XXII. DISSOLUTION
22.1 Dissolution and Wind-Up Purpose
22.1.1 Dissolution and Wind-Up as Public-Benefit Closeout Discipline. 22.1.1(a) Dissolution and wind-up of GCRI Canada shall be treated as a public-benefit closeout discipline and not merely as administrative termination, inactivity, abandonment, or corporate deregistration.
22.1.1(b) Dissolution and wind-up shall preserve, to the maximum lawful extent, GCRI Canada’s public-benefit purpose, nonprofit and non-distributing character, mission lock, non-execution posture, legal separateness, Public-Good Stack role separation, validity-by-record, correctionability, public-safe publication discipline, data rights, cybersecurity, protected knowledge safeguards, anti-inurement, anti-enclosure, and public trust.
22.1.1(c) The purpose of dissolution and wind-up shall be to close GCRI Canada lawfully, responsibly, transparently where public-safe, and records-validly while protecting affected persons, communities, Public Authorities, donors, grantors, sponsors, providers, hosts, universities, partners, Nexus interfaces, public-good assets, records, data, technical assets, and public meaning.
22.1.1(d) No dissolution, wind-up, dormancy, loss of funding, loss of personnel, program termination, technical discontinuation, or operational interruption shall be used to avoid duties of record preservation, correction, public-safe notice, data disposition, grant closeout, donor restriction compliance, contract closeout, protected knowledge protection, or technical asset stewardship.
22.1.1(e) The controlling rule shall be that the final act of a public-benefit institution must itself be public-benefit disciplined.
22.1.2 Dissolution and Wind-Up as Legal, Fiduciary, Technical, Data, Records, Public Authority, Safeguards, Fiscal, Contractual, and Public Trust Process. 22.1.2(a) Dissolution and wind-up shall be conducted as a legal, fiduciary, technical, data, records, Public Authority, safeguards, fiscal, contractual, employment, participant, communications, and public trust process.
22.1.2(b) Legal and fiduciary closeout shall address applicable Canadian federal, provincial, territorial, nonprofit, corporate, tax, employment, privacy, data protection, AI, cybersecurity, sanctions, export-control, competition, contract, intellectual property, research ethics, public authority, professional-boundary, and filing requirements.
22.1.2(c) Technical and records closeout shall address repositories, public-good software, Open Technical Baselines, ontology, controlled vocabulary, dashboards, maps, datasets, APIs, schemas, models, compute records, evidence records, method records, publication records, Gazette notices where applicable, controlled annexes, and authoritative archives.
22.1.2(d) Public Authority and safeguards closeout shall address Public Authority Data, Public Authority references, public authority learning materials, public warning boundaries, emergency command boundaries, community-protected data, Indigenous Knowledge, Local Knowledge, Territorial Knowledge, Cultural Knowledge, Environmental Knowledge, Protected Knowledge, vulnerable persons, protected persons, and public-safe mapping.
22.1.2(e) Fiscal and contractual closeout shall address assets, liabilities, restricted funds, grants, donations, sponsorships, in-kind contributions, contracts, procurement, related-party matters, insurance, indemnities, warranties, service commitments, vendor obligations, and outstanding disputes.
22.1.2(f) The controlling rule shall be that dissolution and wind-up must close every material trust-bearing surface, not only the corporate shell.
22.1.3 Dissolution and Wind-Up as Protection Against Asset Capture, Public-Good Loss, Data Misuse, Protected Knowledge Exposure, Record Destruction, Technical Asset Enclosure, Sponsor Control, Provider Capture, and Misleading Public Claims. 22.1.3(a) Dissolution and wind-up shall protect against asset capture, public-good loss, data misuse, protected knowledge exposure, record destruction, technical asset enclosure, sponsor control, provider capture, private inurement, public authority confusion, finance overclaim, and misleading public claims.
22.1.3(b) No dissolution or wind-up process shall permit sponsors, donors, funders, providers, hosts, vendors, Directors, Officers, members where applicable, contractors, related parties, National Companies, Project SPVs, capital actors, or private persons to capture assets, records, data, technical assets, public-good software, methods, ontology, controlled vocabulary, public authority access, or public trust contrary to law, restrictions, mission, or safeguards.
22.1.3(c) Public-good assets shall be reviewed for continuity, lawful transfer, public-good preservation, open release where appropriate, controlled release where required, archive, retirement, deprecation, security treatment, and anti-enclosure protections.
22.1.3(d) Public materials shall be reviewed so dissolution does not leave stale claims, misleading websites, outdated dashboards, active public authority references, unsupported finance-facing claims, sponsor or provider overclaims, uncorrected technical statements, or uncontrolled Nexus-compatible claims in circulation.
22.1.3(e) The controlling rule shall be that wind-up shall prevent the collapse of governance from becoming an opportunity for capture, misuse, or public misdescription.
22.1.4 Dissolution and Wind-Up as Distinct From Program Suspension, Program Closeout, Project Closeout, Technical Asset Retirement, or Temporary Inactivity. 22.1.4(a) Dissolution and wind-up shall be distinct from program suspension, program closeout, project closeout, technical asset retirement, repository archive, public material withdrawal, temporary inactivity, fiscal pause, staff transition, operational restructuring, or dormancy.
22.1.4(b) Program suspension or closeout shall terminate or pause a specific program but shall not dissolve GCRI Canada unless proper dissolution authority is invoked.
22.1.4(c) Technical asset retirement shall deprecate, archive, transfer, withdraw, or discontinue a technical asset but shall not dissolve GCRI Canada unless part of an authorized dissolution plan.
22.1.4(d) Temporary inactivity, lack of funding, lack of active projects, absence of staff, paused programs, or inactive public communications shall not constitute dissolution and shall not excuse governance, records, data, public claims, public authority, fiscal, contract, cybersecurity, or safeguards obligations.
22.1.4(e) The controlling rule shall be that institutional dissolution requires lawful dissolution authority, while lesser closeout states require their own appropriate records and controls.
22.1.5 Dissolution and Wind-Up as Subject to Applicable Canadian Law, Articles, Bylaw, Board Approval, Member Approval Where Applicable, Tax Status, Donor Restrictions, Grant Conditions, Contracts, Privacy Law, Public Authority Terms, and Protected Knowledge Protocols. 22.1.5(a) Dissolution and wind-up shall be subject to applicable Canadian law, governing instruments, Articles, Bylaw, Board approval, member approval where applicable, required filings, tax status, nonprofit requirements, charitable-status requirements where applicable, donor restrictions, grant conditions, sponsorship terms, contracts, employment obligations, privacy law, data protection law, Public Authority terms, research ethics obligations, IP obligations, sanctions, export controls, and protected knowledge protocols.
22.1.5(b) Where legally controlling requirements conflict with ordinary Charter wind-up preferences, GCRI Canada shall comply with legally controlling requirements while preserving public-benefit safeguards to the maximum lawful extent.
22.1.5(c) Restricted funds, donor-restricted assets, grant-funded assets, public authority-funded materials, contract-specific assets, research assets, data assets, technical assets, and community-protected materials shall be dispositioned according to the applicable restriction, law, agreement, protocol, or court or regulator direction where required.
22.1.5(d) Legal review shall be required before material dissolution action, asset disposition, restricted fund disposition, data transfer, protected knowledge disposition, technical asset transfer, public authority material transfer, public-safe notice, or final filing where risk exists.
22.1.5(e) The controlling rule shall be that dissolution cannot free GCRI Canada from legal, fiduciary, restricted-purpose, data, Public Authority, or protected knowledge obligations.
22.1.6 Dissolution and Wind-Up as Requiring Public-Safe Communication Where Public Materials, Public Reliance, Public Authority References, Nexus Interfaces, or Public-Good Assets Are Affected. 22.1.6(a) Dissolution and wind-up shall require public-safe communication where public materials, public reliance, Public Authority references, Nexus interfaces, public-good assets, public-safe reports, dashboards, maps, datasets, technical releases, public authority learning materials, sponsor materials, provider materials, media materials, websites, or public claims are affected.
22.1.6(b) Public-safe communication shall identify the status of GCRI Canada, affected materials, affected programs, effective dates, replacement or archive status, correction path, public reliance limitations, and boundary language without disclosing confidential, personal, Public Authority, cyber-sensitive, infrastructure-sensitive, finance-sensitive, commercially sensitive, community-protected, Indigenous, Local, Territorial, Cultural, Environmental, or Protected Knowledge materials.
22.1.6(c) Public-safe communication shall avoid implying that dissolution creates public authority approval, finance-readiness, certification, recognition, provider preference, sponsor validation, protocol effect, public warning, emergency command, or execution consequence.
22.1.6(d) Controlled notices shall be used where affected persons, Public Authorities, communities, sponsors, providers, hosts, universities, GRF, GRA, Protocol Authority, Nexus entities, National Companies, Project SPVs, or capital readers require notice but public notice would be unsafe, unlawful, misleading, or over-disclosing.
22.1.6(e) The controlling rule shall be that dissolution must correct public meaning safely before public materials become orphaned.
22.1.7 Dissolution and Wind-Up as Requiring Records-Valid Transition, Correction, Supersession, Withdrawal, Archive, and Final Closeout. 22.1.7(a) Dissolution and wind-up shall require records-valid transition, correction, supersession, withdrawal, archive, legal hold, sealing, deletion where lawful and required, and final closeout.
22.1.7(b) Transition records shall identify authority, plan, owners, custodians, affected assets, affected records, affected data, affected technical assets, affected public materials, affected Public Authorities, affected communities, affected sponsors, affected providers, affected contracts, affected Nexus interfaces, interim controls, notices, corrective actions, and final disposition.
22.1.7(c) Supersession shall identify which instruments, policies, procedures, public materials, technical assets, dashboards, maps, datasets, websites, claims, and interface records are replaced, terminated, transferred, archived, or retired.
22.1.7(d) Correction, withdrawal, and retraction shall be used where dissolution reveals inaccurate, unsupported, misleading, unsafe, unauthorized, or stale materials.
22.1.7(e) Final closeout shall not occur until required filings, asset dispositions, debt and liability closeout, data disposition, records archive, technical asset disposition, public materials closeout, notices, correction actions, and final assurance have been completed or lawfully assigned.
22.1.7(f) The controlling rule shall be that dissolution is complete only when the record proves responsible closeout.
22.1.8 Dissolution and Wind-Up as Requiring Coordination With GCRI US, GRF, GRA, Nexus Standards / Protocol Authority, Nexus Entities, Public Authorities, Donors, Grantors, Sponsors, Providers, Hosts, Universities, Communities, and Partners Where Applicable. 22.1.8(a) Dissolution and wind-up shall require coordination with GCRI US, The Global Risks Forum (GRF), The Global Risks Alliance (GRA), Nexus Standards / Protocol Authority, Nexus Network, Nexus Universe, Nexus Observatory, Nexus Truth Engine, Nexus Risk Management, Nexus Rails, Nexus Grid, Nexus Academy, Regional Nexus Consortiums, National Nexus Consortiums, Public Authorities, donors, grantors, sponsors, providers, hosts, universities, communities, partners, National Companies, Project SPVs, capital readers, and other affected actors where applicable.
22.1.8(b) Coordination shall preserve legal separateness, role separation, data controls, Public Authority boundaries, finance boundaries, sponsor non-control, provider neutrality, protected knowledge safeguards, shared records without shared liability, correction signals, and closeout.
22.1.8(c) Coordination shall not create merger, agency, partnership, joint venture, shared treasury, shared employer status, shared liability, public authority delegation, finance-readiness authority, recognition authority, certification authority, protocol authority, procurement authority, provider preference, sponsor control, or execution authority.
22.1.8(d) Interface closeout shall identify records to transfer, records to retain, records to destroy where lawful, data to return, data to delete, assets to transfer, public claims to correct, shared materials to archive, notices to issue, and continuing obligations.
22.1.8(e) The controlling rule shall be that dissolution may require coordination, but coordination shall not collapse separateness.
22.1.9 Dissolution and Wind-Up as Preserving Public-Good Stack Role Separation and Legal Separateness During Transition. 22.1.9(a) Dissolution and wind-up shall preserve Public-Good Stack role separation and legal separateness during transition.
22.1.9(b) GCRI Canada shall not use wind-up to transfer its public-benefit evidence, methods, observability, ontology, public-good software, Open Technical Baseline, public authority learning, data stewardship, correction, or public-safe publication functions into an enterprise, sponsor-controlled, provider-controlled, finance-execution, public authority-confusing, or private-benefit structure without lawful authority, mission compatibility, conflict review, safeguards, and Board approval where applicable.
22.1.9(c) Transfers to GRF, GRA, Protocol Authority, Nexus entities, public-good recipients, universities, Public Authorities, archives, or other mission-compatible custodians shall preserve the distinct role of each recipient and shall not imply that GCRI Canada’s dissolution transfers powers that GCRI Canada itself did not hold.
22.1.9(d) Public materials shall clarify that asset transfer, record transfer, continuity arrangement, repository transfer, or technical asset stewardship does not create public authority delegation, finance-readiness, certification, recognition, procurement approval, provider preference, sponsor validation, or execution authority by implication.
22.1.9(e) The controlling rule shall be that wind-up may transfer assets or custody, but shall not transfer invented authority.
22.1.10 Dissolution and Wind-Up Records as Final Constitutional Records. 22.1.10(a) Dissolution and wind-up records shall be treated as final constitutional records of GCRI Canada.
22.1.10(b) Such records shall include dissolution authority records, Board records, member approval records where applicable, legal review records, dissolution plan, wind-up plan, asset disposition records, restricted fund records, grant closeout records, donor records, contract closeout records, employment closeout records, data disposition records, Public Authority Data disposition records, protected knowledge disposition records, technical asset records, repository records, IP records, public materials closeout records, notice records, final fiscal records, final tax records, archive records, legal hold records, and final assurance records.
22.1.10(c) Final constitutional records shall be retained permanently or for the legally required and mission-appropriate period where lawful.
22.1.10(d) Access to final constitutional records shall be governed by classification, legal requirements, privacy, cybersecurity, Public Authority sensitivity, finance sensitivity, protected knowledge, legal privilege, archive rules, and public-safe publication discipline.
22.1.10(e) The controlling rule shall be that the final evidence of institutional integrity is the record of how the institution closed.
22.2 Dissolution Authority
22.2.1 Dissolution Shall Require Authority Under Applicable Law, Articles, Bylaw, Board Procedure, Member Rights Where Applicable, and Required Filings. 22.2.1(a) Dissolution of GCRI Canada shall require authority under applicable law, Articles or equivalent governing instruments, the GCRI Canada Bylaw, Board procedure, member rights where applicable, required approvals, required notices, required filings, and any court, regulator, or governmental requirements applicable to the legal form of GCRI Canada.
22.2.1(b) No officer, Director, member where applicable, founder, sponsor, donor, funder, provider, host, Public Authority, partner, committee, council, Working Group, Nexus actor, National Company, Project SPV, or external participant may dissolve GCRI Canada by statement, announcement, inactivity, funding withdrawal, public materials change, operational discontinuation, repository closure, or informal agreement.
22.2.1(c) Dissolution authority shall be identified before any material dissolution communication, asset disposition, data disposition, technical asset transfer, public materials withdrawal, public notice, filing, or final closeout action.
22.2.1(d) Where dissolution authority is uncertain, GCRI Canada shall obtain legal review, preserve records, maintain interim controls, avoid misleading public statements, and refrain from irreversible disposition except as required by law or necessary to prevent harm.
22.2.1(e) The controlling rule shall be that dissolution requires formal legal authority and cannot occur by drift.
22.2.2 Board Review Required Before Dissolution. 22.2.2(a) Board review shall be required before voluntary dissolution or material wind-up action unless a court, regulator, or applicable law requires otherwise.
22.2.2(b) Board review shall consider legal basis, public-benefit rationale, alternatives to dissolution, mission continuity options, fiscal condition, liabilities, restricted funds, grants, donor restrictions, sponsorship obligations, contracts, employment obligations, data obligations, Public Authority obligations, protected knowledge obligations, technical asset continuity, Nexus interface consequences, public materials consequences, public trust consequences, and final assurance needs.
22.2.2(c) The Board shall consider whether program suspension, restructuring, merger where lawful, asset transfer, fiscal sponsorship where lawful, program transfer, technical asset stewardship transfer, or dormancy would better preserve public-benefit purpose than dissolution.
