Summary

  • NRS's role in this subject is advocacy, research, campaigning, convening and authorized member representation. The operational acts belong to RIRs, their contracted operators, affected holders, network operators and independent auditors; citing an NRS position is neither evidence that NRS performs them nor an endorsement by BTW.
  • Registry service levels should describe a condition the holder can verify, not an activity the institution can count. Ticket acknowledgement, platform availability and mean response time remain useful diagnostics, but none proves that the public registration record is accurate or that control has been restored.
  • Five customer journeys need distinct commitments: maintaining record accuracy, correcting an alleged error, completing a permitted transfer, handing off RPKI and related authority safely, and recovering from compromise or provider failure. One general support target cannot represent their different risks.
  • Every clock needs an observable start, a narrow list of permitted pauses, a maximum pause duration and an outcome-based stop. The registry operator should prevent providers from delaying the start by repeatedly declaring a submission incomplete without identifying the missing fact and why it is necessary.
  • Accuracy must be measured at the reliance surface. A correct value in one private system does not satisfy the commitment if authoritative RDAP, delegated files, reverse-DNS authority or RPKI service state still presents a stale or contradictory result.
  • Transfer and certificate handoff are coupled but not identical. The holder must receive one ordered registration change, continuity of essential security authority, retirement of the former provider's control and evidence sufficient to prove each transition without allowing two incompatible current states.
  • Performance reports should disclose percentiles, aged cases, severity, cohort, exclusions, reopening and time to customer-confirmed result. Averages and availability percentages can hide the small tail where number-resource dependence turns delay into operational harm.
  • Missed commitments need consequences: automatic fee credits for defined delay, correction-cost reimbursement, independent review, repeated-failure remediation and, for provable loss, access to a separate compensation regime. A service level without a remedy remains a managerial aspiration.

The role boundary is part of the evidence

NRS's own stated positioning supplies the first boundary for this analysis. It is a membership and advocacy organization pressing for decentralization, exit, portability, redundancy and fewer discretionary choke points. Heng Lu's note on why NRS exists says directly that NRS does not sell products or implement commercial solutions; its role is to change the direction of governance. NRS may therefore publish research, organize campaigns, convene affected operators, support members and represent an organization that has granted it authority. It may not turn that representation into registry authority over anyone else.

The implementation layer is separate. RIRs, their contracted operators, affected holders, network operators and independent auditors remain responsible for any authoritative registry record, allocation, transfer recognition, RPKI or RDAP operation, technical failover, binding review, insolvency act or legally compelled remedy relevant to this article. The NRO coordinates the five RIRs; it is not another name for NRS. IANA numbering services perform their defined coordination role; they are not an NRS department. Courts and lawful public authorities retain the powers their legal systems actually give them.

BTW's role is separate again. BTW reports the observable structure, checks primary sources and labels proposals as proposals. It does not convert NRS advocacy into fact, campaign on NRS's behalf or infer authority from alignment. That reality-not-advocacy discipline is why the institutional nouns in this article matter: a recommendation from NRS, an act by an RIR and an order from a court are three different things.

The customer does not consume the dashboard

Operational teams need dashboards. They need to know whether databases replicate, whether authentication is responding, how many requests arrived, which queues are growing and which dependency is unavailable. Those measures can identify trouble before a holder notices it. The mistake begins when the institution presents the same measures as proof that the customer received the promised service.

Consider a holder whose legal name was updated after a merger. The submission was accepted, and the case-management screen records completion. A private account view shows the new name. Authoritative RDAP continues to show the former company for four days because a publication component failed. From the staff perspective, the case is closed and almost every system is healthy. From the customer's perspective, the record used by counterparties remains wrong.

The difference is not semantic. Internet number records influence due diligence, abuse contacts, transfer checks, routing-security administration and operational trust. RFC 7020 treats registration accuracy and uniqueness as core goals of the Internet Numbers Registry System. Accuracy is therefore not achieved merely because an institution has stored the intended value somewhere. It is achieved when the authoritative service presents the right current state, with consistent supporting authority, to those entitled to rely on it.

