For the complete documentation index, see llms.txt. This page is also available as Markdown.

ARTICLE XVI. RECORDS

Section 452. Validity-by-Record Purpose

452.1 Validity-by-Record Purpose.

452.1.1 Validity-by-Record shall mean that the legal, institutional, technical, public-facing, Nexus-facing, public authority-facing, finance-boundary-facing, research-facing, evidence-facing, software-facing, data-facing, AI-facing, cybersecurity-facing, safeguards-facing, and compliance meaning of any material act, claim, output, permission, authority, role, status, approval, restriction, access, release, correction, or interface of the Corporation exists only to the extent supported by an authoritative record.

452.1.2 Validity-by-Record shall be a governing doctrine of the Corporation and shall apply to all directors, officers, employees, contractors, fellows, advisors, volunteers, contributors, maintainers, reviewers, committee members, council members, working group participants, controlled-room participants, public authority participants, sponsors, donors, funders, providers, hosts, partners, and any other person or entity acting for, with, through, or in reference to the Corporation.

452.1.3 Validity-by-Record shall preserve the Corporation’s non-executing public-good technical role, legal separateness, public-good stack integrity, provider neutrality, sponsor non-control, public authority boundary discipline, finance-boundary discipline, certification and recognition boundary discipline, procurement neutrality, technical truth discipline, public-safe publication discipline, correctionability, and institutional memory.

452.1.4 No title, email, meeting, attendance, oral statement, informal approval, shared mission, draft document, AI output, dashboard, map, public authority presence, sponsor support, provider support, repository access, controlled-room participation, proof receipt, ledger entry, public mention, media statement, or Nexus-facing relationship shall create valid institutional meaning unless supported by an authoritative record.

452.2 Record-Based Governance.

452.2.1 Governance actions of the Corporation shall be valid only where supported by the applicable corporate record, including formation documents, Bylaws, Board resolutions, written consents, meeting minutes, committee records, officer appointments, delegation records, policy approvals, conflict records, member approvals where applicable, and other competent governance records.

452.2.2 Board action shall be interpreted according to the record of action, including date, quorum, notice, consent, approving body, vote or consent method, subject matter, scope, limitations, conditions, effective date, and any required follow-up.

452.2.3 Delegated governance authority shall be valid only to the extent reflected in a competent delegation record. Ambiguity shall be resolved against expanded authority and in favor of Board oversight, public-benefit purpose, non-execution, legal separateness, and boundary discipline.

452.2.4 Governance records shall control over informal understandings, institutional custom, meeting recollection, draft minutes, unapproved notes, public descriptions, slide decks, or verbal statements where inconsistency exists.

452.3 Record-Based Institutional Authority.

452.3.1 Institutional authority to bind, represent, approve, publish, access, release, restrict, correct, contract, spend, speak, delegate, appoint, terminate, refer, or escalate on behalf of the Corporation shall arise only from the Bylaws, Board action, officer authority, written delegation, contract, policy, role object, access object, or other authoritative record.

452.3.2 No person shall claim institutional authority by reason of position, seniority, technical expertise, founding role, public profile, donor relationship, sponsor relationship, provider relationship, public authority relationship, Nexus affiliation, repository access, room access, or repeated practice unless a competent record supports such authority.

452.3.3 Institutional authority records shall define scope, limits, term, approving authority, permitted actions, prohibited actions, reporting duties, escalation duties, revocation path, and correction path.

452.3.4 Apparent authority shall be actively prevented through controlled vocabulary, public-safe notices, access controls, role records, public authority capacity classifications, contract authority matrices, publication approvals, and correction procedures.

452.4 Record-Based Evidence.

452.4.1 Evidence used or issued by the Corporation shall be valid only to the extent supported by source records, evidence records, provenance records, method records, data quality records, reviewer records, conflict records, classification records, confidence records, uncertainty records, limitation records, access records, and correction records.

452.4.2 Evidence shall not be elevated into technical truth, public claim, public-safe summary, public authority learning material, Nexus interface output, GRF-facing input, GRA-facing input, Docket input, Grid input, dashboard, map, technical baseline, publication, or public-good software assertion unless the relevant evidence record supports that use.

452.4.3 Evidence shall remain bounded by its source, scope, method, time, geography, technology domain, data quality, uncertainty, limitation, classification, public-safe status, and correction history.

452.4.4 Evidence without source lineage, authority, classification, or review shall be treated as unverified or restricted unless and until corrected by competent record.

452.5 Record-Based Methods.

452.5.1 Methods used or referenced by the Corporation shall be valid only to the extent supported by method records identifying method name, owner, custodian, version, purpose, scope, assumptions, required inputs, outputs, limitations, validation or review status where applicable, known issues, access class, public-safe status, deprecation status, and correction path.

452.5.2 No method shall be represented as universally valid, legally sufficient, professionally certified, public authority-approved, finance-ready, procurement-ready, recognition-ready, Nexus-compatible, or operationally definitive unless a competent authority record expressly supports the exact statement.

452.5.3 Method records shall control over informal use, prior versions, draft protocols, unreviewed code, AI-generated procedure, dashboard logic, spreadsheet formulas, slide descriptions, or third-party summaries.

452.5.4 Method use shall be recorded where material to a public claim, technical baseline, evidence pack, public authority learning material, dashboard, map, model evaluation, proof receipt, compute workload, inference output, or Nexus interface output.

452.6 Record-Based Public Claims.

452.6.1 Public claims by or about the Corporation shall be valid only where supported by publication approval records, claims substantiation records, evidence records, method records, source lineage, confidence and limitation statements, public-safe review, conflict review where material, sponsor or provider disclosure where material, public authority reference approval where applicable, and correction path.

452.6.2 No public claim shall be based solely on informal opinion, internal enthusiasm, sponsor statement, provider statement, AI output, dashboard output, sensor signal, proof receipt, ledger entry, draft material, or unreviewed analysis.

452.6.3 Public claims shall use approved controlled vocabulary and shall not imply finance-readiness, recognition, certification, procurement approval, public authority adoption, public warning, emergency command, provider preference, legal compliance approval, professional advice, or rating unless a competent record expressly authorizes such claim.

452.6.4 Public claims shall remain subject to correction, supersession, withdrawal, retraction, limitation, redaction, or public-safe clarification where the underlying record changes or is found incomplete, inaccurate, misleading, overclaimed, or unsafe.

452.7 Record-Based Public Authority References.

452.7.1 Public authority references shall be valid only where supported by official capacity records, capacity classification records, public authority permission records, name-use approvals, logo-use approvals, quote approvals, attendance reference approvals, photograph or recording approvals, data contribution approvals, public records considerations, and approved public language where applicable.

452.7.2 Public authority participation shall not be represented as endorsement, adoption, funding approval, procurement approval, public finance approval, regulatory approval, official guidance, public warning, emergency command, sovereign obligation, public-private partnership, recognition, finance-readiness, certification, or provider preference unless competent public authority records expressly support the statement.

452.7.3 Observer status, regulator-listening status, public finance reader status, emergency-learning participation, public infrastructure operator participation, public authority data contribution, or public authority room attendance shall be described only according to the applicable record.

452.7.4 Any public authority reference made without record support shall be corrected, restricted, withdrawn, or clarified promptly.

452.8 Record-Based Nexus Interface Outputs.

452.8.1 Nexus interface outputs, including inputs to or outputs from GCRI Canada interfaces, The Global Risks Forum (GRF) interfaces, The Global Risks Alliance (GRA) interfaces, Nexus Standards interfaces, protocol authority interfaces, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, national companies, Project SPVs, public authorities, and enterprise stack actors, shall be valid only where supported by interface records.

452.8.2 Interface records shall identify the interface, party, purpose, authority, role, scope, access class, data class, public-safe status, owner, custodian, permitted use, prohibited use, boundary language, correction path, and effective status.

452.8.3 Nexus interface outputs shall not create merger, agency, partnership, joint venture, shared liability, public authority delegation, finance-readiness, recognition, certification, procurement approval, provider preference, public warning, emergency command, or enterprise execution by implication.

452.8.4 Routing, compatibility notes, divergence logs, equivalence notes, localization notes, interface maps, proof receipts, shared records, shared rooms, shared repositories, and shared publications shall be interpreted according to their records and not according to external assumptions.

452.9 Record-Based Technical Baselines.

452.9.1 Open technical baselines, reference architectures, schemas, APIs, SDKs, technical profiles, interoperability interfaces, model cards, dataset cards, system cards, benchmark cards, evaluation harnesses, test harnesses, proof receipt profiles, and related public-good technical materials shall be valid only where supported by technical asset records and baseline records.

452.9.2 Baseline records shall identify scope, custodian, owner, version, effective date, review cycle, public-safe status, limitation statement, interoperability function, evidence quality function, data governance function, AI governance function, cybersecurity function, observability function, correction path, deprecation path, and release status.

452.9.3 No technical baseline shall be represented as certification, procurement mandate, legal compliance approval, public authority adoption, provider preference, finance-readiness, recognition, rating, public warning, emergency command, or operational guarantee unless a competent authority record expressly provides that meaning.

452.9.4 Superseded, deprecated, withdrawn, archived, restricted, or draft technical baselines shall not be represented as current except according to their record status.

452.10 Record-Based Software Releases.

452.10.1 Public-good software releases, repository releases, dashboards, maps, code artifacts, APIs, SDKs, schemas, test harnesses, benchmark libraries, proof receipt tools, data tools, AI tools, and related technical assets shall be valid only where supported by release records.

452.10.2 Release records shall include repository, asset identity, owner, maintainer, version, release classification, approval record, changelog, release notes, known issues, known limitations, dependency status, vulnerability status, license status, SBOM status where appropriate, signing status where appropriate, provenance status, rollback path, correction path, security status, public-safe status, export-control status where applicable, and access class.

452.10.3 Repository publication or software availability shall not imply institutional approval beyond the release record, nor shall it imply certification, procurement approval, public authority adoption, finance-readiness, recognition, provider preference, public warning, emergency command, warranty, or fitness for operational use.

452.10.4 Unauthorized releases, insecure releases, mistaken releases, overclaimed releases, or releases affected by data / AI / cyber / privacy / protected knowledge issues shall be subject to hold, quarantine, rollback, takedown, correction, supersession, or withdrawal.

452.11 Record-Based Data Access.

452.11.1 Access to data shall be valid only where supported by lawful basis records, authority records, permission records, consent records where required, notice records where required, data classification records, data owner records, data custodian records, access records, purpose records, use limitation records, retention records, transfer records, AI-use restriction records, public-safe publication records, and correction records.

452.11.2 Data access shall be purpose-limited, least-privilege, classification-aware, time-limited where appropriate, monitored where appropriate, and revocable.

452.11.3 Data access shall not authorize AI training, fine-tuning, embeddings, model improvement, publication, mapping, finance-readiness inputs, recognition inputs, certification inputs, procurement implications, provider development, sponsor benefit, external sharing, or commercial use unless the relevant records expressly authorize such use.

452.11.4 Where data authority is unclear, disputed, incomplete, expired, withdrawn, restricted, or superseded, access shall be restricted until clarified by competent record.

452.12 Record-Based AI Use.

452.12.1 AI use by or for the Corporation shall be valid only where supported by AI-use records, model register records where material, data authority records, permitted use records, prohibited use records, inference records where material, compute workload records where material, human review records, risk classification records, AI vendor records where applicable, AI-use restriction records, public-safe review records, and correction records.

452.12.2 No AI output shall be treated as official truth, evidence conclusion, public authority communication, finance-facing conclusion, recognition-facing conclusion, certification-facing conclusion, public-safe publication, technical baseline, public warning, emergency command, professional advice, or public claim unless the required records and human review support that use.

452.12.3 AI systems shall not be used for unauthorized training, fine-tuning, embedding, retrieval, model improvement, agentic action, public communication, public authority communication, publication, protected knowledge processing, rights-bearing data processing, or external sharing beyond recorded authority.

452.12.4 Material AI use shall remain subject to hallucination review, bias review, civil rights review, accessibility review, safety review, prompt injection review, leakage review, data governance review, and correction.

452.13 Record-Based Controlled-Room Access.

452.13.1 Access to controlled rooms, clean rooms, data rooms, evidence rooms, public authority rooms, regulator-listening rooms, public finance reader rooms, emergency learning rooms, no-download rooms, and other restricted environments shall be valid only where supported by room charter records, owner records, custodian records, admission records, participant capacity records, confidentiality records, data / AI / cyber / privacy review records, competition review records, public authority boundary records, finance boundary records, safeguards review records, access logs where appropriate, exhibit records, and closeout records.

452.13.2 Controlled-room participation shall not constitute endorsement, adoption, approval, funding, procurement, public finance approval, regulatory guidance, public warning, emergency command, sovereign obligation, recognition, finance-readiness, certification, provider preference, or public authority decision.

452.13.3 Room access shall be suspended, revoked, narrowed, or reclassified where the access record no longer supports the participant’s role, authority, purpose, data class, risk class, or confidentiality status.

452.14 Record-Based Finance-Boundary Statements.

452.14.1 Any finance-boundary statement, capital-readability statement, insurance-readiness statement, proof-pack reference, capital-reader reference, Nexus Rails reference, RNFD reference, NFD reference, UNFSD reference, GRA interface statement, investment-related limitation, public finance reader statement, or regulated-perimeter statement shall be valid only where supported by finance-boundary records and approved language.

452.14.2 GCRI US shall not issue finance-readiness, capital-readability, insurance-readiness, investment advice, securities solicitation, broker-dealer activity, finder activity, lending approval, insurance placement, underwriting, rating, public finance approval, public guarantee, public credit, grant approval, tax credit approval, or capital execution statements.

452.14.3 Technical evidence provided by GCRI US to GRA or capital-reader contexts shall remain technical evidence only and shall not create finance reliance unless a competent record from an authorized body expressly provides otherwise.

452.14.4 Finance-boundary overclaims shall be corrected promptly, including through public or controlled correction where reliance risk exists.

452.15 Record-Based Safeguards.

452.15.1 Safeguards concerning civil rights, accessibility, community review, Tribal / Indigenous review, protected knowledge, public-safe mapping, vulnerable populations, health-sensitive data, youth data, rights-bearing data, environmental justice, cultural knowledge, local knowledge, territorial knowledge, consent, non-consent, attribution, non-attribution, withdrawal, restriction, correction, grievance, and do-no-harm shall be valid only where supported by safeguards records.

452.15.2 Safeguards records shall identify affected persons or communities where appropriate, authority, permission, review, restrictions, access class, AI-use limits, publication limits, mapping limits, attribution rules, withdrawal rights where applicable, correction path, and grievance pathway.

452.15.3 The absence of a safeguards record shall require restriction, review, or withholding where activity may affect protected knowledge, rights-bearing persons, vulnerable communities, Tribal / Indigenous interests, local or territorial knowledge, civil rights, accessibility, or public-safe mapping.

452.15.4 Safeguards records shall be interpreted according to the most protective applicable rule where ambiguity exists.

452.16 No Record / No Public Meaning Principle.

452.16.1 No Record / No Public Meaning shall mean that no material public meaning, institutional authority, public claim, public authority reference, finance-boundary statement, recognition implication, certification implication, procurement implication, Nexus-compatible implication, public warning implication, emergency command implication, evidence conclusion, technical baseline status, software release status, data permission, AI permission, controlled-room access, safeguards approval, or correction status shall be valid unless supported by an authoritative record.

452.16.2 Where no record exists, the Corporation shall state no claim, assert no authority, imply no status, grant no access, release no material, rely on no output, and correct any contrary public or controlled statement.

452.16.3 Where a record is missing, incomplete, disputed, outdated, superseded, withdrawn, retracted, archived, sealed, restricted, or inconsistent, the Corporation shall classify the matter conservatively, restrict reliance, preserve relevant records, and route the matter for correction, reconciliation, or Board review where appropriate.

452.17 Validity-by-Record Records.

452.17.1 The Corporation shall maintain Validity-by-Record Records, including validity-by-record purpose records, record-based governance records, institutional authority records, evidence records, method records, public claim records, public authority reference records, Nexus interface output records, technical baseline records, software release records, data access records, AI-use records, controlled-room access records, finance-boundary statement records, safeguards records, no-record / no-public-meaning records, missing-record reviews, authority clarification records, record reconciliation records, corrections, restrictions, withdrawals, retractions, and archive records.


Section 453. Correctionability Purpose

453.1 Correctionability Purpose.

453.1.1 Correctionability shall mean the continuing institutional duty and capability of the Corporation to identify, receive, review, correct, supersede, withdraw, retract, restrict, reclassify, clarify, annotate, notify, archive, and learn from errors, omissions, overclaims, outdated records, invalid records, unsafe outputs, boundary failures, data errors, AI errors, cybersecurity incidents, research integrity issues, public authority misstatements, finance-boundary misstatements, protected knowledge concerns, and other material defects.

453.1.2 Correctionability shall apply to governance records, evidence records, research outputs, methods, ontology, controlled vocabulary, datasets, AI outputs, compute records, proof receipts, dashboards, maps, publications, technical baselines, software releases, repository artifacts, public authority references, finance-boundary statements, Nexus interface outputs, contracts, grants, compliance records, safeguards records, and public-safe summaries.