22.2.2(d) Board review shall be recorded with conflicts, recusals, materials reviewed, legal advice where applicable, decision, conditions, responsible officers, plan approval, and required follow-up.
22.2.2(e) The controlling rule shall be that dissolution is a Board-level constitutional decision unless law provides otherwise.
22.2.3 Member Approval Required Where Applicable. 22.2.3(a) Member approval shall be obtained where required by applicable law, governing instruments, Articles, Bylaw, or member rights.
22.2.3(b) Member approval materials shall identify the dissolution proposal, legal authority, Board recommendation, rationale, effective date, wind-up plan summary, asset disposition summary, public-benefit preservation approach, restricted fund treatment, data disposition approach, technical asset approach, public materials approach, and public-safe communication plan.
22.2.3(c) Member approval shall not be solicited through misleading, incomplete, unsupported, or overbroad materials.
22.2.3(d) Member approval, where required, shall be recorded with notice, quorum, voting, approvals, objections, conditions, and filings.
22.2.3(e) The controlling rule shall be that member rights in dissolution shall be honored where law or governing instruments require them.
22.2.4 Legal Review Required Before Dissolution. 22.2.4(a) Legal review shall be required before voluntary dissolution and before material wind-up actions where legal risk exists.
22.2.4(b) Legal review shall address corporate authority, nonprofit requirements, tax status, charitable-status compatibility where applicable, filings, creditor rights, restricted funds, donor restrictions, grant obligations, sponsorship obligations, contracts, employment obligations, privacy, data protection, Public Authority Data, protected knowledge, IP, software licenses, repository transfers, sanctions, export controls, competition law, litigation, insurance, indemnities, leases, vendors, public communications, and Nexus interface obligations.
22.2.4(c) Legal review shall identify required approvals, required filings, required notices, prohibited dispositions, creditor procedures, asset distribution restrictions, data transfer restrictions, public materials risks, and final record requirements.
22.2.4(d) Legal review shall be updated where the wind-up plan materially changes, new liabilities are discovered, restricted assets are identified, data or protected knowledge issues arise, public authority terms are implicated, or cross-border transfers are proposed.
22.2.4(e) The controlling rule shall be that dissolution shall not proceed on assumed legal authority.
22.2.5 Tax, Nonprofit, Charitable-Status, Restricted Fund, Donor, Grantor, Public Authority, Data, IP, Contract, Employment, and Nexus Interface Review Required Where Applicable. 22.2.5(a) GCRI Canada shall conduct tax, nonprofit, charitable-status where applicable, restricted fund, donor, grantor, Public Authority, data, IP, contract, employment, and Nexus interface review where applicable before dissolution or material wind-up action.
22.2.5(b) Tax and nonprofit review shall address non-distribution, anti-inurement, private benefit, asset distribution, filings, receipting where applicable, restricted assets, related-party issues, and final financial reporting.
22.2.5(c) Donor, grantor, and restricted fund review shall address purpose restrictions, return obligations, transfer permissions, reporting obligations, fund balances, asset purchase restrictions, and final grant reports.
22.2.5(d) Public Authority review shall address Public Authority Data, reference approvals, public authority learning materials, dashboards, maps, controlled rooms, contract terms, confidentiality, public-safe notices, and official status corrections.
22.2.5(e) Data, IP, contract, employment, and Nexus interface review shall address data rights, privacy, protected knowledge, repository ownership, software licenses, technical baselines, assignment rights, termination provisions, contractor obligations, employee obligations, shared records, correction signals, and closeout.
22.2.5(f) The controlling rule shall be that every restricted or reliance-bearing relationship must be reviewed before final dissolution action.
22.2.6 Dissolution Resolution Shall Identify Authority, Rationale, Effective Date, Wind-Up Plan, Asset Disposition Plan, Data Disposition Plan, Records Plan, Technical Asset Plan, Public Communications Plan, and Responsible Officers. 22.2.6(a) Any dissolution resolution shall identify authority, rationale, effective date, wind-up plan, asset disposition plan, data disposition plan, records plan, technical asset plan, public communications plan, responsible officers, delegated authority, reporting obligations, required filings, required approvals, and final closeout criteria.
22.2.6(b) The resolution shall identify whether dissolution is voluntary, involuntary, court-ordered, regulator-directed, merger-related where lawful, restructuring-related, or otherwise legally required.
22.2.6(c) The resolution shall identify restrictions on asset transfer, data transfer, public communications, public claims, sponsor communications, provider communications, Public Authority references, finance-sensitive communications, technical release changes, and Nexus interface communications.
22.2.6(d) The resolution shall require preservation of records, correctionability, public-safe communication, legal hold where applicable, controlled notices where required, and final assurance.
22.2.6(e) The controlling rule shall be that the dissolution resolution must authorize not only the decision to dissolve, but the disciplined way dissolution will occur.
22.2.7 Emergency Dissolution or Court-Ordered Dissolution Shall Be Managed Consistent With Law and Public-Good Safeguards to the Maximum Lawful Extent. 22.2.7(a) Emergency dissolution, involuntary dissolution, administrative dissolution, court-ordered dissolution, regulator-directed dissolution, insolvency process, receivership, trusteeship, liquidation, or other legally compelled wind-up shall be managed consistent with applicable law and public-good safeguards to the maximum lawful extent.
22.2.7(b) Where ordinary Board process is unavailable or legally displaced, the lawful wind-up authority shall be identified and records shall be preserved.
22.2.7(c) GCRI Canada shall, to the maximum lawful extent, preserve data rights, cybersecurity, Public Authority obligations, protected knowledge, restricted fund obligations, public-safe communication, technical asset continuity, public materials correction, and Nexus interface closeout.
22.2.7(d) Emergency constraints shall not justify unnecessary disclosure, data misuse, protected knowledge exposure, asset capture, sponsor control, provider capture, or misleading public claims.
22.2.7(e) The controlling rule shall be that even compelled dissolution shall preserve public-good safeguards wherever law permits.
22.2.8 No Informal Dissolution, Abandonment, Dormancy, or Operational Failure Shall Excuse Records, Data, Technical Asset, Public Authority, Grant, Donor, Contract, and Public Claims Closeout Duties. 22.2.8(a) Informal dissolution, abandonment, dormancy, inactivity, loss of staff, loss of funding, website inactivity, repository inactivity, failure to file, program cessation, or operational failure shall not excuse records, data, technical asset, Public Authority, grant, donor, contract, employment, protected knowledge, public materials, public claims, and Nexus interface closeout duties.
22.2.8(b) If GCRI Canada becomes inactive without formal dissolution, the Board or lawful authority shall determine whether to revive, restructure, maintain dormancy controls, close programs, transfer assets where lawful, or initiate dissolution.
22.2.8(c) Dormancy controls shall preserve records, registered office or contact arrangements where required, access to critical systems, cybersecurity, data rights, legal holds, restricted funds, public claims correction, and public-safe notices.
22.2.8(d) Operational failure creating risk to data, records, public materials, repositories, Public Authority materials, protected knowledge, or public trust shall be treated as an incident requiring triage and correction.
22.2.8(e) The controlling rule shall be that institutional duties do not disappear because institutional activity becomes quiet.
22.2.9 Dissolution Authority Records Shall Be Preserved Permanently Where Lawful. 22.2.9(a) Dissolution authority records shall be preserved permanently where lawful.
22.2.9(b) Such records shall include Board resolutions, member approvals where applicable, legal review records, filings, court orders where applicable, regulator correspondence, tax correspondence, dissolution plan approvals, wind-up authority delegations, responsible officer records, asset disposition approvals, data disposition approvals, technical asset disposition approvals, public communication approvals, and final closeout approvals.
22.2.9(c) Records shall be classified, access-controlled, archived, and protected against unauthorized deletion, alteration, or destruction.
22.2.9(d) Public-safe summaries may be preserved or published where appropriate to maintain public trust and correct public reliance.
22.2.9(e) The controlling rule shall be that dissolution authority must remain provable after the institution ceases ordinary operations.
22.2.10 Dissolution Authority Register. 22.2.10(a) GCRI Canada shall maintain a Dissolution Authority Register if dissolution or material wind-up is initiated.
22.2.10(b) The Register shall identify authority source, decision-maker, approving body, required approvals, Board action, member approval where applicable, legal review, tax review, nonprofit review, filing requirements, effective date, wind-up authority, delegated officers, restricted conditions, responsible persons, required notices, public-safe communication status, and closeout status.
22.2.10(c) The Register shall link to Board records, member records where applicable, legal review records, filings, Dissolution Plan, Asset Distribution Register, Data Disposition Register, Technical Asset Disposition Register, Records Archive Register, Public Materials Closeout Register, Contract Closeout Register, Employment Closeout Register, Public Authority Closeout Register, Nexus Interface Closeout Register, and Final Assurance records.
22.2.10(d) The Register shall be retained permanently or for the maximum lawful and mission-appropriate period.
22.2.10(e) The controlling rule shall be that dissolution authority must be registered because final authority errors are difficult to correct after dissolution.
22.3 Wind-Up Governance
22.3.1 Wind-Up Governance Shall Be Directed by the Board or Lawful Wind-Up Authority. 22.3.1(a) Wind-up governance shall be directed by the Board or by the lawful wind-up authority identified under applicable law, court order, regulator direction, governing instruments, Bylaw, or dissolution resolution.
22.3.1(b) The Board or lawful wind-up authority shall oversee wind-up planning, asset disposition, liability management, restricted fund closeout, grant closeout, donor and sponsor closeout, contract closeout, employment closeout, data disposition, Public Authority Data disposition, protected knowledge disposition, technical asset continuity, public materials correction, records archive, legal hold, and final assurance.
22.3.1(c) Wind-up governance shall preserve fiduciary duties, legal compliance, conflict discipline, anti-inurement, sponsor non-control, provider neutrality, public-good asset protection, and public trust.
22.3.1(d) No person may exercise wind-up authority without written authority, proper scope, conflict review, records duties, and reporting duties.
22.3.1(e) The controlling rule shall be that wind-up requires governance until closeout is complete.
22.3.2 Wind-Up Officer, Liquidator, Trustee, Custodian, Receiver, or Equivalent Role Where Required by Law. 22.3.2(a) A wind-up officer, liquidator, trustee, custodian, receiver, monitor, administrator, or equivalent role shall be appointed or recognized where required by law, court order, regulator direction, governing instruments, Bylaw, or Board resolution.
22.3.2(b) Any such role shall have written authority, defined scope, reporting obligations, records duties, confidentiality obligations, conflict duties, data protection obligations, cybersecurity obligations, Public Authority obligations, protected knowledge obligations, fiscal duties, contract duties, and closeout duties.
22.3.2(c) Where an external person serves in such role, GCRI Canada shall, to the extent lawful, require appropriate confidentiality, data, cybersecurity, records, protected knowledge, public-safe communication, and public-good asset safeguards.
22.3.2(d) Such role shall not use wind-up authority to create private benefit, sponsor advantage, provider preference, improper transfer, public authority confusion, finance overclaim, technical asset enclosure, or public claims overreach.
22.3.2(e) The controlling rule shall be that wind-up authority may be delegated or imposed, but must remain bounded by law and safeguards.
22.3.3 Wind-Up Committee Where Appropriate. 22.3.3(a) The Board or lawful wind-up authority may establish a Wind-Up Committee where appropriate.
22.3.3(b) The Wind-Up Committee may oversee legal closeout, fiscal closeout, restricted fund closeout, grants, contracts, employment, records, data, AI, cybersecurity, technical assets, Public Authority interfaces, community safeguards, protected knowledge, public-safe communications, Nexus interfaces, and final assurance.
22.3.3(c) The Wind-Up Committee shall have a written mandate identifying membership, chair, authority, limits, reporting, quorum where applicable, conflicts, confidentiality, access controls, records, decision authority, escalation triggers, and closeout.
22.3.3(d) The Wind-Up Committee shall not exercise authority beyond law, Bylaw, Board resolution, court order, regulator direction, or its written mandate.
22.3.3(e) The controlling rule shall be that wind-up committees may coordinate closeout but shall not become unbounded dissolution authority.
22.3.4 Wind-Up Delegations Shall Be Written, Limited, Records-Valid, and Consistent With Law and Mission Lock. 22.3.4(a) Wind-up delegations shall be written, limited, records-valid, revocable where lawful, and consistent with applicable law, governing instruments, Bylaw, dissolution resolution, wind-up plan, mission lock, non-execution, anti-inurement, data rights, cybersecurity, protected knowledge, public-safe publication, and public trust.
22.3.4(b) Each delegation shall identify delegate, authority source, scope, limits, term, reporting duty, records duty, conflict duty, confidentiality duty, data duty, cybersecurity duty, public communication limits, approval thresholds, escalation triggers, and closeout duty.
22.3.4(c) Delegations affecting asset disposition, restricted funds, data transfer, technical asset transfer, Public Authority Data, protected knowledge, public communications, contract settlement, employment termination, or Nexus interface closeout shall require heightened review.
22.3.4(d) Unauthorized wind-up action shall be held, reviewed, corrected, ratified where lawful, reversed where possible, or escalated.
22.3.4(e) The controlling rule shall be that wind-up delegation must narrow authority because wind-up decisions are often irreversible.
22.3.5 Wind-Up Shall Preserve Fiduciary Duties and Public-Benefit Duties. 22.3.5(a) Wind-up shall preserve fiduciary duties and public-benefit duties.
22.3.5(b) Directors, Officers, wind-up authorities, committee members, employees, contractors, and delegates shall act in good faith, with due care, within authority, in the best interests of GCRI Canada’s lawful purpose, and consistent with legal requirements and fiduciary duties.
22.3.5(c) Wind-up decisions shall avoid private inurement, improper private benefit, related-party abuse, sponsor control, provider capture, asset stripping, preferential treatment, concealment of liabilities, concealment of conflicts, or misuse of public-good assets.
22.3.5(d) Public-benefit duties shall include preserving public-good assets where lawful, correcting public materials, protecting data rights, safeguarding protected knowledge, honoring donor and grant restrictions, closing Public Authority obligations, and maintaining public trust.
22.3.5(e) The controlling rule shall be that fiduciary duty does not weaken at dissolution; it intensifies.
22.3.6 Wind-Up Shall Preserve Non-Execution Boundaries. 22.3.6(a) Wind-up shall preserve non-execution boundaries.
22.3.6(b) GCRI Canada shall not use wind-up to execute projects, operate public infrastructure, command emergencies, issue official public warnings, make Public Authority decisions, conduct public procurement, approve public finance, provide investment advice, broker transactions, lend, guarantee, underwrite, rate, approve insurance, certify providers by default, create GRF recognition by default, create GRA finance-readiness by default, create Protocol Authority effect by default, or operate market infrastructure.
22.3.6(c) Wind-up transfers, asset dispositions, repository transfers, technical asset transfers, data transfers, public authority material dispositions, public-good software continuity arrangements, and Nexus interface closeouts shall not imply execution authority or downstream project approval.
22.3.6(d) Wind-up communications shall include non-execution boundary language where risk exists.
22.3.6(e) The controlling rule shall be that dissolution does not transform GCRI Canada from evidence steward into execution actor.
22.3.7 Wind-Up Shall Preserve Public Authority Boundaries and Finance Boundaries. 22.3.7(a) Wind-up shall preserve Public Authority boundaries and finance boundaries.
22.3.7(b) Public Authority closeout shall not imply endorsement, adoption, official guidance, public warning, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, public-private partnership, or sovereign obligation by GCRI Canada or by any Public Authority unless separately and lawfully established.
22.3.7(c) Finance-sensitive closeout shall not imply investment advice, solicitation, brokerage, finder activity, lending approval, guarantee, insurance approval, underwriting, rating, finance-readiness, bankability, public finance approval, capital commitment, or transaction execution by GCRI Canada.
22.3.7(d) Public Authority and finance-sensitive materials shall be corrected, withdrawn, archived, transferred, or noticed with proper boundary language.
22.3.7(e) The controlling rule shall be that wind-up must close public authority and finance-sensitive meanings without creating new ones.
22.3.8 Wind-Up Shall Preserve Data Rights, Cybersecurity, Protected Knowledge, and Public-Safe Publication Controls. 22.3.8(a) Wind-up shall preserve data rights, cybersecurity, protected knowledge, and public-safe publication controls.
