Summary
- NANOG’s public mailing-list materials establish an open, archived technical forum with published rules, a subscriber reporting route and an announced escalation sequence. They do not establish how individual reports were handled, whether comparable cases received comparable treatment, who presently performs moderation, or whether participation is representative.
- A proportionate accountability record would add privacy-preserving aggregates: defined rule categories, intake and disposition counts, review windows, reconsideration availability, a policy-change log and clear small-cell limits. It should not turn complaints, private correspondence or volunteer decisions into a public case archive.
The promise and the limit of a visible forum
Technical communities often treat a public archive as evidence of openness. The instinct is understandable. A reader can see that a forum exists, can inspect that it is framed as public, and can find the published expectations that describe what the forum is for. Those are real institutional facts. They matter because a rule that cannot be found, a contact route that cannot be located, or a venue that cannot be inspected leaves a entity with little basis for understanding the terms of participation.
But visibility is not the same thing as a full record of governance. A message archive is designed to preserve messages. A governance record is designed to explain decisions, authority, procedure, comparable treatment and limits. The two can overlap, but they are not interchangeable. A person who sees a technical discussion can know that a discussion was made public. That person cannot, from that fact alone, know who read it, who declined to participate, which concerns were raised outside the list, whether a reported problem was reviewed, whether a rule was applied consistently, or whether any exchange altered an operational decision.
This distinction is especially important for a forum that is both a technical communication venue and a community institution. The mailing list is public-facing enough to create expectations of transparency, yet the work surrounding a list can involve private reports, abusive material, legal sensitivity, spam response, safety concerns and volunteer judgment. A demand that every action become public can create its own harms. A refusal to disclose any aggregate pattern, however, can leave readers unable to distinguish a visible rulebook from an accountable process.
The question is therefore neither whether everything should be disclosed nor whether an archive settles the matter. It is what the public file can responsibly establish, what it cannot establish, and what a minimal additional record might reveal without exposing people.
NANOG’s materials are unusually helpful for making that question concrete. They describe a mailing list as open, public, archived and community-moderated. They state an operational and technical subject perimeter, publish usage restrictions, identify a path through which subscribers may report violations, reserve removal powers and describe an escalation sequence. Separate dated archive material describes earlier committee arrangements and a later platform migration. Taken together, these materials form a public institutional file. They allow a reader to reconstruct the stated rules and some moments in the list’s history.
They do not provide a public case register.
That difference should discipline both praise and criticism. It would be too strong to say that public archives prove an institution is open in every consequential sense. It would be equally too strong to say that the absence of a public enforcement dataset proves secrecy or failure. The reviewed public file does not establish either proposition. It establishes a narrower and still useful proposition: NANOG has made certain rules, access paths, historical notices and archived communications available for public inspection.
What the published list description actually supplies
The public-facing list materials give a reader several kinds of information. First, they state a purpose. The list is presented as a place for technical and operational discussion. That matters because a stated purpose draws a boundary around relevance: it tells entities what sort of exchange the institution says it is convening. It does not prove that every message stays within that boundary, nor does it prove that the boundary is applied identically in every circumstance. It is a public description of intended use.
Second, the materials make the list legible as a service. A reader can locate archive access, subscription paths and a list-owner contact route. These details are operationally modest but institutionally significant. They tell an outside observer that the list is not merely an informal conversation detached from any visible maintenance surface. There is a place to subscribe, a public archive to consult and a stated route to seek help with the list. None of this demonstrates the experience of every subscriber or reader. It simply establishes that those public paths exist.
Third, the usage guidelines describe the list as community-moderated, open, public and archived. Each of those words has a different institutional meaning. “Open” can concern access to reading or participation. “Public” can concern the visibility of posts. “Archived” can concern preservation and retrieval. “Community-moderated” can describe a mode of governance rather than a complete procedure. It is tempting to fold those terms into one larger conclusion about legitimacy. That would be a mistake. A public archive can be open to viewing while participation remains uneven. A moderated forum can publish rules without revealing every decision.
