For the complete documentation index, see llms.txt. This page is also available as Markdown.

ARTICLE XVI. BOUNDARIES

Section 372. Public Authority Boundary Purpose

372.1 Public Authority Boundary Purpose. GCRI Canada shall maintain public authority boundary rules to ensure that all engagement with public authorities, regulators, ministries, departments, agencies, municipalities, Crown entities, public institutions, public infrastructure operators, emergency-management bodies, public health bodies, public safety bodies, public works bodies, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, cyber bodies, public finance readers, public-sector hosts, public-sector universities, public laboratories, and other public bodies is lawful, transparent, capacity-classified, evidence-based, method-governed, non-executing, public-safe, correctionable, and compatible with GCRI Canada’s role as an upstream public-benefit steward of research, evidence, methods, observability, ontology, public-good software, open technical baselines, technical literacy, public-safe publication, and Nexus-compatible interfaces. Public authority engagement shall support learning, evidence literacy, technical literacy, public-safe reporting discipline, scenario and simulation learning, observability understanding, and public-benefit coordination, and shall not create governmental power, public authority delegation, official adoption, public warning authority, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, sovereign obligation, or public-private partnership by implication.

372.2 Lawful Public Authority Engagement. GCRI Canada may engage with public authorities only where such engagement is lawful, mission-aligned, public-benefit oriented, role-separated, capacity-classified, and appropriately recorded. Lawful engagement may include education, evidence literacy, methods literacy, technical literacy, research exchange, public-safe reporting support, observability learning, dashboard and map limitation training, scenario and simulation learning, public authority learning programs, public finance reader literacy, emergency-management learning, infrastructure operator learning, data / AI / cyber literacy, public-good software learning, public-safe publication review, public consultation response, or participation in approved programs. Engagement shall not exceed GCRI Canada’s authority or convert GCRI Canada into a regulator, public agency, public warning body, public finance body, emergency-management body, procurement body, certifier, or execution vehicle.

372.3 Transparent Capacity Classification. Every material public authority engagement shall include transparent capacity classification sufficient to identify whether the public authority participant appears as an official participant, institutional representative, delegated representative, observer, speaker, technical expert, policy discussant, regulator-listening participant, public finance reader, public infrastructure operator, emergency-management participant, public health participant, public safety participant, public works participant, academic representative of a public institution, personal-capacity participant, non-attributable participant, controlled-room participant, host authority, data provider, reviewer, simulation participant, or other defined capacity. Capacity classification shall determine attribution, confidentiality, access, publication, reference language, public-safe treatment, and correction obligations. Ambiguous capacity shall be resolved before public reference.

372.4 Evidence Literacy Support. GCRI Canada may support public authority evidence literacy by explaining source lineage, evidence classification, confidence notes, limitation notes, stale-source handling, missing-source handling, contradiction handling, public-safe summaries, evidence packs, proof packs, observability records, technical evidence inputs, controlled annexes, correction records, and archive status. Evidence literacy support shall assist public authorities and public-sector readers in understanding evidence discipline, but shall not determine facts for legal, regulatory, procurement, public finance, emergency, operational, or public warning purposes. Public authorities remain responsible for their own decisions, statutory duties, evidentiary standards, and legal reliance.

372.5 Technical Literacy Support. GCRI Canada may support technical literacy for public authorities concerning data governance, AI governance, cybersecurity, observability methods, AI-RAN, O-RAN, DePIN, digital twins, geospatial systems, Earth observation, sensing, sovereign compute, verifiable compute, public-good software, technical baselines, interoperability profiles, dashboards, maps, model cards, dataset cards, system cards, benchmark cards, ontology, schemas, APIs, controlled vocabularies, and public-safe publication. Technical literacy support shall be educational and non-executing. It shall not constitute engineering approval, cybersecurity certification, AI certification, public infrastructure approval, procurement specification, compliance determination, public authority adoption, or operational instruction.

372.6 Public-Safe Reporting Support. GCRI Canada may support public-safe reporting by helping public authorities and public-sector readers understand how to communicate evidence, uncertainty, limitations, dashboards, maps, observability outputs, AI-assisted outputs, public authority references, sponsor references, provider references, finance-boundary language, certification-boundary language, procurement-boundary language, and correction paths in a manner that reduces public misunderstanding and overclaim. Such support shall not substitute for public authority communications, statutory notices, official warnings, emergency alerts, public health orders, regulatory guidance, procurement documents, funding decisions, or public finance communications. Public-safe reporting support shall remain advisory, educational, and correctionable.

372.7 Scenario and Simulation Learning Support. GCRI Canada may support scenario and simulation learning, including tabletop exercises, digital twin literacy, resilience scenarios, public-safe dashboards, map exercises, degraded-mode awareness exercises, cyber exercises, AI incident exercises, public authority learning drills, public-safe publication drills, infrastructure learning scenarios, and after-action evidence review. Scenario and simulation support shall be bounded by training, learning, evidence, and methods objectives. It shall not constitute real-world incident command, dispatch authority, evacuation instruction, operational resource direction, public warning, public safety order, public health order, infrastructure operation, public finance approval, procurement approval, or legal determination.

372.8 Observatory and Truth Engine Learning Support. GCRI Canada may support learning concerning Nexus Observatory methods, observability records, telemetry, sensing, AI-RAN / O-RAN evidence methods, DePIN evidence methods, geospatial methods, digital twin methods, degraded-mode awareness, resilience indicators, Truth Engine methods, source comparison, contradiction handling, spoof detection, confidence support, verifiable intelligence records, and public-safe intelligence outputs. Observatory and Truth Engine learning support shall make clear that such outputs are evidence and methods artifacts, not absolute truth, public warnings, emergency commands, public authority decisions, official regulatory determinations, procurement approvals, certification outcomes, finance-readiness determinations, or operational instructions.

372.9 Public Authority Data Handling Discipline. GCRI Canada shall handle public authority data according to lawful basis, authority, confidentiality, classification, data rights, privacy, public authority terms, security, access controls, retention, deletion, publication restrictions, AI-use restrictions, cyber sensitivity, infrastructure sensitivity, protected knowledge overlap, public-safe status, and correction path. Public authority data shall not be uploaded to unapproved AI systems, placed in public repositories, reused outside approved purpose, disclosed beyond authorized access, or converted into public materials without required review. GCRI Canada’s receipt or review of public authority data shall not create public authority status or delegated power.

372.10 Public Authority Reference Discipline. Public authority names, logos, titles, quotes, photographs, attendance, data contributions, comments, facilities, letters, emails, briefings, public finance reader participation, regulator-listening participation, emergency-management participation, infrastructure operator participation, or official-capacity participation shall be referenced only according to approved language, capacity classification, attribution permission, logo permission, confidentiality, public-safe review, and correction rules. Public references shall not imply endorsement, adoption, approval, funding, procurement, public finance approval, regulatory approval, public-private partnership, sovereign obligation, public warning, emergency command, or public authority delegation unless expressly authorized by competent public authority record and approved by GCRI Canada.

372.11 No Governmental Power by Engagement. No public authority engagement shall confer governmental power on GCRI Canada. GCRI Canada shall not acquire, exercise, claim, imply, or accept legislative, regulatory, adjudicative, enforcement, permitting, licensing, inspection, emergency, public warning, public health, public safety, procurement, budgetary, public finance, tax, sovereign, or other governmental power by reason of meetings, participation, funding, data sharing, hosting, observer status, regulator-listening status, public finance reader status, emergency-management participation, infrastructure operator participation, public authority learning, or public-sector collaboration.

372.12 No Delegated Public Authority by Participation. No public authority participation in GCRI Canada programs, councils, committees, working groups, labs, Academy sessions, adoption windows, replication sprints, governed pilots, challenge programs, benchmarking programs, host activations, controlled rooms, public-safe publication review, or Nexus interface activities shall constitute delegation of public authority to GCRI Canada. Any actual public authority delegation, if ever permitted by law, would require separate express lawful instrument, competent public authority action, Board review, legal review, public-safe review, and clear boundary records; participation alone is never sufficient.

372.13 No Public Authority Adoption by Attendance. Attendance, observation, speaking, listening, review, participation, data contribution, public finance reading, regulator listening, emergency-management learning, infrastructure operator input, public-sector hosting, public authority comment, public authority workshop participation, or public authority presence at a GCRI Canada event shall not constitute public authority adoption of GCRI Canada materials, methods, software, technical baselines, dashboards, maps, publications, public-safe summaries, evidence packs, proof packs, Nexus-compatible interfaces, finance-readiness concepts, or technical claims. Adoption exists only where the competent public authority separately and lawfully records adoption within its own authority.

372.14 No Public Warning, Emergency Command, Regulation, Procurement Approval, Funding Approval, Public Finance Approval, or Sovereign Obligation. No GCRI Canada public authority engagement, output, dashboard, map, observability signal, Truth Engine output, public-safe summary, technical note, evidence pack, proof pack, scenario, simulation, exercise, training, Academy material, public report, whitepaper, dataset, software release, technical baseline, curated introduction, capability map, benchmark, challenge result, lab output, or public authority learning material shall constitute public warning, emergency command, regulation, regulatory approval, compliance approval, procurement approval, vendor selection, funding approval, public finance approval, grant approval, budget allocation, appropriation approval, public guarantee, public credit approval, sovereign obligation, public-private partnership, or public authority decision.

372.15 Public Authority Boundary Records. GCRI Canada shall maintain public authority boundary records, including public authority boundary purpose records, lawful engagement records, capacity classification records, evidence literacy support records, technical literacy support records, public-safe reporting support records, scenario and simulation learning support records, Observatory and Truth Engine learning support records, public authority data handling records, public authority reference records, no-governmental-power records, no-delegated-public-authority records, no-public-authority-adoption-by-attendance records, no-public-warning / no-emergency-command / no-regulation / no-procurement-approval / no-funding-approval / no-public-finance-approval / no-sovereign-obligation records, corrections, clarifications, withdrawals, closeouts, and archives.


Section 373. Capacity Classification for Public Authority Participants

373.1 Capacity Classification Requirement. GCRI Canada shall classify the capacity of every material public authority participant before or at the time of participation, and shall update or correct that classification where facts change, ambiguity emerges, public references are proposed, data is contributed, controlled access is requested, publication is planned, or misunderstanding occurs. Capacity classification shall identify the public body, participant role, authority scope, attribution permissions, confidentiality, data rights, public statement limits, access rights, public authority reference limits, and boundary language. Classification shall be specific and shall not allow a person’s government title to imply broader authority than actually recorded.

373.2 Official Participant. An official participant is a person participating on behalf of a public authority in an official capacity within a recorded or reliably evidenced scope. Official participant status shall identify the public body represented, authority basis, subject matter, permitted engagement, attribution permission, public statement limits, data authority, publication review where required, and limits. Official participant status does not imply public authority adoption, public warning authority, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, sovereign obligation, or delegation to GCRI Canada.

373.3 Institutional Representative. An institutional representative is a person participating as a representative of a ministry, department, agency, municipality, Crown entity, utility, public institution, public university, public laboratory, public hospital, public infrastructure operator, or other public-sector institution, but whose authority may be limited to institutional discussion, learning, technical input, or liaison. GCRI Canada shall not treat institutional representative status as equivalent to formal delegated authority unless authority is separately established. Public references shall state institutional role only within approved language.

373.4 Delegated Representative. A delegated representative is a person whose public authority has expressly delegated a defined role for a specific GCRI Canada engagement or related process. Delegation shall be documented or reliably evidenced, scope-bound, revocable where applicable, and limited to the authority actually conferred. Delegated representative status shall not expand GCRI Canada’s authority, create public authority delegation to GCRI Canada, or authorize GCRI Canada to act as a public authority. Any ambiguity shall be resolved conservatively.

373.5 Observer. An observer is a person attending, viewing, listening, or reviewing materials for learning, awareness, monitoring, or informational purposes without decision rights, voting rights, approval rights, adoption rights, endorsement rights, public authority commitment authority, procurement authority, funding authority, regulatory authority, public warning authority, or public finance authority. Observer status shall be recorded where material and shall be accompanied by non-endorsement, no-adoption, and no-reliance language where appropriate.

373.6 Speaker. A speaker is a public authority participant who presents remarks, technical context, institutional experience, policy context, learning content, or public-sector perspective in a GCRI Canada setting. Speaker status shall identify whether remarks are official, personal, educational, non-attributable, or otherwise limited. Speaker participation shall not imply public authority endorsement of GCRI Canada, GCRI Canada endorsement of the public authority, public authority adoption, public warning, regulatory approval, procurement approval, funding approval, or public finance approval.

373.7 Technical Expert. A technical expert is a public authority participant contributing technical knowledge, operational context, scientific knowledge, engineering context, data context, cyber context, AI context, infrastructure context, geospatial context, health context, public safety context, or public works context within a defined scope. Technical expert status shall not be treated as authority to approve GCRI Canada methods, certify outputs, bind a public authority, issue official interpretation, approve procurement, determine compliance, or direct public operations.

373.8 Policy Discussant. A policy discussant is a public authority participant discussing public policy context, governance questions, regulatory landscape, institutional constraints, public-sector needs, risk considerations, or learning topics without issuing official guidance, binding interpretation, regulatory approval, public authority adoption, procurement approval, funding approval, public finance approval, or public warning. Policy discussion shall be characterized as learning and dialogue unless separately authorized by competent public authority record.

373.9 Regulator-Listening Participant. A regulator-listening participant is a public authority participant attending for awareness, listening, technical understanding, policy learning, or market understanding without providing regulatory guidance, safe harbor, compliance determination, permit, approval, enforcement position, official interpretation of law, or endorsement. Regulator-listening participation shall be handled with competition and market conduct controls where industry participants are present. Public references shall be restricted and approved.

373.10 Public Finance Reader. A public finance reader is a public authority, public finance body, development finance body, grant body, guarantee body, treasury body, budget body, municipal finance body, Crown finance body, or other public-sector finance reader reviewing materials for diligence literacy, evidence understanding, technical literacy, or public-benefit learning without committing funds, approving grants, allocating budgets, approving appropriations, approving MDB or DFI support, issuing guarantees, approving public credit, creating sovereign obligations, or making public finance commitments. Public finance reader status shall require non-reliance and finance-boundary language.

373.11 Public Infrastructure Operator. A public infrastructure operator is a public-sector or public-interest operator of infrastructure, including utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, cyber systems, transport systems, public works systems, or other critical systems, participating to provide context, operational knowledge, evidence, data where authorized, or learning. Such status shall not give GCRI Canada operational control or create infrastructure performance warranty, resilience guarantee, procurement approval, public authority adoption, public warning, or public safety command.

373.12 Emergency-Management Participant. An emergency-management participant is a public authority or public-sector participant involved in emergency management, disaster management, incident management, civil protection, public safety coordination, public health emergency coordination, cyber incident coordination, or resilience planning, participating for emergency learning, evidence understanding, scenario practice, simulation, tabletop, Observatory learning, dashboard literacy, map literacy, or after-action review. Such status shall not confer incident command, dispatch authority, evacuation authority, public warning authority, operational resource direction, responder command, or emergency communications authority on GCRI Canada.

373.13 Public Health Participant. A public health participant is a public authority participant associated with public health, health systems, disease surveillance, health emergency management, health data, environmental health, community health, or health-sensitive public-sector functions. Public health participation shall be governed by confidentiality, privacy, health-sensitive data controls, public authority boundaries, public-safe reporting limits, and no-public-health-order language. GCRI Canada shall not issue public health guidance, public health warnings, clinical advice, health orders, or official health determinations by reason of such participation.

373.14 Public Safety Participant. A public safety participant is a public authority participant associated with public safety, policing, fire, emergency services, civil protection, public security, cyber safety, critical incident response, transport safety, or other safety functions. Public safety participation shall be governed by public-safe handling, confidentiality, law enforcement sensitivity where applicable, infrastructure sensitivity, public warning boundaries, emergency command boundaries, and no-operational-direction language. GCRI Canada shall not direct public safety operations.

373.15 Public Works Participant. A public works participant is a public authority participant associated with public works, municipal services, transportation, roads, water, wastewater, waste, public facilities, infrastructure maintenance, utilities coordination, or related systems. Public works participation may support infrastructure context, methods learning, observability literacy, resilience learning, and public-safe reporting, but shall not create public works approval, procurement approval, operational control, infrastructure warranty, resilience guarantee, or public authority adoption.

373.16 Academic Representative of Public Institution. An academic representative of a public institution is a participant from a public university, public college, public research institute, public laboratory, teaching hospital, or other public academic body participating in an academic, research, technical, institutional, or personal capacity. Such classification shall distinguish academic freedom, institutional representation, public authority status, research collaboration, employment affiliation, and personal capacity. Public academic affiliation shall not imply government adoption, public authority delegation, public finance approval, procurement approval, or official policy position.

373.17 Personal-Capacity Participant. A personal-capacity participant is a person employed by, affiliated with, or formerly affiliated with a public authority but participating personally, academically, professionally, or independently, not on behalf of the public authority. Personal-capacity status shall be clearly recorded where material and shall restrict use of official titles, logos, public authority names, or implied official views unless approved. Personal-capacity participation shall not be represented as public authority participation.

373.18 Non-Attributable Participant. A non-attributable participant is a person whose participation may be recognized internally or within controlled records but not attributed publicly, quoted, named, photographed, recorded, or linked to a public authority without permission. Non-attributable status shall be used where confidentiality, learning, Chatham House-style discussion, public authority sensitivity, market sensitivity, protected knowledge, public safety, or policy sensitivity requires it. Non-attribution shall not be used to conceal improper influence or prohibited commitments.

373.19 Controlled-Room Participant. A controlled-room participant is a person permitted to access controlled, restricted, confidential, public authority-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, protected-knowledge, data-room, no-download-room, or other controlled materials. Controlled-room status shall require access approval, confidentiality, purpose limitation, no-redistribution, AI-use restrictions, logging where appropriate, public statement limits, and closeout. Controlled-room participation shall not imply approval, endorsement, adoption, finance-readiness, certification, procurement approval, or public authority delegation.

373.20 Host Authority. A host authority is a public authority or public-sector institution hosting, co-hosting, providing facilities, providing logistical support, providing data access, providing learning context, or otherwise supporting a GCRI Canada program or activity. Host authority status shall be governed by host records, facility rules, data rights, safety, public reference permissions, logo permissions, public authority boundary language, and no-endorsement language. Hosting shall not imply public authority adoption, procurement approval, funding approval, public finance approval, public warning, emergency command, or sovereign obligation.

373.21 Data Provider. A data provider is a public authority participant or public-sector institution providing data, records, documents, telemetry, maps, dashboards, public datasets, restricted datasets, operational context, public authority terms, or other source materials to GCRI Canada. Data provider status shall require data rights, lawful basis, classification, confidentiality, privacy, security, AI-use restrictions, publication limits, retention, deletion, and correction path. Providing data shall not transfer decision authority to GCRI Canada or imply public authority approval of outputs.

373.22 Reviewer. A reviewer is a public authority participant asked to review facts, public authority references, data accuracy, public-safe language, public authority capacity, controlled materials, technical context, public-sector terminology, or publication language within a defined scope. Reviewer status shall not create veto rights, suppression rights, approval rights, adoption rights, or authority over findings unless separately and lawfully recorded. GCRI Canada may accept, reject, record, or correct reviewer comments according to its own governance and legal obligations.

373.23 Simulation Participant. A simulation participant is a public authority participant involved in tabletop exercises, scenario exercises, digital twin exercises, emergency-learning simulations, public-safe publication drills, observability exercises, cyber exercises, dashboard drills, map exercises, or after-action learning. Simulation participation shall be learning-only unless separately authorized by the participant’s public authority for its own purposes. Simulation participation shall not create real-world emergency command, dispatch authority, public warning authority, evacuation authority, operational direction, procurement approval, funding approval, or public finance approval.

373.24 Capacity Review, Confirmation, Update, and Correction. Public authority capacity classifications shall be reviewed, confirmed, updated, or corrected where participation changes, authority changes, public references are proposed, publication is planned, data is contributed, controlled access is requested, official status is questioned, public claims arise, or misdescription is identified. GCRI Canada shall correct public authority capacity errors promptly and proportionately through internal correction, controlled notice, public-safe clarification, revised publication, withdrawal, or archive note where appropriate.

373.25 Capacity Classification Records. GCRI Canada shall maintain capacity classification records, including classification requirement records, official participant records, institutional representative records, delegated representative records, observer records, speaker records, technical expert records, policy discussant records, regulator-listening participant records, public finance reader records, public infrastructure operator records, emergency-management participant records, public health participant records, public safety participant records, public works participant records, academic representative records, personal-capacity records, non-attributable participant records, controlled-room participant records, host authority records, data provider records, reviewer records, simulation participant records, capacity review records, confirmation records, update records, correction records, and archives.


Section 374. Official Capacity Records, Authority Scope, Attribution Permission, Limits, and Approved Public Language

374.1 Official Capacity Record Requirement. GCRI Canada shall require official capacity records where a public authority participant is presented, treated, quoted, recorded, referenced, relied upon, granted access, or engaged as acting in an official capacity. Official capacity records shall identify the public body, participant, title, role, authority basis, scope, subject matter, attribution permissions, quote permissions, logo and name permissions, photograph and recording permissions, data contribution permissions, publication review requirements, approved public language, non-endorsement language, and correction path. Official capacity shall not be inferred solely from title, email domain, attendance, seniority, letterhead, business card, prior relationship, public office, or public-sector employment.

374.2 Written Authority Evidence Where Required. Where law, public authority rules, program risk, publication risk, data sensitivity, public authority reference risk, funding risk, public finance context, emergency-management context, procurement context, or GCRI Canada policy requires it, written authority evidence shall be obtained before official-capacity treatment. Written evidence may include letter, email, delegation record, authorization form, official nomination, participation agreement, memorandum, public authority approval, data-sharing instrument, host agreement, or other competent record. The written evidence shall be retained and shall define scope rather than create open-ended authority.

