Summary

  • NANOG’s current bylaws, certificate of incorporation and Delaware law answer related but distinct questions: who holds authority, which purposes are permitted, how liabilities and claims are treated, and what a dissolved corporation may continue doing while it winds up. None is an operational continuity schedule.
  • NANOG’s 2011–12 history supplies constructive precedent rather than proof of present readiness. The trademark, meeting archives, domain, equipment, intellectual property, procedures and mailing system were handled in distinct stages. That record shows why legal eligibility and operational capability require separate tests.
  • A proportionate public safeguard would expose neither protected records nor the controls securing them. It would state asset and record classes, accountable roles, authorised dispositions, validation methods, successor capabilities, exceptions and completion receipts—distinguishing public preservation, restricted retention and secure deletion.

The most consequential word is “after”

The dissolution clause in NANOG’s current bylaws begins its operative sequence only after liabilities have been paid or provided for. That small word does more work than the broad phrase that follows it. Once obligations have been addressed, the Board is to dispose of the organisation’s assets exclusively for NANOG’s purposes or to qualifying charitable, educational or scientific organisations selected by the Board. Anything not disposed of in that way is to be handled by appropriate judicial or executive authority under applicable law.

It is a sensible legal instruction. It prevents residual property from becoming a private windfall and preserves the public-purpose character of a Delaware nonstock nonprofit. But it answers a destination question at a high level. It does not say how an archived message remains searchable, who proves that a transferred domain still resolves as intended, how a protected report reaches an authorised custodian, whether a contractual right can be assigned, or when an obsolete access mechanism is disabled. Those are not defects in a bylaw. They are different questions, belonging to a different layer of institutional preparedness.

The difficulty hides inside the word “assets,” which sounds singular in governance prose and becomes stubbornly plural in practice. Cash is not a domain. A trademark is not a mailing-list archive. A public presentation is not an incident report. A registration record is not a hardware access device. Each class carries a different combination of title, dependency, privacy obligation, public function and failure mode. Sending all of them toward a permissible charitable purpose would not automatically keep any public-facing function working.

Conversely, keeping a public archive usable might require a service provider that is not the final legal owner of every associated right.

NANOG’s institutional scale must also remain exact. It is a Delaware nonstock nonprofit and a forum for the Internet operations community. It is not a government, a regulator, a Regional Internet Registry, a number-resource registry or an operator of its entities’ networks. Its own corporate transition would therefore concern its domain, identity, archives, communications, agreements and records. It would not itself reassign number resources or change authority over independent networks.

That limitation makes the inquiry smaller than registry continuity, but not trivial: a forum can still hold public knowledge, protected information and durable identifiers whose value depends on orderly custody.

There is no evidence in the public record reviewed for this investigation that NANOG plans to dissolve. Nor is there evidence here of insolvency, an unresolved creditor claim, concealed intent or present operational failure. This is a continuity test, not a prediction. The value of the test lies precisely in applying it while an institution is functioning: legal documents can be read calmly, historical transitions can be examined as evidence, and a proportionate disclosure can be designed without publishing material that should remain protected.

The finding is narrower than an accusation and more useful than reassurance. NANOG’s public legal framework describes authority and permissible endpoints. Its public history demonstrates that selected resources can be transferred deliberately. The bounded source set does not, however, join those facts in a current public schedule: which functions attach to which assets or records, which disposition is authorised, who can operate and validate the result, what must remain restricted, and what evidence would show that a handover or retirement actually finished.

That is a statement about public evidence, not about what the Board, staff or vendors may hold internally.

Three texts perform three different jobs

The current visible bylaws show amendments adopted on 5 November 2025 after they were proposed on 23 September. A stale page description referring to July 2020 does not override that visible adoption record. The text establishes NANOG as a forum for discussion concerning the operation of IP networks. It also expressly distinguishes the organisation from a network operator. That institutional boundary is essential. NANOG convenes, documents and supports a community; it does not operate the entities’ networks.

A continuity analysis must therefore focus on NANOG’s own functions and records, not imply that its corporate status controls Internet traffic.

Within that boundary, the bylaws allocate responsibility. The Board controls the organisation’s property, affairs and business. The Secretary is responsible for adequate records of transactions and Board minutes. The Treasurer is responsible for corporate finances and fiscal records and supervises any appointed fiscal representative. The Executive Director manages day-to-day affairs under Board direction. The same text recognises community communications platforms, including the mailing list, as part of the organisation’s activity. These provisions supply accountable roles.

They do not themselves identify the current technical custodian, transfer method or validation test for every asset class.

The bylaws also contain the liabilities-first dissolution sequence and the permitted charitable-purpose destinations. A separate clause limits recourse by creditors and claimants to the organisation’s funds and property. That limitation says nothing about the existence or value of any future claim; it merely describes where recourse lies under the organisational arrangement. It should not be turned into a prediction about creditors, just as the dissolution clause should not be turned into evidence that dissolution is contemplated.

The certificate of incorporation performs another job. It confirms the nonstock structure—NANOG has no capital stock—and directs dissolution assets to one or more exempt purposes under section 501(c)(3), or to federal, state or local government for a public purpose, with a court handling assets not otherwise disposed of. The certificate does not use the bylaw’s liabilities-first wording, and the two instruments should not be collapsed into a composite quotation. The bylaw states the sequence and gives the Board its disposition instruction; the certificate separately constrains permissible purposes within the corporate charter.

Neither names a present successor for any asset class.

Delaware law supplies the wider winding-up framework. The statute governing nonstock corporations sets out a dissolution procedure that depends on the relevant governing body and, where applicable, members. Which vote, notice, filing or court route would apply to an actual future case would turn on facts outside this record; this article does not offer that legal advice.

Another section continues the corporate body for three years after dissolution, or longer if the Court of Chancery directs, but only for specific winding-up purposes: prosecuting and defending suits, closing affairs, disposing of property, discharging liabilities and distributing what remains. It expressly excludes continuing ordinary business.

That statutory continuation is often easy to misunderstand. It is legal survival for winding up, not a promise of service availability. A corporation may retain the capacity to convey property or defend a claim while a website, archive search or communications channel has already failed. The reverse can also occur: a public archive may remain technically reachable through a service arrangement even after the original corporation has ceased ordinary operations. Corporate existence and functional continuity are connected, but they are not interchangeable.

Delaware’s claims provisions add a third axis. They address known claims as well as contingent, conditional, unmatured and certain unknown claims, and they govern the provision that must be made before distributions. For a nonprofit nonstock corporation, distribution questions also turn on applicable law and the corporation’s certificate and bylaws. This is why a continuity schedule cannot begin with the assumption that every visible asset is immediately available to a successor. Authority, claims provision and disposition come first.

Yet those legal steps still do not reveal the practical location, export form, dependency, retention duty or validation status of any record class.

The three sources therefore form a coherent legal frame without becoming a runbook. The bylaws assign organisational authority and state the liabilities-first, purpose-bound disposition rule. The certificate defines a separate charter constraint. Delaware law provides procedure, winding-up capacity and claim treatment, including special nonprofit-nonstock language where member-distribution provisions conflict with applicable law or the certificate or bylaws. None needs technical handover detail to do its legal job.

Confusion begins only when those endpoints are treated as proof that public functions, protected records and control mechanisms could be transferred or retired safely without further preparation.

An eligible recipient may be unable to operate the function

The most important practical distinction is between legal eligibility and operational capability. A recipient may qualify to receive charitable assets but lack the people, systems, rights or risk controls needed to preserve a particular function. A technically capable contractor may keep a service running but be an inappropriate final owner of the associated intellectual property. A university archive may be suitable for public historical materials while being unsuitable for protected conduct reports. A successor forum might sustain community communications but not accept every legacy agreement.

One institution could fill both roles, but the legal texts do not require that outcome.

