For the complete documentation index, see llms.txt. This page is also available as Markdown.

ARTICLE IV. PARTICIPATION

Section 94. Membership or Memberless Governance Structure

94.1 Membership Determination.

94.1.1 The Global Centre for Risk and Innovation — Canada shall maintain either a statutory membership structure or a memberless governance structure, as determined by its Articles, applicable Canadian law, and the formal records of the Corporation.

94.1.2 The Corporation’s membership structure shall be determined only by lawful corporate instrument, including the Articles, this Bylaw, a Board resolution adopted within lawful authority, a member resolution where required by law, or another governance record expressly authorized by applicable Canadian law.

94.1.3 No person shall be treated as a statutory member, voting member, non-voting member, supporter, subscriber, affiliate, participant, delegate, fellow, advisor, contributor, observer, sponsor, donor, provider, host, public authority participant, or other recognized participant of the Corporation except in accordance with the applicable record, register, admission instrument, participation terms, subscription terms, appointment record, or written authorization.

94.1.4 The Corporation shall not infer a membership structure from informal practice, attendance, public description, sponsorship, donation, technical contribution, public authority participation, use of GCRI Canada materials, access to a repository, attendance at Nexus Universe, participation in a council, involvement in a working group, inclusion in a mailing list, or participation in any program.

94.1.5 Where there is doubt as to whether the Corporation has statutory members, voting members, non-voting members, supporters, subscribers, affiliates, or participants, the Corporation shall apply the most restrictive lawful interpretation until the matter is resolved by the Board, counsel where appropriate, and the official corporate records.


94.2 Statutory Member Structure Where Applicable.

94.2.1 Where the Corporation has statutory members under applicable Canadian law, the Articles, or a lawful governance record, such members shall have only the rights expressly conferred by law, the Articles, this Bylaw, and the official membership register.

94.2.2 A statutory member structure shall be administered in a manner that preserves the Corporation’s nonprofit, non-share, non-distributing, public-benefit, non-executing, public-good technical institution character.

94.2.3 Statutory membership shall not be structured or administered to create private inurement, sponsor control, provider control, donor control, funder control, public authority control, national company control, Project SPV control, investor control, insurer control, lender control, or enterprise stack control over the Corporation.

94.2.4 Statutory members, if any, shall remain subject to the mission lock, public-benefit purpose, non-execution boundary, GCRI / GRF / GRA role separation, public-good stack and enterprise stack separation, public authority boundary, finance boundary, certification boundary, procurement neutrality, provider neutrality, sponsor non-control, data / AI / cyber controls, safeguards, validity-by-record, and correctionability.

94.2.5 Statutory member rights shall be interpreted narrowly where a broader interpretation could affect research independence, evidence integrity, methods integrity, public-good technical asset stewardship, public authority safety, finance-boundary discipline, public-safe publication, or Nexus role separation.


94.3 Memberless Governance Where Applicable.

94.3.1 Where the Corporation is structured without statutory members, governance authority shall reside in the Board of Directors, subject to applicable Canadian law, the Articles, this Bylaw, and any mandatory approvals required by law.

94.3.2 A memberless structure shall not prevent the Corporation from maintaining supporters, subscribers, affiliates, participants, fellows, advisors, councils, committees, working groups, competence cells, contributors, donors, sponsors, providers, hosts, public authority participants, or other non-statutory participation surfaces.

94.3.3 Non-statutory participation in a memberless structure shall not create member rights, voting rights, fiduciary status, governance control, approval rights, veto rights, inspection rights, statutory rights, or authority to bind the Corporation.

94.3.4 A memberless governance structure shall be administered to preserve Board accountability, fiduciary discipline, records discipline, public-benefit purpose, non-execution, role separation, anti-capture, and legal clarity.

94.3.5 Public materials shall not describe supporters, subscribers, affiliates, participants, fellows, advisors, contributors, public authority participants, sponsors, donors, providers, hosts, or partners as “members” where such description would create statutory ambiguity, governance confusion, reliance risk, public authority confusion, finance overclaim, certification implication, or provider-preference implication.


94.4 Board Governance Subject to Law, Articles, and This Bylaw.

94.4.1 The Board shall govern the Corporation subject to applicable Canadian law, the Articles, this Bylaw, and any member approval required by law or the Articles.

94.4.2 The Board’s governance authority shall include responsibility for mission lock, public-benefit purpose, nonprofit character, non-distribution, legal separateness, non-execution, role separation, public-good stack integrity, enterprise stack boundary discipline, research integrity, evidence integrity, methods integrity, public-good technical asset stewardship, data / AI / cyber controls, public authority boundaries, finance boundaries, safeguards, and correctionability.

94.4.3 No membership or participation structure shall diminish the Board’s fiduciary duties or convert non-statutory participants into governance authorities.

94.4.4 Board governance shall not be displaced by councils, committees, working groups, advisory bodies, contributors, subscribers, supporters, sponsors, donors, providers, hosts, public authorities, National Consortium Companies, Project SPVs, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Network, Nexus Standards, Nexus Observatory, Nexus Universe, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, or any other Nexus interface.

94.4.5 Any ambiguity between Board authority and participant influence shall be resolved in favour of lawful Board authority, public-benefit purpose, non-execution, role separation, and validity-by-record.


94.5 No Informal Membership by Participation.

94.5.1 No person shall become a member of the Corporation by informal participation.

94.5.2 Informal participation includes attendance at meetings, receipt of newsletters, participation in consultations, contribution to research, attendance at public authority learning sessions, participation in technical labs, access to controlled materials, involvement in Nexus Universe, participation in a council or working group, contribution to software, provision of data, use of GCRI Canada materials, sponsorship, donation, or public support.

94.5.3 No statement by an officer, director, staff member, advisor, sponsor, donor, provider, public authority participant, host, partner, or participant shall create membership unless authorized by the Corporation’s governing records and entered in the appropriate register.

94.5.4 Where a person is incorrectly described as a member, the Corporation shall correct the description, clarify the person’s actual status, and update applicable records.

94.5.5 Informal membership claims may be restricted, corrected, withdrawn, publicly clarified, or treated as misuse of status.


94.6 No Membership by Donation, Sponsorship, Subscription, Attendance, Contribution, Authorship, Public Authority Participation, Provider Participation, or Technical Access Alone.

94.6.1 A donation, sponsorship, grant, subscription, fee payment, in-kind contribution, underwriting support, cost-recovery payment, or other support shall not create membership.

94.6.2 Attendance at any meeting, council, committee, working group, conference, lab, Academy program, public authority learning session, controlled room, Nexus Universe activity, technical session, or consultation shall not create membership.

94.6.3 Contribution of research, data, evidence, methods, code, software, schemas, models, dashboards, technical baselines, documentation, public comments, peer review, operational context, community knowledge, public authority context, or provider tools shall not create membership.

94.6.4 Authorship, co-authorship, acknowledgment, citation, maintainer status, repository access, dashboard access, data room access, controlled-room access, system access, API access, or technical credentials shall not create membership.

94.6.5 Public authority participation, provider participation, sponsor participation, donor participation, host participation, investor participation, insurer participation, lender participation, National Consortium Company participation, Project SPV participation, or Nexus interface participation shall not create membership.

94.6.6 Membership may arise only through the lawful membership process, record, register, and authority required by this Bylaw and applicable law.


94.7 Distinction Between Statutory Members and Non-Statutory Participants.

94.7.1 The Corporation shall distinguish clearly between statutory members, if any, and non-statutory participants.

94.7.2 Statutory members, if any, are persons admitted or recognized as members under applicable Canadian law, the Articles, this Bylaw, and the official member register.

94.7.3 Non-statutory participants include persons or entities that participate in the Corporation’s activities without statutory member rights.

94.7.4 Non-statutory participants may include supporters, subscribers, affiliates, institutional participants, fellows, advisors, observers, delegates, contributors, technical maintainers, sponsors, donors, providers, hosts, public authorities, universities, laboratories, civil society organizations, media participants, community participants, Indigenous participants, contractors, volunteers, and other participants.

94.7.5 Non-statutory participants shall have only the rights expressly granted by participation terms, subscription terms, contributor terms, access terms, council charters, committee terms, fellowship agreements, advisory letters, contracts, policies, or other lawful records.

94.7.6 Non-statutory participation shall not create voting rights, governance rights, fiduciary authority, inspection rights, approval rights, veto rights, statutory member rights, or authority to bind the Corporation.


94.8 Distinction Between Members, Supporters, Subscribers, Contributors, Fellows, Advisors, Observers, Delegates, Sponsors, Donors, Providers, Hosts, and Public Authorities.

94.8.1 The Corporation shall maintain clear status distinctions among all membership and participation categories.

94.8.2 Members, if any, shall be persons admitted to statutory membership under applicable law and the official member register.

94.8.3 Supporters shall be persons or entities that provide public-good support without statutory member rights or governance control.

94.8.4 Subscribers shall be persons or entities that obtain lawful access, learning, publication, participation, or other approved benefits through subscription terms without governance control.

94.8.5 Contributors shall be persons or entities that contribute research, evidence, data, code, software, schemas, models, documentation, methods, review, or technical input under approved contribution terms.

94.8.6 Fellows and advisors shall be persons appointed or engaged to support research, learning, technical, public-good, safeguards, or advisory work within recorded scope and without automatic governance authority.

94.8.7 Observers and delegates shall participate only within their recorded capacity, authority, access limits, confidentiality duties, and public statement limits.

94.8.8 Sponsors, donors, and funders shall provide lawful support without control, outcome purchase, public authority access purchase, recognition purchase, finance-readiness purchase, certification purchase, procurement advantage, or technical conclusion purchase.

94.8.9 Providers and hosts shall participate under provider-neutrality, procurement-neutrality, data / AI / cyber, conflict, public-safe claims, and anti-capture controls.

94.8.10 Public authorities shall participate only under capacity classification, non-delegation, non-endorsement, public authority boundary, and public-safe reference controls.


94.9 Governance Rights Only by Lawful Record.

94.9.1 Governance rights shall exist only where created by applicable law, the Articles, this Bylaw, a lawful Board resolution, a required member resolution, or another recorded instrument authorized by competent authority.

94.9.2 Governance rights shall not arise by implication, custom, course of dealing, public description, repeated attendance, donation history, sponsorship level, subscription tier, technical centrality, authorship, seniority, public prominence, institutional affiliation, public authority status, provider status, investor status, host status, or Nexus participation.

94.9.3 Any governance right shall identify the holder, legal basis, scope, duration, limits, conditions, conflicts, recusal obligations, access rights, public statement limits, and termination or correction path.

94.9.4 No governance right shall authorize execution of prohibited functions or override mission lock, public-benefit purpose, non-execution, role separation, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, provider neutrality, sponsor non-control, safeguards, data / AI / cyber controls, validity-by-record, or correctionability.

94.9.5 Any purported governance right lacking lawful record shall have no governance effect.


94.10 Membership Structure Records.

94.10.1 The Corporation shall maintain records of its membership or memberless governance structure.

94.10.2 Such records shall include the Articles, this Bylaw, Board resolutions, member resolutions where applicable, legal opinions or counsel notes where appropriate, member registers where applicable, non-voting member registers, supporter registers, subscriber registers, participant registers, admission records, status classification records, rights and limits records, termination records, and correction records.

94.10.3 Membership structure records shall identify whether the Corporation has statutory members, voting members, non-voting members, memberless governance, supporter categories, subscription categories, affiliate categories, or other participation categories.

94.10.4 Records shall identify each category’s rights, duties, access, limits, governance effect, public representation limits, fee treatment, good standing conditions, suspension conditions, termination conditions, and correction path.

94.10.5 The Secretary or another authorized records custodian shall maintain the authoritative membership structure records and shall correct any inconsistency, outdated description, public overclaim, or status ambiguity.


Section 95. Statutory Members, If Any

95.1 Statutory Member Definition.

95.1.1 A statutory member means a person or entity admitted or recognized as a member of the Corporation under applicable Canadian law, the Articles, this Bylaw, and the official member register.

95.1.2 A statutory member shall have only those rights, duties, protections, approval powers, voting powers, notice rights, inspection rights, meeting rights, and other rights that are expressly provided by applicable law, the Articles, this Bylaw, or the lawful membership record.

95.1.3 No person shall be treated as a statutory member unless the Corporation has created or recognized statutory membership through lawful corporate records.

95.1.4 The term “member” shall not be used informally to describe supporters, subscribers, contributors, fellows, advisors, observers, delegates, sponsors, donors, providers, hosts, public authorities, partners, program participants, council participants, working group participants, or technical contributors unless such persons are statutory members.

95.1.5 Where public or internal materials use “member” in a non-statutory sense, the materials shall clarify the non-statutory meaning or be corrected.


95.2 Eligibility for Statutory Membership.

95.2.1 Eligibility for statutory membership shall be determined by applicable law, the Articles, this Bylaw, and Board-approved membership criteria.

95.2.2 Eligibility criteria may include public-benefit alignment, mission alignment, integrity, fit-and-proper review, conflict disclosure, independence review where applicable, sanctions screening, export-control screening where applicable, data / AI / cyber eligibility, confidentiality capacity, public-safe claims discipline, and willingness to comply with this Bylaw.

95.2.3 No person shall be eligible for statutory membership where admission would create unlawful private benefit, sponsor control, provider control, donor control, funder control, public authority control, investor control, insurer control, lender control, National Consortium Company control, Project SPV control, enterprise stack capture, or material mission drift.

95.2.4 The Corporation may establish different classes or categories of statutory membership only where lawful, recorded, and consistent with public-benefit purpose, non-execution, role separation, anti-capture, and records discipline.

95.2.5 Eligibility shall not be based on payment capacity alone, sponsorship level, public prominence, provider status, public authority status, capital status, technical centrality, or ability to confer reputational benefit.


95.3 Admission of Statutory Members.

95.3.1 Admission of statutory members shall occur only through a lawful admission process approved by competent authority.

95.3.2 Admission may require application, eligibility review, conflict disclosure, capacity classification, identity verification, institutional affiliation verification, sanctions review, export-control review, data / AI / cyber review where applicable, public authority boundary review where applicable, sponsor / provider / donor / funder capture review, and written acceptance of this Bylaw and applicable policies.

95.3.3 Admission shall be recorded in the official member register before the admitted person is treated as a statutory member.

95.3.4 Admission may be unconditional, conditional, limited, deferred, refused, or subject to probation where lawful and appropriate.

95.3.5 No officer, committee, council, working group, sponsor, donor, provider, public authority participant, National Consortium Company, Project SPV, or informal leadership group may admit statutory members unless expressly authorized by this Bylaw, the Articles, law, or a Board-approved delegation.


95.4 Rights of Statutory Members.

95.4.1 Statutory members shall have the rights conferred by applicable law, the Articles, this Bylaw, and the official membership record.

95.4.2 Such rights may include notice rights, meeting rights, voting rights, written resolution rights, information rights, approval rights for matters requiring member approval by law, and other rights expressly granted by lawful record.

95.4.3 Member rights shall be exercised in good faith, for the public-benefit purposes of the Corporation, and consistently with mission lock, non-execution, role separation, legal separateness, anti-capture, public authority boundaries, finance boundaries, safeguards, and correctionability.