A registry service operator commitment should begin with the sentence, "The holder will be able to..." The holder will be able to see the accepted correction in authoritative RDAP. The holder will be able to prove that a transfer reached one current provider. The holder will be able to issue and manage valid routing authorizations after a certificate handoff. The holder will be able to recover authority through a tested route when ordinary credentials are unavailable. Those sentences reveal whether a metric describes service or merely administration.

Availability is necessary and radically incomplete

Availability measures whether a service answers. It does not necessarily measure whether the answer is correct, current, authorized or useful. An RDAP endpoint can return an HTTP response throughout an incident while serving a stale holder, an obsolete status or an incomplete event history. A portal can accept a request while placing it in a queue that has no completion standard. A certificate repository can remain reachable while the holder has lost practical control over the credentials needed to update its ROAs.

This distinction is familiar in other infrastructure fields. A payment service can be online while a particular customer's funds are inaccessible. A railway can operate most trains while one passenger's journey fails. A cloud console can load while recovery of a protected account remains impossible. Availability describes one condition of delivery, not the whole result.

The registry operator should retain technical availability commitments for authoritative RDAP, registration change submission, validation, RPKI publication and emergency published contact points. It should publish how availability is measured, from which independent vantage points and with what maintenance exclusions. But each technical measure should sit below a customer-result commitment. An outage may explain why a result was missed; it should not redefine the result as successful.

The same hierarchy applies to support measures. Time to first response is useful because silence increases uncertainty. Yet a quick automated acknowledgement does not correct a wrong record. Number of handled cases may show workload, but it can reward unnecessary exchanges. Customer satisfaction can reveal communication failures, but it cannot validate uniqueness or security. The registry operator needs all these instruments. It should refuse to let any one of them stand in for completed, accurate and safe service.

A service level needs five pieces of grammar

A defensible commitment has five parts: scope, start, result, deadline and consequence. Scope identifies the customer journey and conditions covered. The start is an event both sides can prove, such as receipt of a signed request through an available channel. The result describes the observable end state. The deadline specifies elapsed time or a clearly defined service calendar. The consequence states what occurs if the commitment is missed.

Vague language usually omits at least one part. "We aim to respond promptly" has no result or deadline. "Most changes are processed within two days" does not say when the count begins, what processed means, which changes were excluded or what happens to the rest. "The platform achieved 99.99 percent availability" says nothing about correction. "Complex cases may take longer" gives the provider an unbounded pause under a label it controls.

The registry operator should publish a service-level catalogue in plain language and machine-readable event definitions. The catalogue should distinguish standard requests from contested holder changes, sanctions restrictions, active court orders and suspected fraud. A standard case should not inherit the schedule of litigation. A contested case should not be disguised as ordinary delay. Classification decisions should be recorded, notified and reviewable because classification determines the clock.

The catalogue should also state whose performance is being measured. A retail registrar may receive the request; a common validator may commit the state; an RPKI operator may perform a certificate transition; an RDAP publisher may expose the result. The holder should receive one end-to-end commitment even where several institutions contribute. Allocation of responsibility among providers belongs behind that promise and should not become a reason for the customer to diagnose the chain.

Record accuracy is a maintained condition, not a ticket category

The first service level concerns continuing accuracy. It is broader than the speed of an update request. The registry operator should define the authoritative fields and state transitions that must remain correct: recognized holder identity, public contact or role data permitted for disclosure, resource range, current status, registration dates, service-provider reference, transfer state and links to relevant registration events. It should identify which values are public, restricted or derived, without exposing protected evidence.

RFC 9083 defines the JSON responses used by RDAP for Internet number and other registration data. Its event structures, entities, notices and links enable a richer account of current state than a bare contact row. That technical vocabulary does not decide institutional entitlement, but it gives the registry operator a surface on which accuracy can be tested. The same current fact should not appear differently across authoritative views without an explicit reason and timestamp.

An accuracy commitment needs active controls. Accepted changes should be checked against the public reliance surface after publication. Replicas should be compared for divergence. High-risk changes should receive an independent confirmation to the holder through a previously established channel. Stale states should have maximum ages. Conflicting current states should trigger a severity classification even if no customer has yet complained.

