For the complete documentation index, see llms.txt. This page is also available as Markdown.

ARTICLE XIV. PROGRAMS

Section 331. Program Approval Architecture

331.1 Program Approval Purpose. GCRI Canada shall maintain a program approval architecture for all programs, activation dockets, readiness programs, host activations, adoption windows, replication sprints, governed pilots, labs, Academy programs, training programs, fellowship programs, competence-cell programs, challenge programs, benchmarking programs, partnering programs, curated-introduction programs, capability-mapping programs, and related programmatic activities undertaken, hosted, supported, convened, documented, reviewed, published, or interfaced by GCRI Canada. The purpose of the program approval architecture is to ensure that every program is public-benefit aligned, evidence-based, method-governed, non-executing, public-safe, financially clean, technically controlled, privacy-respecting, data / AI / cyber secure, safeguards-compliant, public authority-boundary-compliant, sponsor-neutral, provider-neutral, procurement-neutral, correctionable, and compatible with GCRI Canada’s role as an upstream research, evidence, methods, observability, ontology, public-good software, and open technical-baseline steward.

331.2 Program Definition. A program means any structured, recurring, time-limited, pilot, cohort, sprint, docket, readiness, learning, training, research, evidence, technical, observability, ontology, software, baseline, fellowship, lab, challenge, benchmarking, host, public authority learning, community safeguards, Nexus interface, or capacity-formation activity organized by or through GCRI Canada under a recorded purpose, scope, authority, participants, deliverables, review pathway, records pathway, and closeout pathway. A program may be internal, public-safe, controlled, restricted, host-based, public authority-facing, community-facing, Academy-facing, consortium-facing, GRA-facing, GRF-compatible, Nexus-compatible, or technical asset-facing, but shall not become an execution mandate merely because it is organized, named, staffed, funded, sponsored, hosted, or externally visible.

331.3 Program Classes. GCRI Canada may classify programs according to purpose, risk, audience, data class, AI-use class, cyber class, public authority class, safeguards class, finance-boundary class, technical asset class, publication posture, and Nexus interface posture. Program classes may include research programs, evidence programs, methods programs, observability programs, ontology programs, public-good software programs, open technical baseline programs, data / AI / cyber programs, public authority learning programs, community safeguards programs, Academy and training programs, fellowship programs, competence formation programs, Nexus interface programs, activation docket programs, host activation programs, adoption window programs, replication sprint programs, governed pilot programs, lab programs, challenge programs, benchmarking programs, partnering programs, curated-introduction programs, and capability-mapping programs. Classification shall determine approval authority, review gates, records, permitted outputs, boundary language, and closeout obligations.

331.4 Research Program. A research program may be approved to conduct or support public-benefit research, field research, desk research, technical research, comparative research, policy-adjacent research, observability research, AI research, cyber research, data governance research, methods research, ontology research, public-good software research, public authority learning research, community safeguards research, or Nexus-compatible research. A research program shall identify research question, scope, methods, evidence sources, ethics requirements where applicable, data rights, privacy controls, protected knowledge safeguards, public authority boundaries, publication posture, conflicts, sponsor or provider independence, and correction path. A research program shall not be used to deliver predetermined sponsor outcomes, provider endorsements, procurement recommendations, finance-readiness conclusions, certification findings, public authority decisions, or public warnings.

331.5 Evidence Program. An evidence program may be approved to collect, organize, classify, compare, review, maintain, correct, or publish evidence records, source records, confidence notes, limitation notes, observability records, technical records, public authority learning records, controlled annexes, public-safe summaries, or Nexus interface evidence inputs. Evidence programs shall maintain source lineage, classification, lawful basis, permissions, review status, uncertainty, public-safe status, and correction path. Evidence programs may support GRF-compatible claims discipline, GRA-facing technical inputs, Nexus Rails technical evidence inputs, Nexus Grid evidence inputs, and public authority learning, but shall not issue recognition, maturity, finance-readiness, certification, procurement approval, public authority approval, or operational instructions.

331.6 Methods Program. A methods program may be approved to design, test, document, compare, revise, publish, or maintain methods, procedures, review frameworks, evaluation pathways, evidence rules, observability methods, AI governance methods, cybersecurity methods, data governance methods, public-safe publication methods, ontology methods, benchmark methods, public authority learning methods, or Nexus-compatible methods. Methods programs shall record assumptions, scope, applicability, limitations, version, reviewer status, adoption status, dependencies, risks, and correction path. A methods program shall not certify implementations, accredit providers, mandate procurement, approve public authority use, determine finance-readiness, or warrant performance.

331.7 Observability Program. An observability program may be approved to support Nexus Observatory methods, telemetry rules, sensing methods, dashboard methods, map methods, digital twin methods, degraded-mode awareness, resilience indicators, AI-RAN / O-RAN observability, DePIN observability, geospatial methods, Earth observation methods, cyber telemetry methods, sensor methods, sovereign compute evidence methods, or public-safe intelligence outputs. Observability programs shall be governed by data / AI / cyber controls, privacy, public authority boundaries, infrastructure sensitivity review, protected knowledge safeguards, dashboard and map limitations, public-safe publication posture, and correctionability. Observability programs shall not constitute emergency command, public warning, infrastructure operation, public authority decision, finance-readiness determination, certification, procurement approval, or provider preference.

331.8 Ontology Program. An ontology program may be approved to create, maintain, localize, align, version, correct, or publish controlled vocabularies, taxonomies, schemas, data dictionaries, risk ontologies, evidence classifications, maturity concepts, technology-family concepts, public authority capacity terms, finance-boundary terms, certification-boundary terms, recognition-boundary terms, AI-readable knowledge structures, semantic mappings, compatibility notes, and divergence logs. Ontology programs shall preserve semantic integrity, interoperability, public-safe claims discipline, role separation, version control, localization discipline, and correctionability. Ontology programs shall not create legal equivalence, certification, recognition, maturity status, finance-readiness, procurement approval, or public authority adoption merely through terminology.

331.9 Public-Good Software Program. A public-good software program may be approved to create, maintain, release, restrict, document, test, version, license, deprecate, retire, or archive public-good software, internal software, restricted software, APIs, SDKs, dashboards, scripts, tools, test harnesses, benchmark tools, verifiable compute tools, observability tools, Truth Engine-supporting tools, repository materials, or technical packages. Such program shall be governed by secure development, repository security, licensing, dependency review, SBOM where appropriate, secrets control, vulnerability management, public-safe release review, contribution rules, IP records, and correction path. Public-good software release shall not make GCRI Canada an operator, managed service provider, certifier, procurement authority, public authority, finance-readiness body, or guarantor.

331.10 Open Technical Baseline Program. An open technical baseline program may be approved to develop, consult on, test, publish, localize, correct, or retire open technical baselines, reference baselines, evidence baselines, Observatory baselines, AI governance baselines, data governance baselines, cybersecurity baselines, interoperability baselines, and conformance-supporting baselines. Such programs shall include scope, intended use, prohibited use, versioning, licensing, public-safe status, security review, dependency review, known limitations, public authority boundary language, finance-boundary language, certification-boundary language, procurement-boundary language, provider-neutrality language, and correction path. Open baseline programs shall not create certification, accreditation, compliance approval, public authority approval, procurement mandate, finance-readiness, insurance-readiness, recognition, maturity, or provider preference.

331.11 Data / AI / Cyber Program. A data / AI / cyber program may be approved to support data governance, AI governance, model governance, cybersecurity, secure development, privacy, access control, incident response, public-safe AI use, AI-assisted publication, prompt and retrieval controls, vector store governance, model-card and system-card governance, vulnerability management, repository hygiene, secure release, cyber-sensitive handling, and controlled technology review. Such program shall be risk-classified, review-controlled, source-controlled, security-controlled, human-accountable, and correctionable. Data / AI / cyber programs shall not authorize unreviewed AI processing, automated public authority action, public warning, emergency command, public authority decision, finance-readiness, certification, procurement approval, or provider selection.

331.12 Public Authority Learning Program. A public authority learning program may be approved to provide educational, technical, evidence, methods, observability, data, AI, cyber, public-safe publication, governance, and capacity-formation materials to public authorities or public-sector readers. Such programs shall classify public authority participation, preserve non-delegation, avoid public authority overclaim, control public authority references, and distinguish learning, listening, reading, commenting, observing, data contribution, and official approval. A public authority learning program shall not create public authority delegation, regulatory approval, public warning authority, emergency command, procurement approval, funding approval, public finance approval, sovereign obligation, or official public-sector status for GCRI Canada.

331.13 Community Safeguards Program. A community safeguards program may be approved to support public-benefit participation, community-safe research, protected knowledge protocols, Indigenous / local / territorial knowledge safeguards, protected participant controls, remote community protection, public-safe mapping review, accessibility, non-extraction, attribution, withdrawal rights, correction rights, and community harm prevention. Such programs shall be governed by custodial authority where applicable, consent or authorization, privacy, safeguards review, public-safe publication, AI-use restrictions, geospatial controls, data rights, and correctionability. Community safeguards programs shall not convert community knowledge into ordinary open data or use participation to manufacture institutional legitimacy, sponsor value, provider value, finance-readiness, recognition, or public authority endorsement.

331.14 Academy and Training Program. An Academy or training program may be approved to deliver evidence literacy, methods literacy, research integrity training, data governance training, AI governance training, cybersecurity training, observability literacy, public authority learning, public-safe publication training, safeguards training, software and baseline training, finance-boundary literacy, and Nexus-compatible institutional literacy. Such programs may include curricula, cohorts, workshops, labs, learning materials, assessments, fellowships, train-the-trainer materials, and competence pathways. Academy and training programs shall not create professional certification, regulated credential, public authority qualification, provider preference, procurement eligibility, finance-readiness, recognition, maturity status, or authority to speak for GCRI Canada unless separately and lawfully approved.

331.15 Fellowship Program. A fellowship program may be approved for research fellows, technical fellows, Academy fellows, visiting fellows, public authority fellows where lawful, community fellows where appropriate, or other time-limited fellows supporting GCRI Canada’s public-benefit mission. Fellowship programs shall require scope, eligibility, selection process, agreement, duties, supervision, confidentiality, IP, data rights, AI-use controls, publication review, conflicts, stipend or support terms where lawful, public statement limits, completion, suspension, termination, and closeout records. Fellowship status shall not create employment, governance authority, public authority status, certification authority, provider preference, finance authority, or right to bind GCRI Canada unless separately recorded.

331.16 Competence Formation Program. A competence formation program may be approved to build capability through competence cells, labs, practice groups, training cohorts, train-the-trainer pathways, technical exercises, applied methods learning, evidence practice, data / AI / cyber practice, public authority learning practice, safeguards practice, software practice, and public-safe publication practice. Such programs shall be capability-forming, not credential-inflating. Participation may evidence completion of a GCRI Canada learning pathway only where recorded, but shall not constitute professional certification, regulated credential, public authority qualification, procurement eligibility, provider approval, finance-readiness, recognition, or maturity status.

331.17 Nexus Interface Program. A Nexus interface program may be approved to support compatibility, evidence inputs, methods inputs, observability inputs, ontology alignment, public-good software, public-safe summaries, Academy materials, Rails technical evidence inputs, Grid evidence inputs, GRF-compatible claims discipline, GRA-facing technical evidence support, consortium interface records, National Working Group support, Regional Nexus Consortium support, or National Nexus Consortium support. Nexus interface programs shall preserve legal separateness, role separation, no agency, no merger, no shared treasury, no shared liability, non-execution, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, provider neutrality, and correctionability.

331.18 Activation Docket Program. An activation docket program may be approved to organize a recorded pathway for intake, readiness review, host review, stakeholder classification, evidence requirements, methods requirements, learning support, public-safe posture, correction, and closeout for a proposed activation, host activation, readiness activity, governed pilot, lab, adoption window, replication sprint, challenge, benchmarking activity, curated introduction, capability mapping, or Nexus-compatible interface. An activation docket program shall be a structured record and coordination surface only. It shall not constitute execution mandate, procurement decision, finance-readiness determination, recognition, maturity determination, public authority approval, public warning, or provider endorsement.

331.19 Program Approval Authority. Program approval authority shall be exercised by the Board, an authorized officer, an authorized committee, or another competent authority under recorded delegation. Approval authority shall identify program class, risk class, scope, permitted activities, prohibited activities, data classes, AI-use classes, public authority classes, safeguards classes, finance-boundary classes, publication posture, deliverables, budget where applicable, sponsor or donor conditions where any, provider involvement where any, host involvement where any, and closeout requirements. No person shall infer program approval authority from authorship, expertise, seniority, fellowship, advisory status, sponsorship, provider participation, public authority participation, host participation, repository access, Academy role, or Nexus participation.

331.20 Board Approval for Material, High-Risk, Cross-Border, Public Authority, Finance-Sensitive, Controlled Technology, or Nexus-Interface Programs. Board approval shall be required for programs that are material to GCRI Canada’s mission, governance, legal exposure, public reputation, public authority relationships, Nexus role, public-safe posture, controlled technology posture, finance-boundary posture, or long-term institutional commitments. Board approval shall be required or may be required for high-risk programs, cross-border programs, public authority-sensitive programs, protected knowledge-sensitive programs, finance-sensitive programs, controlled technology programs, major AI / cyber / data programs, major public dashboard or map programs, major host activations, major Nexus interface programs, major Academy programs, major public-good baseline programs, and programs involving material sponsor, provider, donor, funder, or host implications. Board approval shall be recorded and may impose conditions, review cycles, escalation triggers, and stop-the-line authority.

331.21 Officer Approval Within Delegation. An authorized officer may approve programs within delegated authority where the program is routine, lower-risk, within approved budget where applicable, consistent with GCRI Canada’s public-benefit purpose, and not reserved for Board approval. Officer approval may apply to defined research activities, internal methods work, routine training, routine Academy materials, controlled technical work, ordinary public-safe publications, minor software maintenance programs, internal capability formation, and low-risk program extensions. Officer approval shall not override required committee review, legal review, data / AI / cyber review, public authority review, safeguards review, finance-boundary review, or Board escalation.

331.22 Committee Review Where Required. Committee review shall be required where a program falls within the mandate of a governance, audit, risk, research integrity, data / AI / cyber, privacy, safeguards, public authority interface, publication, technical asset, finance-boundary, or other committee. Committee review may recommend approval, conditional approval, revision, re-scoping, restriction, controlled access, public-safe transformation, escalation, deferral, denial, suspension, or termination. Committee review shall not constitute final approval unless the committee has delegated approval authority by competent record.

331.23 Public-Benefit Alignment Review. Every material program shall undergo public-benefit alignment review proportionate to risk. Public-benefit alignment review shall assess whether the program advances GCRI Canada’s nonprofit, non-share, non-distributing, public-benefit mission through research, evidence, methods, observability, ontology, public-good software, open technical baselines, public authority learning, community safeguards, Academy learning, competence formation, or Nexus-compatible public-good support. Programs that primarily serve private benefit, sponsor value, provider advantage, market positioning, procurement influence, finance promotion, reputation laundering, political endorsement, or institutional overreach shall be denied, re-scoped, or conditioned.

331.24 Non-Execution Review. Every program shall be reviewed for non-execution. Non-execution review shall confirm that the program does not make GCRI Canada an operator, implementer, infrastructure manager, emergency commander, public warning issuer, procurement body, finance arranger, insurer, underwriter, lender, rating agency, certifier, accreditor, recognition authority, public authority substitute, provider selector, National Consortium Company controller, Project SPV controller, or enterprise execution vehicle. Where program activities approach execution boundaries, they shall be narrowed, conditioned, routed to separate competent entities, or denied.

331.25 Data / AI / Cyber / Privacy Review. Programs involving data, AI, cyber, software, dashboards, maps, sensors, AI-RAN, O-RAN, DePIN, digital twins, compute, retrieval, embeddings, model outputs, public authority data, personal information, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, health-sensitive data, finance-sensitive evidence, public repositories, or public-safe outputs shall undergo data / AI / cyber / privacy review. Review shall address lawful basis, data rights, privacy, AI-use authority, model provider terms, cyber controls, access controls, localization, cross-border transfer, public-safe release, incident response, and correctionability.

331.26 Public Authority Boundary Review. Programs involving public authorities, public authority personnel, public authority data, public finance readers, regulators, emergency-management bodies, public infrastructure operators, public health bodies, public safety bodies, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, cyber bodies, public-sector hosts, or public authority-facing materials shall undergo public authority boundary review. Review shall preserve capacity classification, no-delegation, no-public-warning, no-emergency-command, no-regulatory-approval, no-procurement-approval, no-funding-approval, no-public-finance-approval, no-sovereign-obligation, and public reference controls.

331.27 Finance, Certification, Procurement, Recognition, and Provider-Preference Boundary Review. Programs involving finance-readiness language, capital-readability, GRA interfaces, Nexus Rails, proof packs, investor-facing materials, public finance reader materials, insurance-sensitive materials, lender-sensitive materials, procurement-sensitive materials, certification-like outputs, maturity-like outputs, recognition-like outputs, benchmarking, provider comparisons, sponsor support, provider participation, or host participation shall undergo boundary review. Review shall prevent investment advice, solicitation, securities offering, capital commitment, underwriting, insurance approval, lending approval, rating, public finance approval, bankability determination, certification, accreditation, procurement approval, provider preference, recognition purchase, maturity overclaim, sponsor control, and improper private benefit.

331.28 Community Safeguards and Protected Knowledge Review. Programs involving communities, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, protected participants, youth, vulnerable persons, remote communities, community vulnerability, public-safe mapping risk, health-sensitive groups, or protected knowledge shall undergo community safeguards and protected knowledge review. Review shall address custodial authority, consent or authorization, non-extraction, attribution, confidentiality, access controls, AI-use restrictions, publication limits, geospatial generalization, withdrawal rights, correction rights, and harm-prevention measures. Programs shall not convert protected knowledge into ordinary program material.

331.29 Program Approval Records. GCRI Canada shall maintain program approval records, including program approval purpose records, program definitions, program class records, research program records, evidence program records, methods program records, observability program records, ontology program records, public-good software program records, open technical baseline program records, data / AI / cyber program records, public authority learning program records, community safeguards program records, Academy and training program records, fellowship program records, competence formation program records, Nexus interface program records, activation docket program records, approval authority records, Board approval records, officer approval records, committee review records, public-benefit alignment reviews, non-execution reviews, data / AI / cyber / privacy reviews, public authority boundary reviews, finance / certification / procurement / recognition / provider-preference boundary reviews, community safeguards and protected knowledge reviews, conditions, denials, suspensions, terminations, corrections, supersessions, and archives.


Section 332. Activation Docket Model

332.1 Activation Docket Purpose. GCRI Canada may maintain an activation docket model to provide a recorded, disciplined, evidence-based, method-governed, public-benefit pathway for considering, structuring, reviewing, supporting, correcting, and closing activation-related activities, including readiness activities, host activations, governed pilots, labs, adoption windows, replication sprints, benchmarking activities, challenge activities, capability mapping, public authority learning engagements, community safeguards engagements, Nexus interface engagements, public-good software demonstrations, and technical baseline demonstrations. The activation docket model shall preserve order, transparency, role separation, and correctionability without creating execution authority.

332.2 Activation Docket as Recorded Program Pathway. An activation docket shall be a recorded program pathway with a case ID, scope, purpose, authority, participants, host or site context where applicable, public authority context where applicable, sponsor or donor context where applicable, provider context where applicable, community context where applicable, evidence requirements, methods requirements, data / AI / cyber requirements, safeguards requirements, public-safe posture, deliverables, milestones, closeout criteria, and correction path. The activation docket shall be an institutional record and shall not be an informal opportunity pipeline, sponsor pipeline, provider pipeline, procurement pipeline, investment pipeline, or public authority approval pipeline.

332.3 Activation Docket as Evidence, Methods, Readiness, Learning, and Coordination Surface. An activation docket may serve as an evidence, methods, readiness, learning, and coordination surface by organizing source records, method records, readiness records, host records, public authority learning records, safeguards records, technical baseline compatibility records, public-good software support records, data / AI / cyber readiness records, Academy or training records, capability maps, compatibility notes, divergence logs, and public-safe summaries. Such coordination shall be administrative, evidentiary, methodological, and educational in nature. Coordination shall not become operational control, procurement direction, finance execution, provider selection, public warning, emergency command, or public authority action.

332.4 Activation Docket Not as Execution Mandate. No activation docket shall constitute an execution mandate. Opening, maintaining, approving, advancing, closing, or publishing an activation docket shall not authorize GCRI Canada to build, deploy, operate, manage, maintain, command, procure, finance, insure, underwrite, certify, accredit, recognize, rate, or execute any project, host system, infrastructure system, software system, public authority function, National Consortium Company activity, Project SPV activity, provider activity, or enterprise activity. Execution, where lawful and appropriate, must occur through separate competent actors and records.

332.5 Activation Docket Not as Procurement Decision. No activation docket shall constitute a procurement decision, procurement recommendation, preferred provider designation, tender requirement, vendor qualification, purchasing approval, contract award, public-sector eligibility standard, or provider selection. Provider participation, technical contribution, software demonstration, host support, sponsor support, benchmarking involvement, or appearance in an activation docket shall not create procurement preference. Public authorities and other purchasers remain responsible for their own lawful procurement processes.

332.6 Activation Docket Not as Finance-Readiness Determination. No activation docket shall constitute finance-readiness, insurance-readiness, bankability, investability, creditworthiness, underwriting approval, lending approval, rating, public finance approval, capital placement, investor matchmaking, securities offering, solicitation, capital commitment, or finance recommendation. An activation docket may organize technical evidence inputs or finance-boundary learning materials only with non-reliance language and regulated-perimeter controls. GCRI Canada shall not allow docket status to be marketed as capital readiness.

332.7 Activation Docket Not as GRF Recognition or Grid Maturity Determination. No activation docket shall constitute GRF recognition, public standing, legitimacy recognition, Nexus Grid maturity, maturity status, infrastructure readiness status, capability ranking, host readiness guarantee, provider status, project recognition, certification, accreditation, or public approval. An activation docket may provide evidence inputs, methods inputs, correction signals, and compatibility notes to separate competent processes where authorized, but shall not itself create recognition, maturity, standing, or Grid status.

332.8 Activation Docket Intake. Activation docket intake shall collect only information necessary to determine purpose, scope, authority, stakeholders, data class, public authority class, safeguards class, AI-use class, cyber class, finance-boundary class, host class, provider class, sponsor or donor class, publication posture, evidence requirements, methods requirements, risks, and approval path. Intake shall avoid collection of unnecessary personal information, protected knowledge, public authority-sensitive data, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, or confidential provider materials unless lawful, necessary, classified, and controlled.

332.9 Activation Docket Case ID. Each activation docket shall receive a case ID or other unique identifier sufficient to preserve traceability, versioning, review, correspondence, records management, corrections, supersessions, closeout, and archival. The case ID shall not itself imply approval, priority, recognition, public authority support, finance-readiness, procurement eligibility, maturity, provider preference, or Nexus-compatible status. Public references to a case ID shall be controlled where risk of overclaim exists.

332.10 Activation Docket Scope. The activation docket scope shall identify the question, activity, geography, host context, technical context, public authority context, community context, data context, AI context, cyber context, deliverables, non-deliverables, permitted activities, prohibited activities, publication posture, and closeout criteria. Scope shall be narrow enough to prevent drift into execution, procurement, finance, public authority action, certification, recognition, or provider preference. Scope changes shall require recorded review.

332.11 Activation Docket Sponsor, Donor, Host, Provider, Public Authority, Community, and Partner Classification. Each activation docket shall classify sponsors, donors, hosts, providers, public authorities, communities, partners, universities, laboratories, National Consortium Companies, Project SPVs, and other actors by role, capacity, authority, contribution, conflict, benefit, access, public reference permissions, data rights, confidentiality, and boundary limitations. Classification shall distinguish support, participation, hosting, contribution, observation, public authority learning, regulator listening, public finance reading, provider technical contribution, sponsor funding, community input, and official approval. No classification shall imply control, endorsement, procurement preference, finance-readiness, recognition, maturity, or public authority delegation unless expressly and lawfully recorded.

332.12 Activation Docket Evidence Requirements. Activation dockets shall identify evidence requirements, including source records, data records, host records, methods records, technical records, public authority records, safeguards records, observability records, public-good software records, controlled annexes, confidence notes, limitation notes, classification, public-safe status, and correction path. Evidence requirements shall be proportionate to risk and shall not require overcollection. Evidence gaps shall be recorded and shall not be concealed through polished presentation or unsupported claims.

332.13 Activation Docket Methods Requirements. Activation dockets shall identify methods requirements, including applicable methods, method versions, assumptions, exclusions, dependencies, review status, public-safe status, evidence linkages, acceptance gates, benchmarking methods where any, challenge methods where any, readiness methods where any, host activation methods where any, and correction path. Methods shall be selected to fit the docket purpose and shall not be used to imply certification, procurement approval, finance-readiness, public authority adoption, or provider ranking.