374.3 Reliable Authority Evidence Where Written Instrument Is Not Available. Where a written instrument is not available or not customary, GCRI Canada may rely on reliable authority evidence proportionate to risk, including official correspondence, public authority meeting arrangements, verified public role, authorized public event listing, confirmed agency participation, recorded verbal confirmation, prior written engagement, or other reliable indication. Reliable authority evidence shall be documented. Where risk is material or public reference is planned, GCRI Canada shall seek confirmation or use conservative, non-attributable, observer, or personal-capacity classification.

374.4 Authority Scope. Official capacity records shall define authority scope by subject matter, program, meeting, event, document, data contribution, review function, speaking role, attribution, publication, time period, geography, and limitations. Authority scope shall identify what the participant may do and what the participant may not do. Authority to attend shall not imply authority to endorse. Authority to speak shall not imply authority to adopt. Authority to review facts shall not imply authority to approve findings. Authority to provide data shall not imply authority to approve publication.

374.5 Agency, Department, Ministry, Municipality, Crown, Utility, Public Institution, Regulator, Operator, or Other Public Body Identification. Official capacity records shall accurately identify the relevant public body, including agency, department, ministry, municipality, Crown entity, public institution, regulator, public finance body, utility, port authority, telecom authority, energy authority, water authority, public health body, public safety body, public works body, infrastructure operator, university, laboratory, hospital, or other public-sector body. GCRI Canada shall avoid generic references to “government,” “the regulator,” “the public authority,” or “official support” where the specific public body, capacity, and permission are not clear.

374.6 Participant Role. Official capacity records shall identify participant role, including representative, delegate, observer, speaker, reviewer, technical expert, data provider, host, regulator-listening participant, public finance reader, emergency-management participant, public infrastructure operator, public health participant, public safety participant, simulation participant, controlled-room participant, or other capacity. Participant role shall control public language, access, confidentiality, and output treatment. Role ambiguity shall be resolved through clarification or conservative public language.

374.7 Delegated Authority Limits. Where a public authority participant has delegated authority, GCRI Canada shall record the limits of the delegation, including subject matter, decision rights, approval rights, prohibition on commitments, attribution rights, data rights, publication rights, confidentiality, and expiration. GCRI Canada shall not treat delegated authority as authority for public finance approval, procurement approval, regulatory approval, emergency command, public warning, sovereign obligation, or official adoption unless expressly stated by competent public authority record. Delegated authority to participate is not delegation to GCRI Canada.

374.8 Attribution Permission. Attribution permission shall be obtained and recorded before naming a public authority participant, public body, office, title, department, agency, ministry, municipality, Crown entity, regulator, operator, or public institution in a publication, report, website, deck, social media post, press release, donor report, sponsor report, controlled summary, public-safe summary, dashboard, map, dataset, software release, or public event material. Attribution permission may be limited by wording, time, channel, audience, context, and review. Absence of attribution permission shall require non-attribution or removal.

374.9 Quote Permission. Quote permission shall be obtained and recorded before using public authority quotes, paraphrases, endorsements, comments, review statements, event remarks, interview statements, panel remarks, or technical comments in public or controlled materials. Quote permission shall identify exact wording or approved paraphrase, attribution, context, public authority capacity, limitations, and withdrawal or correction path. Quotes shall not be edited to imply endorsement, adoption, procurement approval, finance-readiness, certification, recognition, public warning, or public authority decision.

374.10 Logo and Name Permission. Public authority logos, official seals, crests, names, ministry names, department names, municipality names, Crown names, agency names, regulator names, public institution names, utility names, port names, public university names, public laboratory names, or other official identifiers shall be used only with permission where required and after public authority reference review. Logo or name use shall not imply endorsement, adoption, approval, funding, procurement, public finance approval, public-private partnership, sovereign obligation, public warning, emergency command, or delegation unless expressly authorized and accurately described.

374.11 Photograph and Recording Permission. Photographs, recordings, screenshots, video clips, audio clips, transcripts, event images, meeting images, panel recordings, training recordings, public authority participant images, public-sector facility images, public authority logos visible in images, and controlled-room images shall be used only with appropriate permission and review. Review shall address attribution, consent, privacy, security, public authority sensitivity, infrastructure sensitivity, protected knowledge, public-safe context, and public reference risk. Visual materials shall not create implied endorsement.

374.12 Data Contribution Permission. Public authority data contribution permission shall be recorded before GCRI Canada receives, processes, stores, analyzes, models, publishes, summarizes, embeds, transfers, or otherwise uses public authority data, unless the data is lawfully public and use is permitted. Permission shall identify data class, source, lawful basis, use limits, access limits, AI-use restrictions, model-training restrictions, retention, deletion, publication, public-safe summary, correction, and return. Public authority data contribution shall not imply approval of GCRI Canada outputs.

374.13 Publication Review Where Required. Where public authority terms, data rights, confidentiality, attribution permission, quote permission, protected knowledge, security, public-safe review, law, or agreement requires publication review, GCRI Canada shall conduct or permit such review within recorded scope. Publication review may address factual accuracy, confidential information, data sensitivity, protected knowledge, public authority reference, security, legal compliance, and approved language. Publication review shall not become veto over independent findings, suppression of public-benefit correction, finance-readiness influence, certification influence, procurement influence, or provider preference unless lawful confidentiality or public-safe obligations require restriction.

374.14 Approved Public Language. Approved public language shall be used for public authority references where required or appropriate. Such language shall accurately describe capacity, participation, role, program, and limits. Approved public language may state that a public authority participated as observer, learner, speaker, technical expert, regulator-listening participant, public finance reader, host, data provider, reviewer, or simulation participant, and that participation does not imply endorsement, adoption, approval, procurement, funding, public finance approval, public warning, emergency command, or public authority delegation. Public language shall be plain enough to prevent reasonable misinterpretation.

374.15 Non-Endorsement Language. Non-endorsement language shall be included where public authority references could be misunderstood. Such language may state that public authority participation, attendance, contribution, hosting, review, data sharing, or quote does not constitute endorsement of GCRI Canada, endorsement by GCRI Canada, public authority approval, regulatory approval, procurement approval, funding approval, public finance approval, certification, recognition, public warning, emergency command, public-private partnership, sovereign obligation, or adoption of any output. Non-endorsement language shall be proximate where risk is material.

374.16 No Implied Expansion of Official Capacity. Official capacity shall not expand by implication. A public authority participant’s attendance at one meeting shall not authorize public attribution in another context. Permission to use a name shall not authorize logo use. Permission to quote shall not authorize endorsement language. Permission to review facts shall not authorize approval language. Permission to provide data shall not authorize publication. Participation in one program shall not imply adoption of another program. GCRI Canada shall interpret authority narrowly and correct overbroad use.

374.17 Official Capacity Correction. Where official capacity is misstated, overbroad, stale, ambiguous, disputed, withdrawn, or misused, GCRI Canada shall correct the record and, where necessary, correct public materials, controlled materials, donor reports, sponsor reports, decks, websites, social media, public-safe summaries, dashboards, maps, datasets, software release notes, press materials, or archives. Correction may include revised language, removal of logos, removal of quotes, capacity clarification, public-safe correction notice, controlled notice, withdrawal, or archive note.

374.18 Official Capacity Records. GCRI Canada shall maintain official capacity records, including official capacity requirement records, written authority evidence, reliable authority evidence, authority scope records, public body identification records, participant role records, delegated authority limits, attribution permissions, quote permissions, logo and name permissions, photograph and recording permissions, data contribution permissions, publication review records, approved public language, non-endorsement language, no-implied-expansion records, official capacity corrections, withdrawals, supersessions, and archives.


Section 375. Observer Status

375.1 Observer Status Definition. Observer status means participation by a public authority participant, public-sector person, public institution representative, regulator, public finance reader, infrastructure operator, emergency-management participant, or other approved participant solely for observation, learning, awareness, listening, or informational purposes, without governance authority, approval authority, adoption authority, public authority commitment authority, public warning authority, emergency command, regulatory authority, procurement authority, funding authority, public finance authority, certification authority, finance-readiness authority, provider-selection authority, or authority to bind GCRI Canada or the public authority.

375.2 Observer Participation as Learning and Observation Only. Observer participation shall be treated as learning and observation only. Observers may attend meetings, trainings, Academy sessions, briefings, dashboards, map demonstrations, scenarios, simulations, labs, public-safe reviews, controlled rooms where authorized, or other activities to understand evidence, methods, technical baselines, observability concepts, public-safe publication, data / AI / cyber controls, and Nexus-compatible interfaces. Observation shall not be described as approval, endorsement, adoption, validation, certification, procurement review, funding review, finance-readiness review, public warning review, or public authority decision-making.

375.3 Observer Access Limits. Observer access shall be limited to materials, sessions, data, dashboards, maps, rooms, records, discussions, and systems approved for observer status. Access may be public, public-safe, controlled, restricted, no-download, read-only, time-limited, or otherwise conditioned according to classification. Observers shall not receive access merely because of title or public authority affiliation. Observer access may be denied or revoked for confidentiality risk, data risk, public authority sensitivity, cyber risk, protected knowledge risk, finance-boundary risk, competition risk, conflict, or misuse.

375.4 Observer Confidentiality. Observers shall comply with confidentiality, non-disclosure, non-attribution, controlled-room, data-room, public authority, protected knowledge, cyber-sensitive, infrastructure-sensitive, finance-sensitive, legal, and publication restrictions applicable to the materials and sessions accessed. Confidentiality obligations may survive the observer’s participation. Observer status does not authorize redistribution, public quoting, screen captures, AI uploads, external reports, social media references, provider marketing, public authority claims, or capital-reader use unless expressly authorized.

375.5 Observer Data Access Limits. Observer data access shall be limited by purpose, classification, lawful basis, public authority terms, privacy, protected knowledge, cybersecurity, infrastructure sensitivity, finance sensitivity, AI-use restrictions, model-training restrictions, and publication posture. Observers shall not download, export, copy, scrape, embed, train models on, or reuse data except as expressly authorized. Public authority observers shall not treat access to GCRI Canada data or materials as public authority custody, public record adoption, official notice, regulatory filing, procurement submission, or public finance submission unless separately and lawfully established.

375.6 Observer Public Statement Limits. Observers shall not make public statements implying that observer participation constitutes endorsement, adoption, approval, public authority support, procurement approval, funding approval, public finance approval, regulatory approval, public warning, emergency command, certification, recognition, finance-readiness, provider preference, maturity, or Nexus-compatible status. Any public reference to observer participation shall use approved language and may require GCRI Canada review and public authority review. Unauthorized public statements may require correction, clarification, access revocation, or termination.

375.7 Observer No-Vote Rule Unless Separately Authorized in Advisory Context. Observers shall have no vote, consent right, veto right, approval right, quorum role, decision right, adoption right, or blocking right in GCRI Canada governance, committees, councils, working parties, labs, challenges, benchmarks, programs, publications, technical baselines, software releases, public-safe outputs, corrections, or Nexus interface outputs unless a separate lawful advisory process expressly grants a non-binding advisory vote or recorded input mechanism. Any advisory vote by an observer shall remain non-binding unless otherwise lawfully authorized by competent GCRI Canada governance record.

375.8 Observer No-Governance-Control Rule. Observer status shall not confer governance control over GCRI Canada, including Board decisions, officer decisions, budgets, programs, staffing, research agenda, evidence records, methods, publications, software, technical baselines, data access, public authority interfaces, sponsor benefits, provider references, Nexus interfaces, corrections, or public-safe outputs. Observers shall not direct GCRI Canada personnel or control program outcomes.

375.9 Observer No-Endorsement Rule. Observer status shall not imply endorsement by the observer, the observer’s public authority, the observer’s public institution, GCRI Canada, or any Nexus-compatible body. Observation is not endorsement of GCRI Canada materials, methods, publications, software, technical baselines, dashboards, maps, evidence packs, proof packs, finance-boundary materials, certification-boundary materials, public-safe outputs, or program decisions. Observer references shall include non-endorsement language where material.

375.10 Observer No-Adoption Rule. Observer participation shall not constitute public authority adoption of any GCRI Canada method, baseline, software, dashboard, map, publication, evidence pack, public-safe summary, ontology, Academy material, lab result, sprint result, pilot result, benchmark, challenge output, or Nexus interface output. Adoption requires separate lawful action by the competent public authority within its own governance. GCRI Canada shall not publish “adopted by” language based on observer participation.

375.11 Observer No-Procurement-Approval Rule. Observer participation shall not constitute procurement approval, tender approval, vendor approval, prequalification, preferred provider status, purchasing recommendation, procurement requirement, public-sector eligibility, or contract award. Providers shall not cite public authority observer presence as procurement validation. Public authorities remain responsible for their own procurement processes.

375.12 Observer No-Funding-Approval Rule. Observer participation shall not constitute grant approval, budget approval, appropriation approval, funding commitment, funding recommendation, public finance approval, public guarantee, credit approval, development finance approval, municipal finance approval, Crown finance approval, or public authority financial commitment. Public finance readers and public authority observers shall not be described as funders unless a separate lawful funding record exists.

375.13 Observer No-Regulatory-Approval Rule. Observer participation shall not constitute regulatory approval, compliance determination, legal interpretation, safe harbor, permit, license, enforcement position, official guidance, conformity finding, or regulator endorsement. Regulator observers shall be treated under regulator-listening or observer boundaries unless a separate official public authority record states otherwise.

375.14 Observer No-Public-Warning Rule. Observer participation shall not create public warning authority, public alert authority, emergency bulletin authority, public health warning, public safety warning, evacuation instruction, emergency command, operational resource direction, responder command, or official emergency communications status. Dashboards, maps, simulations, scenarios, and observability outputs reviewed by observers remain non-warning outputs unless separately issued by a competent public authority.

375.15 Observer No-Sovereign-Obligation Rule. Observer participation shall not create sovereign obligation, Crown obligation, municipal obligation, public debt, public guarantee, public-private partnership, concession, procurement commitment, funding commitment, public finance obligation, treaty obligation, intergovernmental obligation, or official public authority undertaking. No observer may bind the public authority through GCRI Canada participation unless separately and lawfully authorized and recorded outside observer status.

375.16 Observer Records. GCRI Canada shall maintain observer records, including observer status definitions, learning and observation records, access limit records, confidentiality records, data access limit records, public statement limit records, no-vote records, no-governance-control records, no-endorsement records, no-adoption records, no-procurement-approval records, no-funding-approval records, no-regulatory-approval records, no-public-warning records, no-sovereign-obligation records, corrections, access revocations, terminations, closeouts, and archives.


Section 376. Regulator-Listening Status

376.1 Regulator-Listening Status Definition. Regulator-listening status means participation by a regulator, regulatory agency, supervisory authority, enforcement body, standards regulator, sector regulator, public authority legal or compliance official, or other public-sector regulatory participant for listening, learning, awareness, technical understanding, policy context, or market understanding only, without providing regulatory guidance, safe harbor, permit, compliance determination, enforcement position, official interpretation of law, regulatory approval, public authority endorsement, procurement approval, finance-readiness determination, certification, public warning, or public authority delegation.

376.2 Listening, Learning, and Technical Understanding Only. Regulator-listening participation shall be limited to listening, learning, technical understanding, evidence literacy, methods literacy, data / AI / cyber literacy, observability literacy, public-safe publication literacy, and public-benefit discussion. Regulator-listening participants may ask questions, provide general context where permitted, identify public sources, or explain general learning needs, but shall not be treated as approving, validating, accepting, endorsing, certifying, adopting, or authorizing any GCRI Canada output, provider activity, public-good software, technical baseline, dashboard, map, dataset, benchmark, challenge result, lab output, or Nexus interface.

376.3 No Regulatory Guidance. GCRI Canada shall not represent regulator-listening participation as regulatory guidance. Statements made in regulator-listening contexts shall not be treated as official guidance, binding interpretation, compliance advice, public authority position, or regulatory direction unless separately issued by the competent regulator through its own official process. GCRI Canada shall use caution in recording, quoting, summarizing, or publishing regulator-listening discussions.

376.4 No Safe Harbor. No regulator-listening participation shall create safe harbor, regulatory immunity, enforcement relief, exemption, waiver, no-action position, comfort letter, compliance blessing, or reduced regulatory exposure for GCRI Canada, any participant, provider, sponsor, donor, host, National Consortium Company, Project SPV, public authority, or other actor. Any safe harbor or no-action status exists only where issued by the competent regulator through lawful official process.

376.5 No Permit. Regulator-listening participation shall not constitute permit, license, authorization, registration, approval, waiver, exemption, consent, certificate, inspection approval, operating authority, data-processing approval, AI deployment approval, cybersecurity approval, infrastructure approval, telecom approval, environmental approval, health approval, public safety approval, or other regulated permission. Participants shall not cite regulator-listening attendance as evidence of permit status.

376.6 No Compliance Determination. Regulator-listening participation shall not determine compliance with laws, regulations, standards, public authority requirements, procurement requirements, data protection requirements, AI requirements, cybersecurity requirements, infrastructure requirements, telecom requirements, finance requirements, insurance requirements, public health requirements, public safety requirements, or other legal obligations. GCRI Canada shall not describe regulator-listening discussions as compliance review or compliance clearance.

376.7 No Enforcement Position. Regulator-listening participation shall not constitute enforcement position, enforcement priority, enforcement waiver, enforcement assurance, enforcement warning, enforcement clearance, regulatory settlement, investigative position, or public authority decision. Any enforcement matter remains within the competent regulator’s own processes. GCRI Canada shall not invite participants to rely on regulator-listening status for enforcement risk management.

376.8 No Regulatory Approval. No regulator-listening meeting, event, workshop, briefing, controlled-room review, dashboard review, map review, software review, technical baseline discussion, evidence pack review, public-safe summary review, challenge, benchmark, lab, pilot, adoption window, or Nexus interface discussion shall constitute regulatory approval. GCRI Canada shall use explicit no-regulatory-approval language where public misunderstanding is reasonably possible.

376.9 No Official Interpretation of Law. No statement made in a regulator-listening context shall be represented as an official interpretation of law unless the competent public authority has issued that interpretation through its own lawful process and authorized attribution. GCRI Canada may summarize legal or regulatory context only with appropriate limitations and, where necessary, legal review. GCRI Canada shall not provide legal advice by attributing informal regulatory discussion to law.

376.10 No Public Authority Endorsement. Regulator-listening participation shall not imply endorsement by the regulator or public authority, endorsement of GCRI Canada by the regulator, endorsement of providers, endorsement of sponsors, endorsement of technical baselines, endorsement of public-good software, endorsement of benchmarks, endorsement of challenge results, endorsement of public-safe outputs, or endorsement of Nexus-compatible architecture. Non-endorsement language shall be used where material.

376.11 Confidentiality and Non-Attribution Where Applicable. Regulator-listening participation may be subject to confidentiality, non-attribution, Chatham House-style rules, controlled-room rules, market-sensitive information controls, public authority restrictions, legal sensitivity, or publication review. GCRI Canada shall not name, quote, paraphrase, photograph, record, or attribute regulator-listening participants without permission. Confidentiality shall not be used to conceal improper influence, regulatory capture, procurement steering, or prohibited commitments.

376.12 Competition and Market Conduct Controls. Where regulator-listening sessions include providers, competitors, sponsors, market actors, capital actors, public authorities, or procurement-sensitive participants, GCRI Canada shall apply competition and market conduct controls. Such controls shall prevent exchange of prices, costs, bids, market strategy, customer allocation, capacity coordination, provider exclusion, procurement steering, investment signalling, insurance coordination, lending coordination, or other market-sensitive conduct. Regulator-listening status shall not sanitize anticompetitive information exchange.

376.13 Regulator-Listening Public Reference Restrictions. Public references to regulator-listening participation shall be restricted, approved, and limitation-bearing. GCRI Canada shall not use regulator names, logos, titles, photos, quotes, attendance, or participation in fundraising, sponsor materials, provider materials, investment materials, public authority-facing materials, procurement materials, certification-like materials, or public reports in a manner that implies approval, endorsement, compliance, safe harbor, permit, enforcement position, or public authority adoption. Unauthorized references shall be corrected.

376.14 Regulator-Listening Correction. Where regulator-listening status is misstated, misused, overclaimed, quoted without permission, used to imply approval, used to suggest compliance, used in provider marketing, used in sponsor materials, used in fundraising, used in public authority-facing materials, or used to influence procurement, finance, certification, recognition, or public authority interpretation, GCRI Canada shall correct the record. Correction may include revised language, removal of references, public-safe clarification, controlled notice, access revocation, participant notice, or withdrawal of materials.

376.15 Regulator-Listening Records. GCRI Canada shall maintain regulator-listening records, including status definition records, listening / learning / technical understanding records, no-regulatory-guidance records, no-safe-harbor records, no-permit records, no-compliance-determination records, no-enforcement-position records, no-regulatory-approval records, no-official-interpretation records, no-public-authority-endorsement records, confidentiality and non-attribution records, competition and market conduct control records, public reference restriction records, correction records, access records, closeouts, and archives.


Section 377. Public Finance Reader Status

377.1 Public Finance Reader Status Definition. Public finance reader status means participation by a public finance body, treasury body, budget office, ministry of finance, development finance institution, multilateral development bank, export credit body, guarantee body, public lender, public insurer, public fund, Crown finance body, municipal finance body, infrastructure finance body, grant program, public-private partnership office, or other public-sector finance reader solely for diligence literacy, evidence understanding, technical literacy, risk-evidence learning, proof-pack literacy, Nexus Rails literacy, GRA interface literacy, public-safe reporting literacy, or public-benefit coordination, without public finance approval, funding commitment, investment recommendation, finance-readiness determination, sovereign obligation, public guarantee, public credit approval, or transaction execution by GCRI Canada.

377.2 Diligence Literacy and Evidence Understanding Only. Public finance reader participation shall be limited to understanding evidence, methods, limitations, technical baselines, public-good software, observability outputs, dashboards, maps, proof packs, finance-boundary language, non-reliance rules, public-safe summaries, and correction paths. GCRI Canada may help public finance readers understand technical evidence and public-benefit context, but shall not conduct public finance diligence for them, approve projects, advise investments, recommend funding, rate credit, underwrite risk, arrange guarantees, or determine bankability. Public finance readers remain responsible for their own processes and decisions.

