Summary

  • The IETF Community Survey 2025 is designed to describe participation, inform leadership and create a time series. Its own method makes its limits visible: 52,660 email addresses were the analytical population, 1,480 responses were retained as valid, and unresolved selection bias remains possible.
  • A survey response is evidence about a respondent population under stated conditions. It is not a vote, a member register, a grant of authority, an appointment or a standards decision.
  • The new open-ended question identified governance and accountability themes among 241 respondents. That is a serious diagnostic signal, but it neither proves a universal preference nor selects a remedy.
  • A public survey-to-disposition receipt should connect each material finding to its scope owner, the decision route, a reasoned action or non-action, implementation evidence and a later review. It would make response visible without pretending that measurement has become mandate.

A survey is a sensor, not a sovereign

The most valuable thing about the 2025 IETF Community Survey is that it does not present itself as a constitution. Its introduction names three purposes: to provide a current size and demographic breakdown; to inform the community, particularly people in leadership roles, about issues affecting it; and to create a time series for assessing natural changes, programmes, organisational changes, and actions by the community or leadership.

Those are serious jobs for a survey. An institution that only counts meeting registrations or mailing-list traffic will miss how a process is experienced by people who read, hesitate, leave, or decide that their contribution will not be heard. A recurring instrument can also show whether a claimed improvement is merely a good story at the time it is announced or a change that persists across cohorts.

But an instrument that informs is not an instrument that authorises. It can establish that a question deserves an answer. It cannot, solely by producing a percentage, determine the proper answer, the official who owns it, or the legal and procedural route by which it should be made binding.

This distinction is not a way to dismiss respondents. It is the condition for taking them seriously. If every expression of concern is flattened into a claim that “the community decided,” the actual content of the concern disappears into a convenient abstraction. A respondent may be reporting a barrier, a confusing escalation path, a bad experience with a working group, a concern about employer influence, or a request for greater clarity. Those observations have different evidentiary weights and call for different responsible bodies.

Calling them all a mandate does not empower the person who raised them; it gives someone else a licence to choose the conclusion in their name.

Heng Lu's distinction between participation and mandate is useful here in its narrowest form. Participation can reveal experience, expertise, warning and objection. It does not, merely by being present in a dataset, establish who may bind an absent party. The converse matters too: a body with a defined duty may not ignore evidence simply because the evidence does not come wrapped as a vote.

The denominator is deliberately imperfect

The report is unusually clear about the object it measured. It created its invitation list from the memberships of active IETF mailing lists, de-duplicated addresses using + notation, removed prior survey opt-outs and addresses thought unable to receive email, and then used 52,660 addresses as the population for analysis.

That is not the same thing as 52,660 people. The report identifies two limitations it did not correct because it lacked the data: one participant can subscribe to different lists with different addresses, and a role address or internal expander can reach more than one person. The survey population is therefore an address-based operational frame. It is useful for an annual survey of people around the IETF's mailing-list system. It is not an electorate, a membership roll, a count of individual principals, or a proxy for all people affected by Internet standards.

The same discipline applies to response. The report says 1,716 responses were received, 1,480 were valid, and the resulting response rate was 2.81%. It gives a maximum margin of error of plus or minus 2.54% for the stated population. It also says that self-selection can create selection bias, that no cross-check could be performed because the necessary data were not available, and that the possibility therefore remains.

These are not embarrassing footnotes. They are the terms under which the measurement can be used honestly. A 1,480-response survey may reveal a pattern worth investigating. It cannot prove that nonrespondents share the same view. Nor does the possibility of selection bias turn every result into noise. The sensible position is narrower: the report establishes what its valid respondents said, how the data were processed, and where extrapolation becomes less certain.

The report even demonstrates why several denominators must remain visible. It compares an estimate of regular posters implied by a survey answer with a separate analysis of unique sending addresses in 2025. That is a bounded check on one participation category, not a conversion of every address into a person or every person into a voter. Good governance begins when a number retains its measuring point.

A theme is not a disposition

The most politically tempting material appears in Q54, the new open-ended question. The report says 241 of the 1,480 survey participants answered it. Its thematic analysis identifies five recurring areas: behavioural barriers and ineffective moderation, corporate capture and loss of individual voice, process inefficiency and RFC pipeline delays, access and global representation, and leadership accountability and governance reform.

None of those headings is trivial. The report also distinguishes how themes appear across participation and leadership-experience groups. That can help a responsible owner ask better questions. For example, a concern about an escalation path may call for a procedural explanation, a policy review, a conduct mechanism, a Board action within administrative scope, or a standards-process route. Those are not interchangeable remedies.

The report takes care not to publish the complete free-text responses: it cites personally identifiable information and the volume of material. It says the thematic summary was produced with an AI assistant. That makes the published themes a useful, but mediated, evidence layer. A theme is not a verbatim record. It is not a ranked ballot. It is not proof that every respondent who used one phrase endorsed every policy later placed beneath that phrase.

