Summary

  • NRS's role in this subject is advocacy, research, campaigning, convening and authorized member representation. The operational acts belong to RIR policy bodies, affected resource holders, network operators and independent researchers; citing an NRS position is neither evidence that NRS performs them nor an endorsement by BTW.
  • Registry policy should be treated as a testable claim about conduct, registry decisions, routing evidence, cost and distribution. Open participation and clear drafting remain necessary, but neither proves that a rule will solve the stated problem under ordinary operating conditions.
  • Every proposal should begin with a public problem dossier that defines the baseline, measures frequency and severity, identifies affected operator classes, distinguishes registry facts from routing observations, and states what evidence would show that no material problem exists.
  • Before adoption, a neutral implementation team should run representative cases, adverse cases, migration cases and counterexamples through the proposed rule. The result should show required inputs, decision points, elapsed time, failure states, appeal paths and effects on existing resource holders.
  • Cost must be allocated rather than described in aggregate. The proposal should identify one-time and recurring cost for the registry operator, large networks, small operators, public bodies, legacy holders and third parties, including delay, evidence retention, legal review, automation and opportunity cost.
  • Counterexamples are constitutional evidence. A proposal that works only for its motivating case is not ready; authors should publish the strongest lawful situations in which the rule denies a legitimate request, rewards the wrong conduct or creates an avoidable continuity risk.
  • Adoption should set outcome measures, a review date, an evidence custodian and a consequence for failure. High-impact rules should lapse, narrow or return for affirmative renewal when measured effects diverge materially from the case on which authority was granted.
  • Demonstrated operational effect does not demand certainty or give staff a veto. It requires decisions under uncertainty to be explicit, comparable and reversible, while emergency authority remains narrow, temporary and subject to rapid retrospective testing.

The role boundary is part of the evidence

NRS's own stated positioning supplies the first boundary for this analysis. It is a membership and advocacy organization pressing for decentralization, exit, portability, redundancy and fewer discretionary choke points. Heng Lu's note on why NRS exists says directly that NRS does not sell products or implement commercial solutions; its role is to change the direction of governance. NRS may therefore publish research, organize campaigns, convene affected operators, support members and represent an organization that has granted it authority. It may not turn that representation into registry authority over anyone else.

The implementation layer is separate. RIR policy bodies, affected resource holders, network operators and independent researchers remain responsible for any authoritative registry record, allocation, transfer recognition, RPKI or RDAP operation, technical failover, binding review, insolvency act or legally compelled remedy relevant to this article. The NRO coordinates the five RIRs; it is not another name for NRS. IANA numbering services perform their defined coordination role; they are not an NRS department. Courts and lawful public authorities retain the powers their legal systems actually give them.

BTW's role is separate again. BTW reports the observable structure, checks primary sources and labels proposals as proposals. It does not convert NRS advocacy into fact, campaign on NRS's behalf or infer authority from alignment. That reality-not-advocacy discipline is why the institutional nouns in this article matter: a recommendation from NRS, an act by an RIR and an order from a court are three different things.

Policy is an empirical claim with coercive consequences

A number-resource policy does more than express a community preference. It changes who may receive an allocation, retain a registration, complete a transfer, create a route-origin authorization, correct a public record or obtain review. Those consequences reach beyond meeting entities. They affect networks that may never speak on a mailing list but must still configure routers, answer abuse reports, maintain credentials, negotiate contracts and explain registry decisions to customers or public authorities.

The rule therefore contains an empirical claim even when its language is normative. A needs test claims that specified documents distinguish genuine operational need from speculation. A transfer condition claims that a particular check reduces fraud or preserves stewardship at tolerable cost. A contact-accuracy rule claims that a defined duty and sanction will improve reachability. A route-security measure claims that the registry action will produce better authorization state without creating unacceptable lockout or concentration risk.

Discussion can refine those claims, but repetition cannot validate them. Ten speakers may share the same untested assumption. A quiet operator may hold the only experience that reveals a costly edge case. Staff may be able to administer a sentence in the normal case while failing when ownership, insolvency, sanctions, public procurement or emergency recovery complicates the facts.

Demonstrated operational effect begins by making the claim visible. The proposer must say what conduct will change, through which mechanism, for which population, over what period and at whose cost. The registry operator can then decide with disciplined uncertainty rather than mistaking textual agreement for practical knowledge.

The constitutional standard should ask five questions

The registry operator should not turn every proposal into an academic research project. It needs a compact standard proportionate to the effect of the rule. Five questions provide that standard.

First, what measured problem justifies intervention? Second, can the proposed text be administered consistently across representative and adverse cases? Third, who pays in money, delay, evidence production, lost options and institutional risk? Fourth, what counterexamples expose limits or perverse incentives? Fifth, when and by what evidence will the registry operator decide whether the rule should continue?