377.3 No Grant Approval. Public finance reader participation shall not constitute grant approval, grant recommendation, grant eligibility, grant scoring, grant award, grant commitment, grant agreement, or grant disbursement. GCRI Canada materials shall not be represented as satisfying public grant requirements unless the relevant grant authority separately and lawfully determines that result. GCRI Canada shall not imply that public finance reader attendance increases grant likelihood.

377.4 No Budget Allocation. Public finance reader participation shall not constitute budget allocation, budget approval, spending authority, treasury approval, departmental approval, municipal allocation, Crown allocation, or public program funding decision. No GCRI Canada output shall be described as creating public budget priority or allocation unless the competent public authority has separately and lawfully made that decision.

377.5 No Appropriation Approval. Public finance reader participation shall not constitute appropriation approval, legislative budget approval, parliamentary approval, council approval, treasury board approval, ministerial approval, cabinet approval, or other public spending authorization. Appropriations and public spending authorities remain within lawful public authority processes. GCRI Canada shall not imply appropriation readiness or approval.

377.6 No MDB Approval. Participation by a multilateral development bank or MDB-affiliated reader shall not constitute MDB approval, project approval, concept note approval, board approval, appraisal approval, procurement approval, guarantee approval, loan approval, grant approval, or investment approval. MDB processes remain separate. GCRI Canada may provide technical evidence literacy only within recorded limits and non-reliance language.

377.7 No DFI Approval. Participation by a development finance institution or DFI-affiliated reader shall not constitute DFI approval, investment approval, loan approval, guarantee approval, grant approval, insurance approval, technical assistance approval, project approval, or due diligence clearance. DFI processes remain independent. GCRI Canada shall not represent DFI reading as capital commitment or finance-readiness.

377.8 No Public Guarantee. Public finance reader participation shall not create public guarantee, sovereign guarantee, municipal guarantee, Crown guarantee, public credit enhancement, insurance guarantee, loss-sharing agreement, public risk transfer, or contingent public liability. Any public guarantee requires separate lawful authority and instrument. GCRI Canada shall not arrange, recommend, underwrite, or imply guarantee support.

377.9 No Public Credit Approval. Public finance reader participation shall not create public credit approval, lending approval, creditworthiness determination, risk rating, bankability determination, insurance-readiness determination, underwriting approval, or public lending commitment. Public credit decisions remain with competent public finance bodies. GCRI Canada shall not provide rating-like public finance outputs.

377.10 No Sovereign Obligation. Public finance reader participation shall not create sovereign obligation, Crown obligation, municipal obligation, public debt, contingent liability, treaty obligation, intergovernmental obligation, appropriation obligation, guarantee obligation, or public-private partnership obligation. GCRI Canada shall not use public finance reader status to imply state support, national commitment, sovereign backing, or public finance obligation.

377.11 No Public Finance Commitment. No public finance reader meeting, briefing, controlled-room access, proof pack review, Nexus Rails interface, GRA-facing discussion, RNFD, NFD, UNFSD reference, capital-reader room, public-safe summary, dashboard, map, evidence pack, technical note, or curated introduction shall constitute public finance commitment. Public finance commitment requires separate express lawful instrument by the competent body. GCRI Canada shall not promise, arrange, solicit, or intermediate such commitments.

377.12 No Investment Recommendation by GCRI Canada. GCRI Canada shall not provide investment recommendations to public finance readers. It shall not recommend projects, issuers, securities, companies, National Consortium Companies, Project SPVs, providers, assets, funds, guarantees, loans, insurance products, or capital allocations. Technical evidence inputs, if provided, shall be non-reliance, public-benefit, limitation-bearing, and correctionable, and shall not constitute securities advice, financial advice, public finance advice, portfolio advice, rating, valuation, or investment suitability analysis.

377.13 No Finance-Readiness Determination by GCRI Canada. GCRI Canada shall not determine finance-readiness, insurance-readiness, bankability, investability, creditworthiness, lendability, public finance readiness, guarantee readiness, capital-readability, underwriting readiness, or transaction suitability. Any references to finance-readiness shall be limited to technical evidence inputs, literacy, proof-pack structure, non-reliance-controlled materials, or separate competent processes outside GCRI Canada’s authority. Public finance reader participation shall not alter this rule.

377.14 Public Finance Reader Non-Reliance Language. Materials provided to public finance readers shall include non-reliance language where material. Such language shall state that GCRI Canada materials are for evidence literacy, methods literacy, technical understanding, public-benefit learning, or non-executing support only, and are not investment advice, securities advice, public finance advice, grant approval, public finance approval, public guarantee, credit approval, underwriting approval, rating, finance-readiness determination, public authority decision, procurement approval, or transaction recommendation. Non-reliance language shall be proximate to finance-sensitive materials.

377.15 Public Finance Reader Records. GCRI Canada shall maintain public finance reader records, including status definition records, diligence literacy and evidence understanding records, no-grant-approval records, no-budget-allocation records, no-appropriation-approval records, no-MDB-approval records, no-DFI-approval records, no-public-guarantee records, no-public-credit-approval records, no-sovereign-obligation records, no-public-finance-commitment records, no-investment-recommendation records, no-finance-readiness-determination records, non-reliance language records, public finance reader access records, corrections, closeouts, and archives.


Section 378. Emergency-Management Participant Status

378.1 Emergency-Management Participant Status Definition. Emergency-management participant status means participation by a public authority, emergency-management body, civil protection body, disaster management body, public safety body, public health emergency body, cyber incident body, infrastructure resilience body, utility emergency function, public works emergency function, or other emergency-relevant public-sector actor for emergency learning, evidence understanding, scenario learning, simulation, tabletop exercise, observability literacy, dashboard literacy, map literacy, after-action learning, public-safe reporting literacy, or resilience methods support, without incident command, dispatch authority, evacuation authority, public warning authority, operational resource direction, responder command, or emergency communications authority by GCRI Canada.

378.2 Emergency Learning and Evidence Understanding Only. Emergency-management participation in GCRI Canada activities shall be limited to emergency learning, evidence understanding, methods literacy, scenario analysis, public-safe publication learning, observability learning, degraded-mode awareness learning, dashboard and map limitation learning, AI incident learning, cyber incident learning, infrastructure resilience learning, and after-action evidence review. GCRI Canada shall not direct emergency operations, instruct responders, issue public alerts, command resources, prioritize dispatch, direct evacuation, or substitute for emergency management organizations.

378.3 Scenario, Simulation, Tabletop, Exercise, Observatory, and After-Action Support. GCRI Canada may support scenarios, simulations, tabletops, exercises, Observatory learning, Truth Engine learning, dashboard literacy, map literacy, cyber exercises, AI incident exercises, infrastructure exercises, public-safe reporting exercises, and after-action support for emergency-management participants. Such support shall be bounded by learning objectives, fictional or controlled assumptions where applicable, public-safe status, data / AI / cyber controls, public authority boundary language, and correction. Exercise materials shall not be treated as live incident instructions unless separately issued by a competent public authority.

378.4 No Incident Command. GCRI Canada shall not exercise incident command, unified command, emergency operations command, emergency coordination command, cyber incident command, public health emergency command, public safety command, infrastructure command, or crisis command by reason of emergency-management participation. Any GCRI Canada role in exercises, scenarios, or evidence review shall be facilitative, educational, technical, or observational only. Incident command remains with competent authorities and operators.

378.5 No Dispatch Authority. GCRI Canada shall not dispatch emergency services, responders, utilities, field teams, public works crews, cyber response teams, medical response, public safety resources, logistics, equipment, or operational support by reason of emergency-management engagement. No dashboard, map, observability output, simulation, scenario, or public-safe summary shall be used as GCRI Canada dispatch authority.

378.6 No Evacuation Authority. GCRI Canada shall not issue evacuation notices, shelter-in-place instructions, relocation orders, route instructions, public movement directions, emergency public health instructions, public safety orders, or protective action directives. Evacuation and protective action authority remains with competent public authorities. Any GCRI Canada materials discussing evacuation or protective action shall be educational, scenario-based, or public-safe only and shall direct readers to competent authorities where appropriate.

378.7 No Public Warning Authority. GCRI Canada shall not issue official public warnings, alerts, emergency bulletins, hazard warnings, public health warnings, public safety warnings, evacuation warnings, cyber public warnings, infrastructure failure warnings, or public authority notices. Observability outputs, degraded-mode indicators, dashboards, maps, simulations, scenarios, Truth Engine outputs, and public-safe summaries shall include non-warning language where material. Public warning authority remains with competent public authorities.

378.8 No Operational Resource Direction. GCRI Canada shall not direct deployment, prioritization, allocation, activation, staging, demobilization, routing, command, or use of operational resources, including responders, equipment, vehicles, facilities, shelters, hospitals, utilities, telecom resources, cyber teams, public works resources, supplies, logistics, or public infrastructure. Scenario discussions of resource needs shall remain learning-only and shall not be operational instructions.

378.9 No Responder Command. GCRI Canada shall not command, supervise, evaluate for operational discipline, authorize, discipline, or direct responders, emergency personnel, public safety personnel, public health personnel, public works personnel, utility crews, cyber responders, volunteers, or mutual aid resources. Participation in GCRI Canada training, exercises, dashboards, or simulations shall not alter responder chains of command.

378.10 No Replacement of Emergency Management Organizations. GCRI Canada shall not replace, duplicate, assume, or present itself as an emergency management organization, emergency operations centre, public safety answering point, public health emergency authority, public warning system, public safety agency, incident command system, utility control centre, cyber emergency response authority, or infrastructure operator. GCRI Canada may support public-benefit learning and evidence methods only within recorded limits.

378.11 Emergency Communications Boundary. Emergency communications by GCRI Canada shall be limited to public-safe corrections, institutional statements, learning materials, non-warning public-safe summaries, or direction to competent public authorities where appropriate. GCRI Canada shall not issue emergency instructions, official alerts, evacuation notices, protective action guidance, operational directives, public health orders, public safety orders, or public authority communications. Crisis communications shall include emergency boundary language where risk of misunderstanding exists.

378.12 Emergency Dashboard Boundary. Dashboards, maps, observability outputs, degraded-mode indicators, resilience indicators, Truth Engine outputs, public-safe intelligence outputs, and scenario tools used in emergency-management learning shall not be represented as official emergency dashboards, public warning dashboards, dispatch dashboards, evacuation dashboards, command dashboards, public authority decision systems, or operational systems unless separately and lawfully issued by a competent public authority outside GCRI Canada’s authority. Dashboard limitations, update status, uncertainty, source lineage, and correction path shall be displayed or recorded where material.

378.13 Emergency-Management Public Reference Controls. Public references to emergency-management participant involvement shall be reviewed and approved. Such references shall not imply that GCRI Canada has emergency command authority, public warning authority, dispatch authority, evacuation authority, responder command, public safety authority, public health authority, infrastructure control, public authority endorsement, official adoption, procurement approval, funding approval, public finance approval, or sovereign obligation. Emergency-management logos, names, photographs, quotes, and titles shall be used only with permission where required.

378.14 Emergency-Management Correction. Where emergency-management participation, outputs, dashboards, maps, scenarios, simulations, exercises, public-safe summaries, public authority references, or public communications are misstated or used to imply emergency command, public warning, dispatch authority, evacuation authority, responder command, public authority adoption, public safety authority, public health authority, procurement approval, funding approval, finance-readiness, or official endorsement, GCRI Canada shall correct the record. Correction may include public-safe clarification, controlled notice, revised materials, removal of references, dashboard notes, map notes, withdrawal, or archive correction.

378.15 Emergency-Management Participant Records. GCRI Canada shall maintain emergency-management participant records, including status definition records, emergency learning and evidence understanding records, scenario / simulation / tabletop / exercise / Observatory / after-action support records, no-incident-command records, no-dispatch-authority records, no-evacuation-authority records, no-public-warning-authority records, no-operational-resource-direction records, no-responder-command records, no-replacement-of-emergency-management-organizations records, emergency communications boundary records, emergency dashboard boundary records, public reference control records, correction records, access records, closeouts, and archives.


Section 379. Public Infrastructure Operator Status

379.1 Public Infrastructure Operator Status Definition. Public infrastructure operator status means participation by a public-sector, Crown, municipal, utility, port, telecom, energy, water, wastewater, food-system, health-system, transportation, public works, cyber, public safety, or other public-interest infrastructure operator for the purpose of providing infrastructure context, operational knowledge, authorized data, technical learning, observability literacy, resilience learning, public-safe reporting support, dashboard and map literacy, scenario learning, or after-action evidence support, without transferring operational control to GCRI Canada or creating procurement approval, public authority adoption, performance warranty, resilience guarantee, public warning authority, or public safety command.

379.2 Operator Context Contribution. A public infrastructure operator may contribute operator context concerning systems, dependencies, constraints, resilience needs, maintenance cycles, public authority interfaces, service obligations, failure modes, data availability, cyber posture, public-safe communication needs, public works constraints, utility realities, telecom realities, port realities, energy realities, water realities, health-system realities, food-system realities, or other infrastructure context. Operator context contribution shall be recorded, classified, and limitation-bearing. Context contribution shall not constitute authorization for GCRI Canada to operate, direct, manage, command, procure, finance, insure, certify, or approve infrastructure.

379.3 Operational Knowledge Contribution. A public infrastructure operator may contribute operational knowledge where authorized and safe, including process knowledge, dependency knowledge, technical constraints, system behaviour, response constraints, restoration practices, dashboard needs, map limitations, sensor realities, AI-RAN / O-RAN context, DePIN context, cyber telemetry context, digital twin assumptions, resilience indicators, and degraded-mode awareness. Operational knowledge shall be handled according to confidentiality, infrastructure sensitivity, cyber sensitivity, public authority terms, protected knowledge overlap, public-safe transformation, and correction. Operational knowledge contribution shall not make GCRI Canada an operator.

379.4 Infrastructure Data Contribution Where Authorized. Infrastructure data may be contributed only where lawful, authorized, classified, secure, and necessary for approved public-benefit purpose. Infrastructure data may include public data, controlled data, telemetry, sensor data, dashboard data, map layers, asset classes, service areas, dependency data, outage history, cyber-relevant data, resilience indicators, or public-safe summaries. Data contribution shall require data rights, confidentiality, AI-use limits, model-training restrictions, access controls, publication limits, retention, deletion, and correction path. Sensitive infrastructure data shall not be publicized without public-safe review.

379.5 Public-Safe Handling of Infrastructure-Sensitive Data. Infrastructure-sensitive data shall be handled to prevent exposure of vulnerabilities, dependencies, critical locations, attack surfaces, cyber-physical risks, service disruption risks, security controls, response constraints, public safety risks, protected communities, or sensitive public authority information. Public-safe handling may require aggregation, generalization, masking, delay, redaction, no-download access, controlled-room review, public authority review, cyber review, infrastructure review, and access limits. Public-safe transformation shall preserve usefulness while preventing misuse.

379.6 No Operational Control by GCRI Canada. Public infrastructure operator participation shall not give GCRI Canada operational control over infrastructure systems, utilities, ports, telecom systems, energy systems, water systems, wastewater systems, food systems, health systems, transport systems, cyber systems, public works, facilities, field crews, response teams, control rooms, command centres, dashboards, sensors, networks, or public authority operations. GCRI Canada may support learning, evidence, methods, observability, and public-safe publication only. Operational control remains with the competent operator and public authority.

379.7 No Procurement Approval by Operator Participation. Public infrastructure operator participation shall not constitute procurement approval, provider selection, vendor qualification, tender requirement, purchasing recommendation, contract award, public-sector eligibility, or endorsement of any provider, software, platform, AI system, cloud system, cybersecurity tool, telecom provider, AI-RAN provider, O-RAN provider, DePIN provider, sensor provider, contractor, consultant, National Consortium Company, Project SPV, or technical solution. Operator participation shall not be cited by providers as procurement validation.

379.8 No Public Authority Adoption by Operator Participation. Public infrastructure operator participation shall not constitute public authority adoption of GCRI Canada materials, methods, public-good software, technical baselines, dashboards, maps, observability outputs, evidence packs, public-safe summaries, ontology, data schemas, Academy materials, challenge results, benchmark outputs, pilot results, lab outputs, or Nexus interface outputs. Adoption exists only where the competent operator or public authority separately and lawfully adopts within its own processes and records.

379.9 No Infrastructure Performance Warranty. GCRI Canada shall not warrant infrastructure performance, service continuity, uptime, resilience, reliability, safety, security, regulatory compliance, cyber maturity, asset condition, public works quality, utility performance, telecom performance, energy performance, water performance, health-system performance, port performance, transport performance, or system readiness by reason of public infrastructure operator participation, data contribution, observability output, dashboard, map, baseline, method, sprint, pilot, lab, benchmark, or public-safe summary. Any statements about performance shall be evidence-limited and non-warranty.

379.10 No Resilience Guarantee. GCRI Canada shall not guarantee resilience, degraded-mode performance, recovery time, recovery point, service restoration, emergency readiness, cyber resilience, climate resilience, infrastructure redundancy, public safety outcomes, public health outcomes, or continuity outcomes for any public infrastructure operator, public authority, host, provider, National Consortium Company, Project SPV, or community. Resilience indicators, scenarios, simulations, benchmarks, dashboards, maps, and public-safe summaries are evidence and learning artifacts only and remain subject to uncertainty and correction.

379.11 No Public Warning or Public Safety Command. Public infrastructure operator participation shall not create public warning authority, public safety command, public health command, public works command, utility command, port command, telecom command, energy command, water command, cyber command, or infrastructure emergency command for GCRI Canada. GCRI Canada shall not issue outage instructions, service restoration orders, evacuation instructions, public safety orders, infrastructure operating instructions, cyber response directives, or public warning notices. Competent operators and public authorities retain such authority.

379.12 Public Infrastructure Operator Reference Controls. References to public infrastructure operators shall be controlled. GCRI Canada shall use operator names, logos, titles, quotes, photographs, facility images, system references, data contributions, dashboard references, map references, public authority relationships, and operational context only with appropriate permission, public-safe review, infrastructure sensitivity review, cybersecurity review, and approved language. References shall not imply endorsement, adoption, procurement approval, finance-readiness, certification, recognition, maturity, resilience guarantee, performance warranty, public warning, or operational control.

379.13 Public Infrastructure Operator Correction. Where public infrastructure operator status, data, operational knowledge, public references, dashboards, maps, observability outputs, scenarios, simulations, public-safe summaries, technical baselines, publications, or partner materials are misstated, overclaimed, stale, unsafe, misleading, or used to imply operational control, procurement approval, public authority adoption, infrastructure warranty, resilience guarantee, public warning, public safety command, provider preference, finance-readiness, certification, recognition, or maturity, GCRI Canada shall correct the record. Correction may include revised language, data restriction, dashboard note, map note, public-safe clarification, controlled notice, access revocation, withdrawal, or archive correction.

379.14 Public Infrastructure Operator Records. GCRI Canada shall maintain public infrastructure operator records, including status definition records, operator context contribution records, operational knowledge contribution records, infrastructure data contribution records, public-safe handling of infrastructure-sensitive data records, no-operational-control records, no-procurement-approval records, no-public-authority-adoption records, no-performance-warranty records, no-resilience-guarantee records, no-public-warning / no-public-safety-command records, public infrastructure operator reference control records, correction records, access records, data disposition records, closeouts, and archives.

Section 380. Public Health, Public Safety, Public Works, Utility, Port, Telecom, Energy, Water, Food, Health, Cyber, and Infrastructure Participants

380.1 Public Health Participant Boundary. Public health participants may engage with GCRI Canada for public-benefit learning, evidence literacy, methods literacy, public-safe reporting, data / AI / cyber literacy, health-system resilience learning, scenario and simulation learning, observability learning, dashboard literacy, map literacy, health-sensitive data governance, public-safe publication review, and after-action evidence understanding. Public health participation shall not authorize GCRI Canada to issue public health guidance, health advisories, disease warnings, clinical recommendations, public health orders, emergency health directions, surveillance determinations, health-system operating instructions, or official health-risk classifications. Health-related outputs of GCRI Canada shall remain evidence, methods, learning, technical literacy, public-safe publication, or correction artifacts unless separately and lawfully issued by a competent public health authority.

380.2 Public Safety Participant Boundary. Public safety participants may engage with GCRI Canada for learning, evidence understanding, scenario design, simulation, tabletop exercise, cyber-physical risk literacy, public-safe reporting, community safeguards, dashboard and map limitation training, infrastructure-sensitive data handling, and after-action review. Public safety participation shall not create public safety command, law-enforcement authority, emergency command, dispatch authority, evacuation authority, responder command, public warning authority, public security determination, public safety approval, or authority for GCRI Canada to direct public safety personnel, resources, equipment, facilities, operations, or communications. Public safety participants shall be capacity-classified, confidentiality-bound where appropriate, and subject to public reference controls.

380.3 Public Works Participant Boundary. Public works participants may contribute public works context, infrastructure constraints, operational knowledge, asset-management context, resilience learning needs, dashboard literacy needs, map limitation context, public-safe reporting needs, and scenario inputs concerning roads, bridges, water, wastewater, waste, facilities, municipal services, utilities coordination, maintenance, recovery, and public works continuity. Public works participation shall not authorize GCRI Canada to approve works, direct works, procure works, certify works, inspect works, operate works, prioritize public works resources, issue public works commands, warrant asset condition, guarantee resilience, or make public authority determinations. Any public works decisions remain with the competent public authority or operator.

380.4 Utility Participant Boundary. Utility participants may engage for learning, evidence understanding, resilience methods, observability literacy, degraded-mode awareness, data sensitivity review, dashboard and map limitation review, cyber-physical risk learning, public-safe publication review, and authorized operational context contribution. Utility participation shall not give GCRI Canada operational control over electric, gas, water, wastewater, district energy, telecom-linked, public works, or other utility systems. No GCRI Canada material shall be represented as utility operating instruction, outage command, dispatch direction, restoration order, procurement approval, regulatory approval, service performance warranty, resilience guarantee, public warning, or public safety command.

380.5 Port Participant Boundary. Port participants may engage with GCRI Canada for evidence literacy, infrastructure resilience learning, logistics-system context, cyber-physical risk literacy, public-safe map review, geospatial sensitivity review, scenario and simulation support, supply-chain observability learning, public authority learning, and after-action evidence review. Port participation shall not authorize GCRI Canada to direct port operations, vessel movements, cargo flows, customs processes, security operations, emergency response, procurement, finance, public warnings, public safety command, or port authority decisions. Port-related maps, dashboards, datasets, and observability outputs shall be reviewed for infrastructure sensitivity, commercial sensitivity, security sensitivity, public authority sensitivity, and public-safe publication.