22.3.8(b) Data disposition shall respect lawful basis, purpose limitation, consent and non-consent where applicable, classification, access rights, correction rights, deletion rights, retention rules, legal holds, Public Authority terms, research ethics, data sharing agreements, cross-border transfer rules, sovereign data requirements, and protected knowledge protocols.
22.3.8(c) Cybersecurity during wind-up shall address identity and access, privileged access, keys, tokens, secrets, repositories, backups, archives, controlled rooms, clean rooms, data rooms, dashboards, maps, APIs, datasets, AI systems, compute environments, decommissioning, transfer, deletion, and incident response.
22.3.8(d) Protected knowledge shall not be transferred, disclosed, archived, published, trained on, embedded, mapped, commercialized, or destroyed except according to lawful authority, community protocols, protected knowledge rules, and public-safe safeguards.
22.3.8(e) Public-safe publication controls shall govern all dissolution communications, public materials updates, public claims correction, Gazette notices, and final reports.
22.3.8(f) The controlling rule shall be that wind-up is not a relaxation of data, cybersecurity, and safeguards discipline.
22.3.9 Wind-Up Shall Preserve Correctionability Until Final Closeout. 22.3.9(a) Wind-up shall preserve correctionability until final closeout.
22.3.9(b) GCRI Canada shall maintain capacity to receive, triage, review, correct, supersede, withdraw, retract, archive, or public-safely clarify material errors in records, public materials, technical assets, datasets, dashboards, maps, public authority references, finance-sensitive materials, sponsor references, provider references, protected knowledge materials, and Nexus interface records during wind-up.
22.3.9(c) Correction responsibilities shall be assigned to an owner and custodian until final closeout or lawful transfer.
22.3.9(d) Final closeout shall identify any continuing correction pathway after dissolution, including successor custodian, archive contact, legal representative, trustee, public-good recipient, or records custodian where lawful and appropriate.
22.3.9(e) The controlling rule shall be that an institution shall not become uncorrectable during the period when its public meaning is most vulnerable.
22.3.10 Wind-Up Governance Records, Decisions, Delegations, and Closeout. 22.3.10(a) Wind-up governance records, decisions, delegations, and closeout records shall be maintained.
22.3.10(b) Records shall identify wind-up authority, Board actions, committee actions, delegations, legal reviews, conflicts, recusals, decisions, asset dispositions, data dispositions, technical asset dispositions, public materials actions, notices, filings, contract closeouts, employment closeouts, restricted fund closeouts, Public Authority closeouts, community safeguard closeouts, Nexus interface closeouts, corrective actions, assurance findings, and final closeout.
22.3.10(c) Wind-up records shall be classified, access-controlled, archived, retained, and protected according to law, legal hold, privacy, cybersecurity, Public Authority sensitivity, finance sensitivity, protected knowledge, legal privilege, and public-safe requirements.
22.3.10(d) Final closeout shall identify completion status, open matters, transferred obligations, residual risks, archive arrangements, and final authority.
22.3.10(e) The controlling rule shall be that wind-up governance must be documented because final decisions may be reviewed after the institution ceases to operate.
22.4 Dissolution Plan
22.4.1 Dissolution Plan Requirement. 22.4.1(a) GCRI Canada shall prepare a Dissolution Plan before voluntary dissolution or material wind-up action, except where legally impossible, impracticable, or displaced by court, regulator, or other lawful authority.
22.4.1(b) The Dissolution Plan shall provide a structured, records-valid, lawful, public-benefit, public-safe, data-safe, cybersecurity-safe, protected-knowledge-safe, fiscally responsible, contract-aware, and Nexus-aware roadmap for wind-up.
22.4.1(c) The Plan shall identify authority, rationale, scope, timeline, owners, custodians, approvals, legal review, filings, asset disposition, liability closeout, restricted fund closeout, data disposition, technical asset disposition, public materials closeout, notices, archive, assurance, and final closeout.
22.4.1(d) The Plan shall be proportionate to the complexity, assets, liabilities, data, technical assets, public materials, Public Authority interfaces, finance-sensitive materials, protected knowledge, and Nexus interfaces affected.
22.4.1(e) The controlling rule shall be that dissolution shall proceed by plan, not by disappearance.
22.4.2 Legal Status and Filing Plan. 22.4.2(a) The Dissolution Plan shall include a legal status and filing plan.
22.4.2(b) The plan shall identify GCRI Canada’s legal form, governing statute, governing instruments, dissolution authority, required Board approvals, member approvals where applicable, notices, creditor procedures where applicable, filings, tax notifications, regulator notifications, court filings where applicable, corporate registry filings, final returns, and final confirmations.
22.4.2(c) The plan shall identify legal deadlines, required forms, signatories, responsible officers, external counsel, filing evidence, and post-filing obligations.
22.4.2(d) The plan shall address administrative dissolution risk, revival options where relevant, name protection, document retention, and public-safe statements about legal status.
22.4.2(e) The controlling rule shall be that legal existence and legal cessation must be tracked precisely.
22.4.3 Governance Closeout Plan. 22.4.3(a) The Dissolution Plan shall include a governance closeout plan.
22.4.3(b) Governance closeout shall address Board meetings, member meetings where applicable, resolutions, delegations, committee closeout, council closeout, Working Group closeout, officer authority, signing authority, conflict review, recusal review, related-party review, policy status, register status, Charter status, Bylaw status, controlled annex status, and final governance records.
22.4.3(c) Governance closeout shall identify who may act during wind-up, who may speak publicly, who may sign filings, who may approve payments, who may approve asset dispositions, who may approve data disposition, who may approve technical asset transfers, and who may approve public-safe notices.
22.4.3(d) Governance closeout shall include a final Board or lawful authority closeout action where required.
22.4.3(e) The controlling rule shall be that governance authority must remain clear until final termination.
22.4.4 Financial Closeout Plan. 22.4.4(a) The Dissolution Plan shall include a financial closeout plan.
22.4.4(b) Financial closeout shall address bank accounts, reserves, accounts payable, accounts receivable, payroll, taxes, reimbursements, credit cards, payment platforms, subscriptions, insurance, leases, liabilities, debts, contingencies, audit or review needs, financial statements, final reports, and account closure.
22.4.4(c) The plan shall identify signing authority, payment approval authority, segregation of duties where feasible, reconciliations, restricted funds, reserve use, creditor procedures, final tax filings, final regulatory filings, and final financial records.
22.4.4(d) Financial closeout shall prohibit private inurement, improper private benefit, related-party abuse, preferential treatment, sponsor-controlled distribution, provider-favored transfer, or undocumented payment.
22.4.4(e) The controlling rule shall be that fiscal integrity must survive until the final account is closed.
22.4.5 Restricted Fund and Grant Closeout Plan. 22.4.5(a) The Dissolution Plan shall include a restricted fund and grant closeout plan.
22.4.5(b) The plan shall identify all restricted funds, donor restrictions, grant conditions, sponsorship restrictions, public authority funds, research funds, in-kind contribution restrictions, asset-use restrictions, reporting obligations, return obligations, transfer permissions, residual balances, and final reports.
22.4.5(c) Restricted funds and grant assets shall not be reallocated, transferred, returned, spent, or repurposed except according to law, agreement, donor restriction, grant condition, court direction where required, and mission-compatible public-benefit purpose.
22.4.5(d) Grant closeout shall include deliverable status, unspent funds, equipment, data, IP, publications, acknowledgments, public claims, confidentiality, records, and audit rights.
22.4.5(e) The controlling rule shall be that restricted purpose remains binding during dissolution.
22.4.6 Contract and Liability Closeout Plan. 22.4.6(a) The Dissolution Plan shall include a contract and liability closeout plan.
22.4.6(b) The plan shall identify contracts, grants, sponsorship agreements, donation agreements, MOUs, data agreements, public authority agreements, research agreements, vendor agreements, employment agreements, contractor agreements, licenses, leases, insurance policies, indemnities, warranties, confidentiality obligations, IP obligations, service commitments, dispute obligations, termination rights, assignment rights, survival clauses, notice requirements, and liabilities.
22.4.6(c) Contract closeout shall determine whether each agreement will be completed, terminated, assigned, transferred, settled, renewed for wind-up purposes, or allowed to expire.
22.4.6(d) Liability closeout shall address known claims, threatened claims, contingent liabilities, insurance notice, legal holds, dispute resolution, settlement authority, and final reserves.
22.4.6(e) The controlling rule shall be that dissolution shall not ignore obligations because operations are ending.
22.4.7 Employment, Contractor, Fellow, Advisor, Volunteer, and Participant Closeout Plan. 22.4.7(a) The Dissolution Plan shall include an employment, contractor, fellow, advisor, volunteer, and participant closeout plan.
22.4.7(b) The plan shall identify employees, contractors, fellows, advisors, volunteers, interns, students, committee members, council participants, Working Group members, contributors, maintainers, reviewers, and other participants affected by dissolution.
22.4.7(c) Closeout shall address notice, compensation, reimbursements, stipends, benefits, taxes, final payments, records, confidentiality, IP, moral rights, data return, device return, credential revocation, repository access, dashboard access, AI tool access, controlled room access, public claims restrictions, references, disputes, grievances, and continuing obligations.
22.4.7(d) Workforce and participant closeout shall comply with applicable employment, contractor, volunteer, fellowship, privacy, human rights, accessibility, occupational health and safety, immigration, tax, contract, and non-retaliation requirements.
22.4.7(e) The controlling rule shall be that people-based obligations require humane, lawful, and records-valid closeout.
22.4.8 Data Disposition Plan. 22.4.8(a) The Dissolution Plan shall include a data disposition plan.
22.4.8(b) The plan shall identify all material data holdings, including personal information, sensitive personal information, rights-bearing data, health-sensitive data, Public Authority Data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, commercially sensitive data, research data, AI data, embedding stores, retrieval sources, logs, backups, dashboards, maps, datasets, community-protected data, and protected knowledge.
22.4.8(c) For each data class, the plan shall identify owner, custodian, lawful basis, purpose, classification, access, retention, deletion, sealing, archive, transfer, return, anonymization or de-identification where appropriate, legal hold, data rights obligations, breach risk, and final disposition.
22.4.8(d) Data shall not be transferred, retained, deleted, destroyed, archived, published, trained on, embedded, or reused during dissolution except according to lawful authority, agreements, rights, restrictions, public-safe review, and records requirements.
22.4.8(e) The controlling rule shall be that data remains rights-bearing during dissolution.
22.4.9 Public Authority Data and Materials Disposition Plan. 22.4.9(a) The Dissolution Plan shall include a Public Authority Data and materials disposition plan.
22.4.9(b) The plan shall identify Public Authority Data, public authority learning materials, dashboards, maps, evidence packs, reports, controlled room materials, Public Authority room materials, correspondence, reference approvals, logos, quotes, photographs, agency names, jurisdiction references, public-safe summaries, and related records.
22.4.9(c) Public Authority Data and materials shall be returned, transferred, archived, sealed, deleted, destroyed, or retained only according to applicable law, Public Authority terms, data agreements, confidentiality obligations, security requirements, public-safe review, and records rules.
22.4.9(d) Public Authority references in websites, reports, dashboards, maps, public-safe summaries, media statements, and public materials shall be corrected, withdrawn, archived, or public-safely clarified where dissolution changes the context of reliance.
22.4.9(e) The controlling rule shall be that Public Authority materials must be closed in a way that preserves public authority boundaries and confidentiality.
22.4.10 Community-Protected and Protected Knowledge Disposition Plan. 22.4.10(a) The Dissolution Plan shall include a community-protected and protected knowledge disposition plan.
22.4.10(b) The plan shall identify community-protected data, Indigenous Knowledge, Local Knowledge, Territorial Knowledge, Cultural Knowledge, Environmental Knowledge, Protected Knowledge, sensitive sites, vulnerable community information, protected person information, public-safe mapping materials, community review records, grievances, remedies, consent and non-consent records where applicable, and safeguard commitments.
22.4.10(c) Disposition shall follow applicable law, community protocols, protected knowledge obligations, data sovereignty principles where applicable, consent and non-consent pathways where applicable, access restrictions, public-safe review, and records requirements.
22.4.10(d) Protected knowledge shall not be transferred to a recipient lacking lawful authority, mission compatibility, safeguard capacity, confidentiality discipline, data protection capacity, cultural safety, and correction pathways.
22.4.10(e) Where appropriate, affected communities shall receive controlled notice, consultation, or remedy pathway information before disposition.
22.4.10(f) The controlling rule shall be that dissolution shall not become extraction, abandonment, or exposure of protected knowledge.
22.4.11 Technical Asset, Repository, Software, Ontology, and Open Baseline Continuity Plan. 22.4.11(a) The Dissolution Plan shall include a technical asset, repository, software, ontology, and Open Baseline continuity plan.
22.4.11(b) The plan shall identify public-good software, repositories, APIs, schemas, datasets, models, benchmarks, dashboards, maps, technical baselines, Open Technical Baselines, ontology, controlled vocabulary, documentation, release notes, SBOMs, issues, pull requests, licenses, contributor records, maintainer rights, signing keys, tokens, secrets, domains, package registries, deployment environments, backups, archives, and known vulnerabilities.
22.4.11(c) Technical assets may be continued, transferred, archived, deprecated, retired, open-released, controlled-released, restricted, withdrawn, or destroyed where lawful and appropriate.
22.4.11(d) Continuity or transfer shall preserve licensing, IP rights, contributor rights, security, vulnerability handling, export-control restrictions, controlled technology restrictions, public-safe documentation, anti-enclosure, and no-certification / no-warranty / no-provider-preference / no-public-authority-approval / no-finance-readiness boundary language.
22.4.11(e) Secrets, keys, tokens, credentials, signing keys, and access rights shall be rotated, revoked, transferred, archived, destroyed, or otherwise managed securely.
22.4.11(f) The controlling rule shall be that technical assets must either continue safely, transfer lawfully, retire clearly, or archive responsibly.
22.4.12 Public Materials, Website, Dashboard, Map, Publication, and Claims Closeout Plan. 22.4.12(a) The Dissolution Plan shall include a public materials, website, dashboard, map, publication, and claims closeout plan.
22.4.12(b) The plan shall identify websites, domains, public pages, reports, whitepapers, technical notes, publications, dashboards, maps, datasets, public-safe summaries, Academy materials, public authority learning materials, sponsor materials, provider materials, social media, media statements, event materials, repository descriptions, public claims, and Gazette notices where applicable.
22.4.12(c) Each material shall be classified for continued availability, correction, supersession, withdrawal, retraction, archive, redirection, public-safe notice, controlled notice, or removal.
22.4.12(d) Public materials shall include status language explaining dissolution, archive status, reliance limits, correction path, no public authority approval, no finance-readiness, no certification, no provider preference, no sponsor validation, no public warning, and no execution authority where relevant.
22.4.12(e) The controlling rule shall be that public-facing materials shall not remain active in a way that misleads readers after dissolution.
22.4.13 Records, Archive, Legal Hold, and Final Report Plan. 22.4.13(a) The Dissolution Plan shall include a records, archive, legal hold, and final report plan.
22.4.13(b) The plan shall identify permanent records, long-term technical memory records, research records, evidence records, data records, AI records, cybersecurity records, Public Authority records, fiscal records, grant records, sponsorship records, donation records, contract records, employment records, governance records, committee records, council records, program records, publication records, correction records, incident records, technical asset records, community safeguard records, protected knowledge records, and Nexus interface records.
22.4.13(c) The plan shall classify records for permanent archive, legal hold, retention, sealing, deletion, secure destruction, transfer, public-safe summary, or controlled access.
22.4.13(d) Final reports may be internal, controlled, public-safe, or legally required and shall protect sensitive information while documenting dissolution actions, asset disposition, records disposition, data disposition, technical asset disposition, notices, and final assurance.
22.4.13(e) The controlling rule shall be that institutional memory shall not be destroyed by institutional closure.
22.4.14 Public-Safe Communication Plan. 22.4.14(a) The Dissolution Plan shall include a public-safe communication plan.
22.4.14(b) The plan shall identify audiences, messages, approval authority, timing, channels, public-safe status, controlled notice needs, Public Authority notice needs, donor and grantor notices, sponsor notices, provider notices, host notices, university notices, community notices, Nexus interface notices, media statements, website statements, dashboard statements, map statements, repository notices, and correction paths.