These questions correspond to the life of a rule. Problem evidence establishes need. Operating tests examine causation and administrability. Cost allocation reveals distribution. Counterexamples test the boundary. Sunset review compares expected and observed effects. Each stage can change the text, narrow its scope, support an alternative or end the proposal without declaring its author defeated.

The standard should be constitutional because ordinary enthusiasm is least reliable when an issue feels urgent or morally obvious. A proposal framed as fairness can obscure the cost of proving eligibility. A proposal framed as security can create a single point of institutional failure. A proposal framed as conservation can preserve incumbency rather than address current scarcity. Requiring the same evidence categories across causes makes those trade-offs easier to see.

Proportionality matters. A correction to an obsolete cross-reference needs little more than a text comparison and implementation confirmation. A rule capable of revoking registration, delaying transfers, altering eligibility or affecting route-security credentials needs the full record and a demanding review term.

The problem dossier comes before the preferred solution

Policy discussions often begin with a drafted remedy. Once language exists, entities argue over verbs and exceptions before agreeing on the condition being repaired. The registry operator should reverse that sequence for material proposals. The first public document should be a problem dossier that does not depend on the proposed answer.

The dossier should define the event of concern in observable terms. “Fraud is increasing” is too broad. A useful definition might identify completed transfers later reversed for falsified authority, applications abandoned after verification, unauthorized account changes, or duplicate claims over the same resource. Each category has a different denominator and may require a different response. Combining them produces a dramatic number without a coherent mechanism.

The dossier should state the time range, geographic reach, data owner, collection limits and confidence interval where appropriate. It should separate reported allegations from confirmed events and identify rule changes or detection improvements that break comparability. A rise in discovered cases can show better controls rather than more underlying misconduct.

Most importantly, it should state a disconfirming threshold. If the alleged harm occurs in only a handful of exceptional cases, causes no durable loss and can be addressed through existing review, the proposed general restriction may be excessive. An author earns credibility by identifying evidence that would weaken the case, not only evidence that can be arranged to support it.

Registry-operator staff should assist with lawful aggregation and confidentiality protection, but the proposer remains responsible for the causal argument. Access to institutional data must not turn administrative preference into presumed necessity.

A baseline prevents improvement from becoming a slogan

Without a baseline, every post-adoption change can be described as success. The registry operator should record the state against which the rule will be judged before implementation begins. The baseline needs volume, rate, duration, distribution and consequence, not a single headline total.

For a transfer rule, relevant measures may include monthly requests, completion rate, median and tail completion time, rejection reasons, contested authority claims, corrections after completion, operator size and destination region. For registration accuracy, measures may include tested contact reachability, correction time, false-positive rate, repeated failures and the relationship between contact failure and actual resource control. For route security, measures may include eligible holdings, authorization coverage, stale authorization frequency, mistaken invalid states and recovery time after credential loss.

The baseline should cover at least one complete operating cycle where the issue is seasonal. Year-end mergers, annual audits, public procurement calendars and membership renewal can change volumes. A short sample may confuse timing with trend. When historical data are incomplete, the dossier should say so and recommend observation before broad intervention.

Distribution is as important as the average. A rule that cuts median processing time while doubling the longest delays for small public networks may not be an improvement. Likewise, a control that stops one severe loss may justify moderate common cost even if average speed falls. The registry operator must predeclare how it will weigh severity against frequency.

The baseline is not sacred. Better measurement may reveal errors. Changes should be versioned and explained, however, so that the reference point cannot move quietly after results disappoint.

Registry evidence and routing evidence are not interchangeable

Number-resource governance operates beside, but does not control, the global routing system. A registration record can show the recognized holder and authorized contacts. A route collector can show that a prefix appeared with an origin autonomous system at observed vantage points. Neither fact alone proves the entire legal, contractual or operational relationship.

Policy proposals routinely risk crossing that boundary. An observed origin may be a customer, transit arrangement, mitigation provider, anycast node, temporary migration or unauthorized announcement. Absence from a collector does not prove non-use. Registration in one name does not prove that every operational role belongs to that entity. A route-origin authorization expresses an authorization state; it does not guarantee propagation, reachability or beneficial ownership.

The problem dossier should therefore carry an evidence map. Each field must be labelled by what it can establish, its observation window, known blind spots and the decision weight it may bear. Registry account history may prove who authenticated an update. Corporate records may support a change of legal control. Contracts may support delegated operation. Routing observations may identify a technical pattern worth inquiry. None should silently substitute for another.

This distinction protects both enforcement and legitimacy. Weak evidence produces inconsistent decisions and encourages sophisticated operators to structure around naive tests. Overclaiming routing data also creates false accusations that are difficult for small networks to rebut. registry policy should use network-resource evidence precisely enough that operators can predict what a fact will and will not decide.