The registry operator should not promise that every historical statement will be free from dispute. Legacy allocations, mergers, insolvencies and old sponsorship relationships can contain incomplete evidence. The promise should be precise: the registry operator will preserve known history, mark genuine uncertainty, avoid presenting an unresolved claim as settled fact, and provide a bounded route to correction. Accuracy includes honest qualification. It does not require the registry to manufacture certainty that the evidence cannot support.

The measurable result is therefore multi-part. The accepted current value must appear on every authoritative reliance surface. No incompatible current value may remain active. The event history must identify when the change took effect. Dependent authority must correspond to the current holder or its authorized provider. The holder must receive confirmation that identifies what changed, where it is visible and how to challenge an error. Only then should the accuracy clock stop.

Correction requires containment before final judgment

A reported error creates two different duties. The first is to contain foreseeable reliance on a potentially wrong state. The second is to determine and publish the correct state. The first can often happen quickly; the second may require evidence from several parties. A single final-resolution target encourages the institution either to leave a dangerous claim unmarked for too long or to make a premature decision merely to stop the clock.

The registry operator should use staged correction commitments. It should acknowledge the allegation and preserve the challenged state. It should perform an initial authority and severity assessment. Where the allegation is credible and the potential harm is material, it should add a neutral status annotation or restrict a high-risk change while review continues. It should identify the evidence needed from each party, decide the issue with reasons, publish the corrected or qualified state, and verify propagation.

The containment step must be carefully bounded. A complainant should not be able to freeze an unrelated holder merely by making an assertion. Initial action should depend on authenticated standing, specific contradictory evidence, signs of compromise or a discrepancy created by the registry operator itself. The annotation should say no more than necessary. It should not imply misconduct before findings exist, and it should expire or be reviewed at a defined time.

A correction clock should not stop when staff send a decision email. It should stop when the authoritative state is corrected or appropriately qualified, contradictory dependent authority is resolved, and the customer receives the evidence of completion. If the allegation is rejected, the result should still include a reasoned notice and removal of any temporary restriction. Reopened cases should be reported, because frequent reopening is evidence that nominal closure is not reliable.

The burden of production should follow custody. The holder can reasonably be asked for corporate authority, transaction documents or proof of identity within its possession. The registry operator should not demand that the holder recreate records that the registry operator or its predecessor was responsible for preserving. Missing institutional evidence is not automatically proof against the customer. Service-level reporting should identify delays caused by provider-held, customer-held and third-party evidence separately rather than assigning every pause to the applicant.

Transfer is complete only when authority has moved once

A portable registration regime depends on a transfer commitment. Without a maximum time and an objective completion state, the incumbent can preserve monopoly through delay while formally accepting the right to leave. The registry operator should distinguish a change of service provider from a sale of the resource, merger, change of holder or disputed succession. Each event has different evidence. A provider switch should not be forced through a title-like review that has nothing to do with the holder's instruction.

The transfer starts when the gaining provider submits an authenticated holder instruction containing the defined minimum data. The common validator should quickly confirm sufficiency. The losing provider may identify a narrow objection: evidence of credential compromise, an active legal restraint, a conflicting holder-change request or a specified unpaid charge directly tied to the transfer service if such a charge is permitted. General dissatisfaction, unrelated debt and silence should not be vetoes.

Completion requires one ordered commit. The common state must name the gaining provider as current, end the losing provider's current authority, preserve the event history and expose the new state through authoritative RDAP. Notifications should go to the holder through established channels and to both providers. Any dependent services that cannot move atomically should enter a defined, short transition with one authoritative direction and no contradictory current instruction.

The registry operator should report transfer duration from holder instruction to customer-verifiable completion, not merely the time spent in the validator. It should show the share completed within target, median, upper percentiles, oldest open case, reason-coded pauses, incumbent objections, rejected objections and post-transfer corrections. The report should separate ordinary provider switches from holder changes and legal disputes. Otherwise, a small number of difficult cases can be invoked to excuse slow routine service, while routine volume can conceal serious tail failures.

A failed transfer should produce more than an apology. The holder should receive a fee credit for avoidable delay, reimbursement of reasonable duplicate service charges caused by the miss, and fast independent review where the former provider appears to have obstructed exit. Repeated obstruction should affect provider qualification. Portability becomes real when the incumbent bears a consequence for making exit unusable.