380.6 Telecom Participant Boundary. Telecom participants may contribute technical context concerning connectivity, resilience, network dependencies, AI-RAN, O-RAN, spectrum-adjacent learning, edge compute, cyber risk, critical communications, degraded-mode awareness, public-safe reporting, and observability methods. Telecom participation shall not authorize GCRI Canada to operate telecom networks, direct network traffic, approve network architecture, certify telecom systems, issue telecom regulatory interpretations, approve procurement, determine public safety communications readiness, or direct emergency communications. Telecom-related materials shall be handled according to cyber sensitivity, infrastructure sensitivity, export-control sensitivity, controlled-technology review, public authority boundary review, and provider-neutrality rules.

380.7 Energy Participant Boundary. Energy participants may engage for learning and evidence understanding concerning energy systems, grid resilience, distributed energy, critical infrastructure dependencies, cyber-physical risk, sensors, AI-RAN / O-RAN-adjacent systems where relevant, DePIN-related learning where relevant, geospatial sensitivity, climate and hazard stressors, public-safe reporting, dashboards, maps, and scenario analysis. Energy participation shall not make GCRI Canada an energy system operator, grid operator, dispatcher, regulator, market operator, procurement body, public warning body, public safety commander, or resilience guarantor. Energy-related outputs shall be evidence-limited, uncertainty-bearing, public-safe, and non-operational unless separately issued by a competent authority or operator.

380.8 Water Participant Boundary. Water participants may engage for public-benefit learning, water-system resilience learning, watershed and infrastructure context, water-quality evidence literacy, climate and hazard scenario learning, public-safe geospatial review, dashboard and map limitation review, cyber-physical risk literacy, and public authority learning. Water participation shall not authorize GCRI Canada to issue drinking-water advisories, boil-water notices, contamination warnings, treatment instructions, infrastructure operating directions, public health orders, procurement approvals, funding approvals, regulatory approvals, or resilience guarantees. Water-related information shall be handled with heightened care where it concerns public health, critical locations, vulnerabilities, community impacts, or protected knowledge.

380.9 Food System Participant Boundary. Food system participants may engage with GCRI Canada for evidence literacy, supply-chain resilience learning, food-security context, climate and hazard scenario learning, public-safe reporting, geospatial review, data governance, cyber-physical risk literacy, and public authority learning. Food system participation shall not authorize GCRI Canada to issue food safety warnings, recall instructions, emergency food distribution orders, agricultural regulatory approvals, procurement approvals, funding approvals, supply allocation instructions, public health determinations, or market directives. Food-system data shall be reviewed for commercial sensitivity, community sensitivity, public authority sensitivity, infrastructure dependency, public-safe status, and potential harm from over-disclosure.

380.10 Health System Participant Boundary. Health system participants may engage for health-system resilience learning, evidence literacy, data / AI / cyber literacy, public-safe publication, scenario and simulation learning, dashboard literacy, map limitation review, cyber risk learning, public health interface learning, and after-action evidence review. Health system participation shall not authorize GCRI Canada to provide clinical advice, triage instructions, hospital operations commands, public health orders, public warnings, emergency medical direction, procurement approvals, funding approvals, regulatory approvals, health-system performance warranties, or resilience guarantees. Health-system materials shall be reviewed for personal information, health-sensitive data, public authority sensitivity, cyber sensitivity, infrastructure sensitivity, and ethical safeguards.

380.11 Cyber Participant Boundary. Cyber participants may engage for cybersecurity literacy, cyber incident learning, vulnerability management literacy, public-safe cyber communication, repository security learning, infrastructure risk learning, public authority learning, AI security learning, and controlled cyber exercise participation. Cyber participation shall not authorize GCRI Canada to operate as a cyber emergency response authority, managed security service provider, law-enforcement cyber authority, regulator, certifier, incident commander, public warning body, procurement approver, or security guarantor. Cyber-sensitive materials shall be handled under approved access controls, vulnerability disclosure rules, non-publication restrictions where required, coordinated correction paths, and no-operational-command language.

380.12 Infrastructure Participant Boundary. Infrastructure participants may engage with GCRI Canada to support public-benefit understanding of infrastructure dependencies, resilience, observability, data sensitivity, cyber-physical risks, public-safe maps, dashboards, degraded-mode awareness, technical baselines, public authority learning, and scenario analysis. Infrastructure participation shall not transfer infrastructure ownership, custody, operation, control, approval, procurement authority, regulatory authority, emergency authority, public warning authority, funding authority, public finance authority, warranty responsibility, or resilience guarantee to GCRI Canada. Infrastructure-related outputs shall be classified, limitation-bearing, public-safe where published, and correctionable.

380.13 Sector-Specific Data Sensitivity. GCRI Canada shall classify sector-specific data sensitivity before receipt, processing, sharing, AI use, modeling, publication, dashboard display, map display, public-safe summary, or controlled-room use. Sector-specific sensitivity may include health-sensitive data, public safety-sensitive data, public works-sensitive data, utility-sensitive data, port-sensitive data, telecom-sensitive data, energy-sensitive data, water-sensitive data, food-system-sensitive data, cyber-sensitive data, infrastructure-sensitive data, public authority-sensitive data, personal information, protected knowledge, commercial sensitivity, geospatial sensitivity, security sensitivity, and finance-sensitive evidence. Sector-specific data shall not be processed through unapproved tools, placed in public repositories, used for model training, exported, disclosed, or published outside recorded permissions.

380.14 Sector-Specific Public-Safe Publication Controls. Sector-specific outputs shall be reviewed for public-safe publication before external release. Review shall assess source support, methods support, public authority capacity, sector sensitivity, infrastructure sensitivity, cyber risk, health risk, public safety risk, commercial sensitivity, protected knowledge, geospatial exposure, community harm, public warning implication, emergency command implication, regulatory implication, procurement implication, funding implication, public finance implication, certification implication, provider preference, and correction path. Public-safe publication may require aggregation, masking, delay, redaction, generalization, controlled summaries, non-public annexes, non-warning language, and public authority reference controls.

380.15 Sector-Specific Emergency-Command Boundary. No participation by any public health, public safety, public works, utility, port, telecom, energy, water, food, health, cyber, or infrastructure participant shall create emergency command authority for GCRI Canada. GCRI Canada shall not issue sector-specific emergency orders, public warnings, operational commands, responder instructions, evacuation instructions, outage instructions, service restoration directions, public health orders, cyber response directives, safety orders, infrastructure control instructions, or resource allocation decisions. Scenario, simulation, tabletop, dashboard, map, observability, and after-action activities shall remain learning, evidence, methods, and public-safe reporting activities.

380.16 Sector-Specific Procurement and Regulatory Boundary. Sector participation shall not constitute procurement approval, vendor approval, provider selection, prequalification, tender requirement, purchasing recommendation, regulatory approval, compliance determination, permit, license, inspection approval, public funding approval, public finance approval, certification, accreditation, recognition, maturity determination, public authority adoption, or official sector endorsement. Providers shall not use sector participant attendance, data contribution, host support, dashboard review, map review, simulation participation, or public authority learning to market procurement validation, regulatory acceptance, public finance readiness, certification, or sector approval.

380.17 Sector Participation Records. GCRI Canada shall maintain sector participation records, including public health participant boundary records, public safety participant boundary records, public works participant boundary records, utility participant boundary records, port participant boundary records, telecom participant boundary records, energy participant boundary records, water participant boundary records, food system participant boundary records, health system participant boundary records, cyber participant boundary records, infrastructure participant boundary records, sector-specific data sensitivity records, sector-specific public-safe publication control records, sector-specific emergency-command boundary records, sector-specific procurement and regulatory boundary records, corrections, clarifications, access revocations, closeouts, and archives.


Section 381. Public Authority Data Contributions

381.1 Public Authority Data Contribution Purpose. GCRI Canada may receive, review, process, store, analyze, transform, summarize, or use public authority data contributions only for approved public-benefit purposes consistent with its role as a non-executing steward of research, evidence, methods, observability, ontology, public-good software, open technical baselines, data / AI / cyber governance, public-safe publication, public authority learning, scenario and simulation learning, and Nexus-compatible interfaces. Public authority data contributions shall support evidence literacy, technical literacy, methods integrity, public-safe reporting, observability learning, dashboard and map discipline, correctionability, and public-benefit capacity formation, and shall not create governmental power, public authority delegation, public authority adoption, public warning authority, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, sovereign obligation, certification, recognition, finance-readiness, or provider preference.

381.2 Data Contribution Authority. Before accepting material public authority data, GCRI Canada shall determine whether the contributor has authority to provide the data and whether GCRI Canada has authority to receive and use it for the stated purpose. Data contribution authority may arise from public law, agreement, authorization, public release, data-sharing instrument, research agreement, host agreement, grant term, public authority consent, official correspondence, or another reliable record. Where authority is unclear, GCRI Canada shall refuse, quarantine, restrict, or seek clarification before use. Data contribution authority shall be interpreted narrowly and shall not expand by implication.

381.3 Contributor Identity and Capacity. Public authority data contribution records shall identify the contributor, public body, office, department, agency, ministry, municipality, Crown entity, utility, regulator, public institution, operator, or other public-sector source, together with the contributor’s capacity, role, title, authority scope, contact, attribution permission, confidentiality status, and correction path. Contributor identity and capacity shall determine permitted use, public references, data rights, access controls, publication review, and correction obligations. Data provided by a person in personal capacity shall not be treated as official public authority data unless authority is established.

381.4 Lawful Basis. Each material public authority data contribution shall have a recorded lawful basis or permitted basis for receipt and use. Lawful basis review shall address statutory authority, public release, consent, authorization, contract, research basis, public-benefit purpose, data-sharing terms, privacy, confidentiality, public records limitations, security classifications, data protection rules, protected knowledge, public authority restrictions, cross-border transfer, and retention. GCRI Canada shall not use public authority data where lawful basis is absent, uncertain, withdrawn, exceeded, or inconsistent with public-safe use.

381.5 Permitted Use. Permitted use shall be recorded before or upon receipt of public authority data. Permitted use may include internal analysis, evidence review, methods testing, observability learning, public authority learning, scenario analysis, simulation, dashboard testing, map testing, public-safe summary, controlled summary, technical baseline development, software testing, Academy materials, controlled-room review, correction, or archival, depending on authority and classification. Permitted use shall identify audience, systems, tools, duration, outputs, publication posture, AI-use permissions, transfer permissions, and closeout.

381.6 Prohibited Use. Prohibited use shall be identified and enforced for public authority data. Prohibited use may include publication, public repository placement, unrestricted sharing, commercial use, provider marketing, sponsor benefit, AI model training, unapproved AI upload, external transfer, cross-border transfer, re-identification, merger with unrelated datasets, use in capital-reader materials, procurement materials, certification materials, public warning materials, emergency command materials, or any use outside recorded purpose. Prohibited use shall be communicated to persons with access and enforced through access controls, system controls, training, and records.

381.7 AI-Use Restrictions. Public authority data shall not be uploaded to, processed by, summarized through, embedded in, trained on, fine-tuned with, indexed by, retrieved through, or exposed to AI systems unless AI-use authority, tool approval, model provider terms, data retention, training restrictions, confidentiality, privacy, cyber controls, public authority terms, protected knowledge safeguards, output review, and correction path are recorded. AI-use restrictions shall apply to generative AI, coding assistants, transcription tools, translation tools, summarization tools, retrieval systems, vector stores, embedding systems, agentic systems, and automated analysis tools. Unapproved AI processing is prohibited.

381.8 Publication Restrictions. Public authority data shall not be published, quoted, mapped, visualized, excerpted, dashboarded, summarized publicly, included in public reports, placed in public repositories, referenced in sponsor or provider materials, or used in public-safe outputs unless publication is authorized and public-safe review is completed. Publication restrictions may require redaction, aggregation, generalization, delay, masking, non-attribution, public authority review, protected knowledge review, cyber review, infrastructure sensitivity review, health sensitivity review, legal review, and limitation language. Publication permission shall not imply endorsement or adoption.

381.9 Transfer Restrictions. Public authority data shall not be transferred to third parties, affiliates, providers, sponsors, donors, funders, hosts, public authorities other than the source authority, universities, laboratories, National Consortium Companies, Project SPVs, cloud providers, AI providers, data rooms, controlled rooms, public repositories, or cross-border systems except as expressly permitted by authority, agreement, classification, and review. Transfer restrictions shall include access class, recipient, purpose, geography, security, onward-transfer limits, AI-use limits, retention, deletion, and audit or verification where appropriate.

381.10 Retention and Deletion Requirements. Public authority data contribution records shall identify retention, deletion, return, archiving, anonymization, aggregation, sealing, or secure disposal requirements. Retention shall account for law, agreement, public authority terms, privacy, research integrity, public-safe publication, incident review, correctionability, audit, legal hold, and institutional memory. Deletion or return shall be documented and shall include derived materials where required. GCRI Canada shall not retain public authority data indefinitely by default where authority or purpose does not justify retention.

381.11 Classification. Public authority data shall be classified according to sensitivity, source, lawful basis, confidentiality, public status, personal information, public authority sensitivity, cyber sensitivity, infrastructure sensitivity, health sensitivity, public safety sensitivity, public works sensitivity, finance sensitivity, protected knowledge, controlled technology, export-control risk, publication posture, AI-use status, access class, and correction path. Classification shall travel with extracts, summaries, dashboards, maps, embeddings, derived outputs, public-safe transformations, controlled annexes, and archives.

381.12 Public Authority Review Rights Where Applicable. Where applicable law, agreement, data rights, confidentiality, public authority terms, publication permission, attribution permission, quote permission, protected knowledge concerns, infrastructure sensitivity, or public-safe review requires public authority review, GCRI Canada shall provide the relevant material for review within recorded scope and timing. Review rights shall not become veto rights over independent findings except to protect confidentiality, legal compliance, security, public authority terms, protected knowledge, or public-safe obligations. Comments and dispositions shall be recorded where material.

381.13 Confidentiality Requirements. Public authority data may be subject to confidentiality requirements arising from law, agreement, classification, public authority rules, public safety, cyber sensitivity, infrastructure sensitivity, health sensitivity, protected knowledge, procurement sensitivity, finance sensitivity, or public trust. Confidentiality requirements shall be recorded and applied through access controls, staff training, no-redistribution rules, no-download restrictions where appropriate, AI-use prohibitions, publication review, secure storage, and incident response. Confidentiality obligations may survive program closeout.

381.14 Cybersecurity Requirements. Public authority data shall be protected by cybersecurity requirements proportionate to sensitivity. Requirements may include approved systems, encryption, MFA, least privilege, logging, monitoring, secure storage, secure transfer, repository controls, no-public-repository placement, endpoint controls, cloud controls, access review, vulnerability management, incident response, backup, retention controls, secure deletion, and offboarding. Public authority data shall not be copied into personal drives, personal email, unapproved tools, shadow IT, informal AI systems, or unmanaged storage.

381.15 Public-Safe Release Review. Before any public-safe release derived from public authority data, GCRI Canada shall conduct public-safe release review. Review shall assess lawful basis, data rights, public authority permission, source support, method support, classification, aggregation, redaction, geospatial sensitivity, cyber risk, infrastructure risk, public safety risk, health risk, protected knowledge, community impact, public warning implication, emergency command implication, regulatory implication, procurement implication, finance implication, certification implication, provider preference, sponsor influence, limitation language, and correction path. Release may be denied, delayed, restricted, generalized, controlled, or withdrawn.

381.16 Correction, Withdrawal, or Update Path. Public authority data contribution records shall include a correction, withdrawal, or update path for inaccurate data, stale data, superseded data, misclassified data, unauthorized data, withdrawn permission, changed public authority terms, public-safe risk, protected knowledge concern, privacy issue, cyber issue, infrastructure sensitivity, public authority misdescription, publication error, AI-processing error, dashboard error, map error, or derived-output error. Correction may include update, restriction, deletion, return, suppression, revised output, public-safe clarification, controlled notice, withdrawal, or archive note.

381.17 Public Authority Data Contribution Records. GCRI Canada shall maintain public authority data contribution records, including purpose records, data contribution authority records, contributor identity and capacity records, lawful basis records, permitted use records, prohibited use records, AI-use restriction records, publication restriction records, transfer restriction records, retention and deletion records, classification records, public authority review right records, confidentiality records, cybersecurity records, public-safe release review records, correction / withdrawal / update path records, access logs where appropriate, incident records, closeouts, and archives.


Section 382. Public Authority References, Logos, Titles, Agency Names, Jurisdictions, Photos, Quotes, Attendance, and Data Contribution References

382.1 Public Authority Reference Control Purpose. GCRI Canada shall control all references to public authorities to prevent misunderstanding, overclaim, implied endorsement, implied adoption, public authority misdescription, public warning implication, emergency command implication, regulatory implication, procurement implication, funding implication, public finance implication, sovereign obligation implication, certification implication, recognition implication, finance-readiness implication, provider preference, sponsor benefit, or public-private partnership implication. Public authority reference controls shall apply to websites, reports, whitepapers, decks, social media, speeches, press releases, donor reports, sponsor reports, grant reports, dashboards, maps, datasets, software releases, public-safe summaries, controlled summaries, event materials, training materials, Academy materials, challenge materials, benchmarking materials, curated introductions, and Partnering Office materials.

382.2 Public Authority Name Reference. A public authority name may be referenced only where the reference is accurate, authorized where required, capacity-classified, public-safe, and accompanied by appropriate limitation language where material. References shall identify the public authority precisely enough to avoid implying broader government support than exists. GCRI Canada shall not use generic or inflated phrases such as “government-backed,” “officially approved,” “public authority endorsed,” or equivalent language unless a competent public authority record expressly supports the exact statement and GCRI Canada approves the language.

382.3 Public Authority Logo Reference. Public authority logos, seals, crests, emblems, insignia, official marks, coat-of-arms, ministry marks, municipal marks, Crown marks, regulator marks, public institution marks, utility marks, or other official identifiers shall be used only with permission where required and only in approved context. Logo use shall not imply endorsement, adoption, approval, funding, procurement approval, public finance approval, regulatory approval, public warning authority, emergency command, sovereign obligation, certification, recognition, finance-readiness, or public-private partnership unless expressly authorized and accurately described.

382.4 Public Authority Title Reference. Public authority titles, official titles, senior titles, ministry titles, agency titles, regulator titles, municipal titles, public institution titles, utility titles, public finance titles, emergency-management titles, and infrastructure operator titles shall be referenced accurately and only within the participant’s approved capacity. A title shall not be used to imply authority beyond the recorded scope. Where a person participates personally or non-attributably, official titles shall be omitted, generalized, or accompanied by limitation language as appropriate.

382.5 Agency, Department, Ministry, Municipality, Crown, Utility, Regulator, Public Institution, or Public Body Reference. References to agencies, departments, ministries, municipalities, Crown entities, utilities, regulators, public institutions, public universities, public laboratories, public hospitals, port authorities, telecom authorities, energy authorities, water authorities, public health bodies, public safety bodies, public works bodies, public finance bodies, or other public bodies shall be accurate, capacity-specific, and approved where required. Reference to one office or participant shall not be used to imply support from an entire government, ministry, jurisdiction, regulator, Crown, or public sector.

382.6 Jurisdiction Reference. Jurisdiction references shall accurately describe geography, public authority level, legal context, program context, and public-sector involvement. References to Canada, a province, territory, municipality, Indigenous government, regional authority, foreign jurisdiction, or international public body shall not imply official adoption, sovereign backing, funding approval, public finance approval, procurement approval, regulatory approval, or public-private partnership unless separately and lawfully recorded. Jurisdiction language shall distinguish location, subject matter, participant affiliation, and official public authority action.

382.7 Public Authority Photograph or Recording. Photographs, videos, audio recordings, screenshots, transcripts, panel recordings, event recordings, facility images, public authority participant images, meeting images, or images showing public authority logos, personnel, premises, vehicles, dashboards, maps, control rooms, or infrastructure shall be used only with appropriate permission, privacy review, security review, public authority reference review, infrastructure sensitivity review, cyber review, protected knowledge review where applicable, and public-safe approval. Visual references shall not be staged or edited to imply endorsement, adoption, emergency command, public warning authority, procurement approval, funding approval, or public finance approval.

382.8 Attendance Reference. Public authority attendance at meetings, workshops, Academy sessions, controlled rooms, labs, simulations, dashboards, map reviews, briefings, challenge events, benchmarking sessions, public-safe reviews, or Nexus-compatible activities may be referenced only where authorized and capacity-classified. Attendance references shall use precise language such as “attended,” “observed,” “participated in learning,” “contributed technical context,” or other approved wording. Attendance shall not be described as approval, adoption, endorsement, validation, certification, procurement review, funding review, regulatory review, finance-readiness review, public warning review, or official mandate.

382.9 Quote Reference. Public authority quotes, paraphrases, statements, comments, panel remarks, interview excerpts, review comments, letters, emails, and recorded observations shall be used only with quote permission or other lawful authorization. Quote references shall preserve context, capacity, limitations, attribution terms, and non-endorsement language where required. GCRI Canada shall not edit, excerpt, combine, or display quotes in a way that implies approval, adoption, public authority endorsement, procurement advantage, finance-readiness, certification, recognition, regulatory approval, public warning, or sovereign obligation.

382.10 Data Contribution Reference. References to public authority data contributions shall be made only where attribution is permitted, data rights allow reference, confidentiality permits reference, public-safe review is complete, and the reference does not expose sensitive data or imply approval. A data contribution reference shall not imply that the public authority approves GCRI Canada analysis, dashboards, maps, publications, models, technical baselines, evidence packs, public-safe summaries, or conclusions. Public authority data may be acknowledged anonymously, categorically, or not at all where required.