22.4.14(c) Communications shall be accurate, records-supported, controlled-vocabulary-compliant, accessible, translated where appropriate, limitation-aware, boundary-safe, and correctionable.
22.4.14(d) Communications shall avoid over-disclosure and shall not imply that dissolution creates endorsement, adoption, finance-readiness, recognition, certification, protocol effect, procurement approval, public warning, emergency command, provider preference, sponsor validation, or execution consequence.
22.4.14(e) The controlling rule shall be that dissolution communications must preserve public trust without creating new misunderstanding.
22.4.15 Dissolution Plan Approval, Versioning, Correction, and Register Entry. 22.4.15(a) The Dissolution Plan shall be approved by the Board or lawful wind-up authority, unless legally displaced by court, regulator, or other lawful process.
22.4.15(b) The Plan shall be versioned, dated, owner-assigned, custodian-assigned, reviewed, classified, and entered into the appropriate dissolution and wind-up registers.
22.4.15(c) Material changes to the Plan shall require approval, legal review where appropriate, update of affected records, and notice where affected persons or public materials are impacted.
22.4.15(d) Errors in the Plan shall be corrected through correction records, supersession where needed, controlled notice or public-safe notice where reliance exists, and assurance follow-up.
22.4.15(e) The controlling rule shall be that the Dissolution Plan must itself be governed as a critical constitutional instrument.
22.5 Public-Benefit Asset Distribution
22.5.1 Remaining Assets Shall Be Distributed According to Applicable Law, Articles, Bylaw, Tax Status, Donor Restrictions, Grant Restrictions, Contractual Obligations, and Public-Benefit Purpose. 22.5.1(a) Remaining assets of GCRI Canada shall be distributed according to applicable law, governing instruments, Articles, Bylaw, tax status, nonprofit requirements, charitable-status requirements where applicable, donor restrictions, grant restrictions, sponsorship terms, contractual obligations, court directions where applicable, regulator directions where applicable, and GCRI Canada’s public-benefit purpose.
22.5.1(b) Assets shall include cash, receivables, reserves, restricted funds, equipment, devices, repositories, software, datasets, technical baselines, IP, licenses, domains, publications, records, contracts, insurance rights, claims, public-good assets, research assets, and any other property or rights held by GCRI Canada.
22.5.1(c) Restricted assets shall be identified and disposed of according to their lawful restriction before unrestricted public-benefit disposition is determined.
22.5.1(d) Asset distribution shall be documented with valuation where appropriate, authority, recipient, restrictions, conditions, transfer instruments, receipts, conflict review, and public-benefit rationale.
22.5.1(e) The controlling rule shall be that assets remaining at dissolution must follow law, restrictions, and public-benefit purpose before convenience or preference.
22.5.2 No Improper Private Distribution. 22.5.2(a) No improper private distribution shall be made upon dissolution or wind-up.
22.5.2(b) Assets shall not be distributed to private persons, Directors, Officers, members where applicable, employees, contractors, fellows, advisors, sponsors, donors, funders, providers, hosts, vendors, related parties, National Companies, Project SPVs, capital actors, or other private actors except where lawful, fair, mission-compatible, conflict-managed, properly documented, and consistent with dissolution requirements.
22.5.2(c) Lawful payment of debts, reasonable compensation, reimbursable expenses, contract obligations, return of restricted funds where required, asset sale at fair value, or other lawful transfer shall not be treated as improper private distribution solely because a private person receives payment, provided the payment is authorized, documented, conflict-managed, and not inurement.
22.5.2(d) Asset distribution shall be reviewed for disguised private benefit, undervalue transfer, sweetheart transaction, insider preference, sponsor preference, provider preference, asset stripping, and capture.
22.5.2(e) The controlling rule shall be that dissolution shall not convert public-benefit assets into private distributions.
22.5.3 No Private Inurement. 22.5.3(a) Private inurement shall be prohibited in dissolution and wind-up.
22.5.3(b) No net earnings, remaining assets, restricted assets, public-good assets, technical assets, data assets, records, IP, licenses, opportunities, public authority access, Nexus interface positions, or public trust benefits shall inure improperly to any Director, Officer, member where applicable, employee, contractor, fellow, advisor, sponsor, donor, funder, provider, host, related party, private person, or private entity.
22.5.3(c) Transactions involving insiders, related parties, sponsors, providers, hosts, vendors, National Companies, Project SPVs, or private actors shall require conflict review, independent review where appropriate, fair value review where applicable, legal review where risk exists, Board or lawful authority approval, and records.
22.5.3(d) Any suspected inurement shall trigger hold, investigation, correction, recovery, disgorgement where appropriate, legal review, reporting where required, and final assurance review.
22.5.3(e) The controlling rule shall be that public-benefit character survives through final distribution.
22.5.4 No Asset Transfer to Sponsor, Donor, Provider, Director, Officer, Member, Contractor, Related Party, National Company, Project SPV, or Private Actor Except Where Lawful, Fair, Mission-Compatible, Conflict-Managed, and Consistent With Dissolution Requirements. 22.5.4(a) No asset shall be transferred to a sponsor, donor, provider, Director, Officer, member where applicable, employee, contractor, fellow, advisor, related party, National Company, Project SPV, vendor, host, private actor, or private entity except where lawful, fair, mission-compatible, conflict-managed, records-valid, and consistent with dissolution requirements.
22.5.4(b) Any such transfer shall identify the asset, valuation, legal basis, restriction status, public-benefit rationale, conflict review, recipient eligibility, conditions, transfer instrument, Board or lawful authority approval, and receipt.
22.5.4(c) Transfers involving technical assets, IP, repositories, datasets, Public Authority Data, protected knowledge, software, Open Technical Baselines, domains, public materials, or public-good methods shall require heightened review.
22.5.4(d) A transfer shall not be approved where it would create sponsor control, provider capture, asset enclosure, private inurement, public authority confusion, finance overclaim, procurement advantage, certification implication, recognition implication, protocol implication, or public trust harm.
22.5.4(e) The controlling rule shall be that sensitive transfers to private or related actors must be exceptional, lawful, fair, justified, and controlled.
22.5.5 Public-Benefit Recipient Eligibility. 22.5.5(a) Public-benefit recipient eligibility shall be assessed before distribution of remaining assets intended for public-benefit continuity.
22.5.5(b) Eligible recipients may include qualified nonprofit, charitable, public-benefit, educational, research, public-good, public authority, archival, technical stewardship, community, Indigenous, university, standards, or mission-compatible entities where lawful and appropriate.
22.5.5(c) Recipient eligibility shall consider legal status, mission compatibility, nonprofit or public-benefit character, governance capacity, fiscal controls, anti-inurement controls, data protection capacity, cybersecurity capacity, IP stewardship capacity, public authority boundary discipline, protected knowledge safeguards, correctionability, public-safe publication discipline, and anti-enclosure posture.
22.5.5(d) A recipient shall not be eligible merely because it is connected to GCRI Canada, a sponsor, a provider, a donor, a Public Authority, a Nexus actor, a National Company, a Project SPV, or a technical contributor.
22.5.5(e) The controlling rule shall be that public-benefit asset continuity requires recipient fitness, not relationship proximity.
22.5.6 Recipient Mission Compatibility Review. 22.5.6(a) GCRI Canada shall conduct recipient mission compatibility review before distributing public-benefit assets.
22.5.6(b) Review shall assess whether the recipient’s purposes, governance, funding model, public claims practices, data practices, technical asset practices, public authority interfaces, finance-sensitive interfaces, sponsor relationships, provider relationships, community safeguards, protected knowledge protocols, and public trust posture are compatible with the asset’s public-benefit purpose and restrictions.
22.5.6(c) Mission compatibility review shall identify whether the transfer could create private benefit, enclosure, data misuse, protected knowledge exposure, sponsor control, provider preference, Public Authority confusion, finance-readiness implication, certification implication, procurement advantage, or execution drift.
22.5.6(d) Transfer conditions may require public-good use, open license, controlled access, no-commercialization limits, no-training limits, data safeguards, public-safe publication limits, correction duties, archive duties, attribution, non-endorsement language, and retransfer restrictions.
22.5.6(e) The controlling rule shall be that assets created for public benefit should remain governed by public-benefit logic after transfer.
22.5.7 Recipient Capacity Review. 22.5.7(a) GCRI Canada shall conduct recipient capacity review before distributing assets requiring stewardship.
22.5.7(b) Capacity review shall assess recipient governance, staffing, technical capability, financial stability, records capacity, cybersecurity capacity, data protection capacity, legal capacity, IP capacity, repository stewardship, software maintenance, archive capacity, public-safe publication capacity, correction capacity, community safeguard capacity, protected knowledge capacity, and continuity capacity.
22.5.7(c) Assets requiring heightened capacity review include sensitive data, Public Authority Data, technical baselines, repositories, software, datasets, dashboards, maps, AI-related assets, cybersecurity materials, controlled annexes, research records, protected knowledge, community-protected data, and long-term archives.
22.5.7(d) Where capacity is insufficient, GCRI Canada shall select another recipient, impose transfer conditions, retain through lawful archive, destroy where lawful and required, or seek court, regulator, donor, grantor, Public Authority, or community direction where appropriate.
22.5.7(e) The controlling rule shall be that asset transfer is not responsible unless the recipient can steward the asset safely.
22.5.8 Recipient Data, Cybersecurity, IP, Public Authority, Protected Knowledge, and Public-Safe Capability Review Where Assets Include Sensitive Materials. 22.5.8(a) Where assets include sensitive materials, GCRI Canada shall conduct recipient data, cybersecurity, IP, Public Authority, protected knowledge, and public-safe capability review.
22.5.8(b) Sensitive materials include personal information, rights-bearing data, health-sensitive data, Public Authority Data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, commercially sensitive data, research data, AI data, embeddings, logs, controlled technology, export-control-sensitive materials, technical baselines, repositories, software, source code, signing keys, datasets, dashboards, maps, protected knowledge, community-protected data, and controlled annexes.
22.5.8(c) Data capability review shall assess lawful basis, data processing terms, access controls, retention, deletion, data rights, breach response, cross-border transfer, sovereign data requirements, Public Authority terms, and re-identification controls.
22.5.8(d) Cybersecurity capability review shall assess identity and access controls, privileged access, key management, repository security, secure development, secure release, vulnerability handling, backups, incident response, and continuity.
22.5.8(e) IP and public-safe review shall assess ownership, licensing, contributor rights, moral rights, open release conditions, anti-enclosure, public claims, public-safe publication, correction path, non-endorsement, and no-certification / no-finance-readiness / no-public-authority-approval boundaries.
22.5.8(f) Protected knowledge and Public Authority review shall assess lawful authority, confidentiality, community protocols, Public Authority terms, reference approvals, access restrictions, public-safe mapping, and notice obligations.
22.5.8(g) The controlling rule shall be that sensitive asset transfer requires recipient capability across every risk dimension the asset carries.
22.5.9 Asset Distribution Records, Valuation, Restrictions, Conditions, and Receipts. 22.5.9(a) GCRI Canada shall maintain asset distribution records, valuations, restrictions, conditions, and receipts.
22.5.9(b) Asset distribution records shall identify asset, asset class, owner, custodian, restriction status, valuation where appropriate, legal authority, approving body, recipient, recipient eligibility review, recipient mission compatibility review, recipient capacity review, conflict review, related-party review, restrictions, transfer conditions, transfer date, receipt, post-transfer obligations, public-safe notice status, and archive.
22.5.9(c) Valuation shall be used where required by law, accounting, tax, restricted fund conditions, conflict review, related-party review, fair value review, insurance, audit, or public-benefit assurance.
22.5.9(d) Transfer conditions shall be written, enforceable where appropriate, mission-compatible, records-valid, and clear as to use, restrictions, data, IP, cybersecurity, protected knowledge, public claims, retransfer, correction, and reporting.
22.5.9(e) Receipts shall be obtained where appropriate and retained with final dissolution records.
22.5.9(f) The controlling rule shall be that asset distribution must be evidenced because final asset movement is final public-benefit accountability.
22.5.10 Asset Distribution Register and Final Assurance. 22.5.10(a) GCRI Canada shall maintain an Asset Distribution Register and conduct final asset distribution assurance.
22.5.10(b) The Register shall identify each distributed, transferred, sold, returned, retained, archived, destroyed, abandoned where lawful, or otherwise disposed asset, including asset description, class, restriction status, valuation, authority, recipient, review status, transfer conditions, date, receipt, records location, public-safe notice status, and closeout.
22.5.10(c) Final assurance shall review whether all assets were identified, classified, valued where required, restricted assets handled correctly, conflicts managed, private inurement avoided, public-benefit purpose preserved, sensitive materials protected, technical assets handled safely, data rights respected, protected knowledge safeguarded, public claims corrected, and records completed.
22.5.10(d) Findings shall require corrective action, recovery, additional notice, legal review, recipient condition enforcement, asset retransfer where possible and lawful, records correction, or Board / lawful authority reporting.
22.5.10(e) The controlling rule shall be that asset distribution is not complete until final assurance confirms that public-benefit assets were lawfully and responsibly dispositioned.
22.6 Restricted Funds, Grants, Donations, and Sponsorship Closeout
22.6.1 Restricted Funds Shall Be Closed According to Restriction, Law, Donor Terms, Grant Terms, Sponsor Terms, and Public-Benefit Purpose. 22.6.1(a) Restricted funds shall be closed according to applicable law, governing instruments, Bylaw, tax-status requirements, donor terms, grant terms, sponsor terms, funder terms, court or regulator directions where applicable, and GCRI Canada’s public-benefit purpose.
22.6.1(b) Restricted fund closeout shall identify each restricted fund, restriction source, fund purpose, balance, allowable uses, prohibited uses, reporting obligations, return obligations, transfer eligibility, re-purposing authority, recipient eligibility, and final disposition.
22.6.1(c) Restricted funds shall not be used to satisfy general liabilities, wind-up convenience, unrelated program costs, private benefit, sponsor benefit, provider benefit, related-party payments, National Company benefit, Project SPV benefit, or Nexus interface costs unless such use is lawful, authorized by the restriction, conflict-reviewed, and records-valid.
22.6.1(d) Where the original restricted purpose can no longer be fulfilled, GCRI Canada shall seek lawful direction, donor or grantor consent where appropriate, court or regulator direction where required, or mission-compatible disposition consistent with applicable law and restriction terms.
22.6.1(e) The controlling rule shall be that restricted purpose survives dissolution and shall be closed by authority, not convenience.
22.6.2 Grant Closeout Shall Include Deliverables, Financial Reports, Unspent Funds, Records, Data Rights, IP Rights, Publication Rights, Confidentiality, and Correction Duties. 22.6.2(a) Grant closeout shall include review and disposition of deliverables, milestones, financial reports, narrative reports, technical reports, unspent funds, equipment, in-kind grant assets, records, data rights, IP rights, publication rights, confidentiality obligations, public acknowledgment terms, audit rights, correction duties, and survival clauses.
22.6.2(b) GCRI Canada shall identify whether each grant deliverable has been completed, partially completed, cancelled, transferred, superseded, withdrawn, archived, or left subject to continuing obligation.
22.6.2(c) Grant-funded data, research outputs, technical assets, public-good software, datasets, dashboards, maps, publications, public authority learning materials, and controlled materials shall be dispositioned according to grant terms, law, data rights, IP rights, Public Authority terms, protected knowledge safeguards, and public-safe publication controls.
22.6.2(d) Unspent grant funds shall be returned, transferred, re-purposed, retained, or distributed only according to law, grant terms, grantor approval where required, and public-benefit purpose.
22.6.2(e) Final grant reports shall avoid overstating deliverables, impact, maturity, finance-readiness, certification, recognition, Public Authority adoption, procurement effect, provider status, sponsor validation, Nexus compatibility, or execution consequence.
22.6.2(f) The controlling rule shall be that grant closeout must reconcile money, promises, outputs, rights, restrictions, and public meaning.
22.6.3 Donation Closeout Shall Respect Donor Restrictions and Tax Requirements. 22.6.3(a) Donation closeout shall respect donor restrictions, tax requirements, nonprofit requirements, receipting obligations where applicable, refund obligations where applicable, donor communications, public acknowledgments, record retention, privacy obligations, and public-benefit purpose.
