# 3. Community Norms

**Purpose.** Nexus Platforms works because it stays **high-trust**, **high-signal**, and **platform-safe**. These norms protect members, protect the integrity of outputs, and keep the space usable for leaders who cannot afford noise.

#### Quick links (bookmark)

* **Network Charters (rules + governance anchors):** <https://therisk.global/network-charters/>
* **Knowledge Base / Help Centre (how-to + support pathways):** <https://therisk.global/kb/>
* **Documentation (reference):** <https://docs.therisk.global/>
* **Groups (work rooms):** <https://therisk.global/groups/>
* **Q\&A (ask how-to / routing questions):** <https://therisk.global/questions/>
* **Ask a question:** <https://therisk.global/questions/ask/>
* **Events:** <https://therisk.global/events/>
* **Access Restricted (if you hit a gate):** <https://therisk.global/access-restricted/>

***

### 3.1 Rules of the Room (must-read)

The Rules of the Room are the operating conditions of membership. They apply across all spaces (Groups, Q\&A, Events, Publishing, and Work Programs).

#### What we expect (always)

* **Be accurate.** Say what you know, what you don’t know, and what you are assuming.
* **Be scoped.** Post with a purpose and a next action (“seeking review”, “seeking collaborator”, “seeking pointer”).
* **Use the right lane.**
  * Questions → **Q\&A:** <https://therisk.global/questions/>
  * Collaboration / delivery → **Groups:** <https://therisk.global/groups/>
  * Scheduled work → **Events:** <https://therisk.global/events/>
* **Keep it platform-safe.** Don’t publish restricted or sensitive content outside the correct room.
* **No misrepresentation.** Roles, titles, endorsements, and authority claims must be true and current (see **3.3**).
* **Respect the room.** No harassment, no spamming, no low-quality volume posting.

#### What happens if you ignore the rules

Content removal, posting limits, room removal, suspension, or termination of access—depending on severity and pattern (see **3.8**).

#### Where the canonical rules live

<https://therisk.global/network-charters/>\
If something feels unclear, ask in Q\&A so the answer becomes reusable:\
<https://therisk.global/questions/>

***

### 3.2 Public-Safe vs Member-Only (how to choose the right visibility)

Nexus Platforms may include spaces with different visibility (public-safe areas and member-only areas). Your job is to choose the safest appropriate lane.

#### 3.2.1 Public-safe (default safe posture)

Use public-safe language when content could be reasonably shared outside the room without harm.

**Good public-safe content**

* high-level insights and lessons learned
* general patterns and templates (no sensitive details)
* event takeaways that do not reveal restricted context
* open questions and requests for public-safe guidance

**Avoid in public-safe**

* internal procedures, security details, vendor weaknesses
* non-public incident details
* personal data or sensitive operational context
* anything that could be misconstrued as endorsement or authority

#### 3.2.2 Member-only (bounded sharing inside governed rooms)

Use member-only rooms when discussing working context, early drafts, or scoped internal details that are still safe for a trusted member audience.

**Good member-only content**

* drafts for review
* scoped working notes
* operational questions relevant to members
* collaboration threads inside groups

#### 3.2.3 If you’re unsure: use the “two-step” method

1. Post a **public-safe summary** (no sensitive detail; just enough for routing).
2. Move deeper material into the correct **member-only** group room (when permitted).

**Routing tools**

* Ask “where does this belong?” in Q\&A: <https://therisk.global/questions/ask/>
* Move collaboration into Groups: <https://therisk.global/groups/>

***

### 3.3 No Misrepresentation (role/title/endorsement hygiene; do/don’t examples)

This is one of the strictest norms. It protects the platform and every member.

#### 3.3.1 What counts as misrepresentation

* Claiming a role you don’t hold (or no longer hold)
* Implying endorsement by **GCRI/GRF/GRA/NSF/Nexus Platforms** when none exists
* Presenting drafts or ideas as “approved standards”
* Using logos/brand language in a way that suggests official authority
* Speaking “for” institutions without explicit authorization

#### 3.3.2 Do / Don’t examples

**DO**

* “I’m a Community Member on Nexus Platforms.”
* “I’m contributing to a working draft and seeking review.”
* “My views are my own; this is not an official position.”
* “I’m participating in a Build; the output is not a released standard.”

**DON’T**

* “I’m the Chair / Lead / Official Representative” (unless formally appointed and current)
* “This is endorsed/approved by Nexus/GCRI/GRF/GRA” (unless explicitly granted)
* “Certified / verified / accredited” (unless the platform has issued that status)
* “Official partner” language without written grant

#### 3.3.3 Safe language you can always use

“Contributor”, “Reviewer”, “Host”, “Builder”, “Mentor”\
These describe your participation lane without implying institutional authority.

If you see possible misrepresentation: follow **Reporting Issues (3.7).**

***

### 3.4 Respectful Conduct and Anti-Spam Norms (what gets removed; why)

Nexus Platforms is designed for principals and operators. Noise is a tax on everyone.