453.1.3 Correctionability shall be treated as a public-benefit obligation, a technical truth obligation, a public-safe publication obligation, a records obligation, a safeguards obligation, and a Nexus coordination obligation.

453.1.4 No person shall resist correction because correction is reputationally inconvenient, sponsor-disfavored, provider-disfavored, funder-sensitive, public authority-sensitive, finance-facing, technically burdensome, or inconsistent with a prior public narrative.

453.2 Correction as Institutional Duty.

453.2.1 The Corporation shall correct institutional records where authority, governance action, delegation, role, access, decision, approval, filing, policy, contract, grant, register, public statement, public authority reference, or Nexus coordination record is inaccurate, incomplete, misleading, outdated, unsupported, unauthorized, superseded, or unsafe.

453.2.2 Institutional correction shall preserve historical traceability and shall identify the original record, correction authority, correction date, reason, corrected record, affected dependencies, notice requirements, and archive status.

453.2.3 Correction shall not be treated as institutional weakness. Correction shall be treated as an integrity function central to the Corporation’s public-good role.

453.3 Correction as Evidence Duty.

453.3.1 The Corporation shall correct evidence where source lineage, data quality, provenance, classification, confidence, uncertainty, limitations, reviewer status, conflict status, public-safe status, or interpretation is inaccurate, incomplete, misleading, outdated, unsupported, or materially contested.

453.3.2 Evidence correction may include source correction, metadata correction, confidence revision, limitation disclosure, reclassification, evidence pack update, dashboard update, map update, proof receipt annotation, public-safe summary correction, controlled correction, withdrawal, or retraction.

453.3.3 Evidence correction shall include downstream dependency review where corrected evidence affects methods, reports, technical baselines, GRA inputs, GRF inputs, Docket inputs, Grid inputs, public authority learning materials, or public claims.

453.4 Correction as Research Integrity Duty.

453.4.1 The Corporation shall correct research outputs where research design, ethics review, consent, source integrity, data handling, analysis, methods, conflicts, sponsor role, provider role, limitation disclosure, uncertainty disclosure, authorship, attribution, publication, or public-safe framing is inaccurate, incomplete, misleading, noncompliant, or materially challenged.

453.4.2 Research integrity correction may include protocol amendment, ethics notification, participant notice where required, dataset restriction, analysis correction, authorship correction, publication correction, withdrawal, retraction, misconduct review, or external referral where required.

453.4.3 Correction shall not be avoided by characterizing research as technical assistance, observability, public authority learning, pilot work, dashboarding, or internal analysis where research integrity duties apply.

453.5 Correction as Public Authority Boundary Duty.

453.5.1 The Corporation shall correct any statement, record, publication, dashboard, map, event material, public authority learning material, public authority reference, quote, logo use, title use, attendance statement, data contribution statement, room record, or communication that implies public authority endorsement, adoption, funding approval, procurement approval, regulatory approval, public finance approval, public warning, emergency command, sovereign obligation, public-private partnership, official guidance, or public authority decision without competent record.

453.5.2 Public authority boundary correction may require direct correction to the affected public authority, public correction, controlled correction, takedown, revised capacity language, removal of logo or quote, correction of event materials, updated dashboard notice, or archive annotation.

453.5.3 Public authority correction shall be handled with confidentiality, public records awareness, public-safe communication, and respect for public authority legal constraints.

453.6 Correction as Finance Boundary Duty.

453.6.1 The Corporation shall correct any statement, record, output, proof receipt, technical evidence pack, public-safe summary, dashboard, map, GRA interface material, capital-reader material, sponsor material, provider material, Project SPV material, national company material, public authority material, or publication that implies finance-readiness, capital-readability, insurance-readiness, investment advice, securities solicitation, broker-dealer activity, finder activity, lending approval, insurance placement, underwriting, rating, public finance approval, public guarantee, public credit, grant approval, tax credit approval, bankability, investability, financeability, or capital execution by GCRI US without competent authority.

453.6.2 Finance-boundary correction shall preserve GRA role separation and may require GRA notice, non-reliance clarification, material withdrawal, publication correction, public authority correction, capital-reader correction, sponsor correction, provider correction, or legal review.

453.6.3 No evidence record, proof receipt, dashboard, KPI, benchmark, technical baseline, Docket input, Grid input, or public-safe summary shall be left uncorrected where it creates finance reliance risk inconsistent with GCRI US’s role.

453.7 Correction as Certification, Procurement, Recognition, Docket, Grid, and Nexus-Compatible Claim Boundary Duty.

453.7.1 The Corporation shall correct any statement or output that implies certification, accreditation, conformance approval, compliance approval, procurement approval, approved vendor status, provider preference, GRF recognition, standing, maturity, registry status, public legitimacy determination, Docket approval, Grid guarantee, Nexus-compatible status, protocol approval, standards approval, or legal compliance approval without competent record.

453.7.2 Such correction may require GRF notice, Nexus Standards notice, protocol authority notice, public correction, controlled correction, removal of marks, revised controlled vocabulary, public-safe limitation language, takedown, supersession, withdrawal, or retraction.

453.7.3 The Corporation shall maintain strict correction discipline where public-good technical assets, open technical baselines, compatibility claims, test results, benchmark results, proof receipts, repository releases, or dashboard outputs could be misused as certification or procurement signals.

453.8 Correction as Data / AI / Cyber / Privacy Duty.

453.8.1 The Corporation shall correct data, AI, cybersecurity, and privacy defects, including unauthorized data access, misclassification, missing lawful basis, missing consent where required, unauthorized transfer, unauthorized AI training, unauthorized embedding, model leakage, hallucination, unsafe output, bias, civil rights impact, prompt injection, data poisoning, cyber incident, repository compromise, secret exposure, credential compromise, privacy breach, or public-safe publication error.

453.8.2 Correction may include access restriction, data deletion where lawful, data reclassification, AI hold, model restriction, inference record correction, compute workload record correction, embedding store restriction or deletion where available, repository quarantine, credential rotation, vulnerability patch, breach notification assessment, public-safe correction, and incident closeout.

453.8.3 Corrections involving public authority data, rights-bearing data, health-sensitive data, youth data, cyber-sensitive data, infrastructure-sensitive data, community-protected data, Tribal / Indigenous data, or protected knowledge shall receive heightened review.

453.9 Correction as Public-Safe Publication Duty.

453.9.1 The Corporation shall correct public-facing outputs where they are inaccurate, unsupported, misleading, outdated, improperly classified, overconfident, public authority-confusing, finance-confusing, certification-confusing, recognition-confusing, procurement-confusing, unsafe, inaccessible, discriminatory, harmful, or inconsistent with public-safe publication standards.

453.9.2 Public-safe publication correction may include erratum, update notice, limitation notice, public clarification, controlled clarification, dashboard banner, map notice, dataset update, software release note, technical baseline supersession, publication withdrawal, public retraction, or takedown.

453.9.3 Public correction language shall be accurate, proportionate, non-defamatory, non-retaliatory, confidentiality-aware, public-safe, and sufficient to prevent continued reliance on the defective output.

453.10 Correction as Community Safeguards and Protected Knowledge Duty.

453.10.1 The Corporation shall correct any activity or output that misuses, exposes, misattributes, fails to attribute, over-attributes, maps, publishes, translates, extracts, trains on, embeds, transfers, commercializes, or otherwise uses community-protected, Tribal / Indigenous, local, territorial, cultural, environmental, ecological, sacred, or protected knowledge beyond recorded authority.

453.10.2 Correction may include immediate access restriction, publication hold, map hold, dashboard hold, takedown, deletion where lawful, redaction, reclassification, attribution correction, non-attribution correction, withdrawal, grievance pathway activation, community notice, Tribal / Indigenous notice where appropriate, and safeguards review.

453.10.3 Correction involving protected knowledge shall be handled with heightened care and shall not expose further protected information through the correction itself.

453.11 Correction as Nexus Coordination Duty.

453.11.1 The Corporation shall correct Nexus coordination records and outputs where interfaces with GCRI Canada, GRF, GRA, Nexus Standards, protocol authorities, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, consortiums, public authorities, national companies, Project SPVs, providers, sponsors, hosts, universities, laboratories, communities, or media are misdescribed, unsupported, outdated, role-collapsing, or boundary-defective.

453.11.2 Nexus coordination correction may require compatibility note update, divergence log update, interface map update, routing record update, cross-entity notice, shared-record correction, shared-room correction, shared-publication correction, proof receipt annotation, or controlled correction.

453.11.3 Correction shall preserve legal separateness, no merger, no agency, no partnership, no joint venture, no shared liability, and no authority to bind across entities absent competent record.

453.12 Correction as Repository and Technical Asset Duty.

453.12.1 The Corporation shall correct repositories, software releases, technical baselines, schemas, APIs, SDKs, technical profiles, dashboards, maps, test harnesses, benchmark libraries, model cards, dataset cards, system cards, benchmark cards, proof receipt tools, documentation, release notes, changelogs, dependencies, SBOMs, signatures, provenance records, and vulnerability records where they are inaccurate, insecure, mislicensed, outdated, overclaimed, unsupported, vulnerable, restricted, or unsafe.

453.12.2 Repository and technical asset correction may include commit correction, release note correction, version update, patch, rollback, deprecation, vulnerability disclosure, license correction, access restriction, repository hold, release hold, artifact quarantine, secret rotation, token revocation, or takedown.

453.12.3 Technical asset correction shall preserve historical traceability and shall not conceal prior errors where traceability is required for audit, security, reliance, or correctionability.

453.13 Correction Without Admission Where Appropriate.

453.13.1 The Corporation may issue a correction, clarification, supersession, withdrawal, retraction, limitation notice, dashboard notice, map notice, release note, or controlled correction without admission of liability, wrongdoing, fault, negligence, or legal responsibility where appropriate and lawful.

453.13.2 Correction Without Admission shall not be used to avoid mandatory reporting, mislead affected persons, suppress material facts, avoid public-safe notice, evade legal duties, or conceal misconduct.

453.13.3 The Corporation may include non-admission language in correction notices where accurate, lawful, and consistent with public-safe communication.

453.14 Public-Safe Correction.

453.14.1 Public-Safe Correction shall be used where a defective or superseded output is public-facing, publicly relied upon, publicly accessible, publicly cited, media-facing, public authority-facing, finance-facing, provider-facing, sponsor-facing, or otherwise capable of external reliance.

453.14.2 Public-Safe Correction shall provide enough information to prevent continued misuse while avoiding overdisclosure of sensitive personal information, public authority data, cyber-sensitive information, infrastructure-sensitive information, protected knowledge, confidential information, privileged material, controlled technology, or security details.

453.14.3 Public-Safe Correction may be paired with controlled correction where additional detail is necessary for authorized recipients.

453.15 Controlled Correction.

453.15.1 Controlled Correction shall be used where correction must be communicated to a limited audience because the underlying materials involve confidential information, privileged information, public authority restricted information, personal information, health-sensitive data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, procurement-sensitive information, protected knowledge, controlled technology, export-controlled materials, sanctions-sensitive matters, or active investigations.

453.15.2 Controlled Correction may be issued to affected public authorities, funders, sponsors, providers, partners, communities, Tribal / Indigenous representatives, vendors, insurers, auditors, counsel, regulators, or other authorized recipients.

453.15.3 Controlled Correction shall be access-controlled, recorded, and coordinated with privilege, confidentiality, legal hold, incident response, and public-safe communication requirements.

453.16 Downstream Correction.

453.16.1 Downstream Correction shall require the Corporation to identify and address records, outputs, systems, publications, repositories, datasets, models, dashboards, maps, proof receipts, technical baselines, software releases, public authority learning materials, GRA inputs, GRF inputs, Docket inputs, Grid inputs, Nexus interface outputs, contracts, grant reports, and third-party materials affected by a correction.

453.16.2 Downstream Correction may require notice to users, custodians, maintainers, reviewers, public authorities, GRA, GRF, Nexus Standards, GCRI Canada, consortiums, funders, sponsors, providers, communities, or other affected parties.

453.16.3 Downstream Correction shall include dependency mapping where material and shall preserve historical traceability.

453.17 Correctionability Records.

453.17.1 The Corporation shall maintain Correctionability Records, including correctionability purpose records, institutional duty records, evidence duty records, research integrity duty records, public authority boundary duty records, finance boundary duty records, certification / procurement / recognition / Docket / Grid / Nexus-compatible claim boundary duty records, data / AI / cyber / privacy duty records, public-safe publication duty records, community safeguards and protected knowledge duty records, Nexus coordination duty records, repository and technical asset duty records, correction-without-admission records, public-safe correction records, controlled correction records, downstream correction records, correction requests, determinations, notices, dependency reviews, closeout records, and archive records.


Section 454. Authoritative Records

454.1 Authoritative Record Definition.

454.1.1 An Authoritative Record means a record recognized by the Corporation as competent to establish, evidence, limit, modify, supersede, withdraw, retract, restrict, correct, or archive the institutional meaning of a governance action, authority, role, evidence conclusion, method, public claim, public authority reference, finance-boundary statement, technical baseline, software release, data access, AI use, controlled-room access, safeguards decision, Nexus interface, compliance matter, or correction.

454.1.2 Authoritative Records may be physical, digital, repository-based, database-based, ledger-compatible, signed, timestamped, version-controlled, or otherwise maintained in an approved system of record.

454.1.3 A draft, informal note, oral statement, unapproved slide, chat message, AI-generated text, dashboard output, unreviewed spreadsheet, sensor signal, proof receipt without supporting authority, or public statement shall not be an Authoritative Record unless adopted or incorporated by competent authority.

454.2 Corporate Records.

454.2.1 Corporate Records shall include formation documents, certificates or articles, Bylaws, amendments, registered office records, registered agent records, principal office records, annual or biennial filings, foreign qualification records, good-standing records, corporate minute books, corporate registers, and records required to preserve the Corporation’s lawful existence.

454.2.2 Corporate Records shall be authoritative for corporate existence, corporate powers, legal form, legal separateness, nonprofit status, governing law, official name, and foundational governance structure.

454.3 Board Records.

454.3.1 Board Records shall include notices, agendas, minutes, written consents, resolutions, votes, approvals, recusals, conflict reviews, committee reports, Board policies, Board delegations, Board appointments, Board removals, Board findings, Board enforcement actions, and Board-approved instruments.

454.3.2 Board Records shall be authoritative for Board action, Board authority, Board oversight, material approvals, reserved powers, and governance decisions.

454.4 Member Records Where Applicable.

454.4.1 Where the Corporation has members, Member Records shall include member registers, member classes, admission records, voting rights, notices, minutes, consents, approvals, resignations, removals, member communications, member disputes, and member approvals required by law or governing instruments.

454.4.2 Member Records shall be authoritative only to the extent the Corporation’s governing instruments or applicable law confer member rights or approval powers.

454.5 Officer Records.

454.5.1 Officer Records shall include officer appointments, resignations, removals, titles, duties, delegations, authority matrices, employment or service terms where applicable, officer approvals, officer reports, officer certifications, officer filings, and officer corrective actions.

454.5.2 Officer Records shall be authoritative for officer authority only within recorded scope and shall not create authority to exceed Bylaws, Board delegations, public authority boundaries, finance boundaries, certification or recognition boundaries, procurement neutrality, or non-execution requirements.

454.6 Committee, Council, Forum, Working Group, and Panel Records.

454.6.1 Committee, Council, Forum, Working Group, and Panel Records shall include charters, memberships, appointments, roles, scope, authority, agendas, minutes, recommendations, reports, recusals, conflict records, attendance records, public authority capacity records, and outputs.

454.6.2 Such records shall be authoritative for the existence and scope of the body but shall not create Board authority, officer authority, public authority authority, certification authority, recognition authority, finance-readiness authority, procurement authority, or enterprise execution authority unless expressly granted by competent record.

454.7 Delegation Records.

454.7.1 Delegation Records shall identify delegated authority, delegating body, delegate, scope, limits, amount thresholds where applicable, subject matter, term, reporting duties, prohibited actions, required approvals, revocation path, and effective date.

454.7.2 Delegation Records shall be interpreted narrowly. No delegation shall be expanded by practice, convenience, technical need, sponsor request, provider request, public authority interest, or Nexus urgency.

454.8 Policy Records.

454.8.1 Policy Records shall include approved policies, procedures, standards, protocols, templates, clause libraries, matrices, schedules, manuals, handbooks, guidance, training materials, review cycles, effective dates, supersession records, and correction records.

454.8.2 Policy Records shall be authoritative only where approved by competent authority and shall not override Bylaws, formation documents, applicable law, or Board reserved powers.

454.9 Fiscal Records.

454.9.1 Fiscal Records shall include accounting records, budgets, financial statements, bank records, treasury records, payment approvals, payroll records, reimbursement records, vendor records, grant cost records, restricted fund records, donation records, sponsorship records, in-kind support records, tax records, audit records, and financial control records.

454.9.2 Fiscal Records shall be authoritative for financial status, restrictions, payments, fiscal approvals, grant costs, fund balances, and financial reporting, subject to correction and audit.

454.10.1 Conflict and Related-Party Records shall include conflict disclosures, related-party disclosures, recusal records, independence determinations, comparability records, Board approvals, excess benefit reviews where applicable, private benefit reviews, sponsor influence reviews, provider influence reviews, and corrective actions.