Certificate handoff is a security outcome, not an attachment

RPKI adds a separate authority surface. A number holder may rely on a hosted service to manage certificate authority functions and publish Route Origin Authorizations. Moving the registration relationship does not automatically move those controls. If the old provider can still act after the transfer, or if the new provider cannot establish valid authority before the old chain ends, the customer may face contradictory authorizations or an avoidable gap.

RFC 6480 describes the Resource Public Key Infrastructure and its purpose in supporting attestations about Internet number-resource holdings. RFC 6492 specifies a provisioning protocol between parent and child certificate authorities. These standards establish technical mechanisms; they do not by themselves allocate commercial responsibility for a provider change. The registry operator must add the service commitment.

The customer result should be stated without assuming one operating model. After handoff, the current holder or its authorized service must be able to manage valid routing authorizations under the new authority arrangement. Intended ROAs must remain continuously available unless the holder explicitly chooses a planned withdrawal. The former provider must lose the ability to make new customer-directed changes. Publication points, manifests and revocation state must converge as designed. Independent relying-party observation should verify that no unintended invalid or conflicting state was created.

The handoff plan should be generated before the registration commit and confirmed with the holder. It should list current authorizations, the intended post-transfer set, certificate and repository dependencies, the sequence of new issuance and old retirement, monitoring vantage points, rollback boundaries and emergency contacts. Secret key material should not be casually transferred merely for convenience; a new authority relationship can be established using the applicable standard mechanisms. The service level measures continuity of authorized effect, not movement of a particular file.

Some transitions will require overlap. Overlap should be narrowly designed so that two service providers do not possess unconstrained power to publish incompatible instructions. The registry operator should define which provider may act at each stage, which changes are frozen, how emergency withdrawal works and the maximum overlap period. The handoff clock stops only after the holder can exercise the new authority, the intended public state validates from independent vantage points and the former provider's change authority is retired.

Recovery is measured by restored control

Recovery covers compromised credentials, lost authenticators, provider outage, registrar insolvency, validator failure and erroneous lockout. Each event threatens a different part of the chain, but the customer asks the same practical question: how can a legitimate representative regain safe control before the dependency becomes an outage?

The registry operator should require a recovery route established before failure. The holder should register more than one authorized person, a secure out-of-band channel and an emergency corporate proof set. The design should support changes in staff without making a departed employee the permanent recovery gate. High-risk recovery should use multiple independent checks and delayed notification where delay reduces takeover risk, while an urgent containment path protects against active compromise.

The service commitment should distinguish containment, provisional continuity and full restoration. Containment can freeze unauthorized change and preserve current routing-security state. Provisional continuity can keep essential publication and contact functions operating under tightly limited authority. Full restoration returns ordinary control to verified representatives, replaces compromised credentials, reviews changes made during the incident and confirms the resulting registration and RPKI state.

A provider's own failure should not suspend the commitment. Qualified registrars and common services should maintain exportable, encrypted continuity material and tested successor arrangements. The holder should not need access to the failed provider's ordinary portal to invoke recovery. The registry operator should test recovery with realistic exercises, including the loss of a provider, unavailability of a senior signatory and disagreement between replicas. A document that has never been executed is not evidence that the customer can recover.

Recovery time should be reported by severity and starting condition. A forgotten password is not comparable to the compromise of an authorized representative or collapse of a provider. Yet classification must not become an excuse for unbounded delay. Every class needs a maximum time to containment, a maximum time to a reasoned recovery plan and a maximum age before senior independent review becomes automatic.

The clock must not belong to the provider alone

Service commitments are easy to improve on paper by manipulating the clock. The provider can say that time begins only when a case is "complete," ask one question at a time, reset the clock after each answer, classify weekends as invisible, or close and reopen the case under a new reference. The registry operator should define clocks so neither side can manufacture performance.

Receipt should be timestamped by an independently auditable service. Within a short sufficiency period, the responsible provider must either accept the submission or issue one consolidated notice identifying each missing item, the rule that requires it and why it is material. If no notice is issued, the substantive clock begins at receipt. Later requests for evidence may pause only the portion genuinely dependent on that evidence and may not erase elapsed time.