332.14 Activation Docket Data / AI / Cyber Requirements. Activation dockets shall identify data / AI / cyber requirements, including data classification, lawful basis, permissions, privacy review, AI-use authority, model and provider terms, embedding and retrieval restrictions, cyber controls, infrastructure sensitivity, secure storage, access controls, cross-border review, localization, compute-to-data where required, public repository restrictions, dashboard and map controls, incident response, and correction path. No docket shall use unapproved AI systems, unapproved storage, shadow IT, uncontrolled repositories, or side-channel processing for restricted materials.

332.15 Activation Docket Public-Safe Publication Posture. Each activation docket shall identify public-safe publication posture, including whether docket existence, title, summary, participants, host, public authority participation, sponsor support, provider contribution, evidence summary, methods summary, dashboard, map, report, dataset, software release, or closeout may be public, public-safe, controlled, restricted, internal-only, embargoed, or not publishable. Public-safe posture shall be reviewed before any external reference. Docket publicity shall not imply approval, adoption, readiness, recognition, maturity, finance-readiness, procurement approval, or provider preference.

332.16 Activation Docket Closeout. Activation docket closeout shall identify completion status, deliverables, non-deliverables, evidence status, methods status, data / AI / cyber status, safeguards status, public authority boundary status, finance-boundary status, publication status, open issues, limitations, correction obligations, successor activities, supersessions, archival status, and lessons learned. Closeout may state that a docket is completed, closed without action, deferred, transferred, superseded, withdrawn, archived, or terminated. Closeout shall not be described as approval, execution, procurement, finance-readiness, certification, recognition, maturity, or public authority adoption.

332.17 Activation Docket Correction. Activation dockets shall remain correctionable. Correction shall be triggered by source error, methods error, public authority misdescription, sponsor or provider misdescription, host misdescription, community safeguards issue, protected knowledge concern, privacy issue, AI hallucination, cyber issue, infrastructure-sensitive exposure, finance overclaim, certification implication, procurement implication, provider preference, public-safe publication issue, stale record, or changed circumstances. Correction may include docket note, revised scope, revised classification, access restriction, publication correction, public-safe clarification, controlled notice, withdrawal, supersession, or archive status update.

332.18 Activation Docket Records. GCRI Canada shall maintain activation docket records, including activation docket purpose records, recorded program pathway records, evidence / methods / readiness / learning / coordination records, non-execution records, non-procurement records, non-finance-readiness records, non-recognition and non-maturity records, intake records, case ID records, scope records, sponsor / donor / host / provider / public authority / community / partner classification records, evidence requirement records, methods requirement records, data / AI / cyber requirement records, public-safe publication posture records, closeout records, correction records, supersessions, withdrawals, terminations, lessons learned, and archives.


Section 333. Program Intake, Scope, Milestones, Acceptance Gates, KPIs, Risk Class, Publication Posture, and Closeout

333.1 Program Intake Requirement. Every material program shall begin with intake sufficient to determine whether the proposed activity is lawful, public-benefit aligned, within GCRI Canada’s role, non-executing, evidence-based, method-governed, technically controlled, financially clean, public-safe, privacy-compliant, data / AI / cyber-compliant, safeguards-compliant, public authority-boundary-compliant, sponsor-neutral, provider-neutral, procurement-neutral, correctionable, and capable of proper records. Intake shall identify program class, origin, proposer, purpose, beneficiaries, participants, stakeholders, host context, public authority context, sponsor or donor context, provider context, data class, AI-use class, cyber class, public-safe posture, and approval path.

333.2 Program Scope Statement. Each program shall have a written scope statement identifying what the program will do, what it will not do, what outputs are intended, what outputs are prohibited, what authority applies, what records will be created, what systems may be used, what data may be processed, what participants may do, what external references may be made, what publication posture applies, and what closeout will require. Scope shall be sufficiently specific to prevent mission drift, execution drift, finance drift, certification drift, procurement drift, provider preference, sponsor capture, public authority role confusion, and uncontrolled public claims.

333.3 Program Purpose Statement. Each program shall have a purpose statement tied to GCRI Canada’s public-benefit mission. The purpose statement shall identify whether the program supports research, evidence, methods, observability, ontology, public-good software, open technical baselines, data governance, AI governance, cyber governance, public authority learning, community safeguards, Academy learning, competence formation, host activation, readiness, benchmarking, lab work, challenge activity, capability mapping, Nexus interface support, or correctionability. The purpose statement shall not be written to disguise private benefit, sales enablement, procurement influence, capital solicitation, provider endorsement, or public authority approval.

333.4 Program Authority Statement. Each program shall identify its approval authority, delegated authority, committee review, Board review where required, legal authority, contractual authority where any, funding authority where any, sponsor or donor restrictions where any, public authority terms where any, data-sharing terms where any, research ethics authority where any, and publication authority. Program authority shall distinguish permission to plan, permission to intake, permission to conduct internal work, permission to involve external participants, permission to publish, permission to share controlled materials, and permission to close out.

333.5 Program Public-Benefit Rationale. Each program shall include a public-benefit rationale explaining how the program advances public-good research, evidence discipline, methods integrity, observability, ontology, public-good software, open technical baselines, public authority learning, safeguards, data / AI / cyber capability, community benefit, institutional learning, technical interoperability, Nexus-compatible public-good architecture, or correctionability. The rationale shall identify the public-interest problem, expected public-benefit contribution, affected communities or stakeholders where relevant, and safeguards against private capture or overclaim.

333.6 Program Non-Execution Boundary Statement. Each program shall include a non-execution boundary statement where material. The statement shall identify that the program does not authorize GCRI Canada to operate systems, command responses, issue public warnings, direct public authorities, procure vendors, select providers, commit capital, arrange finance, underwrite insurance, issue ratings, certify products, accredit actors, recognize maturity, approve public authority actions, manage National Consortium Companies, manage Project SPVs, or execute enterprise projects. Any program with execution-adjacent risk shall include explicit boundary controls.

333.7 Program Nexus Role-Separation Statement Where Applicable. Where a program interfaces with Nexus institutions, GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, Nexus Competence Cells, National Consortium Companies, Project SPVs, providers, hosts, sponsors, capital readers, public authorities, universities, laboratories, or communities, the program shall include a role-separation statement. The statement shall preserve legal separateness, no agency, no merger, no shared treasury, no shared liability, no public authority delegation, no finance execution, no certification authority, no procurement authority, no recognition authority, and no execution authority unless separately lawful and recorded.

333.8 Program Stakeholder Map. Each material program shall include a stakeholder map identifying internal owners, program stewards, reviewers, participants, hosts, sponsors, donors, funders, providers, public authorities, communities, universities, laboratories, partners, Nexus entities, National Consortium Companies, Project SPVs, readers, intended beneficiaries, affected persons, and affected communities where relevant. The stakeholder map shall classify capacities, conflicts, access rights, contribution type, public reference permissions, confidentiality, data rights, decision rights, and boundaries. Stakeholder mapping shall not create governance rights or public authority rights by listing a stakeholder.

333.9 Program Risk Class. Each material program shall receive a risk class proportionate to legal risk, public-benefit significance, public exposure, public authority involvement, data sensitivity, AI use, cyber sensitivity, infrastructure sensitivity, health sensitivity, community safeguards, protected knowledge, finance sensitivity, certification sensitivity, procurement sensitivity, sponsor or provider involvement, cross-border transfer, controlled technology, publication risk, and Nexus interface significance. Risk class shall determine approval level, review gates, records depth, monitoring, escalation, incident readiness, and closeout requirements.

333.10 Program Data Class. Each program shall identify the data classes it may collect, receive, process, store, analyze, link, model, embed, retrieve, publish, transfer, restrict, delete, or archive. Data class shall include whether the program involves public information, internal information, confidential information, personal information, sensitive personal information, public authority data, protected knowledge, community-protected data, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive evidence, controlled technology, or public-safe outputs. Programs shall not process data classes beyond approval.

333.11 Program AI-Use Class. Each program shall identify whether AI use is prohibited, permitted for drafting only, permitted for summarization, permitted for coding, permitted for classification, permitted for retrieval, permitted for analysis, permitted for model evaluation, permitted for embeddings, permitted for controlled-room use, permitted for public-safe publication support, or permitted for other approved purposes. AI-use class shall identify approved tools, prohibited tools, data classes, provider terms, model-training restrictions, human review, output verification, hallucination controls, data leakage controls, and incident response.

333.12 Program Cyber Class. Each program shall identify cyber class, including whether it involves ordinary systems, repository systems, public-facing systems, cyber-sensitive data, vulnerabilities, threat intelligence, incident records, security telemetry, cyber tools, prompt injection tests, model attack tests, critical infrastructure systems, controlled technology, or public authority cyber context. Cyber class shall determine access controls, secure storage, disclosure rules, vulnerability handling, public-safe review, and incident response readiness.

333.13 Program Public Authority Class. Each program shall identify public authority class, including whether public authorities are absent, observers, learners, regulator-listening participants, public finance readers, emergency-management participants, infrastructure-operator participants, official-capacity participants, data contributors, hosts, funders, or decision-makers in a separate process. Public authority class shall determine capacity classification, reference controls, confidentiality, public-safe publication, non-endorsement language, and no-delegation boundaries.

333.14 Program Safeguards Class. Each program shall identify safeguards class, including whether it involves ordinary public materials, community-protected data, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, remote communities, protected participants, youth, vulnerable persons, health-sensitive groups, public-safe mapping risk, or other protected knowledge. Safeguards class shall determine consent or authorization, custodial authority, public-safe transformation, AI-use restrictions, publication limits, withdrawal rights, correction rights, and harm-prevention controls.

333.15 Program Finance Boundary Class. Each program shall identify finance boundary class, including whether it has no finance relevance, incidental finance context, public finance reader context, GRA interface context, Nexus Rails technical evidence input context, insurance-sensitive context, investor-facing context, lender-facing context, capital-reader room context, National Consortium Company context, Project SPV context, RNFD / NFD / UNFSD context, or other finance-sensitive context. Finance boundary class shall determine non-reliance language, regulated-perimeter review, audience controls, access controls, and prohibition on investment advice, solicitation, underwriting, lending, insurance placement, rating, public finance approval, and finance-readiness determination.

333.16 Program Milestones. Each program shall identify milestones proportionate to scope and risk. Milestones may include intake completion, approval, stakeholder classification, evidence readiness, methods readiness, data / AI / cyber readiness, safeguards review, public authority boundary review, finance-boundary review, host readiness, technical baseline review, software release review, training cohort launch, lab launch, adoption window opening, replication sprint opening, benchmarking phase, publication review, controlled release, public-safe release, closeout, and correction review. Milestones shall not be marketed as readiness, certification, procurement status, finance-readiness, recognition, or maturity unless separately lawful and recorded.

333.17 Acceptance Gates. Acceptance gates shall identify conditions that must be satisfied before a program may move from intake to approval, from approval to launch, from launch to external engagement, from external engagement to publication, from controlled release to public release, from pilot to replication, from lab to baseline, from training to completion, or from docket to closeout. Acceptance gates may include evidence sufficiency, methods sufficiency, lawful basis, data / AI / cyber approval, safeguards approval, public authority boundary approval, finance-boundary approval, security review, legal review, host agreement, publication approval, and correction readiness. Acceptance gates shall be recorded and shall not be bypassed for convenience.

333.18 KPIs and KRIs. Programs may use key performance indicators and key risk indicators to support internal management, public-benefit learning, quality assurance, evidence integrity, learning outcomes, software quality, publication timeliness, correction responsiveness, participation diversity, accessibility, security posture, and safeguards performance. KPIs and KRIs shall be designed to support public-benefit governance and shall not create provider rankings, procurement scores, finance-readiness scores, certification scores, recognition scores, maturity ratings, public authority ratings, or investment metrics unless separately authorized by competent process. Indicators shall include limitations where they may be misread.

333.19 Deliverables. Each program shall identify deliverables and non-deliverables. Deliverables may include research notes, evidence records, methods notes, observability records, ontology updates, public-good software releases, technical baselines, training materials, Academy materials, fellowship outputs, competence-cell materials, benchmarking records, challenge records, capability maps, compatibility notes, divergence logs, public-safe summaries, controlled summaries, and closeout reports. Non-deliverables shall include, where applicable, procurement decisions, finance-readiness determinations, certifications, public warnings, public authority decisions, provider endorsements, recognition records, maturity determinations, and execution instructions.

333.20 Publication Posture. Each program shall identify publication posture, including internal-only, controlled, restricted, public-safe summary, public report, public dashboard, public map, public dataset, public software release, public technical baseline, embargoed release, no-publication, or publication after review. Publication posture shall be determined by evidence status, data rights, privacy, protected knowledge, public authority terms, cyber sensitivity, infrastructure sensitivity, finance sensitivity, licensing, export controls, sanctions, public-safe review, and approval authority. No program output shall be published externally merely because the program has completed a milestone.

333.21 Closeout Criteria. Each program shall identify closeout criteria, including completion of deliverables, noncompletion reasons, evidence status, methods status, records status, publication status, access revocation, data disposition, repository status, software status, dashboard or map status, public authority reference status, sponsor or provider reference status, finance-boundary status, safeguards status, correction status, lessons learned, successor program status, and archival status. Closeout criteria shall prevent abandoned programs from becoming unmanaged records, shadow programs, stale dashboards, stale public claims, or uncontrolled repositories.

333.22 Program Closeout Report. A program closeout report shall be prepared where risk, duration, external involvement, public authority involvement, sponsor or provider involvement, publication, technical asset creation, data processing, AI use, cyber sensitivity, community safeguards, finance-sensitive context, or Nexus interface significance warrants. The closeout report shall identify what occurred, what did not occur, outputs, limitations, open issues, corrections, incidents, stakeholder notices, records disposition, access revocation, publication status, successor activities, and lessons learned. Closeout reports may be internal, controlled, restricted, public-safe, or public according to classification.

333.23 Program Correction and Supersession Path. Each program shall maintain a correction and supersession path for program records, outputs, publications, dashboards, maps, datasets, software releases, methods, baselines, training materials, public authority references, sponsor references, provider references, host references, evidence claims, and Nexus interface materials. Correction may be triggered by error, stale data, changed law, changed public authority term, protected knowledge concern, privacy issue, AI hallucination, cyber issue, infrastructure exposure, finance overclaim, certification implication, procurement implication, provider preference, sponsor control implication, or public-safe issue. Supersession shall preserve traceability.

333.24 Program Intake, Scope, Milestone, KPI, and Closeout Records. GCRI Canada shall maintain program intake, scope, milestone, KPI, and closeout records, including intake records, scope statements, purpose statements, authority statements, public-benefit rationales, non-execution boundary statements, Nexus role-separation statements, stakeholder maps, risk class records, data class records, AI-use class records, cyber class records, public authority class records, safeguards class records, finance boundary class records, milestone records, acceptance gate records, KPI and KRI records, deliverable records, publication posture records, closeout criteria, closeout reports, correction paths, supersession paths, notices, lessons learned, and archives.


Section 334. National Readiness Programs

334.1 National Readiness Program Purpose. GCRI Canada may support national readiness programs as public-benefit, evidence-based, method-governed, non-executing programs that help a national context understand, organize, improve, and document readiness for public-good research, evidence architecture, methods discipline, observability, ontology, semantic interoperability, data governance, AI governance, cybersecurity, public authority learning, community safeguards, Nexus Observatory participation, technical baseline adoption, public-good software use, Nexus Universe participation, docket discipline, Grid evidence support, and finance-readiness evidence support without finance-readiness determination. National readiness programs shall support capacity and clarity, not national execution, public authority delegation, procurement approval, public finance approval, sovereign obligation, certification, recognition, or maturity guarantee.

334.2 National Evidence Readiness. National evidence readiness may assess or support whether a national context has evidence records, source lineage, evidence classifications, confidence notes, limitation notes, public authority data terms, community evidence safeguards, technical evidence inputs, correction pathways, controlled annexes, public-safe summaries, and public-good evidence practices sufficient to support public-benefit learning and Nexus-compatible interfaces. National evidence readiness shall not determine recognition, maturity, finance-readiness, procurement eligibility, public authority approval, or project approval. Evidence gaps shall be recorded as gaps, not concealed by narrative.

334.3 National Methods Readiness. National methods readiness may assess or support whether a national context has appropriate methods for research, evidence review, observability, ontology, data governance, AI governance, cybersecurity, public-safe publication, public authority learning, community safeguards, benchmarking, capability mapping, host activation, adoption windows, replication sprints, and correction. Methods readiness shall identify method availability, applicability, localization needs, limitations, review status, versioning, and correction path. Methods readiness shall not certify implementation or approve providers.

334.4 National Observability Readiness. National observability readiness may assess or support the capability to design, govern, and interpret public-safe observability methods, telemetry structures, sensing methods, AI-RAN / O-RAN observability, DePIN observability, geospatial evidence, Earth observation, digital twins, degraded-mode awareness, resilience indicators, dashboards, maps, source lineage, and public-safe intelligence outputs. National observability readiness shall be subject to privacy, cyber, infrastructure, public authority, protected knowledge, and public-safe mapping controls. It shall not create public warning, emergency command, infrastructure operation, or public authority decision authority.

334.5 National Ontology and Semantic Readiness. National ontology and semantic readiness may assess or support the presence of controlled vocabularies, taxonomies, schemas, data dictionaries, risk ontologies, maturity concepts, evidence classifications, technology-family terms, public authority capacity terms, finance-boundary terms, certification-boundary terms, recognition-boundary terms, AI-readable knowledge structures, compatibility notes, divergence logs, and localization pathways. Semantic readiness shall support interoperability and claims discipline, not legal equivalence, certification, recognition, finance-readiness, procurement approval, or public authority adoption.

334.6 National Data Governance Readiness. National data governance readiness may assess or support lawful basis, data classification, data rights, privacy, retention, deletion, access controls, localization, cross-border transfer, compute-to-data, public authority terms, protected knowledge protocols, community safeguards, public-safe release, data room discipline, and correction pathways. National data governance readiness shall not authorize data collection, data sharing, AI use, publication, or transfer absent lawful authority and recorded approvals. Readiness support shall not override national law, public authority terms, Indigenous or community protocols, or privacy rights.

334.7 National AI Governance Readiness. National AI governance readiness may assess or support model registers, AI-use rules, model cards, dataset cards, system cards, benchmark cards, inference records, human review, hallucination controls, prompt injection controls, data leakage controls, bias review, drift review, retrieval controls, embedding controls, agentic AI controls, public-safe AI outputs, AI incident response, and correction paths. National AI governance readiness shall not certify AI systems, approve AI products, issue public authority AI approvals, provide regulated professional advice, or authorize deployment by GCRI Canada.

334.8 National Cybersecurity Readiness. National cybersecurity readiness may assess or support secure architecture, minimum cybersecurity baselines, repository security, secure development, vulnerability management, incident response, secrets control, access control, logging, monitoring, secure release, SBOMs, dependency review, public repository hygiene, cyber-sensitive handling, and public-safe disclosure. National cybersecurity readiness shall not constitute cybersecurity certification, insurance-readiness, underwriting approval, procurement approval, public authority approval, or security guarantee.

334.9 National Public Authority Learning Readiness. National public authority learning readiness may assess or support whether public authorities, public-sector readers, regulators, public finance readers, emergency management bodies, public infrastructure operators, public health bodies, public safety bodies, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, and cyber bodies can access appropriate evidence literacy, methods literacy, data / AI / cyber literacy, observability literacy, public-safe publication literacy, and boundary literacy. Such readiness shall preserve capacity classification and shall not create public authority delegation, official adoption, public warning, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, or sovereign obligation.

334.10 National Community Safeguards Readiness. National community safeguards readiness may assess or support safeguards for community-protected data, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, protected participants, youth, vulnerable persons, remote communities, public-safe mapping risk, attribution, non-extraction, consent or authorization, custodial authority, withdrawal rights, correction rights, and harm prevention. Such readiness shall not convert protected knowledge into open data or substitute GCRI Canada judgment for community or custodial authority.

334.11 National Observatory Readiness. National Observatory readiness may assess or support a national context’s ability to participate in Nexus Observatory methods through public-safe observability, node methods, hub methods, cluster methods, hotspot methods, national dense core concepts, regional cluster concepts, AI-RAN / O-RAN evidence methods, DePIN evidence methods, sensor methods, digital twin methods, geospatial methods, cyber methods, sovereign compute evidence methods, proof traceability, verifiable intelligence, and correction records. National Observatory readiness shall not make GCRI Canada an Observatory operator, emergency commander, public warning issuer, infrastructure manager, public authority, certifier, or finance-readiness decision-maker.

334.12 National Technical Baseline Readiness. National technical baseline readiness may assess or support whether a national context can understand, adopt, localize, test, contribute to, or align with public-good technical baselines, open technical baselines, reference baselines, evidence baselines, Observatory baselines, AI governance baselines, data governance baselines, cybersecurity baselines, interoperability baselines, and conformance-supporting baselines. Such readiness shall include versioning, licensing, known limitations, localization, public-safe review, and correction path. It shall not create compliance approval, certification, procurement mandate, public authority adoption, finance-readiness, or provider preference.

334.13 National Public-Good Software Readiness. National public-good software readiness may assess or support the capability to use, test, contribute to, localize, secure, document, or maintain public-good software, APIs, SDKs, schemas, dashboards, test harnesses, benchmark tools, reference implementations, observability tools, Truth Engine-supporting tools, verifiable compute tools, and public-safe publication tools. Such readiness shall be governed by licensing, repository security, secure development, dependency review, public-safe release, contribution rules, and correctionability. It shall not create operational support obligations, managed service obligations, procurement approval, provider preference, certification, or warranty.

334.14 National Nexus Universe Participation Readiness. National Nexus Universe participation readiness may assess or support whether a national context can participate in Nexus Universe concepts, public-good rails, two-stack discipline, national and regional interfaces, public authority learning, Observatory methods, Academy pathways, Competence Cells, National Working Groups, National Nexus Consortiums, Regional Nexus Consortiums, National Consortium Companies, Project SPVs, and related global-to-local architecture while preserving role separation and legal separateness. Participation readiness shall not create merger, agency, shared treasury, shared liability, public authority delegation, execution authority, finance authority, certification authority, procurement authority, or provider preference.

334.15 National Docket and Grid Evidence Support Readiness. National docket and Grid evidence support readiness may assess or support whether a national context can produce, organize, classify, update, correct, and transmit evidence inputs, methods inputs, observability inputs, technical baseline inputs, public-good software inputs, compatibility notes, divergence logs, and correction signals for activation dockets and Nexus Grid-related evidence surfaces where separately governed. Such support shall not determine Grid maturity, recognition, standing, public legitimacy, finance-readiness, procurement approval, certification, or performance guarantee.

334.16 National Finance-Readiness Evidence Support Without Finance-Readiness Determination. National readiness programs may support national finance-readiness evidence support only by organizing technical evidence inputs, methods records, observability records, public-good baselines, proof pack structures, public-safe summaries, and finance-boundary literacy for separate competent processes. GCRI Canada shall not determine finance-readiness, insurance-readiness, bankability, investability, lending readiness, underwriting approval, rating, public finance approval, capital commitment, or investor suitability. All finance-related national readiness materials shall include non-reliance and regulated-perimeter language where material.

334.17 No National Readiness Program as National Mandate, Procurement Approval, Public Finance Approval, Public Authority Adoption, or Sovereign Obligation. No national readiness program shall constitute or be represented as a national mandate, public authority mandate, public authority adoption, public policy approval, regulatory approval, public warning, emergency command, procurement approval, provider selection, public finance approval, funding approval, public-private partnership, sovereign obligation, national certification, national recognition, maturity status, Grid guarantee, finance-readiness, or execution authority. National readiness is a public-benefit capability and evidence-support posture only, subject to correction and limitation.

334.18 National Readiness Program Records. GCRI Canada shall maintain national readiness program records, including national readiness purpose records, national evidence readiness records, national methods readiness records, national observability readiness records, national ontology and semantic readiness records, national data governance readiness records, national AI governance readiness records, national cybersecurity readiness records, national public authority learning readiness records, national community safeguards readiness records, national Observatory readiness records, national technical baseline readiness records, national public-good software readiness records, national Nexus Universe participation readiness records, national docket and Grid evidence support readiness records, national finance-readiness evidence support records, no-mandate / no-procurement / no-public-finance / no-public-authority-adoption / no-sovereign-obligation records, corrections, supersessions, closeouts, and archives.