454.10.2 Such records shall be authoritative for conflict status and conflict handling but shall not cure undisclosed conflicts or unlawful private benefit unless competent correction occurs.

454.11 Research Records.

454.11.1 Research Records shall include research agendas, protocols, ethics reviews, human-subjects reviews, community reviews, Tribal / Indigenous reviews, protected knowledge reviews, consent records, source records, data records, analysis records, reviewer records, conflict records, limitation records, uncertainty records, publication records, challenge records, and correction records.

454.11.2 Research Records shall be authoritative for research design, authority, review, participant protection, public-safe status, and correction history.

454.12 Evidence Records.

454.12.1 Evidence Records shall include source lineage, source authority, evidence classification, provenance, custody, data quality, method used, reviewer status, confidence, uncertainty, limitation, conflict, classification, permitted use, prohibited use, public-safe status, and correction path.

454.12.2 Evidence Records shall be authoritative for the existence and scope of evidence but shall not convert evidence into recognition, finance-readiness, certification, procurement approval, public authority decision, rating, public warning, emergency command, or legal compliance approval.

454.13 Methods Records.

454.13.1 Methods Records shall include method identity, owner, custodian, version, purpose, scope, assumptions, inputs, outputs, limitations, validation or review status where applicable, applicable domain, known issues, public-safe status, access class, supersession path, deprecation path, and correction path.

454.13.2 Methods Records shall be authoritative for method status and permitted use.

454.14 Ontology and Controlled Vocabulary Records.

454.14.1 Ontology and Controlled Vocabulary Records shall include term definitions, term identifiers, semantic relationships, permitted uses, restricted uses, prohibited uses, translation notes, localization notes, authority requirements, public-safe usage, boundary language, semantic drift reviews, and correction records.

454.14.2 These records shall be authoritative for the meaning of controlled terms, including evidence, verified, validated, public-safe, technical truth, recognition, standing, maturity, Docket, Grid, finance-ready, capital-readable, certified, compliant, approved, public authority, official, observer, regulator-listening, public finance reader, and Nexus-compatible.

454.15 Data / AI / Cyber / Privacy Records.

454.15.1 Data / AI / Cyber / Privacy Records shall include data inventories, data registers, processing registers, lawful basis records, authority records, permission records, consent records, privacy reviews, data protection impact assessments, model registers, AI-use approvals, inference records, compute workload records, proof receipts, cybersecurity records, access logs where appropriate, incident records, breach assessments, vendor records, and correction records.

454.15.2 Such records shall be authoritative for data access, AI use, cybersecurity controls, privacy status, incident status, and restrictions.

454.16 Public-Good Software and Technical Asset Records.

454.16.1 Public-Good Software and Technical Asset Records shall include technical asset register records, repository records, owner records, maintainer records, version records, license records, release records, SBOM records where appropriate, artifact signing records where appropriate, vulnerability records, dependency records, documentation, known issues, known limitations, deprecation records, and correction records.

454.16.2 Such records shall be authoritative for technical asset status but shall not create certification, procurement approval, public authority adoption, finance-readiness, recognition, rating, provider preference, public warning, emergency command, or operational warranty.

454.17 Public Authority Records.

454.17.1 Public Authority Records shall include capacity classifications, official capacity records, observer records, regulator-listening records, public finance reader records, public authority data contribution records, public authority reference approvals, public authority room records, public records considerations, public authority correspondence, public authority notices, and correction records.

454.17.2 Public Authority Records shall be authoritative for public authority participation and reference meaning only within recorded scope.

454.18 Publication and Public Claim Records.

454.18.1 Publication and Public Claim Records shall include publication classification, approval records, claims substantiation, evidence references, method references, source lineage, public-safe review, data / AI / cyber / privacy review, public authority boundary review, finance-boundary review, certification and recognition boundary review, conflict disclosure, limitation notices, version records, publication records, and correction records.

454.18.2 Such records shall be authoritative for publication status, public claim support, limitation language, and correction status.

454.19 Nexus Coordination Records.

454.19.1 Nexus Coordination Records shall include interface registers, federation instruments, MoUs, data-sharing instruments, model-sharing instruments, technical baseline instruments, shared-record instruments, identity objects, role objects, credential objects, access objects, proof objects, proof receipts, compatibility notes, divergence logs, equivalence notes, localization notes, interface maps, routing records, mismatch records, and correction records.

454.19.2 Nexus Coordination Records shall be authoritative for Nexus interface meaning but shall not create merger, agency, partnership, joint venture, shared liability, public authority delegation, finance-readiness, recognition, certification, procurement approval, public warning, emergency command, or enterprise execution by implication.

454.20 Compliance, Risk, Incident, Insurance, Indemnification, and Enforcement Records.

454.20.1 Compliance, Risk, Incident, Insurance, Indemnification, and Enforcement Records shall include compliance registers, risk registers, issue registers, control records, KPI and KRI records, incident records, investigation records, enforcement records, corrective action records, insurance records, claims records, indemnification records, advancement records, legal hold records, and referral records.

454.20.2 Such records shall be authoritative for compliance status, risk status, incident status, insurance status, indemnification status, advancement status, enforcement status, and corrective action status.

454.21 Safeguards and Protected Knowledge Records.

454.21.1 Safeguards and Protected Knowledge Records shall include civil rights reviews, accessibility reviews, community review records, Tribal / Indigenous review records, protected knowledge records, local knowledge records, territorial knowledge records, cultural knowledge records, environmental knowledge records, public-safe mapping records, consent and non-consent records, attribution and non-attribution records, withdrawal records, restriction records, grievance records, and correction records.

454.21.2 Such records shall be authoritative for safeguards permissions, restrictions, access limits, AI-use limits, publication limits, mapping limits, and correction obligations.

454.22 Correction Records.

454.22.1 Correction Records shall include correction requests, challenge records, intake records, triage records, determinations, corrected records, supersession records, withdrawal records, retraction records, public correction notices, controlled correction notices, downstream dependency notices, proof receipt annotations, repository corrections, publication corrections, dashboard corrections, map corrections, closeout records, and archive records.

454.22.2 Correction Records shall be authoritative for corrected status, prior status, dependency status, and continuing limitation.

454.23 Authoritative Record Register.

454.23.1 The Corporation shall maintain an Authoritative Record Register or equivalent system identifying record classes, systems of record, owners, custodians, access classes, retention classes, authority status, supersession paths, correction paths, and archive status.

454.23.2 The Authoritative Record Register shall be used to resolve ambiguity, prevent reliance on drafts, identify controlling records, support audits, support legal holds, support correction, and preserve institutional memory.


Section 455. Minimum Record Metadata

455.1 Metadata Requirement.

455.1.1 Material records shall include minimum metadata sufficient to support authority, traceability, accountability, access control, public-safe interpretation, correctionability, retention, auditability, and interoperability.

455.1.2 Metadata requirements shall apply proportionately according to record class, risk, public status, legal significance, public authority exposure, finance exposure, data sensitivity, AI use, cybersecurity sensitivity, protected knowledge status, and reliance risk.

455.1.3 A record lacking required metadata may be classified as incomplete, draft, restricted, provisional, invalid for public meaning, or subject to correction until metadata is completed.

455.2 Record Identifier.

455.2.1 Each material record shall have a Record Identifier sufficient to distinguish it from other records.

455.2.2 Record Identifiers may be numeric, alphanumeric, repository-based, database-based, docket-based, ledger-compatible, or otherwise generated by an approved system.

455.2.3 Record Identifiers shall not imply approval, publication, recognition, finance-readiness, certification, public authority status, or public-safe status unless the related metadata expressly supports such meaning.

455.3 Case Identifier Where Applicable.

455.3.1 A Case Identifier shall be assigned where a record relates to an incident, investigation, correction, grievance, challenge, dispute, legal hold, public authority matter, finance-boundary matter, data / AI / cyber matter, protected knowledge matter, contract dispute, enforcement matter, or other case-managed process.

455.3.2 Case Identifiers shall support tracking, evidence preservation, access control, status reporting, corrective action, and closeout.

455.4 Title.

455.4.1 Each material record shall include a title that accurately describes the record without creating misleading public meaning.

455.4.2 Titles shall not use restricted terms, including “approved,” “certified,” “recognized,” “finance-ready,” “public authority approved,” “official,” “Grid status,” “Docket approved,” or “Nexus-compatible,” unless such title is supported by competent authority.

455.5 Record Class.

455.5.1 Each material record shall identify its Record Class, including corporate, Board, officer, delegation, policy, fiscal, contract, research, evidence, method, ontology, data, processing, model, inference, compute workload, cybersecurity, technical asset, repository, publication, public authority, Nexus interface, compliance, risk, correction, safeguards, protected knowledge, or other approved class.

455.5.2 Record Class shall guide metadata requirements, access controls, retention, correction path, and system of record.

455.6 Owner.

455.6.1 Each material record shall identify an Owner responsible for the institutional meaning, authority, maintenance, review, and correction of the record.

455.6.2 Ownership may be assigned to a role, office, committee, custodian, program, repository owner, data owner, technical asset owner, or other accountable authority.

455.7 Custodian.

455.7.1 Each material record shall identify a Custodian responsible for storage, access control, retrieval, classification, retention, and preservation.

455.7.2 Custodianship shall not create substantive approval authority unless the record expressly provides such authority.

455.8 Creator.

455.8.1 Each material record shall identify the Creator where practicable.

455.8.2 Creator metadata shall identify person, role, system, model, tool, repository, or source responsible for creation, including AI assistance where material and required.

455.9 Approver.

455.9.1 Each record requiring approval shall identify the Approver and approval authority.

455.9.2 Approval metadata shall include approval date, scope, conditions, limitations, and any required review pathway.

455.9.3 A record without required approval shall be treated as draft, provisional, restricted, or invalid for public meaning until approved.

455.10 Date Created.

455.10.1 Each material record shall include Date Created.

455.10.2 Date Created shall not be backdated or altered except through correction process preserving original metadata.

455.11 Effective Date.

455.11.1 Records with operative effect shall include Effective Date.

455.11.2 Effective Date shall distinguish creation from approval, publication, commencement, expiration, supersession, withdrawal, and archive.

455.12 Version.

455.12.1 Version metadata shall be required for records capable of revision, including policies, methods, datasets, models, software, technical baselines, publications, dashboards, maps, contracts, templates, controlled vocabulary, and interface records.

455.12.2 Versioning shall preserve prior versions, supersession, correction, deprecation, withdrawal, retraction, and archive history where material.

455.13 Authority.

455.13.1 Authority metadata shall identify the source of authority for the record, including Bylaw provision, Board resolution, officer delegation, contract, grant, policy, public authority permission, data authority, consent, license, ethics approval, safeguards permission, or other competent basis.

455.13.2 Where authority is uncertain, absent, expired, disputed, or incomplete, the record shall be restricted or marked as requiring authority review.

455.14 Scope.

455.14.1 Scope metadata shall identify the subject matter, jurisdiction, program, technology, entity, interface, public authority, data class, time period, geography, population, repository, system, publication, or other boundary of the record.

455.14.2 Scope shall be interpreted narrowly and shall not be expanded by implication.

455.15 Source Lineage.

455.15.1 Source Lineage metadata shall identify sources, data origins, prior records, derivations, transformations, methods, models, systems, repositories, and chain-of-custody where material.

455.15.2 Source Lineage shall be required for evidence, datasets, models, methods, public claims, publications, dashboards, maps, proof receipts, technical baselines, AI outputs, compute outputs, and public authority learning materials where material.

455.16 Permissions.

455.16.1 Permissions metadata shall identify who may access, view, edit, approve, publish, download, transfer, cite, map, summarize, train on, embed, process through AI, share, or archive the record.

455.16.2 Permissions shall be purpose-limited, access-classified, and revocable.

455.17 Classification.

455.17.1 Classification metadata shall identify whether the record is public, public-safe, internal, controlled, confidential, restricted, public authority, research, data-room, evidence-room, clean-room, no-download, community-protected, Tribal / Indigenous, finance-sensitive, cyber-sensitive, infrastructure-sensitive, health-sensitive, controlled technology, export-controlled, sanctions-sensitive, privileged, sealed, archived, or another approved classification.

455.17.2 Classification shall determine access, publication, retention, redaction, AI-use restrictions, transfer, and correction.

455.18 Confidentiality Status.

455.18.1 Confidentiality Status shall identify whether the record is public, internal, confidential, privileged, work product, restricted, sealed, subject to contract confidentiality, subject to public authority confidentiality, subject to protected knowledge restrictions, or otherwise restricted.

455.18.2 Confidentiality Status shall not be used to conceal unlawful conduct, suppress correction, or retaliate against reporters.

455.19 Public-Safe Status.

455.19.1 Public-Safe Status shall identify whether a record is approved for public release, approved for public-safe summary, controlled only, restricted, not reviewed, publication-held, withdrawn, retracted, archived, or requiring public-safe review.

455.19.2 No record shall be publicly released or relied upon as public-safe unless the required review supports that status.

455.20 Limitations.

455.20.1 Limitations metadata shall identify known limits, uncertainty, confidence level, excluded uses, non-reliance boundaries, public authority boundaries, finance boundaries, certification boundaries, procurement boundaries, recognition boundaries, data restrictions, AI restrictions, safeguards restrictions, and technical limitations.

455.20.2 Limitation metadata shall be included in public-safe outputs where material to prevent overclaim or misuse.

455.21.1 Related Records metadata shall identify linked records, source records, approvals, contracts, grants, policies, datasets, methods, models, proof receipts, public authority records, correction records, interface records, and dependency records.

455.21.2 Related Records metadata shall support dependency review, downstream correction, legal holds, audits, and public-safe interpretation.

455.22 Supersession Path.

455.22.1 Supersession Path metadata shall identify how a record may be replaced, updated, deprecated, versioned, retired, or superseded.

455.22.2 Supersession shall preserve prior status, effective dates, affected dependencies, and public-safe notice where applicable.

455.23 Correction Path.

455.23.1 Correction Path metadata shall identify how errors, challenges, disputes, limitation updates, source corrections, public authority reference corrections, finance-boundary corrections, safeguards corrections, and technical corrections are raised, reviewed, approved, implemented, and closed.

455.23.2 Records without a correction path shall be restricted where correctionability is material.

455.24 Retention Class.

455.24.1 Retention Class metadata shall identify required retention period, legal hold status, audit requirement, grant requirement, tax requirement, corporate requirement, technical memory requirement, deletion eligibility, archive requirement, and secure disposal requirement.

455.24.2 Retention Class shall be updated where legal holds, investigations, public authority inquiries, grants, disputes, corrections, or protected knowledge restrictions require preservation.

455.25 Access Class.

455.25.1 Access Class metadata shall identify who may access the record and under what conditions, including public, internal, restricted, controlled-room, clean-room, no-download, public authority, privileged, sealed, community-protected, Tribal / Indigenous, or other access class.

455.25.2 Access Class shall be enforced through technical, administrative, contractual, and procedural controls where appropriate.

455.26 Minimum Metadata Records.

455.26.1 The Corporation shall maintain Minimum Metadata Records, including metadata requirement records, record identifier records, Case Identifier records where applicable, title records, Record Class records, Owner records, Custodian records, Creator records, Approver records, Date Created records, Effective Date records, Version records, Authority records, Scope records, Source Lineage records, Permissions records, Classification records, Confidentiality Status records, Public-Safe Status records, Limitation records, Related Records records, Supersession Path records, Correction Path records, Retention Class records, Access Class records, metadata correction records, and archive records.


Section 456. Record Classes and Registers

456.1 Record Classification Purpose.

456.1.1 Record Classes and Registers shall organize the Corporation’s authoritative records into structured systems that support validity-by-record, correctionability, legal compliance, governance accountability, evidence integrity, method integrity, public-safe publication, technical memory, access control, retention, audits, legal holds, and Nexus interoperability.

456.1.2 Registers shall be maintained according to record class, owner, custodian, access class, retention class, authority, metadata, correction path, and archive status.

456.1.3 Registers may be maintained in integrated or separate systems, provided the Corporation can identify controlling records, preserve integrity, support search and retrieval, apply access restrictions, perform correction, and comply with legal holds.

456.2 Corporate Register.

456.2.1 The Corporate Register shall include formation documents, Bylaws, amendments, registered office records, registered agent records, principal office records, annual or biennial filings, foreign qualification records, good-standing records, corporate authorizations, and corporate status records.

456.2.2 The Corporate Register shall preserve legal existence, legal separateness, nonprofit identity, official name, governing jurisdiction, and corporate continuity.

456.3 Board Register.

456.3.1 The Board Register shall include Board members, terms, appointments, resignations, removals, notices, agendas, minutes, written consents, resolutions, votes, recusals, conflict reviews, Board approvals, Board committees, Board reports, and Board enforcement actions.

456.3.2 The Board Register shall be the controlling register for Board authority and governance action.

456.4 Member Register Where Applicable.

456.4.1 Where the Corporation has members, the Member Register shall include member identity, class, admission, rights, voting status, notices, approvals, resignations, removals, restrictions, disputes, and member actions.