#### 3.4.1 Expected conduct

* Disagree with ideas, not people
* Ask clarifying questions before asserting wrongdoing
* Use evidence and scope (“in this context”, “for this use case”)
* Keep language professional and calm, especially under disagreement

#### 3.4.2 What is removed (typical)

* harassment, hate, threats, personal attacks
* repeated off-topic promotion
* low-effort posts with no scope/ask
* copy-paste floods across multiple rooms
* doxxing or sharing personal data
* manipulative “endorsement farming” / pressure tactics

#### 3.4.3 What to do instead of spamming

* Put “how-to” questions in Q\&A (one question per thread): <https://therisk.global/questions/>
* Create one clean group thread (not many scattered posts): <https://therisk.global/groups/>
* Use Events for scheduled sessions (don’t “announce everywhere”): <https://therisk.global/events/>

***

### 3.5 Confidentiality Basics (what not to post; safe summaries)

You should assume that some members are under strict professional constraints (regulatory, corporate, governmental, or research).

#### 3.5.1 Never post

* personal data (yours or others)
* credentials, access keys, internal URLs, non-public system details
* confidential contracts, term sheets, internal memos
* incident details that identify specific targets, weaknesses, or timelines
* anything you are legally bound not to share

#### 3.5.2 Safe summaries (how to share without harm)

Use a public-safe pattern:

* **Context (high-level):** “We observed a continuity issue in a critical workflow.”
* **Impact (generic):** “It caused operational delay, not disclosure.”
* **Lesson (reusable):** “The failure mode was in dependency mapping; here is a general checklist.”
* **Ask:** “Looking for peer review on the checklist.”

If you need to route sensitive material, ask for the correct lane first:\
<https://therisk.global/questions/ask/>

***

### 3.6 IP & Reuse Basics (what you may upload/share; attribution expectations)

Nexus Platforms is a build environment. That only works if IP is handled cleanly.

#### 3.6.1 What you may upload/share

You may upload/share content you have the right to share:

* your own original writing and templates
* public materials with clear permission for reuse
* references and links (preferred for third-party materials)

Best practice: **link to third-party resources instead of uploading them.**

#### 3.6.2 What you must not upload

* proprietary documents without explicit rights to share
* confidential employer/client materials
* copyrighted materials you do not have permission to redistribute
* data that violates privacy, confidentiality, or handling constraints

#### 3.6.3 Attribution expectations (simple rule)

If it’s not fully yours, do one of the following:

* Link the source, or
* Cite the author/organization and the publication date, or
* State “adapted from \[source]” and describe what you changed

If you’re unsure whether something is acceptable to upload, post a public-safe question first:\
<https://therisk.global/questions/ask/>

***

### 3.7 Reporting Issues (conduct, integrity, moderation, platform incidents)

Reporting keeps the community safe. Reports are treated as operational inputs, not “drama.”

#### 3.7.1 What you should report

* harassment or abusive behavior
* misrepresentation (titles, endorsements, authority claims)
* spam or coordinated manipulation
* confidentiality breaches
* suspicious activity or platform security concerns
* persistent off-lane behavior that harms room usability

#### 3.7.2 The fastest reporting paths (choose the right one)

**A) For “where do I report / how do I…” questions**\
Use Q\&A so the guidance becomes reusable:\
<https://therisk.global/questions/ask/>

**B) For operational issues / suspected incidents**\
Use the Help Centre to follow the formal support pathway:\
<https://therisk.global/kb/>

**C) For urgent integrity issues inside a specific room**\
Use that room’s moderator pathway (many groups pin the correct route at the top).\
Start by locating the room:\
<https://therisk.global/groups/>

#### 3.7.3 What to include in a report (so it can be acted on)

* link to the content (URL)
* date/time (approximate)
* what happened (2–5 sentences)
* why it matters (impact)
* screenshots if the content may be deleted or edited

***

### 3.8 Moderator Actions (what happens after a report; escalation path)

Moderation is a safety and integrity function, not a debate function.

#### 3.8.1 What moderators may do

* remove or edit content (for safety, clarity, or confidentiality)
* issue warnings and guidance
* restrict posting temporarily
* remove a member from a group/room
* suspend or terminate platform access for severe/repeated violations
* route incidents through formal handling procedures (where applicable)

#### 3.8.2 Typical response sequence

1. **Triage:** confirm scope, severity, and whether immediate removal is required
2. **Containment:** limit spread (remove content / restrict access if needed)
3. **Review:** assess intent, pattern, and impact
4. **Action:** warning / restriction / removal / escalation
5. **Record:** ensure the issue is logged via the appropriate internal process
6. **Follow-up:** provide guidance to prevent recurrence (when safe to do so)

#### 3.8.3 Escalation path (simple)

* Start with the room-level pathway (group moderators / pinned guidance)
* If unresolved or platform-wide, escalate through the Help Centre: <https://therisk.global/kb/>
* If the question is about process/routing, use Q\&A: <https://therisk.global/questions/ask/>

***

### Platform-Safe Posting Checklist (use before you publish)

Before posting anywhere (Groups, Q\&A, Events, Journals), confirm:

* Is this in the right lane? (Q\&A vs Groups vs Events)
* Is it public-safe for the room’s visibility level?
* Does it avoid misrepresentation?
* Is it scoped with a clear “next action”?
* Do I have the rights to share this material?

If any answer is “not sure,” ask the routing question first:\
<https://therisk.global/questions/ask/>


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.therisk.global/organization/operations/platforms/3.-community-norms.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