Consider the nanog.org domain as a public-interest function rather than a line in an inventory. Legal title to the name is only one element. Continuity also depends on administrative control, renewal, name-service configuration, certificates, hosting, redirects, contact arrangements and the authority to make changes. A valid transfer of the underlying property can coexist with a broken website if one dependency is missed. A flawless technical cutover can still be unauthorised if the people conducting it do not hold the necessary corporate mandate. A useful schedule must join the two sides.

The same logic applies to archives. A collection of message files can be copied without preserving thread structure, timestamps, attachment references, stable links, search behaviour or enough contextual information for readers to understand the record. A web interface can remain online while the underlying export is incomplete or dependent on software that a successor cannot maintain. “Publicly accessible today” is evidence of present access, not proof of independent preservation.

Contracts and accounts introduce another kind of friction. An organisation may depend on hosting, event, insurance, financial or communications arrangements whose transfer is restricted, requires consent or is simply unavailable on the same terms to a new party. The public does not need contract language or account identifiers. It does benefit from knowing whether each material dependency is intended to be assigned, replaced, terminated or retained for a bounded winding-up purpose, and whether the proposed successor has confirmed that it can perform the function.

Protected records create the opposite risk: continuity language can become an excuse for over-retention. Conduct reports, personal information, access records, payment-related material and security-sensitive communications should not be bundled into a public-archive promise. Some records may need restricted preservation under an authorised custodian. Some may need time-limited retention to meet legal or operational obligations. Others may be eligible for secure deletion.

The right question is not “How can everything be saved?” but “What is the authorised disposition of each class, and how can completion be attested without revealing the contents?”

This is why naming a successor in advance is neither necessary nor sufficient. A premature name can constrain the Board’s discretion, become obsolete, or imply a commitment the candidate has never accepted. The more durable disclosure is capability-based: the recipient of a public archive must demonstrate preservation, access and integrity controls; the operator of a communications function must demonstrate service competence and authorised administration; the custodian of protected records must demonstrate restricted access and lawful retention; the holder of residual charitable property must satisfy the applicable legal destination rule.

Such criteria preserve optionality. They allow the Board to select one recipient, several recipients or a combination of owner and service provider when circumstances are known. They also make later decisions testable. Without capability criteria, a charitable name can supply legitimacy without proving continuity. With them, the public can understand the standard even when sensitive details and final counterparties remain undisclosed.

NANOG has already transferred continuity in pieces

NANOG’s own history provides a more informative precedent than an abstract hypothetical. In February 2011, Merit Network announced an agreement reached at NANOG 51 under which the NANOG trademark, meeting archives and nanog.org domain would transfer to the newly formed NewNOG organisation. The effective date was 7 February 2011. Merit described discussions involving NewNOG, Merit and the University of Michigan, and said the community had endorsed NewNOG after its formation as a nonprofit in April 2010.

That announcement is evidence of a named-property transfer, not proof that every institutional function moved in one act. Its precision is its strength. It identifies particular assets and parties. It describes an orderly transition and gives a date. It does not pretend that conveying the trademark, archives and domain automatically completes every later operational change.

The following year makes that point explicit. A May 2012 transition note described a communications committee managing the mailing lists and website, an Executive Director moving equipment and intellectual property, and a secretariat documenting procedures in a playbook. It also said work remained to be done. The note was a contemporary self-report, not an independent assurance, but it captures the anatomy of a real handover: governance assignment, physical or technical movement, documentation, and an honest acknowledgement of incompleteness.

In September 2012, another announcement reported the upgrade and relocation of the mailing-list system. It said the lists had been synchronised and that no messages or archive material had been lost during that bounded move. Again, the value is in the scope. The claim concerned a specific migration. It did not warrant every archive ever created, every future dependency or the current state of restoration capability. But it showed that a class-level transition can end with a concrete validation statement.

Taken together, the 2011–12 record suggests a sequence that remains useful: identify the asset or function; assign authority; move it deliberately; document operating procedures; synchronise where needed; validate a bounded result; state what remains unfinished. That is much closer to continuity assurance than a generic promise to transfer “all assets.” It is also more candid. Complex institutions rarely move as a single entity.

