Summary

  • NRS's role in this subject is advocacy, research, campaigning, convening and authorized member representation. The operational acts belong to RIRs, authorized registration-service operators, holders, lessees and network operators; citing an NRS position is neither evidence that NRS performs them nor an endorsement by BTW.
  • A leased or delegated resource should retain one recognized holder and one allocation history. The operational-use record adds who may use a defined range, for what purpose, through which provider and for what period; it does not silently transfer the underlying right or create a second authoritative resource.
  • Roles must be explicit. The holder, delegatee, technical operator, registration-service provider, RPKI operator, reverse-DNS operator and abuse or security contacts may be different organizations. Each receives only the powers needed for its function, and no role label should imply powers that the governing terms do not grant.
  • Every delegation needs exact scope, start, expiry, renewal rule, permitted subdelegation, routing authority, contact duties, security arrangements, termination consequences and evidence of authorization. Open-ended or vaguely bounded entries should receive enhanced review rather than appearing permanent by neglect.
  • Public RDAP data should reveal enough to direct operational, abuse and accountability questions to a responsible party while protecting personal data, contracts and authentication evidence. Protected records support disputes and lawful review; public transparency is not a demand to expose every commercial term.
  • RPKI, routing, reverse DNS and registration are separate control surfaces. A delegatee may be allowed to originate routes without receiving power to change the holder, transfer the resource or control every cryptographic and naming function. The record must show those boundaries and coordinate their termination.
  • Expiry and revocation must be safe. Advance notices, dependency checks, bounded grace, route and authorization retirement, contact updates, preserved evidence and independent review prevent a commercial disagreement from becoming either an outage or an unauthorized permanent taking.
  • Layered records improve security only if responsibility is enforced. Missing contacts, sham holders, concealed chains, stale terms, unexplained route origin changes and repeated abuse should trigger correction and proportionate limits while preserving holder rights and unaffected services.

The role boundary is part of the evidence

NRS's own stated positioning supplies the first boundary for this analysis. It is a membership and advocacy organization pressing for decentralization, exit, portability, redundancy and fewer discretionary choke points. Heng Lu's note on why NRS exists says directly that NRS does not sell products or implement commercial solutions; its role is to change the direction of governance. NRS may therefore publish research, organize campaigns, convene affected operators, support members and represent an organization that has granted it authority. It may not turn that representation into registry authority over anyone else.

The implementation layer is separate. RIRs, authorized registration-service operators, holders, lessees and network operators remain responsible for any authoritative registry record, allocation, transfer recognition, RPKI or RDAP operation, technical failover, binding review, insolvency act or legally compelled remedy relevant to this article. The NRO coordinates the five RIRs; it is not another name for NRS. IANA numbering services perform their defined coordination role; they are not an NRS department. Courts and lawful public authorities retain the powers their legal systems actually give them.

BTW's role is separate again. BTW reports the observable structure, checks primary sources and labels proposals as proposals. It does not convert NRS advocacy into fact, campaign on NRS's behalf or infer authority from alignment. That reality-not-advocacy discipline is why the institutional nouns in this article matter: a recommendation from NRS, an act by an RIR and an order from a court are three different things.

The record should describe reality without deciding more than it knows

The first duty of a registry record is accuracy about the authority it claims to represent. If it identifies a holder, users should not have to guess whether that organization still has the recognized underlying interest. If it identifies an operational contact, users should not infer that the contact can sell or transfer the resource. Precision is more important than compressing every relationship into one name.

Leased use commonly separates economic and technical roles. A holder may make an address range available for a fixed period. The user may announce it through its own network or ask a hosting company to do so. A security provider may maintain route authorizations. The holder may keep reverse-DNS control, or the user may receive it. Abuse complaints may go to a specialist responder. Billing may pass through another intermediary.

A single organization field cannot convey those differences. Replacing the holder with the user makes the record look current while falsifying continuity. Showing only the holder preserves legal history while sending incident reports to a party that lacks immediate control. Listing every connected business without role boundaries creates noise and may expose private data.