A community can have visible norms without demonstrating that all affected voices regard those norms as fair.
The important point is not that the terms are empty. The important point is that they answer different questions. The archive answers a question about availability of messages. The published guidelines answer a question about stated expectations. The contact information answers a question about a visible route. None answers, by itself, the question of how many people tried to use the route, how quickly a concern was considered, whether the outcome was reconsidered or how often a particular rule category appeared.
This is a general problem in institutional reading. Documents often give the public the language of a process before they give it the evidence of a process. That is not necessarily evasive. Many processes cannot safely publish case-level detail. Yet the language should not be asked to bear more weight than it can carry. The careful reader should say: this is what the institution publicly states; this is the point at which the public record stops; this is the limited kind of additional evidence that would allow a stronger conclusion.
Rules are not a case history
NANOG’s published usage guidelines supply more than an aspiration. They identify restrictions concerning subject matter, conduct, marketing, auto-responses and competition-law risks. They state that subscribers may report violations. They reserve powers to reject or remove content or access under stated circumstances. They also describe an escalating sequence that begins with warnings, includes a 90-day restriction and can lead to permanent removal.
Those are meaningful public commitments. A person entering the list can see that technical and operational relevance is expected, that certain categories of conduct are outside the stated rules, and that there is an announced route from concern to possible consequence. The sequence also tells readers that the visible policy does not present removal as a single undifferentiated act. It describes stages. For a governance observer, that is enough to identify the contours of a stated enforcement design.
It is not enough to identify enforcement practice. The guidelines do not, in the reviewed public file, disclose a complete set of reports, dispositions, rationale categories, response times, reviewer identities, reconsideration requests or reversals. They do not supply denominators from which an observer could calculate how common a type of report is. They do not provide a way to compare like cases. They do not establish whether a warning was issued in any particular instance, whether a restriction was imposed, or whether a permanent removal occurred.
They do not establish that every decision follows the stated sequence in exactly the same way.
That is not a semantic quibble. It is the difference between a rule and an audit trail. A speed-limit sign establishes that a speed limit is stated. It does not establish the number of warnings, the consistency of enforcement or the disposition of an appeal. Similarly, a published escalation sequence establishes that NANOG publicly describes a progression of possible consequences. It does not establish a current enforcement statistic or an individual result.
The distinction also protects against a familiar analytical error: treating silence as a negative finding. If a case record is not visible in an archive, one cannot conclude from that absence that no report was received, that no review took place, or that no action occurred. Many of the most sensitive kinds of report ought not be exposed. Conversely, a public statement that reports may be made does not show that a report is always easy to make, that every reporter is satisfied, or that every concern falls within a visible category. The reviewed public file does not establish either side of those claims.
The useful middle ground is to ask for aggregate, not narrative, evidence. An aggregate record could indicate the number of matters received over a defined period without naming any complainant or subject. It could classify them by rule category without revealing message content. It could report dispositions in broad groups, such as no action, guidance, warning, temporary restriction, referral or another defined outcome, while avoiding cases where the count is too small to protect privacy. It could report a review window as a range or service level rather than expose the calendar of a particular person.
Such a record would not turn moderation into litigation. It would allow the public to see whether the published rulebook has an observable administrative life.
Openness has more than one dimension
“Open” is often used as if it were an all-purpose institutional verdict. In practice, it has several dimensions that should be kept separate. The first is discoverability: can a prospective reader find the forum and understand its stated subject? The public list-information page and guidelines speak to this dimension. The second is visibility: can a reader see a public archive? The archive speaks to that dimension. The third is access: can an interested person subscribe or seek a route to the list owner? The published paths speak to that dimension. The fourth is participation: who can speak, who chooses to speak and who feels able to do so?
The reviewed public file does not establish that dimension in a representative way.