22.6.3(b) GCRI Canada shall distinguish unrestricted donations, restricted donations, conditional donations, donor-advised arrangements where applicable, pledges, recurring donations, in-kind donations, anonymous donations, and donations subject to naming, recognition, reporting, or return terms.
22.6.3(c) Donor-restricted funds or assets shall not be reallocated, transferred, returned, or re-purposed except according to law, donor restriction, donor consent where appropriate, court or regulator direction where required, and public-benefit purpose.
22.6.3(d) Donation closeout shall correct or terminate donor acknowledgments, naming references, website references, public materials, reports, event materials, and sponsor-like visibility where dissolution changes the context of reliance.
22.6.3(e) Donation closeout shall not create donor control, private inurement, public authority access purchase, recognition purchase, finance-readiness purchase, certification purchase, provider preference, or public claims advantage.
22.6.3(f) The controlling rule shall be that donation closeout shall respect donor intent where lawful without allowing donor control.
22.6.4 Sponsorship Closeout Shall Terminate Visibility, Benefits, Logo Use, Name Use, Access Rights, and Public Claims According to Recorded Terms. 22.6.4(a) Sponsorship closeout shall terminate, expire, transfer, or otherwise disposition sponsor visibility, benefits, logo use, name use, acknowledgments, access rights, event references, website references, deck references, public materials, public claims, controlled-room access, data-room access, dashboard access, sponsor-facing reports, sponsor deliverables, and sponsor communications according to recorded sponsorship terms and applicable law.
22.6.4(b) Sponsorship closeout shall identify whether any sponsor benefits survive dissolution, whether any public acknowledgments must be removed or archived, whether logo use must cease, whether sponsor materials must be corrected, and whether sponsor claims must be withdrawn or clarified.
22.6.4(c) Sponsors shall not receive wind-up control, publication veto, correction veto, asset preference, provider preference, Public Authority access, data access, protected knowledge access, technical asset control, finance-readiness status, recognition status, certification implication, or Nexus-compatible status because of sponsorship.
22.6.4(d) Sponsor public claims shall be reviewed and corrected where they imply control, endorsement, validation, public authority approval, procurement advantage, finance-readiness, certification, recognition, or continuing relationship after dissolution.
22.6.4(e) The controlling rule shall be that sponsorship ends as recorded support, not as ownership of institutional meaning.
22.6.5 In-Kind Contribution Closeout Shall Address Ownership, Return, Disposal, Transfer, Data, Cybersecurity, IP, Maintenance, and Public Claims. 22.6.5(a) In-kind contribution closeout shall address ownership, custody, return, disposal, transfer, valuation, maintenance, warranty, support, data, cybersecurity, IP, licenses, confidentiality, export-control status, controlled technology status, public claims, public acknowledgments, and continuing obligations.
22.6.5(b) In-kind contributions may include software, cloud credits, compute, devices, sensors, equipment, data, facilities, staff time, consulting, infrastructure, repository support, cybersecurity tools, AI tools, dashboard tools, event support, public authority learning support, or technical services.
22.6.5(c) GCRI Canada shall identify whether each in-kind contribution is owned by GCRI Canada, loaned to GCRI Canada, licensed to GCRI Canada, held under restricted use, integrated into public-good assets, embedded in technical systems, subject to return, subject to deletion, or subject to continuing access limits.
22.6.5(d) In-kind contribution closeout shall remove or correct claims that such contribution created provider preference, sponsor control, certification, public authority approval, procurement advantage, finance-readiness, recognition, protocol effect, or execution authority.
22.6.5(e) The controlling rule shall be that donated or supplied tools and support must be unwound without transferring control over GCRI Canada’s public-good work.
22.6.6 Unused Restricted Funds Shall Be Returned, Transferred, Re-Purposed, or Distributed Only According to Law and Restrictions. 22.6.6(a) Unused restricted funds shall be returned, transferred, re-purposed, distributed, retained for wind-up purposes, or otherwise dispositioned only according to applicable law, restriction terms, donor terms, grant terms, sponsor terms, funder terms, court or regulator direction where required, and public-benefit purpose.
22.6.6(b) GCRI Canada shall not use unused restricted funds to pay unrelated liabilities, general dissolution costs, unrelated public materials, unrelated technical assets, unrelated Nexus interfaces, private parties, related parties, sponsors, providers, National Companies, Project SPVs, or capital-facing activities unless lawful and permitted by the restriction.
22.6.6(c) Re-purposing of unused restricted funds shall require proper authority, restriction review, consent where required, legal review where appropriate, Board or lawful authority approval, and records.
22.6.6(d) Transfer of unused restricted funds to another recipient shall require recipient eligibility, mission compatibility, capacity review, restriction continuity, and receipt.
22.6.6(e) The controlling rule shall be that unused restricted funds remain restricted until lawfully released, returned, transferred, or fulfilled.
22.6.7 Donor, Grantor, Sponsor, and Funder Notices Where Required. 22.6.7(a) GCRI Canada shall provide donor, grantor, sponsor, funder, and restricted fund notices where required by law, agreement, restriction, public-benefit duty, public-safe communication discipline, or public trust.
22.6.7(b) Notices shall identify dissolution or wind-up status, affected funds, affected deliverables, unspent balances, proposed disposition, required approvals, reporting timeline, public materials consequences, acknowledgment changes, data or IP consequences where relevant, and correction path.
22.6.7(c) Notices shall be accurate, records-supported, boundary-safe, and shall not imply that donors, grantors, sponsors, or funders control dissolution, assets, publications, corrections, public authority interfaces, data, technical assets, or Nexus interfaces.
22.6.7(d) Controlled notices shall be used where public notice would disclose confidential donor information, grant information, financial information, personal information, Public Authority information, cyber-sensitive information, commercially sensitive information, community-protected information, or Protected Knowledge.
22.6.7(e) The controlling rule shall be that funders and supporters shall be notified where required, but not converted into wind-up authorities.
22.6.8 No Closeout Shall Create Donor Control, Sponsor Control, Provider Preference, Public Authority Access Purchase, Recognition Purchase, Finance-Readiness Purchase, or Certification Purchase. 22.6.8(a) No restricted fund, grant, donation, sponsorship, or in-kind contribution closeout shall create donor control, sponsor control, funder control, provider preference, host preference, public authority access purchase, recognition purchase, maturity purchase, finance-readiness purchase, insurance-readiness purchase, certification purchase, protocol effect purchase, procurement advantage, technical validation purchase, or public claims advantage.
22.6.8(b) Closeout negotiations, settlement discussions, fund return, deliverable compromise, asset transfer, public acknowledgment, final report, or continuing archive shall not be used to extract public claims, alter evidence, suppress correction, influence public-safe publication, control data, obtain technical assets, or obtain preferred Nexus interface status.
22.6.8(c) Any pressure to exchange closeout cooperation for public claims, recognition, finance-readiness, certification, provider preference, Public Authority access, or asset transfer shall be treated as a conflict, influence, sponsorship, provider, or governance issue and escalated.
22.6.8(d) Closeout agreements shall include boundary language where risk exists.
22.6.8(e) The controlling rule shall be that support relationships end with records and obligations, not purchased authority.
22.6.9 Restricted Fund Closeout Records and Final Reports. 22.6.9(a) GCRI Canada shall maintain restricted fund closeout records and final reports.
22.6.9(b) Records shall identify fund, donor, grantor, sponsor, funder, restriction, opening balance, receipts, expenditures, deliverables, assets purchased, unspent funds, disposition, consent obtained, legal review, Board or lawful authority approval, final report, notice, public-safe communication, and closeout.
22.6.9(c) Final reports shall distinguish completed work, incomplete work, transferred work, discontinued work, archived work, withdrawn materials, corrected materials, and continuing obligations.
22.6.9(d) Final reports shall not overstate outputs, impact, public authority adoption, finance-readiness, certification, recognition, maturity, provider validation, sponsor validation, Nexus compatibility, or execution consequence.
22.6.9(e) Restricted fund records shall be retained according to law, restriction, grant terms, tax requirements, audit requirements, public-benefit need, legal hold, and records policy.
22.6.9(f) The controlling rule shall be that restricted fund closeout must be proven by records sufficient for trust, audit, and correction.
22.6.10 Restricted Fund, Grant, Donation, Sponsorship, and In-Kind Closeout Register. 22.6.10(a) GCRI Canada shall maintain a Restricted Fund, Grant, Donation, Sponsorship, and In-Kind Closeout Register if dissolution or material wind-up is initiated.
22.6.10(b) The Register shall identify each restricted fund, grant, donation, sponsorship, in-kind contribution, donor, grantor, sponsor, funder, restriction, balance, deliverables, assets, agreements, notices, approvals, required reports, unspent funds, return obligations, transfer obligations, re-purposing authority, public acknowledgment status, public claims review, data rights, IP rights, confidentiality obligations, final disposition, receipt, and closeout.
22.6.10(c) The Register shall link to fiscal records, asset distribution records, grant reports, donation records, sponsorship records, in-kind contribution records, contract records, publication records, public claims records, data disposition records, technical asset records, public materials closeout records, and final assurance records.
22.6.10(d) The Register shall be access-controlled where it contains donor information, confidential grant information, financial information, contract information, personal information, Public Authority information, finance-sensitive information, commercial information, or protected knowledge.
22.6.10(e) The controlling rule shall be that restricted support closeout must be registered because restricted support can otherwise become hidden liability or hidden influence.
22.7 Fiscal Closeout and Final Accounts
22.7.1 Final Accounts Shall Be Prepared According to Law, Accounting Requirements, Board Direction, and Public-Benefit Duties. 22.7.1(a) Final accounts shall be prepared according to applicable law, accounting requirements, tax requirements, nonprofit requirements, Board direction, lawful wind-up authority direction, restricted fund obligations, grant obligations, contract obligations, and public-benefit duties.
22.7.1(b) Final accounts shall present GCRI Canada’s assets, liabilities, revenues, expenses, restricted funds, unrestricted funds, reserves, receivables, payables, commitments, contingencies, asset dispositions, and final distributions.
22.7.1(c) Final accounts shall be prepared with sufficient detail to support filings, creditor processes where applicable, donor and grantor reporting, Board oversight, final assurance, archive, and public-safe fiscal integrity reporting where directed.
22.7.1(d) Final accounts shall not conceal liabilities, related-party transactions, restricted fund balances, sponsor obligations, provider obligations, grant obligations, donor restrictions, asset transfers, in-kind assets, or contingent obligations.
22.7.1(e) The controlling rule shall be that fiscal truth must be complete before institutional closeout.
22.7.2 Final Budget, Cash Flow, Liabilities, Receivables, Payables, Restricted Funds, Reserves, and Asset Disposition Records. 22.7.2(a) Fiscal closeout shall include final budget, wind-up budget, cash flow forecast, liabilities schedule, receivables schedule, payables schedule, restricted fund schedule, reserves schedule, asset disposition schedule, contingent liability schedule, and final distribution schedule.
22.7.2(b) The wind-up budget shall identify legal costs, accounting costs, filing costs, insurance costs, cybersecurity costs, archive costs, data disposition costs, technical asset disposition costs, public materials closeout costs, contract closeout costs, employment closeout costs, and final assurance costs.
22.7.2(c) Liabilities shall be classified as known, disputed, contingent, accrued, contractual, statutory, tax-related, employment-related, grant-related, donor-related, sponsorship-related, data-related, cyber-related, Public Authority-related, IP-related, litigation-related, or wind-up-related.
22.7.2(d) Asset disposition records shall reconcile fiscal records with the Asset Distribution Register and shall identify valuation, restriction status, approval, transfer, sale, return, destruction, archive, or retention.
22.7.2(e) The controlling rule shall be that fiscal closeout requires a complete map of money, obligations, and assets before final distribution.
22.7.3 Payment of Lawful Debts and Obligations. 22.7.3(a) GCRI Canada shall pay lawful debts and obligations according to applicable law, governing instruments, creditor requirements where applicable, contracts, employment obligations, tax obligations, court or regulator direction where applicable, and Board or lawful wind-up authority direction.
22.7.3(b) Payment priority shall be determined by law, creditor rights, restricted fund rules, secured obligations, statutory obligations, employment obligations, tax obligations, contract terms, and lawful wind-up process.
22.7.3(c) Payments shall be authorized, documented, conflict-reviewed where appropriate, supported by invoices or equivalent records, and reconciled.
22.7.3(d) Payments to Directors, Officers, members where applicable, employees, contractors, fellows, advisors, sponsors, providers, hosts, donors, funders, related parties, National Companies, Project SPVs, or other private actors shall receive heightened review where conflict, related-party, inurement, preferential treatment, or public trust risk exists.
22.7.3(e) The controlling rule shall be that lawful obligations may be paid, but final payments must not become disguised private benefit.
22.7.4 Settlement or Provision for Claims. 22.7.4(a) GCRI Canada shall identify, manage, settle, reserve for, insure against, or otherwise provide for claims according to law, contract, insurance, court process, regulator process, and Board or lawful wind-up authority direction.
22.7.4(b) Claims may include creditor claims, employee claims, contractor claims, grantor claims, donor claims, sponsor claims, provider claims, host claims, vendor claims, Public Authority claims, privacy claims, data claims, cybersecurity claims, IP claims, publication claims, public claims disputes, community safeguard claims, protected knowledge claims, tort claims, tax claims, regulatory claims, and litigation.
22.7.4(c) Settlement authority shall be written, limited, conflict-managed, legally reviewed where appropriate, and records-valid.
22.7.4(d) Settlements shall not suppress required correction, conceal public authority confusion, conceal finance overclaim, conceal data breach, conceal protected knowledge exposure, buy public claims, create sponsor control, create provider preference, or transfer public-good assets improperly.
22.7.4(e) The controlling rule shall be that claims closeout must manage liability without trading away public-good duties.
22.7.5 Tax Filings, Returns, Information Reports, Receipts, and Regulatory Filings Where Required. 22.7.5(a) GCRI Canada shall prepare and submit tax filings, returns, information reports, receipts, regulatory filings, corporate registry filings, employment filings, payroll filings, grant reports, donation reports, public authority reports, and final filings where required.
22.7.5(b) Filings shall address final fiscal period, asset distribution, restricted funds, receipts issued where applicable, charitable-status matters where applicable, nonprofit reporting, payroll, taxes withheld, tax slips, information returns, sales taxes where applicable, and other applicable reporting.
22.7.5(c) Receipts, donor records, grant records, and sponsorship records shall be reviewed for accuracy and correction before final filing where required.
22.7.5(d) Filing records, confirmations, correspondence, submissions, and approvals shall be archived.
22.7.5(e) The controlling rule shall be that fiscal and regulatory obligations continue through the final filing.
22.7.6 Audit, Review Engagement, Compilation, Internal Review, or Final Financial Review Where Required or Directed. 22.7.6(a) GCRI Canada shall conduct an audit, review engagement, compilation, internal review, final financial review, or equivalent fiscal assurance where required by law, Bylaw, Board direction, funder requirement, donor restriction, grant condition, Public Authority term, contract, court or regulator direction, or public-benefit duty.
22.7.6(b) The scope may include final accounts, restricted funds, grants, donations, sponsorships, in-kind contributions, related-party transactions, asset dispositions, liabilities, claims, tax filings, public-benefit distribution, anti-inurement, procurement, and final payments.
22.7.6(c) Review findings shall be recorded, corrected, disclosed where required, and included in final assurance.
22.7.6(d) Financial review shall not be described as certification, rating, guarantee, finance-readiness, public finance approval, or external endorsement unless properly authorized by the reviewer and accurate under law.
22.7.6(e) The controlling rule shall be that final fiscal assurance shall match legal, funder, and public trust risk.
22.7.7 Bank Account Closure, Signing Authority Revocation, Payment System Closure, and Financial System Archive. 22.7.7(a) Fiscal closeout shall include bank account closure, signing authority revocation, payment system closure, credit card cancellation, merchant account closure, donation platform closure, payroll system closure, accounting system archive, financial document archive, and financial access revocation.
22.7.7(b) Before closure, GCRI Canada shall ensure lawful debts, final payments, restricted fund dispositions, tax payments, payroll obligations, filing fees, archive costs, final assurance costs, and reserves for claims are addressed.
22.7.7(c) Signing authorities, account administrators, payment approvers, bookkeepers, accountants, and financial system users shall have access revoked or limited according to closeout status.