382.11 Approved Public Language Requirement. Public authority references shall use approved public language where material. Approved public language shall state capacity, role, scope, and limits clearly. Where public misunderstanding is reasonably possible, language shall include that participation, attendance, data contribution, hosting, quote, review, or collaboration does not constitute endorsement, adoption, public authority approval, regulatory approval, procurement approval, funding approval, public finance approval, public warning, emergency command, sovereign obligation, certification, recognition, finance-readiness, or provider preference.

382.12 Attribution Permission Requirement. Attribution permission shall be obtained and recorded before public attribution of a public authority, public official, public employee, public institution, public body, public authority participant, or public authority data contribution where permission is required by law, agreement, policy, confidentiality, publication review, public authority rules, privacy, or public-safe controls. Attribution permission may be limited by wording, audience, channel, duration, publication type, jurisdiction, and withdrawal rights. Absent attribution permission, GCRI Canada shall use non-attributable, generalized, or no-reference treatment.

382.13 Non-Endorsement Statement Requirement. A non-endorsement statement shall be included whenever a public authority reference could reasonably be read as endorsement, adoption, approval, public-private partnership, funding support, procurement approval, regulatory approval, public finance approval, public warning authority, emergency command, certification, recognition, finance-readiness, or public authority delegation. The statement shall be proximate, clear, and proportionate to risk. Non-endorsement language shall not be buried in terms where the main public claim remains misleading.

382.14 Public Authority Review Where Required. Public authority review shall be provided where required by attribution permission, quote permission, logo permission, data-sharing terms, public authority rules, confidentiality, publication agreements, public authority data rights, public-safe review, protected knowledge requirements, or legal obligations. Public authority review shall be limited to the relevant scope and shall not become broad veto over GCRI Canada findings, methods, publications, corrections, technical baselines, or public-safe outputs unless lawful restrictions require non-public treatment.

382.15 No Endorsement, Adoption, Funding, Regulation, Procurement, Warning, Command, Public Finance Approval, or Sovereign Obligation by Reference. No public authority reference, logo, title, agency name, jurisdiction reference, photo, quote, attendance reference, data contribution reference, facility reference, host reference, email reference, meeting reference, or public authority-facing material shall constitute or imply endorsement, adoption, funding approval, grant approval, regulation, regulatory approval, procurement approval, vendor selection, public warning, emergency command, public finance approval, sovereign obligation, public-private partnership, certification, recognition, finance-readiness, provider preference, or public authority delegation unless separately and lawfully authorized by competent public authority record and approved by GCRI Canada.

382.16 Misreference Correction. Where a public authority reference is inaccurate, unauthorized, overbroad, stale, misleading, unattributed without permission, visually misleading, contextually misleading, or used to imply endorsement, adoption, funding, regulation, procurement, public warning, emergency command, public finance approval, sovereign obligation, certification, recognition, finance-readiness, provider preference, or public authority delegation, GCRI Canada shall correct the reference. Correction may include revised language, removal of logo, removal of quote, removal of photo, amended report, amended deck, website correction, social media correction, public-safe clarification, controlled notice, participant notice, withdrawal, or archive correction.

382.17 Public Authority Reference Records. GCRI Canada shall maintain public authority reference records, including reference control purpose records, public authority name reference records, logo reference records, title reference records, public body reference records, jurisdiction reference records, photograph and recording records, attendance reference records, quote reference records, data contribution reference records, approved public language records, attribution permission records, non-endorsement statement records, public authority review records, no-endorsement / no-adoption / no-funding / no-regulation / no-procurement / no-warning / no-command / no-public-finance-approval / no-sovereign-obligation records, misreference correction records, withdrawals, closeouts, and archives.


Section 383. No Public Authority Delegation

383.1 No Public Authority Delegation Rule. GCRI Canada shall not acquire, accept, exercise, imply, or represent public authority delegation by reason of public authority engagement, public authority participation, public authority funding, public authority data contribution, official capacity participation, regulator-listening participation, public finance reader participation, emergency-management participation, infrastructure operator participation, public authority hosting, public authority attendance, public authority review, public authority quote, public authority logo use, public authority learning, scenario participation, simulation participation, dashboard review, Observatory learning, controlled-room participation, or Nexus-compatible coordination. GCRI Canada remains a non-executing nonprofit public-benefit technical institution unless a separate lawful instrument expressly provides otherwise and the Board lawfully approves the scope.

383.2 No Delegation of Governmental Power. No governmental power shall be delegated to GCRI Canada by implication. GCRI Canada shall not exercise legislative, regulatory, executive, adjudicative, enforcement, inspection, permitting, licensing, emergency, public health, public safety, procurement, public finance, budgetary, tax, sovereign, or public works powers through participation or collaboration. Governmental powers remain with competent public authorities acting under their own legal authority. GCRI Canada may support literacy, evidence, methods, and public-safe learning only.

383.3 No Delegation of Regulatory Power. GCRI Canada shall not receive or exercise regulatory power, including rulemaking, regulatory interpretation, compliance determination, permit approval, license approval, inspection approval, enforcement position, no-action position, safe harbor, conformity determination, regulated approval, or regulatory exemption. Regulator participation, listening, discussion, review, or attendance shall not convert GCRI Canada materials into regulatory guidance or compliance clearance. Regulatory authority remains with competent regulators.

383.4 No Delegation of Emergency Power. GCRI Canada shall not receive or exercise emergency power, including incident command, unified command, dispatch, evacuation authority, public warning authority, emergency operations authority, emergency procurement authority, emergency resource direction, emergency communications authority, public health emergency power, public safety command, cyber incident command, or infrastructure emergency command. Emergency-management participation and scenario learning shall remain learning-only unless a competent public authority separately and lawfully acts within its own authority.

383.5 No Delegation of Public Warning Power. GCRI Canada shall not receive or exercise public warning power, alert power, public health warning authority, public safety warning authority, evacuation warning authority, cyber public warning authority, infrastructure failure warning authority, hazard alert authority, emergency bulletin authority, or official notice authority. GCRI Canada dashboards, maps, Observatory outputs, Truth Engine outputs, public-safe summaries, simulations, scenarios, technical notes, and reports shall not be treated as official warnings unless separately issued by a competent public authority outside GCRI Canada.

383.6 No Delegation of Procurement Power. GCRI Canada shall not receive or exercise procurement power for public authorities, including authority to set tender requirements, prequalify vendors, approve vendors, shortlist bidders, evaluate bids, award contracts, recommend purchasing, issue procurement approvals, create public-sector eligibility, or steer procurement. Public authority participation in GCRI Canada programs shall not convert GCRI Canada benchmarking, capability mapping, technical baselines, software, evidence packs, dashboards, maps, or public-safe summaries into public procurement instruments.

383.7 No Delegation of Public Finance Power. GCRI Canada shall not receive or exercise public finance power, including authority to approve grants, allocate budgets, approve appropriations, issue public guarantees, approve public credit, approve MDB support, approve DFI support, approve public loans, approve public insurance, issue public finance ratings, determine public finance readiness, or bind public finance bodies. Public finance reader participation is for literacy and evidence understanding only.

383.8 No Delegation of Grant Approval Power. GCRI Canada shall not receive or exercise public grant approval power, including eligibility determination, scoring, grant award, funding allocation, disbursement approval, match approval, grant compliance approval, or public grant reporting approval for public authorities unless separately and lawfully contracted or authorized in a manner consistent with this Bylaw and not inconsistent with GCRI Canada’s non-execution role. Public authority or grantor participation shall not imply that GCRI Canada can approve public grants.

383.9 No Delegation of Public Health Order Power. GCRI Canada shall not receive or exercise public health order power, including authority to issue disease warnings, isolation orders, quarantine directions, health advisories, clinical directions, health system commands, public health emergency measures, vaccination directives, contamination notices, or other health orders. Health-related engagement shall be evidence, learning, public-safe reporting, and technical literacy only. Competent public health authorities retain all public health powers.

383.10 No Delegation of Public Safety Command Power. GCRI Canada shall not receive or exercise public safety command power, including authority to direct police, fire, emergency medical services, public safety agencies, cyber responders, public works crews, utilities, volunteers, mutual aid, security operations, evacuation, sheltering, public safety communications, or incident response. Public safety learning, scenarios, simulations, dashboards, maps, and observability outputs shall not be treated as command systems.

383.11 No Delegation by Data Contribution. Public authority data contribution shall not delegate authority to GCRI Canada. Receipt, storage, analysis, modeling, mapping, visualization, dashboarding, summarization, public-safe transformation, or publication of public authority data shall not authorize GCRI Canada to make public authority decisions, issue public warnings, approve procurement, approve funding, approve public finance, regulate, certify, command emergencies, or bind the data-providing authority. Data contribution rights shall be limited to recorded permitted use.

383.12 No Delegation by Meeting Attendance. Attendance at meetings, briefings, workshops, Academy sessions, public authority learning events, public-safe reviews, controlled rooms, data rooms, simulations, dashboards, map reviews, labs, challenges, benchmarking sessions, or Nexus-compatible activities shall not delegate public authority to GCRI Canada. Attendance may evidence learning, observation, discussion, or participation only. GCRI Canada shall not characterize attendance as official mandate, adoption, approval, procurement authority, funding authority, public finance authority, regulatory authority, public warning authority, or emergency authority.

383.13 No Delegation by Participation in Simulation, Exercise, Dashboard, Observatory, or Controlled Room. Participation in simulations, exercises, tabletop activities, dashboard reviews, map reviews, Nexus Observatory learning, Truth Engine learning, controlled rooms, no-download rooms, data rooms, labs, pilots, adoption windows, validation sprints, replication sprints, or after-action reviews shall not delegate public authority to GCRI Canada. Simulation roles are fictional or learning-bound unless separately and lawfully adopted by a competent authority for its own purposes. Controlled access shall not imply public authority approval.

383.14 No Delegation by Public Authority Staff Involvement. Involvement of public authority staff, employees, officers, consultants, advisors, secondees, fellows, reviewers, speakers, or technical experts shall not delegate public authority to GCRI Canada. A public authority participant may contribute expertise, context, data, review comments, or learning input within recorded capacity, but such involvement shall not authorize GCRI Canada to act for the public authority or bind the public authority. Staff involvement shall not be used as evidence of official adoption unless separately recorded.

383.15 Public Authority Delegation Correction and Escalation. Where public authority delegation is misstated, implied, claimed, marketed, relied upon, or misunderstood, GCRI Canada shall correct and escalate the matter proportionately. Escalation may include public-safe clarification, controlled notice, revised language, removal of public authority references, withdrawal of materials, correction of dashboards or maps, notice to affected public authorities, legal review, Board review, access revocation, termination of participation, return of data, or suspension of program activity. Any actual proposed delegation shall require legal review, Board review, competent public authority action, public-safe review, and express record.

383.16 No-Delegation Records. GCRI Canada shall maintain no-delegation records, including no-public-authority-delegation rule records, no-governmental-power records, no-regulatory-power records, no-emergency-power records, no-public-warning-power records, no-procurement-power records, no-public-finance-power records, no-grant-approval-power records, no-public-health-order-power records, no-public-safety-command-power records, no-delegation-by-data-contribution records, no-delegation-by-meeting-attendance records, no-delegation-by-simulation / exercise / dashboard / Observatory / controlled-room records, no-delegation-by-public-authority-staff-involvement records, correction and escalation records, legal review records, Board review records, clarifications, withdrawals, closeouts, and archives.


Section 384. No Public-Private Partnership by Participation

384.1 No PPP by Participation Rule. No public authority participation, attendance, data contribution, hosting, public authority learning, Observatory demonstration, Nexus Universe participation, public-safe publication review, dashboard review, map review, controlled-room participation, sponsor presence, provider presence, public materials reference, curated introduction, Partnering Office activity, lab, challenge, benchmark, adoption window, sprint, pilot, fellowship, Academy program, or Nexus-compatible coordination shall create a public-private partnership, concession, joint venture, agency, co-venture, shared-liability arrangement, public procurement relationship, public finance relationship, public authority mandate, sovereign obligation, or official public-sector project with GCRI Canada unless a separate lawful instrument expressly creates such relationship and is approved by competent public authority and GCRI Canada authority.

384.2 No PPP by Meeting. Meetings between GCRI Canada and public authorities, providers, sponsors, hosts, donors, funders, universities, laboratories, communities, National Consortium Companies, Project SPVs, capital readers, or Nexus-compatible actors shall not create a public-private partnership. Meeting agendas, minutes, attendance lists, presentations, discussion notes, follow-up actions, public-safe summaries, or public authority learning materials shall not be described as PPP formation, project approval, procurement initiation, concession negotiation, joint venture creation, or public mandate unless separately recorded by competent lawful instrument.

384.3 No PPP by Attendance. Attendance by public authority participants, providers, sponsors, hosts, donors, funders, public finance readers, regulators, emergency-management participants, infrastructure operators, or public-sector institutions at GCRI Canada activities shall not create a PPP. Attendance may show learning, listening, observation, technical discussion, evidence review, or public-benefit coordination only. Attendance shall not be used in fundraising, provider marketing, sponsor marketing, procurement materials, investment materials, public authority-facing materials, or media to imply PPP status.

384.4 No PPP by Data Contribution. Public authority data contribution, infrastructure data contribution, public-sector context contribution, dashboard input, map input, observability signal, or public authority review shall not create a public-private partnership. Data contribution may support evidence, methods, public-safe publication, learning, or correction within recorded permissions, but shall not create joint ownership, shared liability, public procurement relationship, public finance obligation, public-sector project, concession, operating mandate, or public authority delegation. Data-sharing instruments shall be interpreted according to their terms and shall not be inflated into PPP status.

384.5 No PPP by Public Authority Learning. Public authority learning sessions, Academy programs, public authority literacy modules, regulator-listening sessions, public finance reader sessions, emergency-management learning, infrastructure operator learning, technical literacy briefings, public-safe publication training, scenario learning, simulation learning, or dashboard literacy shall not create a public-private partnership. Learning support shall not be described as public-sector adoption, government partnership, official mandate, public finance pathway, procurement pathway, or public authority program unless separately authorized.

384.6 No PPP by Observatory Demonstration. Demonstration of Nexus Observatory methods, dashboards, maps, sensors, telemetry concepts, AI-RAN / O-RAN evidence methods, DePIN evidence methods, geospatial methods, digital twins, degraded-mode awareness, resilience indicators, Truth Engine methods, public-safe intelligence outputs, or verifiable intelligence records to public authorities shall not create a PPP. Demonstrations shall be learning and evidence demonstrations only and shall not constitute public warning systems, emergency command systems, infrastructure control systems, procurement approvals, public finance approvals, public authority adoption, or official deployment.

384.7 No PPP by Nexus Universe Participation. Participation in Nexus Universe, Nexus-compatible programs, Global Nexus Consortium interfaces, Regional Nexus Consortium interfaces, National Nexus Consortium interfaces, National Working Groups, Nexus Competence Cells, Nexus Academy, Nexus Observatory, Nexus Risk Management, Nexus Rails, Nexus Grid, GRA interfaces, GRF-compatible processes, National Consortium Company interfaces, or Project SPV interfaces shall not create a public-private partnership with GCRI Canada by default. Nexus participation shall preserve legal separateness, role separation, no merger, no shared treasury, no shared liability, non-execution, public authority boundaries, finance boundaries, certification boundaries, procurement neutrality, and correctionability.

384.8 No PPP by Sponsor or Provider Presence. Sponsor or provider presence in a public authority learning session, lab, challenge, benchmark, adoption window, pilot, Academy session, public-safe briefing, dashboard review, map review, controlled room, or Nexus-compatible event shall not create a PPP. Sponsor or provider presence shall not imply public authority endorsement, procurement pathway, public finance pathway, government-backed provider status, approved vendor status, official technology status, certification, recognition, maturity, or finance-readiness. Sponsor and provider participation shall remain subject to non-control, provider neutrality, public claims restrictions, and anti-capture controls.

384.9 No PPP by Public Materials Reference. Public materials referencing public authorities, providers, sponsors, hosts, donors, funders, universities, laboratories, communities, National Consortium Companies, Project SPVs, capital readers, or Nexus actors shall not create a PPP by wording, layout, logos, acknowledgments, photographs, event materials, reports, websites, social media, press releases, dashboards, maps, public-safe summaries, or decks. Public materials shall use approved language and non-PPP language where needed. Use of phrases such as “with,” “in collaboration with,” “supported by,” “hosted by,” or “participant” shall be carefully controlled to avoid PPP implication.

384.10 PPP Only by Separate Lawful Instrument. A public-private partnership, if ever applicable to GCRI Canada, may exist only through a separate lawful instrument approved by competent public authority, approved by GCRI Canada’s Board or other competent authority, legally reviewed, financially reviewed, public authority-boundary reviewed, procurement-reviewed, finance-boundary reviewed, data / AI / cyber reviewed, safeguards-reviewed where applicable, and recorded. Such instrument shall define parties, scope, authority, obligations, liabilities, funding, procurement status, data rights, IP, publication, public authority powers, public-safe controls, termination, correction, and no-unintended-delegation provisions. Participation alone is never sufficient.

384.11 PPP Public Language Controls. GCRI Canada shall not use PPP language, public-private partnership language, government partnership language, official project language, sovereign project language, public mandate language, co-delivery language, concession language, public finance language, procurement language, or official adoption language unless a separate lawful instrument supports the exact statement and approved public language exists. Where collaboration is informal, educational, learning-based, advisory, evidence-based, or non-executing, public language shall say so. Public materials shall include non-PPP and non-endorsement language where material.

384.12 PPP Correction and Clarification. Where GCRI Canada, a public authority, sponsor, provider, host, donor, funder, participant, media outlet, capital actor, National Consortium Company, Project SPV, or other person misstates or implies PPP status without lawful basis, GCRI Canada shall correct or clarify the matter proportionately. Correction may include revised public language, removal of logos, removal of “partnership” phrasing, public-safe clarification, controlled notice, sponsor or provider notice, public authority notice, withdrawal of materials, contract amendment, access revocation, or Board escalation.

384.13 PPP Boundary Records. GCRI Canada shall maintain PPP boundary records, including no-PPP-by-participation records, no-PPP-by-meeting records, no-PPP-by-attendance records, no-PPP-by-data-contribution records, no-PPP-by-public-authority-learning records, no-PPP-by-Observatory-demonstration records, no-PPP-by-Nexus-Universe-participation records, no-PPP-by-sponsor-or-provider-presence records, no-PPP-by-public-materials-reference records, separate lawful instrument records where any, PPP public language control records, correction and clarification records, public authority notices, sponsor and provider notices, withdrawals, closeouts, and archives.


Section 385. No Public Warning, Emergency Command, Procurement Approval, Funding Approval, Regulatory Approval, Public Finance Approval, Sovereign Obligation, or Adoption by Participation

385.1 No Public Warning by Participation. No participation in GCRI Canada activities shall create public warning authority, official alert authority, emergency bulletin authority, hazard warning authority, public health warning authority, public safety warning authority, cyber public warning authority, infrastructure failure warning authority, evacuation warning authority, or official notice authority. Participation includes attendance, observation, speaking, review, data contribution, dashboard review, map review, Observatory learning, Truth Engine learning, simulation, scenario, controlled-room access, lab participation, challenge participation, benchmark participation, public authority learning, and Nexus-compatible coordination. Public warnings remain the responsibility of competent public authorities.

385.2 No Emergency Command by Participation. No participation in GCRI Canada activities shall create emergency command, incident command, unified command, dispatch authority, responder command, evacuation authority, operational resource direction, emergency operations authority, cyber incident command, public health emergency command, public safety command, utility command, port command, telecom command, energy command, water command, infrastructure command, or public works command. GCRI Canada activities may support learning, evidence, methods, and public-safe reporting only. Any real-world emergency command remains outside GCRI Canada unless separately and lawfully exercised by competent authorities.

385.3 No Procurement Approval by Participation. No participation in GCRI Canada activities shall constitute procurement approval, vendor approval, provider selection, bidder prequalification, tender requirement, purchasing recommendation, contract award, public-sector eligibility, procurement score, procurement ranking, procurement due diligence, or official buying signal. Providers shall not cite participation, attendance, data contribution, dashboard review, benchmark participation, challenge result, lab output, Academy completion, or public authority presence as procurement validation. Public authorities and purchasers remain responsible for their own procurement processes.

385.4 No Funding Approval by Participation. No participation in GCRI Canada activities shall constitute funding approval, grant approval, budget approval, appropriation approval, funding recommendation, disbursement approval, public program eligibility, public finance pathway, donor approval, funder approval, public authority funding commitment, or philanthropic funding commitment. Participation may support learning or evidence understanding only. GCRI Canada shall not present participation as increasing funding likelihood or satisfying funding criteria unless a competent funder separately and lawfully states such criteria.

385.5 No Regulatory Approval by Participation. No participation in GCRI Canada activities shall constitute regulatory approval, compliance determination, legal interpretation, permit, license, safe harbor, no-action position, enforcement position, inspection approval, conformity assessment, regulated clearance, or official guidance. Regulator attendance, regulator listening, regulator review, technical discussion, or public authority learning shall not be represented as regulatory acceptance. Regulatory decisions remain with competent regulators.

385.6 No Public Finance Approval by Participation. No participation by public finance readers, development finance institutions, multilateral development banks, export credit bodies, public lenders, public insurers, guarantee bodies, treasury bodies, budget offices, public funds, municipal finance bodies, Crown finance bodies, public-private partnership offices, or public finance participants shall constitute public finance approval, public guarantee, public credit approval, MDB approval, DFI approval, lending approval, insurance approval, underwriting approval, public finance commitment, public finance readiness, bankability, investability, capital-readability, or rating. GCRI Canada shall not provide investment recommendations or finance-readiness determinations.

385.7 No Sovereign Obligation by Participation. No participation in GCRI Canada activities shall create sovereign obligation, Crown obligation, municipal obligation, public debt, contingent liability, public guarantee, public credit obligation, appropriation obligation, intergovernmental obligation, treaty obligation, public-private partnership obligation, concession obligation, procurement obligation, public finance obligation, or official undertaking. Public authority personnel, public authority logos, public-sector facilities, public-sector data, public finance readers, or public comments shall not be used to imply sovereign backing.