Incidents require denominators, not accumulation

A folder of troubling cases can show that a problem exists. It cannot show how much general authority the problem justifies. The registry operator should require a denominator that connects incidents to the population exposed to the rule.

If eight transfers involved contested authority, were they eight of eighty or eight of eighty thousand? Did all eight arise in one corporate form or jurisdiction? Were they detected before completion under current controls? Did losses persist after appeal? If a contact validation exercise found unreachable addresses, how many contacts were tested, by which channel, at what time and with what retry method? A bare percentage without method is equally weak.

Severity can justify action even at low frequency. A single event capable of fragmenting the recognized ledger or disabling a large public network deserves attention. The answer is not to ignore rare harm, but to describe expected loss: probability, scale, reversibility and available containment. That makes a narrow high-assurance control comparable with a broad low-assurance restriction.

Denominators also expose selective visibility. Large operators generate more records and may appear more problematic simply because they are observed. Small holders may have fewer transactions but a higher failure rate. Legacy resources may look inactive under measures designed for frequent account use. Public-sector networks may update slowly because legal authority is dispersed, not because claims are false.

The registry operator should publish both count and rate, with uncertainty. Policy gains honesty when it can say, “We know twelve serious cases, but cannot yet estimate prevalence,” instead of presenting twelve as self-proving scale.

The affected-operator map must precede consensus

An open meeting is not a census of operational exposure. The proposal should identify the classes whose rights, cost or continuity will change, then test whether evidence from those classes is present. The map is analytical, not a quota for speaking.

Useful distinctions include large and small access networks, hosting providers, content networks, exchanges, public bodies, universities, community networks, multinational groups, holders with legacy or sponsored resources, recent transferees and organizations in jurisdictions with currency or document constraints. The same rule can be trivial for an operator with counsel and automated inventory but burdensome for a municipal network with one engineer and paper-era records.

The map should also include indirect parties. Customers may lose continuity when their provider cannot complete a resource update. Security researchers may depend on usable registration contacts. Upstream networks may bear route-filter changes. Banks, insolvency practitioners and courts may need a predictable method to establish authority during restructuring. These parties need not decide number policy, but their operational evidence matters.

The registry operator should publish which affected classes supplied evidence, which were invited and not heard, and which remain unknown. Lack of response is not proof of indifference. It can reflect language, timing, low awareness, fear of exposing commercial facts or the rational choice not to monitor every institutional discussion.

The decision body can still proceed when perfect representation is impossible. It should do so with an explicit uncertainty discount and a narrower rule, stronger safeguards or earlier review where exposure is poorly observed.

An operating test turns sentences into decisions

Before a material rule is adopted, a neutral team should take the proposed text and execute it against a set of fictionalized but realistic cases. The test is not software quality assurance. It is a constitutional demonstration that the rule produces intelligible decisions when facts are incomplete and interests conflict.

Each case should begin with the same materials an applicant or existing holder could reasonably provide. The team records required evidence, questions asked, decision-maker, discretionary judgment, elapsed time, dependencies, result and appeal route. Staff should identify any point at which they had to invent a standard absent from the text. Authors can then amend the rule or make the delegation explicit.

The case set should include the motivating harm, an ordinary compliant request, a small operator, a complex corporate group, a public body, an organization with older records, a cross-border change and an urgent continuity event. It should also include missing documents, conflicting authentic documents and a good-faith error. Testing only cooperative, well-documented applicants proves little.

Results should be public in redacted form. Operators need to see not merely that staff considers the rule implementable, but how decisions differ from current practice. If two qualified reviewers reach opposite outcomes, the ambiguity is policy evidence. If both reach the same outcome for reasons not stated in the rule, hidden discretion has been discovered.

The test does not bind future case decisions. It reveals the operating theory before authority becomes real.

The transaction walk-through should follow time, not just logic

Many policy effects arise from sequence. A requirement may be reasonable in isolation but dangerous when it delays a transfer after payment, blocks a security update during an account dispute or asks an insolvent holder for approval from an officer who no longer has authority. The registry operator should therefore publish a time-ordered walk-through.

The walk-through begins when the operator encounters the rule, not when staff opens a case. It includes discovering the requirement, gathering evidence, translating or certifying documents, obtaining counterparty action, submitting, waiting, answering questions, receiving a decision and seeking review. Where the rule affects an existing registration, it should show what services continue during disagreement.

Elapsed time should be presented as a range, with the slowest credible case. A two-hour staff task may impose six weeks on an operator waiting for a court certificate. A low fee can trigger substantial professional cost. A simple online declaration can be impossible for an institution whose signing authority requires a public meeting.

The walk-through should identify irreversible moments. Once a transfer is recognized, routing and commercial arrangements may change. Once a route-origin authorization is revoked, automated routing decisions may follow. Once public contact data are altered, third parties may rely on them. Policy should place stronger evidence and review before, not after, an irreversible step.

