For the complete documentation index, see llms.txt. This page is also available as Markdown.

VI. Security

99. Purpose, Constitutional Function, and Governing Rule


99.1 Purpose

Part VI constitutes the security, confidentiality, privacy, restricted-handling, and controlled-environment charter of GCRI US. It fixes the constitutional rules by which the Corporation shall protect people, rights-bearing data, repositories, technical infrastructure, governance artifacts, evidence materials, collaboration environments, controlled disclosures, and all other protected information and systems that enable the Corporation to function as a public-benefit steward without causing preventable exposure, misuse, or institutional breakdown.

This Part is necessary because security and privacy in an institution such as GCRI US are not merely operational concerns or back-office technical specialties. They are among the principal conditions under which the Corporation may legitimately operate at all. The Corporation’s work depends upon the capacity to receive, classify, protect, restrict, process, review, publish, retain, and, where necessary, withhold sensitive materials in ways consistent with law, rights, safeguards, mission lock, and public trust. If that capacity fails, then the institution does not merely experience an IT problem. It experiences constitutional failure in the governance of its own legitimacy.

Accordingly, Part VI exists to govern, among other things:

a) how information and systems are classified and protected; b) how access is granted, reviewed, and revoked; c) how controlled rooms, clean rooms, and restricted environments are designated and run; d) how privacy, identity protection, and rights-bearing data are handled; e) how sovereign-sensitive, community-sensitive, and public-authority-sensitive materials are governed; f) how cybersecurity, secure tooling, repositories, and technical infrastructure are protected; g) how incidents, breaches, and exposure events are escalated and remediated; and h) how all such protections remain reviewable, auditable, and aligned with the Corporation’s public-benefit purpose.

Part VI therefore serves as the institutional answer to a core constitutional question: how shall GCRI US protect the people, systems, evidence, and infrastructure entrusted to or created by it, while remaining truthful, rights-aware, and mission-faithful? The answer is not ad hoc prudence. It is governed security and protected handling by design.

This Part shall not be read as an exception to openness, collaboration, or public-good stewardship. It shall instead be read as the condition that allows openness, collaboration, and stewardship to occur without collapsing into unsafe disclosure, false public meaning, avoidable rights harm, or uncontrolled technical exposure.


99.2 Relationship of Part VI to Mission Lock, Safeguards, Public-Benefit Stewardship, and Non-Execution Boundary

Part VI shall be interpreted together with Parts I through V as an integrated component of the Corporation’s constitutional order. It operationalizes, in the domain of security, privacy, confidentiality, and protected handling, the deeper commitments already established elsewhere in these Bylaws: mission lock, public-benefit distinctness, non-execution, anti-capture, protected participation, public-good stewardship, and the rights-and-safeguards logic of Part IV.

Mission lock requires that GCRI US remain a trustworthy steward of public-good institutional infrastructure. That trust cannot be sustained if sensitive materials are mishandled, if repository authority is insecure, if contributor and participant protections are porous, if public-good technical baselines are exposed through unmanaged channels, or if evidence and governance records cannot be protected with integrity. Security under this Part is therefore not external to mission. It is one of the methods by which mission remains real.

The relationship to safeguards is equally direct. Part IV fixed the rights-bearing and non-harm conditions under which the Corporation may act. Part VI supplies the control environment necessary to make those conditions operational. A privacy principle without access control is fragile. A controlled-room duty without secure procedures is theater. A grievance protection without confidentiality discipline is self-defeating. Part VI gives technical, procedural, and custodial form to the rights and safeguards commitments that Part IV made constitutionally binding.

Part VI also supports public-benefit stewardship under Part V. A public-good technical and documentary estate must be not only open where appropriate, but also secure, provenance-preserving, and resistant to hidden compromise. Repository integrity, secure release, controlled derivative handling, and anti-enclosure discipline all depend upon security and confidentiality controls strong enough to preserve continuity without transforming the institution into an opaque black box.

The relationship to the non-execution boundary is equally important. GCRI US is not constituted to act as a market operator, regulated executor, or sovereign authority. Its security architecture must therefore reinforce, rather than blur, that role. Security controls shall not be used to create secret authority, hidden decisionism, or artificial institutional mystique. They shall be used to preserve lawful role performance, not to expand it.

Where tension appears to arise between security and openness, between confidentiality and accountability, or between restricted handling and public-benefit transparency, Part VI shall be interpreted through the broader constitutional hierarchy of the Bylaws: protect rights, preserve truthful public meaning, sustain continuity, and avoid both reckless exposure and unjustified secrecy.


99.3 Security and Privacy as Constitutional Control Surfaces, Not Merely Technical Controls

Security and privacy under these Bylaws shall be treated as constitutional control surfaces and not merely as technical controls, IT functions, or compliance checklists. A control surface is any domain in which institutional behavior determines whether the Corporation remains capable of acting lawfully, safely, truthfully, and within mission. Security and privacy qualify because they shape who may know what, who may act where, what can be trusted, what can be released, what must be withheld, how harm is prevented, and how institutional legitimacy is preserved under pressure.

This means security and privacy are not to be treated as downstream implementation matters that begin only after strategy, governance, publication, or partnership decisions have already been made. They are to be built into those decisions from the outset. The Corporation shall therefore understand that questions such as the following are constitutional in nature:

a) who has access to a protected repository or controlled dataset; b) whether a technical detail should be open, restricted, or controlled-room only; c) whether a participant may safely join a process; d) whether a repository move creates loss of provenance or increased attack surface; e) whether a partner can be trusted with controlled information; f) whether a notification must be made now or delayed to avoid additional harm; and g) whether a technical environment or workflow preserves or defeats the safeguards obligations of Part IV.

The Corporation shall reject narrow formulations such as “security owns this” or “privacy is for counsel and compliance.” Security and privacy are distributed institutional duties under specialist stewardship. Technical experts, legal stewards, governance officers, evidence custodians, repository maintainers, and Board-level oversight functions all participate in the control surface, albeit in different roles.

This clause also means that failure of security or privacy is not to be diagnosed merely as tool failure or user error where the deeper problem is constitutional under-design. If the institution cannot maintain least privilege, cannot restrict disclosure, cannot preserve chain-of-custody, or cannot run a controlled room without leakage, the issue is not only technical weakness. It is governance weakness. Part VI requires that the Corporation think at that level.


99.4 Protection of People, Evidence, Systems, and Public-Good Infrastructure as a Core Institutional Duty

GCRI US shall treat the protection of people, evidence, systems, and public-good infrastructure as a core institutional duty. The Corporation’s security posture shall not be limited to protecting devices or networks in the abstract. It shall protect the broader institutional ecology through which the Corporation performs its mission.

This duty extends to:

a) people whose participation, identity, complaint, dissent, community role, or contribution may expose them to retaliation, coercion, exclusion, or harm if poorly handled; b) evidence and governance artifacts whose integrity, admissibility, traceability, or safe use depend upon proper classification, custody, and controlled access; c) systems, repositories, credentials, release pipelines, communication channels, and collaboration tools through which institutional authority and continuity are exercised; and d) public-good infrastructure, including canonical schemas, repositories, documentation, semantic baselines, and trust-bearing technical surfaces whose compromise would damage not only the Corporation but the common rail it helps steward.

The Corporation shall therefore not treat system protection as separable from human protection. An access-control failure may expose a participant. A publication leak may endanger a community. A repository compromise may distort authoritative meaning. A mishandled badge or token may create false trust. Security under Part VI is therefore human-centered, evidence-aware, and infrastructure-conscious at the same time.

This core duty also requires prioritization. Convenience, institutional speed, partner preference, or prestige shall not outweigh the obligation to protect people and core infrastructure where the two come into conflict. A public-benefit steward may accept friction if that friction is the lawful price of preserving safety, rights, and continuity.

Where the Corporation faces a choice between faster operation and safer custody, the governing presumption shall favor safer custody unless a narrower and recorded justification establishes that the faster path still preserves the constitutional protections of this Part.


99.5 Binding Effect of Part VI Across All Organs, Participants, Platforms, Repositories, Programs, and Cross-Entity Interfaces

Part VI shall bind all organs, officers, committees, employees, contractors, fellows, advisers, contributors, volunteers, repository maintainers, platform administrators, program operators, investigative or grievance handlers, and any other person acting for or through GCRI US with respect to any protected information, controlled process, technical system, repository, collaboration environment, or security-relevant interface within the Corporation’s remit.

Its binding effect extends across, without limitation:

a) governance processes and Board-level materials; b) repositories, codebases, release systems, and technical infrastructure; c) evidence workflows, grievance records, protected reporting channels, and controlled-room deliberations; d) research, publication, and documentation pipelines; e) training environments, collaboration tools, file-sharing systems, and communications channels; f) partner, vendor, host, and contractor interfaces; and g) cross-entity interactions involving GCRI US and any related or adjacent institution where protected information, shared systems, or trust-bearing surfaces are involved.

No person or unit may claim that Part VI does not apply because the material is “only technical,” “only internal,” “only partner-managed,” “just a draft,” “only in Slack,” “already shared informally,” or “just for a short time.” If the information, system, asset, or interaction can materially affect safety, rights, confidentiality, continuity, repository integrity, public meaning, or lawful stewardship, Part VI applies.

Likewise, no cross-entity interface shall be treated as exempt from Part VI merely because another institution also has controls. GCRI US retains its own duties. Shared systems do not dissolve separate constitutional responsibilities. If anything, they increase the need for explicit discipline.

This binding effect shall be interpreted broadly enough to prevent security, privacy, and protected-handling obligations from disappearing into procedural gaps. The Corporation’s duty is not satisfied by having a security team. It is satisfied only when the rules of Part VI shape actual institutional behavior across the full operating surface of GCRI US.


99.6 Interpretive Rule for Part VI

This Part VI shall be interpreted to preserve a controlling proposition: security, privacy, confidentiality, restricted handling, and controlled environments exist in GCRI US to protect people, preserve rights, secure the public-good estate, maintain trustworthy repository and evidence continuity, and prevent both harmful exposure and false institutional opacity.

Where ambiguity exists under this Part, the interpretation that better preserves:

a) stronger protection of people, rights-bearing data, evidence, and core systems; b) earlier use of classification, restriction, and controlled handling where harm or misuse risk is material; c) tighter alignment between security controls and the safeguards logic of Part IV; d) stronger repository, release, and technical continuity protection for the public-good core; and e) clearer accountability across all organs, participants, programs, and cross-entity interfaces

shall prevail unless a contrary result is required by law.

100. Core Security, Privacy, and Handling Principles (GCRI United States)


100.1 Confidentiality, Integrity, Availability, and Auditability as Baseline Principles

GCRI US shall govern all protected information, material systems, repositories, controlled processes, and stewardship-significant technical or documentary assets according to the baseline principles of confidentiality, integrity, availability, and auditability. These principles are not merely technical doctrines. They are the minimum constitutional conditions under which the Corporation may be trusted to receive, hold, process, publish, restrict, or transmit information and infrastructure within its remit.

Confidentiality means that information, systems, and technical details shall be accessible only to those with a lawful and role-faithful basis to know them, and only at the level of exposure necessary for the relevant institutional purpose. Integrity means that records, repositories, outputs, models, configurations, and protected materials shall remain authentic, uncorrupted, and resistant to unauthorized or unrecorded change. Availability means that the Corporation shall preserve access, continuity, and recoverability sufficient to perform its duties and to avoid preventable failure of stewardship. Auditability means that the institution shall preserve enough trace, metadata, and reviewable record to later determine what existed, who accessed it, what changed, and on what authority.

These four principles shall be treated as mutually reinforcing. A system that is highly confidential but not auditable may conceal abuse. A system that is highly available but not integrity-preserving may spread corrupted authority. A record that is auditable but unavailable to lawful stewards may fail continuity. A repository that is open without confidentiality layering may expose protected material. Part VI therefore rejects one-dimensional control design.

Accordingly, the Corporation shall ensure that material decisions about tooling, repositories, publication, controlled handling, access pathways, evidence custody, and incident response are tested against all four principles. No program, repository, or process shall be judged adequately protected merely because one of the four is strong while the others are neglected.

Where tradeoffs appear unavoidable, the Corporation shall resolve them in a manner that best preserves rights, public-benefit continuity, and lawful stewardship under the full constitutional order of these Bylaws. Convenience, platform default, or informal custom shall not be permitted to silently decide such tradeoffs.


100.2 Least-Privilege, Need-to-Know, and Minimum Exposure Rule

All access to systems, records, repositories, evidence materials, credentials, publication workflows, and restricted technical or documentary assets within GCRI US shall be governed by the combined rule of least privilege, need-to-know, and minimum exposure. This rule is one of the primary operating expressions of the rights, safeguards, and public-good continuity commitments fixed elsewhere in these Bylaws.

Least privilege requires that each person, role, process, or system component receive only the permissions required to perform its lawful and designated function, and no more. Need-to-know requires that information access be justified by specific institutional purpose rather than by status, curiosity, convenience, or generalized relevance. Minimum exposure requires that even where access is legitimate, the amount, duration, granularity, and form of the information or system access be kept as narrow as practicable.

Accordingly, GCRI US shall not permit:

a) broad repository or data access merely because an individual is senior or technically capable; b) open-ended administrative rights where narrower scoped rights would suffice; c) routine sharing of sensitive materials with large groups “for awareness”; d) packaging of protected and non-protected materials together where separable handling is possible; or e) long-lived access rights that persist after the specific institutional need has lapsed.

The Corporation shall also recognize that minimum exposure applies not only to human users but to systems, integrations, bots, pipelines, package processes, and automated tooling. A connector with broad data access may be as constitutionally problematic as an overprivileged human user if its scope exceeds what the lawful institutional purpose requires.

This rule shall be implemented prospectively and continuously reviewed. Least privilege is not achieved once and forgotten. Institutional roles change, repositories evolve, projects end, contributors depart, and cross-entity relationships shift. What was once justified access may later become excess exposure. The Corporation shall therefore treat permission review and narrowing as part of ordinary constitutional maintenance, not as an exceptional exercise triggered only by incidents.

Where uncertainty exists, the narrower privilege and narrower exposure setting shall prevail until a stronger case for broader access is recorded and approved.


100.3 Proportionality and Context-Sensitive Protection Requirements

Security, privacy, confidentiality, and protected-handling controls under this Part shall be applied according to proportionality and context-sensitive protection requirements. The Corporation shall neither under-protect sensitive matters by applying generic low-friction controls where higher safeguards are needed, nor over-restrict ordinary matters in ways that needlessly damage public-benefit function, reviewability, or legitimate collaboration.

Proportionality means that the strength, depth, and complexity of controls shall correspond to the seriousness of the risk, the sensitivity of the information or system, the likely consequences of misuse or exposure, and the constitutional significance of the asset or process involved. Context-sensitive protection means that those controls shall be calibrated to actual institutional and social conditions, including vulnerability, community sensitivity, public-authority sensitivity, geopolitical context, rights-bearing character, and likely misuse environment.

Accordingly, GCRI US shall ask, when designing or applying controls:

a) what is being protected and why; b) who could be harmed, misled, excluded, or endangered by weak handling; c) what kind of misuse or compromise is realistically foreseeable; d) whether the control burden is justified by the nature of the risk; and e) whether the same asset or process may require different protection postures in different contexts.

This means, for example, that a public glossary may require openness and provenance discipline, while a rights-sensitive annex linked to the same project may require controlled-room treatment. A code repository may contain public reference modules alongside restricted control surfaces. A cross-border collaboration may require more restrictive data localization and access review than a purely domestic internal workflow. Part VI requires the institution to govern such differences explicitly rather than by accidental inconsistency.

The Corporation shall not confuse proportionality with permissiveness. A lightweight control is not proportionate simply because it is easier to administer. Nor is a heavy control proportionate simply because the material is politically important. Proportion must be tied to actual constitutional risk. Where uncertainty remains material, the more protective temporary posture shall generally prevail until better context-specific classification is recorded.


100.4 Security-by-Design, Privacy-by-Design, and Safeguards-by-Design

GCRI US shall implement security-by-design, privacy-by-design, and safeguards-by-design across its systems, repositories, publication pathways, evidence handling, collaboration tooling, and institutional processes. This means protections under Part VI shall be embedded into architecture, workflow, access logic, repository design, release discipline, and information life-cycle design from the outset rather than added as compensatory patches after strategic or technical decisions are already in motion.

Security-by-design requires that repositories, pipelines, collaboration environments, release systems, access pathways, and system boundaries be built so that secure operation is the normal mode rather than the exceptional discipline of highly attentive users. Privacy-by-design requires that personal, identity-bearing, and rights-bearing data be minimized, segmented, constrained, and protected in the very shape of the systems and workflows that touch them. Safeguards-by-design requires that the full logic of Part IV—including protected participation, controlled disclosure, grievance safety, community-sensitive handling, and non-retaliation—be reflected in the information and process architecture itself.

The Corporation shall therefore avoid governance models that depend excessively on after-the-fact warnings, repeated manual policing, or heroic user behavior to preserve safety. If a platform, workflow, or repository requires users constantly to remember what should have been structurally prevented, the design is likely inadequate.

Accordingly, GCRI US shall prefer, wherever appropriate:

a) segmented environments over flat all-access systems; b) role-based and attribute-based controls over informal judgment alone; c) default-private settings for protected materials rather than default exposure; d) automated provenance, versioning, and logging where such automation preserves governance quality; and e) structured publication and release gates over ad hoc dissemination.

This principle also means that security, privacy, and safeguards review shall occur early in project, platform, and policy design. A release model, repository architecture, partnership workflow, or data flow path that cannot accommodate Part VI without major redesign should be recognized as constitutionally defective before it becomes entrenched.

Where legacy systems prevent full design alignment, the Corporation shall identify the gap, implement compensating controls, and prioritize remediation rather than normalizing architectural misfit as a permanent state.


100.5 No Informal Access, No Unlogged Handling, and No Governance Through Uncontrolled Channels

GCRI US shall prohibit informal access, unlogged handling, and governance through uncontrolled channels for any information, repository, system, process, or artifact whose significance under these Bylaws requires security, privacy, provenance, or handling discipline. The Corporation shall not permit important governance, evidence, security, publication, or rights-sensitive functions to migrate into unofficial or weakly governed channels merely because those channels are faster, socially convenient, or already in common use.