Pauses should use controlled reason codes: awaiting customer evidence, awaiting a named third party, active legal restraint, verified security containment or scheduled customer action. Each pause needs a start notice, the specific condition that will end it and a maximum review interval. The provider should continue work on unaffected tasks. A pause that expires without a decision should escalate automatically rather than silently renew.

Elapsed hours are appropriate for compromise containment, contradictory current authority and severe publication failure because risk continues overnight. A published service calendar may be reasonable for routine identity checks, but it must specify holidays and time zone. Global customers should not face an undefined local-business-day rule. The final report should show both gross elapsed time and excluded time so that customers and reviewers can see whether pauses dominate performance.

The stop event must also be external. "Analyst completed review" is not enough. "Corrected RDAP response observed from three independent vantage points and completion notice delivered" is measurable. "Transfer record committed, old authority retired and gaining provider control confirmed" is measurable. Customer confirmation should be sought, but customer silence should not allow an otherwise verified result to remain open forever. The registry operator can close after objective verification while preserving a simple reopening right.

Targets should follow severity and dependency

One target for every request is both unrealistic and weak. The registry operator should classify service by the consequence of delay. A severe incident includes unauthorized holder change, contradictory current allocation state, loss of control over active routing authorizations, widespread authoritative publication failure or compromise with a credible threat of harmful change. These require continuous response and rapid containment.

A high-priority case includes a substantiated record error affecting a transaction, a blocked provider transfer near a contractual deadline, or recovery where ordinary authority is unavailable but current state remains safe. Standard cases include planned contact changes, routine provider switches and non-urgent historical corrections. Complex adjudication includes conflicting claims that cannot be resolved by administrative evidence alone.

The exact times should be adopted after measured trials, but the constitution of the commitment should be set first. For example, the registry operator could require severe containment within hours, high-priority initial protection within one day, standard submission sufficiency within one service day, routine provider transfer within a small number of elapsed days and reasoned escalation for any case exceeding its class. These are design examples, not claims about a current universal benchmark.

Targets should include a tail obligation. Meeting a deadline for 95 percent of cases says nothing about the remaining five percent unless the remainder receives a maximum age and mandatory review. In number-resource administration, the tail may contain the most dependent customers and the highest harms. The registry operator should pair a percentile target with an absolute backstop, such as independent review after a defined multiple of the normal period.

Severity classification itself should be audited. Providers have an incentive to downgrade incidents to preserve performance. Customers may have an incentive to overstate urgency. The registry operator should publish objective triggers, allow a quick classification challenge and sample both upgraded and downgraded cases. The question is not whose description sounds more dramatic. It is which authority surface is at risk, how soon reliance could cause harm and whether a safe containment measure exists.

Measurement must make the tail visible

An average is especially misleading for services with a long tail. Nine transfers completed in one day and one delayed for ninety-one days produce an average of ten days. That number describes nobody's experience and obscures the case in which exit failed. Medians are useful but limited public evidence for the same reason. The registry operator should report distributions and aged inventory.

For every customer journey, the report should include total cases, completed cases, cases within target, median, 75th, 90th, 95th and 99th percentile where volume permits, maximum age, open age bands and reopened cases. Small samples should be shown as counts rather than unstable percentages. The institution should distinguish customer time, provider time, validator time, third-party time and legal-restraint time without hiding the gross duration.

Cohorts matter. A headline measure can conceal slower service for small holders, customers using less common languages, legacy-resource holders, customers outside the provider's home time zone or organizations changing provider. The registry operator should examine results by provider, region of customer operation, request class and service model while protecting personal and commercially sensitive information. Persistent disparity is a service fact even if aggregate performance looks healthy.

Accuracy measures need denominators. The registry operator should report detected contradictions per active record, customer-reported errors, provider-detected errors, time to containment, time to verified correction and recurrence after correction. A rising report count can mean deteriorating quality or improved detection; the surrounding denominator and source distinguish them. Suppressing complaints to improve a rate would be worse than disclosing them.