456.4.2 Where the Corporation has no voting members, the Corporation may maintain a record stating that no member register is operative except as required by law or future amendment.

456.5 Officer Register.

456.5.1 The Officer Register shall include officer identity, title, appointment, term, authority, delegation, resignation, removal, employment or service status where applicable, reporting duties, and authority limitations.

456.5.2 The Officer Register shall support verification of who may act, sign, approve, certify, file, communicate, or escalate on behalf of the Corporation.

456.6 Director Register.

456.6.1 The Director Register shall include director identity, term, appointment, resignation, removal, committee roles, independence status where applicable, conflict disclosures, training status, contact information, and indemnification or insurance status where appropriate.

456.6.2 The Director Register shall support fiduciary oversight, governance continuity, conflict management, and Board composition compliance.

456.7 Delegation Register.

456.7.1 The Delegation Register shall include delegations of authority by the Board, committees, officers, or policies, including scope, limits, amount thresholds, term, delegate, authority source, reporting duties, required approvals, prohibited actions, and revocation path.

456.7.2 The Delegation Register shall prevent apparent authority, unauthorized contracts, unauthorized public claims, unauthorized public authority references, unauthorized finance-facing statements, unauthorized certification or recognition claims, and unauthorized access.

456.8 Committee and Council Register.

456.8.1 The Committee and Council Register shall include committees, councils, forums, working groups, panels, advisory bodies, and other bodies, including charters, members, chairs, scope, authority, limitations, meeting records, outputs, and reporting duties.

456.8.2 The Register shall distinguish advisory authority, recommendation authority, review authority, and decision authority.

456.9 Conflict Register.

456.9.1 The Conflict Register shall include annual disclosures, transactional disclosures, matter-specific disclosures, recusals, conflict reviews, independence determinations, sponsor influence reviews, provider influence reviews, public authority conflict reviews, and corrective actions.

456.9.2 The Register shall support fiduciary integrity, research independence, provider neutrality, sponsor non-control, procurement neutrality, and private benefit control.

456.10.1 The Related-Party Register shall include transactions, relationships, contracts, payments, grants, reimbursements, licensing arrangements, sponsorships, donations, employment arrangements, consulting arrangements, vendor arrangements, and other matters involving directors, officers, insiders, related persons, substantial contributors, sponsors, providers, or affiliated entities.

456.10.2 The Register shall support private inurement prevention, private benefit review, excess benefit review where applicable, conflict management, and Board oversight.

456.11 Fiscal Register.

456.11.1 The Fiscal Register shall include budgets, financial statements, bank records, treasury records, payment approvals, payroll records, reimbursements, accounts payable, accounts receivable, cost allocations, restricted funds, reserves, audit records, tax filings, financial reports, and financial corrective actions.

456.11.2 The Fiscal Register shall support financial integrity, auditability, grant compliance, tax compliance, and Board oversight.

456.12 Grant, Donation, Sponsorship, In-Kind, Fee, and Support Register.

456.12.1 The Grant, Donation, Sponsorship, In-Kind, Fee, and Support Register shall include grants, public grants, cooperative agreements, donations, restricted gifts, sponsorships, in-kind support, cloud credits, compute credits, software credits, data access, equipment, donated services, fees, acknowledgments, restrictions, reporting duties, public recognition terms, and corrective actions.

456.12.2 The Register shall prevent sponsor control, provider preference, private benefit, restricted fund misuse, public authority overclaim, and purchase-of-outcome implications.

456.13 Contract Register.

456.13.1 The Contract Register shall include contracts, MoUs, grants, sponsorships, donations, vendor agreements, technology agreements, data-sharing agreements, model-sharing agreements, software agreements, repository agreements, licensing agreements, contributor agreements, controlled-room instruments, public authority interface agreements, consortium agreements, enterprise stack interface agreements, insurance agreements, indemnity arrangements, amendments, renewals, terminations, and closeout records.

456.13.2 The Register shall identify counterparty, purpose, owner, authority, amount, term, risk class, public authority exposure, finance exposure, data / AI / cyber exposure, IP exposure, indemnity exposure, reporting obligations, and correction path.

456.14 Procurement Register.

456.14.1 The Procurement Register shall include procurement requests, vendor selections, due diligence, quotes, approvals, conflict reviews, related-party reviews, technology reviews, data processor reviews, AI provider reviews, cybersecurity reviews, public authority restrictions, purchase orders, invoices, and vendor performance records.

456.14.2 The Register shall distinguish procurement by GCRI US from public procurement and shall prevent any implication of public authority procurement approval or provider preference.

456.15 Research Register.

456.15.1 The Research Register shall include research agenda records, protocols, ethics reviews, human-subjects reviews, community reviews, Tribal / Indigenous reviews, protected knowledge reviews, consent records, participant protection records, research outputs, reviewer records, challenges, misconduct reviews, and corrections.

456.15.2 The Research Register shall support research integrity, public-benefit prioritization, safeguards, public-safe publication, and correctionability.

456.16 Evidence Register.

456.16.1 The Evidence Register shall include evidence records, source records, source lineage, data quality, provenance, custody, method linkage, reviewer records, confidence statements, uncertainty statements, limitation statements, classifications, public-safe status, challenge records, and correction records.

456.16.2 The Evidence Register shall prevent unsupported claims, false confidence, evidence misuse, and conversion of evidence into unauthorized recognition, finance-readiness, certification, procurement approval, public authority decision, or public warning.

456.17 Method Register.

456.17.1 The Method Register shall include method identity, version, owner, custodian, purpose, scope, assumptions, inputs, outputs, limitations, validation or review status where applicable, known issues, applicable domains, public-safe status, deprecation status, and correction path.

456.17.2 The Method Register shall identify current, superseded, withdrawn, experimental, restricted, public-safe, and archived methods.

456.18 Ontology and Controlled Vocabulary Register.

456.18.1 The Ontology and Controlled Vocabulary Register shall include term definitions, semantic relationships, term identifiers, permitted uses, restricted terms, prohibited terms, translations, localization notes, role-separation language, public authority language, finance language, certification language, recognition language, Docket language, Grid language, Nexus-compatible language, semantic drift reviews, and corrections.

456.18.2 The Register shall prevent uncontrolled semantic drift, overclaim, misleading public claims, public authority confusion, finance reliance, certification confusion, recognition confusion, and procurement implication.

456.19 Data Register.

456.19.1 The Data Register shall include datasets, data sources, data owners, data custodians, data contributors, authority records, lawful basis, permission, consent where required, license, classification, sensitivity, permitted use, prohibited use, AI-use restrictions, publication restrictions, retention, deletion, transfer restrictions, public-safe status, and correction path.

456.19.2 The Data Register shall apply to public, public-safe, internal, confidential, restricted, rights-bearing, personal, sensitive personal, health-sensitive, public authority, cyber-sensitive, infrastructure-sensitive, finance-sensitive, research-sensitive, community-protected, Tribal / Indigenous, protected knowledge, controlled technology, and archived data.

456.20 Processing Register.

456.20.1 The Processing Register shall record processing activities, purposes, lawful basis, data classes, systems, processors, subprocessors, transfers, retention, security controls, AI use, publication use, data subject rights where applicable, public authority restrictions, and incident history.

456.20.2 The Processing Register shall support privacy compliance, data governance, AI-use control, and public-safe publication.

456.21 Model Register.

456.21.1 The Model Register shall include model identity, version, provider, owner, custodian, purpose, permitted uses, prohibited uses, risk class, data access, evaluation records, known limitations, incident history, monitoring status, retirement status, and correction path.

456.21.2 The Model Register shall include AI systems used for research, drafting, analysis, classification, summarization, coding, inference, public-safe review, dashboards, maps, observability, controlled rooms, and public authority learning where material.

456.22 Inference and Compute Workload Register.

456.22.1 The Inference and Compute Workload Register shall include material AI output records, compute workload records, input records, authority records, environment records, model / code / tool / workflow records, execution records, output records, reviewer records, confidence records, limitation records, classification records, proof receipt references, and correction paths.

456.22.2 The Register shall support verifiable compute, verifiable intelligence, human review, auditability, and correctionability.

456.23 Cybersecurity and Incident Register.

456.23.1 The Cybersecurity and Incident Register shall include cybersecurity policies, assets, access reviews, vulnerabilities, incidents, breaches, AI incidents, repository incidents, supply-chain incidents, secrets incidents, public-safe publication incidents, protected knowledge incidents, severity classifications, containment actions, investigations, notifications, remediation, root cause review, and closeout.

456.23.2 The Register shall support incident response, breach notification assessment, technical resilience, public-safe communication, and auditability.

456.24 Technical Asset Register.

456.24.1 The Technical Asset Register shall include software, repositories, schemas, APIs, SDKs, technical profiles, dashboards, maps, test harnesses, benchmark libraries, proof receipt tools, open technical baselines, reference architectures, model cards, dataset cards, system cards, benchmark cards, documentation, owner, steward, maintainer, license, version, release status, security status, vulnerability status, public-safe status, export-control status, and correction path.

456.24.2 The Register shall prevent technical asset misuse, unmanaged releases, license conflicts, vulnerability exposure, public authority overclaim, finance overclaim, certification overclaim, recognition overclaim, procurement implication, and provider preference.

456.25 Repository Register.

456.25.1 The Repository Register shall include repository identity, owner, maintainer, access class, classification, branch protection, required reviews, commit signing status where appropriate, secrets controls, vulnerability controls, license status, release status, archive status, access reviews, incident history, and correction path.

456.25.2 The Repository Register shall include public, internal, restricted, controlled, archive, and shared repositories.

456.26 Publication Register.

456.26.1 The Publication Register shall include reports, whitepapers, technical notes, method notes, evidence packs, public-safe summaries, controlled annexes, dashboards, maps, datasets, software releases, technical baselines, reference architectures, APIs, SDKs, schemas, public authority learning materials, Academy materials, event materials, media statements, web pages, social media posts, newsletters, public notices, approval records, limitation notices, version status, access class, and correction path.

456.26.2 The Publication Register shall support public-safe publication, claims substantiation, controlled vocabulary, accessibility, public authority boundary review, finance-boundary review, recognition-boundary review, certification-boundary review, procurement neutrality, and correctionability.

456.27 Public Authority Register.

456.27.1 The Public Authority Register shall include public authority contacts, participation records, capacity classifications, official capacity records, observer records, regulator-listening records, public finance reader records, emergency-learning records, public authority data contribution records, public authority reference approvals, public authority room records, public records considerations, public grants, public authority notices, and corrections.

456.27.2 The Register shall prevent public authority overclaim, unauthorized name or logo use, procurement implication, public finance implication, regulatory implication, public warning implication, and emergency command implication.

456.28 Nexus Interface Register.

456.28.1 The Nexus Interface Register shall include interfaces with GCRI Canada, GRF, GRA, Nexus Standards, protocol authorities, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Nexus Competence Cells, global / regional / national / state / territorial / Tribal / local / sector consortiums, public authorities, national companies, Project SPVs, providers, sponsors, hosts, universities, laboratories, communities, civil society, media, and partners.

456.28.2 The Register shall identify interface purpose, parties, owner, custodian, instrument, access class, data class, public-safe status, role separation language, boundary reviews, compatibility notes, divergence logs, routing records, mismatch records, and correction path.

456.29 Compliance and Risk Register.

456.29.1 The Compliance and Risk Register shall include legal compliance, corporate compliance, tax compliance, nonprofit compliance, charitable solicitation compliance, privacy compliance, AI governance compliance, cybersecurity compliance, research ethics compliance, employment compliance, civil rights compliance, accessibility compliance, public authority compliance, sanctions compliance, export-control compliance, competition compliance, professional boundary compliance, contract compliance, grant compliance, insurance compliance, risk items, controls, KPIs, KRIs, findings, incidents, corrective actions, and enforcement records.

456.29.2 The Register shall support Board reporting, annual compliance review, assurance, corrective action, and institutional resilience.

456.30 Correction Register.

456.30.1 The Correction Register shall include correction requests, evidence challenges, method challenges, publication challenges, safeguards grievances, public authority reference corrections, finance-boundary corrections, recognition-boundary corrections, certification-boundary corrections, procurement-boundary corrections, data corrections, AI corrections, cybersecurity corrections, repository corrections, software corrections, technical baseline corrections, public-safe corrections, controlled corrections, downstream dependency notices, supersessions, withdrawals, retractions, archive annotations, and closeout.

456.30.2 The Correction Register shall be authoritative for correction status and shall support dependency review across records, publications, repositories, dashboards, maps, technical assets, Nexus interfaces, GRF inputs, GRA inputs, Docket inputs, and Grid inputs.

456.31 Safeguards and Protected Knowledge Register.

456.31.1 The Safeguards and Protected Knowledge Register shall include civil rights reviews, accessibility reviews, community safeguards, Tribal / Indigenous reviews, protected knowledge records, public-safe mapping reviews, vulnerable population reviews, environmental justice reviews, local and territorial knowledge reviews, consent records, non-consent records, attribution records, non-attribution records, withdrawal records, restrictions, grievances, AI-use restrictions, publication restrictions, transfer restrictions, and corrections.

456.31.2 The Register shall protect communities, rights-bearing persons, Tribal / Indigenous interests, protected knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, and public-safe mapping obligations.

456.32 Record Class and Register Records.

456.32.1 The Corporation shall maintain Record Class and Register Records, including record classification purpose records, Corporate Register records, Board Register records, Member Register records where applicable, Officer Register records, Director Register records, Delegation Register records, Committee and Council Register records, Conflict Register records, Related-Party Register records, Fiscal Register records, Grant / Donation / Sponsorship / In-Kind / Fee / Support Register records, Contract Register records, Procurement Register records, Research Register records, Evidence Register records, Method Register records, Ontology and Controlled Vocabulary Register records, Data Register records, Processing Register records, Model Register records, Inference and Compute Workload Register records, Cybersecurity and Incident Register records, Technical Asset Register records, Repository Register records, Publication Register records, Public Authority Register records, Nexus Interface Register records, Compliance and Risk Register records, Correction Register records, Safeguards and Protected Knowledge Register records, register access records, register retention records, register correction records, and archive records.

Section 457. Corporate Books and Governance Records

457.1 Corporate Books Requirement.

457.1.1 The Corporation shall maintain complete, accurate, current, retrievable, access-controlled, retention-managed, and correctionable corporate books and governance records sufficient to evidence its lawful existence, nonprofit and public-benefit character, nonstock and non-share structure, legal separateness, Board authority, officer authority, delegations, policies, filings, tax posture, public-good technical role, and compliance with these Bylaws.

457.1.2 Corporate books shall be maintained in physical, digital, repository-based, database-based, ledger-compatible, or hybrid form, provided that the system of record preserves authenticity, integrity, version history, authority, metadata, confidentiality, retention, legal hold capability, and correction history.

457.1.3 Corporate books shall be treated as foundational Authoritative Records. Where corporate books conflict with informal statements, public summaries, presentations, correspondence, repository notes, event materials, AI-generated materials, or external descriptions, the corporate books shall control unless corrected by competent authority.

457.1.4 Corporate books shall preserve the Corporation’s role as a United States nonprofit, non-executing, public-good technical institution and shall not be used to imply public authority status, finance-readiness authority, certification authority, recognition authority, procurement authority, provider-selection authority, public warning authority, emergency command authority, or enterprise execution authority.

457.2 Certificate or Articles.

457.2.1 The Corporation shall maintain its certificate of incorporation, articles of incorporation, certificate of formation, charter, or equivalent formation instrument, together with any filings, receipts, acknowledgments, amendments, certificates, state confirmations, and related records.

457.2.2 The formation instrument shall be authoritative for the Corporation’s legal existence, corporate name, nonprofit character, governing jurisdiction, corporate powers, purposes, limitations, registered office or agent references where applicable, and foundational legal status.

457.2.3 No Board resolution, officer action, contract, grant, policy, public authority interface, Nexus coordination instrument, sponsor arrangement, provider arrangement, or public-facing statement shall be interpreted to override the formation instrument except through lawful amendment.

457.3 Bylaws.

457.3.1 The Corporation shall maintain the current official version of these Bylaws and all prior versions, adoption records, amendment records, effective dates, supersession records, and archive records.

457.3.2 The current official Bylaws shall be authoritative for internal governance, Board powers, officer powers, committees, records, role separation, legal compliance, public authority boundaries, finance boundaries, certification and recognition boundaries, procurement neutrality, data / AI / cyber governance, public-safe publication, Nexus coordination, validity-by-record, correctionability, indemnification, advancement, dispute resolution, and enforcement.

457.3.3 Any copy, excerpt, summary, translation, GitBook version, web version, training version, or public-facing explanation of the Bylaws shall be subordinate to the official version unless adopted as an authoritative record.

457.4 Amendments.

457.4.1 The Corporation shall maintain records of all amendments to the formation instrument, Bylaws, Board-approved charters, policies, authority matrices, and other governing instruments.

457.4.2 Amendment records shall identify approving authority, date, effective date, text amended, prior text, revised text, vote or consent, notice where required, member approval where applicable, filing requirements where applicable, implementation actions, and supersession path.

457.4.3 No amendment shall be valid unless adopted according to the governing instrument, these Bylaws, applicable law, and required approval records.