95.4.4 No statutory member right shall be used to obtain improper private benefit, sponsor benefit, provider benefit, donor benefit, public authority advantage, procurement advantage, finance-readiness advantage, certification advantage, recognition advantage, or technical conclusion advantage.

95.4.5 Member information and access rights shall remain subject to confidentiality, privilege, privacy, data protection, cybersecurity, protected knowledge, public authority sensitivity, finance sensitivity, commercial sensitivity, competition-law discipline, and records controls.


95.5 Duties of Statutory Members.

95.5.1 Statutory members shall comply with applicable law, the Articles, this Bylaw, Board-approved policies, member terms, confidentiality obligations, conflict rules, public-safe claims rules, and records requirements.

95.5.2 Statutory members shall support the Corporation’s public-benefit purpose and shall not act in a manner that undermines nonprofit character, non-distribution, legal separateness, mission lock, non-execution, role separation, evidence integrity, methods integrity, research integrity, data / AI / cyber integrity, public authority boundaries, finance boundaries, provider neutrality, sponsor non-control, safeguards, or correctionability.

95.5.3 Statutory members shall disclose conflicts, related-party interests, sponsor relationships, donor relationships, provider relationships, host relationships, public authority roles, investor relationships, insurer relationships, lender relationships, National Consortium Company relationships, Project SPV relationships, and other interests that could affect their duties or the Corporation’s integrity.

95.5.4 Statutory members shall not misuse GCRI Canada’s name, marks, records, technical assets, public-safe publications, data, software, public-good baselines, reports, dashboards, membership status, or Nexus-compatible claims.

95.5.5 Statutory members shall support correction, clarification, withdrawal, retraction, supersession, and public-safe notice where member conduct or member claims create error, ambiguity, overclaim, reliance risk, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, provider preference, sponsor-control implication, or public-safe harm.


95.6 Voting Rights Where Applicable.

95.6.1 Statutory members shall have voting rights only where such rights are provided by applicable law, the Articles, this Bylaw, or a lawful membership class record.

95.6.2 Voting rights shall be exercised only by members in good standing and only within the scope of matters lawfully submitted to members.

95.6.3 Voting rights shall not be purchased, transferred, assigned, pledged, traded, pooled, sponsored, controlled, aggregated, or exercised under improper influence except as expressly permitted by law and recorded.

95.6.4 A member shall not exercise voting rights where the member is subject to mandatory recusal, conflict restriction, suspension, incapacity, loss of good standing, or other lawful limitation.

95.6.5 Voting records shall identify members entitled to vote, quorum, voting thresholds, abstentions, recusals, conflicts, approvals, dissents where recorded, and final result.


95.7 Member Meetings Where Applicable.

95.7.1 Where statutory member meetings are required or authorized, such meetings shall be convened in accordance with applicable law, the Articles, this Bylaw, and Board-approved procedures.

95.7.2 Member meetings may include annual meetings, special meetings, class meetings, approval meetings, informational meetings, or other lawful member proceedings.

95.7.3 Member meetings shall be conducted with proper notice, agenda discipline, quorum determination, voting controls, conflict management, recordkeeping, confidentiality controls, secure participation, and public-benefit orientation.

95.7.4 Member meetings shall not be used to direct prohibited functions, interfere with research conclusions, control evidence outputs, dictate technical baselines, purchase outcomes, influence public authority access, direct finance-readiness outcomes, or substitute for Board reserved matters except where law requires member approval.

95.7.5 Member meeting records shall be maintained in the corporate records.


95.8 Notice, Quorum, Voting, Written Resolutions, and Electronic Participation Where Applicable.

95.8.1 Notice of member meetings shall be provided in accordance with applicable law, the Articles, this Bylaw, and any approved member procedure.

95.8.2 Notice shall identify the meeting date, time, place or electronic platform, purpose, agenda, matters for decision, voting method, quorum requirement, materials, access instructions, confidentiality requirements, and any special resolution or higher threshold.

95.8.3 Quorum shall be determined in accordance with applicable law, the Articles, this Bylaw, and the relevant membership class record.

95.8.4 Written resolutions may be used where lawful and shall be recorded with the same care as meeting resolutions.

95.8.5 Electronic participation may be permitted where lawful and shall include reasonable identity verification, secure access, voting integrity, record integrity, accessibility, confidentiality, and cyber controls.

95.8.6 Member proceeding records shall identify notice, waiver where applicable, quorum, voting, written resolution, electronic participation, conflicts, recusals, materials reviewed, and final action.


95.9 Member Approval Rights Required by Law.

95.9.1 Statutory members shall have approval rights where required by applicable Canadian law, the Articles, or this Bylaw.

95.9.2 Member approval may be required for matters such as amendments, fundamental changes, continuance, amalgamation, dissolution, sale or transfer of substantially all assets, changes to membership rights, or other matters prescribed by law or the Articles.

95.9.3 The Corporation shall identify member approval requirements before taking action on any matter that may require such approval.

95.9.4 No Board, officer, committee, council, sponsor, donor, provider, public authority participant, or partner shall bypass member approval where lawfully required.

95.9.5 Where member approval is required and not obtained, the relevant action shall not take effect to the extent prohibited by law.


95.10 Limits on Member Authority.

95.10.1 Statutory member authority shall be limited to the authority conferred by applicable law, the Articles, this Bylaw, and the official membership record.

95.10.2 Members shall not exercise Board authority, officer authority, committee authority, executive authority, public authority, finance authority, certification authority, procurement authority, provider-selection authority, research-control authority, evidence-control authority, methods-control authority, or execution authority unless expressly and lawfully granted.

95.10.3 Member approval rights shall not be interpreted as authority to manage day-to-day operations or direct technical, research, public authority, finance, provider, sponsor, or Nexus interface outputs.

95.10.4 Members shall not use their status to obtain preferred access, private benefit, public authority access, provider advantage, finance-readiness influence, certification influence, procurement influence, or recognition influence.

95.10.5 Any member authority overclaim shall be corrected.


95.11 No Member Authority to Execute Prohibited Functions.

95.11.1 No statutory member shall have authority to cause, authorize, direct, ratify, or pressure the Corporation to execute prohibited functions.

95.11.2 Prohibited functions include investment advice, securities offering, capital placement, brokerage, finder activity, lending, guarantee, insurance placement, underwriting, rating, public finance approval, grant approval, procurement approval, vendor selection, certification, public authority decision, emergency command, public warning, regulatory approval, enforcement action, or enterprise execution by the Corporation.

95.11.3 No member vote, member resolution, member request, member pressure, or member custom shall authorize prohibited functions.

95.11.4 If a member action would create regulated-activity risk, public authority confusion, finance overclaim, procurement overclaim, certification overclaim, provider preference, sponsor capture, or execution risk, the Corporation shall hold, quarantine, re-scope, correct, or reject the action as appropriate.

95.11.5 Prohibited-function boundary records shall be maintained.


95.12 No Member Authority to Direct Evidence, Methods, Research Conclusions, Technical Baselines, Publications, Public Authority Access, or Nexus Interface Outputs.

95.12.1 Statutory members shall not direct, control, suppress, purchase, pre-clear, veto, or alter GCRI Canada evidence, methods, research conclusions, technical baselines, public-good software, open technical assets, publications, public-safe reports, dashboards, public authority access, Docket inputs, Grid inputs, GRF inputs, GRA inputs, Nexus Standards inputs, Nexus Observatory inputs, Nexus Rails inputs, or Nexus interface outputs.

95.12.2 Members may provide views, comments, evidence, expertise, objections, challenges, or recommendations through approved channels, but such inputs shall be reviewed according to evidence, methods, conflict, public-safe, and correction procedures.

95.12.3 Member influence shall not override research integrity, evidence quality, methodological independence, public-safe publication review, controlled vocabulary, public authority boundary discipline, finance boundary discipline, safeguards, or correctionability.

95.12.4 Any member attempt to direct or control the Corporation’s technical truth function shall be treated as a conflict, capture, or integrity matter.

95.12.5 Such matters shall be recorded and escalated where material.


95.13 Suspension, Termination, Resignation, and Reinstatement of Statutory Members.

95.13.1 Statutory members may resign in accordance with applicable law, the Articles, this Bylaw, and the member terms.

95.13.2 Statutory members may be suspended or terminated where permitted by law for loss of eligibility, failure to maintain good standing, breach of this Bylaw, non-payment of lawful fees where applicable, conflict non-disclosure, confidentiality breach, data misuse, AI misuse, cyber misconduct, harassment, retaliation, protected knowledge breach, public authority overclaim, finance overclaim, certification overclaim, procurement overclaim, provider-preference claim, sponsor-control conduct, or misuse of GCRI Canada name or materials.

95.13.3 Suspension or termination procedures shall provide notice and response opportunity where required or appropriate, subject to urgent protective measures where immediate risk exists.

95.13.4 Reinstatement may be permitted where lawful, appropriate, and supported by corrective action, renewed eligibility, good standing, conflict resolution, compliance acknowledgment, and Board or delegated approval.

95.13.5 Suspension, termination, resignation, and reinstatement shall be recorded in the applicable register.


95.14 Statutory Member Records.

95.14.1 The Corporation shall maintain statutory member records where statutory members exist.

95.14.2 Statutory member records shall include member identity, admission date, class or category, rights, duties, voting status, good standing, contact information, representative information where applicable, conflict disclosures, acknowledgments, fee status where applicable, suspensions, terminations, resignations, reinstatements, voting records, meeting attendance, written resolutions, and member approval records.

95.14.3 Member records shall be maintained subject to privacy, confidentiality, data protection, access, retention, sealing, deletion, and legal hold requirements.

95.14.4 Member records shall identify restrictions, recusals, capacity limits, public statement limits, and correction obligations where applicable.

95.14.5 The Secretary or another authorized records custodian shall maintain the official member register and correct inaccuracies, outdated entries, duplicate entries, unauthorized entries, or status ambiguities.


Section 96. Voting Members, If Any

96.1 Voting Member Eligibility.

96.1.1 Voting members, if any, shall be statutory members who meet the eligibility requirements for voting rights under applicable law, the Articles, this Bylaw, and the official membership record.

96.1.2 Voting member eligibility shall require good standing, lawful admission, proper registration, compliance with this Bylaw, conflict disclosure, and satisfaction of any class-specific requirements.

96.1.3 A person shall not be eligible to vote where the person’s voting rights are suspended, restricted, terminated, not yet effective, conflicted, subject to recusal, or otherwise limited by law, the Articles, this Bylaw, or Board-approved membership terms.

96.1.4 Voting eligibility shall not be granted to create sponsor control, donor control, provider control, public authority control, funder control, investor control, insurer control, lender control, National Consortium Company control, Project SPV control, or enterprise stack capture.

96.1.5 Voting eligibility records shall be maintained and reviewed before member votes.


96.2 Voting Member Admission.

96.2.1 Admission as a voting member shall require lawful admission as a member and express designation of voting rights in the applicable membership record.

96.2.2 The Corporation shall not infer voting rights from membership status, supporter status, subscription status, sponsorship, donation, public authority participation, provider participation, authorship, technical contribution, attendance, participation, payment, or title.

96.2.3 Voting member admission shall be subject to eligibility review, conflict review, independence review where applicable, influence aggregation review, fit-and-proper review, sanctions screening where applicable, and acknowledgment of this Bylaw.

96.2.4 Voting member admission shall be recorded before voting rights may be exercised.

96.2.5 Any defective or unauthorized voting member admission shall be reviewed, corrected, ratified where lawful, or nullified.


96.3 Voting Member Rights.

96.3.1 Voting members shall have only those voting rights conferred by applicable law, the Articles, this Bylaw, and their membership class record.

96.3.2 Voting rights may include voting on directors, amendments, fundamental changes, member approvals, or other matters lawfully submitted to voting members.

96.3.3 Voting rights shall not include authority to manage operations, direct officers, control research, dictate evidence conclusions, alter methods, approve technical baselines, determine public authority access, determine finance-readiness, select providers, certify technologies, approve procurement, or exercise prohibited functions.

96.3.4 Voting members may receive meeting materials and decision materials as required by law and as appropriate to their rights, subject to confidentiality, privilege, privacy, cybersecurity, public authority sensitivity, finance sensitivity, commercial sensitivity, protected knowledge, and public-safe controls.

96.3.5 Voting rights shall be exercised consistently with public-benefit purpose, mission lock, non-execution, role separation, and anti-capture discipline.


96.4 Voting Member Duties.

96.4.1 Voting members shall exercise their rights in good faith and in a manner consistent with the public-benefit purpose of the Corporation.

96.4.2 Voting members shall comply with this Bylaw, member terms, conflict rules, confidentiality rules, public-safe claims rules, data / AI / cyber rules, safeguards rules, public authority boundary rules, finance boundary rules, certification boundary rules, procurement-neutrality rules, provider-neutrality rules, sponsor non-control rules, and correction obligations.

96.4.3 Voting members shall not vote or act to advance improper private benefit, sponsor control, provider control, donor control, funder control, public authority control, investor control, insurer control, lender control, National Consortium Company control, Project SPV control, or enterprise stack control.

96.4.4 Voting members shall disclose actual, potential, perceived, and structural conflicts before exercising voting rights.

96.4.5 Voting members shall support correction where voting member actions, claims, or conflicts create ambiguity, overclaim, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, provider preference, or governance distortion.


96.5 Voting Member Good Standing.

96.5.1 A voting member must be in good standing to exercise voting rights.

96.5.2 Good standing may require continued eligibility, compliance with this Bylaw, payment of lawful fees where applicable, current conflict disclosures, compliance acknowledgments, confidentiality compliance, data / AI / cyber compliance, public-safe claims compliance, and absence of suspension or termination.

96.5.3 A voting member may lose good standing through breach of duties, misconduct, non-payment where applicable, conflict non-disclosure, misuse of name or status, data misuse, AI misuse, cyber misconduct, public authority overclaim, finance overclaim, certification overclaim, procurement overclaim, provider-preference claim, sponsor-control conduct, harassment, retaliation, or other conduct inconsistent with this Bylaw.

96.5.4 Good standing may be restored where lawful and appropriate after corrective action, payment, disclosure, recusal, training, acknowledgment, probation, or Board-approved reinstatement.

96.5.5 Good standing records shall be maintained.


96.6 Voting Member Conflicts.

96.6.1 Voting members shall disclose conflicts before participating in decisions where their personal, financial, institutional, professional, public authority, sponsor, donor, provider, host, investor, insurer, lender, National Consortium Company, Project SPV, or partner interests may affect or appear to affect the vote.

96.6.2 Conflicts may include financial interests, employment relationships, consulting relationships, governance roles, public authority roles, donor relationships, sponsor relationships, provider relationships, contract interests, procurement interests, investment interests, insurance interests, lending interests, research interests, IP interests, data interests, and public claims interests.

96.6.3 The Corporation may require conflict disclosure, recusal, access restriction, voting restriction, abstention, independent review, or other mitigation.

96.6.4 Voting members shall not use voting rights to influence matters from which they should be recused.

96.6.5 Conflict records shall be maintained.


96.7 Voting Member Recusal.

96.7.1 A voting member shall recuse from any matter where required by law, the Articles, this Bylaw, conflict policy, Board determination, member terms, or the most protective lawful interpretation.