The evidence should be independently reproducible. Event timestamps should come from signed or witnessed logs. Public reliance surfaces can be observed from independent networks. Customer notices can carry cryptographic receipts without exposing their contents. Reviewers should be able to reconcile the published aggregate with a protected sample. Trust in the report should not require trust in the same provider whose delay is being measured.

One promise must bind the whole service chain

A customer-result commitment fails if each provider meets its local target while the end-to-end journey fails. The registrar can say it forwarded the request on time. The validator can say it committed promptly after receipt. The RDAP publisher can say its service was available. The RPKI operator can say it never received an authorized handoff. Every local dashboard is green, yet the holder remains stuck between institutions.

The registry operator should assign one accountable service owner for each case. That owner communicates with the holder, observes the end-to-end clock and coordinates contributors. This does not make the owner legally responsible for every external event, but it prevents responsibility from becoming a scavenger hunt. Contracts among qualified providers should allocate delay costs and evidence duties behind the customer-facing commitment.

Each handoff needs a receipt and a maximum acceptance time. A receiving service should reject malformed material quickly with reasons rather than allow it to disappear. Shared event identifiers should connect the transfer, record publication and certificate transition without exposing confidential evidence. Where a dependency misses its target, the case owner should continue informing the holder and invoke escalation; it should not close the case as "sent."

Provider qualification should include end-to-end performance. A registrar with excellent support but repeated validator rejections may need better evidence controls. A publisher with high availability but frequent stale state needs consistency repair. A validator that meets local timing while creating certificate gaps has failed the larger service. The registry operator can use service-chain attribution to improve the correct component while preserving a single promise to the customer.

This architecture also allows competition. Customers can compare registrars on end-to-end results even though some common services are shared. Providers can challenge inaccurate attribution with evidence. The common validator cannot use its central position to erase its own contribution. A shared layer should make responsibility legible, not collective in the sense that nobody is answerable.

Remedies convert measurement into accountability

A target without a consequence may improve attention, but it does not rebalance power. The customer still bears the cost of delay while the provider retains fees and control. The registry operator should attach graduated remedies to missed commitments.

The first remedy is automatic service credit. It should not require the customer to prove monetary loss or spend more time filing a claim. If a standard transfer exceeds the provider-controlled deadline, a defined portion of the relevant fee is credited. If a correction misses its containment target, the credit increases with severity and duration. Automatic credits make measurement financially real while keeping low-value claims proportionate.

The second remedy is reimbursement of direct correction costs created by the miss: duplicate provider charges during an avoidable transfer delay, reasonable verification expense after a registry service operator-authored error, or emergency technical assistance needed to restore an intended routing-security state. Evidence and caps can keep this route administrable. It is different from compensation for wider provable loss, which requires causation review and a dedicated fund.

The third remedy is institutional. Repeated misses should trigger enhanced monitoring, a corrective plan, restrictions on accepting new customers, additional continuity security or loss of qualification. A provider should not be able to treat credits as a price for systematically poor service. Patterns matter: many small misses can reveal a weak service, and one severe unauthorized change can reveal a control failure that percentages conceal.

Remedies should preserve the customer's substantive rights. A small automatic credit should not silently release a larger claim. Accepting urgent correction should not waive review of why the error occurred. Conversely, every delay should not create unlimited liability. The registry operator can distinguish automatic service remedies, direct-cost reimbursement and adjudicated compensation while making each route clear before dependence begins.

Publication must expose service truth without exposing customers

Transparency does not require publication of identity evidence, disputed corporate documents or security details. The registry operator can disclose performance with protected case review. The public report should show the service catalogue, targets, definitions, provider results, common-service results, exclusions, severe incidents, aged cases, remedy totals and changes in classification practice.

Provider-level reporting is necessary. An aggregate across many registrars lets a poor provider hide behind stronger peers. Common-service reporting is equally necessary because every registrar may suffer from the same validator or publisher. Reports should identify small samples carefully and suppress only what would create a genuine re-identification risk. Suppression rules should be fixed before results are known.

Severe incidents need narrative accounts after containment. The account should explain the customer-visible failure, affected authority surfaces, duration, detection route, containment, restoration and preventive action. It should not disclose exploit details that would endanger customers. The central question is whether the institution understands how a green local measure coexisted with a failed customer result.