The registry operator should therefore treat a record as a set of typed, time-bounded assertions. One assertion states who the recognized holder is. Another states who has operational use of a defined range. Others identify who can submit registration changes, originate routes under agreed authority, manage RPKI service, change reverse DNS or receive urgent abuse reports. The record claims only what the evidence supports.

This restraint is protective. The registry operator does not decide that a commercial lease is valid in every jurisdiction merely because it records operational use. It does decide whether the asserted relationship satisfies its own rules for recognition, accountability and global uniqueness. If the private agreement is disputed, the authoritative record can preserve the last uncontested roles while a competent forum decides the contested rights.

One resource can have layered roles but only one recognized holder

The holder is the durable anchor. It is the person or organization recognized in the allocation or accepted transfer history as holding the resource under the applicable rules. A lease does not replace that history. A delegation does not create a parallel block. At every moment, the parent resource and each covered subrange must resolve to one coherent holder lineage.

The operational user, called the delegatee here, receives a bounded permission. It may use all or part of the resource for a stated term and purpose. The permission can include announcing routes, assigning addresses to systems or customers, maintaining contacts, requesting reverse delegation or operating security services. Each power must be granted rather than assumed from the word “delegatee.”

The technical operator is the organization that controls the network equipment or service through which the resource is used. It may be the delegatee, a cloud host, a managed-network company or the holder itself. Identifying it matters during outages and hijacks, but technical control does not by itself establish holder rights.

The registration-service provider authenticates instructions and submits authorized changes. It does not become holder or delegatee by serving either party. An RPKI operator manages a cryptographic service under separate authority. A reverse-DNS operator maintains delegations. An abuse responder receives and acts on reports. A legal contact handles notices about the relationship.

One organization may occupy several roles. The record should still keep the roles distinct because their powers begin and end differently. At lease expiry, the delegatee's use may end while a former technical operator continues a short shutdown duty. The registration provider may remain unchanged. Clear role entries make that transition possible without rewriting holder history.

The holder's rights need an explicit protected core

Better operational accountability will fail politically if holders reasonably fear that disclosure becomes confiscation. The registry operator should define a core that delegation cannot alter without a separate holder-change decision. It includes recognized holder identity, allocation or transfer history, the resource's stable identifier, rights to receive independent notice, rights to replace service providers, and rights to recover operational control when a valid delegation ends.

The holder also retains the power to set the delegation's outer scope, subject to existing policy and law. It authorizes the exact range, term and permitted uses. It decides whether subdelegation, route-origin changes, reverse-DNS changes or hosted RPKI are allowed. It cannot authorize conduct that violates common rules, but the registry operator should not enlarge a delegatee's authority beyond the holder's grant.

These protections do not excuse an absentee holder. A holder must maintain verified contacts, monitor material use, respond when the delegatee fails and preserve evidence of authority. It cannot collect rent while claiming no responsibility for a deliberately opaque arrangement. Repeated refusal to correct dangerous records can justify proportionate restrictions or review of the holder's compliance.

Nor does the protected core make every private clause enforceable through the registry. A holder may have contractual claims for fees or damage, but the registry operator should not shut down operational use merely because an invoice is disputed. Registry action follows defined authority, security and status rules. Private remedies remain available in the chosen forum.

The strongest safeguard is separation of decisions. Ending delegated use changes the operational-use layer. Transferring the resource changes the holder layer. Correcting a contact changes a contact layer. Combining them into one vague “update” invites accidental or strategic loss of rights.

The delegatee needs authority that is real but bounded

Accountability requires more than naming a user who cannot act. A delegatee responsible for a live network needs authority to keep records accurate, respond to incidents and manage the functions included in its agreement. Otherwise every urgent correction must pass through a distant holder, and the public entry becomes decorative.

The delegation should state which instructions the delegatee may submit directly. Low-risk contact updates, network-operation details and abuse-response changes may be allowed within the covered range. Route-origin or RPKI changes may require a stronger approval rule. Holder identity, range expansion, provider replacement and transfer should remain outside the delegatee's unilateral power unless a separate mandate expressly and lawfully covers them.

Authorization can require two parties for high-impact acts. For example, the delegatee proposes a new route origin and the holder confirms it through an independent channel. In another arrangement, a long-standing enterprise delegatee may receive bounded authority to manage origins while the holder receives immediate notice and an emergency stop right. The correct model depends on risk, but it must be visible.