By treating time as an effect, the registry operator can see where provisional continuation, a stay, staged verification or a rollback window is necessary.

Counterexamples are evidence, not obstruction

A strong counterexample satisfies the proposed rule's factual assumptions yet produces an outcome the registry operator would reject. It is more valuable than a vague objection because it locates the boundary of the policy theory.

Consider a rule requiring recent route visibility to prove address use. A legitimate network may hold disaster-recovery space that is deliberately unannounced until a crisis. A public safety network may use resources on a closed interconnection. A migration may temporarily move origin while control remains unchanged. These cases do not prove that routing evidence is useless; they prove that visibility cannot be conclusive by itself.

Consider a rule requiring an officer named in old registration data to approve a transfer. A lawful merger may have extinguished that office. An insolvency practitioner may hold authority despite not appearing in the historic account. A court-appointed administrator may be the only person able to act. The counterexample shows where current-record authentication and legal authority diverge.

Authors should publish the five strongest counterexamples they can find and state whether each leads to an exception, different evidence, a narrower scope or acceptance of residual harm. Opponents should be encouraged to improve those cases rather than multiply slogans. Chairs can distinguish a fatal example from a manageable exception by testing frequency, severity and administrative clarity.

A proposal that survives hostile examples has earned confidence. One that changes in response has gained quality. One that refuses to name a losing case is not ready to exercise high-impact authority.

Costs must be assigned to actors and moments

An impact statement that says “moderate implementation cost” conceals the central distributive question. The registry operator should require a cost ledger by actor, event and period. At minimum, it should identify costs for the registry operator, ordinary operators, small operators, complex cases and third parties.

registry operator costs include system changes, staff training, decision time, legal review, records, communications, appeal capacity and monitoring. Operator costs include learning the rule, inventory changes, evidence retention, professional advice, downtime risk, delay and repeated submissions. Third-party costs may fall on counterparties, sponsoring organizations, upstreams, auditors or public authorities.

The ledger should separate one-time transition from recurring compliance. It should also separate direct expenditure from opportunity cost. A network engineer spending three days reconstructing historical assignments is not free because no invoice exists. A transfer delayed by a month can change financing, acquisition or customer commitments. An additional appeal layer may be expensive yet reduce much larger expected loss.

Cost ranges are more honest than false precision. Assumptions should be visible: transaction volume, staff grade, document availability, automation rate and expected dispute frequency. The proposal should show how results change when those assumptions move.

Finally, the ledger needs incidence. Who ultimately bears the burden? A fee charged to a registry member may be passed to customers. A documentary duty imposed on a recipient may require the source holder to rebuild records. Cost allocation makes explicit whether the people deciding are also the people paying.

The small-operator case is a necessary stress test

Average compliance cost is often measured against the resources of entities most able to attend. The registry operator should require a small-operator case for every material proposal, not as sentiment but as an engineering constraint.

The case should assume limited staff, no dedicated counsel, imperfect historical records, ordinary connectivity and a need to keep serving customers while responding. It should not assume negligence. Many legitimate networks inherited address records through acquisitions, public reorganizations or early Internet arrangements whose documents predate current expectations.

A rule can impose regressive fixed cost even when its nominal terms are equal. Ten hours of evidence work is a small fraction of a large registry department and a critical interruption for a two-person network team. Translation, notarization and travel can vary sharply by jurisdiction. A requirement to maintain a particular automated interface may be cheaper for a large platform than a manual alternative is for a small holder.

The stress test should ask whether the same assurance can be obtained through standard evidence bundles, assisted verification, phased deadlines or risk-based review. Accommodation must not become a route around security. It should preserve the proof objective while changing the means.

If no proportionate path exists, the proposal should say that some legitimate small operators will bear high cost and explain why the avoided harm justifies it. Hidden regressivity is worse than an openly chosen trade-off because it deprives the electorate of the actual decision.

Cost allocation should follow the claimed benefit and caused risk

After measuring cost, policy must decide who should bear it. Three principles can guide that decision: beneficiary, risk creator and common infrastructure.

A transaction-specific check that mainly protects the parties to a transfer may be charged to those parties, provided broader registry integrity is not the dominant benefit. A remediation duty caused by repeated inaccurate submissions may follow the responsible operator. A continuity reserve, secure authentication base or unique ledger benefits the whole system and belongs in common funding even though incidents are uneven.

These principles will sometimes conflict. Enhanced fraud review protects the recipient, existing holder and public record. A pure user-pays fee may discourage legitimate transfers while doing little to deter sophisticated fraud. Common funding may be fairer where every operator benefits from confidence in the register. The registry operator should state which rationale controls and examine behavioural effects.