There is also a fifth dimension: intelligibility of governance. Can a entity understand who has authority, what rules apply, what happens after a report, whether decisions may be reconsidered and how policy changes are communicated? The materials establish part of this picture. They publish rules, a reporting possibility and an escalation sequence. They preserve some historical committee notices. They do not, on the reviewed record, establish a current committee roster, a current decision protocol, an appeals practice or a current review timetable.
These distinctions matter because a community can do well on one dimension and weakly on another without the public file resolving the overall assessment. A forum can be easy to find but difficult for a newcomer to navigate. It can preserve messages but reveal little about the invisible work that keeps the forum usable. It can publish a rule against harmful behavior but protect reporters by keeping the underlying cases confidential. Each of these facts creates a different tension. None should be compressed into a single label such as transparent or opaque.
For NANOG, a careful description is available without overstating the record. The public materials show an openly described technical forum with a public archive, stated rules, a list-owner contact route and a stated reporting mechanism. That is more than an empty webpage. It gives members and observers a visible point of reference. But the reviewed public file does not establish how widely participation is distributed, whether particular voices are absent, whether the archive reflects all relevant deliberation or whether a thread represented a community-wide position. Openness of access and openness of outcome are not the same thing.
The same care is needed when people invoke the archive as proof of consensus. A list can reveal that several messages were exchanged. It cannot reveal every conversation that did not occur, every person who read without posting, every member who lacked time or confidence to reply, or every decision made elsewhere. A thread may be influential, ignored, contested or simply overtaken by events. Without a defined population, a method of observation and a verified decision linkage, it does not establish consensus or representation.
This is not an argument against public archives. On the contrary, archives are valuable precisely because they permit bounded verification. They let a reader inspect what was publicly said and when a public notice appeared. They give future entities a way to locate prior discussion. They can reduce dependence on memory and private recollection. The error begins only when the archive is made to prove the unobservable.
A dated maintenance notice is not a resilience score
The February 2025 archive material adds another useful but limited observation. It records a planned Mailman upgrade and migration and warns of a temporary period during which list access or subscription changes would be unavailable. This establishes that list infrastructure and archive handling were subject to a scheduled maintenance event. It also establishes that the public was told about an anticipated interruption.
That is the proper extent of the conclusion. A maintenance notice does not establish that the migration was completed without difficulty. It does not establish a measured level of availability before or after the event. It does not establish whether archives were complete, whether a subscriber experienced a problem, whether moderation workflows changed or whether the event had a downstream network effect. It is a notice of planned maintenance, not a reliability report.
The temptation to draw a stronger inference is understandable. Infrastructure maintenance is often interpreted through the language of resilience. A public notice can look like proof that a service is well managed, just as an outage notice can be treated as proof that a service is poorly managed. Neither conclusion follows from the notice alone. The visible message shows communication about a planned change. It does not supply an outcome metric, a baseline or a comparative history.
This matters because governance and operations are easy to conflate in a technical community. A platform migration may affect the ability to read archives or manage subscriptions for a period. That does not mean it reveals the quality of content moderation. A rule may regulate auto-responses or commercial promotion. That does not mean it reveals the reliability of the platform. A technical archive may document a maintenance announcement. That does not mean it proves a network event was prevented, caused or resolved by list activity. Each claim needs evidence tailored to the claim.
A sensible public operations record could go somewhat further than a notice without becoming intrusive. It could say that scheduled maintenance occurred, state a broad completion status, identify a retrospective policy change if one was made, and disclose only the kinds of service measures that can be safely and clearly interpreted. But those are recommendations for an accountability design. They are not facts established by the material at hand.
Historical committee notices are historical evidence
The archive also preserves several documents about earlier governance arrangements. A 2009 notice described a five-person Mailing List Committee responsible at that time for list administration and moderation, selected through a then-existing process after an election. Another 2009 announcement stated that a Communications Committee had formerly been the Mailing List Committee and described a wider remit around electronic communications. A 2012 notice described a Communications Committee selected by the Board, a condition concerning concurrent Board service and responsibilities involving list maintenance and minimal moderation.