The delegatee also has duties. It maintains current operational and abuse contacts, reports material changes, prevents unauthorized subdelegation, cooperates with incident response and prepares orderly return. It must not represent itself as holder, pledge the resource as its own or conceal the end date from downstream customers.

Rights to notice and review protect the delegatee as well. A holder should not be able to terminate a critical network instantly on a disputed allegation when the agreement and common rules require notice. Narrow emergency suspension can address imminent harm, followed by rapid independent review. Bounded authority should be dependable enough to support legitimate operations without maturing silently into ownership.

Scope must be exact down to range, role and dependency

A delegation entry begins with the resource covered. For addresses, it identifies the exact prefix or set of prefixes. If a larger block is divided, each subrange must fit within the parent and must not overlap another active delegation. For an autonomous system number, the entry identifies the number and the specific operational powers granted.

Scope also includes service. Permission to assign addresses inside a network is not automatically permission to originate the covering prefix through any network. Permission to originate a route is not automatically permission to create route authorizations, change public contacts or delegate reverse DNS. Each dependency receives an explicit choice.

Purpose can matter when it changes risk or accountability. A holder might delegate a range for an enterprise network, cloud service, connectivity customer, research project or transition pool. The description should be useful without becoming marketing copy or surveillance of end users. Broad labels such as “general network operations” may be adequate when paired with clear roles and contacts.

The record needs a start time, expected activation time and end time. It distinguishes agreement signature from actual operational control. If activation depends on route and security checks, the entry can remain pending until those complete. At expiry, authority ends through a defined sequence rather than through an unnoticed date field.

Geography may be recorded where operationally relevant, but it must not be inferred from the address itself. A delegation can serve several countries or an anycast service. Locations should describe network or legal context at an appropriate level, not create a false territorial identity for the resource.

Exact scope permits partial correction. If one subrange or dependency is disputed, the registry operator can isolate it while leaving unaffected use intact. Vague portfolio-wide entries turn every problem into an all-or-nothing conflict.

Terms should make time and exit observable

An active term is one of the most important differences between delegation and transfer. The record should show when authority began, when it is expected to end and whether renewal requires a new confirmation. An entry with no end, no review and no responsive holder can become a hidden permanent disposition.

Long arrangements may be legitimate. They should include periodic reconfirmation of holder and delegatee contacts, operational scope and dependency control. Reconfirmation is not a chance to confiscate the resource or renegotiate private price. It is evidence that the recorded relationship still exists.

Renewal rules should avoid accidental outages. The registry operator can send advance notices to independently verified contacts. If both parties confirm, the next term is recorded before the old one ends. If the holder confirms but the delegatee is silent, use should not continue indefinitely. If the delegatee confirms but the holder cannot be reached, a short protective period and review may prevent immediate harm while preserving the holder's core.

Early termination requires a basis and effective time. Mutual termination is straightforward. Holder termination follows the authority and notice promised in the delegation. Delegatee exit should allow safe return. Termination for serious security harm may be accelerated, but emergency action needs evidence, narrow scope and rapid review.

Private commercial terms generally remain protected. The public needs to know that authority exists, its broad scope and when it expires; it usually does not need the price, service credits or confidential customer commitments. Reviewers may need protected access to clauses that determine authority. Separating public status from protected evidence permits accountability without publishing the entire agreement.

Contact records should follow functions, not merely organizations

An organization name is not an incident response channel. The record should identify functional contacts for network operations, routing security, abuse, registration authority, legal notice and continuity. Some functions can share a contact, but the responsibilities remain labelled and testable.

Contacts need assurance levels. A public abuse mailbox can be discoverable and easy to use. A credential capable of approving route-origin changes requires stronger authentication and should not be public. An emergency recovery contact may be held in protected form and tested periodically. Treating every contact alike either exposes sensitive access or leaves ordinary reports inaccessible.

The holder and delegatee should each receive independent notices for high-impact changes. A compromised delegatee account should not be able to redirect the holder's warning. A compromised holder account should not silently disable an active network without reaching the operator. Separate channels make collusion harder and error easier to detect.