The precedent should not be overstated. A reported transfer more than a decade ago does not establish current title, custody, export readiness, access control, backup integrity or successor capability. It does not establish whether the domain, trademark, archives and list service now share a custodian or could move on the same timetable. Organisations change. Services are replaced. Records accumulate. Agreements expire. What the record establishes is feasibility and organisational memory: NANOG has publicly described the difference between conveying named property and completing subsequent operational work.

Asking for a contemporary class-level schedule therefore extends a pattern visible in the organisation’s own history rather than importing an alien governance idea.

The historical record also rebuts two opposite mistakes. The first is fatalism: the idea that technical and documentary dependencies are too complex to describe usefully. The transition notes described roles, property classes and validation without exposing sensitive details. The second is complacency: the idea that a legal transfer instrument is enough. The later equipment, procedure and mailing-system work shows that it is not.

A public archive is a function, not merely a pile of files

NANOG’s mailing-list usage guidelines describe an open, community-moderated and publicly archived forum. They say the list reaches more than 10,000 engineers, a descriptive figure that is not independently audited in the materials reviewed here. The public character of the list gives it unusual historical value. Discussions can document operational practice, shared problems, professional norms and institutional memory across decades.

Public availability, however, has several layers. There is access through the current website. There is preservation of the underlying messages and metadata. There is the ability to export them in a documented form. There is integrity: confidence that messages have not silently disappeared or changed. There is reference stability, so citations remain useful. There is discoverability through threading and search. There is restoration, meaning a successor can rebuild a usable service rather than merely possess a copy.

No single layer proves the others. An archive can be visible yet difficult to export. An export can be complete yet unusable without undocumented dependencies. A preserved corpus can lose stable links when placed under a new domain. Search can work while attachments or date fields are missing. A backup can exist but never have been restored. The public record reviewed here does not establish current backup coverage, restoration testing, geographic separation or recovery objectives. That bounded observation says nothing about whether NANOG has private documentation, tested controls or competent operations.

A continuity schedule need not expose architecture or create a security risk. For a public archive, it could name the preservation unit, the authorised custodian role, the intended export form at a useful level, the integrity check, the treatment of stable references, the restoration or migration test, and the evidence of successor receipt. Technical specifics that would increase risk can remain protected. The public needs assurance that the function can survive a change of institution, not a map of every component.

The domain deserves similar treatment because it carries meaning beyond a registration entry. It anchors public references, institutional identity and access to archives and policies. Its continuity test would concern authorised custody, renewal, resolution, certificate continuity, redirect policy and a verified cutover. It would not publish account identifiers, recovery material or control values. Indeed, a schedule that disclosed those details would undermine the very continuity it claimed to support.

The trademark is different again. Its legal transfer and permitted use affect authenticity: readers need to know which successor is authorised to represent the institution or archive. But trademark ownership does not keep a web service running. Pairing the trademark and domain in one broad “digital assets” row might conceal distinct completion tests. A capable schedule can group assets for administration while preserving separate validation where the failure modes diverge.

The public materials associated with meetings also need classification. Published presentations and authorised recordings may be intended for long-term access. Registration data, badge records, private conversations and restricted session material are not simply appendices to the public record. The Code of Conduct expressly recognises consent, privacy and sensitive information across physical and digital spaces. Continuity therefore depends on separating content intended for public preservation from records whose custody must remain limited.

Preservation has a privacy boundary

Institutional memory is often described as if loss were the only danger. For a community forum, inappropriate survival can be harmful too. NANOG’s Code of Conduct prohibits recording private conversations or capturing badges, screens or materials containing sensitive information without permission. It applies in organised in-person venues and digital spaces. It says violation reports are to be handled in the strictest confidence. Its media provisions require consent, protect personal data and attendee information, and restrict publication of security-sensitive operational material.

These commitments change the continuity problem. A dissolution schedule cannot treat every record as public heritage. A protected report may be necessary for a bounded legal, safeguarding or institutional purpose, but the fact that it exists does not create a public-access interest. Personal registration details may support an active event and later become unnecessary. Security-related material may require restricted custody or deletion. Access-control information must be managed without public disclosure. The appropriate disposition can differ even among records held by the same system.