These notices matter because institutions often leave their history in administrative announcements rather than in a single comprehensive constitution. They show that mailing-list administration and moderation had been described as assigned functions, that the names and remit of a committee changed over time, and that selection arrangements were publicly discussed in dated moments. They also demonstrate that “mailing list governance” has not necessarily meant one fixed structure across every period.
The dates are therefore not incidental. They are the principal interpretive boundary. A 2009 description establishes a 2009 description. A 2012 nomination notice establishes a 2012 nomination notice. Neither establishes the present composition of a committee, the present authority of a body, the present selection method, or the actual practice of particular people. Institutional terms can persist after an underlying process changes; an old name can disappear while some function continues; a function can be redistributed without a public archive document that an outside reader has found.
The reviewed public file does not settle these possibilities.
This is a place where apparent specificity can mislead. “Five-person committee” sounds precise, and it is precise about a historical description. It is not a license to describe a current roster or current governance mechanism. “Selected by the Board” sounds like a present rule, but within a dated notice it is evidence of the then-described arrangement. “Minimal moderation” sounds like a stable institutional philosophy, but it is not a current practice metric or an account of how any individual matter was decided.
The disciplined formulation is modest: public archive material records historical committee and selection descriptions. The reviewed public file does not establish whether those descriptions remain current. That sentence is less dramatic than a claim about who governs today, but it is more useful. It tells a reader exactly what has been observed and preserves the question that current documentation would need to answer.
There is a practical lesson here for any membership organization. Historical notices should be easy to distinguish from current policy. A simple current-governance page, dated and maintained, can reduce the risk that readers rely on an old announcement as a living rule. If no such page exists in the materials under review, the responsible observer should not invent one. Nor should the observer assume that historical silence proves present disorder. The public file supports neither inference.
A past debate cannot become a current audit
The January 2005 archive thread supplies a different kind of historical material: contemporary discussion that included reported moderation counts and concerns about transparency. It is valuable as a record that people at the time discussed these questions. It can show that moderation and transparency were subjects of debate. It can preserve how entities framed a problem in that moment.
It cannot be treated as a current statistical record. The reported counts in a discussion are not, in the reviewed public file, a verified present audit. They do not establish a modern baseline, current enforcement scale, consistency of treatment or the adoption of a proposed reform. A thread can document disagreement without resolving it. It can preserve a concern without proving the concern’s conclusion. It can record a suggested mechanism without showing that the mechanism was enacted.
This may sound obvious, but archives encourage a particular kind of over-reading. A searchable old exchange can appear more authoritative than it is because it is accessible and specific. The fact that text is preserved makes it easy to quote or summarize, but preservation is not validation. In a governance inquiry, age adds rather than removes the need for context. A number presented in a 2005 discussion belongs to the discussion unless it is accompanied by a verified method, scope and subsequent confirmation. A contemporary observer’s worry belongs to that observer’s period unless a later record establishes a continuing condition.
The strongest use of the thread is therefore historical and procedural. It shows that there have been public conversations about moderation transparency. That fact may explain why a carefully designed aggregate record would be useful today. It does not prove that present practice has the same gaps, that any old proposal became policy, or that a current institution is bound by the terms of a past debate.
This boundary protects entities as well as institutions. Old threads can contain incomplete context, rhetorical heat and references that were intelligible only to those present. Treating them as a standing dossier on people or decisions would be unfair. The better practice is to extract only the limited institutional observation: the archive preserves a historical discussion. It does not convert that discussion into a current judgment.
Why case-level transparency can be the wrong remedy
A reader who sees published rules but not published outcomes may reasonably want more accountability. The easy response is to demand a public register of every complaint, moderation action and appeal. That response is usually too crude. In a technical mailing list, the very matters that require attention can involve harassment, threats, sensitive professional disputes, personal information, accusations that cannot be safely repeated, legal risk or coordinated spam and abuse.
Public disclosure can expose a reporter to retaliation, revive harmful material, identify a entity through context or create an incentive to litigate every disagreement in front of an audience.