22.7.7(d) Financial systems shall be exported, archived, secured, retained, and access-controlled according to law, accounting requirements, privacy, cybersecurity, audit needs, legal hold, and final records requirements.
22.7.7(e) The controlling rule shall be that financial access shall close only after fiscal obligations are complete and records are secured.
22.7.8 Fraud, Error, Restricted Fund Breach, Private Benefit, or Related-Party Risk Review Before Final Distribution. 22.7.8(a) Before final distribution, GCRI Canada shall review for fraud, error, restricted fund breach, private benefit, private inurement, related-party risk, preferential transfer, duplicate payment, unauthorized payment, payment diversion, sanction or export-control issue, anti-bribery or anti-corruption issue, and financial-services boundary risk.
22.7.8(b) The review shall include final payments, asset transfers, restricted funds, grants, donations, sponsorships, in-kind contributions, procurement, related-party transactions, compensation, reimbursements, benefits, gifts, hospitality, travel, vendor payments, sponsor arrangements, provider arrangements, and National Company or Project SPV interfaces.
22.7.8(c) Suspected issues shall trigger hold, investigation, legal review, recovery, correction, disclosure where required, Board or lawful authority reporting, and final assurance.
22.7.8(d) Final distribution shall not proceed while material unresolved fraud, inurement, restricted fund, sanctions, export-control, or related-party issues remain without lawful disposition.
22.7.8(e) The controlling rule shall be that final distribution requires integrity review before assets leave institutional control.
22.7.9 Final Financial Records and Permanent Archive Where Lawful. 22.7.9(a) Final financial records shall be archived permanently or for the legally required and mission-appropriate period where lawful.
22.7.9(b) Final financial records shall include final accounts, ledgers, bank statements, reconciliations, budgets, restricted fund schedules, grant reports, donation records, sponsorship records, in-kind contribution records, invoices, receipts, tax filings, payroll records, asset disposition records, liability records, claim records, audit or review records, Board approvals, legal review records, and final assurance records.
22.7.9(c) Financial records shall be classified, retained, sealed, deleted where lawful and required, or archived according to law, accounting requirements, tax requirements, privacy, cybersecurity, confidentiality, legal hold, and public-safe publication discipline.
22.7.9(d) Public-safe fiscal summaries may be prepared where directed by the Board or lawful authority and where disclosure is lawful, accurate, and public-benefit aligned.
22.7.9(e) The controlling rule shall be that final financial records must survive dissolution sufficiently to evidence fiscal integrity.
22.7.10 Fiscal Closeout Register and Final Assurance. 22.7.10(a) GCRI Canada shall maintain a Fiscal Closeout Register and conduct final fiscal assurance if dissolution or material wind-up is initiated.
22.7.10(b) The Register shall identify final accounts, assets, liabilities, receivables, payables, restricted funds, grants, donations, sponsorships, reserves, claims, payments, filings, bank accounts, payment systems, signatories, financial systems, audits or reviews, findings, corrective actions, final distributions, archive status, and closeout.
22.7.10(c) Final fiscal assurance shall confirm that financial records are complete, lawful debts are addressed, restricted funds are resolved, filings are submitted, accounts are reconciled, conflicts are managed, related-party risks are reviewed, private inurement is avoided, financial systems are secured, and final records are archived.
22.7.10(d) Findings shall require correction, additional filing, recovery, disclosure where required, legal review, Board or lawful authority reporting, or delayed final distribution.
22.7.10(e) The controlling rule shall be that fiscal closeout is complete only when final accounts, final obligations, final controls, and final records align.
22.8 Contract, Liability, Insurance, and Claims Closeout
22.8.1 Contract Inventory and Closeout. 22.8.1(a) GCRI Canada shall prepare and maintain a contract inventory and closeout plan if dissolution or material wind-up is initiated.
22.8.1(b) The contract inventory shall identify agreements, parties, dates, terms, renewals, notices, termination rights, assignment rights, novation rights, transfer restrictions, payment obligations, deliverables, data rights, IP rights, confidentiality, publicity, audit rights, liability, indemnity, insurance, survival clauses, governing law, dispute resolution, and closeout owner.
22.8.1(c) Agreements shall include leases, services, cloud, repository, software, AI tool, data room, controlled room, clean room, vendor, provider, sponsor, grant, donation, university, Public Authority, host, research, data sharing, data processing, employment, contractor, consultant, licensing, IP, Nexus interface, National Company, Project SPV, and partnership-like instruments where applicable.
22.8.1(d) Each contract shall be classified for completion, termination, expiration, assignment, novation, transfer, continuation, settlement, or archive.
22.8.1(e) The controlling rule shall be that contracts must be inventoried before obligations can be closed.
22.8.2 Contract Assignment, Termination, Expiration, Novation, Transfer, or Continuation Where Lawful and Approved. 22.8.2(a) Contracts may be assigned, terminated, expired, novated, transferred, continued for wind-up purposes, or otherwise dispositioned only where lawful, permitted by contract, approved by proper authority, and consistent with dissolution requirements.
22.8.2(b) Assignment or novation shall identify assignor, assignee, consent requirements, transferred rights, transferred obligations, retained obligations, liabilities, data rights, IP rights, confidentiality, Public Authority terms, protected knowledge terms, public claims restrictions, and post-transfer correction duties.
22.8.2(c) Termination shall comply with notice periods, cure rights, final payment, deliverable handoff, return or deletion of data, return of property, confidentiality, IP, public claims, and survival clauses.
22.8.2(d) Continuation during wind-up shall be time-bound, purpose-bound, cost-controlled, and limited to lawful closeout needs.
22.8.2(e) The controlling rule shall be that contract disposition must be lawful, consent-aware, and records-valid.
22.8.3 Contractual Confidentiality, IP, Data, Publication, Publicity, Audit, Liability, Indemnity, Insurance, and Survival Clauses. 22.8.3(a) Contract closeout shall identify and preserve contractual confidentiality, IP, data, publication, publicity, audit, liability, indemnity, insurance, dispute resolution, governing law, record retention, and survival clauses.
22.8.3(b) Confidentiality obligations shall continue after dissolution where applicable and shall be assigned, retained, archived, or otherwise managed by lawful custodian.
22.8.3(c) IP and data clauses shall govern ownership, licenses, contributor rights, moral rights, data return, data deletion, data transfer, research data, public-good software, open release, controlled release, public-safe publication, and technical asset continuity.
22.8.3(d) Publication and publicity clauses shall be reviewed to correct, withdraw, or terminate use of names, logos, acknowledgments, Public Authority references, sponsor references, provider references, and public claims.
22.8.3(e) Audit, liability, indemnity, and insurance clauses shall be preserved for the period required by contract, law, insurance, legal hold, or risk.
22.8.3(f) The controlling rule shall be that contract survival obligations must survive institutional wind-up by record and custodian.
22.8.4 Lease, Service, Cloud, Repository, Software, Data Room, AI Tool, Vendor, Provider, Sponsor, Grant, University, Public Authority, Host, and Nexus Interface Agreements. 22.8.4(a) The contract closeout plan shall specifically review lease, service, cloud, repository, software, data room, AI tool, vendor, provider, sponsor, grant, university, Public Authority, host, and Nexus interface agreements.
22.8.4(b) Lease and facility agreements shall address notice, surrender, property return, equipment removal, physical records, devices, sensors, keys, badges, access cards, insurance, restoration, and security.
22.8.4(c) Cloud, repository, software, AI tool, data room, controlled room, and technical service agreements shall address export, archive, deletion, transfer, access revocation, key rotation, token revocation, billing termination, backup retention, incident response, and evidence of destruction where appropriate.
22.8.4(d) Provider, sponsor, grant, university, Public Authority, host, and Nexus interface agreements shall address role separation, public claims, data, IP, confidentiality, publicity, access rights, correction signals, closeout, and continuing obligations.
22.8.4(e) The controlling rule shall be that high-dependency contracts require domain-specific closeout, not generic termination.
22.8.5 Liability Identification, Claims Handling, Dispute Resolution, Settlement Authority, and Legal Review. 22.8.5(a) GCRI Canada shall identify liabilities, claims, disputes, threatened claims, contingent claims, unresolved obligations, indemnity demands, insurance matters, and potential legal exposures before final closeout.
22.8.5(b) Claims handling shall identify claim source, claimant, legal basis, factual basis, contract basis, insurance coverage, severity, defense strategy, settlement authority, confidentiality, records, legal hold, public-safe communication, and closeout.
22.8.5(c) Dispute resolution shall follow contract terms, law, Board or lawful wind-up authority direction, and legal review where appropriate.
22.8.5(d) Settlement authority shall be written, limited, conflict-managed, legally reviewed where appropriate, and shall not permit suppression of required correction, concealment of public authority confusion, concealment of finance overclaim, data misuse, protected knowledge exposure, private inurement, or public claims overreach.
22.8.5(e) The controlling rule shall be that claims must be resolved or lawfully provided for before final dissolution closeout.
22.8.6 Insurance Tail Coverage, Claims-Made Coverage, Cyber Coverage, D&O Coverage, E&O Coverage, General Liability, Event Coverage, and Other Coverage Where Appropriate. 22.8.6(a) GCRI Canada shall review insurance coverage during wind-up, including tail coverage, claims-made coverage, cyber coverage, Directors and Officers coverage, errors and omissions coverage, general liability coverage, event coverage, employment practices coverage, fiduciary coverage, property coverage, professional coverage, and other coverage where appropriate.
22.8.6(b) Insurance review shall identify policies, limits, exclusions, claims-made periods, notice obligations, tail availability, extended reporting periods, known claims, potential claims, incidents, cyber events, publication events, data events, Public Authority issues, employment issues, contract disputes, and coverage obligations.
22.8.6(c) Coverage decisions shall consider dissolution timeline, residual risk, legal requirements, Board and Officer protection, public trust, data breach risk, cybersecurity risk, publication risk, protected knowledge risk, and contractual obligations.
22.8.6(d) Failure to obtain available and appropriate tail or extended coverage where material risk exists shall be documented and reviewed.
22.8.6(e) The controlling rule shall be that insurance closeout must address claims that may arise after operations end.
22.8.7 Indemnification and Advancement Obligations Where Applicable. 22.8.7(a) GCRI Canada shall review indemnification and advancement obligations where applicable.
22.8.7(b) Review shall identify indemnified persons, governing instruments, Bylaw provisions, contracts, Director and Officer indemnities, employee indemnities, volunteer indemnities, committee indemnities, advisor indemnities, contractor indemnities, legal limits, exclusions, insurance interaction, and post-dissolution handling.
22.8.7(c) Indemnification and advancement shall not be used to protect fraud, bad faith, willful misconduct, private inurement, unauthorized conduct, or conduct outside lawful authority except to the extent required by law or governing instruments.
22.8.7(d) Indemnification records shall be preserved with final governance and insurance records.
22.8.7(e) The controlling rule shall be that lawful protection of persons serving GCRI Canada must be reconciled with accountability and legal limits.
22.8.8 Contract Closeout Shall Preserve Legal Separateness and Avoid Assumption of Unauthorized Liabilities. 22.8.8(a) Contract closeout shall preserve legal separateness and avoid assumption of unauthorized liabilities by GCRI Canada or by any GCRI, GRF, GRA, Protocol Authority, Nexus entity, Public Authority, National Company, Project SPV, sponsor, provider, host, university, community, or partner.
22.8.8(b) Assignment, novation, transfer, shared closeout, or coordinated wind-up shall include language preserving legal separateness, role separation, no agency, no partnership, no joint venture, no shared treasury, no shared employer status, no shared liability, and no authority transfer unless lawfully and expressly agreed.
22.8.8(c) GCRI Canada shall not assume liabilities of GCRI US, GRF, GRA, Protocol Authority, Nexus entities, National Companies, Project SPVs, providers, sponsors, hosts, Public Authorities, universities, or partners by implication.
22.8.8(d) Other entities shall not be described as assuming GCRI Canada liabilities unless lawful, approved, documented, and contractually effective.
22.8.8(e) The controlling rule shall be that coordination in closeout shall not become liability fusion.
22.8.9 Contract, Liability, Insurance, and Claims Closeout Records. 22.8.9(a) GCRI Canada shall maintain contract, liability, insurance, and claims closeout records.
22.8.9(b) Records shall identify contracts, obligations, notices, terminations, assignments, novations, transfers, settlements, releases, disputes, claims, liabilities, insurance policies, claims notices, coverage determinations, indemnification matters, legal reviews, approvals, final payments, continuing obligations, and archive status.
22.8.9(c) Records shall include confidentiality, IP, data, publication, publicity, audit, liability, indemnity, insurance, and survival obligations.
22.8.9(d) Records shall be retained according to law, contract, legal hold, insurance needs, tax needs, audit needs, privacy, cybersecurity, Public Authority sensitivity, protected knowledge, and public-benefit purposes.
22.8.9(e) The controlling rule shall be that contract and liability closeout must remain provable after counterparties and systems change.
22.8.10 Contract Closeout Register. 22.8.10(a) GCRI Canada shall maintain a Contract Closeout Register if dissolution or material wind-up is initiated.
22.8.10(b) The Register shall identify contract, counterparty, owner, custodian, agreement type, status, termination date, assignment, novation, transfer, continuation, final payment, data obligations, IP obligations, confidentiality obligations, publicity obligations, audit rights, liability provisions, indemnity provisions, insurance requirements, survival clauses, notices, disputes, settlement status, legal review status, archive location, and closeout.
22.8.10(c) The Register shall link to financial closeout records, data disposition records, technical asset records, Public Authority records, sponsor records, provider records, grant records, employment records, insurance records, claims records, Nexus interface closeout records, and final assurance records.
22.8.10(d) The Register shall be access-controlled where it contains confidential, privileged, personal, Public Authority-sensitive, finance-sensitive, commercially sensitive, employment-sensitive, cyber-sensitive, or protected knowledge materials.
22.8.10(e) The controlling rule shall be that contract closeout must be registered because contracts are continuing obligations even when operations end.
22.9 Employment, Contractor, Fellow, Advisor, Volunteer, and Participant Closeout
22.9.1 Workforce Closeout Shall Comply With Applicable Employment, Contractor, Tax, Workplace, Privacy, and Contractual Obligations. 22.9.1(a) Workforce closeout shall comply with applicable employment, contractor, volunteer, fellowship, internship, student, advisor, tax, workplace, privacy, human rights, accessibility, occupational health and safety, immigration, work authorization, benefits, payroll, contract, confidentiality, IP, data, cybersecurity, and non-retaliation obligations.
22.9.1(b) Closeout shall be humane, lawful, records-valid, non-retaliatory, non-discriminatory, accessible, and consistent with public-benefit duties.
22.9.1(c) GCRI Canada shall identify affected persons, legal status, engagement terms, notice obligations, payment obligations, benefit obligations, tax obligations, access rights, confidentiality duties, IP duties, public claims limits, data duties, and continuing obligations.
22.9.1(d) Workforce closeout shall be coordinated with fiscal closeout, contract closeout, records closeout, data disposition, cybersecurity closeout, technical asset closeout, and public materials closeout.
22.9.1(e) The controlling rule shall be that people do not become administrative residue during dissolution.
22.9.2 Employees, Contractors, Fellows, Advisors, Volunteers, Interns, Students, Council Participants, Committee Participants, Working Group Participants, Contributors, and Other Participants. 22.9.2(a) Workforce and participant closeout shall cover employees, contractors, fellows, advisors, volunteers, interns, students, residents, scholars, trainees, council participants, committee participants, Working Group participants, technical task force participants, contributors, maintainers, reviewers, panelists, community participants, public authority participants where applicable, university participants, and other persons with roles in GCRI Canada.
22.9.2(b) Each person or role category shall be reviewed for engagement status, authority, access rights, records responsibilities, confidentiality obligations, data obligations, AI-use limits, cybersecurity obligations, IP obligations, public claims limits, equipment custody, payment obligations, and closeout duties.
22.9.2(c) Persons with access to sensitive systems, controlled rooms, repositories, Public Authority Data, finance-sensitive materials, technical assets, protected knowledge, or public claims authority shall receive heightened closeout review.
22.9.2(d) Advisory, committee, council, fellowship, and contributor roles shall be ended, transferred, archived, or otherwise dispositioned by record.