Three verbs are therefore needed: preserve, retain and delete. Preserve applies to material with enduring public or institutional value, such as authorised archives and governance records, subject to integrity and access requirements. Retain applies to records that must remain available for a limited purpose under restricted custody. Delete applies when continued possession lacks an authorised purpose or creates avoidable risk, after any relevant obligations have been met. “Transfer” can sit across all three: a successor may receive a preservation collection, a restricted retention set or responsibility for verified deletion.

The public disclosure should be asymmetric. For an archive intended for public access, a successor can disclose more about format, completeness, stable references and validation. For protected reports, the disclosure should identify only the class, authorised disposition, accountable custodian role, retention basis at a high level, completion status and any unresolved exception. For access controls, even less should be public: the existence of dual control or a verified revocation process can be attested without identifying holders or mechanisms.

This approach aligns transparency with risk. It avoids the false choice between publishing nothing and publishing everything. A credible institution can show that protected records are accounted for without revealing them. It can show that access has been transferred or revoked without exposing secrets. It can show that personal information has an authorised lifecycle without listing individuals. The proof is a completion statement tied to a class and a responsible role.

The same boundary should apply to exceptions. If a record cannot be transferred because of a consent restriction, an unresolved obligation or a technical defect, the public does not necessarily need the underlying sensitive detail. It needs to know that an exception exists, which authority owns its resolution, what interim protection applies, and whether the exception blocks the public-interest function. A redacted exception register can create accountability without creating a second harm.

The audit shows real categories, not operational readiness

NANOG’s audited financial statements for the year ending 31 December 2024 make the asset-and-obligation problem concrete. The statement reports total assets of $3,597,867 and total liabilities of $1,058,265. Current assets were $3,439,603, including $370,810 in cash, $2,514,410 in investments, $409,211 in accounts receivable and $145,172 in prepaid expenses. Current liabilities consisted of $20,781 in accounts payable and $1,037,484 in deferred revenue.

Net assets totalled $2,539,602, divided between $1,621,057 undesignated and $918,545 designated by the Board. The liquidity note identified $3,294,431 of financial assets, reduced by the Board designation to $2,375,886 available for general expenditure within a year. It says financial assets are structured to be available as general expenditures, liabilities and other obligations come due. These are dated accounting figures, not a present valuation and not evidence of any impending dissolution.

Their relevance is classificatory. Cash, investments, receivables and prepayments do not move in the same way. Accounts payable and deferred revenue represent different obligations. A Board designation affects availability. The audit therefore illustrates why “assets after liabilities” cannot be operationalised as one undifferentiated transfer. It also demonstrates that recognised financial categories already carry distinct treatment.

But a financial audit is not an operational inventory. It does not prove who controls a domain, whether an archive can be restored, whether a service agreement is assignable, where protected records should go or whether an access device has been revoked. Nor is it the source of the legal priority for claims; that sequence comes from the bylaw and applicable law. Using the audit for more than it supports would confuse financial assurance with continuity assurance.

This boundary is valuable. NANOG does not need to force technical assets into financial-statement disclosure to improve continuity. A separate schedule can map public-interest functions and record classes without assigning public dollar values. It can reference accountable roles without revealing sensitive control details. The result complements audited financial reporting rather than pretending to replace it.

The Board already has the stewardship vocabulary

NANOG’s public description of Board responsibilities places the Board’s work in legal and fiduciary terms under Delaware law. It says directors are responsible to members for keeping the organisation open, relevant, useful and financially sound. It identifies stewardship as ensuring that assets are used for public benefit. It also names organisational continuity, transition, structure, planning, information flow, documentation and protection of organisational assets as responsibilities or measures of success.

Where wording on that older descriptive page differs from the current bylaws, the current bylaws are the authoritative source for roles and powers.