Response expectations should be published by function. An abuse report may require acknowledgement within a defined period, while an active route hijack requires immediate escalation. The registry operator should measure reachability and action, not simply whether an email address exists.

Personal data should be minimized. Role accounts are preferable where they are monitored, with protected named escalation contacts behind them. Public entries need not disclose home addresses, identity documents or private telephone numbers. When a sole proprietor is the responsible operator, the registry operator should provide privacy-preserving contact forwarding and verified protected details.

Stale contacts are a status failure. Repeated bounce, unanswered verification or departure of responsible staff should trigger correction notices and, if risk persists, limits on high-impact changes. It should not automatically erase holder rights or terminate legitimate use.

Public and protected views serve different accountability needs

The public view should answer practical questions: which resource is involved, who is the recognized holder to the extent disclosure rules permit, whether delegated use is active, who operates it, who handles abuse, which registration provider serves it, and when the delegation is due for review or expiry. It should expose statuses that materially affect trust without revealing security credentials.

The protected view can hold authority evidence, verified representatives, full agreement references, authentication results, private escalation contacts, dispute material and detailed legal notices. Access should follow role and purpose. Every access and disclosure decision needs a durable record and review route.

This division rejects two extremes. Total secrecy leaves networks and victims unable to find the responsible operator. Total publication exposes individuals, commercial terms and attack surfaces. Layered disclosure can direct questions without turning the registry into a public customer dossier.

Different requesters may receive different lawful detail. An ordinary user sees public operational contacts. A network responding to an active incident may receive a verified escalation path. An independent reviewer can inspect protected authority evidence. A court can seek disclosure through an applicable legal route. The registry operator should publish the categories and decision standards.

Public statuses must be understandable. “Delegated use active,” “return pending,” “security hold” and “under review” should have defined effects. A status should not imply wrongdoing merely because a dispute exists. Historic entries can show that a delegation ended while limiting old personal data.

Disclosure quality is part of legitimacy. Holders and delegatees should be able to see what is public, correct factual errors and challenge disproportionate exposure. Abuse reporters should be able to show when a listed channel failed. Both interests belong in the accountability design.

RDAP should express roles without collapsing them

The Registration Data Access Protocol provides a structured way to present number registration information. RFC 9083 defines JSON responses for RDAP, while RFC 7480 describes its use over HTTP. Layered registry records should use clear entities, roles, statuses, events and links rather than putting a commercial narrative into one unstructured remark.

The response should keep the resource entity stable. The holder is associated through a holder role. The delegatee, technical operator, abuse contact, registration provider and security operator receive distinct associations. Events can identify delegation start, last confirmation, planned expiry and termination. Links can direct authorized users to provider services or protected request channels.

Role vocabulary must be documented and interoperable. If one provider uses “lessee,” another “customer” and another “operator” for materially different powers, users cannot compare records. A controlled core can allow extensions while requiring that every extension state its effect and maps to a common responsibility where possible.

Referral and discovery must still lead to one authoritative answer. RFC 9224 addresses finding authoritative RDAP service. Provider-specific detail may be distributed, but the user should not encounter incompatible holder or delegation states depending on which endpoint answers.

Redaction should be explicit enough to avoid false absence. A response can state that a protected contact exists and provide an accountable relay without exposing the details. It should not imply that no responsible person exists. Access controls described in RFC 7481 support differentiated services, but governance must define who qualifies and how denial is reviewed.

Machine readability helps incident response only when entries are current. Providers should support automated expiry checks, contact validation and conflict detection, while consequential changes remain attributable to authorized humans or organizations.

RPKI authority is related to use but not identical to it

The RPKI architecture described in RFC 6480 supports verifiable statements tied to Internet number resources. A delegation may require the delegatee's network to originate routes, but that practical need does not answer who operates the certificate authority, who may create route authorizations or what happens at expiry.

The record should identify the RPKI arrangement for every active delegated range. The holder may retain control and authorize approved origins. A hosted service may act on joint instructions. The delegatee may receive bounded authority through a delegated arrangement. Each model has different recovery and termination consequences.