Volunteer capacity is another serious concern. A small group maintaining a community service may be able to apply a rule and respond to a concern, yet lack the time and legal support to produce elaborate public explanations for each matter. Requiring a case-by-case publication regime can shift effort away from keeping the forum usable and toward drafting defensive narratives. It can reward strategic complainants who seek an audience rather than a remedy. It can also make moderation more hesitant when rapid response is needed to limit spam, protect entities or reduce harm.
Privacy and safety do not make accountability impossible. They shape the form it should take. An accountability system should minimize the information necessary to establish whether rules have an observable administrative life. It should not publish names, messages, correspondence, specific incident narratives or small counts that permit inference about a person. It should distinguish public information about process from protected information about cases.
There is also a fairness reason to avoid a public case file. A visible complaint can become a permanent reputation event even when it is mistaken, withdrawn, unresolved or handled informally. A public explanation might need to restate allegations to rebut them, causing additional harm. A system that promises complete transparency may unintentionally make people less willing to report sensitive conduct or less willing to seek help from list operators.
The right counterargument, then, is not an afterthought. It is central to any credible proposal. Confidentiality, privacy, safety, anti-harassment practice, legal risk, anti-spam response and volunteer capacity are not excuses that an observer may dismiss because data would be convenient. They are design constraints. A public record that ignores them would be worse than no record if it exposed people or distorted decision-making.
At the same time, the existence of these constraints does not mean the only alternatives are total secrecy and total disclosure. Aggregate reporting is useful precisely because it can create a bridge. It can tell entities whether there were matters in broad categories, how long a process generally took, whether reconsideration existed and whether the written policy changed, while withholding anything that would identify a case. It can be sparse by design. Its purpose is not to narrate conflict. Its purpose is to let the public test the gap between a published process and an entirely opaque one.
The smallest useful accountability record
What would such a record contain? The first element is a stable set of rule categories. The categories should reflect the public rules at a level broad enough to protect privacy: for example, subject relevance, conduct, marketing or promotion, automated responses, competition-law concerns and another carefully defined administrative category. The categories should be published in advance, not constructed after a controversy, so that reporting is comparable across periods. They should not contain names, message excerpts or labels that would turn a small group of reports into a clue about a particular person.
The second element is an intake count. Over a defined reporting period, a record could state how many matters reached the process, perhaps with an explicit statement that it counts reports rather than people. That distinction matters. One person can make more than one report, one incident can generate more than one message and some concerns may be resolved informally before entering a formal channel. The record should define its denominator rather than allow readers to assume a measure of behavior or community sentiment.
The third element is a broad disposition count. Instead of publishing explanations for individual decisions, the record could report categories such as no action after review, guidance or reminder, warning, temporary restriction, another administrative outcome, or a category withheld because disclosure would be unsafe. A disposition taxonomy should be simple enough to maintain and stable enough to compare over time. It should also state that a count cannot measure fairness by itself.
A higher number may reflect more reports, more awareness of the route, a change in categorization, a temporary event or a different threshold for recording matters. The reviewed public file does not provide such counts, so this remains a proposal rather than a claim.
The fourth element is a review window. This need not expose the timing of any particular case. A periodic statement could give a target interval for initial acknowledgement and a broad range for closure, accompanied by a note that complex, safety-sensitive or legally sensitive matters can take longer. The objective is not to manufacture a performance score. It is to give entities a basic sense of whether there is a process that moves, and to show when capacity constraints may require a policy response.
The fifth element is reconsideration availability. A public rule can state whether someone affected by a decision may request reconsideration, what general channel exists for that request and what kinds of matters are excluded. It need not publish the request or its result. The presence of a reconsideration path does not prove every decision is correct. Its value is procedural: it tells entities whether an initial decision is the only possible administrative endpoint.