That vocabulary is well suited to class-level continuity. The Board need not invent a new theory of authority. It can connect existing stewardship duties to a schedule maintained through ordinary governance. The Secretary’s record role, the Treasurer’s financial responsibilities, the Executive Director’s operating role and the Board’s control can become inputs to one coordinated view.

Coordination matters because no officer’s current description spans the whole problem. The Secretary may hold governance records but not manage the technical service. The Treasurer can account for financial property but not validate archive threading. The Executive Director can oversee day-to-day arrangements but may need Board authority for a major disposition. A contractor can perform a migration but cannot create corporate approval. A schedule makes handoffs between roles visible.

The schedule would also improve decisions before any dissolution. Ownership and dependency questions arise during vendor changes, staff transitions, emergency recovery, policy revisions and system replacement. A class with no clear custodian or export test is a present governance weakness even if the institution continues indefinitely. Conversely, a class with a verified lifecycle is easier to operate and less expensive to transfer later.

The public record reviewed here does not show an asset-level dissolution schedule. That does not prove none exists outside public view. Boards often keep sensitive inventories, legal analyses, recovery procedures and access-control arrangements confidential for sound reasons. The case for disclosure rests not on assuming their absence but on identifying the small portion that can safely be made public: functions, classes, accountable roles, disposition paths, capability criteria, validation status and exceptions.

This framing respects the strongest argument against a detailed public plan. A full inventory could advertise dependencies, reveal security posture, expose private counterparties, constrain future discretion or become dangerously stale. Naming a successor too early could create false confidence or a perceived commitment. Publishing access-control specifics would be reckless. Those objections are convincing. They are reasons to design the disclosure carefully, not reasons to rely on the dissolution clause as if it supplied operational assurance.

Public unknowns are questions, not findings

A disciplined inquiry needs an explicit ledger of what the ten public sources do not establish. Otherwise an unknown can slip, almost unnoticed, into a negative finding. The right grammatical form is not “NANOG has no inventory,” but “this source set does not publish an inventory joining owner, custodian role, service dependency, contractual restriction and disposition rule.” The distinction is more than courtesy. It separates verifiable public evidence from speculation about protected internal work.

The first group of unknowns concerns custody and portability. The sources do not identify a preselected successor for the domain, trademark, meeting archive, mailing-list archive, membership and registration data, confidential reports, active agreements, operational accounts or credentials. Nor do they establish which public collections can be exported independently of current software or hosting, which integrity test would detect omission or alteration, or which recipient would issue a custody receipt. A public asset can be visible without those facts being public.

The domain, trademark, archives and list service may also sit with different custodians or require different transfer windows; the material reviewed here does not join them.

The second group concerns capability and contracts. The legal documents describe eligibility and authority, but they do not publish criteria for operating a community communications service or preserving long-term public access. The source set does not establish whether a current venue, hosting, storage, software, payment or other service agreement could be assigned. This does not mean an agreement is non-transferable or a provider is unprepared. It means that “the assets can be disposed of” cannot stand in for the separate questions “the dependency can move,” “a replacement has accepted the function” and “the recipient can perform it.”

The third group concerns protected data and control. The public materials do not publish a dissolution-specific retention or deletion rule for membership, registration, incident, access, financial or vendor records. They do not establish a present credential escrow, dual-control arrangement or emergency account-recovery test. They do not establish current backup coverage, restoration testing, geographic separation or recovery objectives. Public disclosure of the underlying controls would often be harmful, so their absence from these sources is unsurprising.

A privacy-safe schedule would report the class, accountable role and test status—not the credential, recovery method, system location or personal record.

Every item in that ledger remains a bounded public unknown. None supports an allegation of negligence, breach, incapacity, concealment or poor management. A complete internal inventory, current legal advice, tested backups and carefully restricted access arrangements may exist. The public case for a schedule does not depend on denying that possibility. It depends on a narrower proposition: class-level assurances can make continuity legible without publishing the sensitive material that makes continuity possible.

