Summary
- The IETF LLC conflict-of-interest policy separates initial, annual and change-triggered submissions, at-least-annual Board review and annual or update-triggered public posting. Its public register does not display those events separately.
- As checked on 28 August, the page contained 38 links for 36 names and placed two records each for Jean Mahoney and Robert Sparks inside the “Current disclosures” section. A link is therefore an artefact, not a current-person denominator.
- The page proves neither neglect nor an undisclosed conflict. A privacy-safe coverage-and-review receipt could add role, scope dates, form and policy version, confirmation, review, posting and supersession status without publishing protected facts.
One day is clear; three years are not
The newest Board transition leaves a clean two-step record. The IETF Nominating Committee announced Pete Resnick's selection as an IETF Administration LLC director on 4 August 2026. His public conflict-of-interest form is signed 5 August.
That sequence does not tell readers whether the Board found a conflict, because a disclosure is not a finding. It does show that the public register can capture a new covered role quickly.
The puzzle begins when the same page is read as a status register rather than a document shelf. It says the Executive Director, directors and LLC staff have all made disclosures. It places the linked forms under the heading “Current IETF LLC Conflict of Interest Disclosures.” Yet the five directors on the current Board roster have parenthetical dates ranging from Resnick's 5 August 2026 to 30 January 2023 for Chair Mirjam Kühne. George Michaelson's entry is dated July 2025, Gonzalo Camarillo's April 2025 and Roman Danyliw's March 2024.
An old displayed date is not evidence that an annual duty was missed. The Board may have reviewed an unchanged form later. A covered person may have resubmitted the same information. The date may describe signature, submission or public posting rather than the most recent compliance check. The problem is precisely that the public page does not tell the reader which interpretation is correct.
The flat list adds a second warning. As observed on 28 August, it held 38 linked rows for 36 unique names. Jean Mahoney appeared with 2026 and 2025 dates; Robert Sparks appeared with 2025 and 2022 dates. Both entries sat inside the current section rather than one being moved to the separate past-disclosures list.
There may be a sound archival reason. A new form can supersede an old one without making the old file disappear. But once more than one artefact belongs to one person, counting links cannot prove how many current people are covered. The public word “current” needs a state model, not just a shelf label.
The policy contains four clocks
The LLC's Conflict of Interest Policy is unusually helpful because it distinguishes the events that the register compresses.
A Covered Individual must submit a form on initial association with the LLC, on an annual basis established by the Board and whenever a relevant change occurs. At least annually, the Board is to review a current copy of each form. The Board also keeps a private repository of disclosures and associated resolutions, while publishing summaries and individual-level disclosures with confidential or irrelevant information redacted. Public disclosures are to be posted annually or more frequently after updates.
Those duties create at least four clocks:
| Event | Actor | What it proves |
|---|---|---|
| Signature or submission | Covered individual | The person supplied an artefact at a stated time |
| Annual or change-triggered update | Covered individual | The information was refreshed or confirmed under the Board's cycle |
| Review | Unconflicted Board process | A current copy entered compliance monitoring |
| Public posting | Publisher or custodian | A redacted public artefact became available |
None automatically proves the others. A form can be signed promptly and reviewed later. An unchanged form can be confirmed without generating new substantive disclosures. A Board review can occur without a new public PDF unless the register carries a confirmation state. A public posting date says when readers obtained access, not what the Board decided privately.
This is not procedural hair-splitting. The policy deliberately protects a private repository because conflicts and resolutions can contain confidential information. Public proof must therefore be designed around status and scope, not around disclosing everything.
“All” needs a denominator, not more biographies
The page's completeness claim reaches several classes: directors, the Executive Director and staff. The policy reaches further, to contractors and formally authorised volunteers or agents. Contractor forms are directed to the RFP and contracts page rather than kept in the same list.
Separate repositories can be sensible. A procurement reader benefits from seeing a contractor's form beside the contract. A personnel roster and a Board roster serve different purposes. The error would be to assume that every public list has the same scope or that one can be subtracted from another to produce a verified missing-person count.
The IETF Datatracker has a current LLC employees group. The Board page has five named directors and their selection sources. The conflict page has linked artefacts, including repeated names and people whose role cannot be inferred from the row alone. The procurement page holds another class of forms. None of those facts proves that somebody is absent from the private repository.
They do prove that the public reader lacks a denominator snapshot. How many people were covered as directors, employees, contractors and authorised agents on a stated date? How many had a current annual submission? How many were unchanged but confirmed? How many awaited review, had left scope or had a public form on another surface?
A denominator need not identify every contractor or volunteer. It can report role-class counts and link to public individual records where disclosure is already required. The purpose is to let “all” be tested without turning the register into a personnel database.
The IESG page shows the missing distinction
Another IETF governance surface already publishes the concept that the LLC page leaves implicit.