385.8 No Public Authority Adoption by Participation. No participation in GCRI Canada activities shall constitute public authority adoption of GCRI Canada research, evidence, methods, observability outputs, ontology, public-good software, open technical baselines, dashboards, maps, datasets, public-safe summaries, Academy materials, competence-cell materials, challenge results, benchmark outputs, lab outputs, pilot outputs, sprint outputs, proof packs, finance-boundary materials, GRF-compatible inputs, GRA-facing inputs, Nexus Rails inputs, Nexus Grid inputs, or Nexus interface outputs. Adoption requires separate lawful action by the competent public authority.

385.9 No Public Infrastructure Adoption by Participation. No participation by public infrastructure operators, utilities, ports, telecom systems, energy systems, water systems, food systems, health systems, transportation systems, cyber bodies, public works bodies, or infrastructure participants shall constitute public infrastructure adoption of GCRI Canada outputs. Infrastructure adoption, system deployment, operational use, technical integration, procurement, service change, resilience program, or public infrastructure decision requires separate action by the competent operator or authority. GCRI Canada shall not imply deployment by participation.

385.10 No Public Policy Adoption by Participation. No participation by policymakers, policy discussants, ministries, agencies, municipalities, regulators, Crown entities, public institutions, or public-sector participants shall constitute public policy adoption, policy endorsement, legislative support, regulatory support, budget support, ministerial support, cabinet support, council support, departmental position, official strategy, or public authority policy decision. Policy learning and discussion shall remain non-binding unless separately issued through lawful public authority process.

385.11 No Budget or Appropriation Implication by Participation. No participation shall imply budget allocation, appropriation, spending authority, treasury approval, municipal budget approval, ministerial budget approval, Crown funding approval, public program funding, public finance allocation, or financial commitment. GCRI Canada shall not use public authority attendance, public finance reader participation, grantor conversation, or public authority learning to suggest that public funds have been allocated, reserved, approved, or likely.

385.12 No Official Safety, Health, Security, or Resilience Determination by Participation. No participation shall constitute official determination of safety, health, security, cyber maturity, resilience, readiness, reliability, performance, compliance, hazard status, emergency readiness, public health status, public safety status, infrastructure condition, service continuity, vulnerability, or risk acceptability. GCRI Canada outputs may describe evidence, methods, limitations, scenarios, simulations, indicators, or public-safe summaries, but shall not be represented as official safety, health, security, or resilience determinations by participation.

385.13 Required Participation Boundary Language. GCRI Canada shall include participation boundary language where public misunderstanding is reasonably possible. Such language shall state, as applicable, that participation, attendance, observation, review, data contribution, hosting, speaking, public authority learning, regulator listening, public finance reading, emergency-management learning, infrastructure operator input, dashboard review, map review, simulation participation, or controlled-room access does not constitute public warning, emergency command, procurement approval, funding approval, regulatory approval, public finance approval, sovereign obligation, public authority adoption, public infrastructure adoption, public policy adoption, budget approval, safety determination, health determination, security determination, resilience determination, certification, recognition, finance-readiness, or provider preference.

385.14 Participation Overclaim Correction. Where participation is overclaimed by GCRI Canada, a participant, public authority, sponsor, provider, host, donor, funder, capital actor, media outlet, National Consortium Company, Project SPV, or other person, GCRI Canada shall correct the overclaim proportionately. Correction may include revised language, removal of public authority references, removal of logos, removal of quotes, removal of provider claims, public-safe clarification, controlled notice, participant notice, sponsor or provider notice, dashboard note, map note, publication correction, withdrawal, access revocation, termination of participation, or Board escalation. Overclaims involving public warnings, emergency command, procurement, funding, regulation, public finance, sovereign obligation, or adoption shall receive heightened review.

385.15 Participation Boundary Records. GCRI Canada shall maintain participation boundary records, including no-public-warning-by-participation records, no-emergency-command-by-participation records, no-procurement-approval-by-participation records, no-funding-approval-by-participation records, no-regulatory-approval-by-participation records, no-public-finance-approval-by-participation records, no-sovereign-obligation-by-participation records, no-public-authority-adoption-by-participation records, no-public-infrastructure-adoption-by-participation records, no-public-policy-adoption-by-participation records, no-budget-or-appropriation-implication records, no-official-safety / health / security / resilience-determination records, required participation boundary language records, overclaim correction records, participant notices, public-safe clarifications, withdrawals, closeouts, and archives.

Section 386. Public Authority Correction, Withdrawal, and Public Clarification

386.1 Public Authority Correction Purpose. GCRI Canada shall maintain a public authority correction, withdrawal, and public clarification process to ensure that any public authority reference, public authority capacity description, public authority data contribution reference, official-capacity statement, regulator-listening statement, public finance reader statement, emergency-management statement, infrastructure-operator statement, public authority logo use, title use, quote use, photograph use, attendance reference, dashboard reference, map reference, publication reference, donor report, sponsor report, provider reference, capital-reader reference, public-safe summary, or Nexus-compatible interface statement is accurate, current, authorized, capacity-classified, public-safe, limitation-bearing, and correctionable. This process shall protect public trust, prevent public authority confusion, preserve GCRI Canada’s non-executing role, and ensure that no public authority relationship is overstated into endorsement, adoption, public warning, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, public-private partnership, sovereign obligation, certification, recognition, finance-readiness, maturity, provider preference, or public authority delegation.

386.2 Misdescription Trigger. A correction process shall be triggered where a public authority, public authority participant, public authority office, public body, jurisdiction, title, role, agency name, ministry name, municipal name, Crown name, regulator name, public institution name, public infrastructure operator name, public health body, public safety body, public finance body, or public authority relationship is misstated, inaccurately described, overbroadly described, ambiguously described, attributed to the wrong body, attributed to the wrong person, attributed in the wrong capacity, or described in a way that could reasonably mislead a reader. Misdescription includes treating observer status as endorsement, regulator-listening status as approval, public finance reader status as funding commitment, emergency-management participation as command, infrastructure operator participation as operational adoption, or attendance as official authority.

386.3 Overclaim Trigger. A correction process shall be triggered where any GCRI Canada material, participant statement, sponsor material, provider material, donor material, funder material, host material, media statement, social media post, public report, public deck, website, dashboard, map, dataset, software release, Academy material, public authority learning material, challenge output, benchmark output, lab output, adoption-window output, sprint output, or Nexus-compatible statement overclaims public authority involvement. Overclaim includes any implication of official endorsement, adoption, approval, public warning, emergency command, regulation, procurement approval, funding approval, public finance approval, sovereign obligation, public-private partnership, public policy adoption, public infrastructure adoption, finance-readiness, certification, recognition, maturity status, provider preference, or official mandate not supported by competent record.

386.4 Unauthorized Reference Trigger. A correction process shall be triggered where GCRI Canada uses, publishes, displays, distributes, republishes, quotes, photographs, records, maps, dashboard-displays, lists, or otherwise references a public authority, public authority participant, public authority logo, agency name, jurisdiction, title, quote, photograph, attendance, data contribution, facility, public-sector role, or public authority relationship without required permission, outside approved language, outside authorized capacity, outside permitted use, outside confidentiality terms, outside publication review terms, outside data rights, or outside public-safe review. Unauthorized references shall be corrected promptly and may require withdrawal, takedown, public-safe clarification, controlled notice, or archive correction.

386.5 Outdated Capacity Trigger. A correction process shall be triggered where a previously accurate public authority capacity, role, title, authority scope, affiliation, participation status, review status, data contribution status, attribution permission, quote permission, logo permission, public authority relationship, or public reference becomes outdated. Outdated capacity may arise because a participant changes office, leaves public service, changes department, loses delegated authority, changes participation status, withdraws permission, changes public authority policy, changes data terms, changes publication terms, or ceases involvement. GCRI Canada shall not continue using stale capacity language where it may mislead.

386.6 Changed Authority Trigger. A correction process shall be triggered where a public authority participant’s authority expands, narrows, expires, is revoked, is reassigned, becomes disputed, becomes uncertain, or becomes inconsistent with prior public language. Changed authority shall be reflected in capacity records, access records, public language, attribution records, data contribution records, dashboard and map records, controlled-room access, publication approvals, donor and sponsor reports, and archives where necessary. Changed authority shall not retroactively validate prior overclaims or authorize broader use unless expressly recorded.

386.7 Withdrawn Permission Trigger. A correction process shall be triggered where a public authority, public authority participant, public body, data provider, reviewer, host authority, regulator-listening participant, public finance reader, emergency-management participant, infrastructure operator, or other public-sector participant withdraws permission for attribution, quote use, logo use, photograph use, recording use, data use, public reference, publication, dashboard display, map display, controlled-material distribution, or other use. GCRI Canada shall evaluate the effect of withdrawal on existing materials, future materials, public-safe summaries, controlled summaries, datasets, dashboards, maps, repositories, and archives, and shall implement withdrawal, limitation, redaction, correction, or archive notation where required.

386.8 Public Authority Objection Trigger. A correction process shall be triggered where a public authority objects to a reference, capacity statement, logo use, quote, photograph, data contribution reference, publication language, dashboard, map, public-safe summary, donor report, sponsor report, provider reference, public statement, media statement, or Nexus-compatible statement involving that public authority. GCRI Canada shall intake the objection, assess authority, records, public-safe implications, legal implications, data implications, publication implications, sponsor or provider implications, finance-boundary implications, procurement-boundary implications, and correction needs. Objections shall be handled promptly, respectfully, and without conceding unsupported control over independent findings except where correction is justified.

386.9 GCRI Canada-Initiated Correction. GCRI Canada may initiate correction without waiting for a public authority request where internal review, Board review, officer review, publication review, legal review, public-safe review, data / AI / cyber review, safeguards review, media monitoring, participant report, whistleblowing report, or downstream materials review identifies public authority misdescription, overclaim, unauthorized reference, outdated capacity, changed authority, withdrawn permission, public authority confusion, public warning implication, emergency command implication, procurement implication, funding implication, public finance implication, regulatory implication, sovereign obligation implication, public-private partnership implication, finance-readiness implication, certification implication, recognition implication, maturity implication, or provider preference.

386.10 Public Authority-Initiated Correction. A public authority may request correction, clarification, withdrawal, takedown, revised attribution, revised capacity language, removal of a logo, removal of a quote, removal of a photograph, data handling change, publication revision, dashboard change, map change, or public-safe clarification. GCRI Canada shall review such request according to law, agreement, authority, public-safe obligations, research integrity, publication integrity, data rights, protected knowledge, confidentiality, correctionability, and institutional independence. Where the request concerns factual inaccuracy, authorization, confidentiality, data rights, public authority capacity, or public-safe risk, GCRI Canada shall act promptly. Where the request seeks to suppress lawful independent findings without adequate basis, GCRI Canada shall escalate for legal, Board, or appropriate review.

386.11 Controlled Correction Notice. GCRI Canada may issue a controlled correction notice where the correction concerns controlled materials, public authority-sensitive information, cyber-sensitive information, infrastructure-sensitive information, health-sensitive information, finance-sensitive evidence, protected knowledge, confidential data, controlled-room materials, data-room materials, or non-public participant records. A controlled correction notice may be distributed only to affected persons, authorized participants, public authorities, reviewers, sponsors, donors, funders, providers, hosts, or other recipients with need to know. Controlled correction notices shall identify the corrected item, correction reason, effective date, prior language, revised language where appropriate, affected materials, downstream dependencies, and further action.

386.12 Public Clarification. GCRI Canada may issue a public clarification where public misunderstanding is reasonably possible or where a public reference, media report, sponsor claim, provider claim, public authority reference, dashboard, map, report, public-safe summary, social media post, or Nexus-compatible statement could be interpreted as endorsement, adoption, approval, public warning, emergency command, regulation, procurement approval, funding approval, public finance approval, sovereign obligation, public-private partnership, certification, recognition, finance-readiness, maturity, provider preference, or delegation. Public clarification shall be accurate, proportionate, public-safe, non-defamatory, and sufficiently visible to correct the misunderstanding.

386.13 Withdrawal or Takedown. GCRI Canada may withdraw, takedown, restrict, redraft, suppress from public access, replace, archive, or reclassify materials where correction is insufficient to address public authority misdescription, unauthorized reference, public authority objection, withdrawn permission, data rights issue, confidentiality issue, public-safe risk, protected knowledge risk, cyber risk, infrastructure sensitivity, public warning implication, emergency command implication, finance-boundary overclaim, procurement-boundary overclaim, certification overclaim, recognition overclaim, or provider-preference implication. Withdrawal or takedown shall be recorded and shall preserve archive traceability where legally and safely permissible.

386.14 Downstream Materials Review. When a public authority correction, clarification, withdrawal, or takedown occurs, GCRI Canada shall review downstream materials that may repeat or rely on the corrected statement, including websites, reports, whitepapers, decks, social media, press releases, donor reports, sponsor reports, grant reports, provider references, public-safe summaries, controlled summaries, dashboards, maps, datasets, software release notes, repositories, Academy materials, challenge materials, benchmark materials, lab materials, adoption-window materials, sprint outputs, public authority learning materials, media kits, and partner materials. Downstream materials shall be corrected, withdrawn, reclassified, or annotated where necessary.

386.15 Sponsor, Provider, Partner, or Media Correction Where Required. Where a sponsor, provider, partner, host, donor, funder, media outlet, National Consortium Company, Project SPV, capital actor, or other third party uses public authority references in a manner inconsistent with GCRI Canada records or public authority permissions, GCRI Canada may require correction, withdrawal, revised language, removal of logos, removal of quotes, removal of photographs, removal of public authority claims, public-safe clarification, or cessation of use. GCRI Canada may suspend benefits, revoke access, terminate participation, notify affected public authorities, or issue public clarification where misuse materially risks public misunderstanding.

386.16 Public Authority Correction Records. GCRI Canada shall maintain public authority correction records, including correction purpose records, misdescription trigger records, overclaim trigger records, unauthorized reference trigger records, outdated capacity trigger records, changed authority trigger records, withdrawn permission trigger records, public authority objection trigger records, GCRI Canada-initiated correction records, public authority-initiated correction records, controlled correction notices, public clarifications, withdrawals, takedowns, downstream materials reviews, sponsor / provider / partner / media correction records, public authority notices, legal reviews, Board reviews where applicable, revised language, archive notes, closeouts, and retained evidence of correction.


Section 387. Indigenous Rights, Indigenous Data, Indigenous Knowledge, Community Protocols, FPIC Where Applicable, Protected Knowledge, and Public-Safe Mapping

387.1 Indigenous Rights Respect. GCRI Canada shall respect Indigenous rights, Indigenous governance, Indigenous laws and protocols where applicable, treaty rights, Aboriginal rights, rights-bearing communities, Indigenous data sovereignty principles, cultural responsibilities, community decision-making structures, and the dignity, safety, continuity, and self-determination of Indigenous Peoples in all research, evidence, methods, observability, ontology, data / AI / cyber, public-safe publication, mapping, dashboarding, Academy, training, fellowship, lab, challenge, benchmarking, public authority learning, and Nexus-compatible activities. GCRI Canada shall not treat Indigenous participation, knowledge, data, territory, governance, or cultural materials as ordinary institutional inputs subject to extraction, repackaging, AI processing, public mapping, or sponsor use. Where Indigenous rights or protocols apply, they shall be treated as substantive safeguards, not symbolic consultation.

387.2 Indigenous Data Safeguards. Indigenous data shall be handled with safeguards appropriate to the relevant community, Nation, rights-holder, custodian, agreement, law, protocol, consent, non-consent, restriction, context, and sensitivity. Indigenous data may include personal information, community data, territorial data, environmental data, cultural data, land-use data, health data, infrastructure data, public authority data, geospatial data, oral knowledge records, governance records, or derived outputs. Indigenous data shall not be collected, stored, transferred, mapped, modeled, embedded, used for AI, disclosed, published, commercialized, or repurposed without recorded authority and safeguards. GCRI Canada shall support access limits, custodial rights, correction rights, withdrawal rights, attribution preferences, non-attribution preferences, and public-safe transformation.

387.3 Indigenous Knowledge Safeguards. Indigenous knowledge, including oral histories, cultural knowledge, ecological knowledge, territorial knowledge, language knowledge, ceremonial knowledge, sacred knowledge, land-use knowledge, environmental indicators, community risk knowledge, and intergenerational knowledge, shall be handled with respect, restraint, and context. GCRI Canada shall not convert Indigenous knowledge into open datasets, public maps, AI training data, sponsor materials, provider materials, technical baselines, or public-good software artifacts unless authority, consent where applicable, safeguarding, attribution, restriction, and public-safe review support such use. Protected, sacred, restricted, or community-governed knowledge shall remain protected.

387.4 Indigenous Governance Protocols. GCRI Canada shall identify and follow applicable Indigenous governance protocols where activities involve Indigenous Peoples, Indigenous territory, Indigenous data, Indigenous knowledge, Indigenous institutions, Indigenous public authorities, Indigenous governments, Indigenous organizations, Indigenous communities, or Indigenous rights-bearing matters. Governance protocols may concern who may speak, who may authorize, how consent or non-consent is expressed, how knowledge is attributed or protected, how maps are reviewed, how sensitive locations are handled, how disputes are resolved, how benefits are shared, how corrections are made, and how withdrawal is respected. GCRI Canada shall not substitute convenience, sponsor timelines, public authority timelines, or technical timelines for required protocols.

387.5 Local and Territorial Knowledge Safeguards. Local and territorial knowledge, including community observations, environmental knowledge, land-use knowledge, cultural site knowledge, hazard memory, infrastructure vulnerability knowledge, climate exposure knowledge, food-system knowledge, water-system knowledge, health-system knowledge, public safety knowledge, and place-based resilience knowledge, shall be protected against extraction, misuse, misattribution, decontextualization, unsafe mapping, AI misuse, sponsor exploitation, provider exploitation, public authority overreach, and public misunderstanding. GCRI Canada shall classify such knowledge according to sensitivity and shall apply access, attribution, consent, non-consent, withdrawal, correction, and publication controls.

387.6 Community Protocols. GCRI Canada shall respect community protocols where communities establish expectations for engagement, information sharing, consent, meeting conduct, recording, attribution, non-attribution, publication, mapping, photography, translation, language use, elder involvement, youth involvement, accessibility, data custody, protected knowledge, benefit sharing, withdrawal, correction, grievance, or remedy. Community protocols shall be recorded where appropriate and shall inform program design, publication timelines, public-safe review, data / AI / cyber controls, and closeout. GCRI Canada shall not treat community participation as blanket permission for use or public release.

387.7 Free, Prior, and Informed Consent Where Applicable. Where free, prior, and informed consent is applicable under law, agreement, Indigenous protocol, community protocol, funder requirements, ethical standards, or safeguards review, GCRI Canada shall not proceed with relevant data collection, knowledge use, mapping, publication, AI use, external transfer, public-safe release, controlled-room use, or public authority-facing use without satisfying the applicable process. FPIC-related processes shall be free of coercion, prior to the relevant action, informed by clear and accessible explanation, specific enough to define permitted use, and capable of documenting consent, non-consent, conditions, withdrawal, and correction. GCRI Canada shall not treat funding urgency, sponsor interest, public authority interest, or institutional convenience as overriding applicable FPIC requirements.

387.8 Consent, Non-Consent, Attribution, Withdrawal, Correction, and Restriction Pathways. GCRI Canada shall maintain pathways for consent, non-consent, attribution, non-attribution, withdrawal, correction, and restriction where Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, community knowledge, cultural knowledge, environmental knowledge, protected knowledge, community participation, or public-safe mapping is involved. These pathways shall be clear, accessible, culturally appropriate where relevant, language-accessible where needed, and record-supported. Withdrawal or restriction may require removal, redaction, aggregation, access restriction, public-safe correction, controlled notice, publication revision, dashboard update, map revision, archive notation, or cessation of use.

387.9 Protected Knowledge Treatment. Protected knowledge shall be classified, access-limited, purpose-limited, and handled according to authority, protocol, consent, non-consent, restriction, context, and sensitivity. Protected knowledge may include sacred site information, cultural practices, ecological knowledge, territorial knowledge, community risk knowledge, health-sensitive knowledge, infrastructure vulnerability knowledge, safety-sensitive knowledge, or knowledge whose disclosure could create harm, extraction, stigmatization, retaliation, commercial exploitation, or public authority misuse. Protected knowledge shall not be uploaded to unapproved AI systems, embedded in public repositories, displayed in public maps, disclosed to sponsors or providers, used in capital-reader materials, or transferred externally unless expressly authorized and safeguarded.

387.10 Cultural Site Protection. GCRI Canada shall protect cultural sites, sacred sites, burial sites, ceremonial sites, heritage sites, gathering sites, archaeological locations, culturally sensitive landscapes, and other sensitive places from unsafe disclosure, public mapping, geospatial precision, re-identification, exploitation, vandalism, surveillance, commercialization, or public authority misuse. Cultural site information shall be generalized, masked, suppressed, controlled, redacted, or excluded where needed. Public-safe mapping shall avoid revealing precise locations, access routes, vulnerability information, custodial information, or other sensitive details unless authorized by competent custodians and safe to release.

387.11 Environmental Knowledge Protection. Environmental knowledge, including species locations, habitat information, water sources, climate indicators, land-use patterns, resource locations, hazard-sensitive areas, ecological vulnerabilities, and community environmental observations, shall be protected where disclosure could create ecological harm, cultural harm, community harm, exploitation, resource extraction, poaching, vandalism, stigmatization, or public authority misuse. GCRI Canada shall assess environmental knowledge before publication, AI use, mapping, dashboarding, data sharing, or external transfer and shall apply aggregation, masking, seasonal restriction, controlled access, or non-public handling where needed.

387.12 Public-Safe Mapping Rules. Public-safe mapping involving Indigenous, local, territorial, cultural, environmental, community, infrastructure, public health, public safety, or protected knowledge shall be reviewed before release. Mapping review shall assess geospatial precision, re-identification risk, cultural site exposure, environmental exposure, infrastructure vulnerability, public safety risk, community stigmatization, protected knowledge, public authority implications, sponsor or provider misuse, AI-use risk, data linkage risk, and correction path. GCRI Canada may aggregate, generalize, blur, mask, delay, suppress, classify, restrict, or withdraw maps to prevent harm. No map shall be treated as public warning, emergency command, public authority decision, procurement approval, finance-readiness determination, certification, recognition, maturity, or provider preference.