96.7.2 Recusal may require abstention from discussion, abstention from voting, exclusion from materials, exclusion from deliberations, exclusion from controlled rooms, or other access restriction.

96.7.3 Recusal shall be mandatory where a voting member’s interest could materially affect public-benefit purpose, non-execution, role separation, public authority boundary, finance boundary, certification boundary, procurement neutrality, provider neutrality, sponsor non-control, research integrity, evidence integrity, methods integrity, data / AI / cyber integrity, safeguards, or public-safe publication.

96.7.4 Recusal shall not be treated as adverse or punitive where used to preserve institutional integrity.

96.7.5 Recusal records shall identify the matter, member, conflict, restriction, decision authority, and outcome.


96.8 Voting Member Representation and Delegation.

96.8.1 Where an institutional voting member is permitted, it shall designate one or more authorized representatives in accordance with membership terms and applicable law.

96.8.2 Representative authority shall be recorded before the representative participates or votes.

96.8.3 Delegation, proxy, representative substitution, or alternate designation shall be permitted only where lawful and recorded.

96.8.4 A representative shall act within the recorded authority of the voting member and shall remain subject to conflict, confidentiality, public-safe claims, data / AI / cyber, public authority boundary, finance boundary, procurement-neutrality, provider-neutrality, and correction obligations.

96.8.5 No representative shall use institutional voting rights to aggregate influence, conceal conflicts, evade recusal, create sponsor control, create provider control, or purchase outcomes.


96.9 Voting Member Meetings.

96.9.1 Voting member meetings shall be convened and conducted in accordance with applicable law, the Articles, this Bylaw, and approved procedures.

96.9.2 Voting member meetings shall include notice, agenda, quorum, voting procedures, meeting chair, record custodian, conflict process, recusal process, materials control, confidentiality requirements, and voting record.

96.9.3 Voting member meetings may be in person, virtual, hybrid, or by written resolution where lawful.

96.9.4 Voting member meetings shall not be used to direct prohibited functions or override Board authority except where law requires member approval.

96.9.5 Voting member meeting records shall be maintained in the corporate records.


96.10 Voting Member Decision Scope.

96.10.1 Voting member decisions shall be limited to matters lawfully reserved to voting members by applicable law, the Articles, this Bylaw, or Board-approved governance records.

96.10.2 Voting member decisions may include matters requiring member approval by law, such as certain amendments, director elections where applicable, fundamental changes, dissolution, or other statutory matters.

96.10.3 Voting member decision scope shall not include management authority, technical authority, research conclusion authority, evidence conclusion authority, methods authority, publication authority, public authority decision authority, finance-readiness authority, certification authority, procurement authority, provider selection authority, or enterprise execution authority.

96.10.4 Matters outside voting member decision scope shall be ruled out of order, referred to the Board, referred to counsel, re-scoped, or corrected.

96.10.5 Voting member decision records shall identify lawful basis and scope.


96.11 Higher Thresholds Where Required.

96.11.1 Higher voting thresholds shall apply where required by applicable law, the Articles, this Bylaw, membership class terms, or Board-approved governance rules.

96.11.2 Higher thresholds may apply to amendments, fundamental changes, dissolution, continuance, amalgamation, sale or transfer of substantially all assets, changes to membership rights, or other matters requiring special approval.

96.11.3 The Corporation shall identify the applicable voting threshold before member action is taken.

96.11.4 A matter requiring a higher threshold shall not be approved by ordinary majority unless lawful authority expressly permits.

96.11.5 Threshold determination and voting results shall be recorded.


96.12 Voting Rights Not Transferable Except as Lawfully Permitted.

96.12.1 Voting rights shall not be transferred, assigned, pledged, sold, purchased, traded, delegated, syndicated, pooled, sponsored, financed, or otherwise controlled by another person except as expressly permitted by law, the Articles, this Bylaw, and the applicable membership record.

96.12.2 Any proxy, representative designation, alternate appointment, or delegation shall be valid only where lawful, recorded, and consistent with anti-capture controls.

96.12.3 Voting rights shall not be used as consideration for donations, sponsorships, grants, subscriptions, provider contributions, public authority access, investment access, insurance access, lending access, procurement advantage, certification advantage, recognition advantage, or technical conclusion influence.

96.12.4 Any attempted transfer or control of voting rights in violation of this Bylaw may be refused, invalidated, suspended, corrected, or referred for enforcement.

96.12.5 Transfer and proxy records shall be maintained.


96.13 No Vote Purchase, Vote Trading, Sponsored Vote, Proxy Capture, or Influence Aggregation.

96.13.1 No person shall purchase, sell, trade, condition, sponsor, bundle, aggregate, proxy-control, or otherwise manipulate voting rights.

96.13.2 Prohibited conduct includes vote buying, vote trading, sponsored votes, donor-directed votes, provider-directed votes, sponsor-directed votes, funder-directed votes, public authority-directed votes, investor-directed votes, lender-directed votes, insurer-directed votes, National Consortium Company-directed votes, Project SPV-directed votes, and coordinated influence arrangements.

96.13.3 The Corporation shall review related persons, affiliates, controlled entities, sponsored seats, institutional representatives, coordinated participants, and funding arrangements for influence aggregation risk.

96.13.4 Where vote capture risk exists, the Corporation may impose disclosure, recusal, voting restriction, access restriction, suspension, termination, refusal of admission, or other lawful mitigation.

96.13.5 Vote purchase, proxy capture, and influence aggregation records shall be maintained.


96.14 Voting Member Records.

96.14.1 The Corporation shall maintain voting member records where voting members exist.

96.14.2 Voting member records shall include identity, class, admission date, voting status, good standing, representative authority, proxy authority where applicable, conflicts, recusals, suspensions, terminations, reinstatements, meeting attendance, votes cast, written resolutions, approvals, dissents where recorded, and threshold determinations.

96.14.3 Voting records shall identify notice, quorum, agenda, decision question, legal basis, materials reviewed, conflict disclosures, recusals, abstentions, voting threshold, result, effective date, and required follow-up.

96.14.4 Voting member records shall be maintained subject to privacy, confidentiality, privilege, security, access, retention, sealing, deletion, and legal hold requirements.

96.14.5 The Secretary or another authorized records custodian shall maintain and correct voting member records.


Section 97. Non-Voting Members, Supporters, Affiliates, and Institutional Participants

97.1 Non-Voting Membership.

97.1.1 The Corporation may establish non-voting membership categories where lawful, Board-approved, public-benefit aligned, and consistent with the Articles and this Bylaw.

97.1.2 Non-voting members shall not have voting rights unless voting rights are separately and lawfully granted.

97.1.3 Non-voting membership may be used to support public-good participation, research engagement, evidence literacy, technical learning, community engagement, public authority learning, Academy participation, public-good software support, or institutional alignment without creating governance control.

97.1.4 Non-voting members shall be subject to eligibility, admission, good standing, conflict, confidentiality, public-safe claims, data / AI / cyber, public authority boundary, finance boundary, certification boundary, procurement-neutrality, provider-neutrality, sponsor non-control, safeguards, and correction rules.

97.1.5 Non-voting membership shall not imply recognition, certification, professional credential, finance-readiness, procurement advantage, public authority endorsement, provider preference, or Nexus-compatible status.


97.2 Supporter Categories.

97.2.1 The Corporation may establish supporter categories to permit individuals, institutions, communities, universities, laboratories, public-interest organizations, enterprises, public authorities, donors, sponsors, funders, and other lawful supporters to support the Corporation’s public-benefit work without governance control.

97.2.2 Supporter categories may include individual supporters, institutional supporters, public-good supporters, research supporters, technical supporters, community supporters, Academy supporters, open-source supporters, public authority learning supporters, and infrastructure supporters.

97.2.3 Supporter status shall not confer voting rights, fiduciary authority, Board authority, officer authority, certification authority, public authority status, finance-readiness authority, procurement influence, provider preference, recognition status, or authority to bind the Corporation.

97.2.4 Supporter benefits, if any, shall be recorded and may include access to public materials, public-safe briefings, learning opportunities, acknowledgments, invitations, newsletters, or other non-controlling benefits.

97.2.5 Supporter categories shall be administered under support-without-control discipline.


97.3 Affiliate Categories.

97.3.1 The Corporation may establish affiliate categories for institutions, networks, laboratories, academic bodies, community bodies, public-interest organizations, public authorities, technical groups, and other lawful participants that maintain a structured relationship with the Corporation without statutory membership or governance control.

97.3.2 Affiliate status may support research collaboration, evidence exchange, methods review, technical interoperability, public-good software contribution, Academy participation, Observatory methods support, public authority learning, or safeguards alignment.

97.3.3 Affiliate status shall not create branch status, agency, partnership, joint venture, parent-subsidiary relationship, shared treasury, shared liability, shared employer status, public authority delegation, certification, recognition, procurement advantage, finance-readiness, or provider preference.

97.3.4 Affiliate status shall be governed by written terms identifying purpose, scope, authority limits, public references, data access, IP, confidentiality, conflicts, public-safe claims, and correction.

97.3.5 Affiliate records shall be maintained.


97.4 Institutional Participant Categories.

97.4.1 The Corporation may establish institutional participant categories for universities, laboratories, public authorities, civil society organizations, media organizations, community bodies, Indigenous organizations, providers, sponsors, donors, funders, hosts, National Consortium Companies, Project SPVs, and other institutions.

97.4.2 Institutional participant status shall be classified by purpose, capacity, role, rights, access, duties, limitations, public reference rules, data rights, conflict status, and correction path.

97.4.3 Institutional participants may contribute expertise, evidence, data, facilities, tools, field learning, community context, technical comments, public authority context, funding, or other lawful support.

97.4.4 Institutional participation shall not create statutory membership, voting rights, governance control, public authority delegation, procurement advantage, finance-readiness, certification, recognition, provider preference, or execution authority.

97.4.5 Institutional participant records shall be maintained.


97.5 Research Network Participation.

97.5.1 The Corporation may permit research network participation to support public-benefit R&D, evidence development, methods review, reproducibility, peer review, technical baselines, observability methods, ontology development, public-good software, and public-safe publication.

97.5.2 Research network participants may include researchers, universities, laboratories, students, fellows, visiting scholars, technical experts, public authorities, community representatives, Indigenous knowledge holders, civil society actors, providers, and other contributors where appropriate.

97.5.3 Research network participation shall be subject to research integrity, ethics, human-subjects review where applicable, community safeguards, Indigenous / local / territorial knowledge safeguards, protected knowledge controls, sponsor and provider influence controls, data / AI / cyber rules, confidentiality, IP, publication review, and correctionability.

97.5.4 Research network participation shall not create authority to direct research conclusions or publications.

97.5.5 Research network records shall be maintained.


97.6 Technical Contributor Participation.

97.6.1 The Corporation may permit technical contributor participation to support public-good software, open technical baselines, schemas, APIs, SDKs, dashboards, data dictionaries, ontologies, test harnesses, model cards, system cards, benchmark cards, secure release practices, and technical documentation.

97.6.2 Technical contributors may include developers, maintainers, researchers, engineers, data scientists, cybersecurity experts, AI specialists, public authority technical staff, provider personnel, academic personnel, community technologists, and other qualified contributors.

97.6.3 Technical contributor participation shall be governed by contributor terms, IP terms, licensing terms, moral rights treatment where applicable, confidentiality, repository access controls, code review, dependency review, vulnerability disclosure, AI-use rules, data rights, export-control screening where applicable, and conflict disclosure.

97.6.4 Technical contribution shall not confer membership, governance authority, maintainer authority beyond recorded scope, certification authority, provider preference, public authority status, finance-readiness authority, procurement advantage, or authority to alter institutional meaning.

97.6.5 Technical contributor records shall be maintained.


97.7 Public-Good Supporter Participation.

97.7.1 Public-good supporters may participate in the Corporation’s mission by supporting research, evidence infrastructure, methods development, observability, ontology, public-good software, open technical baselines, Academy programs, community safeguards, public authority learning, publications, or other public-benefit activities.

97.7.2 Public-good supporter participation may include attendance, feedback, funding, in-kind support, translation support, accessibility support, open-source maintenance support, technical review, community input, and public-safe dissemination.

97.7.3 Public-good supporter participation shall not create control, governance rights, public authority status, certification, recognition, finance-readiness, procurement advantage, provider preference, or execution authority.

97.7.4 Supporter participation shall be subject to public-safe claims rules and name-use discipline.

97.7.5 Public-good supporter records shall be maintained where material.


97.8 Rights of Non-Voting Members and Supporters.

97.8.1 Non-voting members and supporters shall have only those rights expressly provided by law, the Articles, this Bylaw, membership terms, supporter terms, subscription terms, participation terms, or another lawful record.

97.8.2 Such rights may include access to public materials, newsletters, learning opportunities, public-safe briefings, events, consultations, Academy offerings, open-source participation, or controlled materials where specifically authorized.

97.8.3 Rights may be limited by classification, eligibility, payment status where applicable, confidentiality, data / AI / cyber controls, public authority boundaries, finance boundaries, competition-law discipline, safeguards, public-safe status, and security requirements.

97.8.4 No right of non-voting members or supporters shall include governance control, voting rights, approval rights, veto rights, fiduciary authority, public authority authority, certification authority, finance-readiness authority, procurement authority, provider-selection authority, or execution authority.

97.8.5 Rights shall be revocable, suspendable, or terminable in accordance with applicable terms and this Bylaw.


97.9 Duties of Non-Voting Members and Supporters.

97.9.1 Non-voting members and supporters shall comply with this Bylaw, applicable terms, confidentiality obligations, data / AI / cyber rules, public-safe claims rules, name-use rules, conflict disclosure rules, public authority boundary rules, finance boundary rules, certification boundary rules, procurement-neutrality rules, provider-neutrality rules, sponsor non-control rules, safeguards rules, and correction obligations.

97.9.2 Non-voting members and supporters shall not misrepresent their status, claim governance authority, imply endorsement, imply public authority approval, imply certification, imply finance-readiness, imply procurement advantage, imply recognition, imply provider preference, or imply that support purchases influence.

97.9.3 Non-voting members and supporters shall not misuse GCRI Canada’s name, marks, materials, publications, data, technical assets, software, reports, dashboards, records, or Nexus-compatible language.

97.9.4 Non-voting members and supporters shall disclose conflicts where their participation, funding, contribution, affiliation, or public claims could create ambiguity or risk.

97.9.5 Duties may be enforced by correction, access restriction, suspension, termination, refusal, public clarification, or legal response where appropriate.


97.10 No Governance Control.

97.10.1 Non-voting members, supporters, affiliates, institutional participants, subscribers, contributors, fellows, advisors, observers, delegates, sponsors, donors, providers, hosts, public authorities, and other non-statutory participants shall not have governance control by virtue of such status.

97.10.2 Governance control includes authority to direct the Board, officers, committees, councils, research agenda, evidence conclusions, methods, technical baselines, publications, public authority access, finance-readiness inputs, Docket inputs, Grid inputs, GRF inputs, GRA inputs, Nexus Standards inputs, public-good software, records, or corrections.

97.10.3 Participation, support, contribution, funding, public authority status, provider status, host status, technical centrality, or public prominence shall not create governance control.