This means, among other things, that the Corporation shall not rely on:

a) personal messaging or unmanaged communications tools for handling restricted or governance-significant materials; b) informal file sharing without repository or record discipline; c) unlogged local copies as substitutes for controlled records; d) oral instructions, side-channel approvals, or ephemeral chats as the basis for material release, access, classification, or custody decisions; or e) off-platform collaboration for canonical, sensitive, or restricted matters without explicit exception and compensating controls.

The Corporation shall recognize that informal channels are especially dangerous in mission-driven and technically literate institutions because trust, urgency, and familiarity can create the illusion that speed is harmless. In practice, informal channels often erode provenance, undermine least-privilege discipline, bypass controlled-room conditions, and make later correction or accountability difficult.

This clause does not prohibit all informal conversation. It prohibits reliance on uncontrolled channels for governance-significant handling. A side conversation may occur; it may not become the authoritative place where the institution decides who sees a protected file, what version is current, whether a disclosure is approved, or whether a controlled-room matter may proceed.

Where uncontrolled handling is discovered, the Corporation shall treat it as a governance defect requiring remediation, migration into proper channels, and, where warranted, incident review rather than as harmless workflow improvisation.


100.6 Protection of Human Subjects, Protected Participants, and Rights-Bearing Data as a Priority Over Convenience

In all matters governed by Part VI, protection of human subjects, protected participants, complainants, reporting persons, vulnerable contributors, community representatives, rights-bearing persons, and all corresponding rights-bearing data shall take priority over administrative convenience, technical efficiency, speed of collaboration, ease of dissemination, or ordinary workflow preference.

This principle is necessary because institutional systems and repositories often optimize for throughput, integration, and operational legibility. Yet the cost of that optimization may fall disproportionately on people whose participation, identity, community role, or protected information becomes easier to expose or misuse as a result. These Bylaws require the opposite hierarchy.

Accordingly, GCRI US shall not justify weakened controls by arguments such as:

a) it is easier for the team if everyone can see the file; b) a broader channel is faster for coordination; c) a less segmented repository reduces overhead; d) sharing identity-bearing details will help with relationship management; or e) manual redaction is too cumbersome relative to immediate need.

Where the convenience of the institution conflicts with the safety, dignity, privacy, or exposure posture of protected persons or data, the institution shall bear the burden of inconvenience. That burden is part of public-benefit stewardship.

This clause shall also shape design choices. A workflow that repeatedly requires risky human judgment calls because convenience was prioritized over safe segmentation is likely misdesigned. The Corporation shall treat such patterns as structural issues, not merely as training deficiencies.

Where a temporary urgent need appears to justify more exposure than would ordinarily be acceptable, the matter shall be escalated under the emergency and recorded-authority logic of this Part rather than normalized as convenience-driven exception.


100.7 No Relaxation of Controls by Urgency, Status, Seniority, or External Pressure Without Recorded Authority

No control required by Part VI shall be relaxed, bypassed, widened, delayed, or informally suspended on the basis of urgency, status, seniority, reputational importance, donor preference, partner demand, political pressure, or comparable external or internal pressure without recorded authority and constitutionally sufficient justification.

This means, in particular, that GCRI US shall reject assumptions such as:

a) a senior leader may see everything because they are senior; b) a donor-adjacent or high-profile partner may be granted wider access because the relationship is important; c) a fast-moving incident justifies uncontrolled sharing outside emergency procedures; d) a respected expert or public official may bypass ordinary access or controlled-room admission rules; or e) an urgent deadline permits publication or transfer without proper classification or review.

Urgency may sometimes justify faster action. It does not justify invisible action. If controls must be adjusted in a time-sensitive situation, the adjustment shall occur through a bounded emergency or exceptional pathway, under designated authority, with recorded rationale, scope, and review conditions. The Corporation shall not permit “this is urgent” to become a cultural solvent dissolving security and privacy discipline whenever pressure rises.

Likewise, status and seniority shall not be mistaken for need-to-know. High office may entail broader responsibility, but it does not erase handling logic. A constitutional steward is one who submits even important actors to rules designed to protect rights, trust, and continuity.

Where a person invokes urgency or institutional importance to seek control relaxation outside proper channels, the request itself shall be treated as a governance-sensitive event and handled accordingly.


100.8 Most-Protective Reading Where Harm, Exposure, or Misuse Risk Is Material or Uncertain

In all matters arising under Part VI, where there is material uncertainty about the likelihood, scale, or consequences of harm, exposure, misuse, counterfeit reliance, repository compromise, rights-bearing disclosure, or systemic technical abuse, the Corporation shall adopt the most-protective reading consistent with law and mission until fuller review determines a narrower posture is justified.

For purposes of this rule, a most-protective reading is one that better preserves:

a) narrow access over broad access; b) controlled handling over casual dissemination; c) public-safe summary over risky full disclosure; d) segmented repository structure over flat exposure; e) identity protection over convenience of full context sharing; and f) temporary restriction pending review over irreversible exposure made in optimism.

This rule is not a license for reflexive secrecy. It is a constitutional guard against preventable harm where uncertainty is real and the cost of premature openness may be difficult or impossible to reverse. In practice, exposure harms are often harder to repair than temporary restrictions are to loosen. Repository leakage, public release of rights-sensitive detail, or unsafe cross-border transfer may create consequences that later explanation cannot unwind.

Accordingly, where a material question exists as to whether an asset, disclosure, channel, or access request is safe, the Corporation shall prefer to:

i) classify or restrict provisionally; ii) escalate for review; iii) provide a narrower or sanitized output; iv) defer release until handling conditions are clear; or v) separate protected from non-protected content more aggressively.

The burden of justifying a less protective path shall rest on the party proposing it. Under Part VI, optimism about safety is not a substitute for recorded institutional judgment.


100.9 Interpretive Rule for Core Security, Privacy, and Handling Principles

This Section shall be interpreted to preserve a controlling proposition: the baseline security and privacy posture of GCRI US must protect people, rights-bearing data, evidence, repositories, and public-good infrastructure through disciplined least privilege, context-sensitive controls, secure-by-design architecture, and refusal of uncontrolled handling.

Where ambiguity exists, the interpretation that better preserves:

a) confidentiality, integrity, availability, and auditability together; b) least-privilege, need-to-know, and minimum exposure discipline; c) stronger fit between control level and actual contextual risk; d) design-based rather than ad hoc protection; and e) narrower, safer handling where harm or misuse risk remains materially uncertain

shall prevail unless a contrary result is required by law.

101. Security Classification and Handling Principles (GCRI United States)


101.1 Institutional Information Classification Framework

GCRI US shall maintain a formal institutional information classification framework governing all records, repositories, code, documents, evidence materials, governance artifacts, communications, system outputs, credentials, and other information-bearing assets within its remit. Classification is a constitutional handling discipline, not a clerical label. It determines how the Corporation preserves rights, prevents misuse, protects public-good infrastructure, and maintains truthful public meaning.

The classification framework shall be designed to answer, for any material information object or information environment:

a) what level of protection applies; b) what kinds of handling, access, disclosure, copying, storage, transmission, and publication are permitted; c) what role-based or contextual restrictions apply; d) who may assign, alter, review, or remove the classification; and e) what public, internal, or controlled meaning attaches to that classification.

The Corporation shall not permit classification to be governed through informal custom such as “everyone knows this is sensitive,” “it is in a private folder,” or “this came from leadership.” Such informal handling produces ambiguity, uneven access practice, and weak auditability. A public-benefit steward requires a visible and reviewable classification grammar.

The framework shall extend across:

i) information in repositories, drives, collaboration systems, and communications tools; ii) structured data and technical artifacts; iii) Board and governance records; iv) evidence, grievance, and protected-report materials; v) public documents and publication drafts; and vi) cross-entity or partner-shared materials where GCRI US remains responsible for its own handling obligations.

The Corporation shall also ensure that classification is not treated as a mere top-layer tag detached from the actual risk, rights, or public-meaning condition of the material. Classification must reflect the real handling logic required under Parts IV, V, and VI together. If the class says one thing and the workflow does another, the class is not functioning as governance.


101.2 Categories of Protected Information in Scope

The institutional classification framework shall apply to all categories of protected information materially relevant to the work of GCRI US. Protected information for purposes of this Part includes any information whose misuse, misclassification, overexposure, underprotection, or uncontrolled movement could materially affect rights, safety, trust, repository integrity, public meaning, continuity, legal posture, or the Corporation’s constitutional role.

Protected information categories include, without limitation:

a) personal information and other rights-bearing data; b) protected participation, grievance, reporting, and whistleblower materials; c) sovereign-sensitive, public-authority-sensitive, and jurisdiction-sensitive information; d) Indigenous-sensitive, community-sensitive, or vulnerability-sensitive information; e) controlled evidence, restricted technical assets, security-sensitive documentation, and abuse-prone implementation detail; f) credentials, keys, access artifacts, and system-control materials; g) legal privilege, investigative materials, and litigation-hold content; h) third-party confidential information and contract-protected information; i) high-consequence governance records, Board materials, and controlled-room outputs; and j) any derivative, summary, mapping, or metadata layer that materially preserves or reveals the sensitivity of the underlying source.

The Corporation shall not limit protected information to what is traditionally called “confidential” in common office practice. Some information is protected because it implicates rights and safety. Some because it affects sovereign or community trust. Some because it creates severe technical misuse risk. Some because it carries institutional authority. The framework must therefore be broad enough to capture the actual constitutional reasons information requires protection.

At the same time, the Corporation shall not overprotect ordinary public-benefit materials merely because they are institutionally important. Classification must remain grounded in real handling need. Not every important document is protected; not every protected document is important in the same way. The role of the framework is disciplined differentiation.


101.3 Public, Restricted, Sensitive, Confidential, and Controlled-Room Classes

The Corporation shall maintain a classification structure that clearly distinguishes among Public, Restricted, Sensitive, Confidential, and Controlled-Room classes, together with any sub-classes or operational markers necessary for lawful and effective handling. These classes represent progressively more protective handling states, but they are not mere status ornaments. Each class must correspond to actual access, storage, transmission, review, and publication rules.

For purposes of this Part:

a) Public information is information approved for open circulation, publication, lawful broad access, or ordinary institutional transparency, subject to provenance and version discipline where relevant. b) Restricted information is information that should not be openly distributed and requires bounded internal or specifically authorized access because broader exposure would create material but not necessarily maximal harm or confusion. c) Sensitive information is information requiring tighter contextual controls because misuse, exposure, aggregation, or overbroad access could materially compromise rights, systems, trust, public meaning, partner obligations, or stewardship integrity. d) Confidential information is information requiring strong protection, narrow role-based access, and heightened handling discipline due to rights-bearing, legal, governance, reputational, security, or continuity significance. e) Controlled-Room information is information that may only be handled within a formally designated controlled environment with explicitly managed admission, segmented discussion, and restricted output discipline.

The Corporation may create operational sub-labels or metadata markers within these classes so long as they do not obscure the core constitutional meaning of the classes themselves. For example, technical, legal, community-sensitive, or security-sensitive qualifiers may be added if such qualifiers improve fit-for-purpose governance.

The Corporation shall not permit class inflation. Not everything should be Sensitive or Confidential. Nor shall it permit class dilution, where materials requiring controlled-room handling are merely tagged Restricted because stronger controls are inconvenient. Class discipline is part of institutional truth. A weakly classified environment is as dangerous as an overclassified one, though for different reasons.


101.4 Authority to Assign, Change, Review, and Remove Security Classifications

The authority to assign, change, review, or remove information classifications shall be expressly governed and shall not rest on informal social power, repository ownership alone, or casual user discretion. GCRI US shall determine which officers, custodians, maintainers, designated handlers, reviewers, or governance bodies may lawfully classify and reclassify information and under what standards.

This authority shall be exercised according to role, competence, and institutional responsibility. The Corporation shall not assume that because a person created a document or controls a repository, they necessarily possess unilateral authority to decide its enduring handling class. Nor shall it assume that seniority alone confers classification authority over all information types. Rights-bearing, legal, technical, community-sensitive, and controlled-room materials may require different approving lanes.

Accordingly, the Corporation shall define, as appropriate:

a) who may classify at first instance; b) who may approve a higher or more restrictive classification; c) who may review a classification challenge or dispute; d) who may authorize downgrading, decontrol, or public release; and e) what consultation is required where a material spans several domains, such as rights, security, legal, and public-meaning concerns simultaneously.

The Corporation shall also ensure that classification authority is reviewable. A person with authority to classify may still classify wrongly. There must therefore be a path for correction or escalation where the assigned class appears underprotective, overprotective, or inconsistent with the handling logic required by these Bylaws.

No material classification change shall occur silently if the change materially affects access, public meaning, or downstream reliance. The institution must be able to determine not only what the current class is, but who changed it, why, and when.


101.5 Marking, Labeling, and Metadata Requirements for Classified Materials

All classified or otherwise protected materials shall carry marking, labeling, and metadata sufficient to make their handling status intelligible to lawful users and systems. The Corporation shall not rely on memory, platform visibility settings alone, or implied context to communicate the classification state of a material asset. Handling status must travel with the asset to a degree proportionate to risk.

Accordingly, classified materials shall, as appropriate, include:

a) the classification label itself; b) any sub-class or sensitivity qualifier necessary to govern handling correctly; c) provenance or source status where relevant to handling; d) dissemination restrictions, if any; e) review or expiry date where the class is not indefinite; and f) links or references to the controlling repository or authoritative record where needed to avoid orphaned copies.

Metadata requirements may be especially important for:

i) files moving between repositories or collaboration systems; ii) structured datasets and exports; iii) publication drafts and restricted versions; iv) derivative summaries or controlled-room outputs; and v) cross-border, cross-entity, or vendor-shared materials.

The Corporation shall not assume that a folder name, access group, or collaboration channel alone is enough to communicate handling class once a document or artifact is exported, downloaded, or moved. A classification system that disappears when the file leaves its original environment is not a reliable classification system.

At the same time, marking and metadata shall not themselves defeat the protective purpose of the classification by revealing more than is safe to reveal. Labels should communicate handling needs without creating unnecessary inferential exposure. Part VI therefore requires a balance: enough visible classification data to govern use, but not so much that the label becomes a secondary disclosure vector.


101.6 Least Restrictive Classification Compatible With Safety, Rights, and Institutional Integrity

GCRI US shall apply the least restrictive classification compatible with safety, rights, and institutional integrity. This principle prevents both lazy overclassification and negligent underclassification. The Corporation is not constitutionally permitted to hide ordinary matters by default. Nor is it permitted to expose sensitive matters merely because stronger controls feel burdensome.

The least restrictive compatible classification is the lowest classification that still adequately protects:

a) persons and communities from avoidable exposure or retaliation; b) rights-bearing and identity-bearing information from misuse; c) repositories, systems, and credentials from compromise; d) evidence and governance materials from corruption or counterfeit reliance; and e) public meaning, continuity, and institutional trust from distortion.

This principle requires active judgment. A document that is politically sensitive but already public-safe may not require Confidential treatment. A technical note that looks mundane may nevertheless require Sensitive or Controlled-Room treatment if it reveals abuse-prone architecture. A dataset summary may be Public even if the underlying full dataset is Confidential. Classification must therefore follow actual handling need, not ambient anxiety or prestige signaling.

The Corporation shall not use high classification as a substitute for better redaction, segmentation, repository design, or summary preparation. In many cases, the most constitutional solution is not to overclassify the entire asset, but to split open and restricted layers so that public-benefit transparency and rights protection can coexist.

Where a class is chosen that is more restrictive than ordinarily expected for that kind of material, the institution shall be able to explain why the extra restriction is necessary. The burden is on the classifier, not on later users, to justify non-obvious restriction.


101.7 Periodic Review, Downgrading, Reclassification, and Decontrol Procedures

All classified materials shall be subject to periodic review and, where appropriate, downgrading, reclassification, or decontrol procedures. Classification under Part VI is a governance state, not a permanent moral quality. Information may become less sensitive over time, or in some cases more sensitive because of contextual change, aggregation, public events, or cross-entity developments. The Corporation shall therefore not treat classification as static unless the nature of the material genuinely warrants long-term fixed protection.

Periodic review shall consider, as appropriate:

a) whether the original sensitivity basis remains valid; b) whether context has changed such that broader or narrower access is now appropriate; c) whether portions of the material can be safely separated and reclassified; d) whether continued restriction is still proportionate; and e) whether decontrol, public-safe summarization, or archive reclassification is now possible without defeating rights, safety, or continuity.

Downgrading and decontrol shall not occur casually. They shall be governed by the same seriousness that applies to initial classification. If a formerly Confidential asset is now to be Restricted or Public, the Corporation shall preserve enough record to show why that determination was made and what conditions, if any, still attach to lawful use.

Likewise, if a previously lower-class material must be raised in classification because risk has changed, that shift shall be recorded and communicated to the relevant lawful users. The institution shall not leave access practices lagging behind the risk reality.

This clause is especially important for controlled-room materials, incident artifacts, historical governance records, publication drafts, and technical assets whose sensitivity may diminish after remediation, release, or infrastructure change. A rights-protective institution does not overclassify forever; it re-evaluates with discipline.


101.8 Invalidity of Unmarked or Misclassified Sensitive Handling in the Absence of Recorded Review

Sensitive handling shall not be treated as institutionally valid merely because someone informally believed material was sensitive if the material was left unmarked, misclassified, poorly segmented, or otherwise handled without recorded review where this Part required one. GCRI US shall not allow unmanaged sensitivity to serve as a substitute for formal classification. If a matter genuinely required higher protection, the institution had a duty to classify and govern it accordingly.

This clause exists because organizations often fall into one of two dangerous patterns:

a) they handle sensitive material informally “as if everyone knows,” thereby losing traceability and reviewability; or b) they later claim sensitivity after exposure has already occurred, even though the institution itself failed to classify, mark, or govern the material properly in the first place.

Under these Bylaws, neither pattern is acceptable. If material requires Sensitive, Confidential, or Controlled-Room treatment, the classification must be made visible enough—within the protected operating context—to produce the required handling effects. If that did not occur, the misclassification or non-classification itself becomes a governance defect subject to review and, where warranted, incident handling.

This does not mean that an unmarked but truly sensitive record becomes safe to disclose simply because the institution mishandled it. It means that the institution cannot defend the mishandling by pretending the sensitivity was adequately governed when it was not. The remedy is both protective and corrective: restrict further harm, classify properly, and treat the prior failure as a material control weakness.

