Summary

  • npNOG’s published conduct policy sets a clear behavioural floor and gives organisers power to act quickly.
  • The harder question is whether the public record makes the reporting, conflict and correction process legible without exposing the people it is meant to protect.

A rule with immediate consequences

A code of conduct is not merely a statement of tone. npNOG’s published policy says the conference should be free from harassment across a broad list of protected characteristics. It lists prohibited conduct, tells participants that violations can lead to sanctions or expulsion without a refund, and places that decision within the discretion of conference organisers.

That is a real enforcement rule. It tells a potential harasser that participation is conditional, and it tells an organiser that safety can require an immediate consequence. The policy also extends beyond formal sessions to social events and online or digital spaces. For a technical community whose work moves between workshops, conference rooms, mailing channels and informal gatherings, that scope matters.

The response language is practical. A person who experiences or observes harassment, or has another concern, is told to contact a member of npNOG staff immediately. Staff may help contact venue security or police, provide an escort, or otherwise help the person feel safe for the duration of the event.

Those provisions should not be minimised. A policy that names prohibited conduct, reaches related spaces and authorises removal is more useful than a general promise that everyone should be respectful. It gives organisers room to stop harm before a complete institutional record can be assembled.

The public process becomes less specific after the first report

The policy is clearest at the point of immediate contact: find a staff member. It is less specific about what happens next.

The reviewed page does not identify a role-based reporting contact, a named conduct panel or a confidential channel. It does not say who receives a written account, who can see it, how evidence is retained, how a conflict is handled or which organiser makes a sanction decision. It does not describe a correction or appeal path if facts are disputed. The three reviewed first-party pages also do not publish privacy-safe aggregate counts of reports, remedies or sanctions.

These are documented absences from the reviewed public record, not proof that no internal practice exists. npNOG may brief staff, assign trusted contacts or handle reports through procedures that are not published. The pages do not allow a reader to verify those possibilities either way.

That distinction is essential. A missing public procedure cannot be converted into a claim that an incident occurred, that a report was mishandled or that organisers acted with bias. It does, however, limit what a participant can know before deciding whom to approach and what will happen to the information they share.

Committee names do not answer the conduct question

npNOG’s committee page gives useful institutional context. It describes the Core Committee as the main management committee overseeing npNOG. It assigns conference and workshop content to the Programme Committee and the fellowship programme to the Fellowship Committee. It also says that additional committees are formed for individual meetings.

None of those descriptions explicitly assigns conduct-reporting or sanction responsibility. The Core Committee’s general management role might make it relevant, but that is an inference, not a published case-handling rule. The Programme Committee’s authority over content does not make it the appropriate recipient for a harassment report. The Fellowship Committee’s responsibility for support does not establish a safeguarding role. A meeting-specific committee may handle incidents, but the reviewed page does not say so.

This matters when relationships overlap. A report could involve an organiser, a committee member, a sponsor representative, a trainer or a colleague from the same employer as the person receiving it. The public policy does not describe a recusal rule for that situation. Again, that silence is not evidence of an actual conflict. It is an unresolved design question about how discretion remains credible when the community is small and professionally interconnected.

The general terms add one operational contact: a registration address. They use it for registration inquiries, cancellation and substitution. They do not present it as a confidential conduct-reporting channel. Treating every published email address as interchangeable would create clarity on paper by inventing a role that the source does not assign.

Privacy is not the same as opacity

The strongest argument against extensive disclosure is also the most important one. In a small technical community, even a case stripped of names can be recognisable. Dates, employers, session roles or a description of the remedy may identify a complainant or respondent. Publishing case narratives can deter reporting and turn a safety process into a new source of exposure.

Urgency also matters. An organiser who sees a participant at immediate risk cannot wait for a multi-stage tribunal. Escorting someone, separating participants or involving venue security may require discretion in minutes, not a formal record assembled over days.

Those constraints support a restrained public process, not necessarily an invisible one. npNOG could explain the shape of the mechanism without publishing case facts. A policy can identify a role rather than a person, state how an alternative contact is chosen when that role has a conflict, describe who may access a report, and separate immediate protective measures from a later sanction decision.

It can also state a retention boundary. Participants do not need the contents of prior reports, but they may reasonably want to know whether a report is recorded, how long it is kept and when it can be shared with security, police or another event organiser. If no records are retained, that too is a consequential policy choice worth stating.

A minimum accountable process

The objective need not be a large disciplinary bureaucracy. A compact public protocol could preserve urgent organiser discretion while making five points verifiable.

First, it could name two role-based contacts for each event, with at least one route outside the ordinary reporting line of the other. Second, it could explain the confidentiality boundary and the circumstances in which information may be shared for immediate safety or legal reasons. Third, it could publish a simple recusal rule and identify who takes over when a designated contact is involved. Fourth, it could distinguish temporary protective action from a final sanction and offer a narrow correction path for factual error.

Fifth, it could publish annual or per-event totals only where aggregation cannot expose individuals, including a clear decision to withhold statistics when the numbers are too small.

Support options should also be described without promising services that are not available. The existing policy already mentions escorts, venue security and police. A future version could state whether a participant may bring a support person, whether remote reporting is possible after the event, and whether the organiser can help a person leave a social activity safely. Each commitment should match the capacity organisers actually have.

Sources