Section 335. Host Institution Activations

335.1 Host Institution Activation Purpose. GCRI Canada may support host institution activations as public-benefit, evidence-based, method-governed, non-executing pathways through which a university, laboratory, public authority, community institution, infrastructure institution, research institution, nonprofit institution, private host, public-good facility, controlled-room host, data room host, Academy host, Observatory-related host, technical testing host, or other eligible host may participate in approved GCRI Canada programs. Host activations shall support research, evidence readiness, methods readiness, observability readiness, technical baseline compatibility, public-good software learning, public authority learning, Academy learning, community safeguards, data / AI / cyber readiness, and Nexus-compatible public-good participation without creating GCRI Canada operational control, host endorsement, procurement preference, finance-readiness, certification, recognition, public warning, or public authority delegation.

335.2 Host Eligibility Review. Host eligibility review shall determine whether a proposed host is suitable for the proposed program class, risk class, data class, AI-use class, cyber class, public authority class, safeguards class, finance-boundary class, technical asset class, and publication posture. Review shall consider legal status, governance, facilities, security, safety, data handling capacity, confidentiality capacity, public authority context, community context, protected knowledge obligations, cyber posture, infrastructure sensitivity, conflicts, sponsor or provider relationships, public reference risks, and ability to comply with GCRI Canada’s non-execution, role separation, public-safe, and correctionability requirements.

335.3 Host Capacity Classification. Each host activation shall classify the host’s capacity, including whether the host acts as facility host, research host, Academy host, public authority host, community host, data room host, controlled-room host, technical testing host, Observatory-supporting host, infrastructure host, software testing host, learning host, sponsor-supported host, provider-supported host, public authority learning host, or other defined capacity. Host capacity classification shall determine permitted activities, prohibited activities, access rights, public references, records, confidentiality, data rights, publication rights, and boundaries. Host status shall not imply approval, endorsement, public authority delegation, provider preference, finance-readiness, procurement approval, certification, recognition, or maturity.

335.4 Host Site, Facility, System, Data, Safety, Cybersecurity, and Public Authority Context Review. Host activation shall include review of relevant site, facility, system, data, safety, cybersecurity, and public authority context. Review may include physical site sensitivity, access control, health and safety, cybersecurity posture, network exposure, data storage, public authority presence, infrastructure sensitivity, AI-RAN / O-RAN or DePIN presence, sensor presence, digital twin relevance, geospatial sensitivity, public-safe mapping risk, emergency-management context, public authority terms, insurance or liability context, and incident procedures. GCRI Canada shall not assume responsibility for host operations unless separately and lawfully contracted within non-execution boundaries.

335.5 Host Evidence Readiness. Host evidence readiness may assess or support whether a host can provide, receive, maintain, classify, protect, and correct evidence records relevant to an approved program. Host evidence readiness may include source records, facility records, data records, public authority terms, technical records, observability records, baseline records, access logs, safety records, cyber records, limitation notes, confidence notes, and correction path. Host evidence readiness shall not approve the host, certify the host, determine host maturity, determine host finance-readiness, or provide procurement preference.

335.6 Host Observability Readiness. Host observability readiness may assess or support whether a host can participate in observability methods, telemetry structures, dashboard methods, map methods, sensor methods, AI-RAN / O-RAN methods, DePIN methods, digital twin methods, geospatial methods, degraded-mode awareness methods, cyber telemetry methods, resilience indicator methods, public-safe observability outputs, and correction records. Host observability readiness shall be governed by privacy, public authority terms, cyber and infrastructure sensitivity, protected knowledge, public-safe mapping, and non-warning controls. It shall not make GCRI Canada or the host an emergency command authority through GCRI Canada activation.

335.7 Host Technical Baseline Compatibility. Host technical baseline compatibility may assess or support whether host systems, data structures, workflows, facilities, software, dashboards, schemas, APIs, evidence records, observability methods, cybersecurity controls, AI governance controls, or public-safe publication processes can align with GCRI Canada public-good baselines or Nexus-compatible baselines. Compatibility shall be specific, versioned, limitation-bearing, and correctionable. Technical baseline compatibility shall not constitute certification, compliance approval, public authority approval, procurement approval, finance-readiness, insurance-readiness, provider preference, or performance warranty.

335.8 Host Data / AI / Cyber Readiness. Host data / AI / cyber readiness may assess or support host capability for lawful data handling, privacy, access control, data rooms, controlled rooms, AI-use controls, model and provider terms, retrieval controls, embedding restrictions, cyber controls, secure storage, repository controls, vulnerability handling, incident response, localization, cross-border transfer, compute-to-data, public-safe release, and correctionability. Host readiness support shall not authorize the host to upload restricted materials to unapproved AI systems, use shadow IT, bypass privacy or public authority terms, or treat GCRI Canada review as cybersecurity certification.

335.9 Host Community Safeguards and Protected Knowledge Review. Host activation shall include community safeguards and protected knowledge review where the host context involves Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, community-protected data, protected participants, youth, vulnerable persons, remote communities, health-sensitive groups, public-safe mapping risk, or community-sensitive evidence. Review shall address custodial authority, consent or authorization, attribution, non-extraction, AI-use restrictions, publication limits, access controls, withdrawal rights, correction rights, and harm prevention. Host convenience shall not override safeguards.

335.10 Host Public-Safe Publication Posture. Each host activation shall identify public-safe publication posture, including whether the host name, site, facility, photographs, public authority references, sponsor references, provider references, technical findings, evidence summaries, observability outputs, dashboards, maps, datasets, software releases, Academy materials, or closeout summaries may be public, public-safe, controlled, restricted, internal-only, embargoed, or not publishable. Host publicity shall require permission where needed and shall not imply endorsement, approval, public authority adoption, procurement approval, finance-readiness, certification, recognition, maturity, or public warning.

335.11 Host Provider and Sponsor Boundary Review. Host activations involving providers, sponsors, donors, funders, technology vendors, cloud providers, AI providers, telecom providers, AI-RAN providers, O-RAN providers, DePIN providers, cyber providers, software providers, data providers, consultants, or contractors shall undergo provider and sponsor boundary review. Review shall prevent sponsor control, provider preference, procurement advantage, public authority access purchase, research outcome purchase, recognition purchase, certification influence, finance-readiness influence, improper private benefit, market distortion, and misleading public claims. Host activation shall not convert a provider contribution into GCRI Canada endorsement.

335.12 Host Activation Agreement. A host activation agreement, memorandum, program record, docket record, controlled-room rule set, data-sharing instrument, facility-use agreement, research agreement, Academy agreement, or other competent record shall govern host activation where risk requires it. The agreement or record shall define purpose, scope, roles, permitted activities, prohibited activities, data rights, IP rights, confidentiality, safety, security, access, public authority terms, protected knowledge safeguards, AI-use restrictions, publication rights, public references, sponsor and provider boundaries, liability, insurance where applicable, termination, closeout, data disposition, and correction path. No host activation shall rely solely on informal understanding where material risk exists.

335.13 Host Activation Without GCRI Canada Operational Control Unless Separately and Lawfully Contracted Within Non-Execution Boundaries. Host activation shall not give GCRI Canada operational control over host facilities, host systems, host networks, host infrastructure, host personnel, host public authority functions, host emergency functions, host procurement, host finance, host safety operations, host cyber operations, host data systems, or host provider relationships unless a separate lawful contract expressly provides a limited, non-executing support role consistent with GCRI Canada’s public-benefit purpose and this Bylaw. Even where contracted support exists, GCRI Canada shall not assume public authority, emergency command, procurement, finance, certification, or provider-selection authority.

335.14 Host Activation Without Procurement Preference, Public Authority Endorsement, Finance-Readiness Determination, Certification, Recognition, or Public Warning. No host activation, host readiness review, host evidence record, host observability record, host baseline compatibility note, host public-safe summary, host dashboard, host map, host Academy activity, host lab, host pilot, host adoption window, host replication sprint, host challenge, host benchmarking activity, or host closeout shall constitute procurement preference, public authority endorsement, finance-readiness determination, insurance-readiness determination, investment suitability, bankability, rating, public finance approval, certification, accreditation, compliance approval, recognition, standing, maturity, public warning, emergency command, operational instruction, or public authority decision. Required limitation language shall be included where material.

335.15 Host Activation Closeout. Host activation closeout shall identify completion status, deliverables, non-deliverables, evidence records, methods records, host readiness records, data / AI / cyber records, safeguards records, public authority boundary records, provider and sponsor boundary records, publication status, open issues, limitations, incidents, corrections, data disposition, access revocation, equipment or asset disposition where any, repository status, dashboard or map status, successor activity, and archive status. Host closeout shall not be described as certification, procurement approval, finance-readiness, recognition, maturity, or host endorsement.

335.16 Host Activation Records. GCRI Canada shall maintain host activation records, including host activation purpose records, host eligibility reviews, host capacity classifications, site / facility / system / data / safety / cybersecurity / public authority context reviews, host evidence readiness records, host observability readiness records, host technical baseline compatibility records, host data / AI / cyber readiness records, host community safeguards and protected knowledge reviews, host public-safe publication posture records, host provider and sponsor boundary reviews, host activation agreements or equivalent records, non-operational-control records, no-procurement-preference / no-public-authority-endorsement / no-finance-readiness / no-certification / no-recognition / no-public-warning records, closeout records, correction records, incident records, data disposition records, access revocation records, supersessions, terminations, and archives.

Section 336. Adoption Window Programs

336.1 Adoption Window Program Purpose. GCRI Canada may establish adoption window programs as time-bound, public-benefit, evidence-based, method-governed, non-executing pathways through which eligible participants may learn, review, test, localize, compare, document, or prepare to use GCRI Canada public-good methods, evidence structures, observability methods, ontology materials, public-good software, open technical baselines, data / AI / cyber controls, public-safe publication methods, Academy materials, competence-cell materials, or Nexus-compatible interface practices. Adoption windows shall exist to support disciplined learning, readiness, interoperability, correctionability, and safe institutional adoption of public-good technical architecture, and shall not be used to create procurement preference, provider advantage, sponsor control, certification, recognition, maturity status, finance-readiness, public authority delegation, public warning, or enterprise execution by GCRI Canada.

336.2 Adoption Window as Time-Bound Learning and Readiness Pathway. An adoption window shall be limited by a defined opening date, closing date, purpose, scope, participant category, eligible materials, permitted activities, review gates, support channels, records, public-safe posture, and closeout requirements. An adoption window may permit participants to review methods, test software, evaluate schemas, study baselines, align internal processes, train staff, participate in Academy modules, provide feedback, report issues, document implementation questions, or prepare compatibility notes. An adoption window shall not represent that any participant has completed certification, received approval, obtained procurement qualification, achieved maturity, become finance-ready, or acquired official Nexus status.

336.3 Adoption Window Eligibility. Eligibility for an adoption window shall be determined according to program purpose, participant capacity, legal status, public-benefit relevance, data class, AI-use class, cyber class, public authority class, safeguards class, finance-boundary class, technical capacity, security posture, conflict status, and ability to comply with applicable terms. Eligible participants may include universities, laboratories, public authorities, public-sector readers, nonprofit institutions, community bodies, hosts, technical contributors, competence cells, National Working Groups, consortium participants, providers under provider-neutral rules, sponsors under support-without-control rules, and other approved actors. Eligibility shall not imply endorsement, preferred status, public authority approval, provider selection, finance-readiness, recognition, maturity, or certification.

336.4 Adoption Window Scope. Each adoption window shall have a written scope identifying the materials, methods, software, baselines, learning modules, dashboards, datasets, schemas, technical profiles, evidence packs, Academy materials, competence-cell materials, or Nexus interface practices included in the window. Scope shall identify what participants may do, what they may not do, what outputs may be created, what records shall be kept, what public references are permitted, what data may be processed, what AI use is permitted, what publication posture applies, and what closeout requires. Scope shall be narrow enough to prevent adoption drift into execution, procurement, public authority action, finance-readiness, certification, recognition, maturity, or provider endorsement.

336.5 Adoption Window Technical Baseline Review. Where an adoption window involves open technical baselines, public-good baselines, reference architectures, schemas, interoperability profiles, evidence profiles, Observatory profiles, AI governance profiles, cybersecurity profiles, public-safe publication profiles, or Nexus-compatible baselines, GCRI Canada shall review technical baseline status before inclusion. Review shall identify baseline owner, version, license, intended use, prohibited use, security posture, dependency status, public-safe status, localization needs, known limitations, correction path, and supersession status. Technical baseline participation shall not mean that a participant’s implementation is approved, certified, compliant, procurement-ready, finance-ready, public authority-adopted, or performance-warranted.

336.6 Adoption Window Evidence and Methods Review. Adoption windows involving evidence or methods shall identify applicable evidence records, methods records, source lineage, assumptions, classifications, confidence notes, limitation notes, public-safe status, reviewer status, localization issues, and correction paths. Participants may provide feedback, identify gaps, test examples, submit questions, or document implementation challenges, but such activity shall not convert participant feedback into official evidence, recognition, maturity, public authority approval, finance-readiness, procurement approval, certification, or provider preference unless a separate competent process lawfully adopts the output.

336.7 Adoption Window Public-Good Software Review. Where an adoption window includes public-good software, APIs, SDKs, schemas, dashboards, tools, test harnesses, reference implementations, benchmark utilities, repository materials, packages, or technical assets, GCRI Canada shall review licensing, repository status, release status, documentation, dependency status, security posture, vulnerability disclosure path, contribution terms, known limitations, public-safe status, and correction path. Participants shall be informed that software is provided according to its license and limitations, and that adoption-window participation does not create warranty, managed service obligation, operational support obligation, certification, procurement approval, provider preference, or public authority approval.

336.8 Adoption Window Data / AI / Cyber Review. Adoption windows involving data, AI, cyber, dashboards, maps, models, retrieval systems, embeddings, vector stores, public authority data, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, controlled technology, or public-safe outputs shall undergo data / AI / cyber review. Review shall identify approved systems, prohibited systems, AI-use limits, model-training restrictions, data rights, privacy, access controls, secure storage, repository rules, cross-border transfer issues, localization, compute-to-data requirements where applicable, public-safe publication status, incident response, and correction path. Restricted materials shall not be processed through unapproved tools, informal AI systems, shadow IT, or unlogged storage.

336.9 Adoption Window Public Authority and Public-Safe Claims Review. Adoption windows involving public authorities, public-sector participants, public finance readers, regulators, emergency-management bodies, public infrastructure operators, public authority data, or public authority-facing materials shall undergo public authority and public-safe claims review. Review shall classify public authority capacity, permitted references, non-endorsement language, no-delegation language, no-public-warning language, no-emergency-command language, no-regulatory-approval language, no-procurement-approval language, no-funding-approval language, no-public-finance-approval language, and no-sovereign-obligation language. Public-safe claims shall be evidence-supported, method-bound, limitation-bearing, and correctionable.

336.10 Adoption Window Provider Neutrality. Provider participation in an adoption window shall be governed by provider neutrality. Providers may participate as technical contributors, users, reviewers, demonstrators, maintainers, or learners only under recorded rules that prevent provider preference, procurement advantage, certification implication, public authority access purchase, finance-readiness influence, benchmark manipulation, proprietary lock-in, or use of GCRI Canada materials as marketing endorsement. Adoption-window materials shall not rank, endorse, approve, certify, select, prefer, or promote providers unless a separate lawful and competent process expressly authorizes limited factual reference.

336.11 Adoption Window Sponsor Non-Control. Sponsor, donor, or funder support for an adoption window shall be support-without-control. No sponsor, donor, funder, host, provider, or partner shall control participant selection, evidence outcomes, methods conclusions, technical baseline content, software releases, publication posture, correction decisions, public authority access, provider references, finance-boundary language, certification-boundary language, or program closeout. Sponsor acknowledgments shall be factual, proportionate, non-promotional where required, and subject to approved language and benefit schedules where applicable.

336.12 Adoption Window Records of Participation. GCRI Canada may maintain records of participation in an adoption window, including participant identity, institutional capacity, attendance, modules accessed, materials reviewed, feedback submitted, issues reported, questions answered, software tested, baselines reviewed, completion of internal learning steps, and closeout status. Participation records shall be administrative and evidentiary only. They shall not constitute professional certification, regulated credential, public authority qualification, procurement eligibility, provider approval, finance-readiness, recognition, maturity status, or authority to speak for GCRI Canada.

336.13 Adoption Window Outputs as Non-Certifying and Non-Procurement. Outputs from an adoption window, including notes, reports, feedback summaries, technical issue logs, implementation questions, compatibility notes, baseline comments, software test notes, learning records, dashboards, maps, datasets, public-safe summaries, and closeout reports, shall be non-certifying and non-procurement by default. Such outputs may support learning, correction, interoperability, evidence improvement, methods refinement, and public-benefit capacity, but shall not approve vendors, qualify bidders, select providers, certify implementations, accredit participants, create procurement requirements, or determine compliance.

336.14 Adoption Window No Recognition, Finance-Readiness, or Maturity Determination by GCRI Canada. No adoption window shall constitute GRF recognition, Nexus Grid maturity, standing, public legitimacy, finance-readiness, insurance-readiness, bankability, investability, public finance approval, rating, underwriting approval, lending approval, certification, accreditation, provider preference, public authority adoption, or public authority approval. GCRI Canada may record that a participant engaged in a window, reviewed materials, completed learning steps, submitted feedback, or received public-good support, but shall not characterize such participation as recognition, maturity, finance-readiness, or approval.

336.15 Adoption Window Correction and Closeout. Each adoption window shall remain correctionable and shall close through recorded closeout. Correction may be triggered by source error, method error, baseline error, software vulnerability, data-rights issue, AI hallucination, public authority misdescription, sponsor or provider overclaim, protected knowledge issue, privacy issue, cyber issue, infrastructure-sensitive exposure, finance overclaim, certification implication, procurement implication, or public-safe publication issue. Closeout shall identify participants, materials, outputs, limitations, open issues, corrections, supersessions, publication posture, data disposition, access revocation, repository status, lessons learned, and archive status.

336.16 Adoption Window Records. GCRI Canada shall maintain adoption window records, including adoption window purpose records, time-bound learning and readiness pathway records, eligibility records, scope records, technical baseline review records, evidence and methods review records, public-good software review records, data / AI / cyber review records, public authority and public-safe claims review records, provider neutrality records, sponsor non-control records, records of participation, non-certifying and non-procurement output records, no-recognition / no-finance-readiness / no-maturity records, correction records, closeout records, supersessions, withdrawals, notices, lessons learned, and archives.


Section 337. Replication and Validation Sprints

337.1 Replication Sprint Purpose. GCRI Canada may establish replication sprints as time-bound, method-governed, evidence-based activities designed to reproduce, re-run, verify traceability, compare, test, document, or challenge evidence, methods, software, datasets, models, benchmarks, Observatory signals, sensor outputs, geospatial outputs, public-good baselines, or other technical artifacts. Replication sprints shall support public-benefit research integrity, evidence discipline, reproducibility, correctionability, and technical quality. Replication sprint participation or results shall not certify, approve, rank, endorse, finance, procure, recognize, or determine maturity of any participant, provider, host, project, technology, implementation, or public authority context.

337.2 Validation Sprint Purpose. GCRI Canada may establish validation sprints as controlled, bounded, non-certifying activities designed to assess whether evidence, methods, software, datasets, models, benchmarks, baselines, dashboards, maps, AI-RAN / O-RAN methods, DePIN records, digital twin outputs, cyber methods, geospatial methods, compute records, or public-safe outputs satisfy predefined validation criteria for a stated public-benefit purpose. Validation sprints shall validate within defined scope only and shall not create certification, accreditation, compliance approval, procurement approval, finance-readiness, public authority approval, recognition, maturity, or performance warranty.

337.3 Sprint Scope. Each replication or validation sprint shall have a written scope identifying the artifact, question, method, evidence, data, software, model, signal, baseline, dashboard, map, benchmark, participant role, permitted activities, prohibited activities, criteria, risks, systems, access controls, publication posture, and closeout. Scope shall identify whether the sprint concerns reproduction, verification, validation, stress testing, negative testing, failure capture, comparison, localization, public-safe transformation, or correction. Scope changes shall be recorded and shall not occur informally.

337.4 Sprint Eligibility. Sprint eligibility shall be determined according to technical competence, role, independence, conflict status, confidentiality capacity, data rights, security posture, AI-use permissions, public authority capacity, safeguards obligations, provider relationship, sponsor relationship, and ability to follow sprint rules. Participants may include GCRI Canada staff, fellows, technical contributors, researchers, universities, laboratories, public authority learners, community reviewers, providers under neutrality controls, hosts, and other approved actors. Eligibility shall not imply certification, endorsement, procurement status, or official standing.

337.5 Evidence Replication. Evidence replication may involve rechecking sources, source lineage, provenance, timestamps, classifications, confidence notes, limitation notes, contradiction records, stale-source flags, public authority capacity records, protected knowledge status, data rights, and correction paths. Evidence replication shall distinguish successful replication, partial replication, failed replication, inconclusive replication, source unavailable, source changed, source restricted, method mismatch, and insufficient information. Replication status shall not be overclaimed as absolute truth or public authority approval.

337.6 Method Replication. Method replication may involve reapplying a method, comparing method steps, testing assumptions, checking inputs, confirming exclusions, reproducing outputs, comparing reviewers, evaluating uncertainty treatment, assessing localization effects, and identifying correction needs. Method replication shall be version-specific and limitation-bearing. A method that replicates within sprint scope shall not be represented as universally valid, legally compliant, certified, finance-ready, procurement-ready, provider-preferred, or public authority-adopted.

337.7 Software Replication. Software replication may involve building, installing, running, testing, comparing, containerizing, checking dependencies, reproducing outputs, verifying release artifacts, reviewing licenses, checking vulnerabilities, validating documentation, or confirming repository provenance for public-good software, internal software, restricted software, APIs, SDKs, schemas, dashboards, tools, test harnesses, benchmark tools, or reference implementations. Software replication shall be subject to repository security, secure release, data rights, license, dependency, public-safe, and vulnerability controls. Successful replication shall not create warranty, certification, procurement approval, or managed service obligation.

337.8 Technical Baseline Replication. Technical baseline replication may involve testing whether a baseline, profile, schema, reference architecture, evidence profile, Observatory profile, AI governance profile, cybersecurity profile, data governance profile, or interoperability profile can be interpreted, implemented, localized, or compared within stated conditions. Replication shall record version, dependencies, assumptions, deviations, compatibility notes, divergence logs, and correction path. Baseline replication shall not certify implementation or approve public authority use.

337.9 Dataset, Model, Benchmark, and Evaluation Replication. Replication or validation of datasets, models, benchmarks, evaluation sets, model cards, dataset cards, system cards, benchmark cards, gold vectors, negative tests, and evaluation results shall require review of data rights, source lineage, licensing, privacy, protected knowledge, public authority terms, model identity, provider terms, training restrictions, benchmark secrecy, leakage risk, bias, drift, reproducibility, statistical validity, and correction path. Sprint outputs shall not be used as provider rankings, investment claims, procurement claims, certification claims, or public authority determinations.

337.10 Observatory Signal and Sensor Replication. Replication or validation of Observatory signals, sensor outputs, telemetry, AI-RAN signals, O-RAN signals, DePIN records, geospatial layers, Earth observation outputs, digital twin inputs, cyber telemetry, degraded-mode indicators, or resilience indicators shall require review of source reliability, calibration, timestamps, location sensitivity, infrastructure sensitivity, public authority terms, protected knowledge, data rights, uncertainty, public-safe mapping, and correction path. Signal replication shall not constitute official warning, emergency command, infrastructure operation, or public authority decision.

337.11 AI-RAN, DePIN, Digital Twin, Cyber, Geospatial, and Compute Validation. Validation involving AI-RAN, O-RAN, DePIN, digital twins, cyber tools, geospatial outputs, sovereign compute, verifiable compute, AI models, public-safe intelligence, or mission-critical systems shall be controlled according to sensitivity. Review shall address controlled technology, export controls, sanctions, national security, public-sector sensitivity, cyber risk, infrastructure risk, privacy, protected knowledge, model limitations, compute provenance, reproducibility, output classification, public-safe publication, and correction. Validation shall remain evidence and methods support, not execution authorization.

337.12 Reproducibility Criteria. Reproducibility criteria shall identify what must be reproduced, under what conditions, with what data, software, dependencies, environment, model, parameters, reviewer, confidence threshold, tolerance, and limitation. Criteria may include exact reproduction, statistical reproduction, qualitative reproduction, methodological reproduction, independent reproduction, source-trace reproduction, or controlled reproduction. Criteria shall be recorded before results are characterized as reproduced, partially reproduced, failed, or inconclusive.

337.13 Validation Criteria. Validation criteria shall identify the purpose, expected behaviour, evidence standard, methods standard, technical threshold, security requirement, public-safe condition, data-rights condition, AI-use condition, cyber condition, public authority boundary condition, safeguards condition, finance-boundary condition, and correction condition. Validation criteria shall be proportionate to sprint purpose and shall not be disguised certification criteria unless a separate lawful certification body and record exist.