22.9.2(e) The controlling rule shall be that every role with access, authority, or public meaning requires closeout.
22.9.3 Notice, Final Compensation, Benefits, Stipends, Reimbursements, Taxes, Records, Return of Property, Confidentiality, IP, Data, AI, Cybersecurity, Access Revocation, and Continuing Obligations. 22.9.3(a) Workforce and participant closeout shall address notice, final compensation, benefits, stipends, reimbursements, taxes, withholdings, tax slips, expense claims, records, return of property, device return, badge return, access return, confidentiality, IP, moral rights, data, AI-use limits, cybersecurity, public claims, conflicts, non-retaliation, grievances, and continuing obligations.
22.9.3(b) Final payments shall be lawful, documented, tax-compliant, conflict-reviewed where appropriate, and not used as disguised private benefit, settlement without authority, or silence payment.
22.9.3(c) Return of property shall include devices, storage media, keys, access cards, badges, documents, records, controlled materials, Public Authority materials, sponsor materials, provider materials, protected knowledge materials, and technical assets.
22.9.3(d) Continuing obligations shall include confidentiality, data protection, IP, non-disparagement only where lawful and appropriate, public claims restrictions, protected knowledge obligations, non-retaliation, legal hold, cooperation with audits or investigations where lawful, and correction duties where applicable.
22.9.3(e) The controlling rule shall be that closeout must settle rights and duties without suppressing lawful accountability or correction.
22.9.4 Access Revocation for Systems, Repositories, Data Rooms, Controlled Rooms, Cloud Environments, Dashboards, APIs, AI Tools, Communication Tools, and Physical Locations. 22.9.4(a) Access revocation shall be completed for systems, repositories, data rooms, controlled rooms, clean rooms, evidence rooms, Public Authority rooms, capital-reader rooms, no-download rooms, cloud environments, dashboards, maps, APIs, AI tools, compute environments, communication tools, collaboration tools, finance systems, HR systems, publication systems, domains, social media accounts, package registries, physical locations, devices, and field equipment.
22.9.4(b) Revocation shall be role-based, time-bound, records-valid, and coordinated with preservation of records, legal hold, data disposition, technical asset continuity, and operational closeout.
22.9.4(c) Access needed for lawful wind-up shall be reauthorized under wind-up delegation, limited to closeout purpose, logged where appropriate, and revoked at closeout.
22.9.4(d) External participants shall not retain access to GCRI Canada systems or materials after role closeout unless lawful, documented, mission-compatible, and necessary for approved wind-up purposes.
22.9.4(e) The controlling rule shall be that access must end when authority ends.
22.9.5 Credential, Token, Key, Secret, Badge, Device, and Account Revocation. 22.9.5(a) Credential, token, key, secret, badge, device, and account revocation shall be completed as part of workforce and participant closeout.
22.9.5(b) Revocation shall include passwords, multi-factor authentication, recovery codes, API keys, service tokens, repository tokens, AI tool tokens, cloud credentials, signing keys, wallet keys where applicable, SSH keys, encryption keys, hardware keys, badges, devices, mobile devices, storage media, accounts, mailing lists, shared drives, and administrative access.
22.9.5(c) Shared accounts shall be prohibited for material systems except where legacy or emergency systems require controlled transition; any such exception shall be documented and closed.
22.9.5(d) Key rotation, token revocation, secret destruction, device wipe, device transfer, or forensic preservation shall be conducted according to cybersecurity, records, legal hold, and data rules.
22.9.5(e) The controlling rule shall be that credentials are institutional control points and must not outlive role authority.
22.9.6 Public Claims and Post-Closeout Statements by Former Participants. 22.9.6(a) GCRI Canada shall govern public claims and post-closeout statements by former participants where such statements reference GCRI Canada, its materials, roles, programs, Public Authority interfaces, sponsors, providers, Nexus interfaces, technical assets, reports, dashboards, maps, datasets, public-good software, or public authority learning.
22.9.6(b) Former participants may accurately state historical role, title, period of service, and contributions where such statements are truthful, non-misleading, records-supported, and consistent with confidentiality, data, IP, public claims, Public Authority, finance-boundary, protected knowledge, and public-safe obligations.
22.9.6(c) Former participants shall not claim current authority, continued representation, certification authority, recognition authority, finance-readiness authority, public authority approval, procurement advantage, provider preference, sponsor validation, Nexus-compatible status, or execution authority unless proper records and authority exist.
22.9.6(d) Unauthorized or misleading post-closeout claims shall be corrected, withdrawn, publicly clarified, or legally addressed where appropriate.
22.9.6(e) The controlling rule shall be that former participation may be described honestly but shall not become continuing authority.
22.9.7 Alumni, Former Fellow, Former Advisor, Former Council, Former Contributor, and Former Staff References Shall Be Accurate and Non-Inflated. 22.9.7(a) Alumni, former fellow, former advisor, former council, former committee, former Working Group, former contributor, former maintainer, former contractor, former volunteer, former intern, former student, and former staff references shall be accurate and non-inflated.
22.9.7(b) References shall identify historical capacity, dates where appropriate, role limitations, and whether the person no longer acts for GCRI Canada.
22.9.7(c) References shall not imply current endorsement, current authority, fiduciary status, Public Authority role, certification authority, finance-readiness authority, provider status, sponsor role, procurement role, Nexus authority, or execution authority.
22.9.7(d) Public alumni or former participant lists shall be reviewed for privacy, consent where applicable, accuracy, accessibility, public claims risk, and correction path.
22.9.7(e) The controlling rule shall be that affiliation history shall not be inflated into status.
22.9.8 Grievances, Complaints, Disputes, and Non-Retaliation During Closeout. 22.9.8(a) GCRI Canada shall preserve grievance, complaint, dispute, whistleblower, challenge, and non-retaliation pathways during workforce and participant closeout to the extent lawful and practicable.
22.9.8(b) Grievances may concern compensation, classification, harassment, discrimination, retaliation, confidentiality, IP, data access, protected knowledge, public claims, authorship, attribution, termination, access revocation, safety, or misconduct.
22.9.8(c) Complaints and disputes shall be triaged, recorded, investigated where appropriate, resolved or transferred to a lawful custodian, and linked to legal hold, records retention, and final assurance where material.
22.9.8(d) Dissolution shall not be used to retaliate, suppress claims, destroy evidence, avoid correction, or defeat lawful rights.
22.9.8(e) The controlling rule shall be that closeout must remain fair and accountable even when institutional operations are ending.
22.9.9 Workforce and Participant Closeout Records. 22.9.9(a) GCRI Canada shall maintain workforce and participant closeout records.
22.9.9(b) Records shall identify persons, roles, status, notice, final payments, benefits, reimbursements, tax records, property return, access revocation, credential revocation, confidentiality obligations, IP obligations, data obligations, AI-use obligations, cybersecurity obligations, public claims obligations, grievances, disputes, acknowledgments, and closeout.
22.9.9(c) Records shall be classified and retained according to employment law, tax law, contract obligations, privacy, cybersecurity, legal hold, human rights, insurance, and institutional record requirements.
22.9.9(d) Access to workforce records shall be limited to authorized persons and protected against unauthorized disclosure.
22.9.9(e) The controlling rule shall be that people-closeout records must protect both institutional accountability and personal privacy.
22.9.10 Workforce and Participant Closeout Register. 22.9.10(a) GCRI Canada shall maintain a Workforce and Participant Closeout Register if dissolution or material wind-up is initiated.
22.9.10(b) The Register shall identify person or role category, legal status, engagement type, notice status, final payment status, benefits status, reimbursement status, tax record status, access revocation status, credential revocation status, property return status, confidentiality status, IP status, data status, AI-use status, cybersecurity status, public claims status, grievance status, dispute status, continuing obligations, and closeout.
22.9.10(c) The Register shall link to HR records, contract records, payroll records, access records, cybersecurity records, repository records, data access records, AI use records, technical asset records, public claims records, grievance records, legal hold records, and final assurance records.
22.9.10(d) The Register shall be access-controlled and privacy-protected.
22.9.10(e) The controlling rule shall be that workforce and participant closeout must be registered because people carry access, memory, obligations, and public meaning.
22.10 Data Disposition
22.10.1 Data Disposition Plan Required for All Material Data Holdings. 22.10.1(a) A Data Disposition Plan shall be required for all material data holdings in dissolution, wind-up, dormancy, program closeout, technical asset retirement, or material transfer.
22.10.1(b) The Data Disposition Plan shall cover personal information, rights-bearing data, health-sensitive data, Public Authority Data, cyber-sensitive data, infrastructure-sensitive data, finance-sensitive data, commercially sensitive data, research data, evidence data, Observatory data, Truth Engine data, AI data, model data, embedding stores, retrieval sources, logs, backups, archives, derived data, public datasets, public-safe datasets, controlled datasets, restricted datasets, community-protected data, and Protected Knowledge.
22.10.1(c) The Plan shall identify whether data will be returned, transferred, retained, archived, sealed, deleted, destroyed, de-identified, aggregated, converted into synthetic form, public-safely released, or otherwise dispositioned.
22.10.1(d) No material data disposition shall occur without lawful authority, classification, owner review, custodian review, public-safe review where required, cybersecurity review where required, Public Authority review where required, protected knowledge review where required, and records.
22.10.1(e) The controlling rule shall be that data disposition requires a plan because data obligations survive operational endings.
22.10.2 Data Inventory, Classification, Owner, Custodian, Lawful Basis, Retention Requirement, Deletion Requirement, Transfer Eligibility, Archive Eligibility, Sealing Requirement, and Legal Hold Status. 22.10.2(a) Data disposition shall begin with a data inventory and classification review.
22.10.2(b) For each data holding, GCRI Canada shall identify dataset or data asset name, owner, custodian, source, lawful basis, purpose, classification, sensitivity, rights-bearing status, Public Authority status, protected knowledge status, contract status, consent or non-consent status where applicable, retention requirement, deletion requirement, transfer eligibility, archive eligibility, sealing requirement, legal hold status, access rights, AI-use restrictions, publication limits, and correction path.
22.10.2(c) The inventory shall identify locations, systems, repositories, storage accounts, backups, logs, embeddings, retrieval indexes, model stores, dashboards, maps, APIs, exports, offline copies, local devices, cloud systems, data rooms, controlled rooms, and third-party processors.
22.10.2(d) Data without identifiable authority, source, lawful basis, classification, owner, or custodian shall be quarantined, reviewed, corrected, deleted, sealed, or otherwise dispositioned according to law and risk.
22.10.2(e) The controlling rule shall be that GCRI Canada cannot lawfully disposition data it has not first identified and classified.
22.10.3 Personal Information Disposition. 22.10.3(a) Personal information shall be dispositioned according to applicable privacy law, data protection law, lawful basis, consent where applicable, notice obligations, contract obligations, retention requirements, deletion requirements, access rights, correction rights, legal hold, and public-benefit obligations.
22.10.3(b) Personal information includes identity, contact, location, device, employment, contractor, volunteer, fellow, advisor, participant, donor, sponsor, provider, Public Authority participant, research participant, community participant, financial, health-related, biometric, communication, access-log, and vulnerable person information.
22.10.3(c) Disposition may include deletion, return, transfer, archive, sealing, de-identification, aggregation, or retention under legal hold, provided the method is lawful, necessary, secure, and recorded.
22.10.3(d) Personal information shall not be retained merely because deletion is inconvenient, transferred to a recipient lacking lawful authority and safeguards, included in public materials, used for AI training, embedded in retrieval systems, or archived without retention authority.
22.10.3(e) Where individuals have applicable rights of access, correction, deletion, restriction, objection, portability, or complaint, GCRI Canada shall preserve a lawful pathway during wind-up or transfer responsibility to an authorized custodian where appropriate.
22.10.3(f) The controlling rule shall be that personal information remains rights-bearing until lawfully dispositioned.
22.10.4 Health-Sensitive Data Disposition. 22.10.4(a) Health-sensitive data shall receive heightened disposition safeguards.
22.10.4(b) Health-sensitive data may include health, public health, biosecurity, clinical, sensor, mobility, environmental health, wastewater, vulnerability, population health, research participant, and health-related Public Authority Data.
22.10.4(c) Disposition shall comply with applicable health privacy law, research ethics, consent terms, Public Authority terms, data agreements, grant terms, retention rules, deletion rules, legal holds, de-identification requirements, and public-safe publication rules.
22.10.4(d) Health-sensitive data shall not be transferred, archived, published, mapped, released, trained on, embedded, or reused unless lawful authority, safeguards, recipient capacity, purpose limitation, and records exist.
22.10.4(e) Public-safe summaries may be used only where aggregation, de-identification, suppression, generalization, and public-safe review prevent individual, group, community, or public health harm.
22.10.4(f) The controlling rule shall be that health-sensitive data must be closed with heightened dignity, privacy, and harm-prevention controls.
22.10.5 Public Authority Data Disposition. 22.10.5(a) Public Authority Data shall be dispositioned according to applicable law, Public Authority terms, data contribution records, data sharing agreements, confidentiality obligations, public-safe review, cybersecurity requirements, retention rules, deletion rules, transfer limits, localization requirements, and sovereign data controls.
22.10.5(b) Public Authority Data disposition shall identify the contributing Public Authority, jurisdiction, capacity, permitted use, prohibited use, access class, AI-use limits, publication limits, transfer rights, return obligations, deletion obligations, archive rights, correction rights, and notice requirements.
22.10.5(c) Public Authority Data in dashboards, maps, evidence packs, publications, public authority learning materials, Observatory outputs, Truth Engine outputs, AI systems, or public-safe summaries shall be corrected, withdrawn, archived, transferred, returned, sealed, or deleted according to the Public Authority terms and public-safe status.
22.10.5(d) Public Authority Data disposition shall not imply endorsement, adoption, public warning, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, sovereign obligation, or Public Authority delegation.
22.10.5(e) The controlling rule shall be that Public Authority Data must be returned, retained, transferred, or destroyed only within the authority under which it was received.
22.10.6 Cyber-Sensitive Data Disposition. 22.10.6(a) Cyber-sensitive data shall receive heightened disposition safeguards.
22.10.6(b) Cyber-sensitive data may include vulnerability information, threat intelligence, incident records, logs, credentials, access records, security architecture, penetration testing results, red-team materials, repository security findings, dependency vulnerabilities, SBOMs, keys, tokens, secrets, cryptographic materials, exploit details, and security-sensitive technical notes.
22.10.6(c) Disposition shall include classification, legal review where appropriate, cybersecurity review, retention under legal hold where applicable, secure deletion, secure archive, access revocation, key rotation, secret destruction, transfer restrictions, and incident-risk review.
22.10.6(d) Cyber-sensitive data shall not be publicly released, transferred to unqualified recipients, included in public reports, used in AI tools, stored in uncontrolled repositories, or archived without access controls.
22.10.6(e) Public-safe cybersecurity summaries may be released only where they avoid exploitability, infrastructure targeting, credential exposure, incident-response compromise, or public harm.
22.10.6(f) The controlling rule shall be that cyber-sensitive data must be closed as a security asset, not merely as information.
22.10.7 Infrastructure-Sensitive Data Disposition. 22.10.7(a) Infrastructure-sensitive data shall receive heightened disposition safeguards.
22.10.7(b) Infrastructure-sensitive data may include locations, vulnerabilities, operating conditions, dependencies, maps, sensor readings, geospatial layers, digital twin outputs, facility details, supply chain details, network details, energy systems data, water systems data, food systems data, health infrastructure data, telecommunications data, transportation data, emergency management data, and critical infrastructure indicators.
22.10.7(c) Disposition shall include public-safe mapping review, resolution reduction where appropriate, generalization, redaction, access restriction, transfer review, recipient capacity review, Public Authority review where required, cybersecurity review, and legal review where appropriate.
22.10.7(d) Infrastructure-sensitive data shall not be transferred, published, mapped, archived, or released in a manner that increases targeting, sabotage, exploitation, public panic, community harm, or Public Authority harm.
22.10.7(e) The controlling rule shall be that infrastructure-sensitive data must be dispositioned to prevent physical, cyber, operational, and public safety harm.
22.10.8 Finance-Sensitive and Commercially Sensitive Data Disposition. 22.10.8(a) Finance-sensitive and commercially sensitive data shall be dispositioned according to law, contract, confidentiality, competition safety, finance-boundary controls, Public Authority terms where applicable, grant terms, sponsor terms, provider terms, and records requirements.