Accordingly, the Corporation shall preserve a rule of constitutional candor: sensitivity not governed is sensitivity not yet institutionally protected, and the absence of proper classification is itself an issue demanding attention under Part VI.


101.9 Interpretive Rule for Security Classification and Handling Principles

This Section shall be interpreted to preserve a controlling proposition: classification in GCRI US exists to make handling truthful, reviewable, proportionate, and rights-protective across the full information and repository estate of the institution. It must therefore be explicit, role-governed, properly marked, periodically reviewed, and calibrated to the real constitutional significance of the material.

Where ambiguity exists, the interpretation that better preserves:

a) a coherent institutional classification framework rather than informal custom; b) clear distinction among Public, Restricted, Sensitive, Confidential, and Controlled-Room classes; c) role-governed authority to classify and reclassify; d) strong marking and metadata discipline for protected materials; and e) least restrictive compatible protection together with reviewable upgrading, downgrading, and decontrol

shall prevail unless a contrary result is required by law.

102. Protected Information Categories and Scope (GCRI United States)


102.1 Rights-Bearing Data and Personal Information

GCRI US shall treat rights-bearing data and personal information as a distinct protected information category requiring handling discipline that is informed not only by privacy law, but also by the rights, safeguards, non-retaliation, community-protection, and dignity-preserving obligations already established in Part IV. Personal information under this Part includes direct identifiers, indirect identifiers, quasi-identifiers, linked identity traces, participation-linked metadata, relational indicators, and any combination of data points that can reasonably identify, single out, expose, or materially increase vulnerability of a natural person.

Rights-bearing data is broader. It includes not only data that identifies a person, but data whose handling may materially affect a person’s rights, standing, safety, access, treatment, or exposure even where the information is partially de-identified or embedded in structured systems. The Corporation shall therefore recognize that rights-bearing data may include:

a) grievance and reporting records; b) participation records and consultation submissions; c) personnel, contributor, fellow, or volunteer records; d) access-control, attendance, and repository activity traces; e) profile, role, or community-linked metadata that makes a person inferable in context; and f) derived indicators, aggregated signals, or case-linked materials that remain materially person-affecting even if direct identifiers are absent.

The Corporation shall not treat personal information as protected only when required by a named statute. Nor shall it treat de-identification as a universal release valve. Where contextual re-identification, relational inference, retaliation risk, or social exposure remains plausible, the information remains rights-bearing for purposes of these Bylaws.

Accordingly, all such information shall be classified, accessed, processed, disclosed, and retained under a stricter standard than ordinary administrative data. The question shall not be simply “is this personal data?” It shall also be “what could happen to a person if this data is mishandled, over-shared, misinterpreted, or structurally exposed?” The answer to that second question shall shape the handling posture of the Corporation.

Where uncertainty exists, the Corporation shall presume that person-linked information is rights-bearing until a narrower classification is justified through review.


102.2 Sovereign-Sensitive, Security-Sensitive, and Public-Authority-Sensitive Information

GCRI US shall recognize a distinct protected category for sovereign-sensitive, security-sensitive, and public-authority-sensitive information. This category includes information whose misuse, overexposure, uncontrolled aggregation, or poorly governed transfer could impair lawful sovereign prerogatives, public-order responsibilities, public-authority trust, intergovernmental relations, sensitive institutional interfaces, or the safe operation of public-interest systems.

Such information may include, without limitation:

a) information relating to national or subnational public-authority workflows, institutional structures, or controlled coordination pathways; b) materials whose handling has implications for public order, emergency posture, or security-sensitive governance environments; c) protected interface records with governments, public agencies, regulators, or public authorities; d) architecture, mappings, or system-level information that may reveal sensitive public-sector dependency, vulnerability, or access conditions; e) sovereign data handling rules, localization requirements, or controlled jurisdictional arrangements; and f) context-specific information that may be ordinary in one environment but security-relevant or authority-sensitive in another.

The Corporation shall not assume that because such information is not classified by a government under formal public law, it is therefore institutionally low-risk. GCRI US operates in contexts where sensitive public-authority meaning may arise from relationships, architecture, context, or combination of facts rather than from a preexisting government classification stamp. The Corporation must therefore apply its own constitutional discipline.

This category shall be handled in a manner that respects both the Corporation’s non-executing role and the lawful dignity of public institutions. GCRI US shall not use possession of authority-sensitive information to imply governmental power, privileged standing, or hidden institutional importance beyond the truth. Nor shall it mishandle such information in ways that compromise public trust or cross-border legitimacy.

Where sovereign-sensitive and privacy-sensitive conditions overlap, the more protective combined handling posture shall generally prevail.


102.3 Indigenous, Community, and Vulnerability-Sensitive Information

Any information that is Indigenous-sensitive, community-sensitive, vulnerability-sensitive, or otherwise tied to groups or persons who may experience disproportionate harm from exposure, inference, decontextualization, or misuse shall be treated as a distinct protected information category under this Part. The Corporation shall not assume that standard privacy classifications are sufficient for such information.

This category may include:

a) information relating to Indigenous authorities, governance traditions, community processes, lands, knowledge systems, or collective concerns; b) community-originated knowledge, warnings, observations, or submissions whose meaning and safety depend upon context; c) locational, relational, or issue-specific data that could expose vulnerable communities, local actors, or protected groups to scrutiny, pressure, or retaliation; d) information linked to fragile, conflict-affected, politically sensitive, or socially polarized contexts; and e) any structured or unstructured material whose exposure could deepen marginalization, stigmatization, targeting, or institutional extraction.

The Corporation shall govern this information through a combination of privacy logic, community knowledge logic, safeguards logic, and least-disclosure logic. It shall not permit such material to be normalized as generic “stakeholder input” if that framing strips away the protective context under which it was provided or under which it can be safely understood.

This means the Corporation shall be especially careful with:

i) aggregation that increases legibility; ii) maps or metadata that turn local knowledge into wider strategic visibility; iii) reuse in publications or technical systems beyond the original protected basis; iv) seemingly harmless summaries that, in context, identify or expose the source community; and v) interface transfer to partners, hosts, or repositories whose control environment is not sufficient for the sensitivity involved.

Where there is doubt as to whether a material should be treated as vulnerability-sensitive, the safer classification shall be used until a more precise review is completed. The institution shall not burden vulnerable contributors or communities with proving why they deserved stronger protection after the fact.


102.4 Controlled Evidence, Protected Disclosures, and Whistleblower Materials

All controlled evidence, protected disclosures, whistleblower materials, grievance-linked records, and other reporting-related information shall be treated as a specially protected category requiring heightened handling discipline. These materials are not merely sensitive because of their contents. They are sensitive because of the institutional functions they enable: accountability, protected participation, correction, remedy, and non-retaliatory truth-telling.

This category includes, without limitation:

a) whistleblower submissions, whether attributed, pseudonymous, or anonymous; b) protected reports concerning integrity, retaliation, safeguards, perimeter, or security concerns; c) grievance records, supporting attachments, witness materials, and related case files; d) investigation-bound materials and evidentiary annexes; e) restricted summaries, triage notes, and handling logs for such matters; and f) derived materials whose circulation could reveal the existence, source, or substance of the protected disclosure.

The Corporation shall govern these materials on the assumption that mishandling may produce secondary harm more serious than the original concern raised. Exposure may chill future reporting, reveal vulnerable participants, distort investigations, or create retaliatory opportunity. Accordingly, such materials shall ordinarily require a handling posture stronger than routine administrative confidentiality.

The Corporation shall also distinguish clearly between:

i) the fact that a report exists; ii) the identity of the reporting person or affected persons; iii) the underlying facts alleged; and iv) the institutional response record.

These may require different levels of protection and different access pathways. A person may need to know that a matter is under review without being entitled to see identities or source evidence. The institution must structure the category accordingly.

Where a protected disclosure later proves unfounded, the material does not thereby lose all protective handling retrospectively. The reporting process itself remains protected. That is part of the constitutional seriousness of protected participation under these Bylaws.


102.5 Research-Sensitive, Model-Sensitive, and Abuse-Prone Technical Materials

GCRI US shall treat research-sensitive, model-sensitive, abuse-prone technical materials, and other technically consequential artifacts as a distinct protected information category where broad disclosure, uncontrolled reuse, or imprecise publication could materially increase risk of misuse, exploitation, security compromise, false authority, or public misunderstanding.

This category may include:

a) model configurations, prompts, rule sets, evaluation designs, or performance notes that materially increase misuse capability if widely circulated; b) implementation details of reference systems where public exposure would erode security, safeguards, or controlled-operational integrity; c) technical research outputs whose publication state is not yet mature enough for safe broad circulation; d) abuse-prone workflow details, interface mappings, automation instructions, or dependency disclosures; and e) technical annexes or code-linked materials whose combination with other public information would elevate misuse risk materially.

The Corporation shall not classify all technical material as sensitive. It shall, however, recognize that some technical artifacts are sensitive precisely because they are useful. A technically valuable artifact may create disproportionate harm if repurposed outside its intended governance context. Public-benefit stewardship requires that the Corporation identify and govern such cases before release or integration, not after misuse has already occurred.

This category also applies where technical materials could be misleadingly treated as public authority, operational validation, or canonical institutional commitment beyond what is true. A model note can become a pseudo-standard if handled carelessly. Technical sensitivity therefore includes not only abuse risk, but false institutional meaning risk.

Where the Corporation wishes to preserve public-benefit learning while reducing misuse risk, it shall prefer layered release, sanitized summaries, redacted publications, or segmented repositories rather than an all-or-nothing approach.


102.6 Third-Party Confidential Information and Contract-Protected Information

All third-party confidential information, contract-protected information, and other externally sourced materials whose handling is governed by lawful confidentiality obligations shall be treated as a distinct protected category under this Part. The Corporation shall not weaken or ignore such obligations simply because the material is operationally useful, mission-relevant, or difficult to segregate.

This category may include:

a) partner-shared materials provided under confidentiality or collaboration terms; b) vendor, host, contractor, or service-provider technical and operational information; c) academic, institutional, or public-sector materials shared under restricted terms; d) draft agreements, due-diligence files, or sensitive operational records of counterparties; and e) any information whose disclosure, repurposing, or uncontrolled internal spread would breach a lawful duty owed by GCRI US.

The Corporation shall, however, distinguish between legitimate confidentiality and overbroad contractual secrecy that conflicts with its constitutional duties. Not every document marked confidential by another party is thereby entitled to unrestricted deference if its handling would otherwise require review under Parts IV, V, or VI. The Corporation must govern both sides of the equation:

i) it must honor lawful confidentiality; and ii) it must not allow third-party secrecy terms to silently displace the Corporation’s own duties of safeguards, truthfulness, incident handling, or governance review.

Where a third-party confidentiality obligation conflicts with a legal, ethical, or constitutional obligation of the Corporation, the matter shall be escalated rather than silently resolved through one-sided deference. The existence of confidentiality does not eliminate institutional judgment. It intensifies the need for it.

This category also requires repository and workflow discipline. Contract-protected information shall not be commingled casually with open or canonical assets such that later release, reuse, or migration becomes legally or operationally confused.


The Corporation shall treat legal privilege materials, investigation files, counsel communications, litigation-hold materials, and other legally protected records as a distinct protected information category requiring heightened control, role-based access, preservation discipline, and careful segregation from ordinary operational records.

This category may include:

a) communications seeking or conveying legal advice; b) litigation preparation or dispute-response materials; c) internal investigation notes, evidence collections, and interview materials; d) materials preserved under litigation hold or analogous preservation obligation; and e) privileged or potentially privileged derivative analyses, summaries, and decision documents.

The Corporation shall not assume that because such materials are important, broad internal access is beneficial. Privilege and investigation integrity often depend on controlled distribution, clear labeling, preserved custody, and documented handling. Likewise, the Corporation shall not allow legally protected materials to lose their handling status merely because they are stored alongside ordinary governance or repository records.

At the same time, GCRI US shall not use the language of privilege casually or opportunistically. Privileged handling must correspond to actual legal or investigative status, not serve as a convenience shield against scrutiny where no proper privilege basis exists. Misuse of privileged designation can be as constitutionally damaging as underprotection because it corrodes classification trust.

Where litigation-hold or investigative preservation obligations conflict with ordinary retention or decontrol practices, the preservation obligation shall take precedence until lawfully lifted. The institution must preserve both the material and the integrity of its handling history.


102.8 Credentials, Keys, Tokens, Identity Artifacts, and Access-Control Secrets

All credentials, keys, tokens, identity artifacts, certificate materials, authentication secrets, recovery codes, signing keys, and any other access-control or trust-enabling artifacts shall be treated as one of the highest-sensitivity protected information categories under this Part. Their compromise can undermine repositories, release systems, protected records, cross-entity trust surfaces, and the Corporation’s public-good infrastructure in ways disproportionate to their size or visibility.

This category includes, without limitation:

a) user credentials and privileged credentials; b) API tokens, service-account tokens, signing tokens, and automation secrets; c) cryptographic keys, certificate material, and repository-signing or release-signing artifacts; d) hardware or software factors linked to identity or privileged access; e) backup and recovery secrets; and f) any derived or adjacent material that materially weakens protection of the foregoing.

The Corporation shall not permit such artifacts to be handled as ordinary technical information. They shall be segregated, narrowly accessible, logged, rotated where appropriate, excluded from public and ordinary repository spaces, and governed through stronger procedural controls than standard classified documents.

This category also requires special attention to indirect disclosure. A configuration file, screenshot, debug log, export, or technical note may reveal enough about credentials or identity artifacts to materially compromise them even if the secret itself is not plainly displayed. The Corporation shall govern for inferential compromise, not just direct exposure.

Where a credential, key, or token is suspected to have been exposed, misused, mishandled, or overly distributed, the Corporation shall treat the event as a security-sensitive incident requiring immediate containment, rotation, and review rather than as a minor technical cleanup matter.


102.9 Interpretive Rule for Protected Information Categories and Scope

This Section shall be interpreted to preserve a controlling proposition: GCRI US must classify and govern protected information according to the real constitutional reasons it requires protection—rights, safety, sovereignty, community trust, legal integrity, technical misuse risk, or control-surface sensitivity—rather than according to narrow office conventions or generic confidentiality habits.

Where ambiguity exists, the interpretation that better preserves:

a) stronger protection for rights-bearing and person-affecting information; b) clearer recognition of sovereign-sensitive, community-sensitive, and vulnerability-sensitive categories; c) heightened control over protected disclosures, investigations, and abuse-prone technical materials; d) careful segregation of third-party confidential and legally protected materials; and e) maximum sensitivity treatment for credentials, keys, and access-control secrets

shall prevail unless a contrary result is required by law.


103. Access Governance and Identity Controls (GCRI United States)


103.1 Identity Verification and Access Eligibility Baseline

GCRI US shall maintain a formal identity verification and access eligibility baseline for all persons and non-human actors seeking access to protected information, controlled repositories, sensitive systems, restricted workflows, collaboration environments, release channels, evidence materials, or other security-relevant institutional assets. No access right under this Part shall be treated as legitimate merely because the requester is known socially, affiliated informally, technically capable, or previously trusted in another context. Access must be grounded in verified identity and current institutional eligibility.

For purposes of this Section, identity verification shall require, as appropriate:

a) confirmation of the identity of the individual or system actor seeking access; b) confirmation of the individual’s or actor’s current role, affiliation, and relationship to GCRI US; c) confirmation that the requested access aligns with an approved institutional function; d) confirmation that any prerequisite training, attestation, confidentiality undertaking, or fit-for-role requirement has been satisfied; and e) confirmation that there is no current suspension, role conflict, separation event, or other disqualifying condition.

Eligibility is a distinct question from identity. A person may be who they claim to be and still not be eligible for the requested access. Likewise, a previously eligible person may cease to be eligible because of role change, project completion, conflict of interest, inactivity, lapse of training, departure, or changed classification of the material. The Corporation shall therefore not permit stale role assumptions to substitute for present eligibility review.

This baseline shall also apply to service accounts, automation identities, machine credentials, repository bots, and other non-human actors. GCRI US shall not allow technical agents to operate outside the same constitutional logic merely because they are not human users. If a non-human actor can read, write, release, route, transform, or expose protected materials, its identity and eligibility must be institutionally governed.

Where doubt exists about identity or access eligibility, access shall not be granted until the doubt is resolved through appropriate review. Convenience, urgency, or relationship familiarity shall not displace this baseline.


103.2 Role-Based Access Control and Attribute-Based Restrictions

All material access within GCRI US shall be governed through role-based access control supplemented, where necessary, by attribute-based restrictions. The Corporation shall not rely on flat access models, broad discretionary sharing, or informal administrative grants for systems and materials whose constitutional significance requires precision.

Role-based access control means that permissions are assigned according to defined institutional roles and functions rather than individual preference or ad hoc social hierarchy. Attribute-based restrictions mean that access may also depend on contextual attributes such as project affiliation, jurisdiction, handling clearance, training status, sensitivity of the material, time-limited purpose, device posture, or other relevant governance conditions.

Accordingly, GCRI US shall design access models so that:

a) users receive rights corresponding to what their defined role requires and no more; b) access can be segmented by class of information, repository branch, publication state, system function, geography, or case context; c) sensitive repositories and materials are not made broadly visible merely because users belong to the same general organizational area; d) contextual restrictions can narrow what even otherwise eligible users may do under particular conditions; and e) role and attribute logic remains reviewable, documentable, and technically enforceable.

The Corporation shall not treat role-based control as sufficient where context changes the risk materially. A governance officer may ordinarily require access to Board records, yet not to all controlled-room materials. A repository maintainer may require write access to an open documentation branch, yet not to restricted security configuration layers. A partner representative may need project-specific access, yet only from controlled environments or within a limited time window. Attribute-based restrictions exist to preserve such nuance.

Where a technical platform cannot implement the degree of segmentation required by these Bylaws, the Corporation shall treat that limitation as a governance issue requiring compensating controls, migration, or redesign rather than as a reason to weaken the rule.


103.3 Need-to-Know Approval Requirements for Restricted Materials

Access to Restricted, Sensitive, Confidential, and Controlled-Room materials shall require affirmative need-to-know approval proportionate to the handling class and significance of the material. The Corporation shall not permit elevated classes of information to be accessed merely because an individual’s general role is adjacent to the subject matter. Need-to-know is a substantive institutional test, not a courtesy.

