Summary
- The RSSAC Caucus supplies most of the labour behind RSSAC reports and advisories, but it cannot take formal RSSAC action. RSSAC appoints Caucus members, can change work scopes, reviews drafts and votes on publication.
- Current procedures are more explicit than the process criticised in the 2018 organizational review. They still leave important audit gaps: no published rejection statistics, standardized appeal record, contribution distribution or complete draft-to-final change history was found.
- The Caucus has upstream framing power, not command over the root. RSSAC advice does not allocate number resources, set RIR policy, write IETF standards or compel an independent root server operator or the ICANN Board.
The document has two authorship chambers
RSSAC062, the May 2025 advisory on security-incident reporting, ends with a useful institutional map. It names thirteen RSSAC Caucus contributors. Robert Story is identified as work-party leader. Ken Renard is the RSSAC shepherd. Four ICANN staff members are listed, including an editor. The document then records no dissents and no withdrawals and says that, subject to those sections, it has the consensus approval of RSSAC.
The list does not tell us how many paragraphs each person wrote. It does show that technical contribution, procedural connection, staff support and formal approval are different jobs.
That division is now set out in RSSAC000v10, approved on 4 August 2026. The procedure says the Caucus produces the majority of RSSAC documents, including reports and advisories. It also says RSSAC is the only entity that can take formal action as RSSAC. A Caucus work product moves through Caucus review, then RSSAC review. RSSAC can send comments, edits and questions. Only after the draft stabilizes does the work-party leader ask for formal action and the Chair place approval on a regular-meeting agenda.
Publication is not a signature added by the drafting group. RSSAC applies its quorum and voting rules. Each root server operator has one vote in RSSAC, and a publication requires a 75 per cent supermajority under the current procedure. Staff publishes after approval.
The architecture therefore has two authorship chambers. The broader chamber assembles expertise and produces the first coherent account. The smaller operator-representative chamber decides whether that account may become an RSSAC publication. Neither fact cancels the other.
Admission is the first control point
The current Caucus page displayed 115 member results when captured for this article. The formal RSSAC page displayed 24 results. Those are public roster counts, not measures of active participation or voting power. They nevertheless show why admission matters: the pool from which most documents are produced is materially larger than the body that formally acts.
RSSAC000v10 gives the Membership Committee the initial screen. It evaluates whether an applicant knows RSSAC's work, can devote time and adds useful skills or experience. RSSAC appoints the committee. The public join page currently names Shailesh Gupta, Dave Lawrence, Jeff Osborn and Ken Renard.
The negative path is unusually consequential. If the Membership Committee decides not to recommend a candidate, the candidate's name is not revealed to RSSAC. The committee chair handles an appeal case by case, and the candidate may not reapply within the same twelve-month period. If the committee does recommend a candidate, staff circulates the application to RSSAC for a one-week decision. No objection means admission. One objection is sufficient to reject. An explanation is available on the candidate's request, and an appeal is handled by the RSSAC Chair case by case.
Nothing in the reviewed record proves that this discretion has been abused. The same record does not disclose how many people applied, how many were rejected at either stage, what classes of reason were used, how often explanations were requested, or what appeals produced. The defensible criticism is therefore an audit gap, not an allegation of improper motive.
This is also where formal and practical power diverge. The Membership Committee does not publish RSSAC advice. Yet a candidate stopped before appointment cannot propose, draft or review as a Caucus member. The appointment gate shapes the future evidence pool before any technical claim is debated.
A work item can begin broadly and still end narrowly
Any RSSAC or Caucus member may propose a work item for the appropriate body. A proposal for Caucus work must include a statement of work and can be discussed and modified by the Caucus. RSSAC may then discuss and modify it again. The RSSAC Chair may call a vote before the work begins.
Once a work party is called, staff administers it until a leader is identified. If the leader is not an RSSAC member, the party also needs an RSSAC-member shepherd. The leader coordinates contributors, reviewers and observers and reports progress to RSSAC. RSSAC can replace the leader or take other action if it considers progress limited public evidence.
These rules distribute initiative but retain control of the institutional perimeter. A Caucus member can put a question on the table. Caucus discussion can reshape it. RSSAC still controls whether that question becomes approved work and whether the resulting text becomes formal advice.
The current RSSAC001v3 project supplies a concrete test. Its April 2025 statement of work asks whether service expectations for root server operators should be revised. The work can end without a new document, but only after two weeks' notice on the main Caucus mailing list. If one or more members dissent, the closure question goes to an RSSAC vote. If a new RSSAC001v3 is produced, that document also goes to an RSSAC vote.
This is not Caucus sovereignty. It is delegated technical production with an operator-representative backstop.
The 2018 review is a baseline, not a current verdict
The independent organizational review published in 2018 found two things at once. Technically oriented readers generally valued the quality and visibility of Caucus documents. The reviewers also reported that only 25 to 30 of roughly 90 members were then active, that boundaries with RSSAC were unclear, that priorities could drift and that RSSAC held de facto control because it decided who joined or left.
Those figures and observations are eight years old. Interview quotations in that report are reported perceptions, not proved present conditions. Repeating them as a description of the 2026 Caucus would be unsound.
The later record matters. Recommendation 6a called for a more effective and transparent process for defining projects, engaging and managing members, managing work and promoting output. A 2020 implementation report said substantive work-party discussion and draft review had moved onto the public Caucus mailing list and that the Membership Committee was assessing engagement. It also said structural change remained dependent on the Root Server System Governance Working Group.
In June 2022, the implementation work party called the second review complete from a project-management perspective while still listing Recommendation 6a as dependent on that governance work. The ICANN Board accepted the reported completion status in September 2022 but requested periodic updates on the two dependency-bound recommendations. The third RSSAC review was later deferred; ICANN's current status page says organizational reviews remain deferred until the first Continuous Improvement Program cycle is complete.
RSSAC000v10 now provides stronger present evidence. It specifies proposal stages, leaders and shepherds, public-list work, member review, two-stage draft review, dissent and withdrawal fields, formal action and publication. Those controls answer parts of the 2018 criticism. They do not supply current participation rates, rejection records or a complete history of substantive edits.
The right conclusion is temporal: the visible procedure improved; the outcome evidence needed to test how it operates remains incomplete.
Advice stops before command
ICANN's Bylaws define RSSAC's role through advisory verbs: advise, communicate, assess risk, respond, report and make policy recommendations. The captured rules do not authorize the Caucus to run a root server, direct an independent root server operator, allocate an ASN or IP prefix, alter an RIR policy or write an IETF standard.
Nor does an RSSAC publication bind the ICANN Board. RSSAC000v10 allows an approved document to be shown to the Board for a courtesy 48-hour preview before publication. ICANN also maintains a workflow for receiving, considering, implementing and closing advisory-committee recommendations. A preview and a status workflow establish process. They do not prove acceptance, causation or compulsion.
For number-resource holders, the relevance is indirect but real. Root-system resilience, incident handling and service expectations influence the operating assumptions on which networks depend. The evidence must still be traced through three separate transitions: expert drafting, RSSAC formal advice and downstream implementation. Collapsing those transitions turns a technical publication into an authority it does not possess.
Sources
- ICANN Bylaws
- RSSAC000v10 operational procedures
- How to join the RSSAC Caucus
- RSSAC Caucus member roster
- RSSAC001v3 statement of work
- RSSAC062: Security Incident Reporting
- 2018 independent RSSAC review
- December 2020 implementation progress report
- June 2022 final implementation progress report
- ICANN Board action of 22 September 2022
- Current RSSAC review status
- ICANN recommendations-to-the-Board workflow
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance