For the complete documentation index, see llms.txt. This page is also available as Markdown.

XI. RECORDS

11.6 No-Email-Governance Rule

11.6.1 Email Alone Shall Not Constitute Material Governance Approval Unless Incorporated Into an Approved Record. 11.6.1(a) Email alone shall not constitute material governance approval for GCRI Canada unless the email is incorporated into an approved record through a recognized records process, assigned or linked to a Case ID where required, classified, reviewed, approved by competent authority, and stored in an approved repository or register.

11.6.1(b) Email shall not, by itself, approve Board action, officer delegation, committee action, public-safe publication, data access, AI use, cybersecurity exception, public authority reference, sponsor acknowledgment, provider reference, technical baseline adoption, public-good software release, repository action, evidence pack issuance, Nexus interface, correction, withdrawal, retraction, public claim, finance-facing material, or execution-adjacent interface.

11.6.1(c) An email expressing agreement, non-objection, encouragement, acknowledgment, receipt, review, factual comment, suggested edit, informal approval, operational preference, or personal view shall not be treated as institutional approval unless the applicable governance procedure expressly permits the email to be captured into an approved record and the capture is completed.

11.6.1(d) Email may support the historical record of a process, including notice, circulation, comment, factual correction, reference approval, consultation, or issue escalation, but it shall not replace the decision record, resolution, delegation record, approval form, release record, register entry, or correction record required for material institutional effect.

11.6.1(e) Where a material action was taken in reliance on email alone, the action shall be reviewed, assigned or linked to a Case ID where required, converted into a proper record if lawful and supportable, narrowed, suspended, corrected, or withdrawn where the record cannot bear the action.

11.6.1(f) The controlling rule shall be that email may transmit governance information, but email alone shall not govern GCRI Canada.


11.6.2 Chat Alone Shall Not Constitute Material Governance Approval Unless Incorporated Into an Approved Record. 11.6.2(a) Chat messages, instant messages, collaboration-platform messages, direct messages, threaded comments, reactions, acknowledgments, shared-channel discussions, informal votes, and chat-based instructions shall not constitute material governance approval unless incorporated into an approved record through a recognized records process.

11.6.2(b) Chat shall not approve, authorize, adopt, release, publish, certify, recognize, finance, procure, endorse, route, correct, withdraw, retract, suspend, reinstate, or archive any material GCRI Canada act by itself.

11.6.2(c) Chat may be used for operational coordination, drafting, triage, issue discovery, factual clarification, scheduling, preliminary review, or escalation, but any material decision arising from chat shall be captured in the applicable decision record, case record, form, register, release record, incident record, or correction record.

11.6.2(d) Emojis, reactions, “looks good,” “approved,” “fine,” “no objection,” “ship it,” “send,” “publish,” “okay,” “agree,” or similar informal expressions in chat shall not constitute approval unless the governing process expressly permits such approval and the approval is converted into the required record.

11.6.2(e) Chat content involving sensitive data, public authority information, finance-sensitive information, cyber-sensitive information, infrastructure-sensitive information, community-protected information, Indigenous or protected knowledge, credentials, keys, tokens, secrets, or restricted materials shall be subject to applicable data, AI, cybersecurity, public-safe, confidentiality, and retention controls.

11.6.2(f) The controlling rule shall be that chat may coordinate work, but it shall not silently create institutional authority.


11.6.3 Verbal Assurances Shall Not Constitute Material Governance Approval. 11.6.3(a) Verbal assurances shall not constitute material governance approval, whether given by a director, officer, employee, fellow, advisor, council participant, public authority participant, sponsor, provider, host, university participant, community participant, capital reader, founder, or external actor.

11.6.3(b) Verbal assurances include meeting statements, telephone calls, conference remarks, hallway conversations, event comments, oral approvals, verbal non-objections, public authority comments, sponsor assurances, provider assurances, capital-reader remarks, and informal representations of institutional intent.

11.6.3(c) Verbal assurances may indicate that a matter should be documented, reviewed, escalated, corrected, or converted into a record, but shall not themselves create approval, adoption, authority, recognition, certification, finance-readiness, public authority meaning, procurement approval, provider preference, sponsor benefit, protocol effect, public warning, emergency command, operational clearance, infrastructure operation, or execution consequence.

11.6.3(d) Where a person asserts that verbal approval occurred, the asserted approval shall be treated as unrecorded unless confirmed by a competent written record. GCRI Canada may investigate the context, but institutional effect shall require record creation and review.

11.6.3(e) Where reliance has occurred on verbal assurance, GCRI Canada shall classify the issue, contain reliance where material, create a corrective record, notify affected interfaces where appropriate, and determine whether public-safe clarification, withdrawal, retraction, or relationship action is required.

11.6.3(f) The controlling rule shall be that verbal assurance may prompt governance, but it shall not replace governance.


11.6.4 Slides, Drafts, Meeting Notes, or Informal Working Documents Shall Not Constitute Material Governance Approval Unless Adopted. 11.6.4(a) Slides, drafts, meeting notes, informal working documents, agendas, diagrams, whiteboards, screenshots, draft reports, draft dashboards, draft maps, draft technical baselines, draft public-safe summaries, draft agreements, draft policies, draft publications, draft repository documents, draft AI outputs, and draft evidence packs shall not constitute material governance approval unless adopted through proper authority and incorporated into an approved record.

11.6.4(b) The existence, circulation, discussion, editing, or presentation of a slide deck, draft, note, or working document shall not approve its contents, adopt its assumptions, authorize publication, create public meaning, create institutional position, create public authority meaning, create finance-readiness, create provider preference, create sponsor benefit, create recognition, create certification, create protocol effect, or create execution consequence.

11.6.4(c) Meeting notes shall be evidence of discussion only unless approved as minutes, decision records, action records, or official records through the applicable process. Draft minutes shall remain drafts until adopted or otherwise approved.

11.6.4(d) Informal working documents shall be marked, stored, and handled according to their classification and shall not be externally relied upon unless approved, versioned, public-safe-reviewed where applicable, and released under proper authority.

11.6.4(e) Where a draft or informal document has been treated externally as approved, GCRI Canada shall correct, relabel, restrict, withdraw, request takedown where appropriate, issue public-safe clarification where needed, and update records discipline.

11.6.4(f) The controlling rule shall be that work product becomes governance only when adopted through governance.


11.6.5 Material Decisions Require Case ID, Decision Record, Resolution, Delegation Record, or Other Approved Record. 11.6.5(a) Material decisions of GCRI Canada shall require a Case ID, decision record, Board resolution, officer delegation record, committee record, approval form, register entry, release record, correction record, incident record, or other approved record appropriate to the decision type.

11.6.5(b) Material decisions include decisions affecting governance, authority, policy, Charter interpretation, bylaw implementation, evidence status, method adoption, research approval, data access, AI use, cybersecurity posture, public-safe publication, public authority reference, sponsorship, provider participation, host interface, community safeguard, protected knowledge, technical release, repository access, public claim, Nexus interface, correction, withdrawal, retraction, suspension, reinstatement, retirement, or archive.

11.6.5(c) The required record shall identify the decision-maker, authority source, Case ID where required, date, scope, purpose, classification, affected records, required reviews, conflicts, approval status, conditions, limitations, boundary language, lifecycle status, notice obligations, and correction path.

11.6.5(d) A decision lacking the required record shall not be treated as institutionally complete and shall not be used as the basis for public claims, external reliance, public authority references, finance-facing materials, provider statements, sponsor acknowledgments, technical release, or Nexus routing.

11.6.5(e) The controlling rule shall be that material decisions must enter the record architecture before they can create material effect.


11.6.6 Email and Chat May Support Evidence of Process but Do Not Substitute for Required Records. 11.6.6(a) Email and chat may support evidence of process, including circulation, notice, comment, factual correction, issue escalation, participant consultation, public authority reference review, sponsor acknowledgment review, provider factual review, scheduling, and operational coordination.

11.6.6(b) Email and chat shall not substitute for required records where a form, register entry, decision record, resolution, delegation, release record, incident record, correction record, approval record, or Case ID is required.

11.6.6(c) Where email or chat contains material process evidence, GCRI Canada may preserve, classify, extract, summarize, attach, or cross-reference the communication in the applicable case record, provided privacy, confidentiality, legal privilege, public authority, cybersecurity, protected knowledge, and public-safe controls are observed.

11.6.6(d) Process evidence from email or chat shall be interpreted according to its context and shall not be inflated into authority, approval, adoption, public meaning, or waiver beyond the formal record.

11.6.6(e) The controlling rule shall be that informal channels may prove that process occurred, but the formal record must prove what institutional effect occurred.


11.6.7 Emergency Decisions May Be Recorded After Urgent Action Only Under Emergency Record Rules. 11.6.7(a) Emergency decisions may be recorded after urgent action only under emergency record rules approved by GCRI Canada. Emergency record rules shall apply narrowly and only where delay would materially increase legal, safety, cybersecurity, data, public authority, protected knowledge, public-safe, infrastructure, or institutional harm.

11.6.7(b) Emergency action may include containment of a cybersecurity incident, revocation of access, key rotation, suspension of publication, takedown of exposed materials, restriction of dashboard access, withdrawal of an unsafe map, correction of a public authority overclaim, containment of protected knowledge exposure, suspension of a technical release, or other urgent protective measure.

11.6.7(c) Emergency action shall not be used to create ordinary governance authority, bypass Board review, avoid sponsor or provider conflict review, accelerate publication, issue recognition, create finance-readiness, approve procurement, create public authority meaning, approve provider status, or execute downstream activity.

11.6.7(d) Emergency records shall be created as soon as practicable after the urgent action and shall identify the emergency, actor, authority relied upon, time, affected materials, action taken, reason delay was unsafe, classification, interim controls, required follow-up review, notices, correction path, and closeout.

11.6.7(e) Emergency action shall be reviewed by the appropriate officer, committee, Board, legal function, cybersecurity function, data governance function, safeguards function, or public-safe publication function according to severity and subject matter.

11.6.7(f) The controlling rule shall be that emergency action may precede complete paperwork only to prevent harm, and must be brought back into the record without delay.


11.6.8 No Informal Document May Be Used to Claim GCRI Canada Approval, Recognition, Certification, Public Authority Meaning, Finance-Readiness, Provider Preference, or Sponsor Benefit. 11.6.8(a) No informal document may be used to claim GCRI Canada approval, recognition, certification, maturity status, public authority meaning, finance-readiness, public finance approval, procurement approval, provider preference, sponsor benefit, host approval, Nexus-compatible status, protocol effect, operational clearance, deployment approval, public warning, emergency command, infrastructure operation, or execution authority.

11.6.8(b) Informal documents include unapproved emails, chats, texts, draft slides, draft reports, draft agreements, draft dashboards, draft maps, meeting notes, screenshots, unofficial spreadsheets, internal working documents, personal notes, public event materials, press drafts, AI-generated drafts, and uncontrolled copies.

11.6.8(c) Participants, sponsors, providers, hosts, public authorities, capital readers, universities, media, civil society, National Companies, Project SPVs, and Nexus actors shall not cite informal documents as evidence of status, approval, authority, or benefit.

11.6.8(d) Where informal documents are needed to support a factual statement, they shall be incorporated into a proper record, verified, classified, reviewed, and bounded before use.

11.6.8(e) The controlling rule shall be that no informal document may be converted by use into a badge of GCRI Canada authority.


11.6.9 Correction Required Where Informal Communications Are Misused. 11.6.9(a) Correction shall be required where informal communications are misused to claim or imply GCRI Canada approval, recognition, certification, maturity, public authority meaning, finance-readiness, procurement approval, provider preference, sponsor validation, protocol effect, public warning, emergency command, operational clearance, infrastructure operation, execution authority, or institutional position beyond the record.

11.6.9(b) Correction may include relabeling, withdrawal, retraction where necessary, public-safe clarification, controlled notice, restricted notice, takedown request, replacement with approved record, notice to affected public authorities, notice to sponsors or providers, notice to GRF, GRA, Protocol Authority, Nexus interface actors, National Companies, Project SPVs, capital readers, media, or communities where appropriate.

11.6.9(c) GCRI Canada shall classify misuse by severity, affected reliance, public-safe risk, public authority risk, finance risk, provider or sponsor risk, community safeguard risk, protected knowledge risk, cybersecurity risk, legal risk, and correction urgency.

11.6.9(d) Where informal communications have entered external circulation, GCRI Canada shall identify the current approved record, state the status of the informal communication where appropriate, and preserve a correction record.

11.6.9(e) The controlling rule shall be that informal misuse must be corrected before repetition creates false public meaning.


11.6.10 Training and Enforcement of No-Email-Governance Rule. 11.6.10(a) GCRI Canada shall train directors, officers, members, staff, fellows, advisors, council participants, researchers, technical contributors, sponsors, providers, hosts, public authority participants, university participants, community participants, and relevant external participants on the No-Email-Governance Rule.

11.6.10(b) Training shall cover the difference between informal communication and records, when Case IDs are required, how to convert process communications into approved records, emergency record rules, public authority reference controls, finance-safe language, provider-neutrality language, sponsor non-control language, public-safe publication controls, and correction obligations.

11.6.10(c) Enforcement may include return of incomplete approvals, refusal to publish, suspension of release, restriction of access, retraining, correction notice, public-safe clarification, removal of unauthorized claims, suspension of participation, revocation of role, or escalation to officers, committees, or the Board.

11.6.10(d) Repeated reliance on email, chat, verbal assurances, drafts, or informal materials for material governance shall be treated as a records discipline failure and, where material, a governance risk.

11.6.10(e) The controlling rule shall be that GCRI Canada shall train and enforce so that convenience channels do not become shadow governance.


11.7 Case ID Architecture

11.7.1 Mandatory Case ID for Every Material Act. 11.7.1(a) GCRI Canada shall assign a Case ID to every material act requiring traceability, auditability, classification, review, approval, correction, or cross-reference.

11.7.1(b) Material acts requiring Case IDs shall include governance decisions, evidence intake, evidence pack creation, research protocols, publications, method adoption, ontology changes, controlled vocabulary changes, technical baseline actions, software releases, data access, AI use, model use, compute workloads, cybersecurity incidents, technical incidents, public authority interfaces, sponsorships, provider interfaces, host interfaces, community interfaces, Nexus interfaces, public-safe outputs, corrections, withdrawals, retractions, supersessions, retirements, and archive actions.

11.7.1(c) The Case ID shall serve as the durable link between the act, its authority, records, forms, reviews, approvals, related communications, affected assets, notices, corrections, dependencies, registers, repositories, publications, and archive.

11.7.1(d) No material act requiring a Case ID shall be treated as complete until the Case ID is created, recorded, assigned to an owner and custodian, classified, and entered into the applicable register or repository.

11.7.1(e) The controlling rule shall be that material institutional action must be findable by Case ID.


11.7.2 Case ID for Governance Decisions. 11.7.2(a) Governance decisions shall receive Case IDs sufficient to connect the decision to its authority, records, Board materials, committee materials, officer delegations, conflict records, supporting materials, approvals, public-safe implications, and correction path.

11.7.2(b) Governance Case IDs shall be used for Board resolutions, officer appointments, delegations, committee actions, policy adoption, bylaw implementation, Charter interpretation, member decisions, conflict reviews, major agreements, sponsorship approvals, provider interface approvals, public authority interface approvals, public claims approvals, and material risk acceptances.

11.7.2(c) Governance Case ID records shall identify the decision-maker, authority source, date, scope, affected instruments, affected programs, affected records, conflicts, recusals, required reviews, approval status, effective date, review cycle, responsible custodian, and correction or amendment path.

11.7.2(d) The controlling rule shall be that governance must be traceable from decision to authority and from authority to record.


11.7.3 Case ID for Evidence Intake and Evidence Pack Creation. 11.7.3(a) Evidence intake and evidence pack creation shall receive Case IDs sufficient to trace source, contributor, provenance, custody, classification, review, transformation, public-safe status, interface routing, and correction.

11.7.3(b) Evidence intake Case IDs shall identify source materials, source lineage, contributor, date, data class, evidence class, handling class, access class, rights status, permitted use, prohibited use, confidence, uncertainty, limitations, and initial custodian.

11.7.3(c) Evidence pack Case IDs shall connect underlying evidence records, method records, public-safe review records, controlled annexes, restricted annexes, public authority notes, provider notes, sponsor notes, community safeguard notes, protected knowledge notes, versioning, boundary language, and correction path.

11.7.3(d) Evidence Case IDs shall be used in dashboards, maps, public-safe summaries, GRF inputs, GRA inputs, Protocol Authority inputs, Docket inputs, Grid inputs, and Nexus interfaces where evidence is routed or summarized.

11.7.3(e) The controlling rule shall be that no evidence pack may become institutionally meaningful unless its evidence chain is traceable by Case ID.


11.7.4 Case ID for Research Protocols and Publications. 11.7.4(a) Research protocols and publications shall receive Case IDs sufficient to trace research purpose, authority, collaborators, ethics review where applicable, data use, AI use, methods, conflicts, funding, publication review, public-safe status, and correction.