97.10.4 Any governance-control implication shall be corrected.


97.11 No Fiduciary Authority.

97.11.1 Non-voting members, supporters, affiliates, institutional participants, subscribers, contributors, fellows, advisors, observers, delegates, sponsors, donors, providers, hosts, public authorities, and other non-statutory participants shall not have fiduciary authority unless separately and lawfully appointed as directors or officers.

97.11.2 Advisory, technical, contributor, supporter, or participant status shall not create fiduciary office.

97.11.3 Non-statutory participants shall not act as directors, officers, trustees, governors, managers, agents, or fiduciaries of the Corporation by implication.

97.11.4 Any person with a dual role shall act only within the authority of the role being performed and shall comply with conflict and capacity classification requirements.

97.11.5 Fiduciary-authority overclaims shall be corrected.


97.12 No Authority to Bind GCRI Canada.

97.12.1 Non-voting members, supporters, affiliates, institutional participants, subscribers, contributors, fellows, advisors, observers, delegates, sponsors, donors, providers, hosts, public authorities, and other non-statutory participants shall have no authority to bind GCRI Canada unless expressly authorized by a lawful written delegation.

97.12.2 No authority to bind shall arise from participation, attendance, contribution, authorship, technical access, repository access, public authority role, sponsorship, donation, subscription, institutional affiliation, title, seniority, public prominence, or proximity to GCRI Canada leadership.

97.12.3 Unauthorized commitments, statements, representations, contracts, public claims, public authority references, finance-readiness references, certification references, procurement references, or Nexus-compatible claims shall not bind GCRI Canada.

97.12.4 The Corporation may correct, reject, disavow, withdraw, or take legal action in relation to unauthorized binding claims.

97.12.5 Authority records shall be maintained.


97.13 No Public Representation Authority Without Delegation.

97.13.1 Non-voting members, supporters, affiliates, institutional participants, subscribers, contributors, fellows, advisors, observers, delegates, sponsors, donors, providers, hosts, public authorities, and other non-statutory participants shall not speak for GCRI Canada unless expressly authorized.

97.13.2 Public representation includes public statements, media comments, social media posts, websites, marketing materials, investor materials, procurement materials, public authority materials, reports, decks, speeches, event materials, technical claims, finance-readiness references, certification references, recognition claims, provider claims, and Nexus-compatible claims.

97.13.3 Any authorized public representation shall be limited to approved language, scope, duration, and context.

97.13.4 Public representation authority may be revoked, restricted, corrected, or terminated where misuse, overclaim, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, provider preference, sponsor-control implication, or public-safe risk exists.

97.13.5 Public representation records shall be maintained.


97.14 Non-Voting Member, Supporter, Affiliate, and Institutional Participant Records.

97.14.1 The Corporation shall maintain records for non-voting members, supporters, affiliates, and institutional participants where such categories are established or where participation is material.

97.14.2 Records shall include identity, category, admission or participation date, eligibility review, participation terms, rights, duties, access class, publication class, confidentiality status, conflict disclosures, fee status where applicable, public reference permissions, data access, AI-use permissions, cyber access, public authority capacity, finance-boundary status, provider status, sponsor status, host status, good standing, suspension, termination, reinstatement, and correction history.

97.14.3 Records shall identify whether the participant has no voting rights, no governance control, no fiduciary authority, no authority to bind, and no public representation authority except as recorded.

97.14.4 Records shall be maintained subject to privacy, confidentiality, security, retention, deletion, sealing, access, and legal hold requirements.

97.14.5 The Secretary or another authorized custodian shall maintain and correct such records.


Section 98. Individual Subscriptions

98.1 Individual Subscription Purpose.

98.1.1 The Corporation may establish individual subscriptions to support public-benefit learning, evidence literacy, methods literacy, research engagement, public-good software participation, public-safe publication access, Academy participation, public authority literacy, data / AI / cyber literacy, community safeguards literacy, and Nexus-compatible public-good formation.

98.1.2 Individual subscriptions shall be designed as access, learning, participation, and public-good support mechanisms, not as governance-control mechanisms.

98.1.3 Individual subscription revenues shall be used consistently with the Corporation’s nonprofit, non-share, non-distributing, public-benefit, non-executing, public-good technical institution character.

98.1.4 Subscription design shall avoid private inurement, improper private benefit, pay-to-play, sponsor control, provider preference, certification implication, public authority confusion, finance-readiness implication, procurement implication, and recognition implication.

98.1.5 Individual subscription terms shall identify benefits, limits, access classes, fees, cancellation rights, refund rules, public statement limits, data rules, and correction obligations.


98.2 Eligibility for Individual Subscriptions.

98.2.1 Individuals may be eligible for subscription where they meet the Corporation’s applicable eligibility criteria and agree to the subscription terms.

98.2.2 Eligibility may be open to researchers, students, professionals, public-interest participants, technologists, community participants, public authority learners, civil society participants, media participants, developers, fellows, advisors, and other persons aligned with the Corporation’s public-benefit purpose.

98.2.3 Eligibility may be limited, conditioned, refused, or revoked where necessary to protect safety, confidentiality, data, AI, cybersecurity, controlled materials, public authority boundaries, competition-law discipline, safeguards, protected knowledge, public-safe claims, or institutional integrity.

98.2.4 The Corporation may require identity verification, conflict disclosure, affiliation disclosure, sanctions screening where appropriate, export-control screening where appropriate, and acknowledgment of public-safe claims rules before granting certain subscription benefits.

98.2.5 Subscription eligibility shall not be used to create discrimination, exclusion, retaliation, or improper preference inconsistent with the Corporation’s public-benefit purpose and applicable law.


98.3 Individual Subscriber Rights.

98.3.1 Individual subscribers shall have only those rights expressly provided by subscription terms, this Bylaw, applicable policies, or another lawful record.

98.3.2 Subscriber rights may include access to public materials, public-safe reports, newsletters, learning sessions, Academy offerings, public events, public-good software materials, open technical baseline materials, public-safe summaries, community briefings, or other approved benefits.

98.3.3 Subscriber rights may include limited participation opportunities in consultations, public events, working sessions, technical discussions, public-good learning rooms, or open contribution pathways where authorized.

98.3.4 Subscriber rights shall be subject to classification, eligibility, payment status where applicable, access controls, public-safe review, confidentiality, data / AI / cyber controls, public authority boundaries, finance boundaries, safeguards, and correction rules.

98.3.5 Subscriber rights shall not include statutory membership, voting rights, governance authority, fiduciary status, Board authority, officer authority, public authority status, certification, credential, recognition, finance-readiness, procurement advantage, provider preference, or authority to bind the Corporation.


98.4 Individual Subscriber Duties.

98.4.1 Individual subscribers shall comply with subscription terms, this Bylaw, public-safe claims rules, confidentiality obligations, access rules, data / AI / cyber rules, intellectual property rules, public authority boundary rules, finance boundary rules, certification boundary rules, procurement-neutrality rules, provider-neutrality rules, safeguards, and correction obligations.

98.4.2 Individual subscribers shall not misuse subscription status, public materials, controlled materials, technical assets, software, datasets, reports, dashboards, name, marks, or Nexus-compatible language.

98.4.3 Individual subscribers shall not claim to speak for GCRI Canada, represent GCRI Canada, bind GCRI Canada, approve GCRI Canada outputs, certify technologies, approve providers, imply public authority endorsement, imply finance-readiness, imply procurement advantage, or imply recognition.

98.4.4 Individual subscribers shall protect credentials, access links, documents, controlled materials, and non-public information.

98.4.5 Individual subscribers shall report errors, misuse, public-safe concerns, data issues, AI issues, cyber issues, public authority overclaims, finance overclaims, certification overclaims, procurement overclaims, or provider-preference claims where discovered.


98.5 Subscription Fees.

98.5.1 The Corporation may charge subscription fees approved by the Board or under Board-approved delegated authority.

98.5.2 Subscription fees shall be reasonable, recorded, accounted for, invoiced or receipted as appropriate, and treated in accordance with applicable tax and nonprofit requirements.

98.5.3 Subscription fees may vary by access class, program class, public-interest category, student status, community status, scholarship status, hardship status, institutional support, geography, or other lawful and public-benefit aligned criteria.

98.5.4 A subscription fee shall not purchase governance control, voting rights, certification, professional credential, recognition, finance-readiness, procurement advantage, provider preference, public authority access, technical conclusion, or publication outcome.

98.5.5 Fee waivers, scholarships, sponsored seats, public-interest seats, reduced-fee seats, refunds, and cancellations shall be administered under recorded rules.


98.6 Access Benefits.

98.6.1 Individual subscribers may receive access benefits approved by the Corporation.

98.6.2 Access benefits may include public materials, publications, public-safe summaries, newsletters, briefings, events, Academy content, learning rooms, public-good software materials, open technical baselines, public datasets, open repositories, or other public-benefit materials.

98.6.3 Access to controlled materials shall require additional authorization, classification review, confidentiality acknowledgment, data / AI / cyber review where applicable, and access records.

98.6.4 Access benefits shall not include unrestricted access to confidential, privileged, personal, public authority-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, community-protected, Indigenous / local / territorial knowledge, protected knowledge, or controlled-room materials.

98.6.5 Access may be restricted, suspended, revoked, or corrected where misuse, security risk, confidentiality breach, public-safe risk, or status misrepresentation occurs.


98.7 Learning Benefits.

98.7.1 Individual subscribers may receive learning benefits related to evidence literacy, methods literacy, research integrity, observability literacy, ontology and controlled vocabulary, public-good software, open technical baselines, data governance, AI governance, cybersecurity, public authority literacy, public-safe publication, safeguards, and Nexus architecture.

98.7.2 Learning benefits may include webinars, courses, briefings, reading rooms, workshops, public-safe exercises, Academy sessions, technical explainers, method notes, public-good software walkthroughs, or other educational materials.

98.7.3 Learning benefits shall not constitute professional certification, regulated credential, legal advice, engineering advice, clinical advice, investment advice, insurance advice, accounting advice, rating opinion, public authority qualification, procurement qualification, or provider approval.

98.7.4 Learning records may document attendance or completion but shall not be marketed as professional license, certification, public authority qualification, finance-readiness status, procurement status, or provider recognition.

98.7.5 Learning materials shall include appropriate limitation and non-reliance language.


98.8 Publication Access.

98.8.1 Individual subscribers may receive access to publications, public-safe reports, research summaries, methods notes, technical notes, public-good software release notes, open baseline materials, public dashboards, public-safe maps, newsletters, and other publication classes approved for subscriber access.

98.8.2 Publication access shall be subject to publication class, access class, redaction, embargo, public-safe review, data protection, public authority boundary controls, finance-boundary controls, cybersecurity controls, infrastructure sensitivity controls, commercial sensitivity controls, and protected knowledge safeguards.

98.8.3 Subscriber access to a publication shall not create endorsement of the subscriber, recognition of the subscriber, certification of the subscriber, provider preference, public authority status, finance-readiness, procurement advantage, or right to redistribute controlled materials.

98.8.4 Publications accessed by subscribers shall remain subject to correction, supersession, withdrawal, retraction, archive status, and limitation language.

98.8.5 Subscribers shall not remove disclaimers, limitations, version identifiers, public-safe notices, correction notices, or attribution requirements.


98.9 Public-Good Participation Opportunities.

98.9.1 Individual subscribers may be offered public-good participation opportunities where approved by the Corporation.

98.9.2 Participation opportunities may include consultations, public comments, open-source contributions, technical review sessions, community learning sessions, Academy programs, public-good working sessions, public-safe feedback, evidence-literacy programs, or volunteer opportunities.

98.9.3 Participation opportunities shall be governed by eligibility, scope, confidentiality, IP, data / AI / cyber, conflict, public authority boundary, finance boundary, public-safe claims, safeguards, and correction rules.

98.9.4 Participation shall not create membership, voting rights, governance control, fiduciary authority, authority to bind, public representation authority, certification, recognition, finance-readiness, procurement advantage, provider preference, or public authority status.

98.9.5 Participation records shall be maintained where material.


98.10 No Governance Control by Subscription.

98.10.1 Individual subscription shall not confer governance control.

98.10.2 Subscribers shall not have authority to direct the Board, officers, committees, councils, research agenda, evidence conclusions, methods, technical baselines, software releases, publications, public authority access, Docket inputs, Grid inputs, GRF inputs, GRA inputs, Nexus Standards inputs, or corrections.

98.10.3 Subscription tiers, fees, renewal history, public prominence, professional expertise, technical contribution, public authority role, provider role, sponsor relationship, donor relationship, or host relationship shall not create governance influence.

98.10.4 Subscriber feedback may be received through approved channels but shall be treated as input only.

98.10.5 Governance-control overclaims by subscribers shall be corrected.


98.11 No Certification, Credential, Recognition, or Professional Status by Subscription.

98.11.1 Individual subscription shall not confer certification, credential, recognition, accreditation, professional status, regulated qualification, public authority qualification, technical qualification, provider qualification, finance-readiness status, procurement status, GRF recognition, Grid maturity, Docket status, or Nexus-compatible status.

98.11.2 Attendance at subscriber learning sessions, access to materials, completion of modules, participation in events, or contribution to public-good activities shall not create professional certification or regulated credential by default.

98.11.3 No subscriber shall represent subscription status as evidence of endorsement, certification, recognition, professional qualification, public authority approval, procurement qualification, finance-readiness, insurance-readiness, provider preference, or Nexus-compatible status.

98.11.4 Any badge, attendance record, completion record, or access record issued to a subscriber shall include scope and limitation language.

98.11.5 Certification, credential, recognition, or professional-status overclaims shall be corrected.


98.12 No Authority to Speak for GCRI Canada.

98.12.1 Individual subscribers shall not speak for GCRI Canada unless expressly authorized by a lawful written delegation.

98.12.2 Subscription status shall not authorize a subscriber to issue statements, comments, media responses, public authority communications, investor communications, procurement communications, provider claims, sponsor claims, technical claims, public-safe reports, or Nexus-compatible claims on behalf of GCRI Canada.

98.12.3 Subscribers may describe their subscription status only in approved factual terms and shall not imply employment, agency, advisory appointment, fellowship, membership, certification, public authority status, recognition, provider preference, or endorsement.

98.12.4 Unauthorized public statements may result in correction, takedown request, suspension, termination, public clarification, or legal response.

98.12.5 Public statement and name-use records shall be maintained where material.


98.13 Suspension, Cancellation, Refund, and Termination.

98.13.1 The Corporation may suspend, cancel, restrict, or terminate an individual subscription in accordance with subscription terms, this Bylaw, and applicable law.

98.13.2 Grounds may include non-payment, misuse of status, breach of confidentiality, unauthorized redistribution, misuse of materials, harassment, retaliation, data misuse, AI misuse, cyber misconduct, protected knowledge breach, public authority overclaim, finance overclaim, certification overclaim, procurement overclaim, provider-preference claim, public-safe claims violation, sanctions concern, export-control concern, or conduct inconsistent with public-benefit purpose.

98.13.3 The Corporation may impose interim access restrictions where necessary to protect data, systems, public authority materials, controlled materials, community safeguards, protected knowledge, cybersecurity, or public-safe publication.