Need-to-know approval shall require, as appropriate:

a) identification of the specific material or class of material sought; b) articulation of the specific institutional purpose for which access is required; c) confirmation that the requester’s role includes lawful responsibility connected to that purpose; d) confirmation that a narrower access path would not suffice; and e) approval by an authorized custodian, manager, handler, or designated access authority appropriate to the class of material.

The Corporation shall not accept vague justifications such as “this may be relevant,” “leadership should know,” “I want visibility,” or “it will be helpful for context” where the material is materially protected. Contextual curiosity is not need-to-know. A rights-bearing institution must be stricter than that.

The degree of approval formality may vary by class. Restricted material may in some cases be accessible under standing role rules with logged justification. Confidential and Controlled-Room materials will more often require discrete approval and case-specific access reasoning. What matters is not ritual complexity but constitutional fit between the request and the risk.

Need-to-know approvals shall also be time-aware and scope-aware. Approval to see one controlled bundle or one case file does not automatically authorize access to all similar materials in perpetuity. The institution shall govern the request actually made, not the broader access it might be tempting to infer from it.


103.4 Multi-Factor Authentication and Device Posture Controls

GCRI US shall require multi-factor authentication and appropriate device posture controls for access to material systems, protected repositories, rights-bearing data, restricted technical assets, publication control surfaces, credential stores, evidence environments, and other sensitive institutional resources. The Corporation shall not rely on password-only trust or unmanaged endpoint assumptions where compromise of an account or device could materially harm people, systems, or the public-good estate.

Multi-factor authentication shall be required, at minimum, wherever compromise of a single factor could provide meaningful access to restricted or privileged resources. The Corporation shall also require stronger or layered authentication conditions where the sensitivity of the resource, the privileges granted, or the surrounding threat context warrants it.

Device posture controls may include, as appropriate:

a) requiring access only from approved or managed devices for certain classes of materials; b) requiring baseline security characteristics such as current patching, encryption, screen lock, or malware protection; c) restricting certain administrative or controlled-room access from unmanaged or high-risk environments; d) requiring network or environment controls for high-sensitivity access; and e) using step-up controls for elevated or unusual access attempts.

The Corporation shall not allow convenience exceptions to silently undermine these protections. A user’s importance, familiarity, or urgency shall not justify bypassing multi-factor or device trust requirements outside a recorded emergency or break-glass procedure. Likewise, the fact that a platform technically allows weaker access does not mean the Corporation may accept it.

This clause also applies to non-human identities where technically appropriate. Service accounts, automation paths, and CI/CD or repository release functions shall be protected by controls proportionate to the sensitivity of the assets they can affect. Public-good continuity depends not only on who the users are, but on how the institution proves they are acting from an acceptable trust posture.


103.5 Privileged Access, Elevated Access, and Break-Glass Procedures

Any privileged access or elevated access within GCRI US shall be tightly governed, narrowly granted, time-bounded where possible, and subject to enhanced monitoring. Privileged access includes any access allowing material change to repositories, identity systems, credentials, production systems, release channels, evidence stores, classification settings, logging systems, or other control surfaces whose misuse could materially affect institutional integrity or rights protection.

The Corporation shall distinguish between:

a) standing privileged access necessary for a defined role; b) task-specific elevated access granted for a bounded purpose; and c) break-glass access, meaning emergency access granted outside ordinary pathways to prevent greater harm or restore urgent institutional function.

For privileged and elevated access, the Corporation shall require:

i) explicit designation of the role or task requiring the access; ii) strong authentication and access-path controls; iii) narrow scoping to the systems or materials actually required; iv) logging and review of the relevant actions; and v) removal or expiry once the basis no longer exists.

Break-glass procedures shall be exceptional and shall not become an informal shortcut for ordinary access friction. They shall be invoked only where there is credible urgency and where ordinary pathways are not adequate to prevent material institutional, rights, or system harm. Use of break-glass access shall trigger immediate or near-immediate recording, review, and ratification according to the seriousness of the context.

The Corporation shall not allow “trusted admin culture” to normalize broad privileged standing. Broad standing admin power is often governance convenience disguised as readiness. Under these Bylaws, privileged power must remain exceptional enough that it can be supervised meaningfully.


103.6 Access Reviews, Renewal Cycles, and Access Revocation

All material access rights within GCRI US shall be subject to periodic review, renewal cycles where appropriate, and prompt revocation when the lawful basis for access no longer exists. The Corporation shall not treat access grant as a one-time event followed by indefinite continuation. Persistent access without review is one of the most common ways institutional exposure silently accumulates.

Access review shall consider, as appropriate:

a) whether the person or system still occupies the role for which the access was granted; b) whether the scope of access remains proportionate to current duties; c) whether training, confidentiality undertakings, device controls, or other prerequisites remain current; d) whether the repositories or materials covered have changed class or sensitivity; and e) whether narrower rights or complete revocation are now more appropriate.

Renewal cycles may be especially important for:

i) controlled-room access; ii) cross-border or sovereign-sensitive environments; iii) project-limited partner access; iv) elevated technical privileges; and v) sensitive evidence, grievance, or protected-report environments.

Revocation shall occur promptly when a role ends, a project closes, a relationship terminates, a training requirement lapses, a conflict emerges, a suspension is imposed, or the access otherwise ceases to be justified. The Corporation shall not delay revocation because it is administratively awkward, socially uncomfortable, or operationally convenient to “leave access in place for now.” Delayed revocation is not courtesy. It is governance failure.

Where revocation affects repositories, credentials, signing keys, release authority, or controlled-room lists, the Corporation shall coordinate revocation with continuity and successor controls so that secure transition does not create either orphaned power or service instability.


103.7 Temporary, Emergency, Delegated, and Visitor Access Rules

GCRI US shall maintain explicit rules for temporary, emergency, delegated, and visitor access so that such access does not become a loophole through which Part VI is bypassed. These special access forms may be necessary for lawful institutional function, but they shall remain exceptional, bounded, and reviewable.

Temporary access shall be time-bound and purpose-bound. Emergency access shall be justified by material urgency and handled under recorded authority. Delegated access shall not amount to informal transfer of standing privilege unless the delegation is itself lawfully authorized and documented. Visitor access shall be treated as an access class with narrower default permissions and stronger escort, observation, or environmental control where the sensitivity of the material so requires.

The Corporation shall ensure that such access forms specify, as appropriate:

a) the requesting and approving authority; b) the exact scope of access granted; c) the time period for which the access remains valid; d) any additional restrictions or environmental conditions; and e) the required review, closure, or revocation step once the need has passed.

The Corporation shall not allow “temporary” to become indefinite through renewal-by-inattention, nor “visitor” to become equivalent to full participation because the visitor is prestigious or trusted. Emergency access shall not be used to solve routine planning failures. Delegated access shall not be used to evade least-privilege by asking a better-positioned user to share or proxy broad rights informally.

Where the sensitivity of the material is high, these access forms may require stricter than usual logging, monitoring, controlled-room conditions, or supervised handling. Special access is not lighter access. It is more carefully bounded access.


103.8 Logging, Monitoring, and Auditability of Access Events

All material access events affecting protected information, restricted repositories, privileged functions, controlled environments, publication control surfaces, or other stewardship-significant systems shall be subject to logging, monitoring, and auditability sufficient to support later review, anomaly detection, accountability, and incident response. Access that cannot later be reconstructed in principle is inconsistent with the governance quality required by these Bylaws.

Accordingly, GCRI US shall preserve, to a degree proportionate to the risk and system type:

a) records of access grants, changes, renewals, and revocations; b) logs of entry to sensitive systems or repositories; c) logs of privileged actions, administrative changes, or release-significant events; d) records of controlled-room admission and protected-environment participation where applicable; and e) enough contextual metadata to support investigation, review, and recurrence prevention.

The Corporation shall not require maximal surveillance of every ordinary internal movement. But wherever access to protected or powerful systems materially affects rights, continuity, public meaning, or security posture, the access must be reviewable. Monitoring and auditability are constitutional safeguards, not merely operational telemetry.

The Corporation shall also ensure that logs themselves are appropriately protected. Access logs may reveal rights-bearing patterns, privileged review conditions, or controlled-room participation. Logging is not an invitation to broad internal visibility. It is a control surface requiring its own handling discipline.

Where monitoring reveals anomalous, excessive, stale, or unexplained access behavior, the institution shall respond through the incident, review, or corrective architecture of this Part rather than treating such findings as abstract technical irregularities.


103.9 No Shared Credentials, No Informal Delegation, and No Unrecorded Access Pathways

GCRI US shall prohibit shared credentials, informal delegation of access, and unrecorded access pathways for all material systems, repositories, collaboration environments, evidence stores, release mechanisms, or protected information environments. The Corporation shall not tolerate practices that make it impossible to know who actually accessed or altered a protected asset.

Accordingly, the Corporation shall prohibit, among other things:

a) use of one account by multiple people; b) shared administrative or repository credentials except where technically unavoidable and governed under compensating controls of the highest seriousness; c) forwarding of credentials, tokens, or one-time access artifacts to another person; d) “log in for me” or “just use my access” practices; and e) side-channel viewing or downloading of protected materials by persons who were not directly granted access through the proper record.

The Corporation shall also prohibit informal delegation by which a person with legitimate access becomes the proxy distributor of protected information to others who were never reviewed under the relevant access rules. Need-to-know attaches to the recipient, not only to the original holder.

Where workflow difficulty seems to invite such practices, the Corporation shall treat the difficulty as a design problem to be corrected through proper access pathways rather than allowing informal workaround culture to arise. A secure institution designs for lawful access. It does not accept insecure sharing as an inevitable social patch.

Any discovered shared credential, proxy access, or unrecorded access route shall be treated as a material governance defect and, where the circumstances warrant, as an incident under this Part.


103.10 Interpretive Rule for Access Governance and Identity Controls

This Section shall be interpreted to preserve a controlling proposition: access within GCRI US must always remain identity-bound, role-bound, context-bound, time-bound where appropriate, and auditable. No person or system may access protected institutional assets merely because access would be convenient, prestigious, socially efficient, or technically possible.

Where ambiguity exists, the interpretation that better preserves:

a) verified identity and present eligibility as prerequisites to access; b) role-based and attribute-based narrowing of permissions; c) real need-to-know approval for protected materials; d) stronger controls for privileged, temporary, and emergency access; and e) logging, review, revocation, and prohibition of shared or informal access paths

shall prevail unless a contrary result is required by law.

104. Controlled-Room Doctrine (GCRI United States)


104.1 Controlled Room as a Formal Governance and Handling Environment

A Controlled Room within GCRI US shall mean a formally designated governance and handling environment—physical, virtual, or hybrid—in which access, deliberation, materials, records, and outputs are subjected to heightened restrictions, monitored handling discipline, and bounded disclosure rules because ordinary institutional channels are inadequate to protect rights, safety, integrity, confidentiality, public meaning, repository continuity, or other constitutionally protected interests under these Bylaws.

A Controlled Room is not merely a secure meeting. It is not merely a private folder. It is not merely a smaller audience. It is a distinct institutional state of handling with consequences for:

a) who may be admitted; b) what materials may enter; c) how those materials may be viewed, discussed, copied, or retained; d) what minutes, notes, or summaries may be created; e) how outputs may be sanitized, classified, or released; and f) what audit trail, expiry logic, and escalation standards apply.

The Corporation shall therefore treat Controlled-Room designation as a governance act, not as an informal courtesy among trusted insiders. The existence of a sensitive matter does not by itself create a Controlled Room. A Controlled Room exists only when the institution has deliberately invoked the handling state and the related operating rules of this Part.

This distinction matters because a public-benefit institution can otherwise drift into two opposite pathologies:

i) highly sensitive matters are handled casually in ordinary channels because everyone “knows” they are important; or ii) prestige or political sensitivity is used to create opaque inner circles with no real handling discipline and no reviewable boundary.

Part VI rejects both patterns. Controlled Rooms exist to create a narrow, accountable, rights-aware, and reviewable zone for matters that cannot safely be handled in ordinary channels. They are not a social rank marker. They are not a shield for unrecorded power. They are a formal protective environment serving a defined constitutional purpose.

Where the conditions of a true Controlled Room are not present, the Corporation shall not use the language of controlled handling to create false legitimacy around informal secrecy.


104.2 Purpose and Trigger Conditions for Controlled-Room Use

The purpose of Controlled-Room use is to enable GCRI US to handle specific classes of high-consequence material or deliberation in a manner that preserves people, protected participation, rights-bearing data, evidence integrity, security-sensitive infrastructure, legal and investigatory discipline, and truthful public meaning without collapsing into uncontrolled secrecy or uncontrolled exposure.

Controlled-Room use shall be triggered where credible circumstances indicate that ordinary repositories, meetings, channels, or review processes are insufficient because broader access or less segmented handling would materially risk:

a) retaliation against a reporting, dissenting, or affected person; b) disclosure of rights-bearing, identity-bearing, community-sensitive, Indigenous-sensitive, or vulnerability-sensitive information; c) compromise of security-sensitive or abuse-prone technical details; d) corruption or contamination of evidence, investigation, or grievance integrity; e) counterfeit or distorted public meaning if premature or uncontrolled discussion escapes the protected setting; f) legal privilege loss, litigation prejudice, or severe contractual breach; g) cross-entity handling conflict requiring highly bounded visibility; or h) any comparable harm that cannot be adequately prevented through ordinary Restricted or Confidential handling alone.

The Corporation shall not require absolute certainty of harm before activating a Controlled Room. A credible material risk threshold is enough. If the likely consequence of ordinary handling would be serious and the costs of temporary tighter restriction are proportionate, the safer course shall generally be controlled handling pending review.

At the same time, the trigger is not “importance” alone. Not every strategic, senior, controversial, or politically sensitive matter belongs in a Controlled Room. Controlled-Room use is justified by handling risk, not by prestige, embarrassment, donor sensitivity, or desire for narrative control. A matter may be highly visible and still belong in ordinary governance channels if its sensitivity does not exceed the protections available there.

Accordingly, the Corporation shall activate Controlled-Room treatment only where the risk logic is specific enough that the institution can explain, in the appropriate protected record, why ordinary handling would be constitutionally inadequate.


104.3 Matters Requiring Controlled-Room Treatment

Without limiting the Corporation’s discretion to designate other qualifying matters, the following classes of matters shall ordinarily be treated as requiring Controlled-Room handling unless a narrower but still constitutionally adequate handling regime is affirmatively justified and recorded:

a) protected disclosures, whistleblower materials, retaliation-sensitive grievances, and associated investigative or review files; b) matters involving vulnerable, at-risk, threatened, or otherwise specially protected participants where ordinary visibility would materially increase harm; c) Indigenous-sensitive, community-sensitive, sovereignty-sensitive, or public-authority-sensitive materials whose circulation must remain tightly bounded; d) high-consequence legal strategy, privilege-bearing materials, investigation materials, or litigation-hold-linked evidence; e) security-sensitive technical materials, secrets-adjacent artifacts, high-risk configurations, incident response internals, or abuse-prone implementation details not suitable even for ordinary Confidential circulation; f) evidence sets or governance artifacts whose custody, segmentation, and traceability are central to later legitimacy; g) cross-entity coordination matters where broader disclosure would produce classification conflict, rights harm, or severe public confusion; and h) any matter for which Board-, integrity-, safeguards-, or legal-level review has already determined that ordinary channels are constitutionally inadequate.

The Corporation shall not interpret this list mechanically. Some matters within these classes may be safely abstracted into non-controlled summaries for wider governance use. Others may require Clean-Room treatment rather than ordinary Controlled-Room handling. The point of this clause is to establish the baseline expectation that some categories are presumptively too sensitive for ordinary collaborative handling.

Likewise, the Corporation shall not narrow the category simply because modern tools make broad sharing easier. Ease of distribution is not evidence of constitutional fitness. A single shared link to a case file, an internal wiki page, or a seemingly private channel does not transform ordinary environments into Controlled Rooms.

Where a matter within one of these categories is handled outside a Controlled Room, the decision to do so shall itself be reviewable. The institution must be able to show why a lower handling mode remained adequate.


104.4 Authority to Designate, Activate, and Close a Controlled Room

The power to designate, activate, and close a Controlled Room shall rest only with those officers, functions, or bodies expressly authorized by GCRI US to make such determinations according to the seriousness and type of matter involved. Controlled-Room status shall not arise informally through social practice or unilateral assertion by a participant who prefers tighter handling.

Depending on internal structure and delegation, authority may appropriately reside with or include:

a) designated safeguards, security, legal, integrity, or records functions; b) authorized executive officers acting within their remit; c) specific Board or committee authorities for matters of particular constitutional significance; and d) other formally designated custodians or controllers of specially protected processes, repositories, or evidence environments.

The Corporation shall ensure that designation authority is:

i) narrow enough to prevent prestige-driven overuse; ii) broad enough that urgent protective activation is possible when needed; and iii) documented enough that later review can determine who created the Controlled Room, on what basis, and for what scope.

Activation of a Controlled Room shall require, at minimum:

  1. identification of the matter or class of matter;

  2. statement of the protective basis;

  3. assignment of the initial handling scope and responsible authority; and

  4. creation of a controlled record sufficient to govern access and review.

Closure of a Controlled Room shall likewise require recorded determination that the basis for controlled handling has sufficiently changed, expired, or been resolved such that the matter may be closed, decontrolled, migrated to another class, or archived under a different restricted posture. Closure shall not occur by neglect, by calendar expiration without review, or by loss of attention. If the room is no longer needed, that too must be governed.


104.5 Relationship Between Controlled Rooms and Publication Classes

Controlled-Room designation is distinct from, but closely related to, the publication class of any materials, summaries, decisions, or outputs arising from the protected process. A matter may require Controlled-Room handling even if some final output is later public-safe. Conversely, a material may be Confidential without requiring the full operating environment of a Controlled Room. GCRI US shall keep these concepts analytically separate so that handling discipline and publication discipline remain precise.

Accordingly, the Corporation shall govern:

a) the internal handling environment of the matter; and b) the external or wider internal publication class of any resulting output

as related but not interchangeable decisions.

This means, for example, that:

i) a Controlled-Room case may produce a sanitized summary suitable for a Restricted or even Public class audience; ii) a Controlled-Room deliberation may generate no releasable output beyond a tightly held internal record; iii) a document originating outside a Controlled Room may still become Controlled-Room material because of the way it is later used; and iv) a Controlled-Room matter may require multiple output classes for different audiences.