Route authority should be no broader than necessary. If the delegatee may originate a specific prefix from identified autonomous systems, authorizations can reflect that scope. Permission to operate one service should not become permission to authorize unrelated origins or a less specific covering range. Changes should reach both holder and delegatee through independent notice.

Expiry planning must account for relying-party observation and route continuity. Revoking an authorization too early can make legitimate routes invalid. Leaving it active indefinitely can preserve risk after the delegatee's control ends. The return plan states sequencing, observation and emergency rollback boundaries before activation begins.

Compromise demands rapid action. The party observing an unauthorized origin should reach a security contact with power to coordinate. A temporary hold can prevent further changes while existing safe service continues. Restoration uses a new recorded decision rather than erasing the compromised event.

RPKI evidence strengthens accountability but does not prove every private right. A valid cryptographic entity shows that defined authority was exercised through the recognized arrangement. It does not by itself decide a lease dispute or make the origin holder. The legal and operational layers remain connected but distinct.

Routing operation, registration and reverse DNS need separate switches

Routing is performed by networks that select and propagate paths. Registration records help identify authority and contacts, but they do not command every router. A layered registry record should therefore state who is expected to originate a delegated range and how exceptions are handled without claiming that the registry controls reachability.

Observed origins can be compared with recorded authority. A new unexplained origin should trigger inquiry, not automatic confiscation. Multi-origin operation, anycast, traffic engineering and transition can all be legitimate. The relevant question is whether the holder and delegatee authorized the operation under the recorded terms.

Reverse DNS is another distinct function. The holder may delegate management to the user, keep it, or use a specialist. The operational-use entry identifies the responsible operator and return plan. Terminating the lease without restoring reverse delegation can leave names stale or give a former user residual control.

Registration-service authority also stands apart. A delegatee may update its operational contacts through the holder's provider without gaining power to replace that provider. Alternatively, the parties may choose a provider that serves both, with separate credentials and permissions. The provider must show whose instruction authorized each change.

These separations reduce cascade risk. A dispute about billing should not automatically withdraw route authority, reverse DNS and every contact at once. A confirmed credential compromise may justify suspension of one change channel while routing remains stable. Each control surface receives the narrow response appropriate to it.

The operational-use record ties the surfaces together through a dependency plan. It does not collapse them. That is how a reviewer can explain what failed, what remained safe and which party had power to act.

Abuse accountability needs a reachable operator and an answerable holder

Delegated resources are sometimes attractive to actors who expect the formal holder to absorb complaints while the immediate user remains hidden. A credible record makes that strategy harder. It provides a reachable operational abuse contact and preserves the holder's duty to act when the delegatee repeatedly fails.

The abuse contact should acknowledge reports, request useful evidence and communicate disposition within stated times. It should be protected from automated harassment and unsupported mass complaints. Report quality and response quality both need measurement.

The holder is not automatically liable for every packet sent by a delegatee. It is accountable for choosing and monitoring the relationship, maintaining correct records and using its reserved powers when serious breach is established. The delegatee is accountable for networks and customers within its control. The technical operator is accountable for actions it can actually perform.

Escalation should be graduated. A missed response leads to contact verification. Repeated unresolved reports lead to enhanced review. Evidence of coordinated malicious use may justify restrictions on further subdelegation or high-risk changes. Imminent harm can support narrow emergency action. Termination of all use is a serious remedy requiring authority and review.

Transparency reports can show volumes, response times, correction rates and outcomes without naming victims or publishing unproven accusations. Providers with persistently opaque chains or unreachable operators should face qualification consequences.

The objective is responsive control, not an assumption that leasing itself is abusive. Many delegated arrangements support legitimate hosting, enterprise networks and service continuity. Accurate roles allow evidence to distinguish those uses from deliberate concealment.

Subdelegation must remain a visible chain, not a maze

A delegatee may need to serve downstream customers. Prohibiting every subdelegation could make legitimate business impossible. Allowing unlimited hidden chains can make responsibility untraceable. The holder's terms should state whether subdelegation is permitted, to what depth and under which reporting duties.