98.13.4 Refunds shall be handled in accordance with approved refund rules, tax treatment, and accounting controls.

98.13.5 Suspension, cancellation, refund, termination, and reinstatement records shall be maintained.


98.14 Individual Subscription Records.

98.14.1 The Corporation shall maintain records for individual subscriptions.

98.14.2 Individual subscription records shall include subscriber identity, contact information, subscription category, start date, renewal date, fee status, access benefits, learning benefits, participation opportunities, accepted terms, confidentiality acknowledgments, data / AI / cyber permissions, public statement limits, access logs where appropriate, suspension, cancellation, refund, termination, reinstatement, and correction records.

98.14.3 Subscription records shall be maintained subject to privacy, confidentiality, cybersecurity, retention, deletion, sealing, legal hold, and access controls.

98.14.4 Subscription records shall identify that subscription does not confer membership, voting rights, governance control, fiduciary authority, certification, credential, recognition, public authority status, finance-readiness, procurement advantage, provider preference, or authority to bind GCRI Canada.

98.14.5 The Secretary or another authorized records custodian shall maintain and correct subscription records.

Section 99. Institutional Subscriptions

99.1 Institutional Subscription Purpose.

99.1.1 The Corporation may establish institutional subscriptions to enable lawful institutions to support, access, and participate in the public-benefit work of GCRI Canada, including research, evidence literacy, methods literacy, observability literacy, ontology and controlled vocabulary alignment, public-good software awareness, open technical baseline learning, Academy programs, public authority learning, technical briefings, public-safe publications, and Nexus-compatible public-good formation.

99.1.2 Institutional subscriptions shall be structured as public-benefit access, learning, participation, and support mechanisms only, and shall not constitute statutory membership, voting membership, governance control, certification, recognition, procurement advantage, finance-readiness status, public authority endorsement, provider preference, or authority to bind the Corporation.

99.1.3 Institutional subscriptions may support the Corporation’s financial sustainability, public-good technical infrastructure, research continuity, training programs, public authority learning surfaces, public-safe publication capacity, data / AI / cyber controls, community safeguards, and open technical baseline stewardship, provided that all such support remains subject to support-without-control discipline.

99.1.4 Institutional subscription design shall preserve the Corporation’s nonprofit, non-share, non-distributing, non-charitable unless lawfully changed, public-benefit, non-executing, public-good technical institution character.

99.1.5 No subscription category, tier, package, benefit schedule, public acknowledgment, controlled-material access, training seat, preview window, briefing, or participation opportunity shall be designed or interpreted to permit the purchase of influence over research, methods, evidence, publications, public authority access, technical baselines, software releases, Docket inputs, Grid inputs, GRF inputs, GRA inputs, Nexus Standards inputs, or any other Nexus interface output.


99.2 Eligibility for Institutional Subscriptions.

99.2.1 Institutional subscription eligibility shall be determined by the Board or by delegated authority under Board-approved subscription criteria.

99.2.2 Eligible institutional subscribers may include universities, research institutions, laboratories, public-interest organizations, civil society organizations, media organizations, professional associations, public authorities, public institutions, Indigenous or community institutions, philanthropic organizations, enterprises, providers, hosts, sponsors, donors, funders, and other institutions whose participation is lawful and consistent with the Corporation’s public-benefit purpose.

99.2.3 Eligibility may be conditioned on public-benefit alignment, lawful status, institutional integrity, conflict disclosure, sanctions screening, export-control screening where applicable, controlled-technology review where applicable, public authority capacity classification where applicable, data / AI / cyber eligibility where applicable, confidentiality capacity, public-safe claims discipline, and agreement to institutional subscription terms.

99.2.4 The Corporation may refuse, defer, limit, condition, suspend, or terminate institutional subscription eligibility where participation could create legal risk, reputational risk, sponsor capture, provider capture, public authority confusion, finance overclaim, certification overclaim, procurement overclaim, competition-law concern, data risk, AI risk, cybersecurity risk, protected knowledge risk, community harm risk, or mission drift.

99.2.5 No institution shall be eligible for subscription where the purpose or effect of the subscription would be to purchase governance influence, public authority access, research outcomes, evidence conclusions, methods changes, publication conclusions, technical baseline direction, provider preference, finance-readiness implication, certification implication, procurement advantage, recognition implication, or Nexus-compatible status.


99.3 Institutional Subscriber Representatives.

99.3.1 Each institutional subscriber shall designate one or more authorized representatives for subscription administration, access, learning participation, controlled-material requests, public-safe communications, and other permitted purposes.

99.3.2 Representative designation shall be recorded before the representative receives access to non-public subscription benefits, controlled materials, restricted learning sessions, public authority learning rooms, data rooms, technical rooms, or other participation surfaces requiring identification.

99.3.3 Institutional subscriber representatives shall act only within their recorded representative capacity and shall not be treated as directors, officers, statutory members, voting members, fiduciaries, agents, delegates, spokespersons, certification reviewers, finance-readiness readers, public authority delegates, provider-selection officials, or representatives of GCRI Canada.

99.3.4 Representatives shall comply with all subscription terms, confidentiality obligations, data / AI / cyber controls, access restrictions, public-safe claims discipline, public authority reference rules, finance boundary rules, certification boundary rules, procurement-neutrality rules, provider-neutrality rules, sponsor non-control rules, safeguards obligations, and correction duties.

99.3.5 The Corporation may require replacement, restriction, suspension, removal, or reclassification of an institutional subscriber representative where the representative presents conflict risk, misconduct risk, public authority ambiguity, finance-boundary risk, data risk, AI risk, cyber risk, protected knowledge risk, public-safe claims risk, or anti-capture concern.


99.4 Institutional Subscriber Access Rights.

99.4.1 Institutional subscriber access rights shall be limited to those expressly stated in the subscription terms, benefit schedule, access record, controlled-room admission record, publication class, or other lawful authorization.

99.4.2 Institutional subscriber access rights may include access to public publications, public-safe summaries, learning materials, briefings, Academy sessions, public-good software materials, open technical baseline materials, technical explainers, public-safe dashboards, public events, controlled briefings, or other subscription benefits approved by the Corporation.

99.4.3 Access rights may be differentiated by subscription class, institutional purpose, public-benefit alignment, lawful need, risk class, data class, public authority capacity, controlled-room eligibility, and security review.

99.4.4 Institutional subscriber access rights shall not include unrestricted access to confidential, privileged, personal, public authority-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, Indigenous / local / territorial knowledge, community-protected, protected knowledge, no-download, controlled-room, evidence-room, or data-room materials unless separately authorized and recorded.

99.4.5 Access rights shall not create any right to use GCRI Canada outputs for certification, procurement approval, finance-readiness determination, investment solicitation, insurance placement, public authority endorsement, provider preference, recognition claim, or Nexus-compatible claim except as expressly permitted by approved public-safe language and authoritative records.


99.5 Institutional Subscriber Duties.

99.5.1 Institutional subscribers shall comply with the Articles, this Bylaw, subscription terms, applicable policies, access rules, confidentiality obligations, data / AI / cyber controls, public-safe publication rules, public authority boundary rules, finance boundary rules, certification boundary rules, procurement-neutrality rules, provider-neutrality rules, sponsor non-control rules, competition-law discipline, safeguards obligations, controlled vocabulary, and correctionability.

99.5.2 Institutional subscribers shall not misrepresent subscription status as membership, governance authority, Board relationship, GCRI Canada endorsement, public authority approval, certification, accreditation, recognition, finance-readiness, insurance-readiness, investment suitability, bankability, procurement advantage, provider preference, official partnership, joint venture, agency, or Nexus-wide approval.

99.5.3 Institutional subscribers shall not use subscription access to obtain non-public advantage, competitive advantage, procurement advantage, public authority access, funder access, investor access, technical conclusion influence, research influence, publication influence, or preferential access to GCRI Canada decision-makers outside recorded and lawful participation pathways.

99.5.4 Institutional subscribers shall ensure that their representatives, employees, contractors, agents, affiliates, sponsored seats, invited participants, and downstream users comply with applicable access restrictions, confidentiality requirements, public claims limits, and correction obligations.

99.5.5 Institutional subscribers shall promptly notify the Corporation of unauthorized access, misuse of materials, public overclaim, inaccurate public reference, data incident, AI incident, cyber incident, protected knowledge issue, public authority misdescription, finance overclaim, certification overclaim, procurement overclaim, provider-preference claim, or sponsor-control implication arising from their subscription.


99.6 Institutional Subscription Fees.

99.6.1 Institutional subscription fees shall be approved by the Board or by delegated authority under a Board-approved fee schedule.

99.6.2 Institutional subscription fees shall be recorded, invoiced, receipted, accounted for, and treated in accordance with applicable Canadian tax, nonprofit, accounting, and financial-control requirements.

99.6.3 Institutional subscription fees may be differentiated by institution type, access class, program category, public-interest status, size, geography, public-benefit contribution, scholarship arrangement, sponsored-seat structure, or other lawful and mission-aligned criteria.

99.6.4 No institutional subscription fee shall purchase governance control, voting rights, research conclusions, evidence conclusions, methods outcomes, publication conclusions, public authority access, finance-readiness treatment, insurance-readiness treatment, procurement advantage, certification, recognition, provider preference, technical baseline influence, or Nexus-compatible status.

99.6.5 Fee waivers, reduced fees, public-interest subscriptions, community subscriptions, academic subscriptions, public authority learning subscriptions, sponsored seats, and scholarship arrangements shall be recorded and structured to avoid capture, control, improper private benefit, undue influence, and public-safe claims risk.


99.7 Program Access.

99.7.1 Institutional subscribers may receive access to programs only where such access is expressly authorized under subscription terms, program rules, eligibility criteria, access class, and recorded participation conditions.

99.7.2 Program access may include research briefings, public-good learning programs, Academy programs, technical workshops, public-safe simulations, evidence-literacy sessions, observability-methods sessions, ontology sessions, open technical baseline sessions, public-good software learning, controlled demonstrations, or other approved program surfaces.

99.7.3 Program access shall not permit an institutional subscriber to direct program design, control program outputs, determine participant selection, obtain preferential public authority access, influence evidence conclusions, control technical baselines, receive provider preference, or purchase publication outcomes.

99.7.4 Program access may be restricted or conditioned based on public-benefit purpose, conflict review, data / AI / cyber review, public authority boundary review, finance boundary review, competition-law review, controlled-technology review, safeguards review, and public-safe publication review.

99.7.5 Program access records shall identify the institutional subscriber, representatives, program, access level, purpose, restrictions, confidentiality obligations, public claims limits, and correction path.


99.8 Learning Access.

99.8.1 Institutional subscribers may receive learning access to support evidence literacy, methods literacy, research integrity, observability literacy, ontology literacy, public-good software literacy, open technical baseline literacy, data governance literacy, AI governance literacy, cybersecurity literacy, public authority literacy, safeguards literacy, public-safe publication literacy, and Nexus role-separation literacy.

99.8.2 Learning access may include briefings, courses, workshops, webinars, reading rooms, Academy sessions, technical primers, simulation exercises, public-safe materials, and controlled learning environments where authorized.

99.8.3 Learning access shall not constitute professional certification, regulated credential, public authority qualification, provider qualification, procurement qualification, finance-readiness status, insurance-readiness status, certification, accreditation, recognition, or Nexus-compatible status.

99.8.4 Attendance records, completion records, participation records, or learning acknowledgments shall state their limited purpose and shall not be used as professional licenses, regulated credentials, procurement qualifications, provider endorsements, public authority approvals, or finance-readiness indicators.

99.8.5 Learning materials shall be subject to evidence, methods, public-safe publication, controlled vocabulary, disclaimer, and correction requirements.


99.9 Controlled Material Access Where Authorized.

99.9.1 Institutional subscribers shall have access to controlled materials only where expressly authorized by the Corporation through a recorded access decision.

99.9.2 Controlled material access may require confidentiality agreements, data processing terms, controlled-room admission, no-download restrictions, identity verification, representative approval, sanctions review, export-control review, public authority capacity classification, cyber access review, AI-use review, safeguards review, and conflict disclosure.

99.9.3 Controlled materials may include restricted reports, controlled annexes, draft methods, sensitive evidence, technical baselines under review, cyber-sensitive materials, infrastructure-sensitive materials, public authority-sensitive materials, finance-sensitive evidence, commercially sensitive materials, personal information, community-protected materials, Indigenous / local / territorial knowledge, protected knowledge, or no-download materials.

99.9.4 Controlled material access shall not confer ownership, unrestricted reuse, redistribution rights, publication rights, training rights, AI-use rights, model-improvement rights, public authority reference rights, finance-use rights, certification-use rights, procurement-use rights, or provider-marketing rights except as expressly recorded.

99.9.5 Unauthorized use, redistribution, publication, uploading, model training, embedding, scraping, copying, downloading, screen-capturing, or public reference to controlled materials may result in access suspension, termination, correction, takedown demand, legal response, and incident records.


99.10 No Governance Control by Institutional Subscription.

99.10.1 Institutional subscription shall not confer governance control over GCRI Canada.

99.10.2 Institutional subscribers shall not control, direct, veto, approve, suppress, condition, purchase, or influence Board decisions, officer decisions, committee work, council outputs, research agendas, research conclusions, evidence conclusions, methods, public-good software, open technical baselines, public-safe publications, public authority access, Docket inputs, Grid inputs, GRF inputs, GRA inputs, Nexus Standards inputs, or Nexus interface outputs.

99.10.3 Institutional subscriber status shall not create membership rights, voting rights, fiduciary authority, director status, officer status, committee authority, council authority, agency, partnership, joint venture, shared liability, shared treasury, public authority status, or authority to bind the Corporation.

99.10.4 Higher subscription tiers, larger fee payments, multi-year subscriptions, in-kind support, public authority status, provider status, sponsor status, donor status, technical centrality, host status, or institutional prestige shall not create governance influence.

99.10.5 Any governance-control implication arising from institutional subscription shall be corrected, clarified, withdrawn, or publicly addressed where necessary.


99.11 No Preferred Provider, Sponsor, Public Authority, Finance-Readiness, Procurement, or Recognition Benefit by Subscription.

99.11.1 Institutional subscription shall not confer preferred provider status, preferred sponsor status, preferred donor status, preferred funder status, preferred host status, public authority endorsement, public authority approval, finance-readiness, insurance-readiness, investment suitability, bankability, procurement advantage, certification, recognition, standing, maturity status, Docket status, Grid status, or Nexus-compatible status.

99.11.2 Provider, sponsor, donor, host, public authority, investor, insurer, lender, National Consortium Company, Project SPV, or enterprise actor participation through subscription shall not alter the Corporation’s provider-neutrality, procurement-neutrality, finance-boundary, public authority boundary, certification-boundary, and anti-capture duties.

99.11.3 Institutional subscribers shall not advertise, market, bid, fundraise, solicit investment, solicit public finance, solicit insurance, or seek procurement using subscription status in a manner that implies GCRI Canada endorsement or advantage.

99.11.4 Any subscription benefit that could be misunderstood as recognition, certification, procurement advantage, public authority endorsement, finance-readiness, insurance-readiness, provider preference, or sponsor influence shall be revised, restricted, accompanied by limitation language, or withdrawn.