337.14 Negative Test and Failure Capture. Replication and validation sprints shall capture negative tests, failed replications, unexpected behaviours, uncertainty, vulnerabilities, bias, hallucinations, drift, source conflicts, model failures, dashboard failures, map failures, public-safe failures, protected knowledge issues, privacy issues, cyber issues, infrastructure sensitivity, and boundary overclaims where discovered. Failure capture shall be treated as a public-benefit learning and correction mechanism. Failure records may be restricted where public disclosure would create misuse risk or unfair harm.

337.15 Sponsor, Provider, and Conflict Controls. Sprints involving sponsors, providers, donors, funders, hosts, vendors, National Consortium Companies, Project SPVs, or interested parties shall apply conflict controls, independence review, disclosure, recusal where appropriate, data-room restrictions, benchmark integrity controls, provider-neutral language, sponsor non-control language, and publication controls. No sponsor or provider shall control sprint criteria, suppress results, purchase validation language, influence public authority references, or convert sprint participation into endorsement.

337.16 Public-Safe Results Classification. Sprint results shall be classified before internal circulation, controlled sharing, public-safe summary, dashboard release, map release, software release, dataset release, public report, or Nexus interface use. Result classes may include internal, controlled, restricted, public-safe, public, embargoed, security-sensitive, public authority-limited, safeguards-limited, finance-boundary-limited, or not publishable. Classification shall consider evidence strength, data rights, privacy, protected knowledge, cyber risk, infrastructure risk, public authority meaning, finance implication, certification implication, procurement implication, and provider-neutrality risk.

337.17 No Sprint Result as Certification, Procurement Approval, Provider Preference, Finance-Readiness, Recognition, or Public Authority Decision. No replication sprint, validation sprint, sprint result, sprint score, benchmark result, reproduction note, validation note, software test note, signal replication note, dashboard note, map note, dataset note, model evaluation, or closeout report shall constitute certification, accreditation, compliance approval, procurement approval, provider preference, vendor selection, finance-readiness, insurance-readiness, bankability, investability, rating, public finance approval, recognition, standing, maturity, Nexus Grid status, GRF recognition, public authority decision, public warning, emergency command, or execution instruction. Required limitation language shall be included where material.

337.18 Replication and Validation Sprint Records. GCRI Canada shall maintain replication and validation sprint records, including replication sprint purpose records, validation sprint purpose records, sprint scope records, eligibility records, evidence replication records, method replication records, software replication records, technical baseline replication records, dataset / model / benchmark / evaluation replication records, Observatory signal and sensor replication records, AI-RAN / DePIN / digital twin / cyber / geospatial / compute validation records, reproducibility criteria, validation criteria, negative test and failure records, sponsor / provider / conflict controls, public-safe results classifications, no-certification / no-procurement / no-provider-preference / no-finance-readiness / no-recognition / no-public-authority-decision records, corrections, supersessions, closeouts, and archives.


Section 338. Governed Pilot Programs

338.1 Governed Pilot Purpose. GCRI Canada may establish governed pilot programs as controlled, time-limited, public-benefit learning and evidence processes designed to test, observe, document, compare, refine, or evaluate methods, evidence workflows, observability methods, ontology structures, public-good software, open technical baselines, data / AI / cyber controls, public-safe publication practices, Academy materials, competence-cell methods, host activation methods, or Nexus-compatible interface practices. A governed pilot shall be structured to learn and correct, not to execute, deploy at scale, approve procurement, certify systems, determine finance-readiness, issue public warnings, command public authority action, or operate enterprise functions.

338.2 Pilot as Controlled Learning and Evidence Process. A pilot shall be treated as a controlled learning and evidence process with defined purpose, bounded scope, risk classification, participants, host or site context where applicable, evidence requirements, methods requirements, data / AI / cyber controls, safeguards controls, public authority controls, provider and sponsor controls, publication posture, stop-the-line criteria, closeout, and after-action review. Pilot findings shall be evidence and methods artifacts only and shall not be represented as final proof, operational approval, provider endorsement, public authority adoption, maturity, recognition, or investment suitability.

338.3 Pilot Eligibility. Pilot eligibility shall be determined according to program purpose, public-benefit rationale, host readiness, participant capacity, data rights, AI-use permissions, cyber posture, safeguards obligations, public authority context, finance-boundary risk, technical baseline relevance, provider involvement, sponsor involvement, legal compliance, and correctionability. Eligibility shall not imply approval, endorsement, certification, finance-readiness, procurement status, public authority support, or Nexus maturity. Ineligible or high-risk proposals may be denied, narrowed, deferred, routed to a controlled lab, or converted to a non-public internal study.

338.4 Pilot Charter. Each material pilot shall have a pilot charter identifying purpose, scope, authority, owner, custodian, participants, roles, duration, host context, stakeholder map, evidence requirements, method requirements, data / AI / cyber controls, privacy controls, safeguards controls, public authority controls, provider and sponsor controls, technical baseline controls, risk register, stop-the-line criteria, deliverables, publication posture, closeout criteria, incident path, correction path, and archive requirements. The pilot charter shall distinguish learning outputs from prohibited outputs, including certification, procurement approval, finance-readiness, public warning, public authority decision, provider endorsement, recognition, maturity, and execution instruction.

338.5 Pilot Scope and Limits. Pilot scope shall define permitted activities, prohibited activities, systems, datasets, models, tools, public-good software, baselines, dashboards, maps, sites, participants, timeframe, jurisdictions, outputs, and public references. Scope limits shall prevent pilot drift into operational deployment, production service, managed service, public authority function, emergency command, public warning, public procurement, investment solicitation, insurance placement, underwriting, certification, accreditation, recognition, or maturity determination. Any scope expansion shall require recorded review and approval.

338.6 Pilot Governance. Pilot governance shall identify the pilot owner, responsible officer, reviewers, committees, host contacts, data steward, AI steward, cyber steward, safeguards reviewer, public authority interface reviewer, finance-boundary reviewer, technical asset owner, publication reviewer, and escalation path where applicable. Governance shall include meeting records, decision records, access review, risk review, incident review, stop-the-line authority, correction authority, and closeout authority. Governance shall not create authority for participants, sponsors, providers, hosts, or public authorities to direct GCRI Canada conclusions.

338.7 Pilot Data, AI, Cyber, Privacy, and Security Controls. Pilots involving data, AI, cyber, models, retrieval, embeddings, dashboards, maps, sensors, AI-RAN, O-RAN, DePIN, digital twins, compute, public authority data, protected knowledge, personal information, cyber-sensitive data, infrastructure-sensitive data, health-sensitive data, finance-sensitive evidence, controlled technology, or public repositories shall apply data / AI / cyber / privacy and security controls. Controls shall include lawful basis, classification, access controls, approved tools, AI-use limits, model-training restrictions, encryption, logging, secure storage, localization, cross-border review, compute-to-data where required, incident response, and correction path.

338.8 Pilot Research Integrity Controls. Pilots involving research questions, studies, fieldwork, interviews, surveys, observations, datasets, model results, benchmark results, or research outputs shall apply research integrity controls. Such controls shall include method documentation, evidence sufficiency, ethics review where required, consent or authorization where required, data rights, attribution, conflicts, sponsor influence controls, provider influence controls, reproducibility where appropriate, limitations, negative result capture, failure capture, and correction or retraction pathways.

338.9 Pilot Public Authority Boundary Controls. Pilots involving public authorities, public authority hosts, public authority data, public authority personnel, public finance readers, regulators, emergency management bodies, public infrastructure operators, public health bodies, public safety bodies, or public-sector systems shall apply public authority boundary controls. Controls shall include capacity classification, no-delegation language, no-public-warning language, no-emergency-command language, no-regulatory-approval language, no-procurement-approval language, no-funding-approval language, no-public-finance-approval language, confidentiality, public reference permissions, and official-capacity verification where required.

338.10 Pilot Community Safeguards Controls. Pilots involving communities, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, remote communities, protected participants, youth, vulnerable persons, health-sensitive groups, community data, or public-safe mapping risk shall apply safeguards controls. Controls shall include custodial authority, consent or authorization, non-extraction, attribution limits, public-safe transformation, AI-use restrictions, publication limits, access controls, withdrawal rights, correction rights, harm-prevention measures, and community-sensitive closeout.

338.11 Pilot Provider and Sponsor Controls. Pilots involving sponsors, donors, funders, providers, vendors, hosts, contractors, consultants, cloud providers, AI providers, cybersecurity providers, telecom providers, AI-RAN providers, O-RAN providers, DePIN providers, software providers, data providers, National Consortium Companies, or Project SPVs shall apply provider and sponsor controls. Controls shall prevent sponsor control, provider preference, procurement advantage, certification influence, recognition purchase, finance-readiness influence, research outcome purchase, benchmark manipulation, public authority access purchase, and improper private benefit. Contributions shall be recorded and conflict-reviewed.

338.12 Pilot Technical Baseline Controls. Pilots involving technical baselines, open technical baselines, public-good baselines, reference architectures, schemas, APIs, SDKs, interoperability profiles, evidence profiles, Observatory profiles, AI governance profiles, cybersecurity profiles, public-safe publication profiles, test harnesses, or reference implementations shall apply baseline controls. Controls shall identify version, license, intended use, limitations, known issues, dependency status, security status, public-safe status, compatibility notes, divergence logs, and correction path. Baseline use in a pilot shall not certify or approve implementation.

338.13 Pilot Risk Register. Each material pilot shall maintain a risk register proportionate to risk. The risk register may include legal risk, public-benefit risk, data risk, AI risk, cyber risk, privacy risk, public authority risk, protected knowledge risk, community harm risk, infrastructure risk, health risk, finance-boundary risk, certification-boundary risk, procurement-boundary risk, provider-neutrality risk, sponsor-control risk, publication risk, operational drift risk, and reputational risk. Risk owners, mitigations, review dates, escalation triggers, and residual risk shall be recorded.

338.14 Pilot Stop-the-Line Criteria. Each material pilot shall define stop-the-line criteria. Stop-the-line may be triggered by privacy risk, data leakage, AI hallucination, unsafe AI output, cyber incident, public authority misdescription, protected knowledge concern, community harm risk, infrastructure exposure, public-safe mapping risk, sponsor or provider overreach, finance overclaim, certification implication, procurement implication, legal risk, safety risk, evidence failure, method failure, uncontrolled execution drift, or loss of lawful authority. Stop-the-line shall pause, restrict, re-scope, quarantine, or terminate pilot activity pending review.

338.15 Pilot Publication Posture. Each pilot shall identify publication posture before launch and review it before any external communication. Publication posture may be internal-only, controlled, restricted, public-safe summary, public report, public dataset, public dashboard, public map, public software release, public technical baseline, embargoed, or no-publication. Pilot publication shall be evidence-supported, method-bound, limitation-bearing, public-safe, and boundary-protected. Pilot publicity shall not imply approval, adoption, readiness, certification, procurement eligibility, finance-readiness, recognition, maturity, or provider preference.

338.16 Pilot Closeout and After-Action Review. Pilot closeout shall include after-action review where material. Closeout shall identify activities performed, activities not performed, evidence status, methods status, baseline status, data / AI / cyber status, privacy status, safeguards status, public authority boundary status, sponsor and provider boundary status, incidents, failures, negative results, lessons learned, corrections, open issues, deliverables, non-deliverables, data disposition, access revocation, publication status, successor activity, and archive status. After-action review shall strengthen future programs and shall not be marketed as certification or approval.

338.17 No Pilot as Deployment Approval, Procurement Approval, Certification, Finance-Readiness, Public Warning, Public Authority Decision, or Enterprise Execution by GCRI Canada. No governed pilot, pilot charter, pilot participation, pilot result, pilot report, after-action review, dashboard, map, software output, dataset output, evidence note, method note, baseline note, host record, or closeout record shall constitute deployment approval, production readiness approval, procurement approval, provider selection, certification, accreditation, compliance approval, finance-readiness, insurance-readiness, bankability, investability, underwriting approval, public finance approval, rating, public warning, emergency command, public authority decision, recognition, maturity determination, or enterprise execution by GCRI Canada. Required limitation language shall be included where material.

338.18 Governed Pilot Records. GCRI Canada shall maintain governed pilot records, including governed pilot purpose records, controlled learning and evidence process records, eligibility records, pilot charters, scope and limit records, governance records, data / AI / cyber / privacy / security control records, research integrity records, public authority boundary control records, community safeguards records, provider and sponsor control records, technical baseline control records, risk registers, stop-the-line records, publication posture records, closeout records, after-action reviews, no-deployment-approval / no-procurement / no-certification / no-finance-readiness / no-public-warning / no-public-authority-decision / no-enterprise-execution records, corrections, supersessions, withdrawals, terminations, and archives.


Section 339. Research Labs, Technical Labs, Controlled Labs, Challenge Labs, and Nexus Universe Labs

339.1 Lab Architecture Purpose. GCRI Canada may establish research labs, technical labs, controlled labs, challenge labs, Nexus Universe labs, Academy labs, public-good software labs, observability labs, ontology labs, data / AI / cyber labs, safeguards labs, public authority learning labs, and competence-cell labs as structured environments for public-benefit research, evidence development, methods testing, technical experimentation, public-good software work, open technical baseline development, learning, benchmarking, challenge activity, and controlled collaboration. Lab architecture shall support safe experimentation, capability formation, reproducibility, correctionability, and public-benefit technical stewardship without creating enterprise execution, product certification, procurement preference, finance-readiness, public authority delegation, public warning, or provider endorsement.

339.2 Research Labs. Research labs may conduct public-benefit research, literature review, field methods, evidence synthesis, data analysis, scenario work, public authority learning research, community safeguards research, observability research, AI governance research, cyber governance research, ontology research, and Nexus-compatible institutional research. Research labs shall operate under research integrity, ethics review where required, data rights, privacy, safeguards, public authority boundaries, conflict controls, publication controls, and correction paths. Research lab outputs shall be research and evidence artifacts, not certification, procurement approval, finance-readiness, recognition, maturity, or public authority decision.

339.3 Technical Labs. Technical labs may develop, test, compare, document, or maintain software, schemas, APIs, SDKs, dashboards, maps, test harnesses, benchmark assets, reference implementations, technical baselines, interoperability profiles, observability tools, Truth Engine-supporting tools, verifiable compute tools, AI governance tools, cybersecurity tools, and public-safe publication tools. Technical labs shall apply secure development, repository security, license review, dependency review, vulnerability management, controlled technology review, public-safe review, and release controls. Technical lab outputs shall not be represented as certified, procurement-approved, finance-ready, provider-preferred, or production-operated by GCRI Canada.

339.4 Controlled Labs. Controlled labs may be established for sensitive work involving restricted data, public authority data, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, health-sensitive data, finance-sensitive evidence, controlled technology, AI models, retrieval systems, embeddings, geospatial layers, digital twin inputs, AI-RAN / O-RAN materials, DePIN records, or sovereign-sensitive materials. Controlled labs shall apply room rules, access controls, no-download restrictions where appropriate, logging, confidentiality, AI-use limits, output review, export controls, sanctions review, incident response, and closeout. Controlled lab access shall be need-to-know and purpose-bound.

339.5 Challenge Labs. Challenge labs may organize controlled challenge activities, red-team activities, benchmark challenges, method challenges, data-quality challenges, AI hallucination challenges, prompt-injection challenges, cyber-resilience challenges, public-safe publication challenges, software challenges, interoperability challenges, observability challenges, and evidence-quality challenges. Challenge labs shall define challenge rules, eligibility, conflict controls, data access, scoring limitations, publication posture, failure capture, sponsor and provider controls, public-safe review, and correction path. Challenge results shall not be used as provider rankings, certification, procurement approval, finance-readiness, recognition, maturity, or public authority determination by default.

339.6 Nexus Universe Labs. Nexus Universe labs may support public-benefit exploration of Nexus-compatible architecture, including one rail / two stacks discipline, evidence records, methods records, Observatory methods, ontology alignment, public-good software, open technical baselines, Academy pathways, competence cells, activation dockets, National Working Group interfaces, Regional Nexus Consortium interfaces, National Nexus Consortium interfaces, GRA-facing technical evidence inputs, GRF-compatible claims discipline, Nexus Rails evidence inputs, and Nexus Grid evidence inputs. Nexus Universe labs shall preserve role separation, legal separateness, no merger, no shared treasury, no shared liability, non-execution, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, and correctionability.

339.7 Lab Charter. Each material lab shall have a lab charter identifying lab purpose, class, owner, custodian, authority, participants, eligibility, scope, permitted activities, prohibited activities, data classes, AI-use classes, cyber classes, public authority classes, safeguards classes, finance-boundary classes, IP terms, contribution terms, publication posture, access controls, safety and security rules, deliverables, closeout, correction path, and archive requirements. Lab charters shall distinguish experimentation, learning, research, and technical development from execution, certification, procurement, finance-readiness, recognition, maturity, public warning, or public authority decision.

339.8 Lab Scope. Lab scope shall identify research questions, technical questions, evidence questions, methods questions, software questions, baseline questions, observability questions, ontology questions, challenge questions, learning questions, and Nexus interface questions included in the lab. Scope shall identify excluded activities, such as live operations, emergency response, public authority decisions, procurement activity, finance execution, insurance placement, underwriting, certification, provider selection, public warnings, and enterprise deployment by GCRI Canada. Scope changes shall require recorded review.

339.9 Lab Participants. Lab participants may include GCRI Canada personnel, fellows, researchers, technical contributors, maintainers, reviewers, university participants, laboratory participants, public authority learners, community participants, safeguards reviewers, providers under neutrality controls, sponsors under non-control terms, hosts, students, advisors, and other approved persons. Participants shall be classified by role, access, capacity, confidentiality, conflict status, contribution terms, public statement limits, data rights, AI-use permissions, and offboarding obligations. Participation shall not create governance rights or authority to bind GCRI Canada.

339.10 Lab Access Controls. Lab access shall be role-based, purpose-bound, least-privilege, time-limited where appropriate, logged where required, and aligned with classification. Access controls may include MFA, named-user access, device controls, no-download rooms, repository permissions, data room controls, controlled-room rules, access request approvals, conflict screening, public authority capacity controls, safeguards clearance where applicable, cyber restrictions, and offboarding. Access shall not be granted for convenience, seniority, sponsor interest, provider interest, public authority curiosity, or technical ability alone.

339.11 Lab Data / AI / Cyber Controls. Labs involving data, AI, cyber, repositories, dashboards, maps, models, retrieval, embeddings, vector stores, sensors, AI-RAN, O-RAN, DePIN, digital twins, compute, public authority data, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, health-sensitive data, finance-sensitive evidence, or controlled technology shall maintain data / AI / cyber controls. Controls shall include classification, lawful basis, data rights, AI-use authority, approved tools, model-training restrictions, secure storage, encryption, logging, prompt injection controls, data leakage controls, vulnerability controls, incident response, public-safe output review, and correction path.

339.12 Lab Safety and Security Controls. Labs shall maintain safety and security controls proportionate to physical, cyber, data, AI, infrastructure, public authority, community, legal, export-control, sanctions, and public-safe risk. Safety controls may include facility rules, equipment rules, physical access, health and safety, hazard controls, cyber safety, infrastructure safety, dual-use controls, controlled technology controls, public-safe disclosure controls, emergency contact rules, and incident procedures. Lab safety shall not make GCRI Canada an emergency command or infrastructure operator.

339.13 Lab Public Authority Controls. Labs involving public authorities, public authority personnel, public authority data, public finance readers, regulators, emergency management bodies, public infrastructure operators, public health bodies, public safety bodies, or public-sector hosts shall apply public authority controls. Controls shall include capacity classification, official-capacity verification where required, confidentiality, public reference permissions, no-delegation language, no-public-warning language, no-emergency-command language, no-regulatory-approval language, no-procurement-approval language, no-funding-approval language, no-public-finance-approval language, and no-sovereign-obligation language.

339.14 Lab Community Safeguards Controls. Labs involving communities, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, remote communities, protected participants, youth, vulnerable persons, health-sensitive groups, community data, or public-safe mapping risk shall apply community safeguards controls. Controls shall include custodial authority, consent or authorization, non-extraction, attribution limits, confidentiality, access restrictions, AI-use limits, publication limits, withdrawal rights, correction rights, public-safe transformation, geospatial protections, and harm-prevention measures.

339.15 Lab Provider and Sponsor Controls. Labs involving sponsors, donors, funders, providers, vendors, contractors, consultants, cloud providers, AI providers, cybersecurity providers, telecom providers, software providers, data providers, hosts, National Consortium Companies, or Project SPVs shall apply provider and sponsor controls. Controls shall prevent sponsor control, provider preference, procurement advantage, certification influence, recognition purchase, finance-readiness influence, research outcome purchase, benchmark manipulation, public authority access purchase, improper private benefit, market distortion, and misleading public claims. Contributions and benefits shall be recorded.

339.16 Lab Output Classification. Lab outputs shall be classified before circulation, external sharing, publication, repository placement, dashboard display, map display, dataset release, software release, public-safe summary, controlled summary, or Nexus interface use. Output classes may include internal, controlled, restricted, public-safe, public, embargoed, cyber-sensitive, infrastructure-sensitive, safeguards-limited, public authority-limited, finance-boundary-limited, experimental, superseded, deprecated, or archive-only. Classification shall determine access, handling, review, limitation language, and correction path.

339.17 Lab Publication Review. Lab publications, including reports, notes, papers, decks, dashboards, maps, datasets, software releases, benchmark results, challenge results, public-safe summaries, controlled summaries, public authority-facing materials, sponsor-facing materials, provider-facing materials, and Nexus interface materials, shall undergo publication review proportionate to risk. Review shall assess evidence support, methods support, data rights, AI use, cyber safety, privacy, public authority boundaries, protected knowledge, infrastructure sensitivity, finance-boundary risk, certification-boundary risk, procurement-boundary risk, provider neutrality, sponsor non-control, limitations, and correction path.

339.18 Lab IP and Contribution Terms. Lab participation shall be governed by IP and contribution terms where participants create, contribute, modify, test, document, review, or provide software, datasets, methods, schemas, models, prompts, benchmarks, documentation, technical baselines, evidence records, publications, or other work product. Terms may include contribution agreements, license grants, assignments where appropriate, moral rights treatment where applicable, confidentiality, data rights, patent disclosures, open-source disclosures, AI-use disclosures, conflict disclosures, attribution, publication review, and withdrawal or takedown procedures. Participation shall not create ownership or publication rights beyond recorded terms.

339.19 Lab Correction and Closeout. Labs shall remain correctionable and shall close or renew through recorded process. Correction may be triggered by source error, method error, software error, data-rights issue, privacy issue, protected knowledge concern, public authority misdescription, cyber issue, infrastructure-sensitive exposure, AI hallucination, benchmark defect, challenge defect, finance overclaim, certification implication, procurement implication, provider preference, sponsor control implication, or public-safe issue. Closeout shall identify outputs, non-outputs, records, access revocation, data disposition, repository status, publication status, incidents, corrections, lessons learned, successor activity, and archive status.

339.20 Lab Records. GCRI Canada shall maintain lab records, including lab architecture purpose records, research lab records, technical lab records, controlled lab records, challenge lab records, Nexus Universe lab records, lab charters, scope records, participant records, access control records, data / AI / cyber control records, safety and security control records, public authority control records, community safeguards control records, provider and sponsor control records, output classification records, publication review records, IP and contribution terms, correction records, closeout records, access revocation records, data disposition records, incidents, lessons learned, renewals, terminations, and archives.


Section 340. Structured Data Feeds, Indices, Signal Feeds, Evidence Pack Directories, Schema Registries, and Interoperability Mappings

340.1 Structured Data Feed Purpose. GCRI Canada may create, maintain, receive, publish, restrict, or interface structured data feeds to support public-benefit evidence, methods, observability, ontology, public-good software, public-safe publication, dashboards, maps, Academy materials, activation dockets, readiness programs, labs, benchmarking, and Nexus-compatible interfaces. Structured data feeds shall be governed by source lineage, classification, data rights, update cadence, confidence, limitations, access controls, public-safe status, public authority boundaries, protected knowledge safeguards, data / AI / cyber controls, and correction paths. A structured data feed shall not be treated as rating, certification, procurement approval, finance-readiness, public authority decision, or provider preference.

340.2 Index Purpose. GCRI Canada may maintain indices to organize evidence records, publications, technical assets, schemas, datasets, software releases, observability outputs, public-safe summaries, controlled summaries, public authority learning materials, Academy materials, capability maps, activation dockets, readiness records, lab outputs, challenge outputs, benchmark records, and Nexus interface materials. Indices shall improve findability, traceability, interoperability, and correctionability. Index inclusion shall not imply endorsement, recognition, maturity, public authority approval, finance-readiness, procurement approval, certification, or priority.