457.5 Board Resolutions.

457.5.1 The Corporation shall maintain Board resolutions as Authoritative Records of Board action.

457.5.2 Board resolutions shall identify the action approved, authority basis, date, meeting or consent method, quorum or consent status, voting result, abstentions, recusals, conditions, delegations, effective date, expiration where applicable, reporting obligations, and any required implementation record.

457.5.3 Board resolutions shall be used for material governance actions, reserved matters, officer appointments, committee creation, major contracts, major grants, major policies, annual budgets, major compliance actions, indemnification determinations, advancement determinations, public authority-sensitive matters, Nexus role-separation matters, and any other matter requiring Board authority.

457.6 Member Resolutions Where Applicable.

457.6.1 Where the Corporation has members with approval rights under applicable law, the formation instrument, or these Bylaws, the Corporation shall maintain member resolutions, written consents, notices, voting records, quorum records, class approvals, and related records.

457.6.2 Member resolutions shall be authoritative only for matters within member authority and shall not create Board authority, officer authority, public authority status, finance-readiness authority, recognition authority, certification authority, procurement authority, or enterprise execution authority beyond the governing instruments.

457.6.3 Where the Corporation has no voting members, the corporate books may include a record stating that no member resolution records are operative except as required by future amendment or applicable law.

457.7 Incorporator Records Where Applicable.

457.7.1 The Corporation shall retain incorporator records where applicable, including incorporator consents, initial director appointments, initial bylaws adoption, formation instructions, filing confirmations, resignations of incorporator authority where applicable, and related organizational actions.

457.7.2 Incorporator records shall be maintained as historical governance records and shall not be used to imply continuing authority unless continuing authority is supported by a separate record.

457.8 Registered Office Records.

457.8.1 The Corporation shall maintain current and historical registered office records required by applicable law.

457.8.2 Registered office records shall include address, effective date, change filings, state confirmations, related Board or officer approvals, and records of notices received through the registered office where applicable.

457.8.3 Changes to the registered office shall be recorded and filed where required before being represented externally as effective.

457.9 Registered Agent Records.

457.9.1 The Corporation shall maintain current and historical registered agent records, including agent name, address, consent where required, appointment records, change records, resignation records, state confirmations, and service-of-process records.

457.9.2 Registered agent records shall be monitored to ensure that legal notices, tax notices, state communications, service of process, and official correspondence are received and routed promptly.

457.9.3 Failure, resignation, nonresponse, or change of registered agent shall be escalated and corrected promptly.

457.10 Good Standing Records.

457.10.1 The Corporation shall maintain good standing records for its jurisdiction of formation and any jurisdiction in which it is registered, qualified, licensed, exempt, or otherwise required to maintain legal status.

457.10.2 Good standing records shall include certificates of good standing, status confirmations, filing receipts, renewal confirmations, deficiency notices, delinquency notices, revocation notices, reinstatement records, and corrective actions.

457.10.3 Any risk of loss of good standing shall be treated as a compliance matter requiring escalation, correction, and Board notice where material.

457.11 Annual Reports and State Filings.

457.11.1 The Corporation shall maintain annual reports, biennial reports, information statements, nonprofit filings, state registrations, foreign qualification filings, registered agent filings, officer and director updates, and other state or territorial filings required by applicable law.

457.11.2 Annual reports and filings shall be prepared from current corporate records and shall be reviewed for accuracy before submission.

457.11.3 Filings shall not misstate the Corporation’s nonprofit character, legal name, directors, officers, registered agent, principal office, public authority status, tax status, public-good role, or Nexus role.

457.12 IRS and Tax Status Records.

457.12.1 The Corporation shall maintain IRS and tax status records, including employer identification number records, federal tax classification records, tax-exempt application records where applicable, determination letters where applicable, correspondence with tax authorities, annual information returns, state tax records, local tax records where applicable, unrelated business income reviews, public support records where applicable, and tax status change records.

457.12.2 The Corporation shall not represent that it holds a particular federal, state, charitable, tax-exempt, public charity, private foundation, or other tax status unless supported by competent records.

457.12.3 Tax status records shall be coordinated with nonprofit compliance, private benefit review, restricted fund records, charitable solicitation records, grant records, and public-facing statements.

457.13 Charitable Solicitation Records Where Applicable.

457.13.1 Where charitable solicitation registration, exemption, disclosure, renewal, commercial fundraiser filing, online fundraising compliance, campaign filing, or related charitable registration is required or maintained, the Corporation shall keep complete charitable solicitation records.

457.13.2 Charitable solicitation records shall include jurisdiction, registration number where applicable, effective period, filings, renewals, disclosures, exemptions, campaign materials, fundraiser relationships, acknowledgments, donor communications, and corrective actions.

457.13.3 Solicitation records shall support accurate public statements and shall prevent donor confusion, sponsor-control implication, provider-preference implication, public authority endorsement overclaim, and purchase-of-outcome implication.

457.14 Director and Officer Registers.

457.14.1 The Corporation shall maintain Director and Officer Registers identifying current and former directors and officers, titles, terms, appointment dates, resignation or removal dates, authority scope, committee roles, delegation status, conflict disclosures, training status, contact records, indemnification status where appropriate, and insurance-related status where appropriate.

457.14.2 The Director and Officer Registers shall be used to verify governance authority, signature authority, reporting lines, fiduciary status, conflict obligations, training obligations, and access rights.

457.14.3 The Registers shall not be used to imply authority beyond the governing instruments, Board resolutions, officer delegations, or authority matrix.

457.15 Committee Charters.

457.15.1 The Corporation shall maintain charters for committees, councils, forums, working groups, panels, advisory bodies, and other standing or special bodies where constituted.

457.15.2 Committee charters shall identify name, purpose, authority, limitations, membership, chair, quorum where applicable, reporting obligations, records requirements, conflict rules, confidentiality, public authority boundary rules, finance-boundary rules, certification and recognition boundary rules, data / AI / cyber rules, safeguards requirements, and sunset or review cycle.

457.15.3 Advisory, review, and recommendation bodies shall not be treated as decision-making bodies unless the charter or Board record expressly grants decision authority.

457.16 Policies and Schedules.

457.16.1 The Corporation shall maintain approved policies, procedures, schedules, authority matrices, templates, clause libraries, retention schedules, access schedules, compliance calendars, publication matrices, data classification schedules, AI-use schedules, cybersecurity baselines, public authority reference schedules, finance-boundary language, controlled vocabulary schedules, and related governance instruments.

457.16.2 Policies and schedules shall identify approving authority, effective date, owner, custodian, review cycle, supersession path, correction path, and relationship to the Bylaws.

457.16.3 Policies and schedules shall not override the formation instrument, these Bylaws, applicable law, or Board reserved powers.

457.17 Corporate Seal, Signature, and Certification Records Where Used.

457.17.1 Where the Corporation uses a corporate seal, electronic seal, signature block, digital signature, certificate, attestation, officer certificate, secretary certificate, repository signing key, artifact signing key, or equivalent certification instrument, the Corporation shall maintain records governing its authority, custody, permitted use, access controls, and revocation.

457.17.2 Use of a seal, signature, digital signature, certificate, or attestation shall not create certification, recognition, finance-readiness, procurement approval, public authority adoption, legal compliance approval, public warning, emergency command, or professional assurance unless expressly authorized by competent record.

457.17.3 Unauthorized use of signature, seal, certificate, key, token, attestation, or signing authority shall be treated as a records, security, and authority incident.

457.18 Corporate Books Records.

457.18.1 The Corporation shall maintain Corporate Books Records, including corporate books requirement records, certificate or articles records, Bylaws records, amendment records, Board resolution records, member resolution records where applicable, incorporator records where applicable, registered office records, registered agent records, good standing records, annual reports and state filings, IRS and tax status records, charitable solicitation records where applicable, director and officer registers, committee charter records, policy and schedule records, corporate seal / signature / certification records where used, access records, retention records, correction records, and archive records.


Section 458. Board, Officer, Delegation, and Decision Records

458.1 Board Record Requirement.

458.1.1 The Corporation shall maintain Board records sufficient to evidence lawful notice, quorum, deliberation, conflict handling, approval, abstention, recusal, delegation, ratification, oversight, and decision-making.

458.1.2 Board records shall support fiduciary accountability, nonprofit compliance, public-benefit oversight, legal separateness, non-execution, public authority boundary discipline, finance-boundary discipline, certification and recognition boundary discipline, procurement neutrality, data / AI / cyber oversight, research integrity, public-safe publication, Nexus coordination, validity-by-record, and correctionability.

458.1.3 Board records shall be maintained as Authoritative Records and shall be protected against unauthorized alteration, deletion, publication, or disclosure.

458.2 Board Meeting Notices.

458.2.1 Board meeting notices shall be retained where required by law, the formation instrument, these Bylaws, Board policy, or good governance practice.

458.2.2 Notices shall identify meeting date, time, place or virtual platform, meeting type, purpose where required, special matters where required, notice method, recipients, delivery date, and any waiver of notice.

458.2.3 Notice records shall be used to validate meeting authority and shall be preserved with meeting records.

458.3 Agendas.

458.3.1 Board agendas shall identify matters for discussion, decision, oversight, reserved matter approval, conflict review, executive session, public authority-sensitive review, finance-boundary review, data / AI / cyber review, research integrity review, publication approval, or Nexus coordination review where applicable.

458.3.2 Agendas shall not themselves constitute approval unless incorporated into approved minutes, resolutions, written consents, or other competent records.

458.3.3 Agenda records shall help distinguish discussion, recommendation, decision, delegation, deferral, and action items.

458.4 Materials.

458.4.1 Board materials shall be retained where material to Board decision-making, oversight, risk review, approval, conflict review, financial review, contract approval, grant approval, policy approval, public authority interface review, finance-boundary review, technical baseline review, publication review, insurance review, indemnification review, advancement review, or enforcement action.

458.4.2 Board materials shall be classified by confidentiality, privilege, public authority sensitivity, finance sensitivity, data sensitivity, cyber sensitivity, protected knowledge sensitivity, and public-safe status.

458.4.3 Draft Board materials shall not be treated as Board action unless adopted by resolution, minutes, written consent, or other authoritative record.

458.5 Minutes.

458.5.1 Minutes shall be prepared for Board meetings and shall record date, time, location or virtual method, attendees, absences, quorum, presiding officer, matters considered, actions taken, votes, abstentions, recusals, conflicts, executive sessions where appropriate, resolutions, delegations, reports received, and action items.

458.5.2 Minutes shall be accurate, clear, sufficient to evidence lawful action, and not so detailed as to compromise privilege, confidentiality, security, or sensitive deliberation without need.

458.5.3 Minutes shall be approved according to Board practice and retained as Authoritative Records once approved.

458.5.4 Corrections to minutes shall preserve the original version, correction authority, correction date, reason, and corrected text.

458.6 Attendance.

458.6.1 Attendance records shall identify directors present, directors absent, officers present, invited participants, counsel, advisors, committee representatives, public authority participants, sponsor or provider participants where applicable, and any persons present for only part of a meeting.

458.6.2 Attendance shall not create voting rights, decision authority, approval authority, public authority endorsement, sponsor control, provider preference, certification, recognition, finance-readiness, or procurement implication.

458.6.3 Attendance by non-directors shall be classified by role and capacity where material.

458.7 Quorum.

458.7.1 Board records shall identify whether quorum was present for each meeting and, where necessary, for each action.

458.7.2 Actions taken without required quorum shall not be treated as valid Board action unless later ratified or otherwise cured according to applicable law and these Bylaws.

458.7.3 Quorum records shall account for recusals, conflicts, vacancies, remote participation, and applicable law.

458.8 Votes.

458.8.1 Vote records shall identify the action voted on, voting body, voting method, voting result, and any required threshold.

458.8.2 Where required or appropriate, vote records shall identify directors voting for, against, abstaining, or recused.

458.8.3 Vote records shall distinguish approval, rejection, deferral, authorization to negotiate, authorization to execute, conditional approval, and non-binding direction.

458.9 Abstentions.

458.9.1 Abstentions shall be recorded where material to quorum, approval threshold, conflict management, fiduciary accountability, or Board interpretation.

458.9.2 Abstention shall not be treated as approval unless applicable law or governing documents so provide.

458.9.3 Abstention records may identify whether abstention was voluntary, conflict-related, information-related, or otherwise stated.

458.10 Recusals.

458.10.1 Recusals shall be recorded where a director, officer, committee member, or participant is excluded from deliberation or vote because of conflict, related-party interest, sponsor relationship, provider relationship, public authority relationship, financial interest, personal interest, confidentiality restriction, or other reason.

458.10.2 Recusal records shall identify the matter, person recused, basis, scope, time of departure or nonparticipation where applicable, and whether the person returned after the matter.

458.10.3 Recusal shall be used to preserve fiduciary integrity, research independence, public-good independence, sponsor non-control, provider neutrality, procurement neutrality, and public trust.

458.11 Resolutions.

458.11.1 Resolutions shall state the approved action with sufficient precision to determine authority, scope, conditions, effective date, delegation, limitations, reporting requirements, and record owner.

458.11.2 Resolutions involving public authority interfaces, finance-boundary matters, public-good technical assets, data / AI / cyber systems, protected knowledge, major contracts, grants, insurance, indemnification, advancement, litigation, or enforcement shall include limitation language where needed.

458.11.3 Resolutions shall not be interpreted to authorize activity beyond their text and context.

458.12 Written Consents.

458.12.1 Written consents shall be retained where Board action is taken without a meeting.

458.12.2 Written consent records shall identify the approving directors, action approved, effective date, consent date, delivery method, unanimity or threshold where applicable, and related materials.

458.12.3 Written consents shall have the effect permitted by applicable law and governing instruments and shall be included in the corporate minute book or equivalent governance record system.

458.13 Reserved Matter Records.

458.13.1 Reserved Matter Records shall be maintained for matters requiring Board approval or approval by a specified body, including amendments, major contracts, major grants, budgets, borrowing where applicable, material indemnities, litigation, tax status matters, public authority-sensitive matters, finance-boundary-sensitive matters, public-good technical asset strategy, major policies, major publications, insurance, indemnification, advancement, and dissolution matters.

458.13.2 Reserved Matter Records shall identify why the matter was reserved, approving authority, approval conditions, and implementation owner.

458.14 Officer Appointment Records.

458.14.1 Officer appointment records shall identify officer name, title, appointing authority, appointment date, term where applicable, duties, authority, reporting line, signature authority, limitations, compensation status where applicable, and resignation or removal.

458.14.2 Officer appointment shall not confer authority beyond the Bylaws, Board resolutions, delegations, authority matrix, and applicable law.

458.15 Delegation Records.

458.15.1 Delegation records shall identify delegating authority, delegate, scope, limits, term, amount threshold, subject matter, prohibited matters, required approvals, reporting duties, revocation path, and effective date.

458.15.2 Delegation records shall be required for contract authority, spending authority, publication authority, public authority communications, data access approvals, AI-use approvals, repository approvals, controlled-room approvals, public-safe corrections, and other material authority where not reserved to the Board.

458.15.3 Delegations shall be reviewed periodically and may be suspended, narrowed, or revoked.

458.16 Authority Matrix Records.

458.16.1 The Corporation may maintain Authority Matrix Records identifying who may approve, sign, publish, release, access, spend, contract, hire, terminate, refer, correct, restrict, or escalate matters by role, threshold, risk class, and subject matter.

458.16.2 The Authority Matrix shall distinguish Board authority, officer authority, committee authority, advisory authority, technical maintainer authority, publication authority, public authority reference authority, data authority, AI authority, cybersecurity authority, repository authority, and controlled-room authority.

458.16.3 Authority Matrix Records shall prevent apparent authority and shall be updated when roles, officers, delegations, risk thresholds, or governance structure change.

458.17 Emergency Decision Records.

458.17.1 Emergency Decision Records shall be maintained where urgent action is taken to protect legal rights, public safety, data security, cybersecurity, privacy, protected knowledge, public authority boundaries, finance boundaries, public-safe publication, records, insurance rights, or compliance deadlines.

458.17.2 Emergency Decision Records shall identify trigger, decision-maker, authority basis, action taken, time, reason, affected records, interim nature, required ratification, required notice, and closeout.

458.17.3 Emergency authority shall be interpreted narrowly and shall be subject to ratification, review, sunset, and correction.

458.18 Ratification Records.

458.18.1 Ratification Records shall be maintained where the Board or authorized body ratifies, modifies, rejects, limits, or cures a prior act, emergency decision, unauthorized act, defective approval, missing record, or procedural irregularity.

458.18.2 Ratification shall identify the act ratified, authority basis, reason, limitations, effective date, legal review where appropriate, and any corrective action.

458.18.3 Ratification shall not validate conduct that cannot lawfully be ratified, including unlawful conduct, prohibited private benefit, prohibited public authority delegation, prohibited regulated financial activity, or conduct contrary to public policy.

458.19 Action Item Records.

458.19.1 Action Item Records shall identify tasks arising from Board, officer, committee, compliance, incident, audit, grant, publication, public authority, data / AI / cyber, or Nexus coordination decisions.

458.19.2 Action Item Records shall include owner, due date, status, dependency, required record, escalation point, and closeout.