The Corporation shall not assume that because something was “discussed in a Controlled Room,” it can never be summarized. Nor shall it assume that because a summary is public-safe, the underlying matter never required controlled handling. Confusing these layers leads either to needless opacity or to harmful over-disclosure.

Publication-class decisions arising from Controlled-Room matters shall be made with explicit reference to the risks that justified the Controlled Room in the first place. If a summary can be made truthful and safe without reproducing those risks, the Corporation should consider doing so. If not, the Controlled-Room logic remains controlling.


104.6 No Controlled-Room Use for Mere Convenience or Prestige

GCRI US shall not use Controlled-Room designation for mere convenience, status display, reputational shielding, political sensitivity alone, hierarchical exclusivity, or institutional theater. Controlled Rooms are constitutionally serious handling environments. Their legitimacy depends on being reserved for actual protective need.

Accordingly, the Corporation shall prohibit use of Controlled Rooms merely because:

a) a matter involves senior leadership; b) the participants are high profile; c) a discussion may be embarrassing if leaked; d) the issue is strategically delicate but not rights-, security-, or integrity-sensitive in the sense contemplated by this Part; e) a smaller circle is socially easier to manage; or f) the institution wishes to create an aura of seriousness or exclusivity around the matter.

This prohibition is important because overuse of Controlled Rooms can be as damaging as underuse. If the institution deploys controlled handling as a badge of importance, the result is likely to be:

i) dilution of controlled-room seriousness; ii) unnecessary opacity around ordinary governance; iii) erosion of internal trust; and iv) increased temptation to use handling rules to manage institutional image rather than real risk.

The Corporation shall therefore preserve a culture in which Controlled-Room designation is understood as a burden-bearing protection mechanism, not a privilege. Participants should understand that admission reflects handling necessity, not rank or favor. Non-participants should be able to trust that if a matter is placed in a Controlled Room, there is a real and reviewable protective reason for that decision.

Where a matter can be safely handled in ordinary or merely Restricted channels, those channels shall be used.


104.7 Record of Designation, Scope, Access List, and Expiry Conditions

Every Controlled Room shall have a protected but reviewable record of designation, identifying the scope of the room, the basis for its creation, the assets or matters covered, the admitted participants or participant classes, and any relevant expiry, review, or closure conditions. A Controlled Room without a governance record is merely an informal secrecy practice, which these Bylaws do not permit.

The record shall, as appropriate, include:

a) the title or reference identifier of the matter; b) the designating authority and date of designation; c) the reason controlled handling is required; d) the handling scope, including whether the room covers all related materials or only specified components; e) the initial or current access list, or the rule by which that list is maintained; f) the publication-class relation of any anticipated outputs; and g) review points, expiry conditions, or closure triggers.

This record need not be broadly visible. It may itself be Confidential or Controlled-Room bound. But it must exist in a form that supports later review by authorized functions, including review of whether the room was justified, whether access remained appropriately narrow, and whether the room should have been closed or reclassified earlier.

The Corporation shall not permit “rolling” Controlled Rooms that exist indefinitely without meaningful review. If a room remains open for an extended period, the record shall show why continued controlled status is still needed. Duration without justification is a sign of governance drift.

Where access lists are dynamic, the record shall preserve enough change history that participant additions and removals remain reconstructable. Controlled-room seriousness depends in part on knowing not only what the room was, but who was ever entitled to see what it contained.


104.8 Minimum Transparency and Publishable Summary Rule for Controlled-Room Matters

Although Controlled Rooms are restrictive environments, GCRI US shall maintain a minimum transparency and publishable summary rule for Controlled-Room matters wherever lawful and safe. This means that the existence of controlled handling shall not be used to extinguish all accountability, erase all intelligibility, or create a vacuum in which those outside the room cannot distinguish real governance from mere asserted sensitivity.

Where compatible with rights, safety, privilege, and constitutional handling duties, the Corporation shall consider whether a Controlled-Room matter can support one or more of the following:

a) a public-safe or restricted summary of the category of issue handled; b) a bounded statement that a matter was reviewed or remains under review; c) a de-identified or generalized explanation of the governance action taken; d) a statement of process or classification outcome without revealing protected substance; or e) a later historical or archival clarification once the protective basis has materially diminished.

This rule is not a mandate for forced disclosure. Many Controlled-Room matters will properly remain highly restricted. It is a mandate against total non-explanation where some truthful and safe explanation is possible and where silence would materially harm trust, create false public meaning, or obscure the fact that institutional review actually occurred.

The Corporation shall not use the language of “ongoing sensitivity” to indefinitely avoid asking whether any publishable summary can now be produced. Summary discipline is part of the constitutional balance between protection and accountability. In some cases, the correct answer will be that no summary is safe. That answer is permissible if recorded and periodically re-evaluated. In other cases, a tightly bounded summary may preserve legitimacy without creating exposure. The institution shall choose with seriousness.


104.9 Interpretive Rule for Controlled-Room Doctrine

This Section shall be interpreted to preserve a controlling proposition: Controlled Rooms in GCRI US are formal, reviewable, rights-aware handling environments used only when ordinary channels are constitutionally inadequate, and operated so as to protect sensitive matters without creating unbounded secrecy or prestige-based exclusion.

Where ambiguity exists, the interpretation that better preserves:

a) Controlled Rooms as genuine governance environments rather than informal privacy; b) activation only on the basis of real protective triggers; c) disciplined authority, scope, access records, and closure logic; d) separation between controlled handling and publication-class decisions; and e) the possibility of truthful, safe minimum transparency where the protective basis permits it

shall prevail unless a contrary result is required by law.

105. Controlled-Room Admission Standards (GCRI United States)


105.1 Eligibility Criteria for Admission

Admission to any Controlled Room within GCRI US shall be governed by strict eligibility criteria grounded in role necessity, institutional purpose, safeguards compatibility, and handling competence. Admission is not a right derived from affiliation, seniority, visibility, or proximity to the subject matter. It is a conditional authorization granted only where participation is demonstrably necessary and compatible with the protective conditions that justified the Controlled Room.

Eligibility shall require, at minimum:

a) a defined institutional role or function directly connected to the matter under controlled handling; b) a demonstrable need-to-know aligned with that role; c) current compliance with training, attestation, and handling obligations under Part VI; d) absence of disqualifying conflicts, restrictions, or prior handling breaches; and e) capacity to participate without increasing risk of exposure, misuse, distortion, or retaliation.

The Corporation shall not equate “interest” or “stakeholder relevance” with eligibility. A participant may be materially affected by a matter and still not be eligible for direct admission if their participation would compromise safeguards or handling integrity. In such cases, alternative pathways—such as mediated input, sanitized briefings, or controlled summaries—shall be considered.

Eligibility shall also be dynamic. A person eligible at one stage of a matter may cease to be eligible at another stage due to narrowing scope, increased sensitivity, or role transition. Admission is therefore not permanent unless explicitly structured as such under a defined governance need.

Where eligibility is uncertain, the presumption shall favor non-admission pending review. Controlled Rooms protect against irreversible exposure; admission decisions must reflect that asymmetry.


105.2 Credential, Fit-and-Proper, and Current-Status Requirements

All persons admitted to a Controlled Room must meet credential, fit-and-proper, and current-status requirements proportionate to the sensitivity and constitutional significance of the matter. This requirement ensures that admission reflects not only role alignment but also trustworthiness, competence, and current institutional standing.

Credential requirements may include:

a) verification of identity and institutional affiliation; b) confirmation of role-based authorization; c) completion of required training modules for controlled handling; and d) execution of confidentiality and safeguards undertakings.

Fit-and-proper assessment shall consider:

i) past handling discipline and compliance history; ii) absence of unresolved integrity, security, or retaliation concerns; iii) capacity to respect rights-bearing, community-sensitive, or protected information; and iv) independence and conflict posture where relevant to the matter.

Current-status requirements ensure that admission reflects present conditions. A person whose role has lapsed, whose clearance has expired, whose training is outdated, or whose conflict posture has changed shall not be treated as eligible merely because they were previously admitted.

The Corporation shall not assume that institutional seniority or external reputation substitutes for fit-and-proper status. Controlled-Room participation requires discipline and alignment with institutional safeguards. Prestige without discipline is not sufficient.

Where necessary, admission may be conditional upon additional undertakings, conflict disclosures, or limited-scope participation.


105.3 Need-to-Know Justification and Access Approval Workflow

Admission to a Controlled Room shall require a documented need-to-know justification and adherence to a defined access approval workflow. This workflow shall ensure that admission decisions are deliberate, reviewable, and consistent with the protective basis of the Controlled Room.

The justification shall specify:

a) the precise function the participant will perform; b) the specific information or segment of the matter required; c) the reason that function cannot be fulfilled through lower-access alternatives; and d) the expected duration and scope of participation.

Approval shall be granted only by authorized custodians or controllers of the Controlled Room, consistent with Section 104.4. Depending on the sensitivity, approval may require:

i) single-authority authorization for lower-sensitivity controlled contexts; ii) dual-control or multi-role concurrence for higher-sensitivity or rights-critical matters; and iii) escalation to legal, safeguards, or Board-level authority where warranted.

The workflow shall be recorded in a manner that preserves:

  1. the request;

  2. the justification;

  3. the approving authority; and

  4. any conditions or limitations applied.

The Corporation shall not allow informal admission through verbal invitation, unrecorded inclusion, or implicit participation. Every participant in a Controlled Room must be there through a traceable decision.

Where multiple participants are admitted under a shared justification (e.g., a defined working group), the justification must still be explicit and bounded. Group membership does not override individual need-to-know discipline.


105.4 Confidentiality Undertakings and Controlled-Handling Acknowledgments

All Controlled-Room participants shall execute confidentiality undertakings and controlled-handling acknowledgments appropriate to the classification and sensitivity of the materials involved. These undertakings shall not be treated as ceremonial. They are binding affirmations of understanding and acceptance of the handling rules that govern participation.

Such undertakings shall include, as appropriate:

a) acknowledgment of classification and handling restrictions; b) commitment not to disclose, copy, or transmit materials outside permitted channels; c) acknowledgment of identity protection, non-retaliation, and protected-participation obligations; d) agreement to comply with device, recording, and communication restrictions; e) acknowledgment of monitoring, logging, and auditability requirements; and f) awareness of consequences for breach, including removal, sanction, or escalation.

The Corporation shall ensure that participants understand not only the rules but the reasons behind them. Controlled-room discipline depends on comprehension, not just formal agreement.

Where participants are external to GCRI US, such undertakings shall be aligned with contractual obligations and may require additional legal structuring. However, external status shall not weaken the substance of the obligations.

The Corporation shall not permit participation without executed acknowledgment. Where emergency admission is required, provisional acknowledgment shall be recorded and formalized as soon as practicable.


105.5 Restrictions on Advisers, Observers, Vendors, and External Participants

Admission of advisers, observers, vendors, and other external participants to Controlled Rooms shall be subject to stricter scrutiny than internal participants due to increased risk of exposure, misalignment of obligations, and potential cross-boundary handling conflicts.

The Corporation shall require:

a) explicit justification for external participation beyond general relevance; b) confirmation that the external participant’s role cannot be fulfilled through alternative, lower-exposure means; c) contractual and legal alignment with GCRI US confidentiality and handling obligations; d) restriction of access scope to the minimum necessary subset of materials; and e) heightened monitoring, segmentation, or supervised participation where appropriate.

Observers shall not be admitted merely for informational purposes. A Controlled Room is not an educational or reputational venue. It is a protective environment for specific governance functions.

Vendors and service providers shall not be admitted to Controlled Rooms unless their presence is strictly necessary for technical or operational execution and cannot be substituted by abstracted or mediated input. Even then, their access shall be constrained and, where possible, separated from direct exposure to rights-bearing or high-sensitivity content.

The Corporation shall also consider jurisdictional and cross-border implications of external participation. Admission shall not create unintended transfer of protected information across legal or sovereignty boundaries without proper review.


105.6 Special Conditions for Participation by Public Officials, Community Representatives, and Protected Persons

Participation by public officials, community representatives, Indigenous authorities, or protected persons shall be governed with additional care to preserve both their role dignity and their safety. Such participants may have legitimate need-to-know but may also face heightened exposure risk, political sensitivity, or representational constraints.

Accordingly, GCRI US shall ensure:

a) that participation pathways respect the participant’s institutional or community obligations; b) that handling conditions do not inadvertently expose the participant or their constituency; c) that identity, attribution, and participation records are governed according to risk; d) that participation does not imply endorsement, authority transfer, or institutional alignment beyond what is true; and e) that alternative participation mechanisms are available where direct admission would create disproportionate risk.

For protected persons, including whistleblowers or vulnerable participants, admission may require additional safeguards such as anonymized participation, proxy representation, or segmented sessions. The Corporation shall not force exposure as the price of participation.

The Corporation shall also recognize that some participants may require culturally or contextually specific handling conditions. Controlled-room discipline must be adaptable enough to respect these without weakening core safeguards.


105.7 Admission Denial, Conditional Admission, Suspension, and Removal Procedures

The Corporation shall maintain formal procedures for denial, conditional admission, suspension, and removal of Controlled-Room participants. These procedures ensure that admission remains aligned with evolving risk, role, and handling conditions.

Admission may be denied where:

a) eligibility criteria are not met; b) need-to-know is insufficiently justified; c) conflicts or risks cannot be mitigated; or d) handling competence or compliance is in doubt.

Conditional admission may include:

i) limited-scope access; ii) time-bound participation; iii) supervised or segmented involvement; or iv) additional undertakings or restrictions.

Suspension or removal may occur where:

  1. handling rules are breached or at risk of breach;

  2. role or eligibility conditions change;

  3. new information alters the risk profile; or

  4. continued participation would compromise safeguards.

These decisions shall be recorded and, where appropriate, communicated to the affected party with sufficient explanation consistent with confidentiality constraints.

The Corporation shall not allow continued participation solely to avoid discomfort or reputational friction. Controlled-room integrity requires willingness to adjust access when conditions change.


105.8 Review and Appeal of Access Decisions Where Appropriate

Where appropriate and consistent with the sensitivity of the matter, GCRI US shall provide review or appeal pathways for Controlled-Room access decisions. These pathways shall not undermine the protective purpose of the Controlled Room but shall ensure that access governance remains fair, reasoned, and reviewable.

Review may consider:

a) whether eligibility criteria were correctly applied; b) whether need-to-know was adequately assessed; c) whether alternative participation pathways were properly considered; and d) whether denial or restriction was proportionate to the risk.

Appeal processes shall be:

i) limited to authorized reviewing authorities; ii) conducted within protected handling conditions; and iii) structured to avoid disclosure of the underlying sensitive material beyond what is necessary for review.

The Corporation shall not treat appeals as adversarial proceedings. They are governance checks to ensure that protective decisions remain aligned with institutional principles and are not distorted by error, bias, or misunderstanding.

In some cases, especially involving high-sensitivity or controlled evidence, appeal may be limited or unavailable due to overriding protective considerations. In such cases, the limitation itself shall be recorded and justified.


105.9 Interpretive Rule for Controlled-Room Admission Standards

This Section shall be interpreted to preserve a controlling proposition: admission to Controlled Rooms in GCRI US must remain necessity-driven, role-bound, risk-aware, and reviewable, with protection of people and integrity of the matter prevailing over convenience, status, or inclusion preference.

Where ambiguity exists, the interpretation that better preserves:

a) strict eligibility and need-to-know discipline; b) fit-and-proper and current-status requirements; c) recorded approval workflows and access traceability; d) strong conditions for external and high-risk participants; and e) capacity to deny, restrict, suspend, or remove access where warranted

shall prevail unless a contrary result is required by law.

106. Controlled-Room Operating Procedures (GCRI United States)


106.1 Physical, Virtual, and Hybrid Controlled-Room Modalities

GCRI US may operate Controlled Rooms in physical, virtual, or hybrid modalities, provided that each modality satisfies the substantive protective requirements of Part VI. The constitutional status of a Controlled Room does not depend on whether participants are physically co-located. It depends on whether the environment, tooling, access conditions, records discipline, and handling controls are sufficient to preserve confidentiality, integrity, need-to-know, and bounded output.

A physical Controlled Room shall be one in which the Corporation can control entry, presence, material movement, observation, note-taking, and environmental exposure. A virtual Controlled Room shall be one in which the Corporation can control admission, authentication, device and channel use, session permissions, file handling, and the creation or suppression of derivative artifacts such as recordings, exports, or screenshots. A hybrid Controlled Room shall meet both sets of requirements simultaneously and shall not be treated as constitutionally adequate merely because one side of the room is well controlled while the other is permissive.

The Corporation shall not assume that virtual handling is necessarily weaker or physical handling necessarily stronger. A carefully designed virtual environment may be safer than an informally run in-person meeting. Conversely, a prestigious boardroom may still be constitutionally inadequate if people can enter casually, devices remain uncontrolled, notes are unmanaged, or side-channel disclosures are easy.

Accordingly, before selecting a modality, GCRI US shall consider:

a) the nature and class of the material; b) the number and distribution of lawful participants; c) the degree of rights-sensitive, security-sensitive, or identity-sensitive content involved; d) the technical and environmental controls actually available; and e) whether the chosen modality increases or decreases the risk of leakage, coercion, misinterpretation, or custody failure.

Where no modality can presently satisfy the required safeguards, the Controlled-Room process shall be deferred, narrowed, or redesigned rather than proceeding in a constitutionally inadequate environment.


106.2 Entry, Exit, Attendance, and Presence Verification Controls

All Controlled-Room sessions shall be governed by explicit entry, exit, attendance, and presence verification controls sufficient to ensure that only authorized persons participate, that participation is traceable, and that unauthorized observation or silent presence does not occur.

The Corporation shall ensure, as appropriate, that:

a) entry occurs only through approved and authenticated pathways; b) each admitted participant is verified at the time of entry, whether physically or virtually; c) attendance is recorded in a protected log or equivalent control record; d) participants cannot be substituted, proxied, or silently joined by unapproved persons; and e) exit is controlled in a manner that supports post-session reconciliation of who was present for what portions of the matter.

For physical rooms, presence verification may require room access control, sign-in discipline, observation of who remains in the room, and procedures preventing casual ingress or egress during protected deliberation. For virtual rooms, it may require authenticated session links, active participant verification, disabled anonymous entry, host-controlled admission, and confirmation that off-camera or dial-in ambiguity does not defeat identity assurance. For hybrid rooms, controls shall ensure that remote participants are not structurally less verified than in-room participants, and vice versa.

