Summary
- Resolution 201106.117 was a genuine act of AFRINIC’s private Board. It ratified AFPUB-2010-GEN-006-draft-02 after a recorded policy process, allowing AFRINIC to build and promote a dedicated public abuse-contact path in Whois. It did not confer sovereignty, regulatory jurisdiction, police power, punishment power, confiscation authority or adjudicative jurisdiction.
- The ratified design concerned an object and its contact fields: a unique reference, an
e-mailattribute for personal communication, anabuse-mailboxattribute for automated reports, Whois accessibility, member guidance and implementation work. The record contains no periodic validation cadence, response deadline, investigation duty, merits judgment, customer-action requirement, content-removal power, sanction ladder, resource-revocation rule or appeal forum. - Contactability is a legitimate thin-registry function. A directory can reduce the time and error involved in finding the party capable of receiving an operational report. But delivery is not proof, silence is not a verdict, disagreement is not obstruction, and a published mailbox does not turn the registry that maintains it into the tribunal for the accusation sent through it.
- The strongest operational case for the policy remains strong within its boundary. Resource holders benefit from an intelligible route for complaints; complainants benefit from less misdirection; AFRINIC can require the internal format of its own records to be coherent and technically usable. The boundary is crossed only when record hygiene is treated as authority over conduct or leverage over the continued use of resources.
A small resolution with a consequential boundary
The most revealing fact about Resolution 201106.117 is not that it was weak. It is that it was specific. AFRINIC’s Board ratified a policy intended to make an abuse contact easier to find in the public registry. The policy gave a complaint a better address. It did not give AFRINIC a new jurisdiction over the conduct described in the complaint.
That distinction can disappear when the word “abuse” is allowed to do too much work. Network abuse can involve serious operational, contractual or legal questions. A complaint may describe spam, compromised systems or another form of unwanted activity. But an attribute named for abuse is still an attribute. A Whois object is still a record. A Board resolution within a private registry is still an internal institutional act. None becomes a police power merely because the subject matter carried through the record is serious.
The June 2011 act therefore deserves to be read in two directions at once. In the first direction, it was meaningful. It completed an identifiable stage in AFRINIC’s policy process and authorized implementation work across the registry’s systems and member-facing operations. In the second direction, it was bounded. Its operative material was about publishing contact information, distinguishing kinds of communication, making the information queryable, and encouraging use. It did not decide the truth of future allegations. It did not set a standard for acceptable network conduct. It did not prescribe a punishment.
The resolution register says the Board ratified AFPUB-2010-GEN-006-draft-02, described as the Abuse Contact Policy. It also records that consensus had been reached on the RPD mailing list and at the Johannesburg meeting and that the proposal had been submitted by the PDP co-chair. Those statements establish the institutional route by which the proposal reached the Board. They do not turn the participating community, co-chair or Board into a legislature for African networks, and they do not expand the content of the ratified draft beyond what the draft said.
This is why the difference between a doorbell and a police power is not rhetoric. A doorbell solves a routing problem. It makes it more likely that someone at the responsible network can receive a report. Police or adjudicative power solves—or claims to solve—a different problem: deciding facts, applying standards, compelling action and imposing consequences. Resolution 201106.117 did the former. The instrument contains none of the machinery that would be necessary even to describe the latter.
What the Board actually did
The controlling act belongs to AFRINIC’s June 2011 Board-resolution sequence. The sequence closes with a resolution adjourning a face-to-face meeting held in Dar es Salaam on 6 June. A PGP-signed notice from Acting CEO Alain Aina, sent on 19 June, told the RPD list that the Board had ratified draft-02 during that face-to-face meeting. The notice then said staff would work on implementation and inform the community in due time.
The dates matter because the surviving AFRINIC materials do not align neatly. The current policy archive labels 19 June as the Board-ratification history date, apparently reflecting the date of the signed notice. A later implementation guide gives 2 May, which conflicts with the resolution sequence and the June notice. The sound conclusion is narrow: Resolution 201106.117 sits in the June sequence, the face-to-face meeting was held on 6 June, and the signed public notice was sent on 19 June. The later May statement should not be repeated as settled history.
It is equally important not to merge ratification with deployment. The 19 June notice used the future tense for staff work. Whatever institutional effect ratification had inside AFRINIC, it did not demonstrate that a new production feature was already working. Later materials say implementation followed in 2012, but they disagree over whether the relevant point fell in March or May. That unresolved downstream date does not alter the 2011 act. It confirms that approval and operational implementation were distinct.