Each material subdelegation identifies the covered range, immediate delegator, downstream user, technical operator, contacts and term. The chain must fit within the parent scope and end no later than the parent authority. A downstream party cannot receive a power the parent delegatee lacks.

Public detail can be proportionate. A small end-customer assignment may need an operational contact rather than publication of the full commercial chain. A large independently routed subrange with separate abuse handling requires clearer identification. Thresholds should follow control and impact, not simply address count.

The holder remains visible at the root of the chain. The immediate delegatee remains answerable for downstream compliance unless the rules assign a direct duty. A provider should be able to trace from an observed address to a responsible current operator without exposing every customer publicly.

Termination propagates in an ordered way. A parent cannot promise a downstream term beyond its own. Advance notices should reach affected operators. The return plan accounts for routes, authorizations, reverse DNS and customer migration. Emergency action can isolate one harmful subrange instead of disabling every downstream customer.

Chain depth and churn are risk signals. Rapidly changing users, repeated unreachable contacts or unexplained reassignment may require stronger assurance. They are not automatic proof of wrongdoing. Evidence, reasons and review remain necessary.

Termination must return authority without manufacturing an outage

The end of delegated use is where rights and continuity collide. The holder expects control to return. The delegatee may operate services and customers that cannot disappear without warning. The registry operator should not decide the private commercial dispute, but it must preserve a coherent resource state and safe transition.

The return plan is agreed at activation. It names notice periods, final contact updates, route changes, RPKI actions, reverse-DNS handoff, data export, evidence retention and the effective end of each permission. Parties can vary commercial details, but common minimums protect the record and third parties.

At ordinary expiry, advance notices go to both sides and technical operators. The delegatee confirms shutdown or transition readiness. The holder confirms the next operational state. If both are ready, dependent functions change in sequence and the operational-use status closes with a receipt.

If they disagree, the last uncontested state may continue for a short bounded period when abrupt change would create serious harm. That continuation does not renew the lease or award the resource to the user. It preserves safety while an authorized decision addresses the narrow dispute. Fees and damages remain for the proper forum.

Emergency termination is different. Confirmed hijacking, dangerous credential compromise or deliberate malicious use may require immediate limits. The action should target the affected range or function, preserve evidence, notify parties as soon as lawful and receive rapid independent review.

After return, former delegatee credentials are revoked, public contacts change and lingering authorizations are checked. Historic entries show the period of operational responsibility. Protected evidence remains long enough to resolve later incidents. Clean return is a measured provider and holder duty, not an informal favour.

Insolvency and disappearance require continuity rules

Either party can fail. A holder may dissolve, enter insolvency or lose its only authorized representative. A delegatee may abandon service. A provider may become unreachable. Layered records make it possible to respond to the failed role without assuming that every other role has failed too.

If the delegatee disappears, the holder can activate the agreed return after evidence of failed contact and a bounded waiting period. Technical operators and downstream users receive notice where possible. Existing routes and authorizations are retired in a controlled sequence. The event does not become a holder transfer.

If the holder becomes insolvent, the delegatee does not automatically become holder. A recognized officeholder or competent decision may control the holder's rights, subject to applicable rules. Operational use can continue temporarily when authorized to preserve value and public service. The record identifies the basis and review date.

If both parties are unreachable while critical services remain active, the registry operator needs a continuity power narrower than ownership. It can preserve the last safe state, freeze high-impact changes and seek a qualified representative. It cannot award the resource permanently through administrative convenience.

Provider failure should be least disruptive. Portable records and independent contacts allow another qualified provider to assume service without changing holder or delegatee. The common authority records the substitution and tests dependencies.

Every continuity intervention expires or receives confirmation. Exceptional states should not become forgotten permanent arrangements. Public status communicates uncertainty without exposing protected insolvency details, and an independent reviewer can examine whether the registry operator exceeded its limited role.

Disputes should isolate the contested layer

A holder may allege that the delegatee exceeded scope. A delegatee may allege premature termination. A third party may claim a prior transfer. An abuse reporter may challenge the accuracy of contacts. These disputes concern different layers and should not all produce the same freeze.