The Corporation shall not treat attendance logging as optional because “everyone knows who was there.” In high-sensitivity contexts, later inability to determine participation may undermine review, incident response, or legitimacy of the handling process itself. Presence verification is therefore part of the chain of controlled handling, not a mere administrative convenience.

Where participants join or leave only for a subset of agenda items, the record shall preserve that segmentation sufficiently to support later questions of need-to-know, exposure scope, and controlled-summary preparation.


106.3 Device, Recording, Printing, Copying, and Communication Restrictions

Controlled Rooms shall be subject to strict restrictions on devices, recording, printing, copying, and communications proportionate to the sensitivity of the matter. The Corporation shall not permit uncontrolled personal technology, informal recording habits, or unbounded copying behavior to defeat the purpose of controlled handling.

Accordingly, GCRI US may impose, as appropriate:

a) prohibition or restriction on personal devices in physical Controlled Rooms; b) requirement for managed or pre-approved devices only; c) prohibition on recording, screenshots, transcription, screen capture, photography, or external note-syncing unless expressly authorized; d) prohibition or restriction on printing, downloading, copying, forwarding, exporting, or local saving of materials; and e) prohibition on side-channel communications during the session except through approved and logged pathways.

The Corporation shall not assume that because participants are trustworthy, device restrictions may be relaxed by default. Much controlled-room leakage arises not from malicious intent but from convenience actions: photos of whiteboards, synced meeting notes, copied excerpts into personal apps, prints left behind, or messages sent for quick clarification. These Bylaws require design against that pattern.

Where recording or copying is exceptionally authorized, the authorization shall be specific, narrow, and recorded. The institution shall determine:

i) what may be captured; ii) by whom; iii) for what purpose; iv) under what classification and storage conditions; and v) how the resulting artifact will itself be governed.

Communications restrictions also apply to virtual environments. A participant may not lawfully be “in” a Controlled Room while simultaneously transmitting protected substance through unmanaged chat, email, consumer messaging, or AI tools not approved for the classification level involved. Controlled-room presence entails channel discipline, not merely meeting attendance.


106.4 Screen-Sharing, Whiteboard, Note-Taking, and Collaboration Restrictions

All screen-sharing, whiteboard use, note-taking, and other forms of collaborative interaction inside a Controlled Room shall be governed by restrictions sufficient to prevent uncontrolled derivative artifacts, secondary disclosure, or ambiguity about what constitutes the authoritative record of the session.

The Corporation shall ensure, as appropriate, that:

a) screen-sharing occurs only from approved materials and by authorized participants; b) whiteboards, shared canvases, and collaborative surfaces are configured or managed so that their contents do not persist outside controlled conditions unless expressly authorized; c) note-taking is either prohibited, tightly limited, or conducted only by designated note-holders; and d) no participant treats personal notes as though they were unrestricted personal property once those notes contain controlled-room substance.

The Corporation shall not assume that collaborative productivity tools are neutral. In many cases they automatically store, sync, transcribe, index, or export information beyond the scope intended by the room. Where such tools cannot be configured to preserve controlled handling, they shall not be used for the relevant session.

If limited note-taking is allowed, the Corporation shall determine:

i) who may take notes; ii) what form the notes may take; iii) where they must be stored; iv) whether they are to be surrendered, uploaded, or destroyed after use; and v) whether those notes are themselves part of the controlled record.

Whiteboards and collaborative surfaces shall be treated with special caution because they often create highly distilled, highly sensitive summaries that are easier to photograph or misinterpret than longer primary materials. The same is true of screen-shared dashboards or case summaries. Controlled-room collaboration must therefore be governed not only at the point of access to source materials, but also at the point where new derivative information is created during the room itself.


106.5 Secure Minutes, Limited Notes, and Restricted Summary Preparation

Each Controlled-Room session shall produce only such secure minutes, limited notes, and restricted summaries as are necessary for lawful institutional memory, decision traceability, follow-up action, and later review. The Corporation shall avoid both extremes: no record at all, which invites arbitrariness and amnesia, and over-documentation, which multiplies secondary exposure risk.

Secure minutes shall, where appropriate:

a) record the date, session identifier, scope of the matter, and authorized participants; b) identify the procedural actions taken, decisions reached, unresolved issues, and next-step assignments; c) avoid unnecessary reproduction of protected details, identities, or source-sensitive content; and d) be stored in a protected repository or record system consistent with the classification of the matter.

Limited notes may be prepared only under the rules established in Section 106.4 and shall not substitute for secure minutes unless the designated note function itself constitutes the official record. Restricted summaries may be prepared where a broader but still bounded audience needs to understand the institutional disposition without receiving full controlled-room content.

The Corporation shall ensure that restricted summaries:

i) preserve truth; ii) avoid reconstructing protected details; iii) do not imply more certainty, consensus, or authority than the room actually produced; and iv) remain classified and distributed according to their own proper publication class rather than by casual internal circulation.

No participant may privately publish their own “summary” of a Controlled-Room matter into ordinary channels without authorization. Controlled summary preparation is a stewardship act, not a personal convenience. The distinction between secure minutes, working notes, and releasable summary must remain visible and governed at all times.


106.6 Segmentation by Topic, Case, and Participant Need-to-Know

Controlled Rooms shall be operated with segmentation by topic, case, and participant need-to-know wherever such segmentation is necessary to avoid overexposure. Admission to a Controlled Room does not automatically entitle a participant to all materials or all sub-discussions associated with the room. The Corporation shall structure participation so that the scope of visibility remains as narrow as reasonably possible.

Segmentation may be required where:

a) a single session covers multiple cases or files with different participants or affected persons; b) parts of a matter involve legal, technical, community-sensitive, or rights-sensitive detail not needed by all attendees; c) some participants are present for decision on one component but not for review of source materials underlying another; or d) a hybrid or multi-stage process would otherwise expose more protected content than institutional necessity requires.

Segmentation techniques may include, as appropriate:

i) agenda partitioning; ii) staged entry and exit; iii) differential document access even within the same room; iv) nested controlled-room bundles; and v) separate summaries or note channels for different participant groups.

The Corporation shall not run a broad “everything in one room” model where a more segmented design is feasible. Such designs often arise from scheduling or leadership convenience rather than constitutional necessity. Under Part VI, convenience does not justify excess exposure.

Segmentation is especially important in matters involving protected reporting, community-originated information, legal privilege, high-risk technical details, or cross-entity coordination where different participants may have legitimate need for different slices of the same matter. A well-run Controlled Room is therefore not just closed; it is internally minimized.


106.7 Controlled-Room Timeboxing, Continuation, and Extension Discipline

Controlled-Room handling shall be subject to timeboxing, continuation, and extension discipline. A Controlled Room is not meant to become a standing permanent condition by inertia. Its protected status must be justified for a particular matter, scope, and time horizon, and revisited as those conditions evolve.

Timeboxing means that, where appropriate, the Corporation shall define:

a) the expected duration of the session or handling period; b) the review point at which continuation must be reconsidered; and c) the expiry condition beyond which the room may not simply continue without recorded renewal.

Continuation or extension may be justified where:

i) the matter remains unresolved and ordinary channels remain constitutionally inadequate; ii) the risk profile has not materially diminished; iii) new but related material requires ongoing segmented review; or iv) closure would create greater rights, security, or integrity risk than continued control.

However, the Corporation shall not allow extension because:

a) no one has time to reclassify; b) a room has become the social norm for a working group; c) participants prefer a prestigious closed environment; or d) the institution finds it easier to leave a matter indefinitely “under control” than to decide what should happen next.

Each continuation or extension shall be recorded with enough specificity to show why the room remains necessary, whether the scope has narrowed or expanded, and what the next review point will be. Where a matter has become routine, the Corporation shall consider whether a lower but still adequate classified workflow is now more appropriate. Controlled Rooms are for exception-worthy handling, not permanent institutional style.


106.8 Closure, Material Return, Sanitization, and Secure Disposal Procedures

At the conclusion of a Controlled-Room session or upon formal closure of a Controlled-Room matter, GCRI US shall implement closure, material return, sanitization, and secure disposal procedures sufficient to prevent residue exposure, orphaned copies, stale access, or confusing afterlife of protected artifacts.

Closure procedures shall, as appropriate, include:

a) confirmation that no unauthorized participant remains in the room or session; b) collection, surrender, upload, or destruction of authorized limited notes where required; c) return, deletion, or controlled retention of temporary files, printouts, handouts, or local caches; d) sanitization of whiteboards, shared workspaces, temporary collaboration surfaces, and virtual room artifacts; e) revocation or expiry of temporary access granted for the session; and f) placement of official minutes, summaries, and materials into the appropriate protected repository or record system.

The Corporation shall not treat closure as complete merely because participants log off or leave the room. In many cases, the main risk begins after the session: cached browser files, persistent chat threads, AI-generated recap artifacts, printed documents, photographed screens, unsurrendered notes, or informal follow-up messages. Closure discipline exists to manage the afterlife of the room, not only its live proceedings.

Where material must be retained, retention shall occur under the correct class and repository discipline. Where material should not be retained, deletion or destruction shall be secure, reviewable where necessary, and not left to informal participant discretion. Controlled-room safety depends on both strong entry and strong exit.


106.9 Interpretive Rule for Controlled-Room Operating Procedures

This Section shall be interpreted to preserve a controlling proposition: a Controlled Room in GCRI US is only as real as its operating discipline. Entry controls, device restrictions, note rules, segmentation, timeboxing, and closure procedures are not ancillary. They are what distinguish a constitutionally governed protected environment from an ordinary meeting with a privacy aura.

Where ambiguity exists, the interpretation that better preserves:

a) modality-specific controls equivalent to the risk of the matter; b) verified attendance and participant traceability; c) stricter restrictions on devices, copying, and uncontrolled collaboration; d) secure and minimal record creation together with segmented need-to-know operation; and e) disciplined closure, sanitization, and secure post-session handling

shall prevail unless a contrary result is required by law.

107. Clean-Room Procedures and High-Sensitivity Workflows (GCRI United States)


107.1 Distinction Between Controlled Room and Clean Room

GCRI US shall maintain a clear and enforceable distinction between a Controlled Room and a Clean Room. Although both are protected handling environments, they serve different constitutional functions and shall not be used interchangeably.

A Controlled Room is a protected governance and deliberation environment in which access, discussion, records, and outputs are restricted because ordinary channels are insufficiently safe or sufficiently auditable for the matter at hand. A Clean Room, by contrast, is a higher-discipline environment designed not only to restrict participation but also to structurally limit what information may be brought together, how it may be combined, what transformations may occur, and what outputs may lawfully emerge. The Clean Room is therefore not merely a more secret meeting. It is a controlled processing environment in which the institution deliberately separates source data, processing logic, identities, and resulting outputs in order to reduce misuse, leakage, anticompetitive exposure, rights harm, or impermissible contextual fusion.

The Corporation shall recognize several core differences:

a) a Controlled Room primarily governs who may know and discuss protected matters; b) a Clean Room governs what may be processed, combined, inferred, or emitted even among otherwise authorized participants; c) a Controlled Room may tolerate fuller contextual discussion where lawful need exists; d) a Clean Room is designed specifically to constrain contextual fusion and derivative exposure; and e) a Controlled Room is often deliberative, whereas a Clean Room is often analytical, transformation-oriented, or comparison-oriented.

This distinction matters because misuse of the two concepts produces opposite failures. If a matter requiring Clean-Room discipline is handled only in a Controlled Room, the institution may inadvertently allow impermissible combination, inferential reconstruction, or processing overreach. If a Controlled Room matter is unnecessarily pushed into Clean-Room form, the institution may create unjustified opacity, processing burden, or inability to preserve the deliberative record properly.

Accordingly, GCRI US shall determine for each high-sensitivity matter whether the risk lies chiefly in access and discussion, in which case a Controlled Room may suffice, or chiefly in combination, transformation, aggregation, or derivative output risk, in which case Clean-Room discipline may be required. Where both conditions exist, the stricter combined posture shall govern.


107.2 Clean-Room Use for Competition-Sensitive, Rights-Sensitive, or Highly Restricted Work

GCRI US shall use Clean-Room procedures for competition-sensitive, rights-sensitive, highly restricted, or otherwise high-consequence workflows where the mere fact of lawful access is not sufficient to protect against harm. A Clean Room is particularly appropriate where allowing participants or systems to see, join, compare, or transform source materials in ordinary or even controlled-room fashion would materially increase legal, ethical, or institutional risk.

Clean-Room use may be required where, among other things:

a) the work involves highly sensitive rights-bearing or community-sensitive data that must be analyzed without exposing direct source context broadly; b) the matter involves comparison or aggregation of inputs from different entities where direct raw visibility would create antitrust, competition, confidentiality, or undue-inference risk; c) technical, repository, or governance artifacts must be reviewed in a way that prevents broader source disclosure; d) security-sensitive or abuse-prone materials require bounded analytical treatment without general access to the full source corpus; e) an external partner or vendor must participate in tightly circumscribed processing without broad visibility into protected institutional materials; or f) lawful public-benefit analysis requires the institution to preserve strong separation between source information and resulting publishable or operational outputs.

The Corporation shall not interpret “competition-sensitive” narrowly as relevant only to commercial markets. In a broader governance sense, competitive sensitivity may also arise where institutions, contributors, hosts, or counterparties possess materially sensitive internal information whose direct visibility to others would distort neutrality, trust, or lawful cooperation. Likewise, rights sensitivity is not limited to personal data. It includes situations where the structure of combined information could expose protected communities, whistleblowers, vulnerable participants, or sovereign-sensitive contexts.

The Corporation shall not deploy Clean Rooms merely because a matter is prestigious or politically delicate. Clean-Room use is justified only where risk is materially linked to data combination, direct source visibility, transformation logic, or derivative-output control—not merely to the fact that a discussion is sensitive. Clean-Room treatment must remain a precision instrument.


107.3 Aggregation, Minimization, and De-Identification Requirements in Clean-Room Contexts

All Clean-Room workflows shall be governed by strict requirements of aggregation, minimization, and de-identification proportionate to the nature of the source materials and the risks associated with exposure, inference, or downstream use. The constitutional purpose of a Clean Room is not simply to move sensitive work into a more private environment. It is to change the structure of handling so that fewer harmful facts, identities, or relationships become exposed along the way.

Accordingly, GCRI US shall require that Clean-Room operations, where appropriate:

a) minimize source fields, source rows, source features, or source records to only those necessary for the specific analytical or governance purpose; b) aggregate data or evidence into forms that reduce the ability of participants to trace back to individual persons, communities, institutions, or assets where such traceability is not essential to the lawful purpose; c) apply de-identification, pseudonymization, masking, tokenization, or equivalent methods sufficient to reduce direct and indirect exposure risk; and d) preserve awareness that de-identification is not binary and that contextual re-identification risks must still be governed.

The Corporation shall not mistake reduction in direct identifiers for full risk elimination. In many high-sensitivity contexts, indirect attributes, small sample structures, geographic precision, event timing, or relational linkage may recreate the same exposure that formal de-identification was meant to avoid. Clean-Room minimization must therefore be contextual and adversarially aware: what could a capable insider infer from what remains?

Aggregation and minimization rules shall also govern outputs, not only inputs. A result set that preserves too much granularity, too many small cells, or too many cross-linked dimensions may be functionally equivalent to direct disclosure even if the raw source never left the Clean Room. The Corporation shall therefore assess both ends of the workflow.

Where the legitimate institutional purpose requires some retention of identity-bearing or high-granularity source material, the Clean Room shall still preserve segmentation so that only those roles absolutely requiring such detail may interact with it. The default shall always be less source, less exposure, less reversible inference.


107.4 Separation of Source Data From Publishable or Operational Outputs

A Clean Room within GCRI US shall maintain strict separation between source data and publishable, shareable, operational, or otherwise downstream-usable outputs. The Corporation shall not allow outputs emerging from Clean-Room work to carry through more source detail, inferential traceability, or rights-bearing exposure than is necessary for the legitimate purpose of the output.

This separation means, at a minimum, that:

a) source materials shall remain within the protected Clean-Room handling environment unless a higher-authority reclassification or explicitly governed transfer permits otherwise; b) outputs intended for broader circulation shall be transformed, summarized, abstracted, redacted, or otherwise sanitized before release; c) the relation between source and output shall remain traceable internally for audit and legitimacy purposes without requiring that the output itself reproduce the source; and d) no participant shall treat access to source data as automatically conferring rights to export or repurpose derivative detail beyond the approved output class.

The Corporation shall distinguish among:

i) source-preserving internal analytical artifacts; ii) restricted downstream outputs for narrow internal or cross-entity use; iii) controlled summaries suitable for a larger but still bounded audience; and iv) public-safe outputs that no longer materially expose source-level detail.

The integrity of a Clean Room depends heavily on this separation. Without it, the institution risks creating a protected front-end with an uncontrolled back-end, where the actual harm occurs not through access to the room, but through overly rich derivative outputs. A Clean Room that does not govern outputs is not a real Clean Room.

The Corporation shall also ensure that operational outputs do not silently become a channel for prohibited reuse. A workflow summary, policy option memo, dashboard, benchmark, or technical comparison produced in a Clean Room may still need restrictions if the underlying source sensitivity continues to matter. Separation from source does not eliminate all downstream obligations. It creates the conditions under which those obligations can be narrowed and governed.


107.5 Clean-Room Access, Processing, Review, and Exit Controls

Every Clean-Room environment shall be governed by explicit controls over access, processing, review, and exit. The Corporation shall not allow a Clean Room to be treated as a generic protected workspace where participants may process information freely once admitted. The entire point of the Clean Room is that access and processing remain jointly constrained.

Accordingly, GCRI US shall define, for each Clean Room:

a) who may enter, under what identity and eligibility conditions; b) what source materials may enter and in what form; c) what processing actions, joins, comparisons, queries, transformations, or analytical methods are permitted; d) what review stages or approval gates apply before outputs may leave the room; and e) what closure, sanitization, destruction, or archival requirements apply at exit.

Processing controls may include, as appropriate:

i) approved analytical scripts or methods only; ii) prohibition on free-form extraction or unrestricted exploration where such exploration increases inference risk; iii) restricted joining of datasets or case files; iv) pre-approved query categories; v) stepwise review of intermediate outputs; and vi) logging sufficient to reconstruct what was done and by whom.