The sixth element is a policy-change log. If the rules, categories, selection arrangement or administrative process materially change, a dated public note can tell readers what changed and why at a high level. This is particularly important for a community whose historical materials reveal shifting committee names and remits. A change log prevents current readers from having to infer living policy from old archive notices. It also prevents the aggregate record from becoming misleading when categories or procedures change.
Finally, every element needs a non-disclosure rule. Small cells should be suppressed. A category with a very low count can reveal more than an institution intends, especially in a close community where people may recognize an incident. Reporting periods may need to be combined. Rare but severe categories may need to be grouped or omitted with a stated reason. The policy should explain these limits plainly so that omission is not mistaken for an assertion that nothing happened.
This proposal is deliberately modest. It does not ask NANOG to publish complaints, transcript excerpts, moderator identities, vote records, private messages or individual outcomes. It does not presume that a public list should imitate a court, regulator or large corporate compliance office. It asks only whether a community that publishes rules might also publish a privacy-preserving sign that the rules have a maintainable administrative surface.
Authority, incentives and the problem of legibility
The value of a minimal record is not only numerical. It is also about legibility. Entities are more likely to understand a rule when they can see the categories it covers, the route through which concerns may be raised and the basic shape of the process. Moderators or administrators, meanwhile, benefit when expectations are explicit enough to discourage demands for case-level disclosure that cannot safely be met.
Authority is a sensitive subject in a technical community. A mailing-list convention is not a government, regulator, regional Internet registry or public authority. It does not issue mandatory rules for network operators merely because people discuss operational matters there. Its mailing-list rules are rules of the forum. They govern participation in that forum, not the technical choices of an entire industry. Keeping that distinction clear reduces the risk that governance language is inflated into a claim of external power.
Within the forum, authority may still be consequential. A published rule can shape what people expect to say, how they report a concern and whether they believe a discussion space is usable. Yet the public record must not be used to infer that a particular post controlled an institutional decision or a network deployment. Operational communities often contain people with relevant expertise, but the presence of expertise in an archive does not demonstrate that a list exchange caused an outcome. The reviewed public file does not establish such causality.
The incentives around disclosure are also mixed. Entities may want reassurance that rules are not merely ceremonial. Administrators may want discretion to protect privacy and safety. Potential reporters may need confidence that a concern can be raised without making themselves visible. Volunteers may need a system that is proportionate to their capacity. A well-designed aggregate record does not eliminate these tensions. It makes them discussable in a bounded way.
For example, an annual record with a tiny number of categories could unintentionally invite readers to infer the identity of a case. A quarterly record might be more timely but more risky. A broad category such as conduct could conceal meaningful variation, while a narrow category could expose too much. A target review window could motivate responsiveness, but it might also create pressure to close difficult matters prematurely. A reconsideration channel could improve procedural confidence, but it could be misused to extend a conflict. The design task is to balance these tradeoffs, not to pretend they do not exist.
The central insight is that accountability is not synonymous with maximum disclosure. It is the capacity of a community to state its rules, show the existence of a process at an appropriate level of abstraction, acknowledge limits and update its public account when the process changes. An archive contributes to that capacity. It does not complete it.
What the public file cannot settle about voice
The list’s public availability may make it tempting to speak about entity voice as if the archive were a sample of a defined population. It is not. An archive shows messages that were sent to an archived forum. It does not show the number of people who read silently, the number who chose not to subscribe, the number who left, the geographic or professional distribution of readers, or the reasons a person might decline to contribute. It does not establish whether posters represent operators, vendors, researchers, students, advocates or any other group in proportion to a broader community.
Nor can visible message volume establish that entities agree. Agreement in a thread can be partial, temporary, rhetorical or confined to those who chose to speak. Silence can mean assent, fatigue, lack of access, fear of conflict, different priorities or simple absence. Without a defined question, a known population, a participation method and a way to observe nonresponse, the archive cannot be treated as a referendum.
This matters because claims about representation often become moral claims. If an observer calls a forum “the voice” of a community, people who did not speak may be erased. If an observer calls a thread unrepresentative, that too requires evidence about the relevant population. The responsible position is narrower: the public file establishes a venue in which certain public messages appeared. It does not establish the distribution of opinion beyond those messages.
