawyer's letter arrives. Nor should somebody assume that stepping down erases protection for actions taken during service. The page says continuing cover applies to those past-role actions.

Cover follows the alleged act, not the title alone

The most important sentence is the limiting one. The insurance is described as covering actions that can reasonably be considered part of the person's work in a listed group or role. For a specific situation, the insurer determines coverage after a claim is submitted.

That creates a sequence, not a badge. A person first needs a valid relationship to the role. The alleged act then needs to fall within the work the role entails. A notification and claim bring the facts to the insurer. Only then does the coverage decision acquire a concrete state.

None of those steps decides whether the underlying action complied with IETF procedure. A claim can be covered while the action remains appealable. An action can be properly within a chair's remit while a policy exclusion or other term affects coverage. Insurance responds to risk under a contract; it does not rewrite the process that created the role.

The distinction also protects role holders. Treating a title as automatic cover can create dangerous confidence. Treating the absence of public policy detail as proof of no cover can chill service just as badly. The new page correctly places the decisive claim judgment with the insurer rather than pretending that general web copy can bind every fact pattern.

Two lists have two jobs

Another IETF page uses a deceptively similar vocabulary. The LLC's administrative policies and procedures apply to Covered Individuals: Board directors, employees, contractors, and volunteers or agents formally authorised to act for the LLC in a stated capacity. The page then says that IETF participants, IESG and IAB members, Working Group and Research Group Chairs, the Independent Submissions Editor and the Ombudsteam are not Covered Individuals unless separately authorised in that LLC capacity.

The insurance page includes many of those excluded roles. That is not a contradiction. Covered Individual answers who is subject to a set of LLC governance policies. The insurance list answers for which IETF groups and roles the LLC says it has secured D&O protection. A person can sit inside one perimeter and outside the other because the legal questions differ.

The unsafe move would be to merge the lists. Insurance does not make a Working Group Chair an employee or agent of the LLC. Formal LLC authorisation does not give somebody the IESG's standards authority. A policy term designed for compliance cannot be imported into a claim, and a claim perimeter cannot be imported into a standards process.

Authority still comes from the role instrument

RFC 8711 makes the institutional separation unusually clear. It assigns the LLC Board responsibility for obtaining commercial general liability and other appropriate insurance. The same document says the LLC provides administrative support and has no authority over IETF standards-development activities.

The Board can therefore procure a shield around a standards role without acquiring the role's decision right. The protection follows the institutional need; the mandate remains where IETF process placed it.

The named roles are not interchangeable either. RFC 2418 places a Working Group Chair under an Area Director's appointment and gives the chair bounded responsibilities for managing the group process toward rough consensus. RFC 7776 gives the Ombudsteam a different set of duties, confidentiality obligations, remedies and appeal routes. Sharing an insurer does not collapse those charters into a single office called IETF decision-maker.

That point matters because the insurance page itself uses the phrase decision-making roles. It is sensible shorthand for risk management. It should not become a constitutional category broader than the documents that define each role.

A receipt can reassure without exposing a claim file

The public page does not name the insurer, policy number, coverage period, limits, exclusions, retention, endorsements or any claim. Publication of all those details would not necessarily serve the community. Commercial confidentiality, privilege, security and the privacy of people caught in a dispute are legitimate constraints.

The missing join can be much thinner. For every listed group or role, a public role-and-cover receipt could carry:

Field What it proves
Appointment source and service dates Why the person occupied the role during the relevant period
Governing RFC, charter or procedure Which actions and review paths belonged to that role
Insurance-page version and observation date Which public perimeter statement was in force
Policy-period continuity state Whether protection remained continuous, without publishing limits or commercial terms
Annual orientation or notice state Whether the role class received the promised guidance
Claim state, only where already public Notified, pending, covered, partly covered or denied
Explicit non-conclusions Cover is not authority, consensus, immunity or a liability judgment

For non-public matters, claim fields should stay absent or appear only as anonymous totals. The receipt should never reveal privileged advice, allegations, personal correspondence or an insurer's confidential reasoning. Its job is to show that the three chains exist and are joined, not to publish the case file.

What the record does not establish

No public source reviewed here proves that a listed person faces legal action, that the insurer has accepted or denied anything, or that existing cover is inadequate. The absence of policy limits on a guidance page does not prove low limits. A named role does not prove that every current holder was validly appointed. The phrase reasonably considered does not let an outside observer pre-judge a future claim.

The record also does not show a decision made at the 1 September Board meeting. The Executive Director document is a pre-read. Later minutes, if any, will be a separate evidence object.

Heng Lu's warning that titles are not immunity is best applied here as a design rule, not an accusation. Insurance can legitimately protect people who exercise a bounded role in good faith. It starts to launder mandate only when protection is treated as proof that the title existed, that the act was authorised or that the institution possessed power beyond its charter.

Sources

  1. IETF Chairs Resources — Insurance cover
  2. IETF — Executive Director public report for the 1 September 2026 LLC Board meeting
  3. IETF — Administrative policies and procedures
  4. RFC 8711 — Structure of the IETF Administrative Support Activity, Version 2.0
  5. RFC 2418 — IETF Working Group Guidelines and Procedures
  6. RFC 7776 — IETF Anti-Harassment Procedures
  7. IETF announcement — LLC Board meeting, 1 September 2026
  8. Heng Lu — Mandate Laundering: From RIR Fantasy to Transition Architecture