11.7.4(b) Research protocol Case IDs shall identify researchers, institutions, contributors, funders, sponsors, provider involvement, public authority involvement, community involvement, data classes, methods, review status, approvals, limitations, publication plan, IP status, and correction path.

11.7.4(c) Publication Case IDs shall connect the publication to source records, method records, data records, AI-use records, public-safe review records, public authority reference approvals, sponsor and provider reference approvals, IP and license review, versioning, limitations, and correction path.

11.7.4(d) Publications shall not rely on untraceable evidence, unrecorded methods, unapproved public authority references, unsupported sponsor or provider claims, or undisclosed material AI use where disclosure is required.

11.7.4(e) The controlling rule shall be that research and publication must remain traceable from public text back to source, method, authority, and correction.


11.7.5 Case ID for Methods, Ontology, Technical Baseline, and Software Release Actions. 11.7.5(a) Methods, ontology, technical baseline, and software release actions shall receive Case IDs sufficient to trace adoption, change, release, review, supersession, withdrawal, and archive.

11.7.5(b) Method Case IDs shall identify method name, version, steward, purpose, scope, assumptions, limitations, required inputs, prohibited inputs, review status, challenge path, correction path, and retirement path.

11.7.5(c) Ontology and controlled vocabulary Case IDs shall identify term, taxonomy, schema, semantic crosswalk, change rationale, affected documents, localization notes, divergence logs, equivalence notes, public claims implications, and correction path.

11.7.5(d) Technical baseline Case IDs shall identify baseline name, version, steward, scope, dependencies, external standards mapping, limitations, public-safe status, certification boundary, procurement boundary, finance boundary, provider-neutrality boundary, and correction path.

11.7.5(e) Software release Case IDs shall identify repository, release version, maintainer, contributors, license, IP review, dependency review, SBOM status where applicable, security review, secrets review, public-safe review, release notes, rollback path, vulnerability path, withdrawal path, and archive.

11.7.5(f) The controlling rule shall be that technical assets must be traceable by Case ID through development, release, use, correction, and retirement.


11.7.6 Case ID for Data Access, AI Use, Model Use, Compute Workloads, Cybersecurity Incidents, and Technical Incidents. 11.7.6(a) Data access, AI use, model use, compute workloads, cybersecurity incidents, and technical incidents shall receive Case IDs sufficient to support classification, authorization, monitoring, containment, review, correction, and closeout.

11.7.6(b) Data access Case IDs shall identify requester, approver, purpose, data class, source, access scope, access duration, AI-use limits, transfer limits, retention, logging, security controls, and closeout.

11.7.6(c) AI-use and model-use Case IDs shall identify AI system, model, provider where any, version where known, purpose, input classes, output classes, prompt or retrieval context where material, embedding controls, human review, public-safe status, incident path, and correction path.

11.7.6(d) Compute workload Case IDs shall identify workload purpose, compute environment, custodian, data class, model class, jurisdiction, access controls, output controls, logs where material, retention, deletion, and public-safe review.

11.7.6(e) Cybersecurity incident and technical incident Case IDs shall identify incident type, severity, affected systems, affected records, affected data, containment actions, notification needs, correction actions, vulnerability treatment, post-incident review, and assurance follow-up.

11.7.6(f) The controlling rule shall be that sensitive technical action must be traceable from authorization to closeout.


11.7.7 Case ID for Public Authority Interfaces, Sponsorships, Provider Interfaces, Host Interfaces, Community Interfaces, and Nexus Interfaces. 11.7.7(a) Public authority interfaces, sponsorships, provider interfaces, host interfaces, community interfaces, and Nexus interfaces shall receive Case IDs sufficient to trace actor role, capacity, authority, contribution, access, public claims, restrictions, and correction.

11.7.7(b) Public authority Case IDs shall identify public authority actor, capacity classification, materials, data contribution status, reference permissions, logo or name approval where applicable, public-safe status, no-delegation language, no-endorsement language, no-public-warning language, no-procurement language, no-public-finance language, and correction path.

11.7.7(c) Sponsorship Case IDs shall identify sponsor, donor, or funder identity, support type, value where appropriate, purpose, restrictions, conflicts, non-control terms, public acknowledgment terms, affected assets, dependency implications, correction obligations, and closeout.

11.7.7(d) Provider and host Case IDs shall identify contribution, ownership, custody, IP, data rights, security review, provider-neutrality terms, host boundaries, public claims limits, public authority implications, procurement implications, and correction path.

11.7.7(e) Community interface Case IDs shall identify role, participation pathway, safeguards, consent or non-consent treatment where applicable, protected knowledge controls, public-safe review, grievance pathway, withdrawal pathway, and correction pathway.

11.7.7(f) Nexus interface Case IDs shall identify sending actor, receiving actor, input type, role, version, authority limits, permitted uses, prohibited uses, boundary language, dependency notices, correction path, and closeout.

11.7.7(g) The controlling rule shall be that relationships affecting public meaning must be traceable by Case ID.


11.7.8 Case ID Schema, Uniqueness, Prefixes, Metadata, Lifecycle State, Classification, Owner, Custodian, and Cross-References. 11.7.8(a) GCRI Canada shall maintain a Case ID schema that ensures uniqueness, intelligibility, searchability, classification, lifecycle control, and cross-reference.

11.7.8(b) The Case ID schema may include prefixes indicating record family, such as GOV for governance, EVD for evidence, MTH for methods, RSH for research, DAT for data, AI for AI use, MOD for model use, CMP for compute, CYB for cybersecurity, TEC for technical incident, PUB for publication, REL for release, PA for public authority, SPN for sponsorship, PRV for provider, HST for host, COM for community, NXS for Nexus interface, COR for correction, and ARC for archive, or such other controlled prefixes as GCRI Canada adopts.

11.7.8(c) Each Case ID shall include metadata sufficient to identify owner, custodian, creator, date, version, authority, scope, purpose, classification, handling class, access class, public-safe status, legal or approval basis where applicable, source lineage where applicable, review status, limitations, dependencies, correction path, lifecycle state, related records, and archive status.

11.7.8(d) Lifecycle states may include draft, submitted, intake, under review, approved, active, conditionally approved, restricted, suspended, superseded, withdrawn, retracted, corrected, closed, reopened, retired, archived, sealed, deleted where lawful, or under legal hold.

11.7.8(e) Cross-references shall connect related records, including forms, evidence sources, decision records, releases, publications, public authority references, sponsor records, provider records, data access records, AI-use records, cybersecurity records, incident records, correction records, and archive records.

11.7.8(f) The controlling rule shall be that Case IDs must identify both the thing done and the institutional controls under which it was done.


11.7.9 Case ID Use in Registers, Repositories, Gazette Notices, Publications, Dashboards, Evidence Packs, Decision Packs, and Correction Notices. 11.7.9(a) Case IDs shall be used in registers, repositories, Gazette notices or authoritative notice streams where adopted, publications, dashboards, maps, evidence packs, decision packs, public-safe summaries, controlled annexes, restricted annexes, technical releases, and correction notices where material.

11.7.9(b) Register entries shall include the applicable Case ID and shall allow authorized users to trace status, owner, custodian, classification, lifecycle state, affected records, related materials, and correction path.

11.7.9(c) Repositories shall reference Case IDs in issues, pull requests, releases, changelogs, security advisories, dataset records, model records, method records, and technical baseline records where material.

11.7.9(d) Publications, dashboards, maps, and evidence packs may include public-safe Case ID references where appropriate, but restricted Case IDs or sensitive metadata shall not be exposed where doing so would create security, privacy, public authority, protected knowledge, finance, or public-safe risk.

11.7.9(e) Correction notices shall identify affected Case IDs, corrected Case IDs, superseded Case IDs, withdrawal status, retraction status, dependency notices, and archive relationships where appropriate and safe.

11.7.9(f) The controlling rule shall be that Case IDs create traceability without requiring unsafe public exposure of sensitive record details.


11.7.10 Case ID Closure, Reopening, Supersession, and Archival. 11.7.10(a) Case IDs shall be closed, reopened, superseded, retired, sealed, deleted where lawful and required, or archived according to approved lifecycle rules.

11.7.10(b) Closure shall require completion of required reviews, approvals, notices, corrections, access closeout, dependency checks, public-safe status, and archive or retention classification.

11.7.10(c) Reopening shall occur where new evidence, correction request, incident, public authority issue, finance overclaim, provider overclaim, sponsor issue, community challenge, protected knowledge issue, cybersecurity issue, legal issue, or public-safe concern materially affects a closed case.

11.7.10(d) Supersession shall identify predecessor, successor, reason, continuing validity, affected materials, affected interfaces, affected public claims, and dependency notices.

11.7.10(e) Archival shall preserve traceability while clearly marking that the Case ID is inactive, historical, superseded, withdrawn, retracted, retired, sealed, or otherwise limited.

11.7.10(f) The controlling rule shall be that a Case ID may close operationally, but it must remain reopenable to correction where institutional meaning requires.


11.8 Minimum Metadata Standard

11.8.1 Record Identity. 11.8.1(a) Every material record shall include a record identity sufficient to distinguish it from all other records and to support search, audit, classification, correction, supersession, withdrawal, and archive.

11.8.1(b) Record identity shall include a record title, record type, record identifier, responsible record family, current status, and relationship to any Case ID, register, repository, publication, technical asset, evidence pack, decision pack, or correction record.

11.8.1(c) The controlling rule shall be that every material record must be identifiable before it can be relied upon.


11.8.2 Case ID. 11.8.2(a) Every material record shall include or cross-reference the applicable Case ID unless the record class is expressly exempted under approved records rules.

11.8.2(b) The Case ID shall connect the record to related authority, forms, evidence, decisions, reviews, approvals, releases, publications, incidents, corrections, dependencies, notices, and archives.

11.8.2(c) The controlling rule shall be that material records shall not become orphaned from their case architecture.


11.8.3 Owner. 11.8.3(a) Every material record shall identify an owner responsible for the institutional purpose, continuing relevance, and lifecycle accountability of the record.

11.8.3(b) The owner may be a Board body, officer, committee, program lead, method steward, data steward, technical asset steward, publication steward, public authority interface owner, or other assigned role.

11.8.3(c) Ownership shall not necessarily mean legal ownership of IP or data; it shall mean responsibility for institutional accountability unless otherwise specified.

11.8.3(d) The controlling rule shall be that every material record must have an accountable owner.


11.8.4 Custodian. 11.8.4(a) Every material record shall identify a custodian responsible for maintaining, securing, classifying, updating, storing, preserving, granting access to, restricting access to, and archiving the record.

11.8.4(b) The custodian may be distinct from the owner, creator, approver, or subject-matter steward.

11.8.4(c) Custody shall include responsibility for ensuring that the record remains findable, protected, version-aware, access-controlled, and correctionable.

11.8.4(d) The controlling rule shall be that no material record shall lack a custodian.


11.8.5 Creator. 11.8.5(a) Every material record shall identify the creator or originating actor, including person, office, committee, system, repository process, automated process, external contributor, public authority contributor, provider contributor, sponsor contributor, or other source where applicable.

11.8.5(b) Where a record is system-generated, AI-assisted, imported, derived, or transformed from another source, the creator field shall identify the system or process and shall link to source lineage where material.

11.8.5(c) The controlling rule shall be that the origin of a record must be visible enough to assess responsibility and reliability.


11.8.6 Date and Time. 11.8.6(a) Every material record shall include creation date and time, approval date and time where applicable, effective date, modification date, publication date where applicable, release date where applicable, correction date where applicable, and archive date where applicable.

11.8.6(b) Date and time metadata shall identify timezone or time standard where material to interpretation, incident response, publication status, public-safe reliance, legal hold, or technical release.

11.8.6(c) The controlling rule shall be that timing is part of institutional meaning, especially for evidence, publication, incident, cybersecurity, public authority, finance-facing, and correction records.


11.8.7 Version. 11.8.7(a) Every material record shall identify its version, including draft, submitted, approved, active, provisional, experimental, public-safe, controlled, restricted, superseded, withdrawn, retracted, retired, archived, or other applicable status.

11.8.7(b) Version metadata shall identify predecessor and successor records where applicable, change history, continuing validity, and dependency implications.

11.8.7(c) No material record shall be represented as current where it is draft, superseded, withdrawn, retracted, retired, archived, or otherwise limited.

11.8.7(d) The controlling rule shall be that version status governs permissible reliance.


11.8.8 Authority. 11.8.8(a) Every material record shall identify the authority under which it was created, approved, released, used, corrected, or archived.

11.8.8(b) Authority metadata may include Board resolution, officer delegation, committee mandate, policy, protocol, agreement, public authority basis, data contributor authority, contributor terms, license, research approval, secure release approval, public-safe publication approval, or other governing source.

11.8.8(c) Where authority is uncertain, contested, expired, exceeded, or absent, the record shall be flagged, restricted, escalated, corrected, or suspended.

11.8.8(d) The controlling rule shall be that authority must be mapped, not presumed.


11.8.9 Scope. 11.8.9(a) Every material record shall identify scope, including subject matter, entity, program, project, technology domain, jurisdiction, geography, time period, audience, permitted uses, prohibited uses, affected interfaces, and exclusions.

11.8.9(b) Scope shall be stated narrowly enough to prevent overclaim, authority migration, public authority confusion, finance overclaim, provider preference, sponsor validation, public warning implication, or execution drift.

11.8.9(c) The controlling rule shall be that a record cannot support meaning outside its scope.


11.8.10 Purpose. 11.8.10(a) Every material record shall identify its purpose, including whether it is created for governance, evidence, methods, research, data access, AI use, cybersecurity, public-safe publication, technical release, public authority interface, sponsorship, provider interface, community safeguard, Nexus interface, correction, or archive.

11.8.10(b) Purpose metadata shall prevent reuse beyond the reason for which the record was created unless additional authority and review support reuse.

11.8.10(c) The controlling rule shall be that purpose limitation applies to records as well as data.


11.8.11 Classification. 11.8.11(a) Every material record shall include classification metadata appropriate to its content and use.

11.8.11(b) Classification may include public, public-safe, internal, confidential, restricted, public authority-sensitive, health-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, personal, community-protected, Indigenous, local, territorial, environmental, protected knowledge, export-control-sensitive, sanctions-sensitive, controlled-technology-sensitive, privileged, or legal-hold categories.

11.8.11(c) Classification shall be reviewed and corrected where sensitivity, public-safe status, legal status, data status, or use changes.

11.8.11(d) The controlling rule shall be that classification controls access, use, publication, transfer, AI use, and correction.


11.8.12 Handling Class. 11.8.12(a) Every material record shall identify handling class, including whether the record may be copied, downloaded, exported, shared, attached, printed, indexed, embedded, used in AI systems, used in dashboards, used in maps, placed in data rooms, placed in controlled rooms, or published.

11.8.12(b) Handling class shall reflect privacy, cybersecurity, public authority restrictions, protected knowledge, legal hold, IP, competition safety, export controls, sanctions, controlled technology, and public-safe requirements.

11.8.12(c) The controlling rule shall be that classification identifies sensitivity; handling class governs permitted handling.


11.8.13 Access Class. 11.8.13(a) Every material record shall identify access class, including who may view, edit, approve, export, share, publish, correct, archive, or delete the record.

11.8.13(b) Access shall be role-based, least-privilege, purpose-limited, time-limited where appropriate, authenticated, authorized, logged where material, reviewable, and revocable.

11.8.13(c) The controlling rule shall be that access to records shall be granted by role and purpose, not curiosity, status, sponsorship, provider importance, or public authority prestige.


11.8.14 Public-Safe Status. 11.8.14(a) Every material record shall identify public-safe status where the record may affect publication, external communication, dashboards, maps, reports, APIs, datasets, technical baselines, Academy materials, media, public authority interfaces, finance-facing interfaces, provider references, sponsor references, or public claims.

11.8.14(b) Public-safe status may include not reviewed, internal only, controlled, restricted, public-safe summary available, public-safe release approved, withdrawn, superseded, retracted, or archived.

11.8.14(c) Public-safe status shall not be inferred from public availability, public source data, sponsor request, provider request, public authority interest, or media interest.

11.8.14(d) The controlling rule shall be that external use requires public-safe status, not merely technical readiness.


11.8.15 Legal Basis or Approval Basis Where Applicable. 11.8.15(a) Every material record shall identify legal basis or approval basis where applicable, including data processing basis, public authority data contribution basis, research approval, ethics approval, public-safe publication approval, licensing basis, IP basis, Board approval, officer delegation, committee approval, contract authority, consent or non-consent treatment where applicable, and lawful restriction.

11.8.15(b) Where no legal basis or approval basis is required, the record shall identify the basis for that conclusion where material.

11.8.15(c) The controlling rule shall be that legally or institutionally sensitive records must show why GCRI Canada may hold, use, share, or publish them.