The choice also affects participation. If proposers can impose expensive obligations on a narrow class that is absent from discussion, the political price of policy falls toward zero. Requiring an incidence statement forces the decision body to confront that asymmetry. A high-impact rule should face a stronger mandate when most cost falls on a defined minority.

Scarcity deserves special care. Charges based on IPv4 holdings may approximate ability to pay, service burden or economic benefit, but each theory is different. The registry operator should not treat the apparent market value of an address as institutional revenue waiting to be claimed. Cost allocation must remain tied to the stated policy purpose.

Alternatives should form a ladder, not a ceremonial paragraph

Proposals often list “do nothing” and the preferred rule, making intervention appear inevitable. The registry operator should require an alternatives ladder that moves from observation through guidance and targeted measures to general obligation.

The first rung is better measurement. If prevalence is unknown, a defined observation period may produce more value than immediate restriction. The second is clearer guidance or standardized evidence, useful where inconsistent outcomes arise from uncertainty rather than bad incentives. The third is voluntary support, such as account-security tools or assisted record correction. The fourth is a targeted rule for high-risk transactions. Only then comes a general duty, denial condition or sanction.

For each alternative, the dossier should compare expected harm reduction, cost, error, speed, enforceability and reversibility. A narrow measure may solve less of the problem but preserve more legitimate conduct. A broad measure may be justified where the loss is catastrophic and detection difficult. The point is not always to choose the least restrictive option; it is to show why the chosen rung matches the evidence.

Existing powers belong on the ladder. If current fraud review, appeal or contract enforcement can address the observed cases, the proposer should explain why they failed. Sometimes the failure is resources or inconsistent execution, not missing policy. Writing a new rule can provide symbolic action while leaving the actual constraint untouched.

Alternatives make the causal claim testable. If two measures can be compared during a limited term, the registry operator can learn rather than legislate from intuition.

Implementation analysis must be independent enough to disagree

The people expected to administer a rule hold valuable knowledge about feasibility. They also have institutional interests: manageable workload, familiar tools, legal safety and preferred forms of evidence. The registry operator should use staff analysis without turning it into an unchallengeable verdict.

The official implementation assessment should state required capabilities, estimated cost and time, legal conflicts, data protection effects, training needs, service dependencies, likely dispute volume and unresolved ambiguity. It should distinguish a technical impossibility from inconvenience, and a legal prohibition from conservative preference. Assumptions and confidence should be visible.

Proposal authors should be able to respond. An independent reviewer with registry and operator experience should test material contested claims. The reviewer need not choose policy; its task is to determine whether the operating demonstration is reproducible and whether omitted alternatives or costs could change the decision.

The RIPE policy process offers a useful bounded comparison. Its formal description says the secretariat supplies relevant facts and statistics and publishes an impact analysis addressing possible effects and implementation work, while decisions remain with the community through an open consensus process. The RIPE Policy Development Process therefore separates administrative evidence from final authority.

The registry operator should strengthen that separation with explicit tests and post-adoption measurement. Staff should neither be compelled to implement incoherent text nor empowered to defeat a proposal by asserting difficulty without evidence.

Consensus evaluates objections; it does not manufacture facts

Consensus is valuable because it invites reasons, adaptation and accommodation rather than reducing every issue to a temporary majority. Yet consensus can only evaluate the record placed before it. It cannot make a mechanism work by declaring sufficient support.

RFC 7282 explains rough consensus as attention to whether issues have been addressed rather than a count of agreeing voices. That insight supports the operational-effect standard. A technically grounded objection from a small minority may expose a failure that one hundred supporters have not answered. Conversely, a preference against change need not block a proposal once the actual concern has been addressed with evidence and safeguards.

The registry operator's policy chairs should classify objections by claim. Is the alleged problem unreal, the causal mechanism weak, the text ambiguous, the cost unfair, the counterexample fatal, or the review too late? Each category calls for evidence or amendment. A chair's conclusion should state how material objections were resolved, accepted as residual cost or shown not to affect the proposal.

Support also needs reasons for high-impact rules. A sequence of “support” messages proves participation, not understanding of operating consequences. Chairs should invite supporters to address the strongest contrary case and cost incidence. This improves the common record without converting consensus into a referendum.

The purpose is not procedural perfection. It is to ensure that authority rests on answered operational questions rather than social momentum.

Comparative RIR practice provides mechanisms, not a complete model

Regional Internet registry communities already use elements of evidence-based policy, although their constitutional arrangements differ. The registry operator should borrow mechanisms carefully rather than claim that one regional practice proves a universal answer.

RIPE describes an open, transparent, bottom-up process in which objections need supporting arguments and the secretariat provides facts and an impact analysis. APNIC's Policy Development Process asks entities to examine support and opposition, encourages chairs to restate the problem when interest is weak, and distinguishes minor from major objections. ARIN's current Policy Development Process requires a proposal to contain a clear problem statement, uses staff and legal review, public discussion and Advisory Council decisions before Board adoption.