387.13 No Extraction for Sponsor, Provider, Donor, Funder, Host, Public Authority, or Institutional Convenience. GCRI Canada shall not extract, pressure, solicit, collect, package, translate, map, publish, model, commercialize, or transfer Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, community knowledge, or protected knowledge for sponsor, provider, donor, funder, host, public authority, media, institutional, technical, capital-reader, or program convenience. Public-benefit purpose, respectful process, authority, safeguards, consent where applicable, community protocols, data rights, protected knowledge controls, and correctionability shall govern. Convenience, prestige, funding, urgency, publication interest, dashboard interest, or technical capability shall not override safeguards.

387.14 Safeguards Review Before Publication, Mapping, Data Sharing, AI Use, or External Transfer. Before publication, mapping, dashboarding, data sharing, AI use, embedding, model training, retrieval indexing, external transfer, sponsor disclosure, provider disclosure, public authority-facing disclosure, capital-reader disclosure, public-safe summary, controlled summary, or repository placement involving Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, community knowledge, or protected knowledge, GCRI Canada shall conduct safeguards review. Safeguards review shall determine whether the activity is permitted, prohibited, restricted, subject to consent, subject to community review, subject to redaction, subject to aggregation, subject to controlled access, subject to non-public handling, or subject to withdrawal.

387.15 Indigenous, Community, and Protected Knowledge Records. GCRI Canada shall maintain Indigenous, community, and protected knowledge records, including Indigenous rights respect records, Indigenous data safeguard records, Indigenous knowledge safeguard records, Indigenous governance protocol records, local and territorial knowledge safeguard records, community protocol records, FPIC records where applicable, consent / non-consent / attribution / withdrawal / correction / restriction records, protected knowledge treatment records, cultural site protection records, environmental knowledge protection records, public-safe mapping records, no-extraction records, safeguards review records, public-safe release decisions, controlled-access decisions, correction records, withdrawal records, closeouts, and archives.


388.1 Community Participation Purpose. GCRI Canada may support community participation to ensure that research, evidence, methods, observability, ontology, public-safe publication, public authority learning, dashboards, maps, Academy programs, competence cells, labs, challenges, benchmarking, and Nexus-compatible activities are informed by community context, lived experience, local knowledge, safeguards, accessibility needs, public-safe concerns, and correction pathways. Community participation shall be public-benefit oriented, respectful, non-extractive, accessible, voluntary where appropriate, capacity-aware, and boundary-controlled. Participation shall not be used to manufacture legitimacy, public authority approval, sponsor benefit, provider benefit, finance-readiness, certification, recognition, maturity, procurement advantage, or institutional endorsement.

388.2 Community Participation Without Coercion. Community participation shall not be obtained through coercion, undue influence, funding pressure, public authority pressure, sponsor pressure, provider pressure, access pressure, reputational pressure, emergency pressure, compensation pressure, information asymmetry, or implied loss of benefits. Participation shall be structured so that people and communities can decline, limit, condition, withdraw, correct, or restrict participation where applicable. GCRI Canada shall avoid extractive timelines, tokenistic consultation, performative inclusion, or participation designs that shift institutional burdens onto communities without support.

388.3 Accessibility. GCRI Canada shall support accessibility in community participation through reasonable and appropriate measures such as accessible venues, remote participation, plain-language materials, accessible digital documents, captioning, interpretation, assistive technology compatibility, disability accommodation, flexible scheduling, travel support where approved, caregiver-aware design where feasible, sensory-aware formats where feasible, and alternative contribution methods. Accessibility shall be treated as a participation safeguard and public-benefit requirement, not as an optional courtesy.

388.4 Inclusive Participation. GCRI Canada shall design community participation to include, where relevant and lawful, diverse perspectives across geography, language, age, disability, gender, socioeconomic status, Indigenous identity, local or territorial role, lived experience, sector exposure, climate exposure, infrastructure exposure, public health vulnerability, digital access, and community function. Inclusive participation shall not require disclosure of protected personal characteristics unless lawful, necessary, voluntary, and safeguarded. Inclusion shall be substantive and not used to imply community endorsement.

388.5 Language and Communication Accessibility. GCRI Canada shall support language and communication accessibility where community participation requires translation, interpretation, plain-language explanation, culturally appropriate communication, visual formats, oral formats, community briefings, or accessible technical explanations. Technical materials, public authority boundary language, consent information, non-consent pathways, withdrawal pathways, data-use explanations, AI-use explanations, mapping implications, and correction paths shall be understandable to affected participants where feasible. Lack of clear communication may require deferral, re-scoping, or non-use.

388.6 Remote Community Participation Support. Remote community participation may require additional support for travel, connectivity, timing, language, accessibility, local coordination, meeting format, data collection, mapping review, public-safe publication review, protected knowledge handling, and feedback loops. GCRI Canada shall avoid participation models that impose unreasonable burdens on remote communities or create unsafe disclosure of community location, infrastructure vulnerabilities, environmental knowledge, or protected knowledge. Remote participation support shall not become extraction or dependency.

388.7 Vulnerable Community Participation Support. Where participation involves vulnerable communities, disaster-exposed communities, climate-exposed communities, health-vulnerable groups, infrastructure-exposed groups, marginalized communities, displaced persons, youth, elders, persons with disabilities, remote communities, or communities facing retaliation risk, GCRI Canada shall apply heightened safeguards. Support may include trauma-informed approaches where appropriate, confidentiality, non-retaliation, safe meeting design, consent and non-consent pathways, public-safe publication review, anonymization, grievance channels, and remedy pathways. Participation shall not amplify harm.

388.8 Consent Pathways Where Applicable. Where consent is required or appropriate, GCRI Canada shall provide consent pathways that identify the activity, purpose, use, data collected, knowledge involved, publication potential, AI-use potential, mapping potential, transfer potential, confidentiality, attribution, benefits, risks, withdrawal rights, correction rights, contact point, and limits. Consent shall be specific, informed, voluntary, and recorded where required. Consent to participate shall not automatically imply consent to publish, map, transfer, use AI, disclose to sponsors or providers, or use in unrelated programs.

388.9 Non-Consent Respect. GCRI Canada shall respect non-consent. Non-consent may apply to participation, recording, attribution, publication, data use, AI use, mapping, transfer, public authority disclosure, sponsor disclosure, provider disclosure, capital-reader disclosure, or future use. Non-consent shall not result in retaliation, exclusion from unrelated public-benefit opportunities, loss of respect, reputational harm, reduced community support, or pressure to reconsider. Non-consent shall be recorded where necessary to prevent accidental use.

388.10 Withdrawal Pathways. GCRI Canada shall provide withdrawal pathways where withdrawal is available under law, agreement, protocol, consent terms, ethical practice, safeguards review, or program design. Withdrawal may require cessation of use, removal from future materials, data deletion, attribution removal, map revision, dashboard revision, public-safe correction, controlled notice, archive note, or limitation of future use. Where withdrawal cannot fully remove already public, aggregated, or relied-upon materials, GCRI Canada shall explain limits and consider correction, suppression, or restriction where appropriate.

388.11 Correction Pathways. Community participants and affected communities shall have pathways to request correction of inaccurate, harmful, outdated, misattributed, overbroad, unsafe, or misleading community-related statements, data, maps, dashboards, public-safe summaries, controlled summaries, reports, training materials, Academy materials, donor reports, sponsor reports, provider references, public authority references, or Nexus-compatible outputs. Correction pathways shall be accessible and shall include intake, review, response, action, and closeout. Corrections may include revision, redaction, aggregation, non-attribution, public-safe clarification, controlled notice, withdrawal, or archive note.

388.12 Grievance Pathways. GCRI Canada shall maintain grievance pathways for community participants and affected communities to raise concerns regarding participation, access, consent, non-consent, data use, AI use, mapping, publication, protected knowledge, public authority references, sponsor or provider conduct, discrimination, harassment, retaliation, accessibility, public-safe risks, or harm. Grievance pathways shall be accessible, respectful, non-retaliatory, proportionate, and capable of escalation. Grievances shall be recorded and handled with confidentiality where appropriate.

388.13 Remedy Pathways. Where community participation causes or risks harm, GCRI Canada shall consider remedy pathways proportionate to the harm, its role, authority, and available measures. Remedies may include apology, correction, withdrawal, redaction, access restriction, data deletion, public-safe clarification, controlled notice, process change, safeguards change, training, participant support, referral, escalation, termination of a program, suspension of publication, or other appropriate action. Remedy shall not be limited to reputational management; it shall address the underlying harm where possible.

388.14 Non-Retaliation. GCRI Canada shall not retaliate against any community participant, affected person, community representative, Indigenous participant, local knowledge holder, protected knowledge custodian, fellow, staff member, contractor, volunteer, advisor, public authority participant, provider, sponsor, host, donor, or other person for good-faith refusal, non-consent, withdrawal, correction request, grievance, safeguards concern, protected knowledge concern, public-safe concern, data concern, AI concern, cyber concern, or stop-the-line action. Retaliation includes exclusion, threat, harassment, loss of access, reputational harm, contract retaliation, funding retaliation, career retaliation, public authority pressure, or sponsor / provider pressure.

388.15 Public-Safe Feedback Loops. GCRI Canada shall maintain feedback loops for community-related outputs where feasible and appropriate. Feedback loops may allow affected communities to review public-safe summaries, maps, dashboards, language, attribution, safeguards, publication posture, corrections, and withdrawal requests. Feedback loops shall be designed to avoid endless burden, coercion, tokenism, or sponsor-driven consultation theatre. Feedback may be accepted, rejected, deferred, or incorporated with reasons where appropriate and recorded where material.

388.16 Community Participation Records. GCRI Canada shall maintain community participation records, including participation purpose records, no-coercion records, accessibility records, inclusive participation records, language and communication accessibility records, remote community participation support records, vulnerable community participation support records, consent pathway records, non-consent records, withdrawal pathway records, correction pathway records, grievance records, remedy records, non-retaliation records, public-safe feedback loop records, corrections, withdrawals, closeouts, and archives.


Section 389. Vulnerable Communities, Remote Communities, Territorial Knowledge, Cultural Sites, Environmental Knowledge, and Do-No-Harm Controls

389.1 Vulnerable Community Safeguards. GCRI Canada shall apply vulnerable community safeguards where activities involve communities or groups exposed to heightened risk due to poverty, marginalization, disability, age, health status, displacement, climate exposure, disaster exposure, infrastructure exposure, geographic isolation, digital exclusion, language barriers, legal vulnerability, social vulnerability, public authority sensitivity, retaliation risk, or historical harm. Safeguards shall address consent, non-consent, accessibility, confidentiality, data minimization, public-safe publication, mapping risk, AI-use risk, sponsor or provider influence, public authority pressure, grievance, remedy, and correction.

389.2 Remote Community Safeguards. Remote community safeguards shall address travel burden, connectivity limits, language access, timing, local coordination, cultural protocols, public authority relationships, infrastructure sensitivity, health access, food and water security, emergency access, cyber access, environmental knowledge, protected knowledge, mapping risk, and public-safe publication. GCRI Canada shall not require remote communities to conform to urban institutional participation models where doing so creates exclusion, burden, unsafe disclosure, or extraction. Remote community context shall be treated as material to program design.

389.3 Territorial Knowledge Safeguards. Territorial knowledge, including knowledge of land, waters, routes, seasonal patterns, hazard zones, culturally significant areas, resource locations, infrastructure dependencies, environmental indicators, community boundaries, and place-based risk, shall be protected according to authority, protocol, sensitivity, and public-safe risk. Territorial knowledge shall not be made public, mapped precisely, transferred externally, processed through AI, or used in sponsor, provider, capital-reader, or public authority materials unless safeguards permit. Territorial knowledge may require masking, aggregation, suppression, non-attribution, or controlled access.

389.4 Cultural Site Safeguards. Cultural site safeguards shall protect sacred sites, ceremonial sites, burial sites, archaeological areas, heritage sites, gathering places, language sites, traditional-use sites, cultural landscapes, and other culturally sensitive places from public exposure, exploitation, vandalism, surveillance, commercialization, or unsafe public authority action. GCRI Canada shall assess whether cultural site information should be excluded, generalized, masked, restricted, or handled through controlled annexes. Cultural site information shall not be published merely because it is technically available.

389.5 Environmental Knowledge Safeguards. Environmental knowledge safeguards shall protect sensitive ecological, species, habitat, water, climate, hazard, resource, land-use, and environmental vulnerability information where disclosure could create harm to communities, ecosystems, species, cultural sites, infrastructure, or public safety. Environmental knowledge shall be reviewed for re-identification risk, extraction risk, commercial exploitation, resource exploitation, poaching, vandalism, stigmatization, public authority misuse, and sponsor or provider misuse. Public-safe publication shall be conservative where harm risk is material.

389.6 Disaster-Prone Community Safeguards. Disaster-prone communities shall be protected from outputs that expose vulnerabilities, stigmatize risk, create insurance or finance harm, create public authority misunderstanding, reveal evacuation constraints, expose infrastructure weaknesses, disclose shelter locations unsafely, or generate public panic. Disaster-related maps, dashboards, scenarios, simulations, public-safe summaries, and evidence outputs shall include uncertainty, limitation language, non-warning language, and public authority boundary language where material. GCRI Canada shall not convert learning outputs into emergency instructions.

389.7 Climate-Exposed Community Safeguards. Climate-exposed communities shall be protected from public claims, maps, dashboards, or datasets that overstate vulnerability, understate uncertainty, expose land or resource sensitivity, affect property or insurance perception, trigger stigma, support speculative extraction, or misrepresent community agency. Climate-related outputs shall be evidence-based, limitation-bearing, public-safe, and corrected where assumptions change. Community context, adaptation knowledge, and protected knowledge shall be handled with safeguards.

389.8 Public Health Vulnerability Safeguards. Public health vulnerability safeguards shall apply where activities involve health-sensitive data, disease exposure, environmental health, food and water insecurity, health system access, disability, elder populations, youth, remote health services, public health orders, or health-risk communication. GCRI Canada shall avoid identifying vulnerable individuals or small communities in public outputs unless authorized and safe. Health-related outputs shall not be public health warnings, clinical advice, public health orders, or official health determinations.

389.9 Infrastructure-Exposed Community Safeguards. Infrastructure-exposed communities, including communities near critical infrastructure, utilities, ports, telecom corridors, energy infrastructure, water infrastructure, transportation corridors, industrial facilities, data centres, AI-RAN / O-RAN deployments, sensors, DePIN infrastructure, or cyber-physical systems, shall be protected from outputs that expose vulnerabilities, create safety risk, reveal security-sensitive locations, generate stigma, affect property or insurance perception, or facilitate misuse. Public-safe mapping and dashboarding shall apply aggregation, masking, delay, restriction, or non-public handling where needed.

389.10 Data and Mapping Harm Review. GCRI Canada shall conduct data and mapping harm review where community-related data, Indigenous data, local knowledge, territorial knowledge, cultural sites, environmental knowledge, public health data, public safety data, infrastructure data, or protected knowledge may be collected, stored, mapped, dashboarded, published, transferred, or used in AI systems. Review shall assess re-identification, geospatial exposure, stigmatization, retaliation, exploitation, public authority misuse, sponsor misuse, provider misuse, capital-reader misuse, insurance harm, procurement harm, community harm, ecological harm, and correction path.

389.11 AI and Model Harm Review. GCRI Canada shall conduct AI and model harm review where AI systems, machine learning, embeddings, retrieval systems, simulations, digital twins, dashboards, maps, risk models, scenario models, benchmark models, or automated analysis may affect vulnerable communities, remote communities, Indigenous communities, protected knowledge, public health vulnerability, infrastructure exposure, or public authority perception. Review shall assess bias, hallucination, fabricated citations, representational harm, data leakage, unauthorized model training, overgeneralization, false precision, unsafe inference, protected knowledge exposure, and correctionability.

389.12 Publication Harm Review. GCRI Canada shall conduct publication harm review before releasing community-related materials, maps, dashboards, datasets, reports, public-safe summaries, donor reports, sponsor reports, public authority-facing materials, provider-facing materials, Academy materials, or media materials. Review shall assess whether publication could create harm, stigma, misinterpretation, public authority confusion, public warning implication, emergency command implication, finance or insurance harm, procurement harm, protected knowledge exposure, cultural harm, environmental harm, or community distrust. Publication may be restricted, delayed, redacted, generalized, or withdrawn.

389.13 Sponsor and Provider Harm Review. GCRI Canada shall review sponsor and provider involvement for harm risk where community participation, protected knowledge, public-safe mapping, data access, labs, challenges, benchmarking, dashboards, or technical baselines involve communities. Sponsor or provider involvement shall not create extraction, marketing exploitation, provider preference, public authority access purchase, public legitimacy purchase, protected knowledge access, community pressure, or procurement advantage. Sponsor and provider access may be restricted, anonymized, excluded, or subject to controlled-room rules.

389.14 Do-No-Harm Controls. GCRI Canada shall apply do-no-harm controls proportionate to the activity, community, data, knowledge, public authority context, sponsor context, provider context, and publication risk. Controls may include non-collection, minimization, aggregation, masking, redaction, delayed release, controlled access, consent requirements, non-consent respect, community review, protected knowledge exclusion, AI-use prohibition, public authority boundary language, non-warning language, non-endorsement language, publication restriction, access revocation, program redesign, stop-work, or withdrawal. Do-no-harm shall prevail over speed, visibility, sponsor pressure, provider pressure, publication timelines, or technical interest.

389.15 Corrective Action for Harm Risk. Where harm risk is identified, GCRI Canada shall take corrective action proportionate to the risk. Corrective action may include pausing work, stopping work, changing methods, changing data use, removing data, restricting access, revising maps, revising dashboards, revising publication language, notifying affected parties, seeking additional review, obtaining consent, respecting non-consent, withdrawing materials, issuing correction, providing remedy, escalating to safeguards function, escalating to officers, escalating to the Board, or terminating the activity. Corrective action shall be recorded.

389.16 Safeguards Records. GCRI Canada shall maintain safeguards records, including vulnerable community safeguard records, remote community safeguard records, territorial knowledge safeguard records, cultural site safeguard records, environmental knowledge safeguard records, disaster-prone community safeguard records, climate-exposed community safeguard records, public health vulnerability safeguard records, infrastructure-exposed community safeguard records, data and mapping harm review records, AI and model harm review records, publication harm review records, sponsor and provider harm review records, do-no-harm control records, corrective action records, stop-work records where applicable, correction records, withdrawal records, closeouts, and archives.


Section 390. Protected Participation, Whistleblowing, Dissent Protection, Anti-Retaliation, Confidential Reporting, and Safeguards Escalation

390.1 Protected Participation Purpose. GCRI Canada shall protect good-faith participation, concern reporting, dissent, whistleblowing, stop-the-line use, safeguards escalation, correction requests, grievance use, non-consent, withdrawal, and refusal to support unsafe, unlawful, misleading, overclaiming, extractive, retaliatory, discriminatory, or boundary-violating conduct. Protected participation supports public-benefit purpose, research integrity, evidence integrity, methods integrity, data / AI / cyber integrity, public authority boundary discipline, finance-boundary discipline, procurement neutrality, certification-boundary discipline, sponsor non-control, provider neutrality, community safeguards, protected knowledge, public-safe publication, and correctionability.

390.2 Whistleblowing Protection. GCRI Canada shall not retaliate against any person who in good faith reports fraud, corruption, financial misconduct, data misuse, AI misuse, cyber risk, privacy breach, research misconduct, fabricated citations, evidence manipulation, public authority overclaim, public warning overclaim, emergency command overclaim, finance-readiness overclaim, procurement overclaim, certification overclaim, recognition overclaim, sponsor control, provider preference, protected knowledge misuse, community harm, harassment, discrimination, conflicts, or other misconduct. Whistleblowing protection applies whether the report is later substantiated or not, provided it was made in good faith.

390.3 Dissent Protection. GCRI Canada shall protect good-faith dissent in Board, committee, council, working-party, peer-review, model-review, research, publication, safeguards, public authority, technical, Academy, program, and controlled-room contexts. Dissent may concern evidence sufficiency, method validity, public-safe release, AI output reliability, cyber risk, protected knowledge, community harm, public authority misdescription, finance-boundary risk, certification implication, procurement implication, provider neutrality, sponsor influence, or correction. Dissent shall not be suppressed to protect donor, sponsor, provider, public authority, institutional, media, or timeline interests.

390.4 Good-Faith Concern Reporting. Any director, officer, employee, contractor, fellow, advisor, committee participant, council participant, reviewer, researcher, developer, maintainer, technical contributor, public authority participant, provider, sponsor, host, donor, funder, partner, community participant, protected knowledge custodian, Academy participant, or other person may make a good-faith concern report. Reports may concern actual or potential misconduct, boundary drift, public-safe risk, community harm, data issue, AI issue, cyber issue, research issue, public authority issue, finance issue, procurement issue, certification issue, recognition issue, sponsor issue, provider issue, or correction issue. Reports shall be taken seriously and triaged.

390.5 Confidential Reporting Channels. GCRI Canada may maintain confidential reporting channels for protected participation and safeguards concerns. Confidential reporting channels may include designated officers, Board contacts, committee contacts, safeguards contacts, legal contacts, secure forms, email channels, or third-party channels where adopted. Confidentiality shall be protected to the extent lawful and practical, subject to investigation, legal duties, safety, public authority obligations, data / AI / cyber response, protected knowledge obligations, and Board oversight where required.

390.6 Anonymous Reporting Where Appropriate and Lawful. GCRI Canada may permit anonymous reporting where appropriate and lawful. Anonymous reports shall be triaged based on content, evidence, risk, urgency, and credibility, without dismissing the report solely because the reporter is anonymous. Anonymous reporting may be limited where identity is necessary for investigation, remedy, consent, non-consent, withdrawal, protected knowledge handling, or legal process. GCRI Canada shall not seek to identify anonymous reporters without legitimate need and authority.

390.7 Anti-Retaliation Rule. Retaliation is prohibited. Retaliation includes dismissal, demotion, exclusion, loss of access, threat, harassment, intimidation, contract retaliation, funding retaliation, career retaliation, reputational harm, denial of credit, denial of authorship, denial of participation, public authority pressure, sponsor pressure, provider pressure, adverse assignment, withdrawal of benefits, adverse reference, blacklisting, or other adverse treatment because a person engaged in protected participation. Retaliation may result in corrective action, access revocation, termination of participation, contract termination, Board review, or other remedy.