11.8.16 Source Lineage Where Applicable. 11.8.16(a) Every material evidence, research, data, AI, model, dashboard, map, publication, technical baseline, public-safe summary, or Nexus interface record shall identify source lineage where applicable.

11.8.16(b) Source lineage shall identify origin, contributor, collection method where known, custody, transformations, derived outputs, assumptions, exclusions, uncertainty, confidence, data rights, public authority restrictions, community safeguards, protected knowledge controls, and correction dependencies.

11.8.16(c) The controlling rule shall be that source lineage is required wherever truth claims depend on sources.


11.8.17 Review Status. 11.8.17(a) Every material record shall identify review status, including not reviewed, under review, reviewed, conditionally reviewed, approved, rejected, returned, suspended, escalated, superseded, withdrawn, retracted, or archived.

11.8.17(b) Review metadata shall identify the review type, reviewer, date, conditions, exceptions, unresolved issues, and next review date where applicable.

11.8.17(c) The controlling rule shall be that a record’s review status limits its permissible use.


11.8.18 Limitations. 11.8.18(a) Every material record shall identify limitations where applicable, including assumptions, exclusions, uncertainty, confidence limits, data gaps, method limits, model limits, benchmark limits, public-safe omissions, geographic limits, time limits, legal limits, rights limits, security limits, and role boundaries.

11.8.18(b) Limitations shall travel with derivative outputs, summaries, dashboards, maps, publications, public authority materials, finance-facing materials, provider materials, sponsor materials, and Nexus inputs.

11.8.18(c) The controlling rule shall be that conclusions shall not travel without their limits.


11.8.19 Dependencies. 11.8.19(a) Every material record shall identify dependencies where applicable, including source dependencies, data dependencies, method dependencies, model dependencies, software dependencies, repository dependencies, provider dependencies, sponsor dependencies, platform dependencies, public authority dependencies, community safeguard dependencies, legal dependencies, IP dependencies, and correction dependencies.

11.8.19(b) Dependency metadata shall identify whether a dependency is critical, substitutable, time-limited, controlled, restricted, public-safe, vulnerable, deprecated, or subject to review.

11.8.19(c) The controlling rule shall be that hidden dependencies are a records failure and a capture risk.


11.8.20 Correction Path. 11.8.20(a) Every material record shall identify a correction path, including intake, responsible custodian, review authority, severity treatment, correction options, notice path, dependency review, supersession path, withdrawal path, retraction path where necessary, suspension path, reinstatement path, retirement path, archive path, and closeout.

11.8.20(b) Records without correction paths shall be treated as incomplete for material institutional reliance unless expressly exempted and justified.

11.8.20(c) The controlling rule shall be that a record that cannot be corrected cannot safely govern public-good trust.


11.9 Authority Mapping

11.9.1 Every Material Record Shall Identify Its Authority Source. 11.9.1(a) Every material record shall identify its authority source. Authority shall not be inferred from title, participation, seniority, funding, public authority presence, sponsor support, provider contribution, founder status, technical centrality, academic prestige, event visibility, or repeated use.

11.9.1(b) Authority sources may include the Charter, bylaws, Board resolutions, officer delegations, committee charters, policies, protocols, agreements, contributor terms, data agreements, public authority instruments, licenses, approvals, research protocols, secure release approvals, public-safe publication approvals, or other lawful records.

11.9.1(c) Authority mapping shall identify what the authority permits, what it prohibits, who may act, what review is required, what scope applies, what time limits apply, what boundary language applies, and what correction path applies.

11.9.1(d) The controlling rule shall be that authority must be shown by record before it is exercised.


11.9.2 Board Authority Records. 11.9.2(a) Board authority records shall identify Board actions, resolutions, approvals, interpretations, delegations, policies, risk acceptances, committee authorizations, major relationship approvals, material asset approvals, and correction decisions requiring Board-level authority.

11.9.2(b) Board authority records shall include date, quorum or approval basis where applicable, participating directors, recusals, conflicts, decision text, scope, conditions, effective date, responsible officer, review cycle, and correction or amendment path.

11.9.2(c) Board authority shall not be implied from director comments, informal meetings, email discussion, chat discussion, non-objection, or public statements unless converted into an approved Board record.

11.9.2(d) The controlling rule shall be that Board authority must be exercised through Board records.


11.9.3 Officer Delegation Records. 11.9.3(a) Officer delegation records shall identify the authority delegated to officers, including role, scope, limits, spending authority where any, signing authority where any, publication authority, data authority, technical release authority, public authority interface authority, sponsorship authority, provider interface authority, correction authority, escalation duties, and reporting duties.

11.9.3(b) Delegations shall identify who grants the authority, to whom it is granted, effective date, expiration or review date, permitted acts, prohibited acts, required reviews, required forms, public-safe limits, financial limits, data limits, and correction path.

11.9.3(c) Officers shall not act beyond delegated scope. Where delegation is ambiguous, officers shall escalate, narrow, defer, or refuse the action until clarified.

11.9.3(d) The controlling rule shall be that officer authority is delegated by record and bounded by record.


11.9.4 Committee Authority Records. 11.9.4(a) Committee authority records shall identify each committee’s mandate, composition, authority, advisory or decision-making status, reporting line, quorum or action requirements where applicable, scope, limits, review obligations, conflict rules, confidentiality rules, record obligations, and correction path.

11.9.4(b) Committee authority may include governance review, audit review, data governance review, AI review, cybersecurity review, public-safe publication review, sponsorship review, provider-neutrality review, research integrity review, technical asset review, or correction review only where recorded.

11.9.4(c) A committee shall not exercise Board authority, officer authority, public authority, GRF authority, GRA authority, Protocol Authority, certification authority, finance authority, procurement authority, or execution authority unless a lawful recorded instrument expressly grants a bounded role.

11.9.4(d) The controlling rule shall be that committee authority is whatever the committee charter or recorded delegation says, and no more.


11.9.5 Council Advisory Authority Records. 11.9.5(a) Council advisory authority records shall identify each council’s advisory mandate, membership, role, scope, public claims limits, confidentiality obligations, conflict rules, data access limits, public authority boundary rules, finance boundary rules, sponsor and provider boundary rules, output status, and correction path.

11.9.5(b) Leadership Councils, Helix Councils, expert councils, advisory councils, community councils, public authority learning councils, university councils, technical councils, and other councils shall be advisory unless expressly constituted otherwise by lawful recorded instrument.

11.9.5(c) Council advice shall not bind GCRI Canada, approve publications, issue recognition, issue finance-readiness, create protocol effect, certify providers, approve public authority references, authorize technical releases, or execute activity by default.

11.9.5(d) The controlling rule shall be that council authority is advisory unless a recorded instrument lawfully says otherwise.


11.9.6 Public Authority Capacity Records. 11.9.6(a) Public authority capacity records shall identify the role in which a public authority participates, including learner, observer, regulator-listener, public finance reader, emergency-management participant, public infrastructure participant, public health participant, public safety participant, host, data contributor, funder, reviewer, convenor, or other bounded role.

11.9.6(b) Public authority capacity records shall identify the public authority body, participant role, materials reviewed, data contributed, reference permissions, publication limits, confidentiality, public-safe status, no-delegation boundary, no-endorsement boundary, no-public-warning boundary, no-procurement boundary, no-public-finance boundary, and correction path.

11.9.6(c) Public authority capacity shall not create public authority approval, adoption, regulation, procurement approval, funding approval, public finance approval, public warning, emergency command, official guidance, sovereign obligation, or public-law status by default.

11.9.6(d) The controlling rule shall be that public authority meaning depends on recorded public authority capacity and competent public authority acts, not presence.


11.9.7 Sponsor, Donor, Funder, Provider, Host, Partner, University, Community, and Contributor Authority Records. 11.9.7(a) Authority records for sponsors, donors, funders, providers, hosts, partners, universities, laboratories, communities, civil society actors, media actors, and contributors shall identify role, contribution, rights, obligations, limits, permitted references, prohibited claims, access rights, confidentiality, data rights, IP rights, conflict status, public-safe status, and correction obligations.

11.9.7(b) Sponsor, donor, and funder records shall identify support-without-control terms, no outcome purchase, no pay-to-play, no publication veto, no correction suppression, and public acknowledgment limits.

11.9.7(c) Provider and host records shall identify contribution, ownership, custody, provider-neutrality terms, host boundaries, procurement non-effect, public authority non-effect, finance non-effect, and public claims limits.

11.9.7(d) University and contributor records shall identify research authority, contributor terms, IP, moral rights, licensing, publication controls, research integrity, secure development duties, and correction obligations.

11.9.7(e) Community records shall identify safeguards, consent or non-consent treatment where applicable, attribution or non-attribution, protected knowledge controls, grievance path, withdrawal path, and correction path.

11.9.7(f) The controlling rule shall be that external actors receive only the authority, access, and reference rights recorded for their role.


11.9.8 GRF, GRA, Protocol Authority, Nexus Network, Nexus Observatory, Nexus Rails, Nexus Grid, Nexus Academy, Regional Nexus Consortium, National Nexus Consortium, National Company, and Project SPV Interface Authority Records. 11.9.8(a) Interface authority records shall identify the authority and limits governing GCRI Canada’s interfaces with GRF, GRA, Protocol Authority, Nexus Network, Nexus Universe, Nexus Observatory, Nexus Rails, Nexus Grid, Nexus Academy, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, Nexus Competence Cells, National Companies, Project SPVs, qualified providers, and other Nexus actors.

11.9.8(b) GRF interface records shall distinguish GCRI Canada evidence inputs from GRF recognition, standing, maturity records, claims discipline, registry status, and public-facing legitimacy.

11.9.8(c) GRA interface records shall distinguish GCRI Canada technical evidence from GRA finance-readiness, capital readability, proof-pack discipline, insurance-readiness, capital-reader rooms, and regulated-perimeter discipline.

11.9.8(d) Protocol Authority interface records shall distinguish GCRI Canada technical support from protocol discipline, conformance logic, role keys, smart licenses, proof receipt effect, entitlement states, anchoring discipline, and technical validity surfaces.

11.9.8(e) Nexus body and consortium interface records shall distinguish evidence, methods, technical assets, learning materials, and correction signals from ownership, control, procurement, finance, public authority action, infrastructure operation, or execution.

11.9.8(f) National Company and Project SPV interface records shall distinguish upstream evidence support from downstream execution, project approval, investment recommendation, guarantee, provider selection, procurement, operations, and liability.

11.9.8(g) The controlling rule shall be that Nexus interface authority must be recorded so that interoperability does not become authority migration.


11.9.9 No Authority Beyond Stated Scope. 11.9.9(a) No authority shall exist beyond its stated scope. A record authorizing one act, program, publication, interface, release, data access, AI use, sponsor acknowledgment, provider reference, public authority reference, or correction shall not authorize another act by implication.

11.9.9(b) Authority shall be limited by subject matter, role, person, office, committee, time period, geography, entity, data class, evidence class, asset, publication, interface, review status, public-safe status, and boundary language stated in the record.

11.9.9(c) Authority shall not expand through repetition, convenience, urgency, sponsor request, provider request, public authority interest, finance timeline, event schedule, or past practice.

11.9.9(d) The controlling rule shall be that authority is bounded by the record that grants it.


11.9.10 Authority Ambiguity Requires Escalation, Hold, Clarification, or Refusal. 11.9.10(a) Authority ambiguity shall require escalation, hold, clarification, narrowing, redesign, or refusal. No actor shall resolve material authority ambiguity by acting first and documenting later except under approved emergency record rules.

11.9.10(b) Authority ambiguity includes uncertainty about whether GCRI Canada may publish, release, approve, reference, access data, use AI, route evidence, acknowledge sponsor support, reference a provider, cite a public authority, use protected knowledge, issue a correction, or interface with GRF, GRA, Protocol Authority, Nexus bodies, National Companies, Project SPVs, or capital readers.

11.9.10(c) Where ambiguity creates public authority risk, finance risk, provider preference risk, sponsor control risk, protected knowledge risk, cybersecurity risk, public-safe risk, data risk, IP risk, legal risk, competition risk, or execution risk, the action shall be held until competent review occurs.

11.9.10(d) The controlling rule shall be that unclear authority is not latent authority; it is a duty to stop and clarify.


11.10 Official Registers

11.10.1 Corporate Register. 11.10.1(a) GCRI Canada shall maintain a Corporate Register containing core corporate records necessary to evidence legal identity, nonprofit and non-share status, non-distribution, directors, officers, members where applicable, registered office, filings, corporate changes, statutory records, governance instruments, and continuity.

11.10.1(b) The Corporate Register shall include incorporation documents, articles, Charter records, bylaws, registered office records, director and officer records, member records where applicable, annual filings, statutory returns, corporate resolutions, corporate notices, and other records required by law or governance.

11.10.1(c) The Corporate Register shall distinguish GCRI Canada from GCRI US, GRF, GRA, Protocol Authority, Nexus bodies, National Companies, Project SPVs, providers, sponsors, public authorities, and other actors.

11.10.1(d) The controlling rule shall be that the Corporate Register preserves GCRI Canada’s legal identity and separateness.


11.10.2 Charter, Bylaw, Policy, Procedure, Schedule, Annex, and Manual Register. 11.10.2(a) GCRI Canada shall maintain a Charter, Bylaw, Policy, Procedure, Schedule, Annex, and Manual Register identifying all governing instruments and controlled operational instruments.

11.10.2(b) The Register shall include instrument title, version, custodian, authority, adoption date, effective date, review cycle, status, scope, supersession history, public-safe status, amendment history, archive status, and correction path.

11.10.2(c) No policy, procedure, schedule, annex, manual, template, or guidance document shall silently override the Charter or bylaws.

11.10.2(d) The controlling rule shall be that institutional instruments must be findable, current, versioned, and subordinate to the proper hierarchy.


11.10.3 Board, Officer, Delegation, Committee, Leadership Council, Helix Council, Working Group, Fellow, Advisor, Member, Participant, Contributor, and Staff Registers. 11.10.3(a) GCRI Canada shall maintain registers for Board members, officers, delegations, committees, Leadership Councils, Helix Councils, working groups, fellows, advisors, members, participants, contributors, and staff where applicable.

11.10.3(b) These registers shall identify identity, role, appointment authority, start date, end date where applicable, capacity, permissions, conflicts status, confidentiality obligations, access rights, delegated authority if any, advisory status, public claims limits, training status, and correction obligations.

11.10.3(c) Council, fellow, advisor, participant, contributor, and staff registers shall distinguish participation from authority and shall identify whether the role is advisory, operational, technical, governance, public-facing, restricted, or time-limited.

11.10.3(d) The controlling rule shall be that people-related registers prevent title, presence, or participation from being confused with authority.


11.10.4 Conflict, Recusal, Related-Party, Gifts, Hospitality, Independence, and Integrity Registers. 11.10.4(a) GCRI Canada shall maintain conflict, recusal, related-party, gifts, hospitality, independence, and integrity registers.

11.10.4(b) These registers shall record financial interests, sponsor relationships, provider relationships, public authority roles, capital actor roles, university roles, employment interests, IP interests, procurement interests, advisory interests, family or close relationships where relevant, gifts, hospitality, recusals, mitigation actions, and integrity concerns.

11.10.4(c) Conflict registers shall support capture prevention, provider neutrality, sponsor non-control, public authority boundary discipline, finance boundary discipline, research integrity, technical asset governance, and correctionability.

11.10.4(d) The controlling rule shall be that conflicts must be recorded before they can be managed.


11.10.5 Evidence, Method, Ontology, Controlled Vocabulary, Dataset, Model, System Card, Benchmark Card, Compute Workload, Inference, Truth Engine, Observatory, and Technical Asset Registers. 11.10.5(a) GCRI Canada shall maintain registers for evidence, methods, ontology, controlled vocabulary, datasets, models, system cards, benchmark cards, compute workloads, inference records, Truth Engine records, Observatory records, and technical assets.

11.10.5(b) These registers shall identify source, version, owner, custodian, steward, purpose, scope, classification, public-safe status, rights, review status, limitations, dependencies, authority, lifecycle status, and correction path.

11.10.5(c) Evidence and method registers shall preserve source lineage, method integrity, confidence, uncertainty, limitation treatment, public-safe publication status, and correction.

11.10.5(d) Ontology and controlled vocabulary registers shall preserve definitions, taxonomies, semantic crosswalks, divergence logs, equivalence notes, localization notes, vocabulary drift corrections, and public claims boundaries.

11.10.5(e) Dataset, model, system card, benchmark card, compute workload, and inference registers shall support AI governance, verifiable compute, verifiable intelligence, public-safe review, sensitive data controls, model limitations, and correction.

11.10.5(f) Truth Engine and Observatory registers shall preserve records for evidence processing, source comparison, observability methods, node evidence, sensor evidence, AI-RAN evidence, DePIN evidence, cyber telemetry, geospatial records, digital twins, dashboards, and degraded-mode awareness.

11.10.5(g) The controlling rule shall be that technical truth must be registered before it becomes reusable institutional memory.