340.3 Signal Feed Purpose. GCRI Canada may maintain signal feeds for observability, telemetry, evidence alerts, source updates, correction signals, dashboard updates, map updates, sensor signals, AI-RAN / O-RAN signals, DePIN signals, cyber telemetry, geospatial updates, public-safe intelligence updates, vulnerability notifications, method updates, baseline updates, or Nexus interface updates. Signal feeds shall be classified and limitation-bearing. Signal feeds shall not constitute public warnings, emergency commands, public authority decisions, official alerts, operational instructions, finance-readiness signals, ratings, procurement signals, certification signals, or maturity signals.

340.4 Evidence Pack Directory Purpose. GCRI Canada may maintain evidence pack directories to organize proof packs, evidence packs, assurance packs, source packs, observability packs, compute packs, technical packs, public-safe packs, controlled packs, readiness packs, activation docket packs, host activation packs, lab packs, sprint packs, or Nexus interface packs. Evidence pack directories shall identify pack owner, version, scope, classification, permitted audience, evidence status, methods status, limitations, public-safe status, correction path, and archive status. Directory listing shall not imply approval, certification, finance-readiness, procurement status, recognition, maturity, or public authority endorsement.

340.5 Schema Registry Purpose. GCRI Canada may maintain schema registries for schemas, taxonomies, data dictionaries, ontology files, API schemas, evidence schemas, observability schemas, dashboard schemas, public-safe publication schemas, data / AI / cyber schemas, public authority capacity schemas, safeguards schemas, finance-boundary schemas, technical baseline schemas, and Nexus-compatible interoperability schemas. Schema registries shall preserve semantic versioning, compatibility notes, breaking change records, controlled access, public-safe status, correction path, and supersession history. Schema registry status shall not create certification, legal equivalence, public authority adoption, procurement approval, or finance-readiness.

340.6 Interoperability Mapping Purpose. GCRI Canada may maintain interoperability mappings between GCRI Canada materials, GCRI US materials, GRF-compatible claims discipline, GRA interfaces, Nexus Standards, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, consortium interfaces, national systems, regional systems, external standards, public authority terms, schemas, taxonomies, public-good baselines, technical profiles, and software interfaces. Interoperability mappings shall support translation, alignment, compatibility, localization, and correction, while preserving legal separateness, shared terms without shared authority, no certification by mapping, no accreditation by mapping, no compliance approval by mapping, and no legal equivalence by mapping.

340.7 Feed, Index, Signal, Directory, Registry, and Mapping Owner. Each material feed, index, signal, directory, registry, or mapping shall have an owner responsible for purpose, classification, source support, method support, update status, access controls, public-safe status, limitation language, correction path, deprecation, supersession, and archival. Ownership may be assigned to an officer, function, committee, technical asset owner, data steward, ontology steward, repository owner, program owner, or other competent role. Ownership shall not itself authorize public release, external sharing, or public authority claims without required approval.

340.8 Source Lineage. Feeds, indices, signals, directories, registries, and mappings shall preserve source lineage sufficient to identify sources, transformations, timestamps, versions, permissions, classifications, reliability, public authority terms, protected knowledge restrictions, data rights, methods applied, AI use where any, and correction path. Public-facing versions may summarize lineage where full disclosure would be unsafe or unlawful. Source lineage gaps shall be disclosed, restricted, or corrected where material.

340.9 Data Classification. Each feed, index, signal, directory, registry, or mapping shall be classified according to data type, sensitivity, access class, public-safe status, personal information status, public authority status, protected knowledge status, cyber sensitivity, infrastructure sensitivity, health sensitivity, finance sensitivity, controlled technology status, export-control status, sanctions sensitivity, and publication posture. Classification shall travel with outputs, exports, dashboards, APIs, downloads, summaries, and derived materials.

340.10 Update Cadence. Feeds, indices, signals, directories, registries, and mappings shall identify update cadence, including real-time, near-real-time, periodic, event-driven, manual, paused, historical, deprecated, retired, or archive-only status. Update cadence shall not be overstated. Where updates are delayed, incomplete, source-dependent, review-dependent, or manually maintained, limitations shall be recorded and displayed where material. Update cadence shall not imply emergency monitoring or public warning.

340.11 Confidence and Limitation Notes. Feeds, indices, signals, directories, registries, and mappings shall include confidence and limitation notes where material. Notes may identify source quality, uncertainty, missing data, stale data, incomplete mapping, localization differences, method limitations, model limitations, aggregation, redaction, public-safe transformation, public authority limits, protected knowledge limits, cyber or infrastructure sensitivity, finance-boundary limits, and correction path. Confidence notes shall not be ratings, guarantees, maturity determinations, finance-readiness determinations, or certifications.

340.12 Access Controls. Access to feeds, indices, signals, directories, registries, and mappings shall be controlled according to classification. Controls may include public access, public-safe access, controlled access, restricted access, room-only access, no-download access, API keys, rate limits, authentication, role-based access, attribute-based access, logging, export restrictions, AI-use restrictions, query limits, public authority limitations, safeguards limitations, cyber limitations, infrastructure limitations, finance-boundary limitations, and offboarding. Access controls shall prevent unauthorized scraping, republication, re-identification, protected knowledge exposure, or misuse.

340.13 Public-Safe Status. Each feed, index, signal, directory, registry, or mapping shall identify whether it is public-safe, public-safe after redaction, public-safe after aggregation, public-safe after delay, controlled only, restricted, internal-only, safeguards-limited, public authority-limited, cyber-limited, infrastructure-limited, finance-boundary-limited, experimental, deprecated, retired, or not suitable for external release. Public-safe status shall be reviewed when sources, methods, data classes, access, publication posture, public authority references, AI components, or output meaning changes.

340.14 Correction Path. Each feed, index, signal, directory, registry, or mapping shall have a correction path for source errors, method errors, stale data, missing data, misclassification, public authority misdescription, protected knowledge concern, privacy issue, AI issue, cyber issue, infrastructure-sensitive exposure, finance overclaim, certification implication, procurement implication, provider preference, sponsor control implication, mapping error, schema error, update failure, or public-safe issue. Correction may include update, suppression, restriction, deprecation, supersession, withdrawal, public-safe notice, controlled notice, or archive status change.

340.15 No Feed, Index, Signal, Directory, Registry, or Mapping as Rating, Certification, Finance-Readiness, Procurement Approval, Public Authority Decision, or Provider Preference. No feed, index, signal, directory, registry, mapping, entry, field, score, flag, label, update, alert, compatibility note, divergence log, schema status, evidence pack listing, or signal status shall constitute rating, certification, accreditation, compliance approval, finance-readiness, insurance-readiness, bankability, investability, underwriting approval, lending approval, public finance approval, procurement approval, provider preference, provider selection, public authority decision, public warning, emergency command, recognition, maturity, Nexus Grid guarantee, GRF recognition, or execution instruction. Limitation language shall be included where material.

340.16 Feed, Index, Directory, Registry, and Mapping Records. GCRI Canada shall maintain feed, index, signal, directory, registry, and mapping records, including structured data feed records, index records, signal feed records, evidence pack directory records, schema registry records, interoperability mapping records, owner records, source lineage records, data classification records, update cadence records, confidence and limitation notes, access control records, public-safe status records, correction path records, no-rating / no-certification / no-finance-readiness / no-procurement / no-public-authority-decision / no-provider-preference records, corrections, supersessions, deprecations, withdrawals, retirements, and archives.


Section 341. Academy Programs, Evidence Literacy, AI Governance Literacy, Cybersecurity Literacy, Public Authority Literacy, and Workforce Development

341.1 Academy Program Purpose. GCRI Canada may establish Academy programs as public-benefit learning, training, capacity-formation, literacy, workforce-development, fellowship-support, competence-cell-support, and public authority learning pathways aligned with GCRI Canada’s role as an upstream research, evidence, methods, observability, ontology, public-good software, open technical-baseline, data / AI / cyber, public-safe publication, and Nexus-compatible steward. Academy programs shall build understanding, discipline, and capability, but shall not create professional certification, regulated credentials, public authority qualification, procurement eligibility, provider preference, finance-readiness, recognition, maturity status, or authority to bind GCRI Canada by default.

341.2 Evidence Literacy. Academy programs may teach evidence literacy, including source lineage, evidence classification, confidence notes, limitation notes, public-safe summaries, source comparison, contradiction handling, stale-source handling, missing-source handling, evidence pack structures, activation docket evidence, host evidence readiness, public authority evidence boundaries, protected knowledge evidence safeguards, and correctionability. Evidence literacy shall emphasize that evidence records support disciplined understanding and decision support only, and do not constitute recognition, maturity, finance-readiness, certification, procurement approval, public authority approval, or public warning.

341.3 Methods Literacy. Academy programs may teach methods literacy, including research methods, evidence methods, observability methods, ontology methods, public-safe publication methods, AI governance methods, cybersecurity methods, data governance methods, replication methods, validation methods, benchmarking methods, challenge methods, readiness methods, host activation methods, adoption window methods, and Nexus interface methods. Methods literacy shall distinguish methods from mandates, certifications, public authority decisions, finance determinations, procurement requirements, and operational instructions.

341.4 Research Integrity Literacy. Academy programs may teach research integrity literacy, including research question design, source discipline, attribution, conflicts, methodology, reproducibility, negative results, limitations, publication review, ethics review where required, participant protection, sponsor influence controls, provider influence controls, AI-assisted research controls, correction, supersession, withdrawal, and retraction. Research integrity literacy shall preserve intellectual honesty and shall not be used to market predetermined conclusions or sponsor-funded positions as independent findings.

341.5 Observability Literacy. Academy programs may teach observability literacy, including telemetry concepts, sensing concepts, AI-RAN / O-RAN signal concepts, DePIN telemetry concepts, geospatial evidence, Earth observation, digital twins, degraded-mode awareness, resilience indicators, dashboards, maps, public-safe intelligence outputs, Observatory node methods, hub and cluster concepts, public-safe publication of observability outputs, and correction records. Observability literacy shall emphasize that observability outputs are not public warnings, emergency commands, public authority decisions, infrastructure instructions, finance-readiness, certification, procurement approval, or provider endorsements.

341.6 Ontology and Controlled Vocabulary Literacy. Academy programs may teach ontology and controlled vocabulary literacy, including taxonomies, schemas, data dictionaries, risk ontologies, maturity concepts, evidence classifications, technology-family terms, mission-critical system categories, public authority capacity terms, finance-boundary terms, certification-boundary terms, recognition-boundary terms, AI-readable knowledge structures, semantic versioning, compatibility notes, divergence logs, localization, and correction. Ontology literacy shall prevent role collapse, overclaim, ambiguous public meaning, and misuse of terms such as certified, approved, recognized, finance-ready, procurement-ready, mature, official, sovereign, or Nexus-compatible.

341.7 AI Governance Literacy. Academy programs may teach AI governance literacy, including AI-use classification, model registers, model cards, dataset cards, system cards, benchmark cards, prompt controls, retrieval controls, embeddings, vector stores, model training restrictions, fine-tuning restrictions, human review, hallucination risk, fabricated citations, bias, drift, prompt injection, data leakage, agentic AI controls, AI incident response, public-safe AI outputs, AI-assisted publication, and correctionability. AI governance literacy shall emphasize human accountability and shall not authorize unreviewed AI processing or AI-generated regulated advice.

341.8 Cybersecurity Literacy. Academy programs may teach cybersecurity literacy, including minimum cybersecurity baselines, secure architecture, least privilege, identity and access management, MFA, secrets control, repository security, secure development, vulnerability management, patch management, logging, monitoring, incident response, public repository hygiene, secure release, SBOMs, dependency risk, cyber-sensitive handling, coordinated disclosure, and public-safe cyber communication. Cybersecurity literacy shall not constitute cybersecurity certification, security warranty, procurement approval, insurance-readiness, underwriting approval, or public authority approval.

341.9 Data Governance and Privacy Literacy. Academy programs may teach data governance and privacy literacy, including lawful basis, purpose limitation, minimization, accuracy, storage limitation, bounded use, data rights, privacy impact review, rights-bearing data categories, sensitive data handling, sovereign data zones, localization, compute-to-data, cross-border transfer, de-identification, redaction, public-safe release, no-PII-in-public-repositories, and data disposition. Data governance literacy shall emphasize that data access, storage, AI use, transfer, publication, and reuse require recorded authority and safeguards.

341.10 Public Authority Literacy. Academy programs may teach public authority literacy, including capacity classification, observer participation, regulator-listening participation, public finance reader participation, emergency-management participation, public infrastructure operator participation, official-capacity participation, public authority data handling, public authority reference controls, public-safe learning materials, no-delegation boundaries, no-public-warning boundaries, no-emergency-command boundaries, no-regulatory-approval boundaries, no-procurement-approval boundaries, no-funding-approval boundaries, no-public-finance-approval boundaries, and no-sovereign-obligation boundaries. Public authority literacy shall support lawful understanding and shall not create public authority status.

341.11 Public-Safe Publication Literacy. Academy programs may teach public-safe publication literacy, including publication classes, access classes, handling categories, claims substantiation, evidence records, methods records, controlled vocabulary, limitation language, disclaimers, public authority references, sponsor and provider references, finance-boundary language, certification-boundary language, procurement-boundary language, public-safe maps, dashboards, AI-assisted content, media protocol, corrections, withdrawals, retractions, and archival. Public-safe publication literacy shall build disciplined communication without authorizing participants to publish on behalf of GCRI Canada.

341.12 Community Safeguards and Protected Knowledge Literacy. Academy programs may teach community safeguards and protected knowledge literacy, including Indigenous data, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, community-protected data, protected participants, youth, vulnerable persons, remote community data, public-safe mapping risk, custodial authority, consent or authorization, non-extraction, attribution, confidentiality, AI-use restrictions, publication limits, withdrawal rights, correction rights, and harm prevention. Such literacy shall be taught with respect, context, and humility, and shall not convert protected knowledge into open instructional material.

341.13 Technical Baseline and Public-Good Software Literacy. Academy programs may teach technical baseline and public-good software literacy, including baseline purpose, versioning, licensing, intended use, prohibited use, schemas, APIs, SDKs, repositories, contribution terms, secure development, dependency review, vulnerability disclosure, reference implementations, test harnesses, benchmark tools, documentation, public-safe release, deprecation, retirement, and correction. Technical baseline and software literacy shall clarify that use of materials does not create certification, warranty, procurement approval, finance-readiness, public authority approval, provider preference, or operational support obligations.

341.14 Nexus Architecture and Role-Separation Literacy. Academy programs may teach Nexus architecture and role-separation literacy, including one rail / two stacks discipline, GCRI Canada and GCRI US alignment, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, Nexus Competence Cells, National Consortium Companies, Project SPVs, hosts, sponsors, providers, public authorities, communities, universities, laboratories, and capital readers. Such literacy shall preserve legal separateness, no agency, no merger, no shared treasury, no shared liability, non-execution, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, and correctionability.

341.15 Workforce Development. Academy programs may support workforce development by helping individuals and institutions build skills in evidence practice, methods practice, observability practice, ontology practice, data governance, AI governance, cybersecurity, public-safe publication, safeguards, public authority literacy, technical baseline use, public-good software contribution, research integrity, competence-cell participation, and Nexus-compatible public-good coordination. Workforce development shall be public-benefit and capability-forming. It shall not promise employment, licensure, regulated professional status, procurement eligibility, provider preference, public authority qualification, finance-readiness, recognition, maturity, or certification by default.

341.16 Public-Benefit Learning. Academy programs shall prioritize public-benefit learning, including accessibility, plain-language support where appropriate, multilingual or localized materials where appropriate, public authority learning, community-sensitive learning, open or public-safe materials where appropriate, controlled materials where required, and correction of learning materials as knowledge evolves. Public-benefit learning shall not be distorted by sponsor priorities, provider marketing, funder preferences, political interests, procurement incentives, finance-readiness narratives, or institutional prestige. Learning materials shall remain evidence-supported, method-bound, limitation-bearing, and correctionable.

341.17 No Academy Program as Professional Certification or Regulated Credential by Default. No Academy program, training module, fellowship, competence-cell activity, workshop, lab participation, learning pathway, attendance record, completion record, badge, certificate of attendance, participation note, assessment, exercise, challenge, benchmark, adoption window, or workforce-development activity shall constitute professional certification, regulated credential, licensure, public authority qualification, procurement eligibility, provider approval, finance-readiness, insurance-readiness, bankability, investment suitability, recognition, maturity status, Nexus Grid status, GRF recognition, or authority to speak for or bind GCRI Canada unless a separate lawful and competent credentialing or authorization process is expressly established and recorded. Any completion language shall be carefully limited.

341.18 Academy Program Records. GCRI Canada shall maintain Academy program records, including Academy program purpose records, evidence literacy records, methods literacy records, research integrity literacy records, observability literacy records, ontology and controlled vocabulary literacy records, AI governance literacy records, cybersecurity literacy records, data governance and privacy literacy records, public authority literacy records, public-safe publication literacy records, community safeguards and protected knowledge literacy records, technical baseline and public-good software literacy records, Nexus architecture and role-separation literacy records, workforce-development records, public-benefit learning records, no-professional-certification / no-regulated-credential records, participation records, completion records, curriculum records, trainer records, learning material records, correction records, supersessions, withdrawals, and archives.

Section 342. Role-Based Training, Training Records, Attendance Records, Learning Outcomes, Competence Records, Renewals, Revocations, and Credential Non-Inflation

342.1 Role-Based Training Purpose. GCRI Canada shall maintain role-based training for directors, officers, staff, contractors, fellows, advisors, committee participants, council participants, developers, maintainers, technical contributors, public authority participants, providers, sponsors, hosts, donors, partners, reviewers, authors, repository users, controlled-room users, data-room users, Academy participants, competence-cell participants, and other persons whose roles require awareness of GCRI Canada’s governance, public-benefit purpose, non-execution boundary, role separation, evidence discipline, methods discipline, observability discipline, ontology discipline, public-good software stewardship, open technical baseline stewardship, public-safe publication, data / AI / cyber controls, privacy, public authority boundaries, finance-readiness boundaries, certification boundaries, procurement neutrality, provider neutrality, sponsor support-without-control, community safeguards, protected knowledge, correctionability, and record discipline. Role-based training shall be proportionate to function, risk, access, authority, data class, public-facing status, technical responsibility, and Nexus interface exposure, and shall be designed to form capability without inflating attendance, participation, or completion into professional certification, regulated credential, public authority qualification, procurement preference, finance-readiness status, provider recognition, maturity status, or institutional authority.

342.2 Director Training. Directors shall receive training appropriate to their fiduciary, governance, public-benefit, nonprofit, legal, risk, and oversight responsibilities. Director training may include duties of care, loyalty, prudence, diligence, independence, conflict management, mission fidelity, nonprofit and non-distribution character, public-good stewardship, GCRI Canada’s legal separateness, Nexus role separation, non-execution, validity-by-record, correctionability, anti-capture, sponsor support-without-control, provider neutrality, public authority boundaries, finance-readiness boundaries, certification boundaries, procurement neutrality, publication controls, data / AI / cyber governance, privacy, cybersecurity, protected knowledge safeguards, public-safe maps and dashboards, incident oversight, records retention, and Board continuity. Director training records shall not reduce or replace each director’s independent fiduciary duties under applicable law, the Articles, this Bylaw, and Board-approved policies.

342.3 Officer Training. Officers shall receive training appropriate to delegated authority, operational coordination, corporate administration, program approval, publication approval, contracting, records, finance administration, stakeholder interface, public authority interface, sponsor and provider interface, data / AI / cyber controls, privacy, public-safe publication, and correction responsibilities. Officer training shall emphasize that delegated authority is limited by law, Articles, this Bylaw, Board resolutions, delegation records, role separation, non-execution, finance boundaries, certification boundaries, procurement boundaries, public authority boundaries, and correctionability. Officers shall be trained to identify escalation triggers, stop-the-line situations, conflicts, public-safe publication risks, AI incidents, data incidents, cyber incidents, protected knowledge concerns, public authority misdescription, finance overclaim, certification implication, procurement implication, provider preference, sponsor-control risk, and unmanaged program drift.

342.4 Staff and Contractor Training. Staff and contractors shall receive training appropriate to their access, functions, duties, deliverables, systems, records, data classes, public-facing role, technical role, research role, program role, publication role, or support role. Training may include confidentiality, recordkeeping, approved tools, no-shadow-IT rules, approved AI-use rules, repository hygiene, data classification, privacy, cybersecurity, incident reporting, public authority boundaries, sponsor and provider boundaries, protected knowledge safeguards, public-safe publication, conflict disclosure, IP and contribution terms, and correction pathways. Contractors shall be trained only to the extent appropriate to their contracted role, but lack of training shall not authorize deviation from confidentiality, security, data, AI, cyber, public-safe, or record obligations.

342.5 Fellow and Advisor Training. Fellows and advisors shall receive training appropriate to fellowship scope, advisory scope, research access, publication rights, public statement limits, confidentiality, data rights, IP, AI use, public authority references, sponsor and provider conflicts, community safeguards, protected knowledge, repository access, controlled-room access, public-safe publication, and closeout obligations. Fellowship or advisory status shall not create governance authority, fiduciary authority, employee status, public authority status, certification authority, procurement authority, finance-readiness authority, provider-selection authority, or authority to bind GCRI Canada unless separately and lawfully recorded. Training shall make these limits explicit.

342.6 Committee and Council Training. Committee members, council participants, forum participants, reviewers, working-party participants, drafting-group participants, expert-panel participants, model-review participants, peer-review participants, and advisory-body participants shall receive training appropriate to mandate, advisory status, confidentiality, conflicts, records, voting semantics, dissent capture, minority reports, output limits, public statement limits, public authority boundaries, finance boundaries, certification boundaries, procurement boundaries, provider neutrality, sponsor non-control, public-safe publication, data / AI / cyber handling, protected knowledge safeguards, and correction paths. Training shall make clear that committee, council, forum, panel, working-party, or advisory participation does not create Board authority, officer authority, fiduciary authority, public authority status, certification authority, finance-readiness authority, procurement authority, protocol authority, or execution authority unless expressly and lawfully delegated by competent record.

342.7 Developer and Maintainer Training. Developers, maintainers, technical contributors, repository administrators, open-source participants, package maintainers, dashboard maintainers, schema maintainers, API maintainers, model maintainers, dataset maintainers, and technical asset stewards shall receive training appropriate to secure development, repository security, branch protection, secrets control, dependency review, licensing, IP chain of title, contribution terms, vulnerability disclosure, SBOM practices where appropriate, test harnesses, benchmark integrity, model cards, dataset cards, system cards, AI-use controls, public repository hygiene, no-PII-in-public-repositories, controlled technology, export controls, sanctions, public-good software release controls, deprecation, retirement, and correction. Technical permission shall not be confused with governance authority, publication authority, public authority authority, procurement authority, finance authority, or certification authority.

342.8 Public Authority Participant Training. Public authority participants, public finance readers, regulator-listening participants, emergency-management participants, public infrastructure operator participants, public health participants, public safety participants, municipal participants, Crown entity participants, utility participants, port participants, telecom participants, energy participants, water participants, food-system participants, health-system participants, cyber participants, and other public-sector participants may receive orientation or training appropriate to the program, room, Academy module, learning session, lab, docket, dashboard, map, evidence pack, or public-safe material involved. Such training shall explain capacity classification, confidentiality, permitted use, public reference limits, data contribution controls, public-safe limitations, no-delegation, no-public-warning, no-emergency-command, no-regulatory-approval, no-procurement-approval, no-funding-approval, no-public-finance-approval, no-sovereign-obligation, and correction pathways. Public authority participation in training shall not make GCRI Canada a public authority or make the public authority an endorser by implication.

342.9 Provider, Sponsor, Host, Donor, and Partner Boundary Training. Providers, sponsors, hosts, donors, funders, partners, universities, laboratories, consultants, vendors, National Consortium Companies, Project SPVs, and other external actors participating in approved programs may receive boundary training explaining support-without-control, provider neutrality, procurement neutrality, no recognition purchase, no certification influence, no finance-readiness influence, no public authority access purchase, no research outcome purchase, no benchmark manipulation, no provider preference, no sponsor control, approved acknowledgment language, public reference controls, conflicts, confidentiality, data handling, and correction obligations. Such training shall be used to prevent overclaim and improper private benefit, not to confer preferred status.

342.10 Data / AI / Cyber Training. Data / AI / cyber training shall address data classification, lawful basis, purpose limitation, minimization, access controls, privacy, rights-bearing data, sensitive personal information, public authority data, protected knowledge, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive evidence, AI-use classification, approved AI tools, prohibited AI tools, model-training restrictions, retrieval controls, embedding controls, prompt injection, hallucination, fabricated citations, data leakage, agentic AI limits, repository security, secrets control, vulnerability management, incident reporting, public-safe AI outputs, dashboard and map controls, cross-border transfer, localization, compute-to-data, and correctionability. Training shall emphasize that convenience, technical ability, tool access, or urgency does not authorize prohibited processing.