390.8 Protection Against Exclusion, Threat, Harassment, Loss of Access, Reputation Harm, Contract Retaliation, Funding Retaliation, or Career Retaliation. GCRI Canada shall specifically protect persons from exclusion, threat, harassment, loss of access, reputation harm, contract retaliation, funding retaliation, career retaliation, academic retaliation, community retaliation, sponsor retaliation, provider retaliation, public authority pressure, or program retaliation arising from good-faith reporting, dissent, non-consent, withdrawal, correction request, grievance, stop-the-line action, safeguards concern, or refusal to participate in unsafe conduct. Protective measures may include confidentiality, role adjustment, access safeguards, communication limits, non-contact instructions, interim measures, escalation, or record controls.

390.9 Reporting of Data, AI, Cyber, Research Integrity, Public Authority, Finance, Procurement, Certification, Sponsor, Provider, Safeguards, or Public-Safe Claims Concerns. Protected reporting includes concerns about data leakage, unauthorized AI use, model training misuse, hallucinations, fabricated citations, prompt injection, cybersecurity vulnerabilities, repository exposure, personal information misuse, public authority data misuse, protected knowledge exposure, research manipulation, evidence manipulation, public authority misdescription, public warning overclaim, finance-readiness overclaim, securities or insurance boundary risk, procurement steering, certification implication, recognition implication, sponsor control, provider preference, community harm, public-safe publication risk, dashboard risk, map risk, and misuse of GCRI Canada name or Nexus-compatible claims.

390.10 Intake and Triage. Reports shall be intaken and triaged according to severity, urgency, subject matter, affected persons, affected data, public authority involvement, protected knowledge involvement, public-safe risk, legal risk, financial risk, cyber risk, AI risk, research integrity risk, sponsor or provider risk, community harm risk, and required escalation. Triage may result in immediate containment, stop-work, investigation, referral, correction, legal review, Board review, safeguards review, data / AI / cyber incident response, public authority correction, or closeout.

390.11 Interim Protective Measures. GCRI Canada may implement interim protective measures while reviewing a report. Measures may include pausing publication, restricting access, preserving records, suspending data use, pausing AI processing, removing public authority references, restricting sponsor or provider access, suspending dashboard or map release, issuing hold notices, separating persons, protecting reporters, limiting communications, preserving confidentiality, or escalating to legal counsel. Interim measures shall not presume wrongdoing but shall protect people, records, data, public-safe status, and institutional integrity.

390.12 Investigation and Review. Investigations and reviews shall be fair, proportionate, timely, record-supported, confidential where appropriate, conflict-controlled, and independent where needed. Review may be conducted by officers, Board members, committees, safeguards functions, legal counsel, external experts, data / AI / cyber reviewers, research integrity reviewers, public authority boundary reviewers, or other competent persons. Conflicted persons shall not control the review. Investigations shall respect privacy, protected knowledge, legal privilege, public authority terms, and non-retaliation.

390.13 Corrective Action. Corrective action may include correction, withdrawal, public-safe clarification, controlled notice, revised methods, revised evidence records, data deletion, AI-use restriction, cybersecurity remediation, access revocation, training, policy change, contract change, sponsor benefit restriction, provider restriction, public authority reference correction, publication revision, remedy to affected persons, discipline, termination of participation, Board escalation, legal action, or reporting where required. Corrective action shall address root causes where feasible and shall be recorded.

390.14 Reporting Back Where Appropriate. GCRI Canada may report back to the reporter or affected persons where appropriate, lawful, safe, and consistent with confidentiality, privacy, protected knowledge, legal privilege, public authority terms, and investigation integrity. Reporting back may include acknowledgment, status, outcome category, corrective action taken, or explanation of limitations. GCRI Canada shall not disclose confidential personal, legal, public authority, protected knowledge, cyber-sensitive, or investigation-sensitive details where inappropriate.

390.15 Abuse of Reporting Process. Knowingly false, malicious, harassing, retaliatory, discriminatory, bad-faith, or intentionally misleading reports may be addressed through corrective action. A report shall not be treated as abusive merely because it is mistaken, incomplete, difficult, inconvenient, embarrassing, critical, or not substantiated. Abuse-of-process findings shall require careful review to avoid chilling good-faith reporting, dissent, community grievance, protected knowledge concern, or stop-the-line action.

390.16 Protected Participation Records. GCRI Canada shall maintain protected participation records, including protected participation purpose records, whistleblowing protection records, dissent protection records, good-faith concern reports, confidential reporting channel records, anonymous reporting records where applicable, anti-retaliation records, protection-against-exclusion / threat / harassment / loss-of-access / reputation-harm / contract-retaliation / funding-retaliation / career-retaliation records, subject-matter concern records, intake and triage records, interim protective measure records, investigation and review records, corrective action records, reporting-back records, abuse-of-process records, confidentiality records, closeouts, and archives.


Section 391. Stop-Work and Stop-the-Line Powers for Public Safety, Public Authority Confusion, Community Harm, Protected Knowledge, or Safeguards Breach

391.1 Stop-Work Purpose. GCRI Canada shall maintain stop-work authority to pause, restrict, suspend, or halt work where continuing may create material risk to public safety, public authority clarity, community safety, Indigenous rights, local or territorial knowledge, cultural sites, environmental knowledge, protected knowledge, data protection, AI safety, cybersecurity, privacy, public-safe publication, finance-boundary discipline, procurement neutrality, certification-boundary discipline, recognition-boundary discipline, public warning boundaries, emergency command boundaries, sponsor non-control, provider neutrality, or institutional integrity. Stop-work authority shall prioritize prevention of harm and correction over speed, visibility, funding, sponsor pressure, provider pressure, publication timelines, or program momentum.

391.2 Stop-the-Line Purpose. GCRI Canada shall maintain stop-the-line powers allowing designated persons, and in urgent good-faith circumstances any participant with sufficient concern, to raise an immediate hold or escalation where work appears unsafe, unlawful, misleading, overclaiming, extractive, retaliatory, improperly controlled, improperly public, improperly AI-processed, improperly mapped, improperly public authority-referenced, improperly finance-referenced, improperly certification-referenced, improperly procurement-referenced, or otherwise inconsistent with this Bylaw. Stop-the-line powers shall support correctionability and shall not be treated as disloyalty.

391.3 Public Safety Trigger. Stop-work or stop-the-line may be triggered by risk that a GCRI Canada activity, output, dashboard, map, simulation, scenario, public-safe summary, Observatory-related material, Truth Engine-related material, dataset, software release, technical baseline, public authority learning material, media statement, or public communication could be interpreted as public warning, emergency command, safety instruction, public health order, evacuation instruction, responder command, infrastructure operation direction, cyber response directive, or official safety determination. It may also be triggered by risk of physical harm, cyber-physical harm, public panic, unsafe disclosure, or misdirected reliance.

391.4 Public Authority Confusion Trigger. Stop-work or stop-the-line may be triggered by risk of public authority confusion, including implication of endorsement, adoption, public authority delegation, public-private partnership, public warning, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, sovereign obligation, public policy adoption, public infrastructure adoption, public authority mandate, or official capacity beyond record. Public authority confusion may arise from logos, titles, quotes, attendance references, public authority data references, dashboards, maps, donor materials, sponsor materials, provider materials, public decks, media statements, or public-safe summaries.

391.5 Community Harm Trigger. Stop-work or stop-the-line may be triggered by risk of harm to a community, vulnerable community, remote community, Indigenous community, local community, protected participant, public health-vulnerable group, climate-exposed community, disaster-prone community, infrastructure-exposed community, or other affected group. Harm may include stigmatization, retaliation, exposure of vulnerabilities, unsafe mapping, public authority misuse, sponsor misuse, provider misuse, AI inference harm, finance or insurance harm, reputational harm, loss of trust, cultural harm, environmental harm, or extraction.

391.6 Indigenous, Local, Territorial, Cultural, Environmental, or Protected Knowledge Trigger. Stop-work or stop-the-line may be triggered where Indigenous knowledge, Indigenous data, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sacred site information, protected knowledge, community-protected data, or custodial knowledge is at risk of unauthorized collection, disclosure, publication, mapping, AI use, transfer, sponsor access, provider access, public authority-facing use, capital-reader use, misattribution, decontextualization, extraction, or loss of correction rights. Such trigger shall receive heightened safeguards review.

391.7 Safeguards Breach Trigger. Stop-work or stop-the-line may be triggered by breach or suspected breach of community protocols, Indigenous governance protocols, consent requirements, non-consent restrictions, withdrawal commitments, attribution limits, confidentiality commitments, protected knowledge restrictions, public-safe mapping rules, accessibility commitments, grievance processes, non-retaliation protections, or remedy commitments. Safeguards breach may require immediate containment, access restriction, publication hold, data hold, AI-use hold, mapping hold, or public authority reference hold.

391.8 Data, AI, Cyber, Privacy, or Security Trigger. Stop-work or stop-the-line may be triggered by data leakage, unauthorized access, unauthorized AI upload, model-training misuse, unapproved embeddings, prompt injection, hallucinated citation, fabricated source, cyber vulnerability, repository exposure, secrets exposure, personal information exposure, public authority data misuse, protected knowledge exposure, infrastructure-sensitive exposure, cloud misconfiguration, shadow IT, unapproved storage, unapproved transfer, or security incident. Such trigger may require incident response, system containment, access revocation, forensic preservation, public-safe correction, or legal review.

391.9 Public-Safe Publication Trigger. Stop-work or stop-the-line may be triggered where publication, release, disclosure, dashboard launch, map launch, dataset release, software release, public report, whitepaper, article, social media post, speech, public deck, donor report, sponsor report, provider-facing material, capital-reader material, or public authority-facing material lacks required review, includes unsupported claims, discloses protected information, overstates confidence, omits limitations, uses public authority references improperly, implies finance-readiness, implies certification, implies procurement approval, implies public warning, or creates public-safe risk. Publication shall be paused until review is complete.

391.10 Finance, Procurement, Certification, Recognition, or Public Warning Overclaim Trigger. Stop-work or stop-the-line may be triggered by any claim, implication, output, dashboard, map, publication, donor report, sponsor report, provider material, public authority material, capital-reader material, challenge result, benchmark output, Academy record, competence record, technical baseline, evidence pack, or proof pack that suggests GCRI Canada has issued finance-readiness, insurance-readiness, bankability, investability, public finance approval, procurement approval, provider selection, certification, accreditation, compliance approval, recognition, standing, maturity, public warning, emergency command, public authority decision, or official adoption. Such overclaim shall be corrected before further use.

391.11 Authority to Stop Work. The Board, Chair, authorized officer, safeguards function, data / AI / cyber lead, publication approver, program owner, legal counsel, committee chair, controlled-room custodian, repository custodian, or other designated person may stop work within their authority. In urgent good-faith circumstances, any director, officer, employee, contractor, fellow, advisor, reviewer, maintainer, public authority participant, community participant, protected knowledge custodian, or other participant may raise a stop-the-line concern for immediate review. Raising the concern shall not itself require proof; the purpose is to pause and assess.

391.12 Immediate Containment. Upon stop-work or stop-the-line trigger, GCRI Canada may immediately contain risk by pausing publication, disabling access, restricting downloads, removing materials, pausing AI processing, preserving records, suspending dashboard access, suspending map access, pausing data transfer, freezing repository release, suspending sponsor or provider access, notifying custodians, notifying public authorities where appropriate, securing systems, preserving logs, or issuing internal hold instructions. Containment shall be proportionate and shall not destroy records needed for review.

391.13 Escalation to Officer, Committee, Chair, Board, Counsel, or Safeguards Function. Stop-work and stop-the-line matters shall be escalated according to severity and subject matter. Escalation may go to an officer, program owner, committee, Board Chair, full Board, legal counsel, safeguards function, data / AI / cyber function, research integrity reviewer, public authority boundary reviewer, finance-boundary reviewer, publication approver, or external expert. High-risk matters involving public safety, public authority delegation, protected knowledge, public warning, emergency command, cyber breach, finance overclaim, certification overclaim, procurement overclaim, or serious retaliation shall receive heightened review.

391.14 Restart Conditions. Work may restart only when the relevant authority determines that the trigger has been resolved, mitigated, re-scoped, corrected, or accepted within approved risk limits. Restart conditions may include revised language, public-safe review, data deletion, access restriction, AI-use prohibition, cyber remediation, safeguards approval, community review, public authority clarification, sponsor or provider correction, legal review, Board approval, revised method, revised evidence record, publication hold release, or controlled notice. Restart shall be documented and may be partial, conditional, or time-limited.

391.15 No Retaliation for Good-Faith Stop-the-Line Use. No person shall be retaliated against for good-faith stop-the-line use, stop-work request, publication hold request, safeguards escalation, data concern, AI concern, cyber concern, privacy concern, public authority concern, finance-boundary concern, procurement-boundary concern, certification-boundary concern, recognition concern, sponsor control concern, provider preference concern, protected knowledge concern, community harm concern, or public-safe concern. Retaliation shall be treated as a serious violation and may itself trigger investigation, corrective action, access revocation, or termination.

391.16 Stop-Work and Stop-the-Line Records. GCRI Canada shall maintain stop-work and stop-the-line records, including stop-work purpose records, stop-the-line purpose records, public safety trigger records, public authority confusion trigger records, community harm trigger records, Indigenous / local / territorial / cultural / environmental / protected knowledge trigger records, safeguards breach trigger records, data / AI / cyber / privacy / security trigger records, public-safe publication trigger records, finance / procurement / certification / recognition / public warning overclaim trigger records, authority-to-stop-work records, immediate containment records, escalation records, restart condition records, no-retaliation records, corrective action records, closure records, and archives.


Section 392. Public Authority, Community, Safeguards, Protected Knowledge, and Correction Records

392.1 Public Authority Records. GCRI Canada shall maintain public authority records sufficient to evidence lawful engagement, capacity classification, public authority boundary compliance, non-delegation, no-public-warning, no-emergency-command, no-regulatory-approval, no-procurement-approval, no-funding-approval, no-public-finance-approval, no-sovereign-obligation, no-public-private-partnership, public authority data handling, public authority reference control, public-safe publication, correction, withdrawal, clarification, and closeout. Public authority records shall support accountability, auditability, correctionability, and public trust without creating public authority status or public authority delegation.

392.2 Capacity Classification Records. Capacity classification records shall identify public authority participants, roles, titles, public bodies, authority scope, official-capacity status, observer status, regulator-listening status, public finance reader status, emergency-management participant status, public infrastructure operator status, data provider status, reviewer status, speaker status, technical expert status, personal-capacity status, non-attributable status, controlled-room status, host authority status, and simulation participant status. Capacity classification records shall be updated when authority changes, public references are proposed, data is contributed, or public materials are corrected.

392.3 Official Capacity Records. Official capacity records shall include written authority evidence where required, reliable authority evidence where used, authority scope, public body identification, participant role, delegated authority limits, attribution permissions, quote permissions, logo and name permissions, photograph and recording permissions, data contribution permissions, publication review requirements, approved public language, non-endorsement language, no-implied-expansion records, corrections, withdrawals, and supersessions. Official capacity records shall be interpreted conservatively.

392.4 Reference Approval Records. Reference approval records shall document approval for public authority names, logos, titles, agency names, jurisdiction references, photographs, recordings, attendance references, quotes, data contribution references, public authority facility references, public authority host references, public authority learning references, public authority participant references, public authority-sensitive statements, and public authority-facing materials. Reference approval records shall identify approved language, attribution permission, non-endorsement statement, public authority review where required, public-safe review, expiration, withdrawal, and correction.

392.5 Data Contribution Records. Data contribution records shall document public authority data contributions, Indigenous data contributions, community data contributions, protected knowledge contributions, infrastructure data contributions, health-sensitive data contributions, cyber-sensitive data contributions, public safety-sensitive data, public works-sensitive data, utility data, port data, telecom data, energy data, water data, food-system data, and other sensitive data contributions. Records shall identify authority, lawful basis, contributor identity, capacity, permitted use, prohibited use, AI-use restrictions, publication restrictions, transfer restrictions, retention, deletion, classification, review rights, confidentiality, cybersecurity, public-safe release review, and correction path.

392.6 Room Participation Records. Room participation records shall document controlled-room, data-room, no-download-room, public authority room, public finance reader room, regulator-listening room, emergency-management learning room, infrastructure operator room, safeguards room, protected knowledge room, community review room, cyber-sensitive room, infrastructure-sensitive room, finance-sensitive room, and publication review room participation. Records shall identify attendees, capacity, access class, materials, confidentiality, AI-use restrictions, download restrictions, attribution restrictions, public statement limits, logs where appropriate, access revocation, closeout, and correction.

392.7 Non-Endorsement Records. Non-endorsement records shall document language, approvals, disclaimers, public authority boundary statements, sponsor and provider non-control statements, no-adoption statements, no-public-warning statements, no-emergency-command statements, no-regulatory-approval statements, no-procurement-approval statements, no-funding-approval statements, no-public-finance-approval statements, no-sovereign-obligation statements, no-PPP statements, no-certification statements, no-recognition statements, no-finance-readiness statements, no-provider-preference statements, and corrections where non-endorsement language was missing, insufficient, or misunderstood.

392.8 Community Participation Records. Community participation records shall document participation purpose, participants where appropriate and safe, community capacity, accessibility measures, language access, remote participation support, vulnerable community support, consent pathways, non-consent, withdrawal, correction, grievance, remedy, non-retaliation, public-safe feedback loops, community protocols, meeting notes where appropriate, attribution permissions, non-attribution permissions, public-safe review, and closeout. Community participation records shall be classified where identity, protected knowledge, vulnerability, public authority sensitivity, or retaliation risk exists.

392.9 Indigenous, Local, Territorial, Cultural, Environmental, and Protected Knowledge Records. GCRI Canada shall maintain records concerning Indigenous rights respect, Indigenous data safeguards, Indigenous knowledge safeguards, Indigenous governance protocols, local knowledge safeguards, territorial knowledge safeguards, cultural knowledge safeguards, environmental knowledge safeguards, protected knowledge treatment, cultural site protection, environmental knowledge protection, public-safe mapping, FPIC where applicable, consent, non-consent, attribution, withdrawal, correction, restriction, safeguards review, access class, public-safe release decisions, controlled-access decisions, and archive treatment. Such records shall themselves be protected where their disclosure could reveal sensitive knowledge.

392.10 Consent, Non-Consent, Withdrawal, Restriction, and Correction Records. Consent, non-consent, withdrawal, restriction, and correction records shall document who gave, refused, limited, conditioned, withdrew, restricted, or corrected permission; the scope of the decision; the materials affected; the use affected; the data affected; the AI-use affected; the mapping affected; the publication affected; the transfer affected; the attribution affected; the public authority reference affected; the effective date; the limitations; and the action taken. These records shall guide future use and prevent accidental reuse or overbroad interpretation.

392.11 Grievance and Remedy Records. Grievance and remedy records shall document grievances, concerns, complaints, community concerns, protected knowledge concerns, accessibility concerns, retaliation concerns, public-safe concerns, data concerns, AI concerns, cyber concerns, public authority concerns, sponsor or provider concerns, intake, triage, review, confidentiality, interim measures, decisions, remedies, corrective actions, communication, follow-up, and closeout. Records shall be protected from retaliation, unnecessary disclosure, and misuse.

392.12 Whistleblowing and Protected Participation Records. Whistleblowing and protected participation records shall document protected reports, dissent, good-faith concern reporting, confidential reporting, anonymous reporting where applicable, anti-retaliation measures, interim protective measures, investigation, review, corrective action, reporting back where appropriate, abuse-of-process review, and closure. Such records shall be access-limited, confidential where appropriate, and retained according to law, policy, institutional memory, and correctionability.

392.13 Stop-Work and Stop-the-Line Records. Stop-work and stop-the-line records shall document triggers, reporters, affected materials, affected programs, public safety concerns, public authority confusion concerns, community harm concerns, protected knowledge concerns, safeguards breach concerns, data / AI / cyber / privacy / security concerns, public-safe publication concerns, finance / procurement / certification / recognition / public warning overclaim concerns, immediate containment, escalation, review, restart conditions, corrective action, no-retaliation measures, and closeout. These records shall support learning and prevention, not punishment for good-faith use.

392.14 Public-Safe Mapping Records. Public-safe mapping records shall document maps, geospatial data, dashboards, layers, coordinates, aggregation, masking, redaction, delay, suppression, public authority review, community review, protected knowledge review, cultural site review, environmental knowledge review, infrastructure sensitivity review, cyber review, public health review, public safety review, publication decisions, access class, limitation language, non-warning language, correction path, and withdrawal. Public-safe mapping records shall be protected where they reveal sensitive locations or decision logic.

392.15 Safeguards Review Records. Safeguards review records shall document reviews of Indigenous rights, Indigenous data, Indigenous knowledge, local knowledge, territorial knowledge, cultural sites, environmental knowledge, protected knowledge, vulnerable communities, remote communities, disaster-prone communities, climate-exposed communities, public health vulnerability, infrastructure exposure, AI and model harm, data and mapping harm, publication harm, sponsor and provider harm, accessibility, non-retaliation, consent, withdrawal, correction, and remedy. Review records shall identify decisions, conditions, restrictions, prohibited uses, required corrections, required public-safe controls, and closeout.

392.16 Correction, Clarification, Withdrawal, Retraction, and Closeout Records. GCRI Canada shall maintain correction, clarification, withdrawal, retraction, and closeout records for public authority matters, community matters, safeguards matters, protected knowledge matters, public-safe mapping matters, data contribution matters, publication matters, dashboard matters, map matters, donor reports, sponsor reports, provider references, public authority references, public-safe summaries, controlled summaries, AI-assisted outputs, technical baselines, evidence records, methods records, Academy materials, and Nexus-compatible outputs. Records shall identify trigger, authority, review, affected materials, affected parties, correction language, public-safe or controlled notice, downstream review, archive status, retention, secure disposal where applicable, and final closeout.

Last updated

Was this helpful?