Within AFRINIC, the Board could approve the policy and direct staff to implement it. That is real authority over the registry’s own rulemaking and service machinery. It is neither nothing nor everything. The act could set work in motion in Whois, MyAFRINIC, application forms, request templates, help pages, training and internal support. It could not, by its own force, create governmental sovereignty, general regulatory jurisdiction, investigative jurisdiction or a right to confiscate resources.
The language of ratification should therefore be read as institutional authorization, not territorial command. AFRINIC was coordinating a registry service and maintaining consequential records. Its Board acted within that private organization. The resolution does not identify a public-law delegation, and the available record does not establish the exact legal or bylaw source for the Board’s ratification role. That unknown should remain an unknown. Nothing in the gap justifies inventing a broader jurisdiction.
Nor does the reference to consensus supply the missing power. Consensus in a policy-development process can support legitimacy, test operational acceptability and expose design objections. It does not create sovereignty. The meeting report records that the interim co-chairs determined consensus to progress the proposal to Last Call, with no meeting changes suggested. The Last Call began on 18 March 2011 and ran through 4 April, with a reminder on 3 April. These steps show a process. They do not turn process participation into consent to unstated enforcement powers.
The field design the resolution ratified
The proposed policy’s stated purpose was to create a dedicated object as the preferred place to publish public abuse-contact information in the AFRINIC service region. The practical aim was accuracy in routing: reports should reach the correct network contact more efficiently than they might through generic addresses, remarks or contacts maintained for other purposes.
The design was intelligible because it separated communication modes. The object would carry an e-mail attribute for personal communication and an abuse-mailbox attribute for automatic report handling. The proposal described a unique reference and said the object could be referenced from inetnum, inet6num and aut-num objects. It was to be accessible through Whois. AFRINIC was also directed to publish a best-practice paper and actively inform and encourage members to use the object.
This is a modest architecture, but not a trivial one. A generic administrative address may reach a person who manages registration records but does not operate the affected service. Free-form remarks are inconsistent and hard to process. Automated reports can overwhelm an address intended for individual correspondence. A dedicated object, a distinct automated-report mailbox and a predictable reference can lower search costs for both humans and systems. That is a real improvement in the legibility of the registry.
The division between e-mail and abuse-mailbox also shows why field design should not be confused with substance. One field indicated personal communication; the other was intended for automated report handling. These labels arrange delivery. They do not define what counts as abuse, how evidence should be weighed, whether the named network caused the reported activity, what an adequate response would contain, or which legal or contractual rule should apply.
AFRINIC staff’s January 2011 impact analysis explored how the concept might fit existing records. Staff envisaged an extra optional attribute, possibly named abuse-c, in resource objects, pointing to a person or role object. The referenced object could appear once and would include mandatory e-mail and abuse-mailbox attributes whose values were to be valid e-mail addresses. That was implementation analysis. It disclosed a contemplated object model; it was not additional language silently inserted into Resolution 201106.117.
The proposal author, Tobias Knecht, accepted that abuse-c was an understandable name but identified problems with using ordinary person or role objects. Query restrictions could make a contact harder to retrieve, and multiple abuse-mailbox values could create conflicting answers. He preferred a special role account with a required abuse-mailbox and unrestricted Whois queries. The exchange is useful precisely because it stays at the correct layer: object type, query behavior, uniqueness and field clarity.
The staff view and author’s reply were not identical. That is not a defect to be smoothed away. It reveals the translation from policy purpose to database implementation. The proposal sought a dedicated contact object. Staff evaluated reuse of person or role objects and an abuse-c reference. The author pressed for a special role account to avoid predictable retrieval and ambiguity problems. These were design choices inside a directory service, not disputes over who should judge the merits of an accusation.
Opportunity and encouragement, not an immediate universal mandate
The policy’s member-impact language is another check against exaggeration. It said there would be no immediate impact and described the effect as an opportunity to publish a dedicated abuse contact and obtain the resulting benefits. AFRINIC was to inform and encourage members to use the object. The text did not say that every existing resource object immediately had to carry a reference.
Staff did contemplate points at which contact information would enter normal operations. The new-member form would collect detailed abuse-contact information. During a request for additional resources, an existing member could be asked to create a referenced object or provide the data so AFRINIC could create it. Those plans explain how adoption might be folded into forms and service interactions. They do not transform an optional reference in the analyzed design into a universal ratification-day obligation.
Later AFRINIC guidance described implementation through an IRT object and a mnt-irt reference. Both that guidance and a later operational article treated the resource-object reference as optional. That later evidence is relevant only as confirmation of the original opportunity-and-encouragement character. It should not be used to rewrite the 2011 instrument with later details or to make downstream operations the subject of the analysis.