The first step identifies the contested assertion: holder identity, delegation authority, operational conduct, contact accuracy, routing authority, security service or payment. The registry operator preserves relevant evidence and marks only the affected field or power. Uncontested services continue unless a demonstrated risk links them.

Interim action follows risk. A disputed invoice rarely justifies route withdrawal. Evidence of an unauthorized holder change justifies a stronger hold. A stale abuse contact requires correction. An active compromised RPKI credential requires immediate security action. Reasons and duration are recorded.

The decision maker must be independent of the provider or staff whose act is challenged. Parties receive the substance of the case, an opportunity to answer and a reasoned result, subject to lawful protection of sources and credentials. Urgent action can precede a hearing only when later review is timely and effective.

Remedies should restore the correct layer. They may correct a contact, narrow a delegation, revoke a credential, order a return, compensate delay or recognize a holder change through the separate authority. They should not silently rewrite history. A successor event explains what was wrong and what now governs.

Dispute statistics can expose recurring weak points while protecting parties. If many cases arise from vague scope, unreachable holders or bundled RPKI, the registry operator can improve common terms rather than treating each dispute as isolated misfortune.

Membership accountability should follow durable stakes and current duties

Layered use raises a governance question: who participates in the registry operator's governance? The holder has a durable stake in recognition. The delegatee bears current operational duties. The provider performs a common service. Treating only one class as legitimate can distort policy.

Holders should retain membership standing independent of whether they lease, operate directly or change provider. Delegation must not transfer their vote by default. Otherwise commercial users could accumulate governance power over resources they use only temporarily, and providers could bundle political control into contracts.

Delegatees need an organized voice on operational rules that govern their duties. They can participate through a distinct constituency or verified operational membership. Safeguards should prevent one delegated range from generating unlimited votes through nested customers. Representation should reflect real responsibility without equating it to holder title.

Providers and technical operators likewise need voice but not control over their own qualification and discipline. Conflict rules, balanced chambers or supermajority requirements can stop a service industry from writing permanent advantages. Public-interest and security expertise should inform decisions affecting victims and relying networks.

The record supplies evidence for membership without publishing private agreements. It can confirm that a person represents a current holder or material delegatee at a stated date. When the role ends, the associated standing changes according to published rules. Historic participation remains part of institutional memory.

Fees should also follow roles. The holder may pay for common recognition, the delegatee for operational entries and the provider for qualification. The allocation of cost must not turn nonpayment in one commercial relationship into undisclosed control over another party's rights. Transparent funding supports transparent accountability.

Data quality should be measured as operational truth

Record quality is not the percentage of fields containing some value. It is whether the right party can be reached, whether its authority is current, whether scope matches observed use and whether dependencies can be changed safely. A perfectly formatted stale delegation is still dangerous.

The registry operator should test contact reachability, term confirmation, range overlap, parent-child consistency, provider qualification and dependency status. Observed route origins can highlight unexplained changes. RPKI publication can reveal mismatches. These signals trigger verification; they do not replace human or organizational evidence.

Useful measures include expired-but-active delegations, unreachable abuse contacts, unexplained origins, overdue returns, unresolved dependency mismatches, unauthorized subdelegations, correction time and emergency-action review time. Results should distinguish holder, delegatee and provider responsibility.

False incentives must be avoided. If providers are punished merely for reporting errors, they will hide them. Measures should reward detection, timely correction and transparent learning. Independent sampling can test whether reported performance matches reality.

Holders and delegatees need easy correction channels. A factual contact change should not require a legal dispute. A contested authority change needs stronger review. Risk-based procedures keep routine accuracy work fast while protecting core rights.

Historical quality matters too. Users investigating an incident should be able to identify who had operational responsibility at the relevant time. Retention should preserve role and event evidence while minimizing old personal data. An accurate past supports fair accountability in the present.

A delegated hosting scenario shows the model in operation

Consider a holder that makes a defined IPv4 prefix available to a regional hosting company for three years. The hosting company serves business customers through two network operators. The holder retains its registration provider and uses a specialist hosted RPKI service. Reverse DNS is delegated to the hosting company.