These features show that problem definition, implementation knowledge, reasoned objections and formal stages are compatible with community authority. They do not by themselves guarantee cost allocation, representative operating tests or a consequence when observed effects differ from prediction.

The registry operator can make those missing links explicit. Its standard should require the same five evidence classes regardless of which policy faction benefits. It should also preserve regional knowledge: an operator experience from one service region may illuminate a mechanism without proving identical cost or law everywhere.

Comparisons should therefore be cited for the feature actually borrowed. “Other registries use consensus” is not evidence that a specific registry rule is sound. A published impact analysis method, objection treatment or emergency review can be adapted and then tested against the registry operator's narrower authority.

Transfer rules show why end-to-end testing matters

Transfers bring legal authority, technical records, money, timing and cross-border facts into one decision. A rule that looks simple at the registry boundary can move risk elsewhere.

Suppose the registry operator proposes stronger recipient verification. The problem dossier should distinguish falsified recipient identity, lack of operational capacity, prohibited payment, disputed source authority and later misuse. The operating test should follow seller, recipient, intermediary and registry from initial agreement through recognized completion. It should show what happens if documents expire, corporate control changes, payment is disputed or routing begins before the record changes.

Cost allocation may reveal that the source holder must produce most historical evidence even if the recipient pays the fee. A counterexample may involve a court-supervised sale in which ordinary officer approval is unavailable. Another may involve a multinational group moving resources during a merger without economic transfer to an outsider. The rule needs to separate these facts without creating a custom exception so broad that ordinary fraud can imitate it.

Outcome measures should extend beyond rejection counts. A rise in denied requests can indicate better protection or excessive false positives. Useful measures include confirmed unauthorized attempts, completion time by operator class, decisions changed on review, post-completion corrections, abandoned legitimate requests and evidence defects discovered at each stage.

The example demonstrates why policy cannot be judged at the sentence level. The effect exists across the whole transaction, including conduct the rule unintentionally encourages.

WHOIS and RDAP duties need purpose-specific evidence

Registration-data policy attracts broad claims about transparency, security and accountability. Operational testing should begin by separating purposes: contacting a network, identifying a recognized holder, authenticating a change, investigating abuse, supporting due diligence and publishing information to the general public are not identical functions.

A requirement to publish or validate a field should state which purpose it serves and what event demonstrates success. A reachable operational contact may support incident coordination without proving corporate control. A verified legal name may support attribution while providing no rapid security response. Public disclosure may improve discoverability while creating privacy or personal-safety cost. RDAP's structured access improves machine use, but structure does not settle entitlement or accuracy.

The test set should include sole traders, public bodies, multinational groups, sponsored resources, privacy-sensitive contacts, emergency response and stale historical records. It should examine both false acceptance and false rejection. A contact wrongly marked invalid can trigger sanctions against a legitimate network; a superficially valid mailbox can satisfy a mechanical test while nobody responsible responds.

Costs include recurring validation, secure access controls, support, translation, correction and downstream reliance. Counterexamples should challenge the assumption that one public field can satisfy every audience.

The registry operator should measure results by the stated purpose: successful contact under defined conditions, correction time, authenticated update integrity or justified access outcomes. “More data” is not an operational effect. Usable, proportionate and purpose-bound evidence is.

RPKI policy needs failure recovery in the primary case set

Route-origin authorization can improve routing decisions, but a registry rule affecting credentials also creates high-consequence dependencies. The operating demonstration must include failure and recovery, not only successful issuance.

For any proposed duty or default, the registry operator should test account compromise, key loss, mistaken revocation, corporate transfer, delegated management, expired authorization, conflicting instructions and registry unavailability. It should identify who can restore control, what evidence is required, whether routing can remain stable during review and how quickly relying networks may act on changed state.

The problem data should distinguish lack of authorization coverage from actual route incidents and distinguish invalid state caused by error from unauthorized origination. Coverage can be a useful measure without being the ultimate outcome. A policy that increases signed holdings but also creates more persistent mistaken invalids may trade one risk for another.

Cost allocation includes certificate management, monitoring, incident response, training and recovery readiness on both sides. Small networks may rely on hosted service because local operation is costly; that convenience changes concentration and succession risk. Counterexamples should include a lawful holder locked out during a critical routing event and a compromised holder attempting to preserve malicious authority.

A sunset review should examine recovery time, erroneous state, support burden, adoption and security events. The strongest route-security rule is not the one with the most mandatory language. It is the one that produces accurate authorization and predictable recovery under stress.

IPv4 scarcity can distort both problem definition and remedy

Scarce IPv4 addresses carry economic value, but price and scarcity can cause policy arguments to overstate institutional ownership or treat every inactive-looking holding as waste. Demonstrated effect requires a more careful chain.