The same restraint applies to inclusion and safety. The existence of conduct rules may indicate that an institution recognizes certain risks. It does not establish how safe every entity feels. A public archive may allow an outside reader to search for topics, but it cannot reveal the experience of a person who decided not to post. A reporting route may be valuable, yet the reviewed public file does not establish how often it is used or whether everyone trusts it.
These are questions for different evidence: confidential surveys with appropriate safeguards, independently designed participation research, or carefully anonymized process reporting. They are not answered by the archive alone.
The difference between visibility and operational effect
Technical forums are often close to operational work, which makes causal claims especially tempting. A reader may see a discussion of a routing issue, a maintenance concern or a coordination question and conclude that the list produced a specific operational result. That conclusion generally requires much more than an archive. It would require a traceable connection between the discussion and a decision, evidence about the relevant network or organization, and a method for separating the effect of the discussion from other information and actors.
The materials reviewed here do not provide that connection. The list is described as a technical and operational forum. That establishes a subject perimeter. It does not establish that a message caused a deployment, prevented an outage, changed a commercial decision or affected public policy. A scheduled Mailman migration establishes a maintenance notice for the list infrastructure. It does not establish a network outcome. A historical committee notice establishes a past governance description. It does not establish operational control over participating networks.
Restraint here is not a refusal to recognize the value of technical exchange. Technical discussion can be useful without being reducible to a measurable causal claim in every case. The public archive can preserve ideas, questions and explanations for future readers. It can make it easier to find prior discussion. It can support institutional memory. But an investigator should not write an outcome into the record where the record supplies only a conversation.
This is one reason why a minimal governance record should be kept separate from claims about technical impact. Moderation aggregates might show something about the administration of the forum. They would not show whether the forum improved network resilience, expanded participation or produced consensus. Those are different questions with different evidence requirements. Combining them would make both forms of accountability less credible.
An implementation path that does not create a surveillance system
If a community chose to build the limited record described here, implementation could begin with policy rather than software. The first step would be to define what enters the count. Is a matter counted when a subscriber contacts a list-owner route? When an administrator opens a review? When a decision is made? When a message is rejected? Different choices create different numbers. The rule should be written in plain language and remain stable enough for readers to understand changes over time.
The second step would be to define a small, public taxonomy aligned with the published rules. A record that has too many categories can become a coded case narrative. A record with too few categories can become useless. The appropriate middle ground would be broad, durable categories and a documented method for handling ambiguous matters. The method should avoid retroactive relabeling merely to make one reporting period look better than another.
The third step would be to choose a reporting cadence. An annual report may reduce privacy risk and volunteer burden but provide slow feedback. A longer interval may obscure a policy change. A shorter interval may create unstable small numbers. The choice is a governance judgment, not a technical inevitability. Whichever cadence is chosen, the report should state the period it covers and whether any changes in process make comparison to earlier periods unreliable.
The fourth step would be to build small-cell suppression into the design from the start. It should not be an exception triggered after someone notices a sensitive count. If a category is too small, the report can combine it with another broad category, aggregate periods, or disclose only that a category was withheld under a published privacy rule. The record should never include enough contextual detail for a reader to reconstruct an individual incident from community knowledge.
The fifth step would be to state who is responsible for maintaining the record in functional rather than personal terms. Historical archive notices show that committee arrangements and names can change. A public record should not become stale because it depends on an outdated title. It can identify an administrative function and link any current policy update to a dated change log, without turning the record into a roster of volunteers.
The sixth step would be a review of second-order effects. Would aggregate reporting discourage people from raising a concern? Would it create pressure to classify complex matters too quickly? Would it expose a pattern that is meaningful to an informed insider but opaque to the general reader? Would it attract performative disputes over counts rather than improve the experience of using the forum? These are not reasons to abandon the idea. They are reasons to test it cautiously, with a presumption that privacy and safety take priority over a more detailed public chart.