11.10.6 Software, Repository, Release, Vulnerability, SBOM, Key, Token, Secret, API, Schema, Data Contract, and Technical Baseline Registers. 11.10.6(a) GCRI Canada shall maintain software, repository, release, vulnerability, SBOM, key, token, secret, API, schema, data contract, and technical baseline registers.

11.10.6(b) Software and repository registers shall identify repository owner, custodian, maintainer, contributors, access roles, branch protections, license, IP status, dependencies, security status, release status, archive status, and correction path.

11.10.6(c) Release registers shall identify release authority, release version, release notes, approval records, SBOM status where applicable, signing status where applicable, dependency review, security review, secrets review, public-safe review, rollback path, withdrawal path, and archive.

11.10.6(d) Vulnerability registers shall identify vulnerability, affected assets, severity, discovery date, containment, patch status, disclosure status, advisory status, dependency implications, and closeout.

11.10.6(e) SBOM registers shall identify dependencies, package versions, license status, vulnerability status, maintainer risk, update status, and correction path.

11.10.6(f) Key, token, and secret registers shall identify key type, custodian, purpose, access controls, rotation schedule, expiration, revocation, storage, backup, recovery, incident status, and closeout, without exposing the secrets themselves.

11.10.6(g) API, schema, data contract, and technical baseline registers shall identify version, scope, access controls, compatibility status, deprecation status, public-safe status, authority limits, and correction path.

11.10.6(h) The controlling rule shall be that public-good technical assets require registers capable of proving security, rights, release status, and correctionability.


11.10.7 Data Access, Data Processing, Data Sharing, Public Authority Data, Sovereign Data, Cross-Border Transfer, Privacy Impact Review, and Retention Registers. 11.10.7(a) GCRI Canada shall maintain data access, data processing, data sharing, public authority data, sovereign data, cross-border transfer, privacy impact review, and retention registers.

11.10.7(b) Data access registers shall identify requester, approver, purpose, data class, access scope, duration, AI-use limits, transfer limits, retention, logging where material, and closeout.

11.10.7(c) Data processing and sharing registers shall identify processing purpose, legal or approval basis where applicable, source, recipient, data classes, permitted uses, prohibited uses, retention, deletion, sealing, security controls, and correction path.

11.10.7(d) Public authority data registers shall identify public authority contributor, capacity, authority or basis, restrictions, publication limits, reference limits, public-safe status, and correction path.

11.10.7(e) Sovereign data and cross-border transfer registers shall identify jurisdiction, data location, transfer basis, receiving environment, safeguards, compute-to-data alternatives, conflict-of-law review where material, and closeout.

11.10.7(f) Privacy impact review registers shall identify risk, assessment, mitigation, residual risk, approval, review cycle, and correction path.

11.10.7(g) Retention registers shall identify retention schedule, deletion path, sealing path, archive path, legal hold, and responsible custodian.

11.10.7(h) The controlling rule shall be that data movement and data life must be registered before data can safely support evidence.


11.10.8 AI Use, Model Use, Agentic AI, AI Incident, Retrieval, Embedding, and AI Output Registers. 11.10.8(a) GCRI Canada shall maintain AI use, model use, agentic AI, AI incident, retrieval, embedding, and AI output registers.

11.10.8(b) AI-use registers shall identify AI system, model, provider where any, version where known, purpose, input classes, output classes, prohibited uses, sensitive data restrictions, human review requirements, public-safe status, and correction path.

11.10.8(c) Model-use registers shall identify model identity, source, access method, license or terms, data restrictions, evaluation status, known limitations, retirement status, and replacement status.

11.10.8(d) Agentic AI registers shall identify tools, permissions, action limits, approval gates, logs, prohibited actions, emergency disablement, and incident path.

11.10.8(e) Retrieval and embedding registers shall identify indexed sources, data classes, access controls, embedding scope, retrieval permissions, protected knowledge restrictions, deletion and refresh rules, and correction path.

11.10.8(f) AI output registers shall identify material outputs, model identity, input class, reviewer, public-safe status, limitations, publication status, and correction path where reliance may occur.

11.10.8(g) AI incident registers shall identify incident type, affected system, affected data, severity, containment, correction, notice, and post-incident review.

11.10.8(h) The controlling rule shall be that AI use must be registered because automation shall not become unrecorded authority.


11.10.9 Cybersecurity Incident, Technical Incident, Public-Safe Publication Incident, Boundary Incident, and Safeguards Incident Registers. 11.10.9(a) GCRI Canada shall maintain cybersecurity incident, technical incident, public-safe publication incident, boundary incident, and safeguards incident registers.

11.10.9(b) Cybersecurity incident registers shall record unauthorized access, suspected compromise, exposed secrets, vulnerability exploitation, repository compromise, dashboard compromise, API incident, data-room incident, model exposure, and related events.

11.10.9(c) Technical incident registers shall record software defects, release defects, dependency incidents, model incidents, dataset incidents, compute workload incidents, dashboard incidents, map incidents, API incidents, and technical baseline defects.

11.10.9(d) Public-safe publication incident registers shall record unsafe publication, over-disclosure, sensitive-location exposure, public warning implication, public authority misdescription, finance overclaim, provider overclaim, sponsor overclaim, media misuse, and stale public materials.

11.10.9(e) Boundary incident registers shall record non-execution boundary breaches, public authority boundary breaches, finance boundary breaches, provider-neutrality breaches, sponsor non-control breaches, protocol overclaims, recognition overclaims, and certification overclaims.

11.10.9(f) Safeguards incident registers shall record community harm, protected knowledge exposure, consent or non-consent breach, grievance, withdrawal issue, vulnerable participant exposure, confidential source exposure, and rights-bearing data incidents.

11.10.9(g) Each incident register shall include intake, severity, affected materials, containment, notification, correction, dependency review, post-incident review, corrective actions, and closeout.

11.10.9(h) The controlling rule shall be that incidents must be registered so that harm can be contained, corrected, and learned from.


11.10.10 Sponsorship, Donation, Grant, Restricted Fund, In-Kind Contribution, Membership, Subscription, Training Fee, and Public-Good Support Registers. 11.10.10(a) GCRI Canada shall maintain registers for sponsorships, donations, grants, restricted funds, in-kind contributions, memberships, subscriptions, training fees, controlled-access fees where permitted, maintenance support, and other public-good support.

11.10.10(b) These registers shall identify supporter, amount or value where applicable, support type, purpose, restrictions, term, conflicts, related-party status, public acknowledgment, non-control terms, no outcome purchase, no pay-to-play, public claims limits, affected assets, dependency implications, and correction obligations.

11.10.10(c) Restricted funds shall identify restriction, approval basis, lawful compatibility, mission compatibility, spending limits, reporting duties, and release or closeout conditions.

11.10.10(d) In-kind contributions shall identify ownership, custody, valuation where appropriate, use rights, IP, data implications, security implications, public-safe implications, return or disposal, and closeout.

11.10.10(e) The controlling rule shall be that support must be registered so that contribution does not become control.


11.10.11 Public Authority Capacity, Public Authority Reference Approval, Room Participation, Data Contribution, and Non-Endorsement Registers. 11.10.11(a) GCRI Canada shall maintain public authority capacity, public authority reference approval, room participation, data contribution, and non-endorsement registers.

11.10.11(b) Public authority capacity registers shall identify the public authority actor, participant, role, capacity classification, date, purpose, materials, restrictions, public-safe status, and correction path.

11.10.11(c) Reference approval registers shall identify approved names, logos, titles, quotes, photographs, jurisdiction references, agency names, data contribution references, permitted wording, permitted channels, duration, required disclaimers, and correction path.

11.10.11(d) Room participation registers shall identify controlled-room or data-room participants, role, access class, materials accessed, confidentiality, no-download controls where applicable, public-safe status, and closeout.

11.10.11(e) Data contribution registers shall identify public authority source, authority or basis, data class, permitted use, prohibited use, AI-use limits, retention, transfer, security, publication limits, and correction.

11.10.11(f) Non-endorsement registers shall record boundary language, no-delegation status, no-public-warning status, no-procurement status, no-public-finance status, and any corrective notices issued for overclaim.

11.10.11(g) The controlling rule shall be that public authority participation must be registered so public presence is never mistaken for public power.


11.10.12 Publication, Dashboard, Map, Public Claim, Media, Social Media, Public-Safe Output, Correction, Supersession, Withdrawal, Retraction, and Archive Registers. 11.10.12(a) GCRI Canada shall maintain registers for publications, dashboards, maps, public claims, media, social media, public-safe outputs, corrections, supersessions, withdrawals, retractions, and archives.

11.10.12(b) Publication and public-safe output registers shall identify title, version, source basis, method basis, public-safe review, data review, AI-use review, cybersecurity review, public authority references, sponsor references, provider references, community safeguards, protected knowledge controls, release authority, limitations, and correction path.

11.10.12(c) Dashboard and map registers shall identify source layers, data classes, public-safe transformations, update status, version, confidence, uncertainty, sensitive-location controls, public warning boundary, access controls, and correction path.

11.10.12(d) Public claim and media registers shall identify claim text or summary, approving authority, source record, permitted use, public-safe status, boundary language, channel, date, correction path, and archive.

11.10.12(e) Social media registers shall identify approved posts or campaigns where material, source record, public-safe review, boundary language, correction path, and takedown or update history.

11.10.12(f) Correction, supersession, withdrawal, retraction, and archive registers shall identify affected materials, reason, severity, notice audience, corrected version, successor version, continuing validity, archive status, and closeout.

11.10.12(g) The controlling rule shall be that public meaning must be registered from publication through correction and archive.


11.11 Register Governance

11.11.1 Register Owner and Custodian. 11.11.1(a) Every official register shall have an owner and custodian. The owner shall be responsible for institutional purpose and accountability; the custodian shall be responsible for maintenance, access control, classification, updates, retention, security, and archive.

11.11.1(b) The owner and custodian may be the same role only where appropriate to risk, scale, and segregation-of-duties requirements.

11.11.1(c) Register ownership and custody shall be recorded, reviewed, and updated upon role changes, organizational changes, system changes, or risk changes.

11.11.1(d) The controlling rule shall be that no official register shall be ownerless or custodianless.


11.11.2 Register Scope and Required Entries. 11.11.2(a) Every official register shall identify its scope and required entries. Scope shall include the record classes, acts, assets, relationships, incidents, publications, interfaces, or corrections that must be entered.

11.11.2(b) Required-entry rules shall state when entry is mandatory, what metadata is required, what attachments or linked records are required, who may submit, who may approve, and what lifecycle states apply.

11.11.2(c) A material act required to be entered in a register shall not have complete institutional effect until the entry is created and approved where required.

11.11.2(d) The controlling rule shall be that registers must define what belongs in them so material records do not fall outside governance.


11.11.3 Register Classification and Access. 11.11.3(a) Every official register shall have classification and access rules proportionate to its contents.

11.11.3(b) Registers may contain public, public-safe, internal, confidential, restricted, public authority-sensitive, health-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, personal, community-protected, Indigenous or protected knowledge, export-control-sensitive, sanctions-sensitive, controlled-technology-sensitive, privileged, or legal-hold records.

11.11.3(c) Register access shall be role-based, least-privilege, purpose-limited, authenticated, authorized, logged where material, reviewable, revocable, and capable of supporting controlled access or public-safe summary where appropriate.

11.11.3(d) The controlling rule shall be that a register’s existence does not make all register contents broadly accessible.


11.11.4 Register Update Frequency. 11.11.4(a) Every official register shall identify its required update frequency, including real-time, event-based, daily, weekly, monthly, quarterly, annual, periodic, or review-triggered updates as appropriate.

11.11.4(b) High-risk registers, including cybersecurity incidents, data access, AI use, public authority references, public-safe publications, technical releases, vulnerabilities, corrections, and boundary incidents, shall be updated promptly when material changes occur.

11.11.4(c) Update frequency shall be sufficient to prevent stale records, false public meaning, unsafe publication, access errors, correction delay, or audit failure.

11.11.4(d) The controlling rule shall be that registers must be updated at the speed required by their risk.


11.11.5 Register Entry Authority. 11.11.5(a) Every official register shall identify who may create, approve, edit, correct, suspend, close, reopen, supersede, withdraw, retract, archive, export, or delete entries.

11.11.5(b) Entry authority shall be proportionate to risk and shall preserve segregation of duties where material.

11.11.5(c) Register entries shall not be altered by unauthorized persons, informal request, sponsor pressure, provider pressure, public authority preference, finance timeline, media concern, or convenience.

11.11.5(d) The controlling rule shall be that register entries must be controlled by assigned authority, not informal access.


11.11.6 Register Change Logs. 11.11.6(a) Official registers shall maintain change logs sufficient to show material changes to entries, metadata, classification, access, status, owner, custodian, version, public-safe status, correction status, and archive status.

11.11.6(b) Change logs shall identify who made the change, when, under what authority, what changed, why, and what related records or notices were affected where material.

11.11.6(c) Change logs shall be protected against unauthorized alteration, deletion, silent editing, or concealment.

11.11.6(d) The controlling rule shall be that registers must show not only current status, but how current status came to be.


11.11.7 Register Reconciliation. 11.11.7(a) Official registers shall be reconciled periodically and where triggered by incidents, audits, corrections, public-safe publication review, technical release review, data access review, public authority review, sponsorship review, provider review, or Nexus interface review.

11.11.7(b) Reconciliation shall compare related registers, repositories, Case IDs, publications, dashboards, maps, technical releases, public authority references, sponsor records, provider records, data access records, AI-use records, incident records, and correction records to identify inconsistencies, omissions, stale entries, duplicate entries, orphaned records, or unsupported claims.

11.11.7(c) Reconciliation findings shall be recorded, assigned, corrected, escalated where material, and closed only after affected dependencies are reviewed.

11.11.7(d) The controlling rule shall be that registers must be reconciled because public-good memory cannot remain trustworthy if its records disagree silently.


11.11.8 Register Error Correction. 11.11.8(a) Register errors shall be corrected promptly and proportionately. Errors may include inaccurate metadata, missing entries, duplicate entries, misclassification, access errors, status errors, stale records, incorrect public-safe status, unsupported authority, missing correction path, or incorrect archive status.

11.11.8(b) Register correction shall preserve the original entry where required for audit, identify the error, record the correction, identify the correcting authority, update related records, and issue notices where reliance may be affected.

11.11.8(c) Register correction shall not be treated as reputational failure. It shall be treated as necessary maintenance of institutional truth.

11.11.8(d) The controlling rule shall be that registers must be correctable because records discipline requires repair, not perfection theatre.


11.11.9 Register Export, Reporting, Public-Safe Summary, and Controlled Access. 11.11.9(a) Register export, reporting, public-safe summary, and controlled access shall occur only under approved rules.

11.11.9(b) Register exports shall be classified, access-controlled, purpose-limited, logged where material, protected against onward disclosure, and reviewed for privacy, cybersecurity, public authority sensitivity, protected knowledge, finance sensitivity, commercial sensitivity, IP, competition safety, and public-safe status.

11.11.9(c) Public-safe summaries of registers may be published where appropriate, but shall omit or transform restricted details, sensitive locations, personal information, public authority restricted information, cyber-sensitive details, infrastructure-sensitive details, finance-sensitive details, commercially sensitive details, community-protected information, Indigenous or protected knowledge, secrets, and legal privileged information.

11.11.9(d) Controlled access to registers shall be provided only to authorized persons for recorded purposes and shall be subject to confidentiality, access logging where material, expiration, revocation, and correction obligations.

11.11.9(e) The controlling rule shall be that registers may support transparency, but transparency must be public-safe and controlled where needed.


11.11.10 Register Retention, Archival, Sealing, Deletion, and Legal Hold. 11.11.10(a) Official registers shall have retention, archival, sealing, deletion, and legal hold rules appropriate to their contents and legal obligations.

11.11.10(b) Retention shall be proportionate to statutory requirements, audit need, public-benefit purpose, correction need, institutional memory, privacy, cybersecurity, public authority restrictions, protected knowledge controls, IP obligations, competition safety, and Nexus interface significance.

11.11.10(c) Archival shall preserve historical traceability while marking records as inactive, superseded, withdrawn, retracted, retired, or otherwise limited.

11.11.10(d) Sealing may be required for sensitive records, protected knowledge, confidential source information, legal matters, investigations, cybersecurity incidents, public authority restrictions, or safety reasons.

11.11.10(e) Deletion shall occur only where lawful, authorized, recorded, and consistent with legal hold, correction needs, audit needs, public authority restrictions, protected knowledge requirements, and retention obligations.

11.11.10(f) Legal hold shall suspend deletion, alteration, destruction, or normal archival disposal for affected records and registers.

11.11.10(g) The controlling rule shall be that register lifecycle management must preserve both accountability and lawful protection.


11.11.11 Register Audit and Assurance. 11.11.11(a) Official registers shall be subject to audit and assurance proportionate to risk, sensitivity, public meaning, legal requirements, technical significance, public authority relevance, finance relevance, sponsor relevance, provider relevance, community safeguard relevance, and Nexus interface significance.