What a minimal continuity schedule would contain

A useful schedule can be compact. It does not need a list of every file, account or device. It needs one row for each material public-interest function or record class, maintained by a named accountable role. Eight elements expose the logic:

  1. Function and class. What public or protected purpose does this asset or record support? Examples include public mailing-list access, published meeting materials, organisational identity, governance records, restricted conduct reports, active agreements and access-control custody.
  2. Authority and present custody. Which Board or officer role can approve disposition, and which role currently maintains the class? Public disclosure can name roles rather than individuals or locations.
  3. Legal disposition. Is the class to be conveyed, assigned, terminated or placed with an eligible recipient? Does the final property recipient have to satisfy the charitable-purpose rule?
  4. Transfer or retirement method. At a safe level of abstraction, how will the class leave current custody or cease operation? The public version should omit control values, personal data and exploitable system detail.
  5. Validation. What observable test establishes completeness and usability, or confirms termination and deletion? This might be an integrity check, restoration test, stable-reference sample, authorised receipt or revocation attestation.
  6. Retention or deletion. Is the class preserved and transferred, retained under restricted custody for a stated high-level basis, or securely deleted? The public row records the rule and status, not protected content.
  7. Successor capability. What must the recipient or operator be able and authorised to do? Legal eligibility, service operation, preservation, restricted custody and deletion are separate capabilities.
  8. Completion evidence and exceptions. Who signs the receipt, when does responsibility change, where does the surviving public function reside at a class level, and what unresolved exceptions remain?

Applied to the public mailing-list archive, the row would emphasise preservation, documented export, integrity, stable references, restoration and accessible operation. It would not expose security-sensitive architecture. Applied to the domain and trademark, it would distinguish authority and authenticity from technical resolution and public access. Applied to meeting publications, it would separate authorised public materials from registration and consent-restricted records.

For conduct reports and related protected records, the row would disclose much less: the authorised restricted custodian role, the high-level retention or deletion disposition, the transfer of responsibility, the completion date and any blocking exception. There is no public interest in exposing report contents or identities. The public interest is in knowing that confidentiality obligations survive institutional change.

For contracts and service dependencies, the schedule would say whether the path is assignment, replacement, bounded continuation or termination, and whether the new operator has accepted the function. It would not publish commercial terms. For access controls, the public line would report only that custody was transferred under appropriate control or that access was revoked and verified. No values, holders or recovery details belong in the public document.

A schedule should also resist the temptation to designate a single “successor” for everything. A qualified charitable recipient may receive residual financial property. A preservation institution may hold public archives. A technical provider may operate access under contract. A specially authorised custodian may retain protected records. These roles may coincide, be subcontracted or remain separate. The Board may find one organisation capable of several roles, but the schedule should prove each capability rather than infer it from the name.

The 2011–12 transition supplies a practical template for evidence. The 2011 announcement named assets and the transfer date. The 2012 note described committees, equipment, intellectual property and procedure documentation while admitting unfinished work. The later mail-system announcement reported synchronisation and a bounded no-loss result. A contemporary schedule can use the same grammar: item, authority, movement, procedure, test, exception.

Test the handover, then issue a receipt

Plans are weakest where verbs remain untested. “Preserve” may mean no more than leaving a server powered on. “Transfer” may mean copying data without proving completeness. “Assign” may ignore required consent. “Delete” may mean removing a visible copy while retained versions remain unaddressed. A validation test turns each verb into an accountable claim.

For a public archive, a useful exercise could restore a representative export in an environment independent of the current presentation layer, verify counts and integrity indicators, sample stable references and confirm that an authorised custodian can operate the restored collection. The public result need not reveal architecture. It can state the class tested, date, scope, verification method, material exceptions and responsible role.

For a domain-related function, the test could confirm that authorised control can be transferred, renewal and resolution remain effective, certificates and redirects behave as intended, and old access is revoked. Again, the public result should be an attestation, not an exposure of the mechanism. For protected records, the test would focus on custody authority, restricted access, retention controls and proof that unauthorised copies were not included in a public transfer.