342.11 Research Integrity Training. Research integrity training shall address research design, source discipline, evidence sufficiency, methods documentation, literature use, attribution, authorship, conflicts, sponsor influence, provider influence, data rights, ethics review where required, participant protection, Indigenous / local / territorial knowledge protocols, protected knowledge, community safeguards, statistical limits, model limits, reproducibility, negative results, failure capture, publication review, correction, supersession, withdrawal, retraction, and archive status. Research integrity training shall prevent predetermined conclusions, unsupported claims, fabricated citations, selective source use, public authority overclaim, finance overclaim, certification implication, procurement implication, and provider preference.

342.12 Public-Safe Publication Training. Public-safe publication training shall address publication classes, access classes, handling categories, claims substantiation, evidence records, methods records, source lineage, controlled vocabulary, disclaimers, limitation language, redaction, aggregation, public authority references, sponsor and provider references, finance-boundary language, certification-boundary language, procurement-boundary language, public-safe maps, dashboards, AI-assisted content, media protocol, public reports, whitepapers, datasets, software releases, social media, speeches, decks, corrections, clarifications, withdrawals, retractions, and archival. Public-safe publication training shall make clear that authorship, technical expertise, program participation, or possession of draft materials does not create publication authority.

342.13 Community Safeguards Training. Community safeguards training shall address community-protected data, Indigenous data, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, protected participants, youth, vulnerable persons, remote communities, health-sensitive groups, public-safe mapping risk, custodial authority, consent or authorization, non-extraction, attribution, confidentiality, withdrawal rights, correction rights, AI-use restrictions, publication limits, geospatial generalization, small-cell suppression, retaliation risk, stigmatization, accessibility, and harm prevention. Such training shall be respectful, contextual, and non-extractive, and shall not convert protected knowledge into ordinary instructional material or public datasets.

342.14 Training Records. GCRI Canada shall maintain training records sufficient to evidence who was assigned, offered, attended, completed, renewed, failed, waived, suspended, revoked, or exempted from training. Training records may include role, training module, date, trainer, format, version, attendance, completion, assessment where any, learning outcome, competence note, renewal date, revocation status, restrictions, correction, and closeout. Training records shall be classified where they include employment information, contractor information, public authority participation, protected participant information, security-sensitive details, or controlled-room eligibility.

342.15 Attendance Records. Attendance records may document attendance at training, Academy sessions, workshops, labs, competence-cell sessions, public authority learning sessions, controlled-room orientations, data / AI / cyber training, public-safe publication training, safeguards training, developer training, director training, officer training, and committee or council training. Attendance records shall record presence or participation only and shall not be inflated into competence, certification, credential, public authority qualification, procurement eligibility, finance-readiness, recognition, maturity, or provider approval. Attendance records shall be used carefully in public references.

342.16 Learning Outcomes. Learning outcomes may identify expected knowledge, awareness, practice capability, procedural familiarity, boundary understanding, tool-use discipline, evidence literacy, methods literacy, publication literacy, data / AI / cyber literacy, public authority literacy, safeguards literacy, or technical baseline literacy. Learning outcomes shall be tied to specific modules and shall be limitation-bearing. Learning outcomes shall not be represented as professional standards, regulated competencies, licensing criteria, certification criteria, procurement qualifications, finance-readiness criteria, public authority qualifications, or provider-recognition criteria unless separately and lawfully established.

342.17 Competence Records. Competence records may document demonstrated completion of defined internal learning steps, supervised practice, role readiness, controlled-room orientation, repository readiness, publication workflow readiness, data / AI / cyber handling readiness, safeguards handling readiness, or competence-cell training within GCRI Canada-approved scope. Competence records shall be internal or controlled records unless approved otherwise. Competence records shall be specific, time-bound where appropriate, role-limited, versioned, and subject to renewal, suspension, revocation, and correction. Competence records shall not be generalized into professional certification or external endorsement.

342.18 Renewal Requirements. Training status, access eligibility, competence records, controlled-room eligibility, repository permissions, public-safe publication permissions, data / AI / cyber permissions, safeguards permissions, developer permissions, maintainer permissions, and public authority interface permissions may require renewal at intervals proportionate to risk, law, policy, role, system access, program requirements, incident history, changed tools, changed methods, changed law, changed public authority terms, changed AI systems, changed cyber risk, or changed safeguards obligations. Renewal shall be recorded and may require refresher training, updated assessment, conflict review, access review, or recommitment to terms.

342.19 Revocation or Suspension of Training Status. GCRI Canada may revoke or suspend training status, competence records, access eligibility, controlled-room eligibility, repository permissions, public-safe publication permissions, data / AI / cyber permissions, safeguards permissions, maintainer status, developer status, public authority interface role, or other training-linked status where a person fails required training, breaches confidentiality, misuses data, uploads restricted material to unapproved systems, violates AI-use rules, mishandles protected knowledge, creates cyber risk, misdescribes public authority participation, overclaims finance-readiness, implies certification or procurement approval, acts outside role, fails renewal, creates conflict risk, or otherwise violates program rules. Revocation or suspension shall be proportionate, recorded, and subject to correction or reinstatement where appropriate.

342.20 Credential Non-Inflation Rule. GCRI Canada shall apply a credential non-inflation rule to all training, Academy, competence-cell, fellowship, lab, adoption window, replication sprint, validation sprint, governed pilot, challenge, hackathon, public authority learning, and workforce-development activities. Completion language shall be precise and shall not convert attendance, participation, orientation, module completion, supervised practice, competence record, badge, certificate of attendance, training status, fellowship status, residency status, award, prize, or program participation into professional certification, regulated credential, licensure, public authority qualification, procurement eligibility, provider approval, finance-readiness, insurance-readiness, bankability, investment suitability, recognition, maturity, Nexus Grid status, GRF recognition, or authority to speak for or bind GCRI Canada unless a separate lawful and competent process expressly creates such status.

342.21 No Training Record as Professional License, Certification, Public Authority Qualification, Procurement Preference, Finance-Readiness Status, or Provider Recognition. No training record, attendance record, learning outcome, competence record, renewal, badge, certificate, transcript, completion note, public authority learning record, developer training record, maintainer record, safeguards training record, data / AI / cyber training record, Academy record, fellowship record, lab record, competence-cell record, or program record shall constitute professional license, professional certification, regulated credential, public authority qualification, procurement preference, provider recognition, provider approval, finance-readiness status, insurance-readiness status, public finance readiness, bankability, investment suitability, rating, public authority approval, GRF recognition, Nexus Grid maturity, or authority to bind GCRI Canada. Any public-facing completion statement shall include limitation language where material.

342.22 Training and Competence Records. GCRI Canada shall maintain training and competence records, including role-based training purpose records, director training records, officer training records, staff and contractor training records, fellow and advisor training records, committee and council training records, developer and maintainer training records, public authority participant training records, provider / sponsor / host / donor / partner boundary training records, data / AI / cyber training records, research integrity training records, public-safe publication training records, community safeguards training records, attendance records, learning outcome records, competence records, renewal records, revocation records, suspension records, credential non-inflation records, no-license / no-certification / no-public-authority-qualification / no-procurement-preference / no-finance-readiness / no-provider-recognition records, corrections, reinstatements, closeouts, and archives.


Section 343. Fellowships, Scholarships, Stipends, Awards, Technical Residencies, and Public-Benefit Research Support

343.1 Fellowship Purpose. GCRI Canada may establish fellowships to support public-benefit research, evidence formation, methods development, observability work, ontology stewardship, public-good software, open technical baselines, data / AI / cyber governance, public-safe publication, community safeguards, public authority learning, Academy programs, competence-cell development, Nexus-compatible public-good architecture, and related institutional learning. Fellowship programs shall be mission-bound, time-bound or scope-bound, agreement-based where appropriate, supervised, record-supported, conflict-reviewed, and correctionable. Fellowship status shall not itself create employment, governance authority, public authority status, publication authority, certification authority, procurement authority, finance-readiness authority, recognition authority, provider-selection authority, or authority to bind GCRI Canada.

343.2 Scholarship Purpose. GCRI Canada may establish scholarships to support learning, research participation, Academy participation, technical study, public-good software contribution, safeguards learning, public authority learning, community participation, accessibility, workforce development, or other public-benefit educational purposes consistent with GCRI Canada’s nonprofit and public-benefit character. Scholarships shall be awarded according to recorded criteria and shall not be used to purchase research outcomes, public authority access, community knowledge, provider advantage, sponsor benefit, procurement influence, finance-readiness influence, recognition, certification, or institutional endorsement.

343.3 Stipend Purpose. GCRI Canada may provide stipends to fellows, students, researchers, technical residents, community fellows, visiting contributors, Academy participants, public-benefit trainees, or other eligible persons to support time, access, participation, travel, subsistence, research, public-good technical work, or other approved activities where lawful and consistent with public-benefit purpose. Stipends shall be structured to avoid coercion, improper private benefit, disguised compensation where not intended, conflicts, dependency pressure, protected knowledge extraction, or appearance that payment purchases conclusions, endorsements, public authority access, finance-readiness, certification, procurement advantage, or recognition.

343.4 Award Purpose. GCRI Canada may provide awards to recognize public-benefit contribution, research excellence, evidence integrity, methods improvement, public-good software contribution, public-safe publication contribution, Academy contribution, community safeguards contribution, accessibility contribution, data / AI / cyber contribution, open technical baseline contribution, or Nexus-compatible public-good contribution. Awards shall be based on recorded criteria and shall be carefully described to avoid recognition inflation. An award shall not constitute professional certification, regulated credential, provider endorsement, procurement approval, finance-readiness, public authority approval, GRF recognition, Nexus Grid maturity, or market ranking.

343.5 Technical Residency Purpose. GCRI Canada may establish technical residencies for time-limited, supervised, public-benefit technical work involving software, schemas, APIs, dashboards, maps, test harnesses, benchmarks, model cards, dataset cards, system cards, ontology files, observability tools, verifiable compute tools, public-safe publication tooling, cybersecurity tooling, data governance tooling, AI governance tooling, and open technical baselines. Technical residencies shall be governed by secure development, repository access, contribution terms, IP, licensing, confidentiality, data / AI / cyber controls, public-safe review, vulnerability disclosure, controlled technology review where applicable, and closeout. Residency status shall not confer maintainer authority except as separately recorded.

343.6 Public-Benefit Research Support. GCRI Canada may provide public-benefit research support through funding, in-kind support, data access, controlled-room access, mentorship, supervision, methods support, technical support, publication support, travel support, accessibility support, community participation support, or research infrastructure support. Such support shall be aligned with GCRI Canada’s public-benefit mission and shall be conditioned on research integrity, data rights, privacy, safeguards, public authority boundaries, sponsor and provider independence, publication review, correctionability, and records. Public-benefit research support shall not be used to control conclusions or manufacture legitimacy.

343.7 Eligibility Criteria. Eligibility criteria for fellowships, scholarships, stipends, awards, technical residencies, and research support shall be recorded, fair, mission-aligned, conflict-aware, accessible where feasible, and proportionate to the purpose of the support. Criteria may include public-benefit relevance, competence, need, research fit, technical skill, lived experience, community role, public authority learning relevance, safeguards relevance, accessibility need, diversity of disciplines, geography, institutional role, and capacity to comply with GCRI Canada obligations. Criteria shall not unlawfully discriminate or create private benefit inconsistent with GCRI Canada’s purposes.

343.8 Selection Process. Selection processes shall be recorded and proportionate to the type and value of support. Selection may include application, nomination, eligibility review, conflict review, reviewer scoring, interview, committee review, public-benefit assessment, safeguards assessment, technical assessment, equity and accessibility review, and approval by an authorized officer, committee, or Board where required. Selection shall not be controlled by sponsors, providers, donors, funders, hosts, public authorities, or partners unless their role is expressly limited and consistent with anti-capture controls, conflict rules, and public-benefit purpose.

343.9 Conflict Review. Fellowships, scholarships, stipends, awards, residencies, and research support shall be subject to conflict review. Conflict review shall address relationships with directors, officers, staff, committee participants, council participants, sponsors, donors, funders, providers, hosts, public authorities, universities, laboratories, National Consortium Companies, Project SPVs, partners, reviewers, and applicants. Conflicts may require disclosure, recusal, independent review, modified terms, denial, limitation, or public-safe disclosure where material. Financial support shall not be used to confer improper benefit or influence institutional outputs.

343.10 Equity, Accessibility, and Inclusion Considerations. GCRI Canada may include equity, accessibility, inclusion, geographic diversity, disciplinary diversity, language accessibility, disability access, community participation, Indigenous / local / territorial participation, youth participation where lawful, and underrepresented perspective considerations in fellowship, scholarship, stipend, award, residency, and research support design. Such considerations shall be implemented lawfully, transparently, respectfully, and consistently with public-benefit purpose. Accessibility support may include accommodation, translation, assistive technology, travel support, remote participation, flexible schedules, or other measures designed to enable meaningful participation without coercion or tokenization.

343.11 Research Integrity Requirements. Recipients of fellowships, scholarships, stipends, awards, residencies, or research support shall comply with research integrity requirements where relevant, including source discipline, method documentation, attribution, authorship rules, ethics review where required, consent or authorization where required, data rights, conflict disclosure, sponsor and provider independence, public authority boundary discipline, negative result capture, limitations, correction, withdrawal, retraction, and archive obligations. Research support shall not guarantee publication, favourable findings, provider endorsement, sponsor benefit, finance-readiness, certification, procurement approval, recognition, or maturity status.

343.12 Data / AI / Cyber Requirements. Recipients with access to GCRI Canada systems, data, repositories, AI tools, models, dashboards, maps, controlled rooms, data rooms, public authority materials, protected knowledge, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, or technical assets shall comply with data / AI / cyber requirements. Such requirements may include approved tools, no-shadow-IT, no-unapproved-AI-upload, classification, access controls, MFA, secure storage, model-training restrictions, retrieval restrictions, embedding restrictions, public repository hygiene, vulnerability reporting, incident reporting, data disposition, and offboarding.

343.13 IP and Publication Terms. Fellowships, scholarships, stipends, awards, residencies, and research support may require IP, publication, licensing, contribution, attribution, moral rights, confidentiality, data rights, patent disclosure, open-source disclosure, AI-use disclosure, and work product terms. Terms shall distinguish pre-existing IP, background IP, foreground IP, joint work product, derivative works, public-good software, controlled materials, public-safe publications, controlled annexes, and private work. Publication rights shall be subject to GCRI Canada review where required by law, agreement, privacy, protected knowledge, public authority terms, cybersecurity, export controls, sanctions, or public-safe publication rules.

343.14 Safeguards and Protected Knowledge Terms. Recipients working with communities, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, protected participants, youth, vulnerable persons, remote communities, health-sensitive groups, community-protected data, or public-safe mapping risk shall comply with safeguards and protected knowledge terms. Such terms may include custodial authority, consent or authorization, attribution, non-extraction, confidentiality, access limits, AI-use restrictions, publication limits, withdrawal rights, correction rights, community review, geospatial protections, and harm prevention. Support shall not purchase or pressure disclosure of protected knowledge.

343.15 Payment, Reimbursement, and Tax Treatment. Payments, reimbursements, stipends, scholarships, awards, honoraria, travel support, accessibility support, residency support, and research support shall be authorized, documented, and administered in accordance with applicable law, tax rules, accounting rules, donor or grant restrictions, employment classification, contractor classification, public-benefit purpose, anti-corruption controls, conflict controls, and improper private benefit restrictions. Recipients may be responsible for their own tax reporting where applicable. Payment records shall identify purpose, amount, authority, conditions, restrictions, and closeout.

343.16 No Improper Private Benefit. No fellowship, scholarship, stipend, award, technical residency, or research support shall confer improper private benefit, disguised compensation, political benefit, sponsor benefit, provider advantage, public authority access purchase, research outcome purchase, procurement advantage, finance-readiness influence, certification influence, recognition purchase, maturity overclaim, or institutional legitimacy transfer. Support shall be proportionate, mission-aligned, documented, conflict-reviewed, and consistent with GCRI Canada’s nonprofit and public-benefit purposes.

343.17 Suspension, Termination, Completion, and Closeout. GCRI Canada may suspend, terminate, complete, close out, restrict, or modify a fellowship, scholarship, stipend, award, residency, or support arrangement for breach of terms, conflict, misconduct, research integrity concern, data / AI / cyber incident, privacy issue, protected knowledge concern, public authority misdescription, sponsor or provider overclaim, misuse of GCRI Canada name or materials, failure to complete requirements, legal issue, funding change, program closure, safety risk, or other recorded reason. Closeout shall address deliverables, payments, IP, data disposition, access revocation, publication status, records, corrections, and archive.

343.18 Fellowship, Scholarship, Stipend, Award, Residency, and Support Records. GCRI Canada shall maintain fellowship, scholarship, stipend, award, technical residency, and public-benefit research support records, including purpose records, eligibility criteria, selection records, conflict review records, equity / accessibility / inclusion records, research integrity requirements, data / AI / cyber requirements, IP and publication terms, safeguards and protected knowledge terms, payment / reimbursement / tax records, improper private benefit reviews, suspension records, termination records, completion records, closeout records, access revocation records, data disposition records, publication records, correction records, and archives.


Section 344. Nexus Competence Cell Training, Train-the-Trainer, Public-Safe Playbooks, Controlled Annexes, and Localization

344.1 Competence Cell Training Purpose. GCRI Canada may support Nexus Competence Cell training as a public-benefit capability-formation pathway for evidence practice, methods practice, observability practice, ontology practice, data governance, AI governance, cybersecurity, public-good software, technical baselines, public authority learning, safeguards, protected knowledge, finance-boundary literacy, public-safe publication, and Nexus-compatible role separation. Competence Cell training shall build practical capacity in defined domains while preserving credential non-inflation, non-execution, role separation, provider neutrality, sponsor non-control, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, public-safe publication, and correctionability.

344.2 Train-the-Trainer Purpose. GCRI Canada may establish train-the-trainer pathways to enable approved persons or institutions to deliver localized, controlled, public-safe, and version-aligned learning materials within defined scope. Train-the-trainer materials shall include approved curriculum, facilitator notes, public-safe playbooks, controlled annexes where required, boundary language, evidence and methods records, localization rules, update obligations, correction obligations, public authority reference limits, sponsor and provider limits, safeguards requirements, and no-certification language. Train-the-trainer status shall not create authority to modify institutional meaning, certify participants, approve providers, issue public authority guidance, make finance-readiness claims, or speak for GCRI Canada outside delegated scope.

344.3 Evidence Competence Training. Evidence competence training may cover source records, provenance, custody, timestamps, evidence classification, confidence notes, limitation notes, source comparison, contradiction handling, missing-source handling, stale-source handling, evidence packs, proof packs, activation docket evidence, host evidence readiness, public authority data terms, protected knowledge evidence handling, public-safe summaries, evidence correction, and archive discipline. Evidence competence shall support disciplined understanding and correction, not recognition, maturity, certification, finance-readiness, procurement approval, public authority approval, or public warning.

344.4 Methods Competence Training. Methods competence training may cover method selection, method documentation, versioning, assumptions, exclusions, applicability, evidence linkage, uncertainty treatment, replication, validation, benchmarking, negative testing, public-safe publication methods, observability methods, ontology methods, AI governance methods, cyber methods, public authority learning methods, safeguards methods, and correction methods. Methods competence shall emphasize fit-for-purpose practice and shall not be represented as authority to certify implementations, approve public authority use, rank providers, determine finance-readiness, or mandate procurement.

344.5 Observatory Competence Training. Observatory competence training may cover Nexus Observatory methods, observability records, telemetry, sensors, AI-RAN / O-RAN signals, DePIN records, geospatial evidence, Earth observation, digital twins, degraded-mode awareness, resilience indicators, dashboards, maps, source lineage, public-safe observability outputs, verifiable intelligence, node methods, hub methods, cluster methods, hotspot methods, national dense core concepts, regional cluster concepts, and correction records. Observatory competence shall not create emergency command, public warning authority, infrastructure operation, public authority decision-making, certification, procurement approval, finance-readiness, or provider preference.

344.6 Data Governance Competence Training. Data governance competence training may cover lawful basis, purpose limitation, minimization, bounded use, data classification, rights-bearing data, privacy, data rights, retention, deletion, controlled rooms, data rooms, sovereign data zones, localization, cross-border transfer, compute-to-data, public authority data terms, protected knowledge controls, data-sharing agreements, de-identification, redaction, public-safe release, and correction. Data governance competence shall not authorize access, reuse, transfer, publication, AI processing, or data sharing beyond recorded authority.

344.7 AI Governance Competence Training. AI governance competence training may cover model registers, AI-use classes, approved AI systems, prohibited AI uses, model cards, dataset cards, system cards, benchmark cards, prompt controls, retrieval controls, embeddings, vector stores, training and fine-tuning restrictions, model-improvement restrictions, human review, hallucination, fabricated citations, bias, drift, prompt injection, data leakage, agentic AI, AI incidents, AI-assisted publication, public-safe AI outputs, and correction. AI governance competence shall emphasize human accountability and shall not authorize AI-generated legal, finance, insurance, engineering, clinical, rating, public authority, or emergency instructions by default.

344.8 Cybersecurity Competence Training. Cybersecurity competence training may cover minimum cybersecurity baselines, secure architecture, identity and access management, MFA, least privilege, secure configuration, repository security, secure development, secrets control, dependency review, SBOM practices where appropriate, vulnerability management, patch management, logging, monitoring, detection, incident response, public repository hygiene, cyber-sensitive handling, coordinated disclosure, and public-safe cyber communication. Cybersecurity competence shall not create cybersecurity certification, security warranty, public authority approval, insurance-readiness, underwriting approval, procurement approval, or provider endorsement.

344.9 Public-Good Software and Technical Baseline Competence Training. Public-good software and technical baseline competence training may cover public-good software stewardship, open technical baselines, reference architectures, schemas, APIs, SDKs, dashboards, test harnesses, benchmark tools, model cards, dataset cards, system cards, interoperability profiles, evidence profiles, observability profiles, AI governance profiles, cybersecurity profiles, repository controls, licensing, contribution terms, versioning, vulnerability disclosure, deprecation, retirement, and correction. Competence in these materials shall not create warranty, certification, procurement approval, finance-readiness, public authority approval, provider preference, or operational support obligations.

344.10 Public Authority Learning Competence Training. Public authority learning competence training may cover public authority capacity classification, observer participation, regulator-listening participation, public finance reader participation, emergency-management participation, public infrastructure operator participation, official-capacity participation, public authority data handling, public authority reference controls, public-safe materials, no-delegation, no-public-warning, no-emergency-command, no-regulatory-approval, no-procurement-approval, no-funding-approval, no-public-finance-approval, no-sovereign-obligation, and correction. Public authority learning competence shall support clear boundaries, not public authority status.

344.11 Safeguards and Protected Knowledge Competence Training. Safeguards and protected knowledge competence training may cover Indigenous data, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, community-protected data, protected participants, youth, vulnerable persons, remote communities, health-sensitive groups, public-safe mapping risk, custodial authority, consent or authorization, non-extraction, attribution, confidentiality, AI-use restrictions, publication limits, withdrawal rights, correction rights, geospatial protections, accessibility, and harm prevention. Such training shall be handled with context and respect, and controlled annexes shall be used where open materials would be unsafe or inappropriate.

344.12 Finance-Boundary Literacy Training. Finance-boundary literacy training may cover finance-readiness references, technical evidence inputs, GRA interfaces, Nexus Rails, proof packs, capital-reader rooms, public finance reader rooms, insurance-sensitive evidence, lender-sensitive evidence, RNFD, NFD, UNFSD, non-reliance, no-investment-advice, no-solicitation, no-securities-offering, no-capital-commitment, no-underwriting, no-lending, no-guarantee, no-insurance-approval, no-rating, no-public-finance-approval, no-bankability, and no-finance-readiness determination by GCRI Canada. Such training shall prevent regulated-perimeter drift and shall not prepare participants to solicit capital under GCRI Canada authority.

344.13 Public-Safe Playbooks. GCRI Canada may maintain public-safe playbooks for evidence handling, methods handling, public authority learning, community safeguards, data / AI / cyber handling, AI-assisted content, publication review, dashboard use, map release, public-good software release, technical baseline adoption, adoption windows, replication sprints, validation sprints, governed pilots, labs, challenge programs, competence-cell operations, host activations, and correction pathways. Playbooks shall be versioned, limitation-bearing, classification-controlled, audience-appropriate, and correctionable. Playbooks shall not be treated as certification manuals, procurement manuals, finance manuals, public authority directives, emergency procedures, or execution instructions unless separately and lawfully adopted by competent authority for that distinct purpose.