11.11.11(b) Register audit may assess completeness, accuracy, classification, access, update frequency, authority mapping, metadata quality, change logs, reconciliation, correction history, retention, legal hold, archive status, and continuity.

11.11.11(c) Register assurance may include corrective action plans, training updates, process redesign, access review, technical improvements, classification review, public-safe publication review, cybersecurity review, and Board or committee reporting where material.

11.11.11(d) Audit findings shall be recorded, assigned, tracked, corrected, and closed only after sufficient evidence of remediation.

11.11.11(e) The controlling rule shall be that registers must be assured because records discipline is a living control, not a one-time setup.


11.11.12 Register Failure, Backup, Restoration, and Continuity. 11.11.12(a) GCRI Canada shall maintain rules for register failure, backup, restoration, and continuity.

11.11.12(b) Register failure includes loss of access, corruption, unauthorized alteration, deletion, system outage, platform failure, ransomware, repository compromise, misconfiguration, data loss, synchronization failure, export failure, backup failure, or loss of custodian knowledge.

11.11.12(c) Critical registers shall have backup, restoration, access continuity, exportability, platform portability, successor custodian, incident response, recovery priority, and continuity records.

11.11.12(d) Restoration shall preserve integrity, version history, change logs, classification, access controls, legal hold status, correction records, and archive relationships where feasible.

11.11.12(e) Register failure shall be treated as an incident where it may affect governance, evidence integrity, public-safe publication, public authority boundaries, finance boundaries, provider neutrality, sponsor non-control, technical assets, cybersecurity, protected knowledge, or correctionability.

11.11.12(f) The controlling rule shall be that GCRI Canada’s registers must survive disruption because institutional memory is part of the public-good mission.

11.16 Controlled Vocabulary Register

11.16.1 Controlled Vocabulary Register as Semantic Authority Record. 11.16.1(a) GCRI Canada shall maintain a Controlled Vocabulary Register as the semantic authority record for material institutional terms used in its Charter, bylaws, policies, procedures, schedules, annexes, manuals, evidence records, method records, observability records, Truth Engine records, public-good software, Open Technical Baselines, public-safe publications, dashboards, maps, public authority materials, finance-facing materials, GRF inputs, GRA inputs, Protocol Authority inputs, Nexus interface records, public claims, correction notices, and external communications.

11.16.1(b) The Controlled Vocabulary Register shall preserve semantic discipline so that words used by GCRI Canada do not drift into authority, recognition, finance-readiness, certification, public authority meaning, procurement effect, provider preference, sponsor validation, protocol effect, public warning, emergency command, operational clearance, infrastructure operation, or execution consequence beyond their recorded meaning.

11.16.1(c) The Controlled Vocabulary Register shall identify defined terms, term status, approved definition, permitted uses, prohibited uses, public-safe definition where applicable, technical definition where applicable, legal-boundary notes where applicable, public authority boundary notes where applicable, finance boundary notes where applicable, localization notes, translation notes, semantic crosswalks, divergence notes, equivalence notes, supersession history, and correction path.

11.16.1(d) A term shall not acquire institutional meaning merely because it is used repeatedly, used in slides, used in email, used in chat, used by sponsors, used by providers, used by public authorities, used by media, used by capital readers, used in AI outputs, used in dashboards, used in maps, used in technical repositories, or used in external materials. Material institutional meaning shall arise from the Controlled Vocabulary Register or another competent authoritative record.

11.16.1(e) Where a term is not yet registered, ambiguous, contested, localized, translated, externally borrowed, standards-derived, public authority-adjacent, finance-adjacent, certification-adjacent, protocol-adjacent, or execution-adjacent, GCRI Canada shall use the narrowest and safest meaning until the term is reviewed and recorded.

11.16.1(f) The controlling rule shall be that GCRI Canada’s vocabulary is part of its governance architecture, and semantic authority shall be recorded, not inferred.


11.16.2 Core Institutional Terms. 11.16.2(a) The Controlled Vocabulary Register shall include core institutional terms necessary to define GCRI Canada’s identity, role, purpose, limits, and institutional separateness.

11.16.2(b) Core institutional terms shall include, where applicable, GCRI Canada, The Global Centre for Risk and Innovation, Canadian public-benefit institution, nonprofit, non-share, non-distributing, non-charitable unless lawfully changed, non-executing, non-market, non-sovereign, public-good stack, enterprise stack, mission lock, public-good stewardship, evidence-and-methods mandate, public-safe publication, validity-by-record, correctionability, legal separateness, role separation, public authority boundary, finance boundary, provider neutrality, sponsor non-control, anti-capture, anti-enclosure, audit-defensibility, and public trust.

11.16.2(c) Core institutional terms shall be defined to prevent GCRI Canada from being misdescribed as a regulator, public authority, certifier, recognizer, finance actor, investment adviser, broker, underwriter, lender, insurer, rating agency, guarantor, procurement body, Protocol Authority by default, market infrastructure operator, managed service provider, vendor, consultancy, event brand, media platform, National Company, Project SPV, provider, host, operator, infrastructure owner, infrastructure operator, public warning authority, emergency command actor, or execution vehicle.

11.16.2(d) Core institutional terms shall include boundary notes identifying what the term authorizes, what it does not authorize, what external actors may not infer from it, what public claims require review, and what correction path applies where the term is misused.

11.16.2(e) The controlling rule shall be that core institutional terms shall preserve GCRI Canada’s identity before they are used to describe its activities.


11.16.3 Evidence Terms. 11.16.3(a) The Controlled Vocabulary Register shall include evidence terms used to describe source materials, evidence records, source lineage, evidence quality, evidence packs, evidence inputs, maturity evidence inputs, finance-facing evidence inputs, Observatory evidence, Truth Engine evidence, public-safe summaries, controlled annexes, restricted annexes, and correction records.

11.16.3(b) Evidence terms shall include, where applicable, evidence, evidence record, source, source lineage, provenance, custody, contributor, confidence, uncertainty, limitation, assumption, data-to-evidence, evidence class, evidence quality, evidence intake, evidence pack, evidence input, maturity evidence input, finance-facing evidence input, public-safe evidence, controlled evidence, restricted evidence, stale evidence, corrected evidence, superseded evidence, withdrawn evidence, retracted evidence, and archive evidence.

11.16.3(c) Evidence terms shall distinguish evidence from recognition, maturity status, certification, finance-readiness, public authority approval, procurement approval, provider endorsement, sponsor validation, protocol effect, public warning, emergency command, operational clearance, infrastructure operation, and execution.

11.16.3(d) Evidence definitions shall require source lineage, classification, scope, confidence, uncertainty, limitations, review status, public-safe status, and correction path where the term is used in material records or public-facing materials.

11.16.3(e) The controlling rule shall be that evidence terms shall make evidence usable without allowing evidence to become downstream authority by vocabulary drift.


11.16.4 Methods Terms. 11.16.4(a) The Controlled Vocabulary Register shall include methods terms used to describe GCRI Canada’s evidence methods, research methods, observability methods, ontology methods, Truth Engine methods, verifiable compute methods, verifiable intelligence methods, public-safe publication methods, secure release methods, data governance methods, AI governance methods, cybersecurity methods, safeguard methods, and correction methods.

11.16.4(b) Methods terms shall include, where applicable, method, method record, method adoption, method review, method library, evidence method, evaluation method, benchmark method, calibration method, reproducibility, replication, challengeability, public-safe method, data method, AI method, cybersecurity method, observability method, ontology method, Truth Engine method, correction method, superseded method, withdrawn method, retired method, and method archive.

11.16.4(c) Methods terms shall distinguish method support from certification, approval, conformance, recognition, maturity, finance-readiness, procurement, public authority action, protocol effect, provider preference, sponsor validation, public warning, operational command, and execution.

11.16.4(d) Method definitions shall identify whether a method is draft, experimental, internal, controlled, public-safe, adopted, deprecated, superseded, withdrawn, retired, or archived, and shall identify required inputs, prohibited inputs, assumptions, limitations, review status, and correction path.

11.16.4(e) The controlling rule shall be that a method term shall describe how GCRI Canada structures truth, not imply that GCRI Canada has decided what others must do.


11.16.5 Observability Terms. 11.16.5(a) The Controlled Vocabulary Register shall include observability terms used in relation to Nexus Observatory methods, sensors, nodes, hubs, clusters, hotspots, regional clusters, national dense cores, dashboards, maps, AI-RAN, O-RAN, DePIN, cyber telemetry, geospatial systems, digital twins, simulations, degraded-mode awareness, and public-safe outputs.

11.16.5(b) Observability terms shall include, where applicable, observability, Observatory, Observatory method, node, hub, cluster, hotspot, regional cluster, national dense core, sensor, telemetry, signal, indicator, dashboard, map, geospatial layer, digital twin, simulation, degraded mode, live reading, observation record, node evidence, sensor evidence, AI-RAN evidence, DePIN evidence, cyber telemetry evidence, public-safe map, controlled map, restricted map, and Observatory evidence pack.

11.16.5(c) Observability terms shall distinguish observation from public warning, emergency command, public authority action, operational control, infrastructure operation, public safety order, public health order, procurement approval, finance-readiness, provider endorsement, certification, recognition, protocol effect, and execution.

11.16.5(d) Observability definitions shall identify update status, timestamp, scope, confidence, uncertainty, latency, limitations, source lineage, public-safe transformation, public authority boundary, community safeguard, protected knowledge control, sensitive-location control, and correction path where material.

11.16.5(e) The controlling rule shall be that observability terms shall make systems more intelligible without making GCRI Canada an operator, warning authority, or command body.


11.16.6 Truth Engine Terms. 11.16.6(a) The Controlled Vocabulary Register shall include Truth Engine terms used to describe source comparison, evidence processing, contradiction detection, confidence treatment, uncertainty treatment, inference records, evidence-to-summary methods, AI-assisted review, public-safe transformation, and correction signals.

11.16.6(b) Truth Engine terms shall include, where applicable, Truth Engine, truth engine method, source comparison, source weighting, contradiction, corroboration, confidence, uncertainty, inference, inference record, evidence graph, retrieval, embedding, citation, extraction, classification, limitation, validation within record, verification within record, challenge, correction signal, dependency notice, and truth output.

11.16.6(c) Truth Engine terms shall be defined so that “truth” means bounded institutional technical truth within recorded evidence, methods, source lineage, review status, confidence, uncertainty, limitations, and correction path, and not legal truth, public authority truth, finance truth, market truth, public warning, certification, recognition, protocol effect, or execution authority.

11.16.6(d) Truth Engine definitions shall include prohibited uses for claiming official truth, final truth, regulatory truth, public authority approval, finance-readiness, provider endorsement, sponsor validation, certification, recognition, or automatic decision effect.

11.16.6(e) The controlling rule shall be that Truth Engine language shall strengthen evidence discipline without inflating GCRI Canada into the authority that decides downstream consequences.


11.16.7 Verifiable Compute and AI Terms. 11.16.7(a) The Controlled Vocabulary Register shall include verifiable compute and AI terms used in relation to compute workloads, model use, AI outputs, inference records, proof receipts, confidential computing, secure enclaves, compute-to-data, retrieval, embeddings, model cards, dataset cards, system cards, benchmark cards, agentic AI, and verifiable intelligence.

11.16.7(b) Verifiable compute and AI terms shall include, where applicable, verifiable compute, verifiable intelligence, compute workload, compute-to-data, confidential computing, secure enclave, model, model use, model card, dataset card, system card, benchmark card, inference record, AI output, AI-assisted output, agentic AI, retrieval, embedding, prompt, prompt library, proof receipt, hash, signature, timestamp, provenance record, and audit trail.

11.16.7(c) These terms shall distinguish computational verifiability, auditability, provenance, and integrity from truth, approval, certification, recognition, finance-readiness, public authority action, protocol effect, provider endorsement, sponsor validation, public warning, emergency command, operational clearance, infrastructure operation, and execution.

11.16.7(d) AI terms shall identify where human review, public-safe review, data classification, sensitive data exclusion, AI-use restriction, retrieval control, embedding control, incident path, and correction path are required.

11.16.7(e) Verifiable compute terms shall state that hashes, signatures, timestamps, proof receipts, blockchain anchors, and technical logs may support integrity of a record within scope, but shall not make the underlying claim true, approved, certified, recognized, finance-ready, public-authority-approved, or executable by default.

11.16.7(f) The controlling rule shall be that compute may help prove what happened, but it shall not by itself decide what the record means.


11.16.8 Public-Good Software and Technical Baseline Terms. 11.16.8(a) The Controlled Vocabulary Register shall include terms for public-good software, technical baselines, reference architectures, APIs, schemas, data contracts, repositories, releases, SBOMs, dependency records, secure release, and technical asset governance.

11.16.8(b) Public-good software and technical baseline terms shall include, where applicable, public-good software, technical asset, Open Technical Baseline, reference architecture, technical profile, interoperability profile, schema, API, data contract, data dictionary, repository, release, release candidate, SBOM, dependency, vulnerability, secure release, rollback, hotfix, deprecation, supersession, withdrawal, retirement, fork, compatibility claim, and external use.

11.16.8(c) These terms shall distinguish public-good technical support from vendor status, managed service status, certification, conformance status, procurement preference, provider ranking, finance-readiness, public authority approval, protocol effect, market infrastructure, infrastructure operation, and execution.

11.16.8(d) Technical baseline definitions shall include scope, version, steward, public-safe status, dependencies, external standards mapping where applicable, limitations, permitted uses, prohibited uses, and boundary language stating that alignment does not create certification, procurement approval, finance-readiness, public authority adoption, provider preference, or protocol effect by default.

11.16.8(e) The controlling rule shall be that public-good technical terms shall preserve open technical usefulness without creating proprietary gatekeeping or authority over downstream action.


11.16.9 Public Authority Terms. 11.16.9(a) The Controlled Vocabulary Register shall include public authority terms used in relation to public authority participation, public authority learning, regulator-listening, public finance reader status, emergency-management participation, public authority data contributions, reference approvals, public authority boundaries, and no-delegation controls.

11.16.9(b) Public authority terms shall include, where applicable, public authority, public authority participant, public authority learning, capacity classification, regulator-listening, public finance reader, emergency-management participant, public infrastructure participant, public health participant, public safety participant, public authority data, public authority reference, public authority approval, public authority adoption, official guidance, public warning, emergency command, procurement approval, funding approval, public finance approval, sovereign obligation, and no-delegation.

11.16.9(c) Public authority terms shall distinguish attendance from endorsement, learning from adoption, data contribution from approval, regulator-listening from regulatory guidance, public finance reading from public finance approval, emergency-management participation from emergency command, and public-safe output from official public warning.

11.16.9(d) Public authority definitions shall require capacity classification, reference approval where material, no-endorsement language, no-delegation language, no-public-warning language, no-procurement language, no-public-finance language, and correction path.

11.16.9(e) The controlling rule shall be that public authority language shall protect public power from being implied through GCRI Canada proximity.


11.16.10 Finance-Readiness Terms. 11.16.10(a) The Controlled Vocabulary Register shall include finance-readiness terms used in relation to GRA, capital readability, proof-pack discipline, capital-reader rooms, public finance readers, insurance-readiness, risk evidence, diligence gap maps, and finance-boundary safety.

11.16.10(b) Finance-readiness terms shall include, where applicable, finance-readiness, capital-readiness, capital readability, bankability, fundability, investment readiness, insurance-readiness, proof pack, diligence gap map, capital-reader room, public finance reader, public finance approval, guarantee, rating, underwriting, lending decision, insurance approval, capital commitment, investment advice, securities solicitation, brokerage, and financial execution.

11.16.10(c) Finance-readiness terms shall distinguish GCRI Canada technical evidence from GRA finance-readiness, capital-reader review, investment advice, securities activity, underwriting, lending, insurance placement, rating, guarantee, public finance approval, capital commitment, and financial execution.

11.16.10(d) Finance-facing definitions shall require no-investment-advice, no-securities-solicitation, no-brokerage, no-underwriting, no-lending, no-insurance, no-rating, no-guarantee, no-public-finance-approval, no-capital-commitment, no-finance-readiness-by-GCRI, and no-financial-execution-by-GCRI language where material.

11.16.10(e) The controlling rule shall be that finance-readable evidence is not finance-readiness, and finance terms shall be governed to prevent market overclaim.


11.16.11 GRF, GRA, Protocol Authority, Nexus Network, Nexus Universe, Nexus Observatory, Nexus Rails, Nexus Grid, Nexus Academy, National Company, Project SPV, Provider, Sponsor, Host, Community, and Participant Terms. 11.16.11(a) The Controlled Vocabulary Register shall include terms defining GCRI Canada’s relationships with The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards / Protocol Authority, Nexus Network, Nexus Universe, Nexus Observatory, Nexus Rails, Nexus Grid, Nexus Academy, Regional Nexus Consortiums, National Nexus Consortiums, National Working Groups, Nexus Competence Cells, National Consortium Companies, Project SPVs, qualified providers, sponsors, donors, funders, hosts, communities, civil society, media, capital readers, participants, fellows, advisors, councils, and contributors.