99.11.5 Misuse of institutional subscription status shall be subject to correction, suspension, termination, public clarification, and legal response where appropriate.


99.12 No Use of Subscription to Influence Research, Methods, Evidence, Publications, or Technical Baselines.

99.12.1 Institutional subscribers shall not use subscription status, subscription fees, access benefits, representative relationships, sponsored seats, in-kind support, institutional prestige, public authority status, provider status, donor status, host status, or technical contribution to influence research, methods, evidence, publications, software, open technical baselines, public-good technical assets, controlled vocabulary, public-safe reports, dashboards, maps, Docket inputs, Grid inputs, GRF inputs, GRA inputs, Nexus Standards inputs, or Nexus Observatory inputs.

99.12.2 Institutional subscribers may provide comments, evidence, technical input, challenge submissions, public authority context, community context, field learning, or method feedback only through approved intake channels and subject to evidence, methods, conflict, confidentiality, public-safe, and correction review.

99.12.3 Institutional subscriber inputs shall be evaluated on merit, provenance, relevance, reliability, permission, safeguards compliance, and public-benefit value, not on fee level, sponsor status, donor status, provider status, host status, public authority status, or institutional influence.

99.12.4 No institutional subscriber shall receive a publication veto, research finding veto, suppression right, pre-clearance right, technical baseline approval right, evidence conclusion approval right, methods approval right, or public authority access right unless expressly required by law or a lawful agreement and approved within the Corporation’s non-executing role.

99.12.5 Attempts to influence research, methods, evidence, publications, or technical baselines through subscription shall be treated as potential capture, conflict, or integrity incidents.


99.13 Institutional Subscription Records.

99.13.1 The Corporation shall maintain institutional subscription records.

99.13.2 Institutional subscription records shall include institutional identity, legal status, representatives, subscription category, start date, renewal date, termination date, fee schedule, invoices, payments, waivers, sponsored seats, benefits, access rights, learning rights, program access, controlled material access, confidentiality acknowledgments, data / AI / cyber permissions, public authority capacity classification where applicable, conflict disclosures, sanctions and export-control screening where applicable, suspension, cancellation, refund, termination, reinstatement, and correction records.

99.13.3 Records shall identify that institutional subscription does not confer statutory membership, voting rights, governance control, fiduciary authority, public authority authority, certification, recognition, finance-readiness, procurement advantage, provider preference, sponsor control, or authority to bind GCRI Canada.

99.13.4 Institutional subscription records shall be maintained subject to privacy, confidentiality, cybersecurity, access, retention, deletion, sealing, legal hold, and audit requirements.

99.13.5 The Secretary, Treasurer, or another authorized records custodian shall maintain, reconcile, and correct institutional subscription records.


Section 100. Host Institution Participation

100.1 Host Institution Definition.

100.1.1 A host institution means an institution that lawfully provides or makes available facilities, sites, rooms, campuses, labs, observability locations, test environments, data environments, public authority contexts, community contexts, equipment, systems, infrastructure, staff support, learning environments, public-good program surfaces, or other hosting capacity for GCRI Canada activities.

100.1.2 Host institutions may include universities, laboratories, public institutions, municipalities, public authorities, utilities, ports, telecom entities, health institutions, emergency-management organizations, community institutions, Indigenous institutions, civil society organizations, private facilities, research campuses, technical campuses, sovereign compute hosts, observability node hosts, Nexus Universe hosts, or other lawful hosts.

100.1.3 Host institution status shall be a participation and support status only and shall not create statutory membership, governance control, agency, partnership, joint venture, public authority delegation, certification, procurement advantage, provider preference, finance-readiness, recognition, or shared liability.

100.1.4 Host institution status shall be defined by a written host record, host agreement, program charter, site record, access record, or other lawful instrument.

100.1.5 Any ambiguity regarding host status shall be resolved in favour of non-execution, legal separateness, public authority boundary discipline, provider neutrality, procurement neutrality, data / AI / cyber controls, safeguards, and validity-by-record.


100.2 Host Institution Eligibility.

100.2.1 Host institution eligibility shall be determined by the Corporation under Board-approved or delegated criteria.

100.2.2 Eligibility may require lawful authority to host, facility suitability, safety readiness, cybersecurity readiness, data governance readiness, privacy readiness, accessibility readiness, insurance suitability, conflict review, sanctions screening, export-control screening, public authority capacity classification where applicable, community safeguards review, protected knowledge review, and alignment with the Corporation’s public-benefit purpose.

100.2.3 A host institution shall not be eligible where hosting would create unacceptable legal risk, safety risk, public authority confusion, procurement risk, provider preference, sponsor capture, data risk, AI risk, cyber risk, community harm, protected knowledge risk, environmental harm, infrastructure sensitivity risk, or mission drift.

100.2.4 Eligibility may be conditioned, limited, site-specific, program-specific, time-limited, access-limited, controlled-room-limited, data-limited, or subject to periodic review.

100.2.5 The Corporation may suspend, restrict, revoke, or decline host status where eligibility conditions are not met or where continued hosting would threaten public-benefit purpose, safety, legal compliance, safeguards, records integrity, or role separation.


100.3 Host Participation Purposes.

100.3.1 Host institution participation may support research, public-benefit R&D, technical testing, evidence collection methods, observability methods, public authority learning, Academy programs, labs, controlled rooms, public-safe demonstrations, community engagement, software testing, open technical baseline evaluation, scenario exercises, simulations, and Nexus-compatible public-good activities.

100.3.2 Host participation shall be limited to recorded purposes and shall not create broad authority to use host facilities, host data, host systems, host staff, host public authority references, host community relationships, or host infrastructure beyond the approved scope.

100.3.3 Host participation shall be structured to preserve host legal obligations, host safety obligations, host data obligations, host community obligations, host public authority obligations, host employment obligations, host security obligations, and GCRI Canada’s non-executing public-good role.

100.3.4 Host participation shall not convert GCRI Canada into an operator of host systems, owner of host assets, public authority for host activities, emergency command body, procurement body, finance-readiness authority, certification body, or enterprise execution actor.

100.3.5 Host participation purposes shall be recorded in a host agreement, program charter, site record, activation record, or other official record.


100.4 Host Support for Research, Labs, Observability, Public Authority Learning, Technical Testing, Academy Programs, or Public-Good Infrastructure.

100.4.1 A host institution may support GCRI Canada research by providing lawful access to facilities, contextual information, field settings, institutional expertise, data environments, controlled rooms, learning rooms, or research infrastructure.

100.4.2 A host institution may support labs, including research labs, technical labs, controlled labs, challenge labs, Academy labs, public authority learning labs, observability labs, or Nexus Universe labs, subject to approved lab charters and controls.

100.4.3 A host institution may support observability activities, including Observatory node methods, hub methods, cluster methods, hotspot methods, regional cluster methods, national dense core methods, sensor methods, AI-RAN methods, O-RAN methods, DePIN methods, digital twin methods, cyber telemetry methods, geospatial methods, degraded-mode awareness methods, and public-safe dashboard methods.

100.4.4 A host institution may support public authority learning through briefings, exercises, simulations, public-safe demonstrations, evidence-literacy sessions, technical-literacy sessions, public-safe reporting sessions, or other capacity-classified activities.

100.4.5 A host institution may support public-good infrastructure only within recorded scope, lawful authority, safety controls, data / AI / cyber controls, public authority boundaries, safeguards, and non-execution limits.


100.5 Host Duties.

100.5.1 Host institutions shall comply with host agreements, this Bylaw, applicable policies, facility rules, safety rules, confidentiality obligations, data / AI / cyber controls, public-safe claims rules, public authority reference rules, finance boundary rules, certification boundary rules, procurement-neutrality rules, provider-neutrality rules, sponsor non-control rules, safeguards obligations, and correction duties.

100.5.2 Host institutions shall provide accurate information regarding facility status, access limits, safety conditions, system ownership, data authority, public authority context, community context, security requirements, and known risks.

100.5.3 Host institutions shall not represent hosting as endorsement, certification, recognition, public authority approval, procurement approval, finance-readiness, insurance-readiness, provider preference, public-private partnership, or GCRI Canada operational control.

100.5.4 Host institutions shall protect confidential materials, controlled materials, data, credentials, devices, logs, evidence artifacts, public authority materials, community-protected materials, Indigenous / local / territorial knowledge, protected knowledge, and technical assets accessed or created through hosting.

100.5.5 Host institutions shall support correction, incident response, access revocation, closeout, public clarification, and records reconciliation where host participation creates error, overclaim, ambiguity, incident, or boundary risk.


100.6 Host Data, Facility, Security, Safety, Access, and Public Authority Context Records.

100.6.1 The Corporation shall maintain host records sufficient to establish lawful authority, scope, safety, security, data handling, public authority context, and access limits.

100.6.2 Host records shall include the host institution identity, site or facility description, authority to host, host representatives, access permissions, permitted uses, prohibited uses, safety requirements, security requirements, insurance requirements where applicable, data classifications, AI-use permissions, cyber controls, public authority capacity classifications, community safeguards, protected knowledge flags, and closeout obligations.

100.6.3 Facility records shall identify whether the host environment includes labs, field sites, campuses, control rooms, controlled rooms, no-download rooms, observability nodes, sensor environments, AI-RAN environments, O-RAN environments, DePIN environments, digital twin environments, data rooms, or other controlled environments.

100.6.4 Public authority context records shall identify whether the host is a public authority, public institution, public infrastructure operator, public health body, emergency-management body, utility, municipality, Crown-related body, regulator, public finance reader, or other public-sector participant.

100.6.5 Host records shall be maintained subject to confidentiality, privacy, security, public authority sensitivity, infrastructure sensitivity, cyber sensitivity, protected knowledge, retention, legal hold, and correction requirements.


100.7 Host Public Reference Controls.

100.7.1 Any public reference to a host institution shall require authorization consistent with host terms, public-safe publication rules, public authority reference rules where applicable, sponsor and provider reference rules where applicable, and approved public language.

100.7.2 Public references may include host name, logo, site, facility, event, quote, photograph, data contribution, public authority participation, program participation, or technical role only where recorded and approved.

100.7.3 Public host references shall not imply endorsement, adoption, public authority approval, procurement approval, provider preference, certification, recognition, finance-readiness, insurance-readiness, public-private partnership, joint venture, operational control, emergency command, public warning authority, or sovereign obligation.

100.7.4 Host references shall include non-endorsement, non-execution, and limitation language where needed.

100.7.5 Unauthorized, outdated, inaccurate, or misleading host references shall be corrected, withdrawn, clarified, or taken down.


100.8 Host Participation Without Public Authority Delegation.

100.8.1 Host participation shall not create public authority delegation to GCRI Canada.

100.8.2 Where a host institution is a public authority, public institution, public infrastructure operator, public health body, public safety body, municipality, utility, emergency-management organization, regulator, or other public-sector entity, hosting shall remain learning, evidence, methods, technical, observability, public-safe, or capacity-building participation only unless a separate lawful public authority instrument expressly provides otherwise.

100.8.3 Host participation shall not authorize GCRI Canada to issue public warnings, emergency commands, permits, approvals, regulatory guidance, procurement decisions, funding decisions, public finance decisions, public health orders, public safety commands, infrastructure commands, or sovereign obligations.

100.8.4 Any public authority ambiguity arising from hosting shall be escalated, clarified, recorded, and corrected.

100.8.5 Public authority delegation boundary records shall be maintained.


100.9 Host Participation Without Procurement Preference.

100.9.1 Host participation shall not confer procurement preference on the host institution or any host-affiliated provider, vendor, sponsor, contractor, funder, National Consortium Company, Project SPV, or enterprise actor.

100.9.2 Hosting shall not be represented as bid advantage, vendor selection, preferred provider status, procurement approval, technical qualification, public authority procurement endorsement, or public contract readiness.

100.9.3 Host participation in research, labs, public authority learning, technical testing, observability, Academy programs, or Nexus Universe activities shall not create procurement recommendations by GCRI Canada.

100.9.4 Any procurement-related public claim based on host participation shall be reviewed and corrected.

100.9.5 Procurement-neutrality records shall be maintained where host participation intersects with provider, vendor, public authority, or procurement-sensitive contexts.


100.10 Host Participation Without Provider Preference.

100.10.1 Host participation shall not confer preferred provider status, required provider status, approved provider status, certified provider status, or Nexus-compatible provider status.

100.10.2 A host institution or host-affiliated provider shall not use hosting to claim GCRI Canada endorsement, technical approval, certification, procurement advantage, finance-readiness, recognition, or public authority approval.

100.10.3 Provider tools, systems, data, compute, sensors, AI-RAN components, O-RAN components, DePIN infrastructure, dashboards, cybersecurity tools, or other technical assets used in a host environment shall be treated as contributions or contextual systems only, not as preferred solutions.

100.10.4 GCRI Canada shall preserve provider neutrality in host environments and may require conflict disclosure, benchmarking controls, clean-room procedures, and public-safe claim restrictions.

100.10.5 Provider-preference overclaims arising from hosting shall be corrected.


100.11 Host Participation Without Asset Transfer Unless Expressly Recorded.

100.11.1 Host participation shall not transfer ownership of host assets to GCRI Canada unless expressly provided by a lawful written instrument.

100.11.2 Host participation shall not transfer ownership of GCRI Canada assets to the host institution unless expressly provided by a lawful written instrument.

100.11.3 Asset-related matters shall identify ownership, custody, license rights, access rights, use restrictions, maintenance responsibilities, risk allocation, insurance responsibilities, data rights, IP rights, export-control status, security requirements, return obligations, decommissioning obligations, and closeout requirements.

100.11.4 Assets may include equipment, facilities, software, sensors, AI-RAN components, O-RAN components, DePIN equipment, compute credits, cloud resources, datasets, models, dashboards, technical baselines, repositories, documents, keys, credentials, and public-good technical assets.

100.11.5 Asset transfer, custody, return, disposition, and closeout records shall be maintained.


100.12 Host Participation Without GCRI Canada Operational Control of Host Systems Unless Lawfully Contracted and Non-Executing.

100.12.1 Host participation shall not give GCRI Canada operational control over host systems unless such control is expressly authorized by a lawful written agreement and remains within the Corporation’s non-executing role.

100.12.2 GCRI Canada shall not operate, command, dispatch, maintain, direct, control, or assume responsibility for host emergency systems, public infrastructure systems, public health systems, public safety systems, utility systems, telecom systems, port systems, energy systems, water systems, food systems, cyber systems, production systems, or mission-critical systems unless lawfully contracted for a non-executing, limited, technical, research, learning, or advisory support function.

100.12.3 Technical integration, observability access, dashboard access, data access, simulation access, sensor access, AI-RAN access, O-RAN access, DePIN access, digital twin access, or compute access shall not be treated as operational control.

100.12.4 Any operational-control ambiguity shall trigger hold, legal review, public authority boundary review, safety review, data / AI / cyber review, and correction where necessary.

100.12.5 Operational-control boundary records shall be maintained.


100.13 Host Confidentiality, Data, AI, Cyber, Safety, and Safeguards Obligations.

100.13.1 Host institutions shall comply with confidentiality, data governance, privacy, AI governance, cybersecurity, physical security, safety, accessibility, public authority, infrastructure sensitivity, community safeguards, Indigenous / local / territorial knowledge, protected knowledge, and public-safe publication obligations applicable to the hosted activity.