Exit controls shall be at least as strict as entry controls. Nothing may leave the room unless it has been reviewed under the output discipline of this Section and the resulting artifact is assigned an appropriate handling class. Participants may not personally decide that a derivative chart, cell count, note, export, or visual is “safe enough” to circulate.

Where a Clean Room is established for a discrete workflow, its processing permissions shall expire or be re-reviewed once that workflow concludes. Standing ambient Clean-Room access without purpose-bound processing logic is inconsistent with the doctrine of this Part.


107.6 No Public Release of Clean-Room Materials Without Recorded Reclassification or Sanitization

No material originating from a Clean Room shall be publicly released, openly repository-published, broadly circulated, or otherwise treated as public-safe unless it has undergone recorded reclassification, sanitization, or equivalent formal review sufficient to establish that release will not defeat the protections that justified Clean-Room handling in the first place.

This rule applies not only to raw source data, but also to:

a) intermediate analytic outputs; b) derived tables, charts, dashboards, and extracts; c) summary memos and technical comparisons; d) model outputs or evaluation artifacts built from Clean-Room source materials; and e) metadata, notebooks, scripts, prompts, or configurations that preserve too much of the source logic or inferential structure.

The Corporation shall not rely on intuition or informal consensus to determine that Clean-Room outputs are releasable. Public or broad release requires a recorded institutional judgment that:

i) the output is sufficiently abstracted, aggregated, redacted, or otherwise transformed; ii) no rights-bearing, community-sensitive, competition-sensitive, or sovereignty-sensitive source condition is materially defeated; iii) no inferential reconstruction path remains that would be constitutionally significant; and iv) the publication class assigned to the output accurately reflects its new risk profile.

Reclassification or sanitization may result in more than one permissible output class. A public-safe executive summary may be releasable while the detailed technical annex remains Restricted or Confidential. A partner-safe comparison may be permissible while underlying case-linked evidence remains permanently confined to the Clean Room. The Corporation shall preserve such distinctions explicitly.

Where uncertainty remains material, the output shall remain non-public until the uncertainty is resolved by the appropriate review authority. Clean-Room discipline is defeated by irreversible release made in optimism.


107.7 Independent Review and Auditability of Clean-Room Operations

All Clean-Room operations shall be subject to independent review and auditability proportionate to their constitutional significance. A Clean Room is a high-trust environment by design, and precisely for that reason it must be reviewable. The Corporation shall not allow the language of heightened protection to create zones in which no one can later assess whether the protections were actually real, proportionate, and lawfully applied.

Auditability shall require, as appropriate:

a) a recorded designation basis and scope; b) participant and access records; c) source-ingestion records; d) processing logs or equivalent controlled action traces; e) output review decisions and classification outcomes; and f) closure, retention, and destruction records.

Independent review may involve, depending on the context:

i) internal security, safeguards, legal, privacy, or records functions not operationally identical to the processing team; ii) Board-level or designated oversight where constitutional significance is high; iii) sampling or retrospective review of Clean-Room practices across matters; and iv) external review support where legally appropriate and consistent with the handling posture of the room.

The Corporation shall not equate “technical reproducibility” with governance auditability. A room may be analytically sound yet constitutionally deficient if access was too broad, source minimization too weak, or outputs insufficiently sanitized. Auditability must therefore examine both process and principle.

Where review identifies repeated patterns of overexposure, insufficient minimization, poor output discipline, or unjustified use of Clean-Room designation, the matter shall be treated as a structural control weakness and not merely as an isolated workflow defect.


107.8 Cross-Entity and Third-Party Conditions for Clean-Room Participation

Where a Clean Room involves cross-entity participation or third-party participation, including hosts, vendors, contractors, partner institutions, public authorities, researchers, or related Nexus-oriented bodies, GCRI US shall impose additional conditions sufficient to preserve its own constitutional duties while respecting lawful partner constraints. Shared participation shall not dilute Clean-Room discipline.

Such conditions may include, as appropriate:

a) written participation terms and handling undertakings; b) explicit specification of what source materials each entity may contribute or access; c) segmentation between parties where common visibility would be excessive or legally problematic; d) jurisdiction, localization, conflict-of-law, and confidentiality review before source ingestion or output transfer; e) restrictions on onward use, derivative analysis, retention, or local copying by external participants; and f) agreed procedures for incident response, disputes, review, and exit.

The Corporation shall not assume that because another entity has its own controls, those controls are equivalent to or substitutable for the obligations of GCRI US. If a third party cannot meet the necessary handling standard, the Clean-Room workflow must be redesigned, narrowed, or declined rather than weakened.

Cross-entity Clean Rooms are especially sensitive because they can unintentionally become channels for impermissible competitive exposure, uncontrolled data combination, sovereignty conflict, or false assumptions of shared authority. GCRI US shall therefore preserve role clarity at all times. Joint participation does not create fused governance unless formally and lawfully established at a level higher than this workflow.

Where a cross-entity Clean Room cannot be run in a manner that preserves both collaboration and constitutional integrity, the Corporation shall choose integrity over convenience.


107.9 Interpretive Rule for Clean-Room Procedures and High-Sensitivity Workflows

This Section shall be interpreted to preserve a controlling proposition: a Clean Room in GCRI US exists to constrain not only access, but also combination, processing, inference, and derivative output in circumstances where high-sensitivity work cannot be handled safely through ordinary or even standard controlled-room methods.

Where ambiguity exists, the interpretation that better preserves:

a) the distinction between Controlled-Room and Clean-Room purposes; b) stronger minimization, aggregation, and de-identification of source materials; c) clearer separation of protected source data from downstream outputs; d) tighter control over what may be processed, exported, or reclassified; and e) stronger auditability and cross-entity safeguards for high-sensitivity workflows

shall prevail unless a contrary result is required by law.

108. Chain-of-Custody for Evidence and Governance Artifacts (GCRI United States)


108.1 Chain-of-Custody as a Mandatory Condition for Sensitive Evidence Handling

GCRI US shall treat chain-of-custody as a mandatory condition for the lawful, trustworthy, and governance-valid handling of sensitive evidence, protected records, controlled-room materials, restricted technical artifacts, incident evidence, grievance files, investigatory materials, and other stewardship-significant artifacts whose institutional value depends materially upon their traceability, authenticity, and integrity.

Chain-of-custody under these Bylaws is not limited to forensic or criminal-law style evidence handling. It is a broader institutional discipline governing whether GCRI US can later show, with sufficient confidence and legitimacy:

a) what a protected artifact was; b) where it came from; c) who handled it and under what authority; d) whether it was altered, copied, moved, segmented, transformed, or summarized; and e) whether the current state of the artifact can still be relied upon for governance, review, incident response, corrective action, or historical record.

This discipline is mandatory because many of the Corporation’s most consequential materials are not merely informative. They are constitutive of institutional action. A grievance annex may ground a remedy decision. A protected disclosure may trigger escalation. A repository snapshot may support an integrity investigation. A controlled-room summary may anchor later governance review. If the institution cannot show how these materials moved and changed, it cannot fully defend either their use or the legitimacy of the decisions based upon them.

Accordingly, GCRI US shall not treat chain-of-custody as necessary only in exceptional crisis conditions. It shall be built into ordinary handling wherever the significance of the artifact requires later proof of authenticity, integrity, or handling correctness.

Where chain-of-custody is absent, incomplete, or materially unreliable, the Corporation shall not simply presume that the artifact remains fully fit for all purposes. The gap itself becomes a governance fact requiring classification, review, and, where appropriate, limitation on reliance.


108.2 Scope of Materials Subject to Custody Controls

Custody controls under this Section shall apply to all materials whose sensitivity, evidentiary significance, governance consequence, or protected-handling status requires traceable movement and controlled integrity. The Corporation shall interpret the scope of custody-governed materials broadly enough to capture not only traditional evidence files but also the many modern technical and documentary artifacts on which institutional legitimacy now depends.

Materials subject to custody controls may include, without limitation:

a) protected disclosures, whistleblower materials, grievance records, witness materials, and associated evidentiary annexes; b) legal and investigation materials, incident records, privileged submissions, and preservation-bound content; c) controlled-room records, clean-room source materials, and restricted summaries; d) sensitive repository exports, release artifacts, signed packages, configuration states, logs, and forensic captures; e) records of access, classification, sanction, remedy, or governance actions where later review may depend on authenticated lineage; f) structured datasets, extracts, redacted variants, de-identified derivatives, and transformation outputs where the relation between versions matters; and g) any other artifact for which integrity, origin, and movement are materially relevant to its lawful institutional use.

The Corporation shall not assume that because a material is digital, reproducible, or cloud-stored, ordinary file history is sufficient to satisfy custody requirements. Many digital artifacts can be copied, altered, renamed, exported, or context-stripped in ways that preserve technical existence while destroying evidentiary confidence. Part VI requires stronger discipline where governance consequence is real.

At the same time, the Corporation need not impose full custody controls on every ordinary working note or low-significance internal record. The duty is proportional. What matters is whether later legitimacy depends materially on being able to prove the artifact’s origin, integrity, and controlled movement. If it does, custody controls apply.

Where doubt exists, the safer presumption shall be that the material is custody-governed until the contrary is reviewed and recorded.


108.3 Custody Record, Identifier, Timestamp, and Handler Requirements

Every custody-governed artifact shall have a corresponding custody record sufficient to establish its identity, handling history, and integrity status across its institutional life cycle. The Corporation shall not permit sensitive evidence or governance-significant artifacts to exist in a state where their provenance and handling must later be reconstructed from memory, fragmented logs, or email chains.

The custody record shall, as appropriate, include:

a) a unique identifier or functionally equivalent means of distinguishing the artifact from other items; b) description of the artifact or asset class sufficient to support later recognition without unnecessary overexposure; c) source or origin information, including date or intake context where relevant; d) timestamps for creation, receipt, access, movement, duplication, transformation, review, release, archival, or destruction events; e) identity of the authorized handler or handling function associated with each material custody event; and f) classification, repository, or storage context sufficient to preserve handling meaning.

The Corporation shall not allow anonymous or unattributed handling of custody-governed materials except where protected anonymity is itself required, in which case the handling architecture shall still preserve a traceable protected identifier or equivalent control record. Chain-of-custody must remain institutionally knowable even where public disclosure of identity would be unsafe.

Handler requirements mean that every material custody event shall be attributable to a person, role, or system actor authorized to perform the relevant action. “Someone moved the file” or “the team updated the artifact” is not sufficient. Precision matters, especially where later challenge or incident review may turn on who acted and under what authority.

Timestamps and identifiers shall be precise enough to support serious later review, but the Corporation shall also ensure that custody records do not become unnecessary secondary exposure surfaces. The record must preserve accountability without defeating the protective purpose of the underlying classification.


108.4 Transfer, Copying, Access, and Movement Controls

All transfers, copies, access events, exports, downloads, uploads, migrations, segmentations, and other movements of custody-governed materials shall be subject to explicit controls proportionate to the sensitivity and institutional consequence of the artifact. The Corporation shall not allow sensitive evidence or governance artifacts to drift through repositories, inboxes, shared drives, personal devices, or partner systems in ways that weaken the chain of custody.

Accordingly, GCRI US shall require, as appropriate:

a) documented authorization for transfer or copying; b) preservation of classification and provenance across movement; c) restriction on uncontrolled duplication or informal side-channel forwarding; d) use of approved channels and approved storage contexts only; e) segmentation or redaction where the whole artifact need not move; and f) reconciliation of custody records after significant movement or handoff.

The Corporation shall distinguish between access and custody. A person may view an artifact without becoming its custodian. But where an access event includes possession, download, local save, transformation, annotation, or onward routing, the action may have custody implications and must be governed as such.

The Corporation shall also recognize that copying is often the critical custody event. A copied artifact may be harder to govern than the original if the copy loses repository linkage, provenance markers, or handling metadata. Accordingly, the institution shall avoid multiplying copies unless operationally or legally necessary. Where copies must exist, their relation to the primary artifact and their own classification state must remain explicit.

Where custody-governed material crosses system boundaries, organizational boundaries, or jurisdictional boundaries, the movement shall be subject not only to ordinary transfer controls but also to any applicable privacy, sovereignty, controlled-room, or partner-security constraints under this Part.


108.5 Tamper-Evidence, Integrity Checks, and Preservation Rules

GCRI US shall maintain tamper-evidence, integrity checks, and preservation rules sufficient to support confidence that custody-governed materials remain authentic, complete within the relevant scope, and not silently altered in ways that would materially impair lawful reliance.

Tamper-evidence does not require that every artifact be cryptographically sealed in all contexts, but it does require that the Corporation use technical or procedural means adequate to reveal unauthorized or unexplained alteration where such alteration would matter. These means may include, as appropriate:

a) repository commit history and protected branch discipline; b) hashes, signatures, checksums, or equivalent technical integrity markers; c) sealed or restricted storage environments; d) document version locking and controlled edit paths; e) evidentiary comparison logs; and f) procedural witness, dual-control, or controlled-review mechanisms where technical controls alone are insufficient.

Preservation rules require that the artifact be kept in a state sufficient for its legitimate future use. This may include preserving original form, preserving metadata, preserving relation to source bundles, preserving redaction history, preserving linked summary context, or preserving the fact of supersession rather than silently overwriting the earlier state.

The Corporation shall not equate ordinary backup with evidentiary preservation. A backup may preserve bytes while destroying the interpretive and custodial context needed for governance reliance. Likewise, routine collaborative editing history may not be sufficient to show whether a change was authorized, integrity-preserving, or constitutionally significant. Part VI requires a stronger fit between preservation method and the kind of artifact involved.

Where an artifact cannot feasibly be preserved in fully original form, the Corporation shall preserve enough information about the transformation or migration that later users can still understand what was lost, what was preserved, and what degree of reliance remains justified.


108.6 Admissibility and Traceability Standards for Governance Use

Any custody-governed material used for governance, oversight, sanction, remedy, incident response, publication correction, or other consequence-bearing institutional action shall satisfy sufficient admissibility and traceability standards for the purpose to which it is being put. Under these Bylaws, admissibility is not a narrow courtroom concept. It is the standard by which the Corporation determines whether an artifact is institutionally fit to support serious action.

Traceability requires that the institution can show how the artifact entered the record, how it moved, whether it remained materially intact, and what transformations occurred. Admissibility requires that the artifact’s handling quality, integrity, and contextual reliability are sufficient for the decision at hand. An artifact may be usable for low-stakes background awareness yet not fit for formal sanction. It may be adequate for triage but not final disposition. Part VI requires such distinctions to be made explicitly.

Accordingly, before relying materially on a custody-governed artifact, the Corporation shall ask, as appropriate:

a) is the origin of this artifact sufficiently known; b) has the chain-of-custody remained materially intact; c) have there been any unexplained gaps, copies, or transformations; d) does the current form preserve enough context for fair and accurate interpretation; and e) is the artifact fit for this specific governance purpose?

The Corporation shall not treat all traceable materials as equally admissible. Nor shall it discard all imperfect materials as worthless. Institutional seriousness requires calibrated judgment. Some artifacts with modest custody weaknesses may still support contextual review or preliminary concern assessment. Others may require independent corroboration. Others may need to be excluded from high-consequence reliance altogether.

The key requirement is that the Corporation not overstate the evidentiary confidence of materials whose custody record does not justify that confidence.


108.7 Breach, Break, or Gap in Custody and Required Remediation

Any breach, break, gap, unexplained divergence, or other material weakness in chain-of-custody shall be treated as a governance-significant event requiring classification, review, and, where appropriate, remediation. The Corporation shall not conceal or normalize custody weakness simply because it is administratively inconvenient or because the underlying material remains substantively important.

A custody issue may arise where:

a) an artifact’s source cannot be reliably established; b) a transfer or copy occurred outside approved channels; c) a handler or access event cannot be identified; d) an unexplained version difference or integrity anomaly appears; e) local copies proliferated without control; or f) an artifact left and re-entered controlled custody without adequate record.

Upon identifying such a gap, GCRI US shall, as appropriate:

i) contain further movement of the artifact; ii) classify the severity and likely effect of the custody problem; iii) determine whether the artifact can still be relied upon, and for what purposes; iv) reconstruct the handling history as far as reasonably possible; v) create a corrective custody record documenting both the gap and the remediation; and vi) assess whether the issue reflects a larger control weakness requiring structural correction.

The Corporation shall not assume that every custody gap invalidates all use. Nor shall it assume that a gap is harmless unless proven otherwise. The question is how the gap affects the integrity, context, and fitness of the material for the intended institutional purpose. The more severe the consequence-bearing use, the more demanding the remediation and admissibility review shall be.

Where a gap implicates rights-bearing information, protected disclosures, legal privilege, or restricted technical assets, the matter may also trigger incident handling under other sections of Part VI.


108.8 Retention, Secure Archival, and Disposal of Custody-Governed Materials

All custody-governed materials shall be subject to disciplined retention, secure archival, and disposal rules consistent with their classification, legal status, governance significance, and continuing need for institutional traceability. The Corporation shall not permit sensitive evidence or governance artifacts to remain indefinitely in uncontrolled limbo, nor shall it destroy them casually in ways that erase needed institutional memory or frustrate later review.

Retention shall be determined by considering, as appropriate:

a) the legal or policy obligations applicable to the material; b) whether the artifact may be needed for remedy, audit, appeal, recurrence analysis, historical record, or successor governance; c) the sensitivity and exposure risk of continued retention; and d) whether a lower-risk archival form can preserve necessary traceability without preserving unnecessary direct exposure.

Secure archival shall require that retained materials remain:

i) protected by appropriate classification and access control; ii) linked to their custody records, identifiers, and provenance metadata; iii) retrievable by authorized functions when legitimately needed; and iv) protected against silent degradation, integrity loss, or archival orphaning.

Disposal shall occur only under rules sufficient to ensure that:

  1. the basis for destruction is lawful and recorded;

  2. any litigation hold, investigation hold, or preservation override has been cleared;

  3. all known copies subject to disposal control are addressed to the extent reasonably possible; and

  4. the fact of disposition remains in the institutional record even when the artifact itself no longer does.

The Corporation shall not preserve full copies of highly sensitive material where a lower-exposure retained record of the fact, provenance, and disposition would suffice. Nor shall it destroy custody-governed material so completely that the institution can no longer explain what once existed, why it mattered, and what became of it. Stewardship requires both memory and restraint.