458.19.3 Open action items involving legal compliance, public authority boundaries, finance boundaries, data / AI / cyber risk, protected knowledge, public-safe publication, or filings shall be monitored until completion.

458.20 Decision Records.

458.20.1 Decision Records shall document material decisions by the Board, officers, committees, delegated authorities, technical custodians, publication authorities, data authorities, AI authorities, cybersecurity authorities, controlled-room authorities, and compliance authorities.

458.20.2 Decision Records shall identify decision, authority, rationale, record basis, alternatives where material, limitations, affected records, public-safe status, implementation owner, correction path, and review cycle.

458.20.3 The Corporation shall maintain Decision Records, including Board record requirement records, meeting notice records, agenda records, materials records, minutes, attendance records, quorum records, vote records, abstention records, recusal records, resolution records, written consent records, reserved matter records, officer appointment records, delegation records, authority matrix records, emergency decision records, ratification records, action item records, decision records, corrections, and archive records.


Section 459. Research, Evidence, Methods, Ontology, and Technical Truth Records

459.1 Research Record Requirement.

459.1.1 The Corporation shall maintain Research Records sufficient to evidence the purpose, authority, integrity, ethics, methods, data, sources, analysis, review, limitations, conflicts, public-safe status, correctionability, and technical truth basis of research conducted or supported by the Corporation.

459.1.2 Research Records shall apply to public-good R&D, evidence work, methods work, observability work, ontology work, public-good software research, open technical baseline research, verifiable compute and intelligence work, public authority learning support, Nexus Truth Engine methods, Nexus Observatory methods, and all exponential-technology domains within the Corporation’s mission.

459.1.3 Research Records shall distinguish research, evidence, methods, public-safe summaries, public authority learning materials, GRA-facing technical inputs, GRF-facing technical inputs, Docket inputs, Grid inputs, and public claims.

459.2 Research Protocols.

459.2.1 Research protocols shall identify research purpose, research question, public-benefit rationale, methods, data sources, participant involvement where applicable, ethics review status, safeguards review status, data classification, AI-use plan, cybersecurity controls, publication plan, limitations, review plan, correction path, and responsible owner.

459.2.2 Protocols shall be required for material research activities and shall be proportionate to risk, public authority exposure, data sensitivity, human-subjects involvement, protected knowledge, biosecurity sensitivity, public health sensitivity, AI use, cyber sensitivity, and public-safe publication risk.

459.2.3 Research shall not proceed beyond approved scope where protocol approval or review is required.

459.3 Ethics Review Records.

459.3.1 Ethics Review Records shall document ethical review of research or evidence activities where required or appropriate.

459.3.2 Ethics Review Records shall identify reviewer or review body, protocol reviewed, risk assessment, participant protections, consent requirements, privacy controls, data minimization, public-safe publication controls, community safeguards, protected knowledge restrictions, AI-use controls, conflict review, conditions, approval, denial, deferral, or required modifications.

459.4 IRB or Equivalent Review Records Where Applicable.

459.4.1 Institutional Review Board or equivalent review records shall be maintained where human-subjects research or analogous review is required by law, institutional requirement, grant term, public authority requirement, ethical standard, contract, or policy.

459.4.2 Records shall include submissions, determinations, approvals, exemptions where applicable, continuing review, adverse event reporting, amendments, consent forms, recruitment materials, participant communications, withdrawal records, and closeout.

459.4.3 No activity shall avoid IRB or equivalent review by being labeled observability, learning, technical support, dashboarding, or public authority support where review is required.

459.5 Community, Tribal / Indigenous, Local, Territorial, Cultural, Environmental, and Protected Knowledge Review Records.

459.5.1 The Corporation shall maintain review records where research, evidence, mapping, observability, publication, AI processing, dashboarding, or technical work involves community-protected knowledge, Tribal / Indigenous knowledge, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, ecological knowledge, sacred knowledge, sensitive locations, vulnerable communities, or protected knowledge.

459.5.2 Such records shall identify permission, non-permission, consent, non-consent, attribution, non-attribution, withdrawal rights where applicable, restrictions, access class, AI-use limits, mapping limits, publication limits, transfer limits, grievance pathways, and correction path.

459.5.3 Protected knowledge records shall be access-controlled and shall not expose the protected knowledge through the record system itself.

459.6 Source Records.

459.6.1 Source Records shall identify source origin, source authority, source date, source custodian, source classification, license or permission, reliability status, access restrictions, citation requirements, permitted use, prohibited use, public-safe status, and correction path.

459.6.2 Source Records shall be required for material evidence, datasets, public claims, reports, dashboards, maps, models, technical baselines, software outputs, public authority learning materials, and Nexus interface outputs.

459.6.3 Unverified, disputed, restricted, anonymous, AI-generated, or synthetic sources shall be labeled and handled according to risk.

459.7 Dataset Records.

459.7.1 Dataset Records shall identify dataset name, owner, custodian, source, authority, license, version, data classes, data subjects or rights-bearing persons where applicable, geography, time period, collection method, transformations, quality status, missingness, limitations, permitted use, prohibited use, AI-use restrictions, publication restrictions, retention, deletion, access controls, and correction path.

459.7.2 Dataset Records shall distinguish raw, cleaned, derived, synthetic, aggregated, anonymized, de-identified, restricted, public-safe, archived, and withdrawn datasets.

459.7.3 Dataset Records shall be linked to dataset cards where appropriate.

459.8 Evidence Records.

459.8.1 Evidence Records shall identify evidence item, source lineage, authority, provenance, method used, data quality, reviewer status, confidence, uncertainty, limitations, classification, access class, public-safe status, permitted use, prohibited use, affected outputs, and correction path.

459.8.2 Evidence Records shall distinguish evidence from opinion, recognition, finance-readiness, certification, procurement approval, public authority decision, public warning, emergency command, and legal compliance approval.

459.8.3 Evidence Records shall be required before material evidence is used in public claims, public-safe summaries, technical baselines, public authority learning materials, GRF-facing inputs, GRA-facing inputs, Docket inputs, Grid inputs, or Nexus interface outputs.

459.9 Confidence and Uncertainty Records.

459.9.1 Confidence and Uncertainty Records shall document confidence level, uncertainty sources, sensitivity, assumptions, data gaps, method limitations, known unknowns, temporal limits, geographic limits, population limits, technology-domain limits, and interpretation limits.

459.9.2 Confidence and uncertainty shall be recorded for material evidence, dashboards, maps, forecasts, simulations, AI outputs, digital twins, observability outputs, public-safe summaries, technical baselines, and public claims.

459.9.3 Unsupported confidence claims shall be corrected.

459.10 Source Lineage and Provenance Records.

459.10.1 Source Lineage and Provenance Records shall identify origin, chain of custody, transformations, derivations, contributors, systems, methods, models, compute environments, repositories, timestamps, version history, and correction history.

459.10.2 Provenance Records shall support reproducibility where appropriate, auditability, verifiable compute, proof receipts, public-safe publication, technical truth, and downstream correction.

459.10.3 Provenance gaps shall be disclosed where material.

459.11 Method Records.

459.11.1 Method Records shall document methods used by the Corporation, including purpose, scope, inputs, outputs, assumptions, limitations, required data quality, review status, validation status where applicable, known issues, applicable domains, non-applicable domains, public-safe status, and correction path.

459.11.2 Methods shall be recorded for material research, evidence, observability, ontology, AI evaluation, benchmark, dashboard, map, proof receipt, public authority learning, technical baseline, and Nexus interface outputs.

459.12 Method Version Records.

459.12.1 Method Version Records shall identify current version, prior versions, effective date, supersession date, deprecated status, changes, rationale, affected outputs, migration notes, and correction obligations.

459.12.2 Use of outdated methods shall be recorded, justified, or corrected where material.

459.12.3 Method version changes shall trigger downstream dependency review where public claims, technical baselines, dashboards, maps, public authority learning, GRF inputs, GRA inputs, Docket inputs, or Grid inputs are affected.

459.13 Ontology Records.

459.13.1 Ontology Records shall document controlled concepts, taxonomies, schemas, relationships, identifiers, domain mappings, interoperability mappings, localization notes, translation notes, public-safe meaning, boundary meaning, and correction history.

459.13.2 Ontology Records shall support semantic interoperability across GCRI US, GCRI Canada, GRF, GRA, Nexus Standards, Nexus Network, Nexus Observatory, Nexus Universe, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, consortiums, public authorities, and enterprise stack interfaces.

459.14 Controlled Vocabulary Records.

459.14.1 Controlled Vocabulary Records shall define permitted, restricted, and prohibited terms for evidence, methods, technical truth, verification, validation, public-safe status, recognition, standing, maturity, finance-readiness, capital-readability, insurance-readiness, certification, accreditation, conformance, compliance, procurement, public authority status, observer status, regulator-listening status, public finance reader status, Docket, Grid, Nexus-compatible, and related terms.

459.14.2 Controlled Vocabulary Records shall be used to prevent semantic drift, public authority confusion, finance reliance, certification overclaim, recognition overclaim, procurement implication, provider preference, and public warning confusion.

459.14.3 Public-facing materials shall use controlled vocabulary where material.

459.15 Observability Records.

459.15.1 Observability Records shall document observability methods, node records, hub records, cluster records, hotspot records, regional cluster records, national dense Nexus core records, sensor records, AI-RAN / O-RAN records, DePIN records, DLT records, digital twin records, cyber telemetry records, geospatial records, Earth observation records, edge compute records, dashboard records, degraded-mode awareness records, public-safe output records, and correction paths.

459.15.2 Observability Records shall distinguish technical observation from public warning, emergency command, public authority decision, finance-readiness, certification, recognition, procurement approval, rating, or provider preference.

459.16 Truth Engine Methods Records.

459.16.1 Truth Engine Methods Records shall document methods, evidence rules, inference rules, confidence logic, limitation logic, source weighting where applicable, contradiction handling, correction logic, AI-use restrictions, reviewer requirements, and public-safe output controls used in or in support of Nexus Truth Engine methods.

459.16.2 Truth Engine Methods Records shall not be represented as automatic truth, public authority decision, finance-readiness, certification, recognition, procurement approval, public warning, or emergency command.

459.17 Peer Review Records.

459.17.1 Peer Review Records shall document peer review where required or appropriate, including reviewer identity or anonymized status, reviewer qualification basis, independence, conflict status, review scope, materials reviewed, findings, dissent, limitations, recommendations, and resolution.

459.17.2 Peer review shall not be overstated as certification, public authority approval, legal compliance approval, finance-readiness, recognition, or guarantee.

459.18 Reviewer Notes.

459.18.1 Reviewer Notes shall be retained where material to evidence integrity, method integrity, publication approval, technical baseline approval, dataset release, model evaluation, public authority learning material, or correction.

459.18.2 Reviewer Notes may be confidential, privileged, controlled, or restricted and shall be access-controlled according to classification.

459.18.3 Reviewer Notes shall preserve dissent, limitation, uncertainty, and unresolved concerns where material.

459.19 Research Conflict Records.

459.19.1 Research Conflict Records shall document conflicts involving researchers, reviewers, sponsors, providers, funders, hosts, public authorities, universities, laboratories, communities, capital actors, enterprise stack actors, and other participants.

459.19.2 Conflict records shall identify disclosure, review, recusal, mitigation, public-safe disclosure where required, and correction.

459.19.3 Undisclosed or unmanaged conflicts affecting research outputs shall trigger correction or misconduct review where material.

459.20 Research Misconduct Records.

459.20.1 Research Misconduct Records shall document allegations, intake, triage, investigation, interim measures, findings, corrective action, publication holds, dataset holds, method holds, retractions, withdrawals, referrals, and closeout for alleged or confirmed research misconduct, evidence misconduct, method misuse, technical truth misrepresentation, fabrication, falsification, plagiarism, improper source omission, unsupported confidence claim, limitation suppression, sponsor distortion, provider distortion, or AI-generated fabrication.

459.20.2 Research Misconduct Records shall be confidential or restricted where appropriate and shall preserve due process, non-retaliation, privilege, and public-safe correction.

459.21 Technical Truth Records.

459.21.1 Technical Truth Records shall document the record basis for material technical truth statements made or supported by the Corporation, including source records, evidence records, method records, reviewer records, confidence records, uncertainty records, limitation records, public-safe review, controlled vocabulary records, and correction records.

459.21.2 Technical Truth Records shall not convert technical truth into legal truth, public authority decision, professional advice, finance-readiness, certification, recognition, procurement approval, public warning, emergency command, rating, or guarantee.

459.21.3 The Corporation shall maintain Research, Evidence, Methods, Ontology, and Technical Truth Records, including research requirement records, protocol records, ethics review records, IRB or equivalent review records where applicable, community / Tribal / Indigenous / local / territorial / cultural / environmental / protected knowledge review records, source records, dataset records, evidence records, confidence and uncertainty records, source lineage and provenance records, method records, method version records, ontology records, controlled vocabulary records, observability records, Truth Engine Methods Records, peer review records, reviewer notes, research conflict records, research misconduct records, technical truth records, corrections, and archive records.


Section 460. Data, AI, Cybersecurity, Privacy, Verifiable Compute, and Controlled-Room Records

460.1 Data Governance Records.

460.1.1 The Corporation shall maintain Data Governance Records sufficient to evidence lawful basis, authority, permission, consent where required, classification, access control, data stewardship, use limitation, retention, deletion, transfer control, public-safe publication, AI-use restriction, correctionability, and compliance with applicable privacy, cybersecurity, public authority, research, protected knowledge, and contractual requirements.

460.1.2 Data Governance Records shall apply to public data, public-safe data, internal data, confidential data, restricted data, rights-bearing data, personal information, sensitive personal information, health-sensitive data, public authority data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, research-sensitive data, community-protected data, Tribal / Indigenous data, protected knowledge data, controlled technology data, export-controlled data, and archived data.

460.2 Data Inventory.

460.2.1 The Corporation shall maintain a Data Inventory identifying material datasets, data sources, data owners, data custodians, data contributors, data users, systems, repositories, locations, data classes, sensitivity, authority, permitted uses, prohibited uses, AI-use restrictions, publication restrictions, retention, deletion, and correction path.

460.2.2 The Data Inventory shall support lawful processing, privacy by design, access control, public-safe publication, public authority data protection, protected knowledge protection, and cross-border transfer review.

460.3 Data Processing Records.

460.3.1 Data Processing Records shall document processing purposes, lawful basis, authority, systems, processors, subprocessors, recipients, transfers, retention, deletion, security controls, AI use, publication use, rights handling where applicable, and incident history.

460.3.2 Processing Records shall be maintained for material processing activities and for processing involving personal information, sensitive data, public authority data, health-sensitive data, rights-bearing data, protected knowledge, AI systems, or cross-border transfers.

460.4 Lawful Basis Records.

460.4.1 Lawful Basis Records shall identify the legal, contractual, ethical, public authority, research, consent-based, permission-based, license-based, or other competent basis for collection, receipt, storage, processing, analysis, publication, transfer, retention, deletion, AI use, and correction of data.

460.4.2 Where lawful basis is absent, unclear, expired, withdrawn, disputed, or incomplete, data shall be restricted until authority is clarified.

460.4.3 Lawful Basis Records shall be interpreted according to the most restrictive applicable rule where multiple jurisdictions, data classes, permissions, or safeguards apply.

460.5.1 Permission and Consent Records shall document consent where required, permission where applicable, non-consent, refusal, withdrawal, limitation, attribution, non-attribution, permitted use, prohibited use, publication permission, mapping permission, AI-use permission, transfer permission, retention permission, and correction requests.

460.5.2 Consent and permission records shall be clear, specific, recorded, revocable where applicable, and linked to affected data, outputs, publications, dashboards, maps, models, and repositories where material.

460.5.3 Withdrawal or restriction shall trigger access review, use review, publication review, AI-use review, downstream dependency review, and correction where required.

460.6 Data Classification Records.

460.6.1 Data Classification Records shall identify classification, sensitivity, access class, confidentiality status, public-safe status, AI-use status, publication status, transfer status, retention class, and correction path.

460.6.2 Data Classification Records shall distinguish public, public-safe, internal, confidential, restricted, controlled, public authority, rights-bearing, personal, sensitive personal, health-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, research-sensitive, community-protected, Tribal / Indigenous, protected knowledge, controlled technology, export-controlled, sanctions-sensitive, youth data, sealed, and archived data.

460.6.3 Reclassification shall be recorded with authority, reason, effective date, affected access rights, affected outputs, and correction obligations.

460.7 Access Records.

460.7.1 Access Records shall identify who may access data, systems, repositories, models, rooms, dashboards, maps, publications, technical assets, and proof objects, for what purpose, under what authority, for what duration, and subject to what restrictions.

460.7.2 Access Records shall distinguish view, edit, approve, download, export, transfer, publish, map, train, fine-tune, embed, retrieve, share, archive, and administrative access.

460.7.3 Access Records shall be least-privilege, classification-aware, purpose-limited, revocable, and reviewed periodically where risk requires.

460.7.4 Access without record support shall be restricted or revoked.

460.8 Public Authority Data Records.

460.8.1 Public Authority Data Records shall document authority, capacity, data contribution agreement where appropriate, dataset description, permitted use, prohibited use, classification, confidentiality, AI-use restrictions, publication restrictions, retention, deletion, transfer restrictions, public records considerations, correction rights, withdrawal rights where applicable, and public-safe review.