11.16.11(b) GRF terms shall distinguish registry, recognition, standing, maturity records, claims discipline, stakeholder formation, public-safe reporting, and public-facing legitimacy from GCRI Canada evidence and methods inputs.

11.16.11(c) GRA terms shall distinguish finance-readiness, capital readability, proof-pack discipline, insurance-readiness, capital-reader rooms, and regulated-perimeter discipline from GCRI Canada technical evidence.

11.16.11(d) Protocol Authority terms shall distinguish protocol discipline, conformance logic, role keys, smart licenses, proof receipt effect, entitlement states, anchoring discipline, and technical validity surfaces from GCRI Canada technical support.

11.16.11(e) Nexus Network, Nexus Universe, Nexus Observatory, Nexus Rails, Nexus Grid, and Nexus Academy terms shall distinguish GCRI Canada inputs from network ownership, event operations, infrastructure operation, finance execution, maturity record issuance, professional certification, regulated credentialing, public authority action, and execution.

11.16.11(f) National Company and Project SPV terms shall distinguish downstream execution, commercial delivery, financing, procurement, operations, liability, and project outcomes from GCRI Canada’s upstream evidence and methods role.

11.16.11(g) Provider, sponsor, host, community, participant, fellow, advisor, council, university, media, and capital-reader terms shall identify duties, permitted references, prohibited claims, role boundaries, public-safe limits, and correction paths.

11.16.11(h) The controlling rule shall be that relationship terms shall preserve role separation before they facilitate collaboration.


11.16.12 Term Status, Definition, Prohibited Uses, Permitted Uses, Public-Safe Definition, Translation Notes, Localization Notes, and Correction Path. 11.16.12(a) Each term in the Controlled Vocabulary Register shall include term status, approved definition, permitted uses, prohibited uses, public-safe definition where applicable, technical definition where applicable, legal-boundary notes where applicable, public authority boundary notes where applicable, finance boundary notes where applicable, translation notes, localization notes, semantic crosswalks, divergence notes, equivalence notes, supersession history, and correction path.

11.16.12(b) Term status may include proposed, under review, adopted, active, public-safe, internal, controlled, restricted, deprecated, superseded, withdrawn, retired, archived, contested, localization-specific, translation-specific, or prohibited.

11.16.12(c) Prohibited uses shall identify language that may create overclaim, public authority confusion, finance overclaim, certification implication, recognition implication, provider preference, sponsor validation, protocol effect, public warning implication, emergency command implication, market implication, operational clearance, infrastructure operation, or execution consequence.

11.16.12(d) Permitted uses shall identify the role, record class, publication class, handling class, interface, and boundary language under which the term may be used.

11.16.12(e) Public-safe definitions shall be used where a term must be explained to public audiences without exposing restricted information, creating false certainty, or inflating GCRI Canada’s authority.

11.16.12(f) Translation and localization notes shall identify jurisdiction-specific, language-specific, cultural, community, Indigenous or protected knowledge, public authority, finance, legal, technical, and semantic issues that may affect meaning.

11.16.12(g) Correction paths shall permit term correction, relabeling, public-safe clarification, controlled notice, restricted notice, deprecation, supersession, withdrawal, or archive where misuse, drift, ambiguity, or harm occurs.

11.16.12(h) The controlling rule shall be that terms shall carry their meaning, limits, and correction path wherever they are used.


11.17 Controlled Vocabulary Change Control

11.17.1 Term Proposal. 11.17.1(a) New terms, revised terms, deprecated terms, localized terms, translated terms, external standards terms, public authority terms, finance-facing terms, technical terms, community safeguard terms, protected knowledge terms, and Nexus interface terms shall be proposed through a controlled vocabulary change process.

11.17.1(b) A term proposal shall identify the proposed term, current term if any, proposed definition, reason for proposal, intended use, affected instruments, affected records, affected publications, affected technical assets, affected interfaces, public-safe implications, public authority implications, finance implications, technical implications, safeguards implications, translation or localization implications, prohibited uses, permitted uses, and correction path.

11.17.1(c) Term proposals may originate from directors, officers, staff, fellows, advisors, councils, researchers, technical contributors, public authority interfaces, community interfaces, GRF, GRA, Protocol Authority, Nexus bodies, providers, sponsors, universities, civil society, media review, capital-reader interfaces, or correction processes, but no originator shall acquire authority over the term by proposing it.

11.17.1(d) Proposed terms shall be marked as proposed and shall not be used as adopted semantic authority until reviewed and adopted.

11.17.1(e) The controlling rule shall be that new language enters GCRI Canada through proposal before it becomes institutional vocabulary.


11.17.2 Term Review. 11.17.2(a) Proposed terms shall undergo review proportionate to their institutional, legal, technical, public authority, finance, safeguard, publication, and Nexus significance.

11.17.2(b) Term review shall assess definition clarity, role boundary impact, consistency with the Charter, consistency with bylaws and policies, relation to existing terms, risk of overclaim, risk of vocabulary drift, public-safe usability, translation risk, localization risk, public authority ambiguity, finance ambiguity, provider or sponsor misuse risk, technical precision, and correctionability.

11.17.2(c) Term review shall identify whether the term should be adopted, modified, limited, restricted, localized, crosswalked, deprecated, rejected, or escalated for higher review.

11.17.2(d) Term review shall produce a record identifying reviewers, review date, issues, decisions, conditions, permitted uses, prohibited uses, public-safe definition where needed, and correction path.

11.17.2(e) The controlling rule shall be that terms shall be reviewed for institutional effect, not merely wording preference.


11.17.3 Legal Boundary Review. 11.17.3(a) Legal boundary review shall be required for terms that may affect legal identity, corporate authority, nonprofit status, public-benefit purpose, non-execution, public authority meaning, certification implication, finance implication, regulated perimeter, IP, licensing, data rights, privacy, cybersecurity, protected knowledge, public claims, or external reliance.

11.17.3(b) Legal boundary review shall identify whether a term could imply that GCRI Canada is a regulator, public authority, certifier, recognizer, finance actor, investment adviser, broker, underwriter, lender, insurer, rating agency, guarantor, procurement body, Protocol Authority, market infrastructure operator, vendor, consultancy, infrastructure operator, public warning authority, emergency command actor, National Company, Project SPV, provider, host, operator, or execution vehicle.

11.17.3(c) Legal boundary review shall assess whether the term requires disclaimers, boundary language, restricted use, public-safe definition, controlled use, prohibition, or external legal review before adoption.

11.17.3(d) Terms that create unacceptable legal boundary risk shall be rejected, narrowed, replaced, or restricted.

11.17.3(e) The controlling rule shall be that words that could change legal meaning require legal-boundary discipline before use.


11.17.4 Public Authority Boundary Review. 11.17.4(a) Public authority boundary review shall be required for terms that may imply public authority endorsement, adoption, approval, regulation, procurement approval, funding approval, public finance approval, public warning, emergency command, official guidance, compliance determination, enforcement position, sovereign obligation, public-law status, or delegation to GCRI Canada.

11.17.4(b) Public authority boundary review shall assess whether the term distinguishes attendance from endorsement, learning from adoption, regulator-listening from regulatory guidance, public finance reader status from public finance approval, emergency-management participation from emergency command, public-safe output from public warning, and data contribution from public authority approval.

11.17.4(c) Public authority terms shall include capacity classification requirements, reference approval requirements, no-delegation language, no-endorsement language, no-public-warning language, no-procurement language, no-public-finance language, and correction path where material.

11.17.4(d) Terms that could reasonably create public authority confusion shall be narrowed, restricted, paired with boundary language, or rejected.

11.17.4(e) The controlling rule shall be that GCRI Canada shall not let vocabulary borrow public power.


11.17.5 Finance Boundary Review. 11.17.5(a) Finance boundary review shall be required for terms that may imply finance-readiness, investment readiness, bankability, fundability, insurance-readiness, public finance approval, grant approval, budget allocation, guarantee, rating, underwriting, lending decision, insurance approval, capital commitment, investment advice, securities solicitation, brokerage, or financial execution.

11.17.5(b) Finance boundary review shall assess whether the term distinguishes technical evidence from GRA finance-readiness, capital-reader access from capital commitment, proof input from proof-pack conclusion, risk evidence from insurance approval, public finance reader status from public finance approval, and diligence support from investment advice.

11.17.5(c) Finance-facing terms shall include no-investment-advice, no-securities-solicitation, no-brokerage, no-underwriting, no-lending, no-insurance, no-rating, no-guarantee, no-public-finance-approval, no-capital-commitment, no-finance-readiness-by-GCRI, and no-financial-execution-by-GCRI boundaries where material.

11.17.5(d) Terms that create unacceptable finance overclaim risk shall be rejected, replaced, narrowed, restricted, or routed to GRA or other competent finance-facing authority for clarification.

11.17.5(e) The controlling rule shall be that finance language shall not turn evidence into market signal beyond the record.


11.17.6 Technical Review. 11.17.6(a) Technical review shall be required for terms concerning evidence methods, observability, Truth Engine methods, AI, verifiable compute, software, APIs, schemas, data contracts, technical baselines, cybersecurity, repositories, releases, benchmarks, models, datasets, dashboards, maps, digital twins, AI-RAN, O-RAN, DePIN, sensors, and other technical assets.

11.17.6(b) Technical review shall assess precision, interoperability, external standards alignment, compatibility, versioning implications, dependency implications, security implications, public-safe implications, implementation ambiguity, misuse risk, and correctionability.

11.17.6(c) Technical terms shall distinguish benchmark from ranking, compatibility from conformance, baseline alignment from certification, proof receipt from approval, dashboard display from operational command, model output from institutional truth, and secure release from security guarantee.

11.17.6(d) Technical review shall identify whether a term requires an API definition, schema definition, glossary entry, technical note, public-safe definition, restricted definition, or standards crosswalk.

11.17.6(e) The controlling rule shall be that technical vocabulary must be precise enough to interoperate and bounded enough not to overclaim.


11.17.7 Safeguards Review. 11.17.7(a) Safeguards review shall be required for terms involving communities, Indigenous knowledge where applicable, local knowledge, territorial knowledge, environmental knowledge, cultural sites, protected knowledge, vulnerable participants, protected persons, health-sensitive data, rights-bearing data, public-safe mapping, consent, non-consent, withdrawal, grievance, remedy, and correction.

11.17.7(b) Safeguards review shall assess whether a term may extract, flatten, expose, misattribute, appropriate, commercialize, tokenize, map, model, dashboard, publish, or reuse protected knowledge or community context beyond safe and lawful bounds.

11.17.7(c) Safeguard-sensitive terms shall include consent and non-consent treatment, attribution and non-attribution, public-safe mapping controls, protected knowledge classification, grievance pathways, withdrawal pathways, remedy pathways, and correction paths where applicable.

11.17.7(d) Terms that could create harm, stigma, re-identification, sensitive-location exposure, protected knowledge exposure, or community misrepresentation shall be revised, restricted, localized, or rejected.

11.17.7(e) The controlling rule shall be that words used about people, communities, places, and knowledge must protect dignity and safety before they serve institutional convenience.


11.17.8 Translation and Localization Review. 11.17.8(a) Translation and localization review shall be required where terms are translated, localized, adapted to Canadian, provincial, territorial, Indigenous, local, community, sectoral, public authority, technical, legal, or international contexts, or mapped to external standards.

11.17.8(b) Translation review shall assess whether a translated term preserves meaning, boundaries, public-safe status, legal limits, public authority limits, finance limits, technical precision, safeguards, and correctionability.

11.17.8(c) Localization review shall assess whether local usage changes authority, implies public authority adoption, weakens safeguards, changes data meaning, creates finance overclaim, alters provider-neutrality, creates sponsor validation, or departs from Nexus role separation.

11.17.8(d) Localization notes shall identify jurisdiction, language, context, divergence from source term, equivalence status, non-equivalence status, partial equivalence, public-safe definition, and correction path.

11.17.8(e) The controlling rule shall be that translation and localization shall improve intelligibility without changing authority by accident.


11.17.9 Adoption, Effective Date, Supersession, and Public-Safe Notice. 11.17.9(a) Terms shall be adopted only through a recorded controlled vocabulary approval process identifying authority, version, definition, effective date, permitted uses, prohibited uses, affected records, affected publications, affected interfaces, public-safe definition, and correction path.

11.17.9(b) The effective date of a term shall identify when the term controls new records and whether prior records require migration, annotation, correction, supersession, or archive marking.

11.17.9(c) Supersession shall identify the prior term, successor term, reason, continuing validity where any, affected records, affected public claims, affected translations, affected localizations, affected technical assets, and required notices.

11.17.9(d) Public-safe notice shall be issued where adoption or supersession of a term materially affects public-facing meaning, public authority interpretation, finance-facing interpretation, provider or sponsor references, technical baselines, dashboards, maps, reports, public claims, or Nexus interfaces.

11.17.9(e) The controlling rule shall be that a term becomes authoritative only when adopted, dated, bounded, and notice-ready.


11.17.10 Deprecation, Retirement, Withdrawal, and Archive of Terms. 11.17.10(a) Terms may be deprecated, retired, withdrawn, restricted, prohibited, superseded, or archived where they become inaccurate, misleading, unsafe, legally risky, public authority-confusing, finance-overclaiming, technically obsolete, safeguard-defective, provider-biased, sponsor-influenced, translation-defective, localization-defective, or inconsistent with GCRI Canada’s Charter.

11.17.10(b) Deprecation shall identify that the term should no longer be used in new records except under stated conditions. Retirement shall identify that the term is no longer maintained for current use. Withdrawal shall identify that the term should not be relied upon because it is materially defective or unsafe. Archive shall preserve historical traceability without current validity.

11.17.10(c) Deprecation, retirement, withdrawal, and archive records shall identify affected materials, replacement terms where any, continuing validity where any, notice audience, migration requirements, public-safe implications, and correction path.

11.17.10(d) Withdrawn or retired terms shall not continue in public-facing materials without status marking and appropriate boundary language.

11.17.10(e) The controlling rule shall be that obsolete or unsafe language must be retired from authority, not left to drift.


11.17.11 Vocabulary Drift Detection. 11.17.11(a) GCRI Canada shall maintain processes for vocabulary drift detection across governance records, publications, public claims, dashboards, maps, technical baselines, repositories, public authority materials, finance-facing materials, provider materials, sponsor materials, Academy materials, media materials, social media, GRF inputs, GRA inputs, Protocol Authority inputs, and Nexus interfaces.

11.17.11(b) Vocabulary drift includes use of terms beyond approved meaning, use of unapproved terms as authority terms, inflation of evidence into recognition, technical readiness into finance-readiness, public authority learning into adoption, baseline alignment into certification, provider participation into endorsement, sponsor support into validation, dashboard display into warning, proof receipt into approval, or compatibility into protocol effect.

11.17.11(c) Drift detection may occur through register reconciliation, publication review, public claims review, public authority review, finance-safe review, provider-neutrality review, sponsor review, community challenge, media monitoring, repository review, AI-output review, incident intake, or audit.

11.17.11(d) Vocabulary drift shall be classified by severity, affected audience, public-safe risk, public authority risk, finance risk, provider or sponsor risk, technical risk, community safeguard risk, and correction urgency.

11.17.11(e) The controlling rule shall be that vocabulary drift is an institutional risk because words can create false authority before actions do.


11.17.12 Correction of Misused or Inflated Terms. 11.17.12(a) Misused or inflated terms shall be corrected where a term is used to overstate GCRI Canada authority, imply recognition, imply maturity, imply certification, imply finance-readiness, imply public authority approval, imply procurement approval, imply provider preference, imply sponsor validation, imply protocol effect, imply public warning, imply emergency command, imply operational clearance, imply infrastructure operation, or imply execution.

11.17.12(b) Correction may include relabeling, revision, public-safe clarification, controlled notice, restricted notice, term deprecation, term supersession, publication correction, dashboard label correction, map label correction, repository correction, media correction request, sponsor or provider correction demand, participant retraining, or public claim withdrawal.

11.17.12(c) Term misuse correction records shall identify the term, misuse, affected materials, affected audience, severity, correction action, notice audience, responsible custodian, related Case IDs, and closeout.

11.17.12(d) Repeated misuse of a term shall trigger review of the term definition, public-safe definition, training, templates, public claims controls, and access to the term in external materials.

11.17.12(e) The controlling rule shall be that inflated language shall be brought back to the record before it becomes institutional overclaim.


11.18 Classification Architecture

11.18.1 Document Classification. 11.18.1(a) GCRI Canada shall maintain a document classification architecture for governance instruments, records, drafts, reports, publications, public-safe summaries, controlled annexes, restricted annexes, technical notes, dashboards, maps, datasets, software documentation, API documentation, public authority materials, finance-facing materials, sponsor materials, provider materials, community materials, Academy materials, and Nexus interface materials.