Deletion requires a receipt too. The accountable party should be able to state which class was retired, under whose authority, on what date, what systems or custodians were in scope at a safe level, how completion was verified and what exceptions remain. It may be impossible or undesirable to claim metaphysical erasure from every medium. A credible statement defines its scope and limitations rather than promising the impossible.

The final handover receipt is the bridge between governance and operation. It should identify the class, the authorising body, the transferring custodian, the receiving or retiring party, the effective time, the test performed, exceptions, and the surviving location or status in non-sensitive terms. For shared or staged responsibility, it should say when each duty changes. If a service provider operates a function while another body owns the property, both roles should appear.

Receipts also protect successors. They prevent an incoming institution from being assumed to hold records it never received or to operate a function it never accepted. They create a clean point for responsibility, reduce later disputes and allow the public to distinguish a completed handover from a proposed one. In a winding-up context, that clarity assists the Board as much as the community.

Testing should occur before a crisis. A periodic tabletop review can reveal a missing consent, an obsolete contact, an undocumented dependency or a restoration failure while remedies remain available. It can be scoped to classes and performed without simulating dissolution of the organisation itself. The result is ordinary resilience: better records, clearer authority and a shorter path through any major transition.

Continuity is a public function, not institutional immortality

The aim of continuity planning is not to make NANOG permanent. Nonprofit institutions can change form, merge functions, retire services or eventually wind up. Corporate law recognises that possibility and supplies an orderly process. The public interest lies in preventing valuable functions and protected obligations from falling into the gap between a legal disposition and an operational reality.

For NANOG, those functions are bounded. The organisation is a forum, not an operator of its entities’ networks. Its public value includes convening, community communications, published knowledge, institutional identity and trustworthy governance. Its duties also include careful handling of personal, confidential and security-sensitive records created through that work. A continuity schedule should preserve the former without exposing the latter.

The current legal texts provide legitimate authority. The Board controls the organisation’s property and affairs. The bylaws direct assets, after liabilities are paid or provided for, toward NANOG’s purposes or eligible nonprofit recipients. The certificate separately protects the exempt- or public-purpose destination. Delaware law addresses procedure, claims and the limited continuation needed to wind up. These rules are necessary, and none should be criticised for failing to describe an archive export or access revocation.

The missing public bridge is operational evidence. Which functions attach to which classes? Which classes are preserved, restricted, transferred, replaced, terminated or deleted? Which recipient is legally eligible, and which operator is practically capable? What test proves the result? What receipt fixes the moment of responsibility? These questions can be answered without naming a successor today and without publishing secrets.

NANOG’s history makes the answer credible. In 2011, named assets moved under an announced agreement. In 2012, people continued with equipment, intellectual property, procedures and a mailing-system migration. A later announcement made a bounded validation claim. The transition was not one legal sentence; it was a series of custody acts.

That is the standard a future continuity disclosure should recover. Not a dramatic dissolution scenario. Not a public inventory of sensitive systems. Not a promise that every record will survive. A simple schedule, maintained under existing Board stewardship, would classify the function, establish lawful disposition, protect restricted material, test the handover and record completion.

The difference between a charitable recipient and a working successor is the distance between permission and performance. Law can determine where property may go and which obligations come first. A current class schedule can then preserve Board discretion while making the operational standard visible. Prepared custody, capable operation and verifiable receipts show that a useful function survived. Where preservation would be unlawful, unnecessary or unsafe, the same discipline shows that a record or control ended within a defined scope.

Continuity is not a promise that everything lives forever; it is evidence that every material class reached an authorised end.

Sources

  1. NANOG Bylaws
  2. NANOG Articles of Incorporation
  3. Delaware Code, Title 8, Chapter 1, Subchapter X
  4. Merit Network: New Agreement Transfers NANOG Trademark and Resources
  5. NANOG Transition Update, May 2012
  6. NANOG Mailing-List Migration Announcement, September 2012
  7. NANOG Mailing-List Usage Guidelines
  8. NANOG, Inc. 2024 Audited Financial Statements
  9. NANOG Code of Conduct
  10. NANOG Board Responsibilities