460.8.2 Public Authority Data Records shall prevent unauthorized publication, unauthorized AI use, public authority overclaim, procurement implication, public warning confusion, emergency command confusion, and improper disclosure.

460.9 Health-Sensitive Data Records.

460.9.1 Health-Sensitive Data Records shall document authority, lawful basis, consent where required, privacy classification, health sensitivity, public health context where applicable, participant protection, permitted use, prohibited use, AI-use restrictions, publication restrictions, de-identification or aggregation where applicable, retention, deletion, breach notification assessment, and correction path.

460.9.2 Health-sensitive data shall not be used for unauthorized AI training, public mapping, public warning, clinical guidance, public health order, finance-readiness input, provider benefit, sponsor benefit, or public-safe publication beyond recorded authority.

460.10 Cyber-Sensitive and Infrastructure-Sensitive Data Records.

460.10.1 Cyber-Sensitive and Infrastructure-Sensitive Data Records shall document data concerning vulnerabilities, threat intelligence, incident artifacts, network architecture, telecom infrastructure, AI-RAN / O-RAN systems, energy systems, water systems, food systems, ports, transportation, public safety systems, public health systems, digital twins, geospatial layers, operational technology, industrial systems, and other sensitive infrastructure.

460.10.2 Such records shall include classification, access limits, publication restrictions, AI-use restrictions, mapping restrictions, transfer restrictions, security controls, public-safe review, and incident response path.

460.10.3 Cyber-sensitive or infrastructure-sensitive data shall not be disclosed in a manner that enables targeting, exploitation, disruption, evasion, public panic, or operational harm.

460.11 Community-Protected and Protected Knowledge Data Records.

460.11.1 Community-Protected and Protected Knowledge Data Records shall document community-protected, Tribal / Indigenous, local, territorial, cultural, environmental, ecological, sacred, sensitive site, and other protected knowledge data.

460.11.2 Records shall identify permission, non-permission, consent, non-consent, attribution, non-attribution, withdrawal, restriction, access class, AI-use restriction, mapping restriction, publication restriction, transfer restriction, commercialization restriction, grievance pathway, and correction path.

460.11.3 These records shall be maintained in a manner that protects the protected knowledge itself and shall not expose sensitive content through metadata, summaries, maps, embeddings, or public-safe notices.

460.12 Cross-Border Transfer Records.

460.12.1 Cross-Border Transfer Records shall document transfers, access, storage, processing, publication, cloud-region use, remote access, repository access, model access, technical assistance, or controlled-room participation involving data, software, models, source code, technical materials, or protected knowledge across jurisdictions.

460.12.2 Records shall include sending jurisdiction, receiving jurisdiction, lawful basis, transfer mechanism, data class, public authority restrictions, privacy review, cybersecurity review, export-control review, sanctions review, controlled technology review, protected knowledge review, localization requirements, onward transfer restrictions, and correction path.

460.12.3 Where transfer authority is unclear or insufficient, transfer shall be denied, delayed, localized, anonymized, aggregated, controlled-roomed, or otherwise restricted.

460.13 Model Register Records.

460.13.1 Model Register Records shall identify each material AI system or model used by or for the Corporation, including model identity, version, provider, owner, custodian, purpose, permitted uses, prohibited uses, risk class, data access, deployment context, evaluation record, known limitations, monitoring status, incident history, retirement status, and correction path.

460.13.2 Model Register Records shall include AI systems used for drafting, summarization, coding, analysis, classification, inference, research, public-safe review, observability, dashboards, maps, public authority learning, technical asset development, cybersecurity, and controlled-room support where material.

460.13.3 No model shall be used for material public-facing, public authority-facing, finance-facing, recognition-facing, certification-facing, or safeguards-sensitive outputs without required records and human review.

460.14 Dataset Card, Model Card, System Card, Benchmark Card, and Evaluation Harness Records.

460.14.1 Dataset Card Records shall describe dataset origin, purpose, composition, collection method, authority, consent or permission, limitations, quality, bias risks, privacy risks, public authority restrictions, protected knowledge restrictions, AI-use restrictions, and recommended uses.

460.14.2 Model Card Records shall describe model purpose, provider, version, capabilities, limitations, evaluation results, risk class, permitted uses, prohibited uses, human review requirements, incident history, and correction path.

460.14.3 System Card Records shall describe AI or technical system architecture, components, data flows, human oversight, access controls, safeguards, limitations, monitoring, incident response, and public-safe boundaries.

460.14.4 Benchmark Card Records shall describe benchmark purpose, scope, dataset, evaluation method, limitations, known biases, version, intended uses, prohibited uses, and correction path.

460.14.5 Evaluation Harness Records shall document test harnesses, gold vectors, negative tests, evaluation workflows, scoring logic, limitations, version, reviewer status, and correction path.

460.15 Inference Records.

460.15.1 Inference Records shall be maintained for material AI outputs, including input record, authority record, model record, system or tool record, prompt or workflow record where appropriate, execution timestamp, output, reviewer, confidence, limitations, classification, public-safe status, permitted use, prohibited use, and correction path.

460.15.2 Inference Records shall be required where AI output materially informs evidence, research, public claims, public authority learning, publications, dashboards, maps, technical baselines, software releases, controlled-room outputs, GRA-facing inputs, GRF-facing inputs, Docket inputs, Grid inputs, or Nexus interface outputs.

460.15.3 Inference Records shall not be treated as proof of truth, public authority decision, finance-readiness, certification, recognition, procurement approval, public warning, emergency command, or professional advice.

460.16 Compute Workload Records.

460.16.1 Compute Workload Records shall document material compute tasks, including purpose, authority, input data, environment, code, model, tool, workflow, compute provider, jurisdiction or region where material, execution parameters, output, reviewer, classification, proof receipt where applicable, and correction path.

460.16.2 Compute Workload Records shall support verifiable compute, auditability, source lineage, reproducibility where appropriate, security, public authority data protection, protected knowledge protection, and correctionability.

460.16.3 Compute Workload Records shall be required where compute outputs materially affect public-safe publications, dashboards, maps, evidence packs, models, technical baselines, public authority learning, or Nexus interface outputs.

460.17 Proof Receipt Records.

460.17.1 Proof Receipt Records shall document proof receipts issued, relied upon, linked, restricted, annotated, corrected, or withdrawn by the Corporation.

460.17.2 Proof Receipt Records shall identify subject, issuer, source references, authority references, method references, data references, model or system references where applicable, compute or inference references where applicable, timestamp, hash or tamper-evidence reference where appropriate, access class, limitation statement, confidence statement, public-safe status, and correction path.

460.17.3 Proof Receipt Records shall not be treated as certification, recognition, finance-readiness, procurement approval, public authority decision, rating, public warning, emergency command, legal compliance approval, or guarantee.

460.18 Cybersecurity Logs and Incident Records.

460.18.1 Cybersecurity Logs and Incident Records shall include access logs where appropriate, authentication records, administrative action records, repository logs, cloud logs, endpoint logs, network logs, vulnerability records, scanning records, SBOM records where appropriate, artifact signing records where appropriate, secrets scanning records, incident reports, severity classifications, containment actions, key rotation records, token revocation records, forensic records where applicable, notification assessments, remediation records, root cause reviews, and closeout.

460.18.2 Cybersecurity logs shall be retained according to risk, legal requirements, contracts, public authority restrictions, privacy rules, incident response needs, and records policy.

460.18.3 Cybersecurity logs shall be access-controlled and shall not be publicly disclosed where disclosure would expose vulnerabilities, systems, identities, infrastructure, public authority data, or protected knowledge.

460.19 Controlled-Room, Clean-Room, Data-Room, Evidence-Room, Public Authority Room, and No-Download Room Records.

460.19.1 Room Records shall be maintained for controlled rooms, clean rooms, data rooms, evidence rooms, public authority rooms, regulator-listening rooms, public finance reader rooms, emergency learning rooms, and no-download rooms.

460.19.2 Room Records shall include room charter, purpose, owner, custodian, admission criteria, participant screening, capacity classification, conflict review, confidentiality terms, competition controls, public authority boundary controls, finance boundary controls, data / AI / cyber / privacy controls, protected knowledge controls, no-download rules, AI-use restrictions, exhibit records, access logs where appropriate, room outputs, publication controls, closeout, and correction path.

460.19.3 Room participation shall not constitute endorsement, adoption, approval, funding, procurement, public finance approval, regulatory guidance, public warning, emergency command, sovereign obligation, recognition, finance-readiness, certification, provider preference, or public authority decision.

460.20 Data, AI, Cybersecurity, Privacy, Compute, and Room Records.

460.20.1 The Corporation shall maintain Data, AI, Cybersecurity, Privacy, Compute, and Room Records, including data governance records, Data Inventory records, processing records, lawful basis records, permission and consent records, data classification records, access records, public authority data records, health-sensitive data records, cyber-sensitive and infrastructure-sensitive data records, community-protected and protected knowledge data records, cross-border transfer records, Model Register Records, dataset card / model card / system card / benchmark card / evaluation harness records, inference records, compute workload records, proof receipt records, cybersecurity logs and incident records, controlled-room / clean-room / data-room / evidence-room / public authority room / no-download room records, corrections, restrictions, holds, deletions, retention records, access reviews, and archive records.

Section 461. Public-Good Software, Technical Asset, IP, Repository, and Release Records

461.1 Technical Asset Register Records.

461.1.1 The Corporation shall maintain Technical Asset Register Records for each material public-good technical asset created, adopted, stewarded, maintained, released, restricted, deprecated, withdrawn, archived, or otherwise controlled by the Corporation.

461.1.2 Technical Asset Register Records shall identify asset identifier, asset name, asset class, owner, steward, maintainer, repository location, version, license, release status, public-safe status, confidentiality status, security status, dependency status, vulnerability status, export-control or controlled-technology status where applicable, data / AI / cyber / privacy status, community safeguards and protected knowledge status, Nexus interface status, correction path, deprecation status, retirement status, and archive status.

461.1.3 Technical Asset Register Records shall apply to public-good software, open technical baselines, reference architectures, schemas, APIs, SDKs, technical profiles, interoperability interfaces, dashboards, maps, model cards, dataset cards, system cards, benchmark cards, evaluation harnesses, test harnesses, gold vectors, negative tests, benchmark libraries, ontologies, controlled vocabularies, data dictionaries, proof receipt tools, verifiable compute methods, verifiable intelligence methods, and related technical memory assets.

461.1.4 No technical asset shall be represented as current, released, public-safe, Nexus-compatible, approved, recognized, certified, finance-ready, procurement-ready, public authority-adopted, or operationally validated unless the Technical Asset Register Record supports that exact status.

461.2 Public-Good Software Records.

461.2.1 The Corporation shall maintain Public-Good Software Records for software developed, contributed to, maintained, released, restricted, archived, or referenced by the Corporation as public-good infrastructure.

461.2.2 Public-Good Software Records shall include software purpose, public-benefit function, repository, owner, maintainer, contributor history, license, version, documentation, release notes, changelog, known issues, known limitations, dependency profile, secure development records, vulnerability records, public-safe use guidance, access class, correction path, and deprecation path.

461.2.3 Public-Good Software Records shall distinguish software as public-good technical support from certification, procurement approval, public authority adoption, provider preference, finance-readiness, recognition, rating, public warning, emergency command, or operational guarantee.

461.2.4 Software outputs, scripts, dashboards, AI-assisted tools, proof receipt tools, observability tools, and public authority learning tools shall not be treated as official truth or operational command unless competent records expressly authorize the applicable limited use and required human review has occurred.

461.3 Open Technical Baseline Records.

461.3.1 The Corporation shall maintain Open Technical Baseline Records for each baseline adopted, maintained, released, superseded, withdrawn, or archived by the Corporation.

461.3.2 Open Technical Baseline Records shall identify baseline name, baseline identifier, scope, owner, custodian, version, effective date, review cycle, public-safe status, limitation statement, interoperability function, evidence quality function, data governance function, AI governance function, cybersecurity function, observability function, public authority learning function, Nexus compatibility support function, known limitations, correction path, supersession path, deprecation path, and archive status.

461.3.3 Open Technical Baseline Records shall expressly preserve that a baseline is a public-good reference material and does not by itself constitute certification, procurement mandate, legal compliance approval, provider preference, public authority adoption, recognition, finance-readiness, rating, public warning, emergency command, or operational assurance.

461.4 Reference Architecture Records.

461.4.1 The Corporation shall maintain Reference Architecture Records for non-executing design support materials involving observability, AI-RAN / O-RAN, DePIN, DLT, digital twins, cyber telemetry, geospatial systems, Earth observation, edge compute, sovereign compute, verifiable compute, public authority learning, data rooms, controlled rooms, Nexus Hubs, Nexus Clusters, Nexus Hotspots, Regional Clusters, National Dense Nexus Cores, and related exponential-technology infrastructure.

461.4.2 Reference Architecture Records shall identify architecture purpose, scope, assumptions, components, interface boundaries, security assumptions, data assumptions, AI assumptions, public authority boundary language, finance-boundary language, public-safe status, version, reviewer status, known limitations, permitted uses, prohibited uses, correction path, and supersession path.

461.4.3 Reference Architecture Records shall state that reference architectures are non-executing design support and shall not be treated as engineering certification, procurement specification mandate, public authority adoption, compliance approval, operational approval, finance-readiness, recognition, provider preference, public warning, or emergency command.

461.5 Schema, API, SDK, Profile, and Interface Records.

461.5.1 The Corporation shall maintain records for schemas, APIs, SDKs, technical profiles, interoperability interfaces, federation interfaces, evidence metadata profiles, method profiles, ontology profiles, dataset profiles, model register profiles, inference record profiles, compute workload profiles, proof receipt profiles, observatory node profiles, AI-RAN / O-RAN signal profiles, DePIN and DLT telemetry profiles, digital twin output profiles, cyber telemetry profiles, public-safe dashboard profiles, public-safe map profiles, and Nexus interface profiles.

461.5.2 Such records shall identify identifier, owner, custodian, version, specification, validation rules, permitted uses, prohibited uses, access class, authentication or authorization requirements where applicable, data classification, security requirements, public-safe status, dependency records, test records, deprecation records, correction path, and release status.

461.5.3 Schema, API, SDK, Profile, and Interface Records shall distinguish technical interoperability from certification, procurement approval, public authority adoption, finance-readiness, recognition, rating, or Nexus-compatible approval unless separately and expressly authorized by competent record.

461.6 IP Ownership Records.

461.6.1 The Corporation shall maintain Intellectual Property Ownership Records for works, inventions, data assets, datasets, software, models, documentation, technical baselines, schemas, APIs, SDKs, reference architectures, reports, publications, dashboards, maps, evaluation assets, benchmark assets, ontologies, controlled vocabularies, and other intellectual property created, acquired, licensed, assigned, commissioned, contributed, or stewarded by or for the Corporation.

461.6.2 IP Ownership Records shall identify owner, creator, contributor, employer or contractor status, assignment status, license status, pre-existing materials, derivative works, joint works, commissioned works, data rights, model rights, software rights, documentation rights, research output rights, public-good mission overlay, sponsor or funder restrictions, public authority restrictions, protected knowledge restrictions, and correction path.

461.6.3 No person shall claim ownership, exclusive control, commercial enclosure, sponsor control, provider control, or unauthorized derivative control over public-good technical assets where the Corporation’s records establish otherwise.

461.7 Contributor Records.

461.7.1 The Corporation shall maintain Contributor Records for contributors, maintainers, reviewers, code owners, documentation contributors, data contributors, model contributors, ontology contributors, benchmark contributors, community contributors, university contributors, public authority contributors, and other persons contributing to technical assets or public-good records.

461.7.2 Contributor Records shall identify contributor identity, affiliation, role, contribution type, authority, conflict disclosures, contributor terms, confidentiality obligations, IP treatment, license or assignment status, data / AI / cyber duties, export-control duties where applicable, public-safe claims duties, protected knowledge duties, access class, and offboarding or revocation status.

461.7.3 Contributor status shall not confer authority to bind the Corporation, approve releases, alter institutional meaning, issue public claims, certify, recognize, determine finance-readiness, approve procurement, represent public authority approval, or claim Nexus-compatible status without separate competent record.

461.8 Contributor License Agreement Records.

461.8.1 The Corporation shall maintain Contributor License Agreement Records where contributor license agreements are required, accepted, rejected, modified, superseded, or terminated.

461.8.2 Contributor License Agreement Records shall identify contributor, contribution scope, license grant, patent grant where applicable, copyright treatment, moral rights treatment where applicable, attribution, warranties or disclaimers, authority to contribute, employer consent where required, open-source compatibility, public-good licensing compatibility, restricted asset exclusions, protected knowledge exclusions, and effective date.

461.8.3 Contributions lacking required contributor license records shall be restricted, rejected, segregated, re-permissioned, or otherwise corrected before release where material.

461.9 Assignment Records.

461.9.1 The Corporation shall maintain Assignment Records for intellectual property, inventions, copyrightable works, software, documentation, data rights, model rights, technical asset rights, trademarks, and other rights assigned to or by the Corporation.