344.14 Controlled Annexes. Controlled annexes may be used where training materials include sensitive examples, public authority-sensitive content, protected knowledge, cyber-sensitive details, infrastructure-sensitive details, finance-sensitive evidence, legal-sensitive content, controlled technology, incident materials, vulnerability examples, benchmark-sensitive materials, or community-sensitive context. Controlled annexes shall have access controls, permitted-use rules, no-download rules where appropriate, AI-use restrictions, redistribution limits, publication limits, retention, deletion, correction path, and closeout. Controlled annexes shall not be reproduced into public materials without public-safe review.

344.15 Localization for Canadian, Provincial, Territorial, Indigenous, Community, Regional, National, and International Contexts. Competence Cell training, train-the-trainer materials, playbooks, controlled annexes, and Academy materials may be localized for Canadian, provincial, territorial, municipal, Indigenous, community, regional, national, international, linguistic, legal, cultural, technical, public authority, or Nexus-contextual needs. Localization shall preserve GCRI Canada’s public-benefit purpose, legal separateness, role separation, non-execution, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, provider neutrality, sponsor non-control, privacy, data / AI / cyber controls, protected knowledge safeguards, controlled vocabulary, semantic compatibility, versioning, correctionability, compatibility notes, and divergence logs. Localization shall not become local capture or unauthorized modification of institutional meaning.

344.16 No Competence Cell Training as Certification by Default. No Competence Cell training, train-the-trainer pathway, playbook, controlled annex, localized material, learning module, attendance record, completion record, practical exercise, badge, competence note, trainer authorization, or localized delivery shall constitute certification, professional credential, regulated credential, public authority qualification, procurement eligibility, provider approval, finance-readiness, insurance-readiness, bankability, investment suitability, recognition, maturity status, Nexus Grid status, GRF recognition, or authority to speak for or bind GCRI Canada by default. Any limited authorization must be separately lawful, recorded, scope-bound, and limitation-bearing.

344.17 Competence Cell Training Records. GCRI Canada shall maintain Competence Cell training records, including competence cell training purpose records, train-the-trainer records, evidence competence training records, methods competence training records, Observatory competence training records, data governance competence training records, AI governance competence training records, cybersecurity competence training records, public-good software and technical baseline competence training records, public authority learning competence training records, safeguards and protected knowledge competence training records, finance-boundary literacy training records, public-safe playbook records, controlled annex records, localization records, no-certification-by-default records, attendance records, completion records, trainer records, renewal records, revocation records, correction records, supersessions, withdrawals, and archives.


Section 345. Challenge Funds, Prizes, Bounties, Hackathons, Module Foundries, and Venture-Building Enablement Without Investment Execution

345.1 Challenge Fund Purpose. GCRI Canada may establish challenge funds or challenge-style support mechanisms to stimulate public-benefit research, evidence improvement, methods refinement, public-good software development, open technical baseline contribution, data / AI / cyber improvement, public-safe publication tooling, safeguards innovation, observability methods, ontology improvements, Academy materials, competence-cell materials, replication, validation, benchmarking, and Nexus-compatible public-good capability. Challenge funds shall be governed as public-benefit program mechanisms and shall not constitute investment funds, venture funds, securities offerings, capital placement vehicles, brokered transactions, procurement programs, provider selection processes, public finance approvals, finance-readiness determinations, certification programs, recognition programs, or maturity determinations by GCRI Canada.

345.2 Prize Purpose. GCRI Canada may offer prizes to recognize specific public-benefit outputs, including reproducible evidence work, methods improvement, public-good software contribution, secure release improvement, ontology contribution, data governance improvement, AI governance improvement, cybersecurity improvement, public-safe mapping method, accessibility improvement, community safeguards tool, public authority learning material, challenge solution, benchmark improvement, or technical baseline contribution. Prizes shall be awarded under recorded rules and shall not imply certification, procurement approval, provider preference, finance-readiness, public authority endorsement, recognition, maturity, investment selection, or market ranking.

345.3 Bounty Purpose. GCRI Canada may establish bounties for defined public-benefit tasks, including vulnerability reporting, documentation improvement, test creation, negative test capture, bug identification, benchmark defect identification, schema issue identification, public-safe publication error identification, accessibility issue identification, AI hallucination detection, data leakage detection, prompt injection testing, source correction, and repository hygiene improvement. Bounties shall be scoped, lawful, non-exploitative, secure, and public-safe. Bounty participation shall not authorize unlawful access, data exfiltration, public disclosure of vulnerabilities, protected knowledge exposure, public authority data access, or use of GCRI Canada systems beyond approved scope.

345.4 Hackathon Purpose. GCRI Canada may conduct hackathons as time-bound, rules-governed, public-benefit technical and learning events for public-good software, data governance tools, AI governance tools, cybersecurity tools, observability prototypes, ontology tools, dashboards, maps, accessibility tools, public-safe publication tools, Academy materials, competence-cell materials, and Nexus-compatible public-good prototypes. Hackathons shall emphasize learning, prototyping, experimentation, and public-good contribution, and shall not be used to procure vendors, select providers, certify products, approve deployments, raise capital, endorse companies, confer public authority approval, or determine finance-readiness.

345.5 Module Foundry Purpose. GCRI Canada may establish module foundries to design, assemble, test, document, version, and improve modular public-good assets, including software modules, schema modules, training modules, Academy modules, competence-cell modules, public-safe playbook modules, dashboard modules, map modules, AI governance modules, cybersecurity modules, observability modules, ontology modules, evidence-pack modules, host activation modules, adoption-window modules, and Nexus-compatible interface modules. Module foundries shall operate under technical asset governance, IP and contribution terms, secure development, public-safe review, version control, licensing, and correctionability. Module foundry outputs shall not be treated as commercial products approved by GCRI Canada or as procurement-ready offerings.

345.6 Venture-Building Enablement Purpose. GCRI Canada may provide venture-building enablement only in a non-executing, public-benefit, finance-boundary-controlled manner, limited to evidence literacy, methods literacy, technical baseline literacy, public-good software literacy, public authority boundary literacy, data / AI / cyber literacy, safeguards literacy, public-safe publication literacy, capability mapping, problem definition, public-good architecture understanding, responsible innovation practices, and controlled introductions where authorized. Venture-building enablement shall not include investment advice, capital raising, securities offering, brokerage, finder activity, investment selection, company formation control, Project SPV control, National Consortium Company control, management services, transaction execution, underwriting, lending, insurance placement, rating, public finance approval, procurement approval, certification, recognition, maturity determination, or provider endorsement by GCRI Canada.

345.7 Public-Benefit Alignment. Challenge funds, prizes, bounties, hackathons, module foundries, and venture-building enablement shall be public-benefit aligned. Alignment review shall assess whether the activity advances GCRI Canada’s research, evidence, methods, observability, ontology, public-good software, open technical baseline, data / AI / cyber, public-safe publication, Academy, competence-cell, safeguards, public authority learning, or Nexus-compatible mission. Activities primarily serving private commercialization, sponsor marketing, provider advantage, procurement influence, capital promotion, talent capture, data extraction, protected knowledge extraction, or institutional overclaim shall be denied, re-scoped, or conditioned.

345.8 Eligibility and Selection. Eligibility and selection rules shall be recorded before awards, prizes, bounties, hackathon participation, module foundry participation, or venture-building enablement are offered. Rules may address participant type, legal eligibility, age where relevant, jurisdiction, public-benefit relevance, technical capacity, conflicts, sponsor or provider relationships, public authority capacity, safeguards obligations, data / AI / cyber requirements, IP terms, prior conduct, sanctions, export controls, controlled technology, and ability to comply with rules. Selection shall be fair, transparent where appropriate, conflict-reviewed, and insulated from improper sponsor, provider, donor, funder, host, or public authority control.

345.9 Rules and Terms. Each challenge fund, prize, bounty, hackathon, module foundry, or venture-building enablement activity shall have rules and terms proportionate to risk. Rules and terms may address scope, eligibility, judging criteria, award criteria, payment conditions, deliverables, prohibited conduct, confidentiality, data rights, IP, licensing, AI-use rules, public-safe publication, security, vulnerability disclosure, public authority references, sponsor and provider references, conflicts, code of conduct, sanctions, export controls, tax treatment, disqualification, suspension, termination, correction, and dispute handling. Rules shall not be written to imply certification, procurement approval, finance-readiness, recognition, maturity, or provider endorsement.

345.10 IP and Contribution Terms. IP and contribution terms shall govern submissions, code, documentation, datasets, models, prompts, schemas, APIs, dashboards, maps, playbooks, training modules, designs, methods, benchmarks, test harnesses, vulnerability reports, and other work product created or contributed through challenge funds, prizes, bounties, hackathons, module foundries, or venture-building enablement. Terms may require license grants, assignments where appropriate, open-source licensing, contributor license agreements, moral rights treatment where lawful, patent disclosures, third-party rights disclosures, confidentiality, attribution, publication review, takedown rights, and correction. Participants shall not submit materials they lack authority to contribute.

345.11 Data / AI / Cyber Rules. Data / AI / cyber rules shall govern permitted tools, approved platforms, AI-use limits, model-training restrictions, data classes, prohibited data, public authority data, protected knowledge, personal information, cyber-sensitive materials, infrastructure-sensitive materials, finance-sensitive evidence, controlled technology, repository access, secrets, credentials, vulnerability testing, prompt injection testing, logging, storage, public repository use, cross-border transfer, incident reporting, and output classification. Activities shall use synthetic, dummy, de-identified, aggregated, public-safe, or approved controlled data where appropriate. Restricted data shall not be used without recorded authority.

345.12 Research Integrity Rules. Research integrity rules shall govern submissions, claims, evidence, sources, methods, benchmarks, evaluations, results, demonstrations, public statements, citations, AI-assisted outputs, and publication. Participants shall not fabricate data, fabricate citations, conceal conflicts, misrepresent results, misuse public authority references, overstate provider performance, suppress negative results, manipulate benchmarks, copy protected materials, misrepresent AI-generated work, or present sponsor-driven conclusions as independent. Research integrity violations may result in disqualification, award withdrawal, publication correction, access revocation, and incident review.

345.13 Sponsor and Provider Controls. Sponsor and provider controls shall apply where sponsors, donors, funders, providers, vendors, hosts, cloud providers, AI providers, cybersecurity providers, telecom providers, software providers, data providers, National Consortium Companies, Project SPVs, or partners support or participate in challenge funds, prizes, bounties, hackathons, module foundries, or venture-building enablement. Controls shall prevent sponsor control, provider preference, procurement advantage, benchmark manipulation, public authority access purchase, finance-readiness influence, certification influence, recognition purchase, award purchase, research outcome purchase, improper private benefit, and misleading public claims. Sponsor and provider acknowledgments shall use approved language.

345.14 Public Authority Boundary Controls. Activities involving public authorities, public authority participants, public authority data, public finance readers, regulators, emergency management bodies, public infrastructure operators, public health bodies, public safety bodies, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, cyber bodies, or public-sector hosts shall apply public authority boundary controls. Controls shall include capacity classification, public reference permission, non-endorsement language, no-delegation, no-public-warning, no-emergency-command, no-regulatory-approval, no-procurement-approval, no-funding-approval, no-public-finance-approval, no-sovereign-obligation, and public-safe review.

345.15 Payment, Award, and Tax Controls. Payments, awards, prizes, bounties, reimbursements, stipends, grants, travel support, credits, in-kind awards, cloud credits, compute credits, software credits, and other benefits shall be authorized, documented, and administered according to applicable law, tax rules, accounting rules, donor or sponsor restrictions, grant restrictions, sanctions, export controls, anti-corruption controls, conflict controls, and improper private benefit rules. Award records shall identify recipient, basis, amount or value, conditions, payment authority, tax treatment where applicable, restrictions, and closeout. Payment or award shall not purchase endorsement, recognition, finance-readiness, certification, procurement advantage, public authority access, or research conclusion.

345.16 No Investment Advice, Capital Raising, Brokerage, Finder Activity, Securities Offering, or Investment Selection. No challenge fund, prize, bounty, hackathon, module foundry, venture-building enablement, demo day, curated introduction, capability map, public-safe summary, mentor session, capital-reader room, sponsor event, provider event, pitch-style presentation, or related program shall constitute investment advice, securities advice, capital raising, brokerage, finder activity, securities offering, investor solicitation, investment selection, portfolio recommendation, valuation opinion, capital commitment, public finance approval, insurance placement, underwriting, lending, guarantee, rating, or transaction execution by GCRI Canada. Where investor-facing or capital-reader activity exists, it shall be boundary-reviewed, non-reliance-controlled, and limited to public-benefit learning or technical evidence context.

345.17 No Award as Certification, Procurement Approval, Provider Preference, Public Authority Endorsement, Finance-Readiness, Recognition, or Maturity. No award, prize, bounty payment, hackathon result, module foundry output, challenge outcome, judging result, demo selection, finalist status, winner status, shortlist, public mention, badge, certificate of participation, public-safe summary, or venture-building enablement record shall constitute certification, accreditation, compliance approval, procurement approval, provider preference, vendor selection, public authority endorsement, public authority approval, finance-readiness, insurance-readiness, bankability, investability, underwriting approval, lending approval, public finance approval, rating, recognition, standing, maturity status, Nexus Grid status, GRF recognition, public warning, emergency command, or execution instruction. Required limitation language shall be included where material.

345.18 Challenge, Prize, Bounty, Hackathon, Module Foundry, and Venture-Building Records. GCRI Canada shall maintain challenge, prize, bounty, hackathon, module foundry, and venture-building records, including challenge fund purpose records, prize purpose records, bounty purpose records, hackathon purpose records, module foundry purpose records, venture-building enablement purpose records, public-benefit alignment reviews, eligibility and selection records, rules and terms, IP and contribution terms, data / AI / cyber rules, research integrity rules, sponsor and provider control records, public authority boundary control records, payment / award / tax records, no-investment-advice / no-capital-raising / no-brokerage / no-finder-activity / no-securities-offering / no-investment-selection records, no-award-as-certification / no-procurement / no-provider-preference / no-public-authority-endorsement / no-finance-readiness / no-recognition / no-maturity records, conflicts, disqualifications, suspensions, terminations, corrections, withdrawals, closeouts, and archives.

Section 346. Partnering Office, Curated Introductions, Needs Discovery, Capability Mapping, Delegation Design, and No Brokerage

346.1 Partnering Office Purpose. GCRI Canada may establish a Partnering Office as a public-benefit, non-executing, evidence-based, method-governed, boundary-controlled function to support needs discovery, capability mapping, curated introductions, delegation design support, ecosystem navigation, public authority learning, host activation support, research collaboration support, technical baseline awareness, public-good software awareness, Academy and competence-cell pathway support, and Nexus-compatible coordination. The Partnering Office shall operate as a structured institutional interface for learning, coordination, documentation, and public-benefit alignment, and shall not operate as a broker, finder, investment bank, placement agent, procurement adviser, vendor selector, insurance intermediary, lender arranger, public finance arranger, public authority delegate, project developer, managed service provider, or enterprise execution vehicle. The Partnering Office shall preserve GCRI Canada’s legal separateness, nonprofit and non-distribution character, non-execution boundary, role separation, public authority boundaries, finance-readiness boundaries, certification boundaries, procurement neutrality, provider neutrality, sponsor support-without-control, data / AI / cyber controls, protected knowledge safeguards, public-safe publication discipline, and correctionability.

346.2 Needs Discovery. The Partnering Office may conduct needs discovery to understand public-benefit needs, research needs, evidence needs, methods needs, observability needs, ontology needs, data governance needs, AI governance needs, cybersecurity needs, public-good software needs, technical baseline needs, public authority learning needs, community safeguards needs, Academy needs, competence-cell needs, host readiness needs, adoption-window needs, replication-sprint needs, governed-pilot needs, lab needs, benchmarking needs, capability gaps, and Nexus-compatible interface needs. Needs discovery shall be documented, capacity-classified, conflict-reviewed where appropriate, and limited to understanding and routing needs within lawful and approved pathways. Needs discovery shall not become consulting execution, procurement specification, vendor selection, investment diligence, insurance placement, public authority decision-making, public warning, emergency command, certification, recognition, maturity determination, or finance-readiness determination.

346.3 Capability Mapping. The Partnering Office may maintain capability maps to identify institutions, research groups, public authorities, public-sector readers, community bodies, hosts, universities, laboratories, providers, technical contributors, maintainers, fellows, Academy pathways, competence cells, software assets, technical baselines, data / AI / cyber capabilities, observability capabilities, safeguards capabilities, public-safe publication capabilities, and Nexus-compatible resources relevant to public-benefit activities. Capability mapping shall be evidence-supported, classification-controlled, limitation-bearing, provider-neutral, sponsor-neutral, public authority-boundary-compliant, and correctionable. Inclusion in a capability map shall not imply endorsement, preferred status, procurement eligibility, certification, finance-readiness, recognition, maturity, public authority approval, public authority adoption, provider selection, or public legitimacy.

346.4 Public-Benefit Matching for Learning, Research, Evidence, Methods, Technical, or Capacity Purposes. The Partnering Office may support public-benefit matching among eligible persons, institutions, programs, hosts, public authorities, communities, researchers, technical contributors, competence cells, Academy pathways, and Nexus-compatible actors for learning, research, evidence, methods, technical, capacity-formation, public-good software, open technical baseline, observability, ontology, data / AI / cyber, safeguards, or public-safe publication purposes. Such matching shall be purpose-bound, non-exclusive where appropriate, transparent to affected parties where appropriate, conflict-reviewed where material, and governed by role separation. Matching shall not create agency, partnership, joint venture, shared liability, shared treasury, investment recommendation, procurement recommendation, provider preference, certification, recognition, maturity, public authority delegation, or finance-readiness.

346.5 Curated Introductions. The Partnering Office may make curated introductions where a recorded public-benefit rationale supports connecting parties for learning, research, evidence development, methods review, host readiness, technical baseline awareness, public-good software contribution, Academy participation, competence-cell development, public authority learning, safeguards consultation, or Nexus-compatible coordination. A curated introduction shall be factual, limited, non-exclusive unless justified, and accompanied by boundary language where appropriate. GCRI Canada shall not represent that an introduction is a recommendation, endorsement, procurement shortlist, investment opportunity, insurance placement, lending opportunity, public finance opportunity, certification pathway, recognition pathway, maturity pathway, or public authority approval. The introduced parties shall remain responsible for their own due diligence, agreements, compliance, conflicts, and decisions.

346.6 Delegation Design Support. The Partnering Office may support delegation design by helping parties distinguish roles, authorities, decision rights, advisory functions, public authority capacities, data rights, evidence responsibilities, methods responsibilities, publication responsibilities, technical stewardship responsibilities, host responsibilities, sponsor support roles, provider contribution roles, public-good support roles, and execution responsibilities across lawful structures. Delegation design support shall be educational, architectural, and boundary-oriented. It shall not itself delegate public authority powers, procurement powers, finance powers, certification powers, recognition powers, employment powers, fiduciary powers, execution powers, emergency powers, or authority to bind any party. Any actual delegation, agency, contracting, procurement, finance, public authority action, or execution relationship must be created by separate competent legal instrument and competent authority.

346.7 Ecosystem Navigation Support. The Partnering Office may provide ecosystem navigation support to help participants understand GCRI Canada programs, Academy pathways, competence-cell pathways, activation dockets, adoption windows, replication sprints, governed pilots, labs, challenge programs, benchmarking activities, public-good software assets, open technical baselines, Nexus interfaces, GCRI US alignment, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Global Nexus Consortium, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, National Consortium Companies, Project SPVs, public authorities, hosts, sponsors, providers, universities, laboratories, communities, and capital readers. Ecosystem navigation shall preserve role separation and shall not imply that GCRI Canada controls the ecosystem, guarantees access, guarantees outcomes, approves participants, selects vendors, places capital, arranges insurance, procures services, certifies systems, recognizes status, or issues public authority mandates.

346.8 Public Authority Learning Support. The Partnering Office may support public authority learning by routing public authorities, public-sector readers, regulators, public finance readers, emergency-management participants, public infrastructure operators, public health participants, public safety participants, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, and cyber bodies to appropriate learning materials, evidence literacy pathways, methods literacy pathways, data / AI / cyber literacy, observability literacy, public-safe publication materials, Academy programs, controlled rooms, or public-safe summaries. Such support shall be capacity-classified and shall not create public authority delegation, public warning authority, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, official adoption, public-private partnership, sovereign obligation, or authority for GCRI Canada to act on behalf of any public body.

346.9 Provider Neutrality. The Partnering Office shall maintain provider neutrality in all needs discovery, capability mapping, curated introductions, ecosystem navigation, benchmarking support, lab support, challenge support, adoption-window support, host activation support, and public authority learning support. Provider neutrality requires that GCRI Canada not prefer, endorse, rank, select, certify, procure, recommend, approve, promote, or disadvantage providers except through a separate lawful and competent process expressly authorized for a defined non-procurement public-benefit purpose. Provider participation, technical contribution, public-good software contribution, sponsorship, hosting, demonstration, benchmarking participation, or capability-map inclusion shall not create provider preference, procurement advantage, certification implication, finance-readiness, public authority endorsement, recognition, maturity, or Nexus-approved status.

346.10 Sponsor and Donor Non-Control. Sponsor, donor, funder, philanthropic, grant, in-kind, host, or partner support for Partnering Office activities shall be support-without-control. No sponsor, donor, funder, host, provider, partner, or contributor shall control needs discovery, capability mapping, curated introductions, participant routing, public authority access, provider references, sponsor references, evidence conclusions, methods conclusions, benchmark design, challenge rules, publication posture, correction decisions, or Nexus interface meaning. Sponsorship, donation, funding, or in-kind support shall not purchase public authority access, provider preference, procurement advantage, finance-readiness influence, certification influence, recognition, maturity status, research outcome, public-good baseline language, or public-safe publication treatment.

346.11 No Brokerage. GCRI Canada shall not act as broker, dealer, investment broker, insurance broker, loan broker, public finance broker, commercial broker, transaction broker, procurement broker, technology broker, data broker, or intermediary for compensation in connection with investments, securities, loans, insurance, guarantees, public finance, procurement, contracts, vendor selection, capital placement, asset sales, or transactions. Partnering Office activities shall be structured as public-benefit learning, evidence, methods, capacity, and coordination support only. No curated introduction, capability map, program routing, public authority learning session, capital-reader room, challenge, hackathon, lab, adoption window, or governed pilot shall be characterized as brokerage.

346.12 No Finder Activity. GCRI Canada shall not engage in finder activity by identifying, introducing, soliciting, referring, matching, or routing investors, lenders, insurers, guarantors, public finance institutions, purchasers, vendors, acquirers, issuers, sponsors, providers, National Consortium Companies, Project SPVs, or transaction participants for the purpose of compensation tied to investment, insurance, lending, public finance, procurement, sale, financing, capital raising, securities issuance, or transaction completion. Curated introductions shall not include transaction advocacy, negotiation, valuation, term discussion, success-based compensation, investment recommendation, securities recommendation, insurance recommendation, lending recommendation, underwriting recommendation, or public finance recommendation.

346.13 No Success Fee for Capital, Procurement, Insurance, Lending, or Transactions. GCRI Canada shall not receive or agree to receive a success fee, contingent fee, finder fee, brokerage fee, placement fee, referral fee, transaction fee, commission, carried interest, underwriting compensation, insurance commission, lending fee, capital-introduction fee, procurement-introduction fee, or other compensation contingent on capital raised, investment made, securities sold, insurance placed, loan closed, guarantee issued, public finance approved, vendor selected, procurement awarded, contract executed, acquisition completed, or transaction consummated. Cost-recovery fees, subscriptions, grants, donations, sponsorships, or program fees may be permitted only where lawful, public-benefit aligned, non-contingent on regulated or transactional outcomes, conflict-reviewed, and recorded.

346.14 No Investment Recommendation. The Partnering Office shall not recommend investments, securities, projects, issuers, funds, tokens, companies, National Consortium Companies, Project SPVs, providers, assets, infrastructure, insurance products, loans, guarantees, public finance instruments, or capital allocations. It shall not provide buy / sell / hold advice, suitability analysis, valuation conclusions, risk-return recommendations, portfolio advice, investment rankings, diligence opinions, rating-like outputs, or investor targeting. Any capital-reader, GRA interface, Nexus Rails, RNFD, NFD, UNFSD, or finance-adjacent reference shall be non-reliance-controlled and limited to technical evidence, public-benefit learning, or boundary-controlled coordination.