100.13.2 Host institutions shall implement reasonable access controls, safety controls, incident reporting pathways, data protection measures, cyber controls, and confidentiality protections appropriate to the host environment and activity.

100.13.3 Host institutions shall not use GCRI Canada data, outputs, tools, publications, models, dashboards, evidence artifacts, or technical assets for unauthorized AI training, embedding, model improvement, publication, redistribution, procurement, provider marketing, finance-readiness, certification, recognition, or public authority representation.

100.13.4 Host institutions shall report data incidents, AI incidents, cyber incidents, safety incidents, public authority misdescription, protected knowledge breach, unauthorized access, and public-safe publication risks promptly.

100.13.5 Host obligations shall survive termination to the extent required by law, contract, confidentiality, data protection, IP, records, safeguards, correctionability, and non-reliance duties.


100.14 Host Participation Records.

100.14.1 The Corporation shall maintain host participation records.

100.14.2 Host participation records shall include host identity, host representatives, facility or site description, host authority, host agreement, program or lab charter, access permissions, safety records, security records, data classifications, AI-use permissions, cyber controls, public authority capacity classification, equipment and asset records, insurance records where applicable, public reference approvals, conflict disclosures, sponsor or provider relationships, public-safe publication posture, incident records, correction records, closeout records, and asset return or disposition records.

100.14.3 Host participation records shall identify that hosting does not create public authority delegation, procurement preference, provider preference, certification, finance-readiness, recognition, asset transfer, operational control, partnership, agency, joint venture, shared liability, or shared treasury unless expressly and lawfully recorded.

100.14.4 Records shall be maintained subject to privacy, confidentiality, cyber, infrastructure sensitivity, public authority sensitivity, protected knowledge, retention, deletion, sealing, legal hold, and access controls.

100.14.5 The Secretary or another authorized records custodian shall maintain and correct host participation records.


Section 101. Developer, Maintainer, Technical Contributor, and Open-Source Participant Categories

101.1 Developer Category.

101.1.1 The Corporation may recognize a developer category for persons who contribute code, software modules, scripts, tools, schemas, APIs, SDKs, dashboards, tests, documentation, build systems, security improvements, integrations, or other technical work to GCRI Canada public-good software or technical assets.

101.1.2 Developer status shall be a technical contribution status only and shall not create statutory membership, voting rights, governance authority, fiduciary authority, employment status, agency, authority to bind, public representation authority, certification authority, procurement authority, provider-selection authority, finance-readiness authority, or public authority status.

101.1.3 Developers shall work within approved repositories, contribution pathways, issue trackers, coding standards, security standards, licensing terms, AI-use rules, data rules, and review procedures.

101.1.4 Developer participation may be public, controlled, restricted, internal, volunteer, contractor-based, fellow-based, employee-based, institutional, sponsored, academic, provider-affiliated, public authority-affiliated, or community-based, as recorded.

101.1.5 Developer records shall identify status, authority, access, contribution terms, IP terms, confidentiality obligations, security obligations, and public statement limits.


101.2 Maintainer Category.

101.2.1 The Corporation may recognize a maintainer category for persons authorized to review, triage, merge, release, document, maintain, secure, or administer specified technical assets or repositories.

101.2.2 Maintainer authority shall be expressly recorded and limited by repository, asset, role, permission, branch, release channel, time period, security class, and review requirement.

101.2.3 Maintainer status shall not create authority to alter institutional meaning, change controlled vocabulary, amend technical baselines of constitutional significance, certify conformance, approve procurement, select providers, determine finance-readiness, issue public authority communications, or bind the Corporation unless separately authorized by lawful record.

101.2.4 Maintainers shall comply with secure development lifecycle controls, code review rules, branch protection, release procedures, dependency governance, SBOM requirements where applicable, vulnerability disclosure procedures, key and credential controls, and correctionability.

101.2.5 Maintainer permissions may be suspended, restricted, revoked, or rotated to preserve security, independence, continuity, anti-capture, and public-good asset integrity.


101.3 Technical Contributor Category.

101.3.1 The Corporation may recognize a technical contributor category for persons or institutions that contribute technical input, methods, evidence artifacts, schemas, data tools, models, benchmarks, evaluation harnesses, documentation, designs, interface mappings, security findings, test vectors, or other technical contributions.

101.3.2 Technical contributor status may apply whether the contributor is an individual, university, laboratory, public authority participant, community technologist, provider, vendor, sponsor, host, contractor, fellow, advisor, volunteer, employee, or external expert.

101.3.3 Technical contributor status shall be subject to contribution intake, contributor terms, IP review, data rights review, security review, AI-use review, export-control review where applicable, conflict disclosure, sponsor / provider disclosure, and public-safe claims discipline.

101.3.4 Technical contribution shall not confer ownership of GCRI Canada public-good assets, control over technical baselines, provider preference, certification, recognition, finance-readiness, procurement advantage, or public authority approval.

101.3.5 Technical contributor records shall identify contribution type, rights, restrictions, attribution, review status, acceptance status, rejection status, quarantine status, modification status, withdrawal status, and correction path.


101.4 Open-Source Participant Category.

101.4.1 The Corporation may permit open-source participation in repositories, tools, documentation, issue trackers, public-good software, open technical baselines, schemas, test harnesses, and other public technical assets.

101.4.2 Open-source participants shall comply with the applicable license, contribution guidelines, code of conduct, contributor terms, IP terms, security rules, vulnerability disclosure rules, public-safe claims rules, and repository governance procedures.

101.4.3 Open-source participation shall not confer membership, governance authority, maintainer authority, release authority, certification authority, provider preference, procurement advantage, finance-readiness, recognition, public authority status, or authority to speak for the Corporation.

101.4.4 Public repository access does not authorize access to restricted repositories, controlled rooms, sensitive datasets, non-public methods, cyber-sensitive materials, public authority-sensitive materials, finance-sensitive materials, or protected knowledge.

101.4.5 Open-source participation may be limited, suspended, blocked, moderated, or terminated for security risk, abuse, harassment, IP concern, license concern, data leakage, public-safe claims risk, or other integrity concern.


101.5 Eligibility and Screening.

101.5.1 Developer, maintainer, technical contributor, and open-source participant eligibility shall be determined by contribution category, access level, repository class, asset sensitivity, data sensitivity, public authority sensitivity, export-control status, cyber risk, and institutional risk.

101.5.2 Screening may include identity verification, affiliation disclosure, conflict disclosure, sanctions screening, export-control screening, controlled-technology review, cybersecurity review, IP review, data rights review, AI-use review, public authority boundary review, sponsor / provider influence review, and prior conduct review.

101.5.3 Enhanced screening shall apply before granting maintainer access, write access, release access, production access, controlled-room access, data access, model access, secure enclave access, key access, credential access, or access to sensitive technical assets.

101.5.4 Eligibility may be refused, limited, conditioned, suspended, or revoked to protect security, public-good assets, data, privacy, public authority materials, protected knowledge, public-safe publication, export-control compliance, sanctions compliance, and institutional integrity.

101.5.5 Eligibility and screening records shall be maintained.


101.6 Contributor Terms.

101.6.1 Contributors shall be subject to written or electronically accepted contributor terms appropriate to the contribution type and access level.

101.6.2 Contributor terms shall address contribution scope, originality, authority to contribute, IP rights, license grants, moral rights treatment where applicable, third-party rights, open-source compliance, data rights, confidentiality, security, vulnerability disclosure, AI-use disclosure, conflict disclosure, sponsor / provider disclosure, attribution, public reference limits, and correction obligations.

101.6.3 Contributor terms may differ for employees, contractors, fellows, volunteers, academic participants, public authority participants, provider personnel, sponsor personnel, host personnel, open-source contributors, controlled-room contributors, and maintainers.

101.6.4 No contribution shall be accepted where the contributor lacks authority to contribute or where acceptance would create unacceptable IP, data, security, export-control, sanctions, protected knowledge, public-safe claims, or anti-capture risk.

101.6.5 Contributor terms shall be recorded and retained.


101.7 Contributor License Agreements or Assignment Instruments.

101.7.1 The Corporation may require a contributor license agreement, assignment instrument, employment work-product agreement, contractor IP assignment, fellow agreement, open-source contributor agreement, or other rights instrument before accepting contributions.

101.7.2 Rights instruments shall identify ownership, license scope, sublicensing rights, patent rights where applicable, moral rights waiver or consent where lawful and appropriate, attribution, restrictions, confidential information, data rights, export-control limitations, and public-good asset treatment.

101.7.3 Contributions to public-good software or open technical baselines shall be structured to preserve lawful reuse, interoperability, correctionability, security, public-benefit purpose, and anti-enclosure controls.

101.7.4 Contributions containing third-party rights, restricted data, public authority data, personal information, protected knowledge, controlled technology, confidential materials, or license-incompatible code shall be rejected, quarantined, modified, or accepted only under recorded restrictions.

101.7.5 Contributor license and assignment records shall be maintained.


101.8 Moral Rights Treatment Where Applicable.

101.8.1 Where applicable law recognizes moral rights, the Corporation shall address moral rights in contribution terms, employment agreements, contractor agreements, fellow agreements, assignment instruments, license agreements, or other rights records.

101.8.2 The Corporation may require a waiver, consent, non-assertion, or other lawful treatment of moral rights where necessary to permit public-good use, modification, correction, translation, adaptation, security patching, publication, supersession, deprecation, retirement, or archival.

101.8.3 Moral rights treatment shall be obtained in a manner consistent with applicable law, fairness, attribution discipline, public-benefit purpose, research integrity, and public-good technical asset stewardship.

101.8.4 Attribution may be provided where appropriate, but attribution shall not imply endorsement, employment, membership, maintainer authority, certification, provider preference, public authority approval, finance-readiness, or governance control.

101.8.5 Moral rights records shall be maintained.


101.9 Repository Access Rules.

101.9.1 Repository access shall be granted only according to approved repository access rules, role-based access, least-privilege principles, identity verification, security review, contribution status, and recorded authority.

101.9.2 Repository access classes may include public read access, contributor access, triage access, write access, maintainer access, release access, administrator access, security access, restricted repository access, controlled repository access, and emergency access.

101.9.3 Access to non-public repositories shall require recorded purpose, access approval, confidentiality acknowledgment, security obligations, data classification review, AI-use restrictions, export-control review where applicable, and offboarding procedures.

101.9.4 Personal accounts, shared credentials, unapproved mirrors, shadow repositories, unauthorized forks, unapproved AI coding environments, or unlogged storage shall not be used for official repository work.

101.9.5 Repository access shall be reviewed periodically and revoked when no longer required.


101.10 Code Review Duties.

101.10.1 Developers, maintainers, and technical contributors shall comply with code review duties applicable to the repository, asset class, risk class, and release class.

101.10.2 Code review shall assess functionality, security, privacy, data handling, AI-use implications, dependency changes, license compatibility, IP rights, public-safe implications, controlled vocabulary implications, export-control implications, and technical baseline implications.

101.10.3 No material code, schema, model, dashboard, test harness, API, SDK, release, or technical baseline change shall be merged or released without the required review.

101.10.4 Maintainers shall not self-approve high-risk, security-sensitive, release-critical, or conflict-affected changes except under recorded emergency procedures and subsequent review.

101.10.5 Code review records shall be maintained.


101.11 Secure Development Duties.

101.11.1 Developers, maintainers, and technical contributors shall follow secure development lifecycle requirements.

101.11.2 Secure development duties may include threat modeling, secure design, secure coding, dependency review, static analysis, dynamic testing, secret scanning, vulnerability management, branch protection, release signing, SBOM preparation where appropriate, logging, monitoring, rollback planning, and incident reporting.

101.11.3 Contributors shall not introduce malicious code, unauthorized telemetry, hidden dependencies, license-incompatible components, embedded credentials, personal information, protected knowledge, public authority-sensitive data, cyber-sensitive data, infrastructure-sensitive data, or unauthorized AI-generated code.

101.11.4 Security vulnerabilities shall be reported through approved vulnerability disclosure channels and shall not be publicly disclosed before appropriate coordinated handling where disclosure could create harm.

101.11.5 Secure development records shall be maintained.


101.12 Dependency, License, and Vulnerability Disclosure Duties.

101.12.1 Contributors shall disclose material dependencies, libraries, packages, models, datasets, tools, licenses, third-party rights, and known vulnerabilities associated with their contributions.

101.12.2 Dependencies shall be reviewed for security, license compatibility, maintenance status, provenance, supply-chain risk, export-control concerns, sanctions concerns, data handling, AI-use risk, and public-good asset compatibility.

101.12.3 Contributors shall disclose known vulnerabilities, weaknesses, insecure defaults, exposed secrets, unsafe assumptions, model risks, dependency risks, and known failure modes.

101.12.4 Contributions with undisclosed dependencies, incompatible licenses, unresolved vulnerabilities, unclear provenance, or unacceptable supply-chain risk may be rejected, quarantined, modified, restricted, or withdrawn.

101.12.5 Dependency, license, and vulnerability records shall be maintained.


101.13 Confidentiality and Controlled-Room Duties.

101.13.1 Developers, maintainers, technical contributors, and open-source participants with access to confidential or controlled materials shall comply with confidentiality and controlled-room obligations.

101.13.2 Controlled-room duties may include no-download restrictions, access logging, non-disclosure, restricted copying, restricted screenshots, secure device use, controlled AI-use rules, no external upload, no public discussion, and return or deletion obligations.

101.13.3 Controlled materials may include draft methods, non-public research, restricted evidence, public authority materials, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, personal information, protected knowledge, confidential code, credentials, keys, or security findings.

101.13.4 Controlled-room status shall not confer governance authority, institutional authority, certification authority, finance-readiness authority, public authority status, provider preference, or public statement authority.

101.13.5 Breach of confidentiality or controlled-room duties may result in suspension, revocation, termination, correction, incident response, and legal action.


101.14 AI-Use, Data, Privacy, Cyber, and Export-Control Duties.

101.14.1 Developers, maintainers, technical contributors, and open-source participants shall comply with AI-use, data governance, privacy, cybersecurity, export-control, sanctions, and controlled-technology rules applicable to their work.

101.14.2 Contributors shall not upload restricted materials, confidential code, personal information, public authority data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive evidence, Indigenous / local / territorial knowledge, protected knowledge, or controlled technology to unapproved AI systems.

101.14.3 Contributors shall not use restricted data for model training, fine-tuning, embedding, retrieval indexing, model improvement, benchmarking, or public demonstrations without recorded authorization.

101.14.4 Contributors shall comply with export-control and sanctions restrictions regarding repository access, controlled-room access, technical data, software, AI models, cryptography, cyber tools, telecom systems, AI-RAN, O-RAN, DePIN, geospatial systems, Earth observation, robotics, drones, autonomous systems, quantum-adjacent technologies, and other dual-use materials.

101.14.5 AI-use, data, privacy, cyber, sanctions, and export-control records shall be maintained where material.


101.15 No Maintainer Authority to Change Institutional Meaning Without Authorization.

101.15.1 Maintainer authority shall not include authority to change the institutional meaning of GCRI Canada outputs, controlled vocabulary, public claims, technical baselines, public-good asset status, Nexus-compatible claims, evidence classifications, maturity concepts, public authority classifications, finance-boundary terms, certification-boundary terms, or role-separation language unless expressly authorized.