The distinction between a mandatory field inside an object and a mandatory reference from every resource object is especially important. Under staff’s reading, once the dedicated referenced object existed, e-mail and abuse-mailbox were required within it. But the path from every existing inetnum, inet6num or aut-num object to such a contact was not established as universally mandatory at ratification. “Required within the chosen record” and “required for every holder in every record” are different propositions.
That distinction is easy to lose because database schemas often mix obligation levels. An attribute can be mandatory in an object class even when creation or linkage of that object is optional. A form can prompt for information without proving that refusal triggers a sanction. A staff workflow can encourage completion without creating a legal duty to respond to every report. Institutional analysis has to preserve these layers instead of turning technical cardinality into punitive jurisdiction.
Accuracy was expressly left unsolved
The ratified proposal acknowledged a problem that many later readings might be tempted to pretend it solved. Whois data can be inaccurate. The text said the new object would face that general problem and expressly said the proposal would not improve Whois data accuracy. It suggested that inaccurate or non-working objects might be reported through some mechanism, but placed that mechanism in another proposal.
This admission sharply bounds the policy. Staff said field values must be valid e-mail addresses, but the available material does not define “valid.” It could refer to syntax, a deliverable mailbox, ownership by the intended operator or a capability to respond. The 2011 record does not choose among those meanings. There is no periodic deliverability test, proof-of-delivery method, response clock, substantive adequacy test or procedure for false positives.
Objective record hygiene is still within a thin registry’s legitimate role. A system can enforce that a field uses the expected form. Staff can avoid duplicate or ambiguous references. A directory operator can make a query return the intended attribute. It can correct a plainly malformed record through an appropriate record-maintenance process. These acts maintain the directory as a directory.
But even a reachable mailbox proves very little about the allegation it receives. Delivery does not identify the actor responsible for traffic. A resource holder may route addresses to customers, downstream networks or hosted systems. Automated reports can be incomplete or mistaken. A mailbox owner may investigate and disagree. A response may be delayed by the complexity of tracing an event. None of those possibilities was resolved by the object schema, and the schema did not claim to resolve them.
The correct boundary is therefore not “accuracy does not matter.” It is that different kinds of accuracy demand different institutions. Syntactic field correctness, unique references and predictable query output are registry questions. Mailbox reachability is a contactability question, if a policy creates an objective and fair way to test it. The truth of an accusation, the adequacy of an investigation and the remedy for unlawful conduct are substantive questions. Resolution 201106.117 remained on the first side of that line and did not construct a regime for the second.
What the instrument did not create
The absence of enforcement machinery is not a technical omission to be filled by implication. It is decisive evidence of the instrument’s scope. The ratified material contains no response-time duty, no standard for the content of a response, no requirement to act against a customer, no mandate to investigate, no test for deciding whether an abuse report is true, and no authority to remove content or control speech.
It also contains no warning ladder, fine, service restriction, contract-termination path, resource revocation, deregistration, RPKI impairment, reverse-DNS removal, transfer denial, confiscation or comparable punishment for contact failure. Those concepts cannot be imported backward from later proposals, later disputes or general anxieties about registry power. The owned act is the June 2011 ratification and its contact-field design. Its silences must remain silences.
Because the policy did not create an adverse merits or resource-sanction decision, it did not set out a hearing, an appeal or an independent review forum for one. That absence cannot be inverted into a claim that AFRINIC possessed an unreviewable power. The more faithful inference is that the instrument did not create the substantive decision in the first place. There was no adjudicative outcome for the text to send on appeal.
This category separation protects both the usefulness of the registry and the rights of the people who depend on it. If a contact record is wrong, the record can be corrected. If an allegation concerns a customer, the operator can investigate under its technical procedures and contracts. A provider may enforce its own agreement. A complainant may use an available legal remedy. A competent public authority or court may act within its jurisdiction. Each role has a different source of authority and a different standard of proof.
AFRINIC’s role was different. As a private bookkeeper and coordinator, it maintained the registry surface through which strangers could identify and contact the relevant network party. Its possession of a consequential ledger did not make it a sovereign, regulator, police force, punisher, confiscator or adjudicator. A database operator does not acquire the powers of every institution that uses data from the database.
This matters in both directions. Describing AFRINIC as “only” a private coordinator should not erase the practical effect of its systems. Registry choices can shape operational continuity and the visibility of resource records. But acknowledging consequence does not authorize mission expansion. Precisely because the ledger matters, the authority exercised through it should stay close to the technical and contractual function that justifies the ledger.