The irreversible risk is the creation of a permanent public incident record by accident. Once names, message snippets or sufficiently detailed case descriptions are published, they can be copied beyond the control of the forum. That is why the recommended record is aggregate and deliberately unspectacular. A modest table that tells readers a process exists may be more responsible than a dramatic transparency exercise that harms the people it claims to protect.
The strongest case for leaving the archive alone
It is worth stating the strongest argument against any additional public record. NANOG may already provide the information that a public technical mailing list needs to provide: a visible purpose, access paths, a public archive, rules and a route to report violations. Moderation may be rare, largely preventive or highly context-specific. Additional reporting could consume volunteer effort without yielding a reliable measure of fairness. It could invite outsiders to treat small aggregate counts as a scorecard, make weak inferences about community health or pressure administrators to disclose matters that should remain confidential.
The historical materials also caution against a simplistic demand for structural certainty. A community’s arrangements can evolve, and dated notices may preserve only snapshots of that evolution. Requiring a permanent public explanation for every shift could produce paperwork that outruns practical need. A functional technical forum may be better served by clear current rules and responsive administration than by an elaborate governance publication.
This argument deserves respect. It recognizes that a mailing list is not a public court and that volunteer institutions have finite capacity. It also recognizes that the archive itself is already a significant public good. The appropriate answer is not to insist that every forum must adopt the same reporting design. It is to say that if members or administrators seek a middle path, a privacy-preserving aggregate record is one available option.
The recommended record should therefore be evaluated against a high threshold. It should exist only if it can be maintained accurately, interpreted cautiously and produced without exposing entities. It should be discontinued or redesigned if it creates identifiable small cells, encourages retaliatory attention or diverts disproportionate effort from keeping the list usable. Its value lies in modest procedural reassurance, not in the production of a spectacle.
A more precise public vocabulary
The practical benefit of this inquiry may be linguistic. Public discussion of community institutions often collapses many questions into a few charged words: open, censored, transparent, captured, representative or accountable. The reviewed public file does not establish most of those larger judgments. A more precise vocabulary would improve discussion.
Instead of saying the archive proves transparency, one can say that a public archive exists and preserves public messages. Instead of saying the published rules prove fair enforcement, one can say that the rules describe an escalation sequence and a reporting route. Instead of saying a dated committee notice identifies current authority, one can say that it records a historical arrangement. Instead of saying an old thread proves a present problem, one can say that it preserves a contemporary concern.
Instead of saying that a technical discussion caused an operational outcome, one can say that the list is publicly described as a technical and operational forum.
None of these formulations is evasive. Each makes a claim that the public file can bear. They also make room for the evidence that would be needed to go further: a current governance statement, an appropriately protected aggregate record, a methodology for studying participation, or independent evidence linking discussion to an operational decision. Precision is not a retreat from accountability. It is the condition for accountability claims that can survive scrutiny.
For NANOG, the central conclusion is therefore simple. The public file can show a forum with visible rules, archives, access paths, a reporting possibility, an announced escalation sequence, historical committee descriptions and a dated maintenance notice. It cannot, on this material alone, show a completed case file, an individual sanction, a current moderator roster, consistent enforcement, appeal practice, representative participation, consensus or a network effect. A small aggregate record might narrow some of those gaps without turning private governance into a public case archive.
Whether such a record is worthwhile is a design question for the community, not a factual conclusion the archive can decide.
Sources
- https://nanog.org/nanog-mailing-list/usage-guidelines/
- https://lists.nanog.org/mailman3/lists/nanog.lists.nanog.org/
- https://lists.nanog.org/archives/list/[email protected]/2025/2/?page=2
- https://lists.nanog.org/archives/list/[email protected]/2009/7/
- https://lists.nanog.org/archives/list/[email protected]/2009/10/
- https://lists.nanog.org/archives/list/[email protected]/2012/10/
- https://lists.nanog.org/archives/list/[email protected]/2005/1/
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