461.9.2 Assignment Records shall identify assignor, assignee, subject matter, consideration where applicable, effective date, scope, exclusions, moral rights treatment where applicable, prior rights, third-party rights, sponsor or funder restrictions, public authority restrictions, public-good mission overlay, and recording or filing status where applicable.

461.9.3 Assignment Records shall be reviewed for private benefit, private inurement, sponsor control, provider control, public-good asset enclosure, export-control, sanctions, protected knowledge, and public-benefit compatibility where material.

461.10 Licensing Records.

461.10.1 The Corporation shall maintain Licensing Records for open-source licenses, open data licenses, documentation licenses, research licenses, public-good licenses, restricted licenses, dual licenses, commercial licenses where public-good-compatible, standards-support licenses, model licenses, dataset licenses, API licenses, SDK licenses, repository licenses, and technical baseline licenses.

461.10.2 Licensing Records shall identify license selected, assets covered, version, approval authority, compatibility review, restrictions, public-good rationale, commercial use treatment, data restrictions, model restrictions, export-control restrictions, sanctions restrictions, protected knowledge restrictions, attribution requirements, copyleft or permissive obligations, termination rights, enforcement pathway, and correction path.

461.10.3 Licensing Records shall prevent closed capture of public-good baselines, sponsor enclosure, provider enclosure, unauthorized commercial reuse, misleading compatibility claims, and misuse of GCRI US marks or Nexus identity.

461.11 Repository Records.

461.11.1 The Corporation shall maintain Repository Records for public, internal, restricted, controlled, archive, shared, mirror, forked, or federation-linked repositories.

461.11.2 Repository Records shall identify repository name, URL or location, owner, maintainer, code owners, access class, classification, branch protection, required reviews, commit signing status where appropriate, release process, secrets controls, dependency controls, vulnerability controls, license status, public-safe status, export-control status where applicable, protected knowledge status, incident history, and correction path.

461.11.3 Repository access or public repository visibility shall not imply release approval, technical truth, certification, procurement approval, public authority adoption, finance-readiness, recognition, provider preference, public warning, emergency command, or warranty.

461.12 Secure Development Records.

461.12.1 The Corporation shall maintain Secure Development Records for material software, technical assets, dashboards, maps, APIs, SDKs, schemas, models, evaluation tools, repositories, and release workflows.

461.12.2 Secure Development Records shall include secure design review, threat modeling, code review, peer review, dependency review, license review, vulnerability review, secrets review, secure configuration review, test coverage, negative testing, security testing, accessibility testing where applicable, privacy testing where applicable, AI safety testing where applicable, public-safe output testing where applicable, release readiness review, and correction actions.

461.12.3 Secure Development Records shall support secure release, vulnerability management, public-safe publication, repository integrity, and technical trust.

461.13 Dependency and SBOM Records.

461.13.1 The Corporation shall maintain Dependency Records and Software Bill of Materials Records where appropriate for public-good software, technical assets, repositories, dashboards, maps, APIs, SDKs, model tools, proof receipt tools, and release artifacts.

461.13.2 Dependency and SBOM Records shall identify dependencies, versions, licenses, maintainers, known vulnerabilities, provenance, update status, transitive dependencies where appropriate, security review, license review, replacement status, exception approvals, and correction path.

461.13.3 Dependencies with unresolved critical risk, incompatible licenses, unknown provenance, abandoned maintenance, malicious indicators, or restricted technology concerns shall be restricted, remediated, replaced, or escalated according to risk.

461.14 Vulnerability Records.

461.14.1 The Corporation shall maintain Vulnerability Records for vulnerabilities affecting software, repositories, dependencies, dashboards, maps, APIs, SDKs, cloud systems, identity systems, controlled rooms, AI systems, models, data systems, proof receipt tools, and public-good technical assets.

461.14.2 Vulnerability Records shall include intake, reporter handling, severity classification, exploitability assessment, affected assets, affected versions, public-safe communication status, embargo status where appropriate, patch plan, remediation clock, release of fix, user notice, public authority notice where required, repository hold, release hold, credential rotation where required, post-incident review, and closeout.

461.14.3 Vulnerability Records shall be access-controlled where disclosure could enable exploitation or harm.

461.15 Secrets, Keys, Tokens, and Credentials Records.

461.15.1 The Corporation shall maintain Secrets, Keys, Tokens, and Credentials Records for cryptographic keys, signing keys, repository tokens, cloud credentials, API keys, access tokens, service accounts, recovery codes, environment variables, secret stores, and sensitive configuration.

461.15.2 Such records shall identify owner, custodian, permitted use, access class, rotation schedule, expiration, storage location, emergency revocation path, break-glass procedure where applicable, access logs where appropriate, incident history, and disposal status.

461.15.3 Secrets shall not be committed to public repositories, shared through unapproved channels, embedded in public artifacts, used beyond scope, or retained after authority ends.

461.16 Release Records.

461.16.1 The Corporation shall maintain Release Records for public, controlled, restricted, emergency, pre-release, beta, archive, rollback, and withdrawn releases.

461.16.2 Release Records shall identify release authority, release candidate review, release classification, version, changelog, release notes, known issues, known limitations, migration notes, compatibility notes, license status, security status, vulnerability status, dependency status, SBOM status where appropriate, signing status where appropriate, provenance status, public-safe status, rollback plan, deprecation notice, and correction path.

461.16.3 No release shall be represented as certified, recognized, finance-ready, procurement-approved, public authority-adopted, provider-preferred, public warning-capable, emergency command-capable, or guaranteed unless separate competent authority exists.

461.17 Deprecation and Retirement Records.

461.17.1 The Corporation shall maintain Deprecation and Retirement Records for technical assets, software, repositories, APIs, SDKs, schemas, profiles, methods, datasets, models, dashboards, maps, technical baselines, proof receipt tools, evaluation harnesses, and other assets no longer current.

461.17.2 Deprecation and Retirement Records shall identify reason, effective date, replacement asset where applicable, migration path, support status, security status, affected users, affected dependencies, public-safe notice, archive status, and correction path.

461.17.3 Deprecated or retired assets shall not be represented as current, supported, public-safe, or Nexus-compatible except according to their record status.

461.18 Fork, Compatibility, and Nexus-Compatible Claim Records.

461.18.1 The Corporation shall maintain Fork, Compatibility, and Nexus-Compatible Claim Records for external implementations, forks, derivative uses, compatibility claims, conformance claims, test results, integration claims, and Nexus-compatible references involving GCRI US technical assets.

461.18.2 Such records shall identify claimant, asset, license basis, test basis, review status, approved language where any, prohibited language, limitations, GRF interface where recognition meaning is possible, Nexus Standards or protocol authority interface where standards meaning is possible, GRA interface where finance meaning is possible, correction path, and enforcement status.

461.18.3 Forking, using, integrating, passing tests, referencing, or commercially deploying a GCRI US asset shall not create automatic compatibility, Nexus-compatible status, certification, procurement eligibility, public authority adoption, GRF recognition, GRA finance-readiness, provider preference, or public-good legitimacy.

461.19 Takedown and Enforcement Records.

461.19.1 The Corporation shall maintain Takedown and Enforcement Records for unauthorized use, IP infringement, license violation, mark misuse, compatibility overclaim, certification overclaim, recognition overclaim, finance-readiness overclaim, procurement implication, public authority overclaim, security exposure, protected knowledge exposure, privacy exposure, controlled technology exposure, or other misuse of technical assets.

461.19.2 Takedown and Enforcement Records shall include intake, evidence, notice, takedown request, correction demand, platform notice, counter-notice where applicable, legal review, public-safe communication, settlement, referral, litigation, restoration, or closeout.

461.19.3 Enforcement shall be proportionate, records-based, non-retaliatory, and consistent with public-good mission, open licensing, public-safe protection, and legal obligations.

461.20 Technical Asset Records.

461.20.1 The Corporation shall maintain Technical Asset Records, including Technical Asset Register Records, Public-Good Software Records, Open Technical Baseline Records, Reference Architecture Records, Schema / API / SDK / Profile / Interface Records, IP Ownership Records, Contributor Records, Contributor License Agreement Records, Assignment Records, Licensing Records, Repository Records, Secure Development Records, Dependency and SBOM Records, Vulnerability Records, Secrets / Keys / Tokens / Credentials Records, Release Records, Deprecation and Retirement Records, Fork / Compatibility / Nexus-Compatible Claim Records, Takedown and Enforcement Records, correction records, legal hold records, and archive records.


Section 462. Public Authority, Government Interface, Public Sector, and Capacity Records

462.1 Public Authority Register.

462.1.1 The Corporation shall maintain a Public Authority Register recording material interactions, participation, references, data contributions, rooms, funding, grants, notices, approvals, restrictions, corrections, and capacity classifications involving public authorities.

462.1.2 The Public Authority Register shall include federal, state, District of Columbia, territorial, Tribal / Indigenous where lawfully and respectfully engaged, local, county, municipal, metropolitan, public health, emergency management, public safety, public works, utility, port, transportation, telecom, energy, water, food, cyber, environmental, housing, education, research, health-system, regulatory, procurement, public finance, legislative, judicial, inspector general, and oversight interfaces where material.

462.1.3 The Public Authority Register shall preserve non-delegation, non-endorsement, non-procurement, non-funding-approval, non-public-finance-approval, non-regulatory, non-public-warning, non-emergency-command, and public authority boundary discipline.

462.2 Public Authority Participant Records.

462.2.1 Public Authority Participant Records shall identify each public authority participant where material, including name, institution, role, capacity classification, authority basis, contact record, participation purpose, permitted attribution, confidentiality status, public records considerations, data contribution status, room participation status, approved public language, and correction path.

462.2.2 Participation records shall distinguish official participants, institutional representatives, delegated representatives, observers, regulator-listening participants, public finance readers, emergency-management participants, public health participants, public safety participants, public infrastructure operator participants, academic representatives, personal-capacity participants, non-attributable participants, controlled-room participants, data providers, reviewers, and simulation or tabletop participants.

462.2.3 Public authority participation shall not be treated as endorsement, adoption, approval, funding, procurement, regulatory guidance, public finance approval, public warning, emergency command, sovereign obligation, recognition, finance-readiness, certification, or provider preference.

462.3 Capacity Classification Records.

462.3.1 Capacity Classification Records shall identify the capacity in which each public authority participant or public-sector actor participates in a meeting, room, event, review, publication, data contribution, public authority learning activity, simulation, tabletop, after-action process, or Nexus interface.

462.3.2 Capacity Classification Records shall include classification, authority evidence, limits, attribution permission, approved public language, access rights, confidentiality obligations, public records considerations, and expiration or review date.

462.3.3 Ambiguous capacity shall be classified conservatively and shall not be represented as official capacity without competent record.

462.4 Official Capacity Records.

462.4.1 Official Capacity Records shall document when a public authority participant is acting in an official capacity and shall include written authority where available, institutional confirmation where appropriate, scope of authority, limits of authority, attribution permission, approved public language, logo and name use permission, quote permission, data contribution permission, confidentiality limits, public records considerations, legal review where required, term, expiration, and withdrawal of authority.

462.4.2 Official Capacity Records shall not be expanded by implication and shall not create public authority endorsement, funding approval, procurement approval, regulatory approval, public finance approval, public warning, emergency command, sovereign obligation, or public-private partnership unless expressly stated by competent public authority record.

462.5 Observer Records.

462.5.1 Observer Records shall document public authority or public-sector observer status, including observer identity, institution, purpose, meeting or room, access limits, confidentiality, non-attribution where applicable, no-endorsement language, no-adoption language, no-funding-approval language, no-procurement-approval language, no-regulatory-approval language, no-public-finance-approval language, no-public-warning language, no-emergency-command language, and correction obligations.

462.5.2 Observer Records shall be used to prevent overclaim by the Corporation, observers, sponsors, providers, public authorities, media, or third parties.

462.6 Regulator-Listening Records.

462.6.1 Regulator-Listening Records shall document regulator participation in listening capacity only, including identity, agency, scope, materials reviewed, confidentiality status, public records considerations, no-regulatory-guidance language, no-regulatory-approval language, no-safe-harbor language, no-permit language, no-compliance-determination language, no-enforcement-position language, no-waiver language, and reference controls.

462.6.2 Regulator attendance shall not be relied upon as regulatory approval, guidance, safe harbor, enforcement position, waiver, compliance determination, policy adoption, or public authority endorsement.

462.7 Public Finance Reader Records.

462.7.1 Public Finance Reader Records shall document public finance reader participation, including role, institution, room or material reviewed, purpose, access limits, confidentiality, no-grant-approval language, no-budget-allocation language, no-appropriation language, no-public-finance-approval language, no-MDB / DFI approval language, no-public-guarantee language, no-public-credit language, no-tax-credit-approval language, no-sovereign-obligation language, no-capital-commitment language, and no-investment-advice language.

462.7.2 Public Finance Reader Records shall preserve GCRI US role separation from GRA, public finance bodies, grantors, budget authorities, treasury authorities, MDBs, DFIs, lenders, insurers, ratings agencies, and capital actors.

462.8 Emergency-Management Participant Records.

462.8.1 Emergency-Management Participant Records shall document participation by emergency management, public safety, public health, public works, public infrastructure, and related public-sector personnel.

462.8.2 Such records shall identify whether participation is for learning, simulation, tabletop exercise, after-action learning, observability literacy, technical literacy, public-safe decision-support literacy, or other non-command purpose.

462.8.3 Records shall include no-incident-command language, no-dispatch-authority language, no-evacuation-authority language, no-emergency-alert language, no-public-warning language, no-public-health-order language, no-safety-command language, and no-operational-resource-direction language.

462.9 Public Infrastructure Operator Records.

462.9.1 Public Infrastructure Operator Records shall document interactions with utilities, ports, transportation systems, telecom operators, energy systems, water systems, food systems, public works, public health systems, public safety systems, cyber operators, and publicly regulated or publicly owned infrastructure operators.

462.9.2 Records shall identify operator capacity, public authority relationship, data contribution status, infrastructure sensitivity, cyber sensitivity, confidentiality, public-safe mapping restrictions, access class, publication restrictions, AI-use restrictions, and correction path.

462.9.3 Public infrastructure operator participation shall not create operational control, public authority decision authority, procurement approval, provider preference, public warning, emergency command, or infrastructure command by GCRI US.

462.10 Public Authority Data Contribution Records.

462.10.1 Public Authority Data Contribution Records shall identify contributing authority, capacity, authority record, data contribution agreement where appropriate, dataset description, permitted use, prohibited use, classification, confidentiality, AI-use restrictions, publication restrictions, retention, deletion, transfer restrictions, public records considerations, legal holds, withdrawal or correction rights, public-safe review, and correction path.

462.10.2 Public authority data shall not be published, mapped, trained on, embedded, transferred, used in finance-facing materials, used in provider-facing materials, or externally shared beyond recorded authority.

462.11 Public Authority Reference Approval Records.

462.11.1 Public Authority Reference Approval Records shall document approvals for public authority name use, logo use, title use, quote use, attendance reference, photograph, recording, event reference, data contribution statement, official capacity language, observer language, personal-capacity language, and non-attributable participation language.

462.11.2 Approved references shall include required non-endorsement, non-adoption, non-funding-approval, non-procurement-approval, non-regulatory-approval, non-public-finance-approval, non-public-warning, non-emergency-command, and non-sovereign-obligation language where appropriate.

462.11.3 Any public authority reference lacking approval shall be held, corrected, withdrawn, or reclassified.

462.12 Public Authority Room Records.

462.12.1 Public Authority Room Records shall be maintained for public authority rooms, regulator-listening rooms, public finance reader rooms, emergency learning rooms, controlled rooms, clean rooms, data rooms, evidence rooms, and no-download rooms involving public authorities.

462.12.2 Such records shall include room charter, admission criteria, capacity classification, confidentiality terms, public records considerations, public sector constraints, data / AI / cyber / privacy controls, competition controls, public authority boundary controls, finance and procurement boundary controls, public-safe publication controls, room outputs, closeout, and correction path.

462.12.3 Public Authority Room Records shall state that room participation does not create endorsement, adoption, approval, funding, procurement, public finance approval, regulatory guidance, public warning, emergency command, or sovereign obligation.

462.13 Government Funding Records.

462.13.1 Government Funding Records shall document government funding review, eligibility, award, restrictions, allowable costs, reporting obligations, audit obligations, procurement obligations, data rights, IP rights, publication terms, lobbying restrictions, political activity restrictions, public authority references, public records implications, and corrective actions.

462.13.2 Government funding shall not be represented as public authority delegation, public authority endorsement, public finance approval, procurement approval, recognition, finance-readiness, certification, provider preference, public warning, or emergency command authority.

462.14 Public Grant Records.

462.14.1 Public Grant Records shall document federal, state, territorial, local, Tribal / Indigenous government, public university, public laboratory, public agency, cooperative agreement, subaward, and other public grant activity where applicable.

462.14.2 Public Grant Records shall include application, award, budget, terms, restrictions, deliverables, reports, allowable cost review, procurement requirements, subaward records, audit records, public authority data terms, publication terms, IP terms, closeout, and correction records.