The strongest case for a real contact obligation
The best argument for a robust contact policy is not difficult to state. A public registry contact is useful only if resource holders supply it, maintain it and make it technically usable. An empty field, a malformed address or an unreachable mailbox defeats the routing function. If every participant can ignore the schema, the collective benefit of a standard contact path collapses.
The staff impact analysis reinforces that operational case. Implementation would not be a single database alteration. It implicated the new-member form, additional resource requests, MyAFRINIC, Whois, request templates, website help, training and internal guidance. Staff estimated roughly sixty days for full implementation and classified long-term internal impact as minimal, within a zero-to-three-month range. The estimate does not establish the actual deployment date, but it shows that a usable contact path required coordinated work.
A registry may therefore insist that records in its system comply with objective format rules. It may decide that a dedicated object must contain the fields its schema defines. It may design forms to collect the data and prompts to encourage an existing member to create the reference. It may make clear that automated reports and personal communications should not be mixed. It may publish best practice so members understand the operational benefit.
These measures can improve the common service without deciding a single abuse allegation. They reduce misdirection. They prevent ambiguity about which address should receive automated reports. They make it easier for operators to separate machine-generated volume from human correspondence. They also help resource holders by providing a channel they control rather than forcing outsiders to guess among unrelated contacts.
The argument becomes unsound only when necessity is allowed to jump categories. From “the mailbox should be properly formatted” it does not follow that “the registry may decide whether the mailbox owner answered well.” From “the contact should be reachable” it does not follow that “silence proves the reported conduct.” From “the registry must protect its record system” it does not follow that “the registry may impair number resources to compel a substantive outcome.” Each step would require new authority, new standards, procedural safeguards and remedies absent from Resolution 201106.117.
The strongest contrary case therefore supports the thesis rather than defeating it. A useful registry needs disciplined records. The policy ratified in 2011 provided a reasonable architecture for that discipline. Its legitimacy depended on remaining a contact-publication measure. The more consequential the registry’s operational position, the more important it is not to convert that position into a shortcut around the institutions responsible for contracts, evidence, law and adjudication.
The institutional power chain
The policy’s path can be described without attributing power to the wrong actor. A proposal author developed a dedicated-contact mechanism. The author’s expertise and advocacy helped define the design, but authorship did not make the proposal binding. Participants discussed it, and the interim co-chairs at AFRINIC-13 determined consensus to move it to Last Call. That determination advanced the process; it did not create public authority.
Staff then evaluated implementation. Their analysis addressed attributes, object types, forms, portals, support and timing. The author challenged part of the object model. Those exchanges exposed operational tradeoffs. The PDP co-chair later submitted the proposal, and AFRINIC’s Board ratified it through Resolution 201106.117. The Board act made the policy an internal commitment for AFRINIC and placed implementation with staff.
After ratification, resource holders and operators would supply or maintain contact information and handle reports within their own operational and legal responsibilities. Complainants would use the public route. Customers, providers and security teams would investigate or act under their relevant relationships. Courts and lawful authorities would retain their own roles when legal compulsion or adjudication was necessary.
No link in this chain absorbed all the others. The proposal author did not become a regulator. Meeting participants did not become a regional sovereign. Staff did not become investigators of every allegation by designing a database field. The Board did not become a court by ratifying the field. The operator receiving a complaint did not become guilty by being listed. And the complainant did not obtain a judgment merely by sending a report.
This distributed chain is a feature, not a failure. It allows the registry to specialize in a useful coordination function while leaving fact-finding and remedy with actors that possess the relevant evidence, relationship or legal authority. The public directory connects the actors. It does not collapse their roles into the institution that maintains the directory.
Contactability is not a verdict
A dedicated abuse contact can be judged on a simple question: did it improve the probability that a report reached a party capable of receiving it? That is a contactability measure. It says nothing by itself about whether the report was accurate, complete, proportionate or made in good faith.
Confusing delivery with proof creates several errors at once. It treats the label attached to the message as a finding. It treats the recipient’s silence as agreement. It treats a private registry’s visibility into its own records as visibility into customer systems, traffic logs and contractual arrangements. It treats operational delay as defiance. And it treats the continued registration of number resources as a lever for resolving a controversy that may belong elsewhere.
The policy text resisted that confusion by staying narrow. It designed a preferred public contact location. It distinguished personal from automated correspondence. It asked AFRINIC to expose the object through Whois and to encourage use. It acknowledged that data accuracy remained a general unresolved problem. It did not describe a complaint tribunal.
The wider framework supplied by Heng Lu makes the institutional logic explicit. A thin abuse-contact rule belongs with directory accuracy and objective contactability. It must not mutate into conduct regulation, content judgment, revocation leverage, punishment or confiscation. The registry is a private bookkeeper and coordinator even when the book it keeps matters deeply. Consequence does not produce sovereignty.