101.15.2 Technical changes that affect legal meaning, governance authority, public meaning, public authority interpretation, finance-readiness implication, certification implication, procurement implication, provider preference, or Nexus interface meaning shall require governance review and recorded approval.

101.15.3 Maintainers shall not use release notes, repository descriptions, README files, badges, metadata, tags, documentation, issue comments, package descriptions, or public repository statements to create institutional claims beyond approved language.

101.15.4 Unauthorized institutional meaning changes shall be corrected, reverted, superseded, withdrawn, clarified, or publicly corrected where necessary.

101.15.5 Institutional-meaning change records shall be maintained.


101.16 No Technical Permission as Governance Authority.

101.16.1 Technical permissions, including repository access, maintainer rights, administrator rights, data access, dashboard access, API access, credential access, release access, or controlled-room access, shall not constitute governance authority.

101.16.2 Technical permission shall not authorize a person to make Board decisions, officer decisions, public authority decisions, finance-readiness decisions, certification decisions, procurement decisions, provider-selection decisions, recognition decisions, or public statements on behalf of the Corporation.

101.16.3 Technical control over systems, repositories, workflows, dashboards, models, schemas, or release pipelines shall remain subordinate to this Bylaw, Board authority, officer delegations, public-good purpose, non-execution, role separation, data / AI / cyber controls, and correctionability.

101.16.4 Technical actions exceeding authorized scope may be invalid, restricted, reversed, suspended, quarantined, or corrected.

101.16.5 Technical permission and authority records shall be maintained.


101.17 Suspension, Revocation, and Offboarding.

101.17.1 Developer, maintainer, technical contributor, and open-source participant access may be suspended, restricted, revoked, or terminated where required to protect security, confidentiality, data, privacy, public authority materials, protected knowledge, public-good assets, repository integrity, public-safe claims, institutional meaning, or legal compliance.

101.17.2 Grounds may include misconduct, harassment, retaliation, security breach, data misuse, AI misuse, cyber misconduct, IP violation, license violation, dependency risk, secret exposure, public overclaim, provider-preference claim, sponsor-control conduct, conflict non-disclosure, sanctions concern, export-control concern, or breach of contributor terms.

101.17.3 Offboarding shall include access revocation, credential revocation, key rotation where needed, repository permission removal, controlled-room removal, return or deletion of materials, confidentiality reminder, contribution status review, and correction of public references where necessary.

101.17.4 Emergency suspension may occur before full review where immediate risk exists.

101.17.5 Suspension, revocation, and offboarding records shall be maintained.


101.18 Developer, Maintainer, Technical Contributor, and Open-Source Records.

101.18.1 The Corporation shall maintain records for developers, maintainers, technical contributors, and open-source participants where material or where access is non-public.

101.18.2 Records shall include identity, affiliation, category, contribution terms, license or assignment instruments, moral rights treatment where applicable, access level, repositories, permissions, contribution history, code review records, security review records, dependency records, vulnerability records, AI-use disclosures, data access, controlled-room access, conflict disclosures, sponsor / provider disclosures, sanctions and export-control screening where applicable, suspension, revocation, offboarding, and correction records.

101.18.3 Records shall identify that technical participation does not confer membership, voting rights, governance authority, fiduciary authority, public authority status, certification, recognition, finance-readiness, procurement advantage, provider preference, or authority to bind the Corporation.

101.18.4 Records shall be maintained subject to privacy, confidentiality, cybersecurity, repository security, retention, deletion, sealing, legal hold, and access controls.

101.18.5 The technical function, Secretary, or another authorized records custodian shall maintain and correct such records.


Section 102. Academic, University, Laboratory, and Research Network Participation

102.1 Academic Participation Purpose.

102.1.1 Academic participation shall support the Corporation’s public-benefit research, evidence, methods, observability, ontology, public-good R&D, public-good software, open technical baseline, public authority learning, safeguards, and Nexus-compatible public-good purposes.

102.1.2 Academic participation may include research collaboration, peer review, methods review, evidence review, reproducibility work, replication work, student engagement, fellowship programs, technical labs, public authority learning, public-safe publication, public-good software development, and open technical baseline development.

102.1.3 Academic participation shall preserve research integrity, independence, methodological rigor, conflict disclosure, sponsor independence, public-safe publication discipline, data / AI / cyber controls, safeguards, protected knowledge protections, and correctionability.

102.1.4 Academic participation shall not create certification, recognition, public authority approval, provider endorsement, procurement advantage, finance-readiness, professional credential, public warning authority, or execution authority.

102.1.5 Academic participation records shall identify scope, institution, participants, authority, data, IP, publication rights, ethics requirements, conflicts, and correction paths.


102.2 University Participation.

102.2.1 Universities may participate as research collaborators, host institutions, public-good technical contributors, Academy partners, fellowship partners, lab hosts, public authority learning supporters, observability-methods contributors, or public-safe publication collaborators.

102.2.2 University participation shall be governed by written agreements, institutional approvals, research ethics requirements, IP terms, data terms, confidentiality terms, publication review, student supervision rules, conflict controls, and safeguards requirements.

102.2.3 University participation shall not create agency, partnership, joint venture, shared liability, shared treasury, parent-subsidiary status, branch status, public authority delegation, certification, recognition, procurement advantage, provider preference, finance-readiness, or authority to bind the Corporation.

102.2.4 University names, logos, faculty titles, student affiliations, lab names, public authority affiliations, and host references shall be used only under approved public reference rules.

102.2.5 University participation records shall be maintained.


102.3 Laboratory Participation.

102.3.1 Laboratories may participate in research, technical testing, controlled experiments, validation, replication, benchmarking, model evaluation, sensor evaluation, AI-RAN methods review, O-RAN methods review, DePIN methods review, cybersecurity methods review, geospatial methods review, digital twin review, secure compute review, or other approved public-good technical activities.

102.3.2 Laboratory participation shall be governed by lab charters, agreements, safety protocols, security protocols, data / AI / cyber controls, export-control review, controlled-technology review, IP terms, publication rules, research integrity controls, and public-safe output rules.

102.3.3 Laboratory outputs shall be treated as evidence, method, technical, validation, replication, or research artifacts, not as certification, public authority approval, procurement approval, provider endorsement, finance-readiness, rating, or guarantee.

102.3.4 Laboratory participation involving public authority systems, critical infrastructure, controlled technology, cyber tools, personal information, protected knowledge, or sensitive data shall require enhanced review and recorded controls.

102.3.5 Laboratory participation records shall be maintained.


102.4 Research Network Participation.

102.4.1 The Corporation may maintain research networks to coordinate researchers, universities, laboratories, fellows, technical experts, public authorities, community participants, Indigenous knowledge holders, civil society actors, media researchers, providers, hosts, and other contributors within lawful and public-benefit purposes.

102.4.2 Research network participation may support agenda formation, methods review, evidence challenge, peer review, reproducibility, replication, public-good software, open baselines, public authority learning, public-safe publication, safeguards review, and Nexus semantic alignment.

102.4.3 Research network participants shall not have governance authority, Board authority, officer authority, statutory member rights, public authority status, certification authority, finance-readiness authority, procurement authority, provider-selection authority, or authority to bind GCRI Canada.

102.4.4 Research network outputs shall require adoption, approval, publication review, or other competent authority record before obtaining institutional meaning.

102.4.5 Research network records shall be maintained.


102.5 Research Collaboration Agreements.

102.5.1 Research collaborations shall be governed by written agreements where material, cross-institutional, funded, data-intensive, IP-significant, public authority-sensitive, controlled-technology-sensitive, community-sensitive, or publication-significant.

102.5.2 Research collaboration agreements shall address scope, purpose, authority, roles, funding, budget, data rights, IP rights, confidentiality, publication rights, research ethics, human-subjects review, community review, Indigenous / local / territorial knowledge safeguards, protected knowledge, AI-use, cyber controls, export controls, sanctions, conflicts, sponsor influence, provider influence, attribution, correction, and closeout.

102.5.3 Research collaboration agreements shall include non-execution, non-certification, non-procurement, non-finance, non-public-warning, public authority boundary, provider-neutrality, sponsor non-control, and non-endorsement language where relevant.

102.5.4 No collaboration agreement shall give a collaborator control over GCRI Canada governance, research conclusions, evidence conclusions, methods, publications, technical baselines, public authority access, Docket inputs, Grid inputs, GRF inputs, GRA inputs, or Nexus interface outputs.

102.5.5 Research collaboration agreement records shall be maintained.


102.6 Joint Research Programs.

102.6.1 The Corporation may participate in joint research programs with universities, laboratories, public authorities, community institutions, civil society organizations, Indigenous institutions, providers, hosts, sponsors, donors, funders, and other institutions where lawful and public-benefit aligned.

102.6.2 Joint research programs shall have recorded scope, governance, roles, authority limits, data rules, IP rules, publication rules, funding rules, conflict rules, safeguards rules, public-safe output rules, and correction paths.

102.6.3 Joint research programs shall preserve GCRI Canada’s legal separateness and shall not create partnership, joint venture, agency, shared liability, shared treasury, public authority delegation, certification authority, finance-readiness authority, procurement authority, provider preference, or execution authority.

102.6.4 Joint research outputs shall identify authorship, ownership, review status, evidence basis, methods basis, limitations, public-safe classification, and correction path.

102.6.5 Joint research program records shall be maintained.


102.7 Fellowships, Visiting Researchers, Students, and Supervisors.

102.7.1 The Corporation may engage fellows, visiting researchers, students, interns, residents, supervisors, academic advisors, and other academic participants in accordance with written terms.

102.7.2 Such terms shall address role, scope, supervision, eligibility, stipend or reimbursement where applicable, institutional affiliation, research ethics, confidentiality, IP, data access, AI-use, cyber controls, publication review, attribution, conflicts, safeguards, public statements, and offboarding.

102.7.3 Students and fellows shall not be given access to sensitive materials unless appropriate review, supervision, consent, confidentiality, data / AI / cyber controls, and safeguards are in place.

102.7.4 Supervisors shall not use their role to control GCRI Canada conclusions, public outputs, technical baselines, publication decisions, public authority access, or Nexus interface outputs outside recorded collaboration authority.

102.7.5 Fellowship, visiting researcher, student, and supervisor records shall be maintained.


102.8 Research Ethics and Institutional Review Requirements.

102.8.1 Research activities shall comply with applicable research ethics, institutional review, human-subjects, privacy, health information, community, Indigenous, protected knowledge, public authority, and legal requirements.

102.8.2 Research ethics review may be required for human-subjects research, health-sensitive data, personal information, vulnerable participants, community-protected knowledge, Indigenous knowledge, local or territorial knowledge, protected environmental knowledge, public authority data, AI processing, geospatial mapping, sensor-based observability, or public-safe publication involving harm risk.

102.8.3 Where a university, laboratory, public authority, host, funder, or partner requires institutional review, the Corporation shall coordinate review responsibilities and retain evidence of approval, exemption, deferral, or other determination.

102.8.4 Absence of formal external ethics review shall not excuse the Corporation from applying internal safeguards and do-no-harm review where appropriate.

102.8.5 Research ethics and institutional review records shall be maintained.


102.9 Publication Rights and Publication Review.

102.9.1 Research collaboration terms shall define publication rights, review procedures, embargoes, attribution, confidentiality, redaction, public-safe release, controlled annexes, correction rights, and withdrawal rights.

102.9.2 Publication review shall preserve research independence and shall not be used by sponsors, donors, providers, hosts, collaborators, public authorities, or partners to suppress findings, purchase conclusions, alter evidence, distort methods, create endorsements, or avoid lawful correction.

102.9.3 Publication review may protect confidential information, personal information, public authority-sensitive information, cyber-sensitive information, infrastructure-sensitive information, protected knowledge, IP, export-controlled information, and public-safe concerns.

102.9.4 Publications shall disclose sponsorship, donor support, provider involvement, host involvement, public authority participation, conflicts, AI-use, data sources, methods, limitations, and uncertainty where appropriate and public-safe.

102.9.5 Publication review and publication rights records shall be maintained.


102.10 IP, Data, Confidentiality, and Attribution Terms.

102.10.1 Academic, university, laboratory, and research network participation shall include IP, data, confidentiality, and attribution terms appropriate to the activity.

102.10.2 IP terms shall address background IP, foreground IP, jointly created IP, public-good technical assets, software, schemas, models, datasets, publications, methods, technical baselines, moral rights, license rights, open-source releases, restricted assets, and anti-enclosure controls.

102.10.3 Data terms shall address lawful basis, ownership or control, permitted use, prohibited use, access, storage, localization, cross-border transfer, AI-use, publication, retention, deletion, de-identification, protected knowledge, public authority data, and correction.

102.10.4 Confidentiality terms shall protect non-public materials while preserving lawful research integrity, correctionability, public-safe disclosure, legal compliance, and required reporting.

102.10.5 Attribution terms shall not imply endorsement, certification, recognition, public authority approval, finance-readiness, procurement advantage, provider preference, or governance control.


102.11 Human-Subjects, Community, Indigenous, Health-Sensitive, and Protected Knowledge Review.

102.11.1 Research involving human subjects, personal information, health-sensitive information, community knowledge, Indigenous knowledge, local knowledge, territorial knowledge, protected environmental knowledge, culturally sensitive knowledge, vulnerable participants, or protected participants shall require appropriate review before collection, processing, sharing, publication, or use in AI systems.

102.11.2 Review shall consider consent, non-consent, withdrawal, correction, attribution, confidentiality, de-identification, aggregation, public-safe mapping, publication risk, community harm, cultural harm, data sovereignty, Indigenous governance protocols, vulnerable participant protections, and remedy pathways.

102.11.3 No research participant, community, Indigenous knowledge holder, vulnerable participant, or protected participant shall be coerced into participation.

102.11.4 Community and Indigenous participation shall not be extracted for sponsor, provider, donor, host, public authority, institutional, or reputational convenience.

102.11.5 Review records and safeguards records shall be maintained.


102.12 No Academic Participation as Certification, Recognition, Public Authority Approval, or Provider Endorsement.

102.12.1 Academic, university, laboratory, or research network participation shall not be represented as certification, recognition, accreditation, public authority approval, provider endorsement, procurement approval, finance-readiness, insurance-readiness, investment suitability, bankability, rating, guarantee, or Nexus-compatible status.

102.12.2 Peer review, technical review, laboratory validation, academic collaboration, university hosting, or research participation shall not constitute certification or conformance approval unless a separate lawful certification program has been established and the output is expressly issued under that program.

102.12.3 Academic affiliations, university names, laboratory names, professor titles, student involvement, or peer review references shall not be used to imply public authority endorsement, commercial endorsement, provider preference, procurement advantage, or finance-readiness.

102.12.4 Any academic participation overclaim shall be corrected.

102.12.5 Academic participation boundary records shall be maintained.


102.13 Academic Independence and Conflict Controls.

102.13.1 Academic participation shall be structured to preserve academic independence, research integrity, methodological independence, publication integrity, and public-benefit purpose.