346.15 No Vendor Selection. The Partnering Office shall not select vendors, approve vendors, prequalify vendors, shortlist vendors, rank vendors, recommend vendors, designate preferred providers, determine procurement eligibility, create tender requirements, issue purchasing recommendations, or act as procurement adviser. Capability mapping, technical contribution records, benchmark participation, hackathon participation, lab participation, adoption-window participation, curated introductions, or public-good software contributions shall not become vendor selection. Any external party seeking vendors or services shall conduct its own lawful procurement, contracting, diligence, and decision process.

346.16 No Procurement Steering. The Partnering Office shall not steer procurement toward or away from any provider, sponsor, donor, funder, host, partner, National Consortium Company, Project SPV, software, platform, cloud provider, AI provider, cybersecurity provider, telecom provider, AI-RAN provider, O-RAN provider, DePIN provider, consultant, contractor, or vendor. Procurement steering includes shaping requirements, timing introductions, presenting comparisons, controlling access, framing capability maps, using benchmark outputs, or designing programs in a manner that creates an unfair advantage in procurement. GCRI Canada may provide public-good technical baselines and learning materials only with non-procurement language and provider-neutral discipline.

346.17 No Public Authority Delegation. No Partnering Office activity, needs discovery, capability mapping, curated introduction, public authority learning support, delegation design support, ecosystem navigation, host activation support, adoption window, lab, benchmark, challenge, or program routing shall constitute public authority delegation, official mandate, regulatory approval, public warning, emergency command, procurement approval, funding approval, public finance approval, public-private partnership, sovereign obligation, or authority for GCRI Canada to act for or bind any public authority. Public authority participation shall be capacity-classified and reference-controlled. Public authority decisions remain with the competent public authority.

346.18 Partnering Office Records. GCRI Canada shall maintain Partnering Office records, including Partnering Office purpose records, needs discovery records, capability mapping records, public-benefit matching records, curated introduction records, delegation design support records, ecosystem navigation support records, public authority learning support records, provider-neutrality records, sponsor and donor non-control records, no-brokerage records, no-finder-activity records, no-success-fee records, no-investment-recommendation records, no-vendor-selection records, no-procurement-steering records, no-public-authority-delegation records, conflict reviews, capacity classifications, approved language, limitation language, corrections, withdrawals, closeouts, and archives.


Section 347. Benchmarking Subscriptions, Market Baseline Libraries, and Anti-Collusion Safeguards

347.1 Benchmarking Subscription Purpose. GCRI Canada may establish benchmarking subscriptions only as public-benefit, evidence-based, method-governed, access-controlled, provider-neutral, competition-law-compliant mechanisms to support technical learning, evidence literacy, methods comparison, baseline awareness, interoperability, public-good software improvement, secure development, public-safe publication, data / AI / cyber governance, observability methods, and capability formation. Benchmarking subscriptions shall not be used to facilitate collusion, price coordination, bid coordination, market allocation, provider exclusion, procurement steering, investment signalling, rating, certification, finance-readiness, public authority approval, or provider preference. Subscription access shall be governed by approved terms, data rights, confidentiality, anti-collusion safeguards, publication posture, and correctionability.

347.2 Market Baseline Library Purpose. GCRI Canada may maintain market baseline libraries as curated, evidence-supported, public-safe or controlled collections of non-sensitive reference materials, public information, technical baselines, public-good software references, interoperability profiles, capability categories, methods notes, benchmark methods, historical public-safe data, aggregated indicators, and learning materials intended to support public-benefit understanding and disciplined comparison. A market baseline library shall not function as a market intelligence service for competitive coordination, a vendor ranking system, procurement advisory product, investment research product, rating product, certification registry, finance-readiness registry, or provider endorsement mechanism.

347.3 Evidence-Based Benchmarking. Benchmarking conducted or supported by GCRI Canada shall be evidence-based, method-bound, source-documented, limitation-bearing, versioned where appropriate, and correctionable. Benchmarking shall identify benchmark purpose, scope, criteria, data sources, collection method, aggregation method, exclusions, uncertainty, confidence, publication posture, and known limitations. Evidence-based benchmarking may support learning, technical quality, reproducibility, public-good baseline improvement, and correction, but shall not be represented as certification, procurement approval, provider ranking, finance-readiness, public authority decision, rating, recognition, maturity, or guarantee.

347.4 Technical Baseline Benchmarking. Technical baseline benchmarking may compare systems, tools, schemas, APIs, public-good software, dashboards, maps, datasets, AI models, cybersecurity controls, observability methods, interoperability profiles, evidence profiles, data governance profiles, AI governance profiles, cybersecurity profiles, or open technical baselines against defined technical criteria. Such benchmarking shall identify version, environment, assumptions, dependencies, test data, limitations, reproducibility, security posture, and correction path. Technical baseline benchmarking shall not certify an implementation, approve a product, rank a provider for procurement, determine compliance, determine finance-readiness, or create a public authority-approved standard.

347.5 Public-Safe Comparative Outputs. Comparative outputs shall be public-safe or controlled according to sensitivity. Public-safe comparative outputs may use aggregation, anonymization, de-identification, generalization, categorical descriptions, ranges, confidence notes, limitation language, and no-provider-preference language to support learning without exposing confidential, personal, protected, cyber-sensitive, infrastructure-sensitive, finance-sensitive, public authority-sensitive, or market-sensitive information. Controlled comparative outputs shall be limited to approved audiences under confidentiality, no-redistribution, AI-use restrictions, and competition-law safeguards.

347.6 Aggregation and De-Identification. Benchmarking outputs involving multiple providers, hosts, participants, public authorities, projects, datasets, systems, or market actors shall use aggregation, de-identification, anonymization, masking, suppression, or generalization where necessary to prevent re-identification, provider-specific disclosure, market-sensitive inference, competition-law risk, public authority misdescription, protected knowledge exposure, community harm, or unfair reputational impact. Aggregation and de-identification shall be reviewed for residual risk and shall not be used to create misleading precision or conceal material limitations.

347.7 Independent Administration. Benchmarking subscriptions and market baseline libraries shall be independently administered by GCRI Canada or by an approved neutral function operating under GCRI Canada controls. Independent administration shall include defined criteria, records, conflict review, sponsor and provider controls, clean-team procedures where needed, access controls, limitation language, correction path, and review cycles. Sponsors, providers, donors, funders, hosts, subscribers, public authorities, or benchmarked actors shall not control benchmark criteria, inclusion, exclusion, scoring, publication, suppression, or correction in a manner that compromises neutrality or public benefit.

347.8 Competition and Antitrust Review. Benchmarking, market baseline libraries, subscriptions, clean rooms, clean teams, comparative outputs, challenge outputs, hackathon outputs, capability maps, and provider-facing or market-facing materials shall undergo competition and antitrust review where they may involve competitors, market-sensitive information, pricing, costs, margins, capacity, bids, customer information, roadmaps, future strategy, output levels, supply constraints, procurement plans, compensation, market shares, allocation, or provider exclusion. Review shall determine whether the activity is permitted, must be aggregated, must be delayed, must be anonymized, must be clean-roomed, must be restricted, must be re-scoped, or must be denied.

347.9 Market-Sensitive Information Controls. Market-sensitive information shall not be collected, shared, published, benchmarked, discussed, stored, or used except under approved controls. Market-sensitive information includes current or future prices, discounts, costs, margins, bids, bid strategies, procurement strategies, capacity, production, roadmaps, customer lists, market shares, compensation, supplier terms, transaction terms, investment terms, financing terms, insurance terms, underwriting terms, or commercially sensitive competitive information. Controls may include exclusion, aggregation, delayed reporting, clean-team handling, access restriction, legal review, and publication limits.

347.10 Clean-Team and Clean-Room Structures. Where benchmarking or market baseline work requires exposure to sensitive non-public information, GCRI Canada may use clean-team or clean-room structures. Clean-team and clean-room structures shall define permitted persons, permitted data, prohibited data, confidentiality, access controls, no-download rules, aggregation rules, output review, legal review, public-safe review, AI-use restrictions, retention, deletion, conflict controls, and closeout. Clean-room status shall not authorize anticompetitive coordination, procurement steering, provider preference, or transaction facilitation.

347.11 No Price Coordination. No benchmarking subscription, market baseline library, clean room, clean team, provider discussion, challenge activity, hackathon, capability map, curated introduction, public-safe output, or controlled comparative output shall be used to coordinate prices, discounts, fees, wages, rates, premiums, lending terms, underwriting terms, subscription prices, bid prices, contract prices, or future pricing strategy. GCRI Canada shall exclude, aggregate, delay, restrict, or deny pricing-related information where necessary to prevent price coordination risk.

347.12 No Bid Coordination. No GCRI Canada benchmarking, capability mapping, curated introduction, Partnering Office activity, challenge, hackathon, lab, adoption window, or market baseline activity shall be used to coordinate bids, tenders, proposals, procurement timing, procurement responses, consortium bids, public-private partnership bids, vendor strategies, subcontracting allocations, or bid/no-bid decisions. GCRI Canada shall not facilitate exchange of bid-sensitive information or create procurement steering through benchmark design or access.

347.13 No Market Allocation. No benchmarking subscription, market baseline library, curated introduction, capability map, clean room, provider discussion, public-safe output, or controlled output shall be used to allocate customers, territories, sectors, public authorities, hosts, projects, technologies, markets, opportunities, supply, capacity, or roles among providers, sponsors, partners, National Consortium Companies, Project SPVs, or other market actors. GCRI Canada shall preserve open public-benefit access, provider neutrality, and anti-capture discipline.

347.14 No Provider Exclusion. Benchmarking, market baseline libraries, capability maps, adoption windows, labs, challenges, hackathons, public-good software pathways, technical baseline pathways, and Partnering Office activities shall not be used to exclude providers, restrict competition, create unjustified barriers, blacklist vendors, deny lawful participation for anticompetitive reasons, or create closed provider clubs. Eligibility restrictions may be imposed only for lawful, public-benefit, security, data rights, safeguards, conflict, capacity, export-control, sanctions, public-safe, or program-integrity reasons and shall be recorded.

347.15 No Procurement Steering. Benchmarking outputs, market baseline libraries, subscription materials, comparative tables, capability maps, public-safe summaries, controlled summaries, challenge results, hackathon results, lab outputs, and technical baseline notes shall not be used by GCRI Canada to steer procurement toward or away from any provider, vendor, tool, platform, cloud, AI provider, cybersecurity provider, telecom provider, AI-RAN provider, O-RAN provider, DePIN provider, consultant, contractor, National Consortium Company, Project SPV, or commercial actor. Any procurement use by external parties remains their own responsibility and shall not be represented as GCRI Canada procurement advice.

347.16 No Benchmark as Rating, Certification, Finance-Readiness, Procurement Approval, Public Authority Decision, or Provider Preference. No benchmark, benchmark score, baseline comparison, market baseline library entry, subscription output, comparative summary, challenge score, lab result, capability map entry, evidence classification, confidence note, or technical baseline result shall constitute rating, certification, accreditation, compliance approval, finance-readiness, insurance-readiness, bankability, investability, underwriting approval, lending approval, public finance approval, procurement approval, provider preference, provider selection, public authority decision, public warning, emergency command, recognition, maturity, Nexus Grid status, GRF recognition, or performance guarantee. Required limitation language shall accompany benchmark outputs where material.

347.17 Benchmark Correction and Supersession. Benchmarking outputs, market baseline library entries, subscription materials, comparative outputs, capability maps, benchmark methods, technical baseline comparisons, and benchmark records shall remain correctionable and supersedable. Correction or supersession shall occur where sources change, methods change, data is stale, participant information is incorrect, aggregation creates misleading results, de-identification fails, market-sensitive information is exposed, competition-law risk emerges, public authority misdescription occurs, provider preference appears, sponsor influence appears, finance overclaim occurs, certification implication arises, procurement implication arises, public-safe risk emerges, or error is discovered. Corrections may include update, suppression, withdrawal, controlled notice, public-safe notice, reclassification, method revision, or archive-status change.

347.18 Benchmarking and Market Baseline Records. GCRI Canada shall maintain benchmarking and market baseline records, including benchmarking subscription purpose records, market baseline library purpose records, evidence-based benchmarking records, technical baseline benchmarking records, public-safe comparative output records, aggregation and de-identification records, independent administration records, competition and antitrust review records, market-sensitive information control records, clean-team and clean-room records, no-price-coordination records, no-bid-coordination records, no-market-allocation records, no-provider-exclusion records, no-procurement-steering records, no-benchmark-as-rating / certification / finance-readiness / procurement-approval / public-authority-decision / provider-preference records, correction records, supersession records, withdrawal records, reclassification records, notices, and archives.


Section 348. Program Records, Participant Records, Funding Records, Deliverables, Acceptance Records, Corrections, and Closeout

348.1 Program Record Requirement. GCRI Canada shall maintain program records for each material program, activation docket, readiness program, host activation, adoption window, replication sprint, validation sprint, governed pilot, lab, Academy program, training program, fellowship program, competence-cell program, challenge program, benchmarking program, partnering activity, curated introduction, capability mapping activity, structured data feed, market baseline library, module foundry, or related programmatic activity. Program records shall preserve authority, scope, public-benefit rationale, non-execution boundary, role separation, risk classification, stakeholder classification, evidence records, methods records, data / AI / cyber records, public authority records, safeguards records, funding records, deliverables, acceptance gates, publication posture, corrections, closeout, retention, and archival.

348.2 Program Charter Records. Program charter records shall identify program name, program class, purpose, public-benefit rationale, approval authority, owner, custodian, scope, permitted activities, prohibited activities, participants, stakeholder map, risk class, data class, AI-use class, cyber class, public authority class, safeguards class, finance-boundary class, sponsor or donor context, provider context, host context, technical asset context, deliverables, milestones, acceptance gates, KPIs and KRIs where any, publication posture, incident path, correction path, closeout criteria, and archive requirements. Program charters shall distinguish public-benefit program outputs from prohibited execution, procurement, finance, certification, recognition, maturity, public warning, or public authority outputs.

348.3 Program Intake Records. Program intake records shall document the origin, proposer, requested activity, public-benefit need, intended participants, affected stakeholders, host or site context, public authority context, community context, sponsor or donor context, provider context, data needs, AI-use needs, cyber needs, technical baseline relevance, public-good software relevance, observability relevance, ontology relevance, publication expectations, funding expectations, risks, conflicts, approvals required, and decision to approve, deny, re-scope, defer, route, or archive. Intake records shall prevent informal programs, shadow programs, side-channel programs, and undocumented external commitments.

348.4 Program Approval Records. Program approval records shall identify approving authority, date, version, scope approved, conditions, exclusions, required reviews, Board approval where required, officer approval where applicable, committee review where applicable, legal review where required, data / AI / cyber review where required, public authority boundary review where required, safeguards review where required, finance-boundary review where required, certification-boundary review where required, procurement-boundary review where required, provider-neutrality review where required, sponsor non-control review where required, and approval expiration or review date where applicable. Approval records shall distinguish planning approval, launch approval, external engagement approval, controlled-release approval, public-release approval, and closeout approval.

348.5 Participant Records. Participant records shall identify persons and institutions participating in programs, including directors, officers, staff, contractors, fellows, advisors, committee participants, council participants, working-party participants, developers, maintainers, technical contributors, public authority participants, providers, sponsors, donors, funders, hosts, universities, laboratories, communities, National Working Groups, consortium participants, National Consortium Companies, Project SPVs, reviewers, trainers, learners, challenge participants, benchmark participants, curated-introduction participants, and capability-map subjects where appropriate. Participant records shall identify role, capacity, access, confidentiality, conflict status, data rights, public reference permission, contribution terms, and closeout status.

348.6 Capacity and Role Records. Capacity and role records shall distinguish Board role, officer role, employee role, contractor role, fellow role, advisor role, observer role, learner role, reviewer role, public authority official-capacity role, regulator-listening role, public finance reader role, emergency-management participant role, public infrastructure operator role, community participant role, protected knowledge custodian role, sponsor role, donor role, funder role, provider role, host role, partner role, contributor role, maintainer role, trainer role, participant role, National Consortium Company role, Project SPV role, capital reader role, and public-safe audience role. Capacity and role records shall prevent role collapse, authority inflation, public authority misdescription, sponsor control, provider preference, finance overclaim, certification implication, procurement implication, recognition implication, and maturity overclaim.

348.7 Conflict and Recusal Records. Conflict and recusal records shall document disclosed interests, financial interests, sponsor relationships, donor relationships, funder relationships, provider relationships, host relationships, public authority relationships, family or personal relationships, employment relationships, advisory relationships, investment interests, IP interests, research conflicts, publication conflicts, procurement conflicts, finance-boundary conflicts, certification-boundary conflicts, benchmark conflicts, challenge conflicts, and other interests that may affect program integrity. Records shall identify review, mitigation, recusal, independent review, limitation, denial, or approval. Conflict controls shall apply to program approval, selection, judging, benchmarking, publication, curated introductions, funding, and closeout.

348.8 Data / AI / Cyber Records. Data / AI / cyber records shall document data classes, lawful basis, permissions, privacy review, AI-use class, approved AI tools, prohibited AI tools, model-training restrictions, retrieval restrictions, embedding restrictions, cyber class, access controls, secure storage, repositories, dashboards, maps, public authority data, protected knowledge, personal information, cyber-sensitive materials, infrastructure-sensitive materials, health-sensitive data, finance-sensitive evidence, controlled technology, localization, cross-border transfer, compute-to-data, incident response, data disposition, and correction. These records shall be sufficient to audit whether program data and technical systems remained within approved boundaries.

348.9 Public Authority Records. Public authority records shall document public authority participation, public authority capacity classification, public authority data terms, public authority names, titles, agencies, public authority references, public authority quotes, public authority attendance, public authority data contributions, public finance reader participation, regulator-listening participation, emergency-management participation, infrastructure-operator participation, official-capacity verification, public reference permissions, confidentiality, no-delegation boundaries, no-public-warning boundaries, no-emergency-command boundaries, no-regulatory-approval boundaries, no-procurement-approval boundaries, no-funding-approval boundaries, no-public-finance-approval boundaries, no-sovereign-obligation boundaries, corrections, and closeout.

348.10 Safeguards and Protected Knowledge Records. Safeguards and protected knowledge records shall document community-protected data, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred-site information, protected participants, youth, vulnerable persons, remote communities, health-sensitive groups, public-safe mapping risk, custodial authority, consent or authorization, attribution, non-extraction, confidentiality, access limits, AI-use limits, publication limits, withdrawal rights, correction rights, community review where applicable, geospatial protections, redactions, controlled annexes, and harm-prevention measures. These records shall be classified and protected according to sensitivity.

348.11 Funding Records. Funding records shall document funding sources, grants, donations, sponsorships, subscriptions, fees, in-kind contributions, cost-recovery arrangements, awards, prizes, bounties, stipends, scholarships, fellowships, reimbursements, technical credits, cloud credits, compute credits, software credits, host contributions, public authority contributions, donor restrictions, sponsor benefits, conflict reviews, permitted use, prohibited use, benefit schedules, public acknowledgment language, and financial closeout. Funding records shall preserve nonprofit, non-distribution, public-benefit, anti-capture, sponsor non-control, provider-neutrality, procurement-neutrality, and finance-boundary discipline.

348.12 Grant, Donation, Sponsorship, Subscription, Fee, In-Kind, and Cost-Recovery Records. GCRI Canada shall maintain distinct records for grants, donations, sponsorships, subscriptions, participation fees, program fees, Academy fees, benchmarking subscriptions, challenge funds, prizes, bounties, fellowships, scholarships, stipends, awards, in-kind support, host support, provider credits, donor support, public authority support, and cost-recovery arrangements. Records shall identify source, amount or value, purpose, restrictions, conditions, conflicts, benefits, tax treatment where applicable, recognition language, reporting obligations, refund or clawback terms where any, no-control terms, no-procurement terms, no-finance-readiness terms, no-certification terms, and correction path. No funding record shall be used to imply approval, influence, recognition, maturity, or provider preference.

348.13 Deliverable Records. Deliverable records shall identify program outputs, including research notes, evidence records, methods notes, observability records, ontology updates, public-good software releases, open technical baselines, schemas, APIs, SDKs, dashboards, maps, datasets, model cards, dataset cards, system cards, benchmark cards, training materials, Academy materials, competence-cell materials, public-safe playbooks, controlled annexes, adoption-window outputs, sprint outputs, pilot outputs, lab outputs, challenge outputs, capability maps, curated-introduction records, public-safe summaries, controlled summaries, closeout reports, and archive materials. Deliverable records shall identify status, owner, version, classification, approval, limitations, public-safe status, and correction path.

348.14 Acceptance Records. Acceptance records shall document whether deliverables, milestones, evidence packs, methods notes, software releases, datasets, dashboards, maps, training modules, challenge outputs, benchmark outputs, pilot outputs, lab outputs, adoption-window outputs, or closeout requirements satisfy predefined acceptance gates. Acceptance may be full, partial, conditional, rejected, deferred, superseded, withdrawn, or not applicable. Acceptance records shall not be described as certification, procurement approval, finance-readiness, recognition, maturity, public authority approval, provider preference, public warning, emergency command, or execution authorization unless a separate lawful and competent process expressly provides otherwise.

348.15 Milestone Records. Milestone records shall document program milestones, including intake, approval, launch, participant onboarding, training, access activation, evidence readiness, methods readiness, data / AI / cyber readiness, safeguards review, public authority boundary review, finance-boundary review, host readiness, baseline review, software review, lab phase, sprint phase, pilot phase, benchmark phase, challenge phase, publication review, controlled release, public-safe release, closeout, and correction review. Milestone records shall support management and traceability only and shall not be publicly overclaimed as readiness, certification, procurement status, finance-readiness, recognition, maturity, public authority approval, or provider ranking.

348.16 KPI and KRI Records. KPI and KRI records shall document indicators used to manage program quality, timeliness, public-benefit contribution, accessibility, participation, evidence quality, methods quality, software quality, training completion, correction responsiveness, security posture, privacy posture, safeguards performance, public authority boundary performance, finance-boundary performance, certification-boundary performance, procurement-neutrality performance, provider-neutrality performance, sponsor non-control, and incident learning. KPIs and KRIs shall be limitation-bearing and shall not become external ratings, provider rankings, procurement metrics, finance-readiness metrics, certification scores, maturity scores, public authority scores, or recognition indicators unless separately and lawfully authorized.

348.17 Publication and Communications Records. Publication and communications records shall document program-related websites, articles, social media, speeches, media responses, decks, reports, whitepapers, datasets, software releases, dashboards, maps, repositories, public authority-facing materials, sponsor-facing materials, provider-facing materials, investor-facing or capital-reader materials, Academy materials, public-safe summaries, controlled summaries, press releases, event materials, approved language, disclaimers, publication dates, versions, approval records, public-safe reviews, public authority reviews, finance-boundary reviews, certification-boundary reviews, procurement-boundary reviews, sponsor and provider reference reviews, and correction paths.

348.18 Correction, Supersession, Withdrawal, and Retraction Records. Program correction records shall document errors, omissions, misclassifications, stale records, source issues, method issues, data issues, AI hallucinations, fabricated citations, privacy issues, cyber issues, protected knowledge concerns, public authority misdescriptions, sponsor or provider overclaims, finance overclaims, certification implications, procurement implications, provider-preference issues, public-safe publication issues, dashboard issues, map issues, software issues, dataset issues, benchmark issues, challenge issues, pilot issues, lab issues, and closeout issues. Supersession, withdrawal, and retraction records shall identify reason, authority, date, affected materials, affected participants, notices, replacement outputs, archive status, and dependency review.

348.19 Closeout Records. Closeout records shall document completion, noncompletion, termination, suspension, transfer, deferral, withdrawal, supersession, archival, or renewal of programs. Closeout records shall identify deliverables, non-deliverables, open issues, limitations, incidents, corrections, access revocation, data disposition, repository disposition, dashboard or map status, software status, publication status, public authority reference status, sponsor or provider reference status, funding closeout, participant closeout, IP closeout, confidentiality survival, successor activities, lessons learned, and archive status. Closeout shall prevent stale programs, unmanaged data, obsolete public claims, uncontrolled repositories, and authority inflation.

348.20 Archival, Retention, Deletion, and Secure Disposal Records. GCRI Canada shall maintain archival, retention, deletion, and secure disposal records for program records according to applicable law, corporate governance requirements, nonprofit requirements, public authority terms, data rights, privacy obligations, research integrity, protected knowledge obligations, cybersecurity needs, contractual obligations, donor and grant terms, publication risk, correctionability, institutional memory, and public-benefit need. Records may be retained, sealed, restricted, redacted, anonymized, aggregated, returned, deleted, securely destroyed, archived, or transferred to successor systems according to classification and authority. Secure disposal shall not occur where legal hold, public authority term, research integrity, protected knowledge obligation, incident review, audit requirement, or correctionability requires retention.

Last updated

Was this helpful?