The registry operator should publish revisions. If a report later proves wrong, the original and corrected figures, reason and date should remain visible. Performance data should not become a public-relations product that can be silently improved. The credibility of the service level depends partly on the institution's willingness to correct its own account of correction.

An independent reviewer should test a sample of successful, missed and excluded cases. Sampling only failures can miss false success; sampling only random cases can miss severe tails. The reviewer should trace each selected case from receipt through authoritative observation and remedy. Findings should identify control weaknesses without turning customers into examples they did not consent to become.

Service levels need change control of their own

An institution can weaken a commitment without openly abolishing it. It can redefine completion, enlarge exclusions, move cases into a new class, alter the service calendar or stop publishing a percentile. The registry operator should treat definitions as part of the customer bargain rather than editable dashboard settings.

Material changes should receive notice, a redline, stated evidence and independent impact analysis. The change record should show who benefits, which existing cases are affected and whether performance would appear better under the new definition without any improvement in service. Historical reports should remain comparable or provide a bridge between definitions.

Emergency changes may be necessary during a major security event. They should be narrow, time-limited and reviewed after the event. An emergency should not become a permanent suspension of correction or transfer rights. If a target cannot safely be met, the registry operator should state the revised customer protection, the reason and the route for urgent exceptions.

Customers and providers should have standing to challenge a definition that produces perverse behavior. A target that rewards premature closure, discourages difficult corrections or makes providers avoid small customers is badly designed even if compliance is high. Governance should examine behavior around the metric, not just the number.

Five cases show what an outcome changes

A stale RDAP name after an accepted merger update. The registrar accepts the evidence on Monday and marks the case complete. The private account changes immediately, but authoritative RDAP continues to show the old company until Friday. Under an activity-based measure, the registrar met its target. Under the registry-record accuracy commitment, the clock continues until the public reliance surface shows the accepted state and the holder receives confirmation. The publication failure is attributed to the responsible service, and an automatic credit follows if the deadline was missed.

A correction allegation supported by an old allocation letter. A network operator finds that the public record identifies a company that dissolved years earlier. The operator supplies a successor document; the registry operator holds different historical evidence. The final answer cannot be immediate. The correction commitment still requires quick preservation, standing checks, a neutral status if reliance risk is credible, one consolidated evidence request and a reasoned decision by a maximum age. Uncertainty becomes a managed state rather than an excuse for silence.

A provider switch obstructed by unrelated debt. The current holder instructs a gaining registrar. The losing provider entities because the holder disputes a consulting invoice unrelated to registration service. Under a vague transfer promise, the objection may pause the case indefinitely. Under the registry operator's rules, the validator rejects an objection outside the permitted categories, commits the provider change, retires the former authority and leaves the commercial dispute to its proper forum. Exit cannot be collateral for every private claim.

A hosted RPKI move with active ROAs. The holder changes provider while several route authorizations are in use. Treating the registration change as complete before the new authority works could create an invalid state; leaving old credentials active could create a security risk. The handoff commitment inventories intended authorizations, establishes the new relationship, verifies relying-party state, restricts changes during any short overlap and retires old authority. Completion means continuous authorized effect and customer control, not an email saying the files were sent.

A registrar fails during account compromise. The holder reports suspicious changes, but the ordinary provider is unreachable. A portal-availability target offers no protection. The registry recovery commitment allows the holder to invoke an independent emergency channel, freezes further high-risk change, preserves safe RPKI state, verifies representatives through pre-established evidence and activates a successor provider. The customer result is restored controlled authority, with a later review of every incident-period change.

These cases also show why no single speed number is enough. Some outcomes require publication, some a reasoned treatment of uncertainty, some one ordered commit, some cryptographic continuity and some substitute service. The common principle is that the clock ends at a condition the customer and an independent reviewer can verify.

The strongest objections can be answered without making promises fictional

The first objection is that registries cannot control every dependency. Courts, corporate registries, sanctions authorities, customers and network operators may all affect a case. That is true. A service level should not pretend otherwise. It should identify external restraints, require timely action on the controllable parts, disclose gross and excluded time, and maintain escalation. Limited control justifies careful attribution, not the disappearance of an end-to-end commitment.