The IESG Conflict of Interest page has its own policy, actors and authority. It does not govern the LLC. Its disclosure table nevertheless separates an original date from later changes and unchanged confirmations. Roman Danyliw's IESG row preserves a 2021 disclosure, a 2024 update and confirmations in 2025 and 2026.
That design answers a narrow public question: did the record remain untouched because nobody checked it, or because the person confirmed that it remained current? It does not expose private Board deliberation. It does not republish family information. It adds a verb—confirmed—and a date.
The comparison should not become an argument for one uniform IETF conflict regime. The IESG decides within the standards leadership structure; the LLC Board oversees an administrative company. RFC 8711 gives the LLC strategy, budget, staffing, contracting and compliance responsibilities while keeping it out of standards oversight. Different authorities can use different policies while sharing a basic documentary grammar.
A form revision is not a policy revision
The LLC Board's approved minutes for 20 November 2024 record an electronic vote approving a revised Conflict of Interest form. The public policy still identifies itself as version 1, last updated 31 October 2019. Individual PDFs also carry policy-version text, and some filenames or templates refer to form version 1.
That combination does not prove that anyone used the wrong document. A form can change layout or questions while the governing policy remains version 1. Nor do the minutes establish which public PDF first used the revised design.
It does expose a second versioning problem. Policy version and form version are not synonyms. A durable register should say which policy imposed the duty and which form collected the response. Otherwise a future reader cannot tell whether two visually different artefacts implement the same rule or whether a substantive rule change occurred.
File identity matters too. A stable URL is convenient, but it does not by itself record whether bytes were replaced. A public fingerprint and supersession link can preserve the reviewed artefact without making the register responsible for judging its contents.
Daniel Kade's coverage-and-review receipt
The narrow repair is a receipt joined to each current covered role.
It starts with a stable person or role identifier and a role class: director, employee, contractor or authorised agent. It records when coverage began and, when applicable, ended. That prevents a former role from looking like a current compliance gap and a new role from inheriting an unrelated old form.
The receipt then binds the authoritative public artefact: form signature or submission date, form version, policy version, public URL and file fingerprint. A later form is linked as a supersession, not silently substituted.
The annual state can remain terse. Submitted, confirmed unchanged, update requested, review complete, superseded and no longer covered are enough when paired with dates and the responsible institutional actor. If a resolution or mitigation exists but is private, the public state can say private resolution recorded without revealing its facts. Redaction can likewise be recorded as present with a reason category rather than exposed content.
Finally, the page should publish a dated coverage summary by role class and identify the source surface for each class. Contractor records can stay with contracts; the register only needs a join that proves where the public artefact lives and whether it is in the current cycle.
This receipt does not evaluate whether an employer, board seat or consultancy creates a conflict. It does not replace recusal or enforcement. It does not transfer review authority from the Board to a web editor. It makes the lifecycle of the evidence auditable.
What the record cannot establish
The current page does not establish that any named person failed to disclose, that an old form is false or that the Board missed a review. The existence of a relationship on a form is not a finding of bias, misconduct or required recusal.
The repeated rows are not proven errors. They may preserve legitimate history. The Datatracker staff group is not proven to enumerate every employee, contractor, volunteer and agent covered by the LLC policy. The contractor pointer is not concealment; it is evidence that the public record spans more than one surface.
The 2024 compliance report to the Internet Society says the LLC has a process to request, assess and publish conflict disclosures from key personnel and contractors. That is institutional evidence of a process. It is not a per-person status receipt, and it does not need to become one.
The bounded conclusion is simpler. The register is strong enough to show public artefacts and fast onboarding. It is not structured to show which annual event makes each artefact current. Transparency should not force readers to infer compliance from a PDF date or infer failure from its age.
Sources
- https://www.ietf.org/administration/policies-procedures/conflict-interest/coi-disclosures/
- https://www.ietf.org/administration/policies-procedures/conflict-interest/
- https://www.ietf.org/administration/llc-board/
- https://mailarchive.ietf.org/arch/msg/ietf-announce/qXNftRFCQzuU9TL26U_44niOXBk/
- https://www.ietf.org/media/documents/Resnick_Pete_IETF_LLC_CoI_20260805_REDACTED.pdf
- https://www.ietf.org/media/documents/IETF_LLC_Conflict_of_Interest_Form-MirjamKuhne-sig-REDACTED.pdf
- https://www.ietf.org/media/documents/George_Michaelson_IETF_LLC_COI_9July2025-REDACTED.pdf
- https://www.ietf.org/about/groups/iesg/iesg-coi-policy/
- https://datatracker.ietf.org/group/llc-staff/
- https://www.ietf.org/administration/rfps-and-contracts/
- https://www.ietf.org/media/documents/Report_to_ISOC_re_Compliance_Program_2025-01-09.pdf
- https://www.ietf.org/media/documents/2024-11-20-llc-board-minutes.pdf
- https://datatracker.ietf.org/doc/html/rfc8711
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