The NRS resource-holder perspective sharpens the risk on the other side of the ledger. A registry occupies a chokepoint because errors or discretionary decisions can propagate into a holder’s ability to operate. That risk supports correctable, bounded contact records. It does not prove any improper motive in 2011, and it does not show that the 2011 Board imposed a sanction. It explains why later readers should refuse to discover sanction power in a text that did not contain it.
The LARUS operator-continuity perspective similarly explains why institutional categories matter. Registry decisions can affect infrastructure reliance, so the distinction between correcting a record and impairing a resource is not academic. BTW’s adjacent research shows the value of complaint routing and public records for strangers seeking an accountable counterparty. Those benefits strengthen the case for the doorbell. They do not turn the doorbell into a verdict.
A counterfactual that preserves both usefulness and restraint
Without a dedicated contact-object design, a person reporting an operational problem might search through generic addresses, administrative contacts and remarks. The message could reach someone concerned only with registration paperwork, disappear into a mailbox not meant for automated volume, or be delayed while one organization tried to identify the responsible team. Operators would receive reports inconsistently, and complainants would spend more effort locating a plausible recipient.
With a dedicated contact that remains a contact, the registry can improve this situation. A predictable query points to the intended channel. Separate fields distinguish personal communication from automated reporting. Best-practice guidance helps members configure the route. Forms and service interactions can prompt the creation of the object. The result is less search, less misdirection and clearer responsibility for receiving the initial message.
Nothing in that counterfactual requires AFRINIC to decide the merits. Once delivered, the report returns to the institutions and relationships capable of handling it. The operator can inspect technical evidence. A customer can explain or remediate. A provider can apply its contract. A complainant can pursue an appropriate remedy. A competent authority or court can use lawful powers. AFRINIC’s work is complete when the directory function has made the relevant party findable under the rule it administers.
This division also creates better accountability. If the mailbox format is wrong, AFRINIC’s record process can address the format. If a complainant fabricates evidence, that question is not hidden inside a registry workflow. If an operator fails a contractual duty, the contract supplies the standard. If conduct is unlawful, public law supplies the competent authority and procedural safeguards. Each dispute is evaluated within a framework designed for it.
By contrast, an expanded registry role would concentrate incompatible functions. The same body maintaining resource records would receive allegations, define acceptable response content, assess guilt and control an operational chokepoint. Resolution 201106.117 did not establish that arrangement. Reading it as though it did would not merely exaggerate the policy. It would erase the deliberate institutional distinction that makes a thin contact function defensible.
What may be concluded, and what must remain unknown
The record supports a firm bounded conclusion. AFRINIC’s private Board ratified draft-02 in the June 2011 sequence. The policy was intended to create a dedicated, Whois-accessible place for abuse-contact information, with distinct fields for personal and automated communications and a reference architecture for resource objects. AFRINIC could organize its staff and systems to implement that policy.
The record also supports a firm negative conclusion. Ratification did not create sovereignty, regulatory jurisdiction, police power, punishment, confiscation or adjudication. The text established no periodic validation regime, response-content standard, investigation duty, abuse finding, sanction ladder, revocation mechanism or appeal process. Later policy concepts cannot be treated as latent powers in the 2011 act.
Several matters remain unresolved. The public Board register does not disclose attendance, individual votes, abstentions, conflicts or a signed minute excerpt specific to the resolution. The available set does not identify the exact legal or bylaw basis of the Board’s ratification role. The historical draft page viewed by the Board is no longer available at its former location in the checked public record. The meaning of “valid” e-mail in the staff analysis is undefined.
The chronology also retains genuine friction. The June meeting sequence and signed notice control over a later guide’s inconsistent 2 May statement. The exact 2012 production implementation date is unresolved because AFRINIC materials point to March and different May dates. The approximately sixty-day estimate is not a work ledger and cannot establish how long implementation actually took.
There is no basis to invent motive around these gaps. The record does not prove fraud, corruption, bad faith, capture or punitive intent by the Board, co-chairs, staff or proposal author. It does not prove that Resolution 201106.117 caused a revocation, content removal, speech restriction, fine, police referral, court case or confiscation. The absence of such evidence should not be replaced with speculation.
The restraint required by the evidence is the same restraint required by the institution. The resolution should receive credit for the contact problem it addressed. It should not receive powers it did not claim. A better doorbell is useful public infrastructure. It becomes dangerous only when the keeper of the address book is invited to decide what every ring means.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