The second objection is that rigid deadlines encourage unsafe approval. A target that rewards acceptance at any cost would be reckless. The operator's commitments should measure safe results and allow narrow evidence pauses. They should pair ordinary deadlines with containment and reasoned escalation. The answer to safety is not indefinite provider discretion; it is a clock that recognizes what can be completed now and what requires adjudication.

The third objection is that public performance tables invite gaming. Any metric can be gamed. That is why the registry operator should publish definitions, tails, exclusions, reopening, cohorts and independent samples. A hidden metric is not immune to gaming; it is merely harder for customers to challenge. Multiple related measures make manipulation more expensive. If fast closure causes repeated reopening, the reopening rate reveals it.

The fourth objection is cost. Independent observation, continuity arrangements and customer remedies require funding. Yet delay already has a cost, currently transferred to holders and networks. The registry operator should price the cost of reliable service openly and compare it with duplicate charges, failed transactions, emergency engineering and prolonged disputes. A cheap registry that externalizes correction and recovery is not necessarily efficient.

The final objection is that customers care only about routing. Registries do not direct all routing, and a correct registration record cannot guarantee reachability. But registration, RDAP, reverse authority and RPKI affect evidence and security around routing. The registry operator should make no promise outside its control. It should make strong promises about the authority surfaces it does control and the handoffs it chooses to offer.

A practical registry-operator service constitution

The registry operator can adopt the design in a sequence that preserves ambition. First, define the five customer journeys and their observable end states. Map every contributing service and identify the evidence that proves completion. Publish a temporary baseline using historical cases without yet attaching penalties, so definitions can be tested against reality.

Second, set severity classes, receipt rules, permissible pauses and independent observation. Require providers to issue consolidated sufficiency notices and preserve gross time. Test the measures against cases involving ordinary updates, legacy evidence, provider exit, active ROAs and loss of provider availability. Revise any rule that can be satisfied while the customer remains unable to use the service.

Third, attach automatic credits and direct-cost reimbursement. Publish provider-level and common-service results. Give an independent reviewer access to protected samples and authority to require corrected reporting. Tie repeated failure to qualification rather than allowing providers to purchase permanent nonperformance through small credits.

Fourth, connect the service catalogue to the wider remedy system. A missed clock should create evidence for compensation where provable loss exists, but the claimant should not need to relitigate basic timestamps or whether the commitment was missed. Shared facts reduce dispute cost while preserving separate review of causation and amount.

Finally, make the commitments durable. Definitions, historical series and change records should remain public. Continuity exercises should test both technology and customer access. Customers should be able to export their service history and current authority evidence. Successor providers should be able to assume service without the failed incumbent's cooperation when pre-defined conditions are met.

The governing test is simple: if staff stop looking at their own screens and stand in the holder's position, can they prove that the promised condition exists? If not, the metric is diagnostic rather than contractual. Diagnostics help run the service. Customer-result commitments make the service answerable.

Service quality is part of authority

Internet number administration is often discussed as if legitimacy comes from history, recognition, community participation or technical competence. Each can matter. None is sufficient where the institution controls changes that customers cannot readily obtain elsewhere. Authority is also expressed in the time it takes to correct an error, permit an exit, restore control and make dependent security state safe.

A provider that can impose immediate consequences on a holder but offers only aspirational timing for its own corrections has asymmetric power. An institution that counts consultations but not days of unresolved wrong state measures voice without remedy. A common validator that serializes every provider change but accepts no end-to-end commitment recreates monopoly at the coordination layer.

The registry operator can choose a different standard. It can use technical measures to maintain reliability while judging service at the point where reliability becomes meaningful to a customer. It can separate genuine external restraint from provider delay. It can make safe complexity visible without allowing complexity to become an unlimited extension. It can connect missed promises to money, review and qualification.

The result would not be a guarantee that every dispute ends quickly or every network remains reachable. It would be a guarantee of institutional conduct: observable starts, honest classification, bounded pauses, verifiable outcomes, transparent tails and consequences for failure. That is the appropriate ambition for a system whose records and security handoffs can shape real operational dependence.

Sources

NRS and BTW role sources