The risk runs in two directions. One group may cite “corporate capture” as proof that the IETF has already reached a conclusion about a named company, leader, or working group. Another may say that 241 free-text responses are too few to matter. Both shortcuts erase the actual finding. The first turns a bounded perception report into an accusation and a verdict. The second treats only decisive power as worthy of attention.

The proper question is more demanding: what did the published evidence show, who has authority over the part of the problem within their scope, what did they decide, and what later evidence would show whether their decision addressed the issue? Until those propositions are joined, public debate is left with one document that measures concern and another, perhaps much later, that announces action without showing its ancestry.

The next record is a decision record

The IETF already has more than one type of authority. RFC 8711 gives the IETF Administration LLC responsibility for administrative support, operations, finance, fundraising and compliance. It also states directly that the LLC has no authority over IETF standards-development activity. The current Board page, meanwhile, exposes a different administrative surface: Board composition, regular meetings with an observer-open portion, agendas, approved minutes and resolutions.

These distinctions prevent a false all-or-nothing conclusion. A survey finding about an administrative matter may properly enter an LLC or Board route. A survey finding touching a standards decision does not let the LLC substitute an administrative resolution for the relevant technical process. A complaint that touches several layers may require several answers, each from its own owner. The presence of a single survey report does not merge them.

Formal selection, confirmation and recall procedures likewise do not arise from a survey result. RFC 8713 names processes for those acts. A perception survey might prompt people to assess whether a route is intelligible or whether an existing process should be reviewed. It does not silently execute that process.

The useful public object is therefore a survey-to-disposition receipt. It need not expose confidential complaints, identity data or internal deliberation. It should, however, preserve a thin chain:

  1. The frozen survey report, question or thematic finding, together with its denominator and stated limitation.
  2. The precisely framed issue accepted for consideration, or a clear explanation of why no action falls within the receiving body's remit.
  3. The named scope owner and the existing decision route: for example, an administrative policy review, a Board resolution, a community consultation, an established conduct procedure, or a separate IETF standards process.
  4. The decision, including a decision not to act, with the reason, date and authority responsible.
  5. Any implementation owner, measurable output, review date and later correction.

This is not a demand that every percentage creates a public case file. The threshold should be materiality: recurring signals, a stated leadership priority, a claimed response, or a subject where an institution invokes the survey to justify action. Nor does it put an opinion poll above professional judgement. It makes professional judgement legible when it claims to have listened.

Visibility must not destroy candour

A temptation follows any request for traceability: publish all the inputs. Here that would be the wrong remedy. The report says the free-text material includes personally identifiable information. Open responses can also contain names, descriptions of conflicts, safety concerns, employment circumstances, or details that make a participant identifiable within a small technical community.

The receipt should be public at the level of finding and disposition, not at the level of raw testimony. It can preserve the relevant question identifier, aggregate denominator, version of the report, scope classification, public decision reference, and review date without releasing a response, an IP address, a private escalation, or a confidence alleged for an individual speaker.

There is a second privacy boundary. A public response should not fabricate certainty by converting an anonymous theme into a named claimant. A body may state that it considered the report's published thematic finding. It should not say that a particular person demanded a particular result unless that person made the demand through a public, attributable route.

This limited visibility gives the public something it can actually test: whether a claimed response addressed the stated finding, whether the owner acted within scope, whether the implementation was completed, and whether the next survey or another relevant measure suggests a change. It does not ask readers to trust a black box, but neither does it turn a feedback channel into a surveillance system.

The hard case is a sensible non-decision

Not every finding requires a new policy. A valid outcome may be that the evidence is too broad for one owner, already covered by a different process, unsuitable for public treatment, or not yet specific enough to design a remedy. The receipt must allow that result. Otherwise, officials will be rewarded for announcing symbolic actions merely to avoid an apparent gap.

But a non-decision should be an explicit state, not a disappearance. “No action from this route” can say that the relevant responsibility lies elsewhere, that the report has been incorporated into an existing review, that the data are insufficient for a defined intervention, or that no change is currently warranted. A future reader can then distinguish non-action with reasons from a record whose trail simply ended.

The same applies after action. An adopted policy, revised guidance, new meeting format or published escalation path is not evidence that the original concern has been solved. It is evidence that a particular body took a particular step. Outcome needs its own measure, its own date and, where possible, a comparison that does not pretend that a survey score proves causation.

The 2025 survey supplies the first half of this discipline: bounded observation with a disclosed method. The next half is not louder consultation. It is a visible, scope-correct decision trail. That trail would let the IETF treat respondents as sources of evidence rather than as rhetorical cover, and let those who hold responsibility show what they did with the evidence without borrowing an authority the survey never gave them.

Sources

  1. IETF Community Survey 2025 — Final
  2. IETF Community Survey 2025 announcement
  3. IETF reports and surveys
  4. RFC 8711: Structure of the IETF Administrative Support Activity, Version 2.0
  5. RFC 8713: IAB, IESG, IETF Trust, and IETF LLC selection, confirmation, and recall
  6. IETF Administration LLC Board
  7. Heng Lu, The Multi-Stakeholder Mirage