The registry record keeps the holder and allocation history unchanged. It adds the hosting company as delegatee, the two expected route origins, the technical operators, the RPKI service operator, reverse-DNS responsibility, public abuse channel, protected security contacts, start date, expiry and no-subdelegation-beyond-customer-assignments condition.

The hosting company can update ordinary operational contacts. A route-origin change requires its request and independent holder confirmation. Holder transfer, range expansion and registration-provider replacement remain unavailable to it. Both parties receive high-impact notices.

During the second year, one operator changes. The company submits evidence, the holder confirms the new origin, the RPKI operator updates authorization in a coordinated window and the old origin retires. The holder has not reacquired or reissued the prefix; an operational layer has changed.

Near expiry, the parties decide not to renew. Notices reach customers and operators. Reverse DNS returns, route authorizations change, the company exports incident records and its credentials expire. The public status closes on the effective date while historic responsibility remains visible.

A billing dispute continues in court, but it does not produce two holders or allow the company to hold the global record hostage. The holder recovers operational control under the recorded term. The company retains its claim for money and receives review if the return departed from agreed authority. Layered records keep technical continuity and legal remedies from consuming each other.

The standard should reject concealment without prohibiting useful delegation

A sound registry-operator position is neither “all leasing is legitimate” nor “all leasing is abuse.” It asks whether the arrangement preserves unique holder recognition, exposes accountable operational control, respects policy, protects security and provides safe return. Evidence determines the answer.

Certain signs justify enhanced scrutiny: a nominal holder with no reachable representative, rapid serial delegation, undisclosed subdelegation, repeated malicious use, mismatched route origins, terms that outlast the holder's authority, or a provider that markets anonymity from accountability. Scrutiny means verification and proportionate response, not automatic forfeiture.

Other signs support confidence: independently confirmed parties, exact ranges, current contacts, bounded terms, clear dependency control, tested return, timely incident response and consistent route evidence. The registry operator should make these practices easier and cheaper than concealment.

Rules should apply to substance rather than labels. Calling a transaction “hosting,” “sponsorship,” “management” or “temporary transfer” should not determine its treatment. The relevant facts are who controls use, for how long, under which powers and with what path back to the holder.

Provider incentives matter. A registration provider paid per entry may tolerate low-quality chains. Qualification and audit should test whether it verifies roles and corrects stale records. A holder paid for use may ignore abuse. Reserved duties and enforceable notices keep it engaged. A delegatee seeking stability may overstate ownership. Public role labels and separate holder history prevent that drift.

The model succeeds when legitimate delegation becomes easier to distinguish from concealment. Accuracy supports both commerce and enforcement because each party knows the powers it has and the duties it cannot outsource.

Layered accountability preserves rights by naming control honestly

The central choice is not between holder rights and operational transparency. A precise record can protect both. It preserves one durable holder while identifying the party that can stop an attack, correct a route, answer an abuse report or return a range today. It makes term and authority visible without turning temporary use into title.

This design requires discipline. Roles must carry defined powers. Terms must expire or be reconfirmed. Contacts must be reachable. Public disclosure must be useful but proportionate. RPKI, routing, reverse DNS and registration must be coordinated without being confused. Disputes must stay within the layer they actually concern.

The registry operator should treat these duties as part of global uniqueness. Duplicate allocation is not the only kind of incoherence. A record that names one holder while everyone knows an undisclosed party controls the resource is also incoherent. So is a record that names the current user as if history and underlying rights vanished.

Layering provides the honest middle. The holder remains the holder. The delegatee receives real bounded authority. Operators and contacts are accountable for their functions. Providers compete in service while submitting to one current authoritative state. Independent review corrects mistakes without allowing either contract power or technical possession to decide everything.

Leased and delegated use will continue because networks need flexibility and IPv4 scarcity creates strong incentives to put dormant capacity into service. Governance should not rely on denial. It should make the arrangement legible, secure and reversible. Clear roles, terms and contacts are how accountability improves without stripping the rights that make orderly return possible.

The practical test is simple to state even when implementation is demanding: an informed outsider should be able to identify the durable holder, find the responsible current operator, understand the limits and duration of operational authority, and determine how safe control returns. If any of those answers is missing, the record is not yet adequate for a resource on which other networks depend.

NRS and BTW role sources