A proposal intended to improve utilization should define the observable harm. Is it fraudulent acquisition, inaccurate registration, artificial barriers to transfer, market opacity, route fragmentation or inability of new networks to obtain addresses? Each problem has a different mechanism. A rule forcing return after a period of no public routing, for example, assumes route visibility proves legitimate use and that reclaimed space will produce greater value after transition. Both assumptions need testing.

Counterexamples include private interconnection, reserved migration capacity, disaster recovery, security-related withdrawal and networks visible outside common collectors. Cost includes renumbering, customer coordination, equipment replacement, contract effects and loss of resilience. The registry operator must also consider whether sophisticated holders can satisfy formal activity tests while smaller legitimate holders cannot.

Transfer-market evidence can reveal demand and price signals, but the market is not a complete measure of public network value. Nor does scarcity permit the registry operator to turn policy into an unbounded claim on asset appreciation. Its authority remains the integrity and continuity of recognized number-resource administration.

An effective scarcity policy should show a measurable improvement in access, accuracy or use without hiding distributional loss behind the language of efficiency.

Provisional policy creates a lawful space for learning

When evidence supports action but key effects remain uncertain, the registry operator should prefer a provisional rule over permanent speculation. Provisional authority is not a weak version of policy; it is a defined experiment with safeguards.

The adoption resolution should specify scope, eligible cases, start and end dates, maximum exposure, data to collect, operator notice, review protection and the decision required at expiry. The rule should avoid irreversible effects unless the harm of delay is greater. A small cohort or voluntary early-use period may reveal administrative difficulty before universal application.

The comparison design should be ethically and operationally credible. The registry operator need not randomize resource rights. It can compare before and after, eligible cohorts, staged regions or alternative evidence bundles while accounting for major differences. The point is to learn enough to refine the mechanism, not to claim laboratory certainty.

Provisional status must be real. Staff contracts, systems and communications should not assume renewal. Expiry should restore the prior rule or a predeclared safe state unless affirmative evidence supports continuation. Operators should know what happens to pending cases and decisions made during the term.

A successful provisional rule may become permanent after review. A failed one should end without institutional shame. The registry operator gains legitimacy when it can stop a plausible idea because results did not justify its cost.

Outcome measures must be chosen before adoption

Metrics selected after implementation invite self-congratulation. The registry operator should approve a measurement schedule with the rule. It should include output, outcome, error, distribution and system-risk measures.

Output records what the registry operator did: cases reviewed, validations sent, authorizations issued or corrections completed. Outcome records whether the target harm changed. Error covers false acceptance, false rejection, reversals and avoidable delay. Distribution shows effects by operator class, resource type or relevant region. System risk tracks continuity, security and concentration consequences.

Every measure needs an owner, source, frequency and limitation. Where confidential cases prevent publication, the registry operator can provide aggregated counts and permit an independent reviewer to inspect the underlying record. A metric that cannot be produced without disproportionate surveillance should be replaced rather than quietly omitted.

Targets should be ranges with guardrails. Reducing completion time is not success if unauthorized changes rise. Raising contact response is not success if legitimate holders are suspended on faulty tests. Increasing RPKI coverage is not success if recovery from mistaken revocation becomes dangerously slow. A balanced set prevents one visible number from consuming the mission.

The adoption record should also identify exogenous events that may confound comparison: major market shifts, legal changes, security incidents or simultaneous policy changes. Review can then reason about causation instead of claiming every movement for the rule.

Sunset review must carry a consequence

A review that merely requires a report preserves the status quo. For high-impact registry policy, the adoption resolution should state what happens if the evidence is late, incomplete or materially adverse. The consequence can be lapse, narrowing to a safe core, suspension of sanctions or a required affirmative renewal.

The review date should match the mechanism. A new evidence requirement may reveal administrative errors within months, while transfer-market effects may need several operating cycles. Early checkpoints can protect against acute harm without pretending to settle long-term benefit. No term should be so long that the original authors, data and affected operators disappear before judgment.

The review should compare the original problem dossier, predicted effects and cost ledger with observed results. It should explain variance, identify unanticipated conduct, revisit counterexamples and publish operator experience. The question is not whether staff implemented faithfully. It is whether the rule produced enough net benefit to retain authority.

Renewal should allow amendment. If one evidence path works and another creates delay, the registry operator can narrow the rule. If the problem was smaller than estimated, guidance may replace obligation. If severe harm emerged, the registry operator can strengthen safeguards with a new demonstrated case.

Automatic consequence changes incentives throughout the term. It gives management a reason to preserve measurement, authors a reason to remain engaged and operators a credible opportunity to show cost.

Independent review should test the evidence chain, not choose policy

The registry operator needs an evaluator capable of checking whether claims connect from problem to result. Independence does not require an outside body unfamiliar with number resources. It requires freedom from responsibility for proposing, administering or defending the rule.