11.18.1(b) Document classification shall identify whether a document is draft, internal, confidential, restricted, controlled, public-safe, public, superseded, withdrawn, retracted, retired, archived, sealed, or under legal hold.

11.18.1(c) Document classification shall determine permitted access, editing, review, circulation, publication, export, AI use, indexing, repository placement, retention, correction, and archive treatment.

11.18.1(d) Classification shall be applied at creation, reviewed before circulation or publication, updated when status changes, and corrected where misclassified.

11.18.1(e) The controlling rule shall be that a document’s classification governs what may be done with it before its content is used.


11.18.2 Evidence Classification. 11.18.2(a) GCRI Canada shall maintain evidence classification for evidence records, evidence inputs, source materials, evidence packs, Observatory records, Truth Engine records, maturity evidence inputs, finance-facing evidence inputs, public-safe summaries, controlled annexes, restricted annexes, and correction records.

11.18.2(b) Evidence classification shall identify source type, source lineage, provenance, custody, evidence class, confidence, uncertainty, limitations, permissions, public-safe status, review status, sensitivity, permitted uses, prohibited uses, and correction path.

11.18.2(c) Evidence may be classified as public, public-safe, internal, confidential, restricted, public authority-sensitive, health-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, personal, community-protected, Indigenous or protected knowledge-related, environmental-sensitive, controlled-technology-sensitive, or otherwise restricted.

11.18.2(d) Evidence classification shall prevent evidence from being reused in public claims, dashboards, maps, public authority materials, finance-facing materials, provider materials, sponsor materials, GRF inputs, GRA inputs, Protocol Authority inputs, or Nexus interfaces beyond its recorded classification and permitted use.

11.18.2(e) The controlling rule shall be that evidence classification determines whether evidence may be seen, summarized, routed, published, or relied upon.


11.18.3 Data Classification. 11.18.3(a) GCRI Canada shall maintain data classification for all data collected, received, generated, processed, transformed, stored, accessed, transferred, published, archived, or deleted by or for GCRI Canada.

11.18.3(b) Data classification shall include, where applicable, public data, public-safe data, internal data, confidential data, restricted data, personal data, health-sensitive data, rights-bearing data, public authority data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, commercially sensitive data, community-protected data, Indigenous knowledge-related data, local knowledge data, territorial knowledge data, environmental data, protected knowledge data, export-control-sensitive data, sanctions-sensitive data, controlled-technology data, privileged data, and legal-hold data.

11.18.3(c) Data classification shall determine lawful basis or approval basis where applicable, purpose limitation, access, AI use, transfer, retention, deletion, sealing, publication, dashboarding, mapping, public-safe transformation, and correction.

11.18.3(d) Data classification shall be reviewed before data is used in AI tools, embeddings, retrieval systems, models, dashboards, maps, datasets, public repositories, public-safe summaries, public authority materials, finance-facing materials, sponsor materials, provider materials, or Nexus interfaces.

11.18.3(e) The controlling rule shall be that data cannot become evidence, AI input, publication material, or technical asset input safely unless its classification is known.


11.18.4 AI Output Classification. 11.18.4(a) GCRI Canada shall classify AI outputs according to their source inputs, model use, purpose, review status, public-safe status, sensitivity, reliability, human review status, and permitted use.

11.18.4(b) AI output classification shall identify whether the output is draft, internal, reviewed, human-reviewed, public-safe, controlled, restricted, not for reliance, publication-ready, superseded, corrected, withdrawn, or archived.

11.18.4(c) AI outputs derived from restricted, confidential, public authority-sensitive, health-sensitive, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, personal, community-protected, Indigenous or protected knowledge, export-control-sensitive, sanctions-sensitive, controlled-technology-sensitive, or privileged materials shall inherit protective handling unless reviewed and transformed into a safe derivative.

11.18.4(d) AI outputs shall not be treated as evidence, institutional findings, public-safe publications, technical baselines, public authority materials, finance-facing materials, provider references, sponsor materials, or public claims unless reviewed, recorded, classified, and approved for that use.

11.18.4(e) The controlling rule shall be that AI output classification shall prevent fluency from being mistaken for authority.


11.18.5 Cybersecurity Classification. 11.18.5(a) GCRI Canada shall maintain cybersecurity classification for records, systems, repositories, vulnerabilities, incidents, dashboards, APIs, keys, tokens, secrets, software, dependencies, release artifacts, data rooms, controlled rooms, AI systems, compute workloads, and public-safe outputs.

11.18.5(b) Cybersecurity classification shall identify whether information is public, public-safe, internal, confidential, restricted, cyber-sensitive, vulnerability-sensitive, exploit-sensitive, credential-sensitive, infrastructure-sensitive, incident-sensitive, disclosure-controlled, embargoed, or legal-hold.

11.18.5(c) Cybersecurity classification shall determine access, disclosure, coordinated disclosure, advisory treatment, public-safe summary, technical detail limitation, repository handling, release timing, patch timing, key rotation, incident notification, and correction path.

11.18.5(d) Cybersecurity-sensitive material shall not be placed in public repositories, public tickets, public dashboards, AI prompts, public datasets, public-safe summaries, media materials, sponsor materials, provider materials, or public authority materials unless reviewed and approved for that handling class.

11.18.5(e) The controlling rule shall be that cybersecurity classification shall disclose enough to correct and protect, but not enough to create avoidable harm.


11.18.6 Public Authority Classification. 11.18.6(a) GCRI Canada shall maintain public authority classification for records involving public authority participation, public authority data, public authority references, regulator-listening status, public finance reader status, emergency-management participation, public infrastructure participation, public health participation, public safety participation, public authority learning, funding discussions, public authority review, and public authority corrections.

11.18.6(b) Public authority classification shall identify capacity, authority or basis where applicable, confidentiality, data contribution status, publication permission, reference approval, logo or name-use approval, public-safe status, no-delegation boundary, no-endorsement boundary, no-public-warning boundary, no-procurement boundary, no-public-finance boundary, and correction path.

11.18.6(c) Public authority materials may be classified as public, public-safe, internal, confidential, restricted, public authority-controlled, public finance-controlled, emergency-sensitive, infrastructure-sensitive, health-sensitive, safety-sensitive, or otherwise restricted.

11.18.6(d) Public authority classification shall prevent public presence from becoming public authority meaning beyond the competent public authority record.

11.18.6(e) The controlling rule shall be that public authority classification protects public trust by keeping public power from being implied through records.


11.18.7 Finance-Sensitive Classification. 11.18.7(a) GCRI Canada shall maintain finance-sensitive classification for records, evidence inputs, proof inputs, controlled-room materials, data-room materials, capital-reader materials, GRA-facing inputs, public finance reader materials, diligence-gap materials, risk evidence, and finance-facing public claims.

11.18.7(b) Finance-sensitive classification shall identify whether materials may be used for technical evidence only, GRA input, capital-reader reading, public finance reader reading, controlled-room use, data-room use, public-safe summary, restricted use, or no finance-facing use.

11.18.7(c) Finance-sensitive materials shall include boundary language prohibiting treatment as investment advice, securities solicitation, brokerage, underwriting, lending decision, insurance placement, rating, guarantee, public finance approval, capital commitment, finance-readiness by GCRI Canada, project approval, procurement approval, or financial execution.

11.18.7(d) Finance-sensitive classification shall determine access, onward disclosure, public-safe summary, correction notice, GRA routing, capital-reader room use, and public claims limits.

11.18.7(e) The controlling rule shall be that finance-sensitive classification prevents technical evidence from becoming market signal beyond the record.


11.18.8 Community-Protected and Protected Knowledge Classification. 11.18.8(a) GCRI Canada shall maintain community-protected and protected knowledge classification for records involving communities, Indigenous knowledge where applicable, local knowledge, territorial knowledge, cultural knowledge, environmental knowledge, sensitive sites, protected persons, vulnerable communities, confidential sources, whistleblowers, rights-bearing data, health-sensitive data, and public-safe mapping.

11.18.8(b) Community-protected and protected knowledge classification shall identify consent or non-consent treatment where applicable, authority or permission where applicable, attribution or non-attribution, sensitivity, public-safe status, mapping restrictions, AI-use restrictions, transfer restrictions, retention limits, grievance path, withdrawal path, remedy path, and correction path.

11.18.8(c) Protected knowledge shall not be treated as open data, ordinary evidence, public authority material, sponsor material, provider material, finance-facing material, AI-training material, dashboard content, map layer, public repository content, or media material without recorded safeguards and approval.

11.18.8(d) Classification shall travel with derivatives, summaries, translations, embeddings, retrieval indexes, model outputs, maps, dashboards, public-safe summaries, reports, technical baselines, Academy materials, GRF inputs, GRA inputs, Protocol Authority inputs, and Nexus interfaces.

11.18.8(e) The controlling rule shall be that protected knowledge remains protected even when transformed into institutional records or technical outputs.


11.18.9 Software and Technical Asset Classification. 11.18.9(a) GCRI Canada shall maintain software and technical asset classification for public-good software, repositories, releases, APIs, schemas, data contracts, technical baselines, reference architectures, datasets, models, dashboards, maps, evaluation harnesses, benchmark harnesses, scripts, templates, SBOMs, dependencies, keys, tokens, secrets, and release artifacts.

11.18.9(b) Software and technical assets may be classified as draft, experimental, internal, controlled, restricted, public-safe, open, public, deprecated, superseded, withdrawn, retired, archived, security-sensitive, export-control-sensitive, sanctions-sensitive, controlled-technology-sensitive, or legal-hold.

11.18.9(c) Technical asset classification shall determine access, repository placement, license treatment, public release, secure release requirements, dependency review, SBOM requirements, vulnerability review, public-safe review, fork permissions, compatibility claims, and correction path.

11.18.9(d) Open or public release shall not occur unless the asset is rights-reviewed, security-reviewed, public-safe-reviewed, classified, versioned, licensed, and correctionable.

11.18.9(e) The controlling rule shall be that technical assets must be classified before they are shared, released, reused, or relied upon.


11.18.10 Publication Classification. 11.18.10(a) GCRI Canada shall maintain publication classification for reports, public-safe summaries, technical notes, research publications, dashboards, maps, datasets, software releases, API releases, schema releases, Gazette notices, correction notices, supersession notices, withdrawal notices, retraction notices, archive notices, media materials, social media materials, and Academy materials.

11.18.10(b) Publication classification shall identify whether the material is internal draft, internal review, controlled draft, controlled annex, restricted annex, public-safe summary, public report, technical note, research publication, dashboard release, map release, dataset release, software release, API or schema release, Gazette notice, correction notice, supersession notice, withdrawal notice, retraction notice, archive notice, or other approved class.

11.18.10(c) Publication classification shall determine review requirements, release authority, public-safe status, data restrictions, public authority reference controls, finance-safe language, provider and sponsor reference controls, protected knowledge controls, correction path, and notice obligations.

11.18.10(d) A publication class shall not be used to imply greater authority than the record supports. A public report shall not become recognition; a technical note shall not become certification; a dashboard release shall not become public warning; a dataset release shall not authorize unrestricted reuse; a software release shall not create managed service status.

11.18.10(e) The controlling rule shall be that publication class governs both release and reliance.


11.18.11 Handling Class, Access Class, Release Class, and Retention Class. 11.18.11(a) GCRI Canada shall assign handling class, access class, release class, and retention class to material records and assets.

11.18.11(b) Handling class shall determine whether materials may be copied, downloaded, exported, printed, indexed, embedded, used in AI systems, placed in dashboards, mapped, included in public-safe summaries, attached to emails, shared in chat, placed in repositories, or transferred.

11.18.11(c) Access class shall determine who may view, edit, approve, release, correct, export, archive, seal, delete, or otherwise handle the material.

11.18.11(d) Release class shall determine whether the material may be public, public-safe, controlled, restricted, internal, embargoed, delayed, redacted, aggregated, synthetic, no-download, room-only, or withheld.

11.18.11(e) Retention class shall determine retention period, deletion path, sealing path, archive path, legal hold treatment, and destruction or preservation requirements.

11.18.11(f) The controlling rule shall be that classification identifies sensitivity, while handling, access, release, and retention classes govern institutional behavior.


11.18.12 Classification Review, Reclassification, Downgrade, Upgrade, Correction, and Archive. 11.18.12(a) Classifications shall be reviewed, corrected, downgraded, upgraded, reclassified, superseded, withdrawn, sealed, deleted where lawful, or archived where circumstances require.

11.18.12(b) Review shall occur at creation, before publication, before transfer, before AI use, before repository placement, before dashboarding, before mapping, before public authority use, before finance-facing use, before provider or sponsor reference, before Nexus routing, after incidents, after correction requests, and during periodic assurance where material.

11.18.12(c) Downgrade shall occur only where review confirms that a material may safely move to a less restrictive classification. Upgrade shall occur where sensitivity, risk, legal status, public authority status, finance sensitivity, cybersecurity risk, protected knowledge status, community safeguard need, or public-safe risk increases.

11.18.12(d) Misclassification shall be corrected through a correction record identifying affected materials, prior classification, new classification, reason, authority, affected uses, notice audience, dependency implications, and archive relationship.

11.18.12(e) Archived materials shall retain their classification unless reclassified by proper authority. Archive status shall not make restricted materials public.

11.18.12(f) The controlling rule shall be that classification is a lifecycle discipline, not a one-time label.


11.19 Publication Classes

11.19.1 Internal Draft. 11.19.1(a) Internal Draft shall mean a working material prepared for internal development, discussion, drafting, research, design, or preliminary review, and not approved for external circulation, public-safe publication, public authority use, finance-facing use, provider or sponsor reference, or Nexus routing unless separately authorized.

11.19.1(b) Internal Draft materials shall be clearly marked as drafts, versioned where material, classified, access-controlled, and stored in an approved repository or workspace appropriate to their sensitivity.

11.19.1(c) Internal Draft status shall not create institutional position, approval, adoption, public meaning, certification, recognition, finance-readiness, public authority meaning, provider preference, sponsor benefit, protocol effect, public warning, emergency command, operational clearance, infrastructure operation, or execution.

11.19.1(d) The controlling rule shall be that an internal draft is a working record, not an institutional act.


11.19.2 Internal Review. 11.19.2(a) Internal Review shall mean a material under review by authorized internal reviewers for governance, legal, evidence quality, methods, data, AI, cybersecurity, public-safe publication, public authority reference, finance boundary, provider neutrality, sponsor non-control, IP, licensing, safeguards, or technical release purposes.

11.19.2(b) Internal Review materials shall identify review purpose, reviewer class, review status, unresolved issues, required approvals, limitations, and correction path.

11.19.2(c) Internal Review status shall not authorize publication, external reliance, public claims, public authority references, finance-facing use, provider statements, sponsor acknowledgments, or technical release unless review is completed and approval is recorded.

11.19.2(d) The controlling rule shall be that materials under review remain under review until the record says otherwise.


11.19.3 Controlled Draft. 11.19.3(a) Controlled Draft shall mean a draft that may be circulated to a defined external or restricted audience for review, consultation, factual check, public authority review, sponsor factual review, provider factual review, community review, technical review, or other bounded purpose.

11.19.3(b) Controlled Draft materials shall identify permitted audience, purpose, handling class, access limits, onward disclosure limits, review instructions, non-reliance language, public claims prohibition, and correction path.

11.19.3(c) Controlled Draft status shall not permit the recipient to treat the material as adopted, approved, public-safe, certified, recognized, finance-ready, public authority-approved, provider-endorsed, sponsor-validated, protocol-effective, or executable.

11.19.3(d) The controlling rule shall be that controlled circulation is not adoption.


11.19.4 Controlled Annex. 11.19.4(a) Controlled Annex shall mean a non-public or limited-access annex that contains material unsuitable for public release but appropriate for defined controlled audiences under access, confidentiality, handling, and public-safe restrictions.

11.19.4(b) Controlled Annex materials may include detailed evidence, source lineage, technical methods, public authority context, finance-sensitive context, provider details, sponsor details, community safeguards, restricted methodology, or other information requiring controlled access.

11.19.4(c) Controlled Annexes shall identify access audience, handling restrictions, permitted uses, prohibited uses, public-safe summary availability, onward disclosure restrictions, retention, correction path, and archive status.

11.19.4(d) Controlled Annex status shall not authorize public release or public claims based on restricted detail.

11.19.4(e) The controlling rule shall be that controlled annexes support serious review without unsafe public disclosure.


11.19.5 Restricted Annex. 11.19.5(a) Restricted Annex shall mean an annex containing information that requires heightened restriction due to privacy, public authority sensitivity, cybersecurity sensitivity, infrastructure sensitivity, finance sensitivity, commercial sensitivity, community protection, Indigenous or protected knowledge, export controls, sanctions, controlled technology, legal privilege, legal hold, confidential sources, whistleblower protection, or safety.

11.19.5(b) Restricted Annexes shall be limited to authorized persons with a recorded need to know and shall be subject to strict handling, no-download where appropriate, controlled-room or data-room treatment where appropriate, access logging where material, retention controls, and correction path.