108.9 Interpretive Rule for Chain-of-Custody for Evidence and Governance Artifacts

This Section shall be interpreted to preserve a controlling proposition: where GCRI US relies on sensitive evidence or governance-significant artifacts, it must be able to show what the artifact was, where it came from, how it moved, whether it remained intact, and what degree of reliance it can honestly support. Chain-of-custody is therefore a condition of institutional legitimacy, not just administrative neatness.

Where ambiguity exists, the interpretation that better preserves:

a) broad enough scope for custody controls to cover modern technical and governance artifacts; b) stronger identification, timestamping, and handler traceability; c) tighter controls on transfer, copying, and movement; d) clearer response to breaks or gaps in custody; and e) secure retention, archival, and disposition that preserve both integrity and institutional memory

shall prevail unless a contrary result is required by law.

109. Privacy and Data Rights Baseline (GCRI United States)


109.1 Privacy as a Core Institutional and Safeguards Obligation

Privacy within GCRI US shall be treated as a core institutional obligation and not merely as a technical compliance matter, statutory checklist, or downstream constraint on otherwise preferred institutional behavior. Privacy is one of the constitutional means by which the Corporation preserves dignity, protected participation, lawful trust, and disciplined stewardship of rights-bearing information. It is therefore inseparable from the safeguards architecture of Part IV and the security architecture of Part VI.

The Corporation shall understand privacy not only as protection against unauthorized disclosure, but as a broader governance discipline concerning:

a) whether information is collected at all; b) whether collection is proportionate to mission and lawful purpose; c) whether identity-bearing and person-affecting information is used only within the bounds of legitimate institutional need; d) whether information is retained, linked, or combined in ways that increase exposure beyond what was justified at intake; and e) whether the people and communities affected by institutional data processing remain protected from misuse, coercion, retaliation, stigmatization, surveillance-like handling, or decontextualized secondary use.

Accordingly, privacy under these Bylaws shall be understood as protecting not only the individual data subject in a narrow legal sense, but also the broader trust conditions under which participation, grievance, evidence submission, research collaboration, community engagement, and public-benefit institutional work remain possible. A technically secure institution can still violate privacy if it collects too much, keeps too much, reuses too freely, or broadens internal visibility without necessity. Privacy therefore begins before access control and extends beyond it.

This clause also means that GCRI US shall not justify privacy-weak practices on the basis that the institution is mission-aligned, nonprofit, or acting in the public interest. Public-interest purpose is not a waiver of privacy duty. It increases the obligation to act with restraint because the institution’s legitimacy depends on being trusted with sensitive information without normalizing over-collection or over-processing.

Where privacy interests appear to conflict with convenience, analytic ambition, or institutional appetite for visibility, privacy shall prevail unless a lawful, proportionate, and recorded basis supports a narrower conclusion.


109.2 Lawful Basis, Purpose Limitation, and Proportionality in Data Processing

GCRI US shall process personal information and other rights-bearing data only on a lawful basis, for a defined and legitimate purpose, and in a manner that is proportionate to that purpose. The Corporation shall not gather, retain, analyze, share, or repurpose person-affecting information merely because it may be useful later, may enrich institutional visibility, or might support unspecified future initiatives.

A lawful basis under this Part requires more than abstract institutional good intent. It requires that the Corporation be able to identify, for the relevant processing activity:

a) the institutional function the processing serves; b) the legal, governance, or operational basis under which the processing is justified; c) the category of information involved; d) the persons or communities affected; and e) why the same purpose cannot reasonably be served through less intrusive means.

Purpose limitation requires that the Corporation define, at or before meaningful collection or use, what the processing is for, and that the information not later be expanded into unrelated or materially broader uses absent a fresh, lawful, and recorded basis. Proportionality requires that even where the purpose is legitimate, the intensity, granularity, duration, and spread of processing be no greater than necessary.

Accordingly, the Corporation shall reject practices such as:

i) collecting identity-rich data for vague “context”; ii) retaining broad person-linked datasets simply because storage is easy; iii) merging protected information streams into larger analytic environments without renewed review; iv) repurposing grievance, participation, or community data for secondary institutional analytics absent a proper basis; and v) justifying broad processing with generalized claims of public-benefit usefulness.

The relevant test shall always be: what exactly is the institution doing with this information, why is that use necessary, and is the scope of processing no wider than required? If those questions cannot be answered clearly, the processing is constitutionally suspect under this Part.

Where several lawful bases may appear available, the Corporation shall prefer the one that best preserves transparency, restraint, and rights protection rather than the one that simply gives the institution the widest practical latitude.


109.3 Data Minimization, Accuracy, and Storage Limitation

GCRI US shall govern all person-affecting and rights-bearing information according to the principles of data minimization, accuracy, and storage limitation. These principles are structural safeguards against institutional overreach, not mere data hygiene.

Data minimization means the Corporation shall collect, receive, retain, expose, and process only the minimum amount of information reasonably necessary for the lawful and defined purpose at issue. This includes minimization of:

a) fields and attributes collected; b) precision and granularity of the information; c) number of persons or teams exposed to the information; d) duration of retention; and e) number of systems, repositories, or workflows through which the information travels.

Accuracy means that where the Corporation relies upon person-affecting information, especially for rights-sensitive, grievance-sensitive, access-sensitive, or governance-significant purposes, it shall take reasonable steps to ensure that the information is not materially false, stale, or misleading in context. Accuracy here is not only factual correctness at a point in time; it also includes contextual accuracy sufficient to avoid unfair or unsafe institutional use.

Storage limitation means that the Corporation shall not preserve person-linked or rights-bearing information longer than reasonably necessary for the relevant purpose, legal obligation, or controlled institutional memory need. Information retained beyond purpose becomes institutional risk unless a fresh basis for retention is recorded.

The Corporation shall therefore not normalize:

i) broad “keep everything” approaches for convenience; ii) indefinite retention of identity-bearing drafts, exports, or derivative notes; iii) stale copies of controlled records across unmanaged systems; or iv) retention of data-rich source materials where lower-risk summaries or structured retention substitutes would suffice.

These principles apply not only to direct collections from individuals, but also to data received from partners, public authorities, repositories, technical systems, and derived analytical workflows. The fact that information arrived from elsewhere does not reduce the Corporation’s duty to minimize and limit its own processing.

Where uncertainty exists about whether a field, retention period, or derivative copy is truly necessary, the narrower position shall generally prevail.


109.4 Rights of Access, Correction, Restriction, and Deletion Where Applicable

GCRI US shall recognize and implement rights of access, correction, restriction, and deletion, or their functional equivalents, where applicable under law, policy, contractual undertaking, or constitutional fairness within the institutional order. The Corporation shall not treat such rights as purely external compliance burdens. They are part of the institution’s obligation to remain truthful and proportionate in its treatment of person-affecting information.

Accordingly, where applicable and consistent with lawful restrictions, the Corporation shall support:

a) access by a person to information about them or materially affecting them; b) correction of inaccurate, incomplete, or contextually misleading information; c) restriction of certain processing or dissemination where there is credible basis to question necessity, lawfulness, or proportionality; and d) deletion or equivalent reduction of retained information where continued retention is no longer justified.

The Corporation shall, however, apply these rights with constitutional seriousness rather than simplistically. Some requests may intersect with:

i) litigation holds or investigation preservation duties; ii) rights of other persons or protected participants; iii) controlled-room or privilege-based restrictions; iv) integrity of grievance and evidence files; or v) statutory or institutional retention obligations.

In such cases, the Corporation shall not merely refuse without explanation. It shall provide the narrowest lawful and safest response consistent with the governing constraints, preserve a record of the request and disposition, and where possible provide partial accommodation, explanation, or staged handling.

The Corporation shall also avoid performative rights pathways that exist only in theory. A right to correction that cannot alter materially harmful internal records, or a right of access so opaque that no reasonable person can use it, is not institutionally serious. Rights handling must be legible, timely, and tied to actual internal authority to change or restrict the relevant processing.


109.5 Privacy Impact Review for High-Risk Activities and Systems

GCRI US shall require privacy impact review for all activities, systems, repositories, workflows, tools, or programs that present high privacy risk, heightened rights-bearing exposure, or meaningful possibility of person-affecting harm if designed or operated without additional scrutiny. The Corporation shall not wait for privacy harm to become visible in practice before reviewing structurally risky systems.

A privacy impact review shall ordinarily be required where, among other things:

a) a system processes sensitive personal or rights-bearing data at scale or with heightened granularity; b) multiple data sources are being linked or combined in ways that increase inference power; c) a new repository, analytics workflow, collaboration tool, or automation layer materially changes visibility or processing capability; d) cross-border transfer, sovereign-sensitive context, or multi-party access is involved; e) public-benefit technical infrastructure may expose participation, grievance, community, or protected-subject data through architecture rather than overt disclosure; or f) a tool or workflow introduces meaningful risk of secondary use, re-identification, profiling, automated triage, or unanticipated public-meaning effects.

The review shall consider, as appropriate:

i) the categories of information involved; ii) the legitimate purpose of the processing; iii) the persons, communities, or rights surfaces affected; iv) whether the system is over-collecting, over-linking, or over-retaining; v) whether safer design alternatives exist; and vi) what mitigations, restrictions, or redesigns are necessary before deployment or expansion.

The Corporation shall not reduce privacy impact review to a standard-form template that always produces clearance. It is a constitutional checkpoint intended to change design where necessary. If the review reveals that a proposed system cannot operate consistently with the privacy baseline of this Part, the Corporation shall narrow, redesign, or decline it rather than accepting privacy harm as a cost of technical ambition.


109.6 Separation Between Governance Need, Research Need, and Convenience Use

GCRI US shall maintain strict separation among governance need, research need, and convenience use when processing personal information or rights-bearing data. The mere fact that the Corporation can derive additional insight from data does not establish that it may lawfully or legitimately do so.

Governance need refers to processing necessary to fulfill the Corporation’s constitutional, legal, records, oversight, safeguards, access-control, incident-response, or other institutional governance functions. Research need refers to processing reasonably necessary for defined research, analytical, or methodological purposes within the Corporation’s lawful remit, subject to privacy and safeguards constraints. Convenience use refers to processing performed because it is helpful, efficient, informative, or operationally attractive, but not necessary in the stronger institutional sense.

These categories must not be collapsed. A dataset legitimately collected for governance need does not thereby become open for research use. A research-derived corpus does not automatically become fair game for broader governance monitoring. Convenience use shall not be quietly justified by stretching the meaning of either governance or research.

The Corporation shall therefore ask, whenever a new use is proposed:

a) what category of need is actually being asserted; b) whether the data was originally collected under that category or another one; c) whether the proposed use materially broadens the processing beyond the original basis; and d) whether less intrusive alternatives would satisfy the need.

This separation is particularly important where data from grievances, protected participation, access logs, community engagement, or controlled technical systems could appear analytically useful for secondary projects. Such use may be tempting precisely because the data is rich. That richness does not create permission. On the contrary, it creates heightened duty to resist unjustified internal expansion of use.

Where category ambiguity exists, the proposed processing shall be treated as a broader new use requiring additional review rather than as an automatic continuation of prior handling.


109.7 No Re-Identification, Secondary Use, or Broadening of Processing Without Recorded Authority

GCRI US shall prohibit re-identification, secondary use, and broadening of processing of personal information, de-identified information, or rights-bearing data without recorded authority establishing a lawful, proportionate, and safeguards-compatible basis for the new activity. The Corporation shall not treat prior possession of data as a continuing license to make the data more revealing, more reusable, or more institutionally useful over time.

Accordingly, the Corporation shall not:

a) attempt to re-identify de-identified or pseudonymized information except where explicitly authorized and necessary for a lawful institutional purpose; b) reuse data collected under one purpose for materially different downstream purposes without fresh review; c) combine datasets or metadata layers in ways that broaden inference power beyond the original basis of handling; d) transform internal administrative traces into analytics, training, or publication inputs without recorded authority; or e) migrate sensitive or person-affecting information into broader technical or research environments simply because a tool makes the transfer easy.

Recorded authority for such actions shall, at minimum, identify:

i) the proposed new use; ii) the reason the existing basis is insufficient or needs extension; iii) the legal, safeguards, and proportionality basis for the change; iv) the risks created by greater identifiability or broader use; and v) the mitigations or restrictions required to keep the processing constitutionally acceptable.

The Corporation shall presume that re-identification and secondary use are high-risk moves unless proven otherwise. Even where lawful, they can corrode trust, chill participation, and convert protected datasets into internal surveillance or repurposing reservoirs. Part VI rejects that drift. The institution is entitled to learn and improve, but not by silently broadening the meaning of entrusted information.


109.8 Privacy Escalation, Review, and Complaint Handling

GCRI US shall maintain clear pathways for privacy escalation, privacy review, and privacy complaint handling so that privacy issues are surfaced, assessed, and resolved as governance matters rather than left to informal discomfort or silent noncompliance. Privacy concerns shall be capable of being raised by staff, contributors, protected participants, affected individuals, community representatives, or other legitimate actors without retaliation or procedural obscurity.

Privacy escalation may be triggered by, among other things:

a) suspected over-collection or unnecessary processing; b) unclear lawful basis or unclear purpose expansion; c) excessive internal visibility or inappropriate repository placement; d) disputed accuracy or harmful persistence of person-affecting records; e) proposed re-identification, linkage, or secondary use; f) cross-border handling uncertainty; or g) complaint by an affected person that the institution’s handling is unsafe, inaccurate, disproportionate, or insufficiently legible.

The Corporation shall ensure that privacy complaints and escalations are:

i) routed to a function with competence and authority to act; ii) recorded in a manner consistent with sensitivity and non-retaliation; iii) reviewed proportionate to seriousness; iv) resolved through reasoned disposition, corrective action, restriction, clarification, or refusal with explanation; and v) linked, where appropriate, to broader safeguards, incident, grievance, or legal pathways.

The Corporation shall not treat privacy complaints as nuisance objections to operational efficiency. Nor shall it force privacy concerns into purely legal channels if the issue is fundamentally one of design, access, minimization, or institutional judgment. Privacy under this Part is a living control surface. Complaint handling is therefore part of control governance, not just dispute management.

Where a privacy issue reveals broader structural weakness—such as habitual over-retention, role overexposure, or uncontrolled tool use—the response shall extend beyond the individual case to remediation of the underlying architecture.


109.9 Interpretive Rule for Privacy and Data Rights Baseline

This Section shall be interpreted to preserve a controlling proposition: privacy in GCRI US means disciplined restraint in the collection, use, combination, retention, and expansion of person-affecting and rights-bearing information, together with real institutional pathways for correction, challenge, and redesign where that restraint is not being honored.

Where ambiguity exists, the interpretation that better preserves:

a) privacy as a core institutional and safeguards obligation; b) lawful basis, purpose limitation, and proportionality in processing; c) minimization, accuracy, and storage limitation over convenience accumulation; d) strict separation among governance need, research need, and convenience use; and e) strong controls against re-identification, secondary use, and unreviewed broadening of processing

shall prevail unless a contrary result is required by law.

110. Personal Information and Rights-Bearing Data Handling (GCRI United States)


110.1 Categories of Personal and Rights-Bearing Data in Scope

For purposes of Part VI, personal information and rights-bearing data shall include any information, record, signal, metadata, inference, identifier, or structured relation that can identify, single out, affect, expose, profile, disadvantage, or materially alter the treatment of a natural person or protected participant. GCRI US shall interpret this category functionally and contextually, not narrowly or mechanically.

This category includes, without limitation:

a) names, contact details, addresses, identification numbers, credentials, employment or affiliation records, and other direct identifiers; b) indirect identifiers, quasi-identifiers, participation metadata, location data, device data, access logs, meeting attendance, role history, and repository activity traces; c) grievance, whistleblower, complaint, witness, protected-reporting, ethics, safeguards, or incident-linked records; d) health, vulnerability, community, Indigenous, biometric, demographic, political, professional, security, or high-risk contextual information; e) derived profiles, risk indicators, eligibility notes, access decisions, review notes, case tags, and status classifications; and f) any combination of otherwise low-sensitivity data that becomes identifying, exposing, or rights-affecting when aggregated or linked.

GCRI US shall not treat data as outside this category merely because it is pseudonymized, partly de-identified, held in a technical log, embedded in a model, or stored in a structured repository. If a person can reasonably be affected by the data or by decisions made from it, the data remains rights-bearing for purposes of these Bylaws.

Where doubt exists, the data shall be treated as rights-bearing until a narrower classification is recorded.


110.2 Collection Restrictions and Necessity Test

GCRI US shall collect personal information and rights-bearing data only where collection satisfies a strict necessity test tied to a lawful, defined, and proportionate institutional purpose. The Corporation shall not collect identity-rich, person-affecting, or rights-sensitive data because it may become useful, because it improves convenience, or because a platform default makes collection easy.

Before collection, the Corporation shall determine:

a) the specific institutional purpose; b) the lawful or governance basis for collection; c) the minimum data fields required; d) whether a non-identifying, pseudonymous, aggregated, or less intrusive alternative would suffice; e) the intended retention period or review point; and f) the handling class and access restrictions applicable from intake.

Collection shall be prohibited or re-scoped where:

i) the purpose is vague, speculative, or excessive; ii) the same purpose can reasonably be achieved with less person-affecting data; iii) the proposed collection creates disproportionate exposure for protected participants or vulnerable persons; iv) the Corporation lacks adequate security, privacy, or handling controls for the data; or v) collection would undermine trust, safe participation, or the non-retaliation architecture of these Bylaws.

The Corporation shall not allow general institutional ambition to become a standing justification for broad data intake. Public-benefit stewardship requires disciplined restraint.


110.3 Use Restrictions and Internal Access Controls

Personal information and rights-bearing data shall be used only for the purpose, function, and handling context for which it was collected or lawfully re-authorized. GCRI US shall not permit internal access merely because data is available within institutional systems, relevant to general work, or interesting for broader analysis.

Internal access shall be governed by:

a) classification and handling class; b) role-based and attribute-based access controls; c) need-to-know approval for restricted or sensitive categories; d) purpose limitation and use separation; e) logging of access where material; and f) periodic review and revocation.

The Corporation shall prohibit:

i) browsing of person-affecting records without institutional need; ii) reuse of grievance, protected-reporting, or participation data for unrelated analytics or communications; iii) transfer of personal data into open repositories, unmanaged workspaces, or external tools without recorded authority; iv) use of access logs, attendance records, or participation metadata for informal monitoring or retaliation; and v) internal copying that strips classification, provenance, or handling metadata.