The reviewer should have access to confidential evidence under strict safeguards, reproduce aggregate measures, sample case classifications, test cost assumptions and examine decisions changed on appeal. It should disclose limitations and disagreements. Its report should not declare whether a value choice is correct; that remains for the authorized decision body.

For example, the reviewer can conclude that a validation rule reduced unreachable contacts but imposed substantially greater cost on public bodies than forecast. The registry operator then decides whether that trade-off is acceptable, whether accommodation can preserve assurance, or whether the rule should narrow. Separating fact review from policy choice prevents technical authority from becoming political authority.

Operators should be able to submit structured evidence directly to the reviewer, including cases where fear of retaliation or commercial sensitivity limits public discussion. Aggregated treatment must prevent an anecdote from masquerading as prevalence while preserving early warning of severe harm.

Reviewers should rotate, publish conflicts and avoid consulting relationships tied to the rule. Their methods should be stable enough for comparison across policies. Over time, a consistent evidence practice will let the registry operator learn which forecasts are reliable and where institutional optimism recurs.

Emergency authority is compatible with demonstrated effect only if it expires

Some threats cannot wait for a complete baseline and full case series. An active credential compromise, duplicate control claim or legal prohibition may require immediate protective action. The evidence standard should contain an emergency path rather than encourage officials to bypass it informally.

Emergency authority should require a specific imminent harm, a written causal explanation, the least irreversible measure, a short fixed duration and preserved access to independent review. It should not be used because ordinary discussion is inconvenient or because proponents fear opposition. Core registration and continuity should remain available wherever safely possible.

The temporary decision should collect evidence from its first day. Which cases invoked the rule? Which actions prevented harm? Which legitimate activities were delayed? Which assumptions proved wrong? A retrospective operating test should begin promptly, with an affirmative decision required for any permanent successor.

The emergency measure must expire even if the permanent proposal is still under discussion. Otherwise urgency becomes a ratchet: temporary controls create systems and expectations that then serve as evidence for their own continuation. A narrowly tailored bridge can be renewed once only on public reasons if removing it would recreate the imminent threat.

Demonstrated effect does not mean waiting for perfect knowledge. It means matching the burden of proof, reversibility and duration to the uncertainty under which authority is exercised.

Adoption should begin with the highest-impact rules

The registry operator should phase the standard rather than demand immediate reconstruction of every existing policy. New rules affecting eligibility, transfer, revocation, public registration data, route-security credentials or service continuity should comply from the start. Existing rules in those categories should receive scheduled reviews based on risk and complaint history.

The registry operator should publish shared definitions for cost, adverse case, affected operator, outcome and material variance. It should maintain a neutral case library that authors can adapt without exposing real confidential disputes. Staff should receive resources for measurement and implementation analysis; evidence duties without capacity would produce delay and superficial reports.

An initial year could test the method on several proposals of different scale. The review should ask whether the standard improved decisions, discouraged weak proposals, created excessive burden or shifted influence toward actors able to commission analysis. If resource inequality appears, the registry operator should provide neutral research support to credible proposals rather than waive evidence for powerful sponsors.

Existing policies should not be presumed invalid because their original record lacked modern measures. The question is prospective: which high-impact rules now show recurring cost, uncertainty or severe consequence and therefore deserve review? Stability matters, but it should not shield effects from observation.

The first institutional success will not be a high rejection rate. It will be a visible change in proposals: narrower claims, better cases, clearer cost, stronger safeguards and honest terms.

Demonstrated effect makes authority corrigible

The deepest value of the standard is not technocracy. It is corrigibility: the ability of an institution to discover that a rule is wrong, identify how it is wrong and change course before dependence turns error into permanence.

Number-resource operators cannot casually exit the recognized ledger when policy disappoints them. That dependence creates a reciprocal duty. The registry operator must show that restrictions arise from observed need, that administration can be reproduced, that burdens are knowingly allocated, and that losing evidence has constitutional force.

Problem data prevents anecdote from becoming jurisdiction. Operating tests prevent elegant text from hiding impossible decisions. Cost allocation prevents broad entities from governing a silent minority for free. Counterexamples prevent the motivating case from defining the universe. Sunset review prevents yesterday's confidence from owning tomorrow's facts.

None of these mechanisms eliminates judgment. They improve the conditions under which judgment is exercised. Values still decide how much fraud risk, delay, privacy, scarcity and resilience the registry operator will tolerate. Consensus still weighs objections. Elected bodies still carry responsibility. But the choice is attached to consequences that can be observed and revisited.

A policy should govern because its demonstrated effect justifies common authority, not because its language once gathered momentum. For an institution entrusted with unique number-resource records, that is the difference between merely making rules and remaining worthy of obedience.

NRS and BTW role sources