11.19.5(c) Restricted Annexes shall not be summarized, cited, copied, exported, embedded, used in AI systems, mapped, dashboarded, or incorporated into public materials unless reviewed and transformed into a public-safe or controlled form.

11.19.5(d) The controlling rule shall be that restricted annexes preserve evidence while preventing exposure.


11.19.6 Public-Safe Summary. 11.19.6(a) Public-Safe Summary shall mean a summary approved for public or broader external communication after review for source lineage, limitations, confidence, uncertainty, privacy, cybersecurity, sovereign data, public authority sensitivity, finance sensitivity, provider neutrality, sponsor non-control, community safeguards, Indigenous and protected knowledge, sensitive locations, IP, licensing, export controls, sanctions, controlled technology, and correction path.

11.19.6(b) Public-Safe Summary shall preserve public understanding without exposing restricted information or implying certification, recognition, finance-readiness, public authority approval, procurement approval, provider endorsement, sponsor validation, protocol effect, public warning, emergency command, operational clearance, infrastructure operation, or execution.

11.19.6(c) Public-Safe Summaries shall identify version, date, scope, limitations, status, correction path, and boundary language where material.

11.19.6(d) The controlling rule shall be that public-safe means safe for public meaning, not merely sanitized for publication.


11.19.7 Public Report. 11.19.7(a) Public Report shall mean a report approved for public release under GCRI Canada’s publication authority, public-safe review, records discipline, source-lineage requirements, and correction path.

11.19.7(b) A Public Report shall identify title, version, date, authority, scope, purpose, source basis at a public-safe level, method basis at a public-safe level, limitations, confidence or uncertainty treatment where applicable, public authority references where approved, sponsor and provider references where approved, and correction path.

11.19.7(c) A Public Report shall not be represented as recognition, certification, finance-readiness, public authority approval, procurement approval, provider endorsement, sponsor validation, protocol effect, public warning, emergency command, operational clearance, infrastructure operation, or execution.

11.19.7(d) The controlling rule shall be that public reporting communicates evidence and methods within bounds; it does not create downstream authority.


11.19.8 Technical Note. 11.19.8(a) Technical Note shall mean a technical publication explaining methods, architectures, baselines, evidence handling, data structures, AI governance, cybersecurity practices, software, APIs, schemas, repositories, dashboards, maps, benchmarks, models, or other technical subjects.

11.19.8(b) Technical Notes shall identify version, scope, assumptions, dependencies, limitations, public-safe status, technical status, review status, and correction path.

11.19.8(c) Technical Notes shall not create certification, conformance, procurement preference, finance-readiness, public authority approval, provider endorsement, protocol effect, operational clearance, infrastructure operation, managed service status, warranty, guarantee, or execution authority by default.

11.19.8(d) The controlling rule shall be that technical explanation is not technical approval unless a competent record says so.


11.19.9 Research Publication. 11.19.9(a) Research Publication shall mean an academic, technical, public-benefit, peer-reviewed, preprint, working paper, research report, field note, evaluation, benchmark analysis, or other research output associated with GCRI Canada.

11.19.9(b) Research Publications shall identify authorship, contributor roles, funding, sponsor roles, provider roles, public authority roles, conflicts, methods, data limits, ethics status where applicable, AI use where material, limitations, public-safe restrictions, and correction path.

11.19.9(c) Research Publications shall not convert GCRI Canada into a university, certifier, provider test lab, regulator, finance actor, public authority, public warning authority, or execution actor.

11.19.9(d) The controlling rule shall be that research publication must preserve uncertainty, limitations, conflicts, and correctionability.


11.19.10 Dashboard Release. 11.19.10(a) Dashboard Release shall mean the release of an interactive or static dashboard, evidence display, Observatory display, Truth Engine display, public-safe visualization, technical asset display, or related interface.

11.19.10(b) Dashboard Releases shall identify source basis, data classes, update status, timestamp, version, confidence, uncertainty, limitations, public-safe transformations, access class, public authority boundaries, public warning boundaries, finance boundaries, provider and sponsor boundaries, and correction path.

11.19.10(c) Dashboard Releases shall not create public warning, emergency command, public authority action, operational control, procurement approval, finance-readiness, provider endorsement, sponsor validation, certification, recognition, protocol effect, infrastructure operation, or execution.

11.19.10(d) The controlling rule shall be that dashboard display is evidence display, not command.


11.19.11 Map Release. 11.19.11(a) Map Release shall mean release of a map, geospatial layer, GIS product, Earth observation output, sensor map, risk map, public-safe map, digital twin spatial display, or location-based visualization.

11.19.11(b) Map Releases shall identify source layers, resolution, date, update frequency, public-safe transformation, omitted layers, sensitive-location controls, public authority restrictions, community safeguards, protected knowledge controls, limitations, confidence, uncertainty, and correction path.

11.19.11(c) Map Releases shall not expose protected persons, sensitive locations, infrastructure vulnerabilities, community-protected information, Indigenous or protected knowledge, or public authority restricted information.

11.19.11(d) Map Releases shall not constitute public warning, evacuation instruction, public authority action, emergency command, operational control, procurement approval, finance-readiness, provider endorsement, certification, recognition, protocol effect, or execution.

11.19.11(e) The controlling rule shall be that maps must be public-safe because accuracy can expose harm.


11.19.12 Dataset Release. 11.19.12(a) Dataset Release shall mean release of a dataset, derived dataset, synthetic dataset, aggregated dataset, benchmark dataset, evaluation set, calibration set, validation set, or data extract.

11.19.12(b) Dataset Releases shall require data classification, rights review, privacy review, re-identification review, public authority review where applicable, community safeguard review, protected knowledge review, cybersecurity review, IP and licensing review, AI-use review, public-safe review, and correction path.

11.19.12(c) Dataset Releases shall identify dataset card, source lineage at an appropriate level, version, license, permitted uses, prohibited uses, limitations, bias risks, re-identification risks, public-safe status, and withdrawal path.

11.19.12(d) Dataset Release shall not authorize unrestricted reuse unless the license and public-safe status expressly permit it.

11.19.12(e) The controlling rule shall be that data release must be governed before it is open.


11.19.13 Software Release. 11.19.13(a) Software Release shall mean release of public-good software, code, scripts, tools, packages, containers, reference implementations, templates, test harnesses, evaluation harnesses, or related technical artifacts.

11.19.13(b) Software Releases shall identify repository, version, license, maintainer, contributors, IP status, dependency review, SBOM status where applicable, security review, secrets review, public-safe review, release notes, known issues, rollback path, vulnerability disclosure path, correction path, and archive status.

11.19.13(c) Software Release shall not create vendor status, managed service status, warranty, guarantee, security certification, procurement approval, finance-readiness, public authority approval, provider endorsement, protocol effect, infrastructure operation, or execution authority by default.

11.19.13(d) The controlling rule shall be that public-good software release provides tools, not institutional approval of downstream use.


11.19.14 API / Schema Release. 11.19.14(a) API / Schema Release shall mean release of APIs, schemas, data dictionaries, data contracts, interface specifications, interoperability profiles, or related technical interface assets.

11.19.14(b) API / Schema Releases shall identify version, scope, access controls, authentication requirements where applicable, rate limits where applicable, compatibility status, breaking changes, deprecation rules, data classification implications, security review, public-safe review, permitted uses, prohibited uses, and correction path.

11.19.14(c) API / Schema Release shall not create public authority meaning, certification, procurement preference, finance-readiness, provider preference, protocol effect, entitlement state, operational clearance, infrastructure operation, or execution by default.

11.19.14(d) The controlling rule shall be that interfaces enable interoperability, not authority migration.


11.19.15 Gazette Notice. 11.19.15(a) Gazette Notice shall mean an authoritative notice issued through the GCRI Canada Gazette or other authoritative notice stream under proper publication authority.

11.19.15(b) Gazette Notices shall identify notice type, authority, date, effective status, scope, affected records, affected versions, public-safe status, handling class, correction path, and archive status.

11.19.15(c) Gazette Notice shall not create legal effect beyond the stated scope and underlying authority.

11.19.15(d) The controlling rule shall be that Gazette notice communicates status; it does not enlarge status.


11.19.16 Correction Notice. 11.19.16(a) Correction Notice shall mean a notice that corrects error, omission, misclassification, overclaim, boundary defect, public authority misdescription, finance overclaim, provider overclaim, sponsor overclaim, technical defect, public-safe defect, or other record defect.

11.19.16(b) Correction Notices may be public-safe, controlled, restricted, internal, or sealed according to the affected material and risk.

11.19.16(c) Correction Notices shall identify affected material, affected version, correction action, corrected version where any, effective date, continuing validity where any, notice audience, and correction path.

11.19.16(d) The controlling rule shall be that correction notice repairs reliance.


11.19.17 Supersession Notice. 11.19.17(a) Supersession Notice shall mean a notice that one material, version, record, term, method, baseline, release, publication, dashboard, map, dataset, or public claim has been replaced by another.

11.19.17(b) Supersession Notices shall identify predecessor, successor, reason, effective date, continuing validity where any, affected dependencies, transition notes, and correction path.

11.19.17(c) Supersession shall not conceal error requiring correction or retraction.

11.19.17(d) The controlling rule shall be that supersession must show what replaces what and what remains valid.


11.19.18 Withdrawal Notice. 11.19.18(a) Withdrawal Notice shall mean a notice that material is removed from current reliance, use, circulation, or publication.

11.19.18(b) Withdrawal Notices shall identify affected material, version, reason at the appropriate handling class, effective date, continuing restrictions, successor material where any, reliance implications, and correction path.

11.19.18(c) Withdrawal may be required for public-safe defects, misclassification, authority defects, rights issues, public authority confusion, finance overclaim, provider or sponsor overclaim, security concerns, protected knowledge risk, or technical defect.

11.19.18(d) The controlling rule shall be that withdrawn material shall not continue to function as current authority.


11.19.19 Retraction Notice. 11.19.19(a) Retraction Notice shall mean a notice that material should not be relied upon because of material defect, unsafe disclosure, unsupported claim, misrepresentation, rights violation, authority defect, or other serious issue.

11.19.19(b) Retraction Notices shall identify affected material, version, retraction scope, reason at a public-safe or controlled level, effective date, correction or replacement where any, reliance implications, and archive status.

11.19.19(c) Retraction shall be used where correction or supersession is insufficient to repair reliance.

11.19.19(d) The controlling rule shall be that retraction protects trust by clearly removing defective material from reliance.


11.19.20 Archive Notice. 11.19.20(a) Archive Notice shall mean a notice that material has been moved to archive status and is preserved for historical, audit, legal, institutional memory, or correction purposes.

11.19.20(b) Archive Notices shall identify archived material, version, archive date, archive reason, current validity status, access class, retention class, legal hold status where applicable, and correction path where applicable.

11.19.20(c) Archive status shall not make material current, approved for reliance, public, open, or unrestricted.

11.19.20(d) The controlling rule shall be that archives preserve memory without preserving current authority.


11.20 Access Classes and Handling Classes

11.20.1 Public. 11.20.1(a) Public shall mean material approved for general public access without restriction other than applicable law, license terms, attribution requirements, public claims limits, correction notices, and boundary language.

11.20.1(b) Public materials shall be reviewed for public-safe release, data protection, cybersecurity, public authority references, finance-safe language, provider and sponsor references, protected knowledge, IP, licensing, export controls, sanctions, controlled technology, and correction path before release.

11.20.1(c) Public access shall not mean unrestricted reuse unless the applicable license permits it.

11.20.1(d) The controlling rule shall be that public materials may be widely accessible, but they remain bounded by their record, version, license, and correction path.


11.20.2 Public-Safe. 11.20.2(a) Public-Safe shall mean material approved for external communication because it has been reviewed and transformed to avoid unsafe disclosure, public authority confusion, finance overclaim, provider preference, sponsor validation, protected knowledge exposure, privacy harm, cybersecurity harm, infrastructure harm, or execution implication.

11.20.2(b) Public-Safe materials may be public or controlled depending on audience and handling class.

11.20.2(c) Public-Safe status shall require source lineage, limitations, boundary language, version status, and correction path where material.

11.20.2(d) The controlling rule shall be that public-safe is a safety and meaning classification, not merely a publicity label.


11.20.3 Internal. 11.20.3(a) Internal shall mean material available only to authorized GCRI Canada personnel, governance actors, or approved participants for internal institutional purposes.

11.20.3(b) Internal materials may not be externally circulated, quoted, published, relied upon by external actors, placed in public repositories, used in public claims, or provided to sponsors, providers, public authorities, capital readers, media, or Nexus actors unless reclassified or authorized.

11.20.3(c) Internal materials shall still be subject to classification, access controls, retention, legal hold, and correction.

11.20.3(d) The controlling rule shall be that internal does not mean informal or uncontrolled.


11.20.4 Confidential. 11.20.4(a) Confidential shall mean material requiring protection from unauthorized disclosure because of governance sensitivity, contractual duty, personal information, commercial sensitivity, research sensitivity, public authority sensitivity, sponsor or provider sensitivity, community context, security concern, or institutional risk.

11.20.4(b) Confidential materials shall be accessed only by authorized persons for recorded purposes and shall be subject to confidentiality obligations, handling restrictions, access review, and correction path.

11.20.4(c) Confidential materials shall not be placed in public repositories, public chat, public datasets, AI tools, public dashboards, public maps, media materials, or public-safe summaries unless reviewed and transformed for safe release.

11.20.4(d) The controlling rule shall be that confidential materials require controlled trust, not casual circulation.


11.20.5 Restricted. 11.20.5(a) Restricted shall mean material requiring heightened access limitation because unauthorized disclosure, misuse, or misinterpretation could create legal, safety, cybersecurity, public authority, finance, community, protected knowledge, privacy, commercial, or institutional harm.

11.20.5(b) Restricted materials may include public authority restricted data, health-sensitive data, cyber-sensitive information, infrastructure-sensitive information, finance-sensitive information, commercially sensitive information, personal information, community-protected information, Indigenous or protected knowledge, legal privileged material, controlled technology, export-control-sensitive material, sanctions-sensitive material, credentials, keys, tokens, secrets, incident information, and confidential source information.

11.20.5(c) Restricted materials shall be handled under strict access controls, least privilege, logging where material, no-download restrictions where appropriate, controlled-room or data-room treatment where appropriate, retention limits, and correction path.

11.20.5(d) The controlling rule shall be that restricted material shall not travel beyond the audience and purpose approved for it.


11.20.6 Controlled Room. 11.20.6(a) Controlled Room shall mean a controlled access environment for review of sensitive records, evidence, technical materials, public authority materials, finance-facing materials, provider materials, sponsor materials, community materials, or protected knowledge under defined access, confidentiality, logging, handling, and onward-use restrictions.

11.20.6(b) Controlled Rooms may be physical, digital, hybrid, or procedural, and shall identify participant roles, permitted materials, prohibited materials, access duration, download rules, copy rules, AI-use restrictions, screenshot restrictions where applicable, notes rules, public claims restrictions, and closeout.

11.20.6(c) Controlled Room participation shall not create approval, recognition, finance-readiness, certification, public authority meaning, provider preference, sponsor benefit, protocol effect, or execution.

11.20.6(d) The controlling rule shall be that controlled rooms permit bounded review, not status creation.


11.20.7 Clean Room. 11.20.7(a) Clean Room shall mean a controlled environment designed to permit analysis, comparison, computation, review, or interoperability without exposing underlying restricted data, protected knowledge, proprietary information, public authority information, personal data, or sensitive materials beyond approved limits.

11.20.7(b) Clean Rooms shall include purpose limitation, access control, output review, no-export rules where appropriate, compute-to-data controls where appropriate, logging where material, AI-use limits, and correction path.

11.20.7(c) Clean Room outputs shall be classified and reviewed before release or reuse, and shall not be assumed public-safe merely because the process was controlled.

11.20.7(d) The controlling rule shall be that clean rooms reduce exposure but do not eliminate review.


11.20.8 Data Room. 11.20.8(a) Data Room shall mean a controlled environment for access to data, evidence, documentation, proof inputs, diligence materials, public authority materials, or finance-sensitive materials by authorized persons under defined rules.

11.20.8(b) Data Room access shall identify participant role, purpose, materials, classification, download restrictions, onward disclosure limits, AI-use restrictions, retention, audit logs where material, public claims limits, and closeout.

11.20.8(c) Data Room access shall not create finance-readiness, investment advice, public finance approval, certification, recognition, public authority approval, procurement approval, provider endorsement, sponsor validation, or execution.

11.20.8(d) The controlling rule shall be that reading in a data room is access to evidence, not approval of what the reader may later do.


11.20.9 Evidence Room. 11.20.9(a) Evidence Room shall mean a controlled environment for review, challenge, comparison, verification within record, evidence pack assembly, evidence quality review, source-lineage review, or correction of evidence.

11.20.9(b) Evidence Rooms shall identify evidence classes, source materials, participants, review scope, permitted use, prohibited use, public-safe status, notes rules, extraction rules, and correction path.