22.10.8(b) Finance-sensitive data may include budgets, cost models, capital-reader materials, GRA interface materials, Proof Pack inputs, public finance reader materials, underwriting-adjacent information, insurance-adjacent information, financial projections, project economics, valuation materials, procurement-sensitive information, grant finance, and sponsor finance information.
22.10.8(c) Commercially sensitive data may include trade secrets, vendor information, provider data, sponsor data, host data, technical pricing, proprietary specifications, competitive information, confidential proposals, contract terms, and market-sensitive information.
22.10.8(d) Disposition shall avoid investment advice implication, finance-readiness implication, rating implication, guarantee implication, public finance approval implication, procurement advantage, competition breach, provider preference, sponsor control, or confidential information exposure.
22.10.8(e) The controlling rule shall be that finance-sensitive and commercial data must be closed without creating market signals or unfair advantage.
22.10.9 Community-Protected and Protected Knowledge Data Disposition. 22.10.9(a) Community-protected and Protected Knowledge data shall receive heightened disposition safeguards.
22.10.9(b) Such data may include community-protected data, Indigenous Knowledge, Local Knowledge, Territorial Knowledge, Cultural Knowledge, Environmental Knowledge, sacred or sensitive site information, community vulnerability information, protected person information, traditional ecological knowledge, cultural protocols, local observations, community review records, grievance records, and public-safe mapping records.
22.10.9(c) Disposition shall follow applicable law, community protocols, data sovereignty principles where applicable, consent and non-consent pathways where applicable, protected knowledge agreements, access restrictions, public-safe review, and remedy obligations.
22.10.9(d) Protected Knowledge shall not be transferred, archived, published, mapped, trained on, embedded, commercialized, or destroyed contrary to lawful authority, community protocol, protected knowledge obligation, or public-benefit safeguard.
22.10.9(e) Affected communities shall receive notice, consultation, return, deletion, sealing, archive, transfer information, or remedy pathway where required or appropriate.
22.10.9(f) The controlling rule shall be that protected knowledge shall not become exposed, orphaned, extracted, or enclosed because GCRI Canada is dissolving.
22.10.10 Research Data, Evidence Data, Observatory Data, Truth Engine Data, AI Data, Model Data, Embedding Stores, Logs, Backups, Archives, and Derived Data Disposition. 22.10.10(a) Research data, evidence data, Observatory data, Truth Engine data, AI data, model data, embedding stores, retrieval sources, prompts, outputs, inference records, logs, backups, archives, derived data, synthetic data, aggregated data, redacted data, and metadata shall be dispositioned according to classification, lawful basis, research ethics, data rights, retention rules, deletion rules, legal holds, Public Authority terms, community safeguards, protected knowledge protocols, cybersecurity rules, and public-safe publication controls.
22.10.10(b) Research and evidence data shall preserve provenance, source lineage, method records, consent where applicable, ethics conditions, limitation notes, correction path, and retention or deletion obligations.
22.10.10(c) Observatory and Truth Engine data shall preserve confidence, uncertainty, source status, public-safe status, dashboard status, map status, correction signals, and downstream dependency review.
22.10.10(d) AI data and model-related records shall identify training restrictions, fine-tuning restrictions, embedding restrictions, retrieval authority, vendor processing, logs, inference records, output retention, deletion obligations, and leakage risks.
22.10.10(e) Backups and archives shall not become loopholes for retaining data that must be deleted, sealed, returned, or access-restricted.
22.10.10(f) The controlling rule shall be that derived and technical data must be dispositioned with the same seriousness as source data where it carries rights, risk, or public meaning.
22.10.11 Deletion, Return, Transfer, Sealing, Archive, De-Identification, Aggregation, or Destruction According to Law and Authority. 22.10.11(a) Data may be deleted, returned, transferred, sealed, archived, de-identified, aggregated, converted to synthetic data, securely destroyed, or retained under legal hold only according to law, authority, classification, purpose, consent where applicable, Public Authority terms, community protocols, contract obligations, retention requirements, deletion requirements, and public-benefit safeguards.
22.10.11(b) Deletion shall be secure, documented, and applied to active systems, repositories, devices, exports, backups where feasible and lawful, logs where appropriate, embeddings where feasible, retrieval stores, and third-party systems according to retention and legal hold requirements.
22.10.11(c) Return or transfer shall require recipient authority, recipient capacity, transfer instrument, data protection terms, cybersecurity controls, Public Authority approval where required, protected knowledge safeguards, cross-border review, and receipt.
22.10.11(d) Sealing and archive shall identify custodian, access class, retention period, legal hold status, conditions for access, correction path, and eventual disposition.
22.10.11(e) De-identification, aggregation, and synthetic transformation shall be reviewed for re-identification risk, linkage attack, mosaic effect, group harm, community harm, and public-safe release risk.
22.10.11(f) The controlling rule shall be that disposition method must match the data’s legal status, risk, and continuing obligations.
22.10.12 Data Disposition Certificates, Logs, and Final Register. 22.10.12(a) GCRI Canada shall maintain data disposition certificates, logs, and a final Data Disposition Register.
22.10.12(b) Disposition certificates and logs shall identify data asset, owner, custodian, source, classification, lawful basis, disposition method, authority, reviewer, date, system, repository, third-party processor, deletion evidence, transfer receipt, archive location, sealing status, legal hold status, Public Authority approval where required, community or protected knowledge approval where required, cybersecurity review, and closeout.
22.10.12(c) The final Data Disposition Register shall identify all material data holdings and their final disposition status, including returned, transferred, retained, archived, sealed, deleted, destroyed, de-identified, aggregated, public-safely released, or held under legal hold.
22.10.12(d) The Register shall link to privacy records, Public Authority Data records, research records, evidence records, AI records, cybersecurity records, technical asset records, community safeguard records, protected knowledge records, contract records, grant records, archive records, and final assurance records.
22.10.12(e) Data disposition records shall be retained according to law, legal hold, public-benefit need, privacy, cybersecurity, Public Authority terms, protected knowledge safeguards, and records policy.
22.10.12(f) The controlling rule shall be that data disposition is not complete until the disposition record proves what happened to the data, why it was lawful, and who remains responsible where any responsibility survives.
22.11 Public Authority Data and Material Disposition
22.11.1 Public Authority Data Shall Be Disposed According to Public Authority Terms, Law, Confidentiality, Classification, Permitted Use, Retention, Transfer, Publication, and Correction Obligations. 22.11.1(a) Public Authority Data and Public Authority materials shall be disposed according to applicable law, Public Authority terms, data contribution records, data sharing agreements, confidentiality obligations, classification, permitted use, prohibited use, retention obligations, deletion obligations, transfer restrictions, publication restrictions, correction obligations, cybersecurity requirements, localization requirements, sovereign data requirements, and public-safe review.
22.11.1(b) Public Authority Data shall include data, documents, records, dashboards, maps, reports, evidence packs, room materials, correspondence, meeting records, attendance records, comments, technical inputs, Public Authority learning materials, Public Authority references, and any other materials contributed by, derived from, or associated with a Public Authority.
22.11.1(c) Public Authority materials shall not be retained, transferred, archived, sealed, deleted, destroyed, published, summarized, trained on, embedded, retrieved, mapped, or reused unless lawful authority, Public Authority terms, classification review, access controls, public-safe review where required, and records exist.
22.11.1(d) Public Authority Data disposition shall preserve no Public Authority delegation, no endorsement, no adoption, no official guidance, no public warning, no emergency command, no regulatory approval, no procurement approval, no funding approval, no public finance approval, no sovereign obligation, and no public-private partnership by implication.
22.11.1(e) The controlling rule shall be that Public Authority Data must leave GCRI Canada’s active control with the same or greater discipline under which it entered.
22.11.2 Public Authority Materials Inventory. 22.11.2(a) GCRI Canada shall prepare a Public Authority materials inventory before disposition of Public Authority Data or materials.
22.11.2(b) The inventory shall identify Public Authority entity, jurisdiction, participant, capacity classification, authority source, material type, source, owner, custodian, classification, access class, permitted use, prohibited use, confidentiality status, Public Authority terms, data terms, AI-use limits, publication limits, retention requirement, deletion requirement, transfer eligibility, archive eligibility, sealing requirement, legal hold status, correction path, and final disposition.
22.11.2(c) The inventory shall include Public Authority Data in repositories, dashboards, maps, datasets, evidence packs, technical notes, reports, AI systems, model inputs, embedding stores, retrieval sources, logs, backups, controlled rooms, data rooms, Public Authority rooms, communication systems, public authority learning materials, public-safe summaries, and public materials.
22.11.2(d) Public Authority materials lacking clear source, authority, terms, classification, or custodian shall be quarantined and reviewed before any disposition.
22.11.2(e) The controlling rule shall be that no Public Authority material shall be closed, transferred, deleted, or archived until it is identified and classified.
22.11.3 Public Authority Data Return, Deletion, Sealing, Archive, or Transfer. 22.11.3(a) Public Authority Data may be returned, deleted, sealed, archived, transferred, retained under legal hold, or otherwise dispositioned only according to applicable law, Public Authority terms, authority records, classification, data sharing agreements, confidentiality obligations, cybersecurity requirements, retention rules, and public-safe review.
22.11.3(b) Return shall identify recipient, authority, transfer method, data scope, security method, receipt, residual copies, backups, logs, and continuing obligations.
22.11.3(c) Deletion shall be secure, documented, and applied to active systems, repositories, devices, exports, dashboards, maps, datasets, AI retrieval stores, embeddings where feasible and lawful, logs where appropriate, backups where feasible and lawful, and third-party systems where applicable.
22.11.3(d) Sealing and archive shall identify custodian, legal basis, access class, retention period, access conditions, Public Authority approval where required, correction path, and eventual disposition.
22.11.3(e) Transfer shall require recipient authority, recipient capacity, data protection terms, cybersecurity controls, Public Authority approval where required, cross-border review, sovereign data review, legal review where appropriate, and receipt.
22.11.3(f) The controlling rule shall be that Public Authority Data disposition must be evidenced by the authority, method, recipient, residual-copy treatment, and continuing obligation.
22.11.4 Public Authority Dashboard, Map, Report, Evidence Pack, Room, and Data Contribution Closeout. 22.11.4(a) GCRI Canada shall close out Public Authority dashboards, maps, reports, evidence packs, controlled rooms, data rooms, Public Authority rooms, capital-reader rooms involving Public Authority materials, learning rooms, and Public Authority data contributions.
22.11.4(b) Dashboard and map closeout shall identify data sources, Public Authority contributions, access lists, publication status, public-safe status, update status, stale-data warnings, archive status, withdrawal status, correction path, and whether public or controlled notices are required.
22.11.4(c) Report and evidence pack closeout shall identify source lineage, Public Authority contribution status, permitted use, confidentiality, Public Authority review, publication limits, correction status, supersession status, archive status, and recipient obligations.
22.11.4(d) Room closeout shall identify participant access, attendance logs, materials index, data contributions, downloads where permitted, no-download compliance, AI-use compliance, output records, correction signals, access revocation, and archive.
22.11.4(e) Public Authority data contribution closeout shall identify whether data is returned, deleted, sealed, archived, transferred, retained, or transformed into public-safe summary under lawful authority.
22.11.4(f) The controlling rule shall be that Public Authority materials embedded in outputs and rooms must be closed at the output level, not only at the source-file level.
22.11.5 Public Authority Reference Closeout for Names, Logos, Titles, Quotes, Photographs, Attendance, and Data Contributions. 22.11.5(a) GCRI Canada shall close out Public Authority references concerning names, logos, titles, agency names, jurisdiction names, quotes, photographs, attendance, data contributions, room participation, dashboard access, map access, public authority learning participation, public-safe reports, and related public materials.
22.11.5(b) Reference closeout shall identify approved wording, approval duration, permitted channel, attribution limits, logo-use limits, quote-use limits, photo-use limits, attendance description, data contribution description, capacity language, boundary language, termination requirements, correction requirements, and archive status.
22.11.5(c) References shall be removed, corrected, archived, superseded, withdrawn, or public-safely clarified where dissolution, wind-up, program closeout, material change, or Public Authority request changes the context of reliance.
22.11.5(d) Public Authority references shall not continue to imply endorsement, adoption, official guidance, public warning, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, public-private partnership, sovereign obligation, or Public Authority delegation.
22.11.5(e) The controlling rule shall be that Public Authority names and offices shall not become orphaned public claims after closeout.
22.11.6 Public Authority Notices Where Required. 22.11.6(a) GCRI Canada shall provide Public Authority notices where required by law, agreement, Public Authority terms, data contribution records, confidentiality obligations, public-safe communication discipline, incident response duties, correction duties, or public trust.
22.11.6(b) Notices may address dissolution, wind-up, program closeout, data disposition, dashboard closeout, map closeout, room closeout, evidence pack closeout, report closeout, technical asset transfer, public material correction, Public Authority reference change, breach, incident, legal hold, or archive.
22.11.6(c) Notices shall identify affected materials, authority, proposed disposition, timing, Public Authority action requested where any, confidentiality treatment, public-safe status, access changes, correction path, and continuing obligations.
22.11.6(d) Notices shall be controlled where public notice would disclose confidential Public Authority information, security-sensitive information, infrastructure-sensitive information, personal information, finance-sensitive information, cyber-sensitive information, community-protected information, or Protected Knowledge.
22.11.6(e) The controlling rule shall be that Public Authorities shall receive notice where their data, name, reliance, or obligations are affected, but notice shall not create GCRI Canada public authority power.
22.11.7 Public Authority Records Retained for Legal, Audit, and Historical Purposes Only Where Lawful. 22.11.7(a) Public Authority records may be retained for legal, audit, regulatory, accountability, historical, institutional memory, correction, or public-benefit purposes only where lawful and consistent with Public Authority terms, confidentiality, classification, data rights, retention rules, legal holds, and public-safe safeguards.
22.11.7(b) Retained Public Authority records shall be classified, access-controlled, sealed where appropriate, encrypted where appropriate, archived with custodian, and protected against unauthorized disclosure, AI use, publication, transfer, or public claims.
22.11.7(c) Retention shall not be used to continue a Public Authority relationship, imply ongoing participation, preserve unauthorized Public Authority references, or retain data beyond lawful purpose.
22.11.7(d) Public-safe summaries may be retained or published only where Public Authority terms, confidentiality, data rights, and public-safe review permit.
22.11.7(e) The controlling rule shall be that Public Authority records may be remembered only within lawful and bounded purposes.
22.11.8 Public Authority Misdescription Correction Before Final Closeout. 22.11.8(a) GCRI Canada shall correct Public Authority misdescription before final closeout.
22.11.8(b) Misdescription includes any statement, reference, dashboard, map, report, evidence pack, website, deck, social media post, sponsor material, provider material, public-safe summary, public authority learning material, or Nexus-facing material that implies Public Authority endorsement, adoption, official guidance, public warning, emergency command, regulatory approval, procurement approval, funding approval, public finance approval, sovereign obligation, or public-private partnership without lawful authority.
22.11.8(c) Correction may include public-safe correction notice, controlled notice, removal, withdrawal, retraction, supersession, archive note, website correction, dashboard notice, map notice, Public Authority clarification, sponsor correction, provider correction, media correction, or Nexus interface correction.
22.11.8(d) Correction shall be coordinated with the affected Public Authority where required or appropriate and shall protect confidential and sensitive materials.
22.11.8(e) The controlling rule shall be that Public Authority misdescription must be corrected before GCRI Canada leaves materials in final archive or public circulation.
22.11.9 Public Authority Disposition Records and Acknowledgments. 22.11.9(a) GCRI Canada shall maintain Public Authority disposition records and acknowledgments.
22.11.9(b) Records shall identify Public Authority entity, jurisdiction, participant, capacity, material, data, source, authority, classification, permitted use, disposition method, return record, deletion record, sealing record, archive record, transfer record, receipt, acknowledgment, notice, correction, public-safe status, and closeout.
22.11.9(c) Acknowledgments shall be obtained where appropriate for return, transfer, deletion confirmation, archive approval, continuing confidentiality, reference removal, or final closeout.
22.11.9(d) Records shall be retained according to law, Public Authority terms, legal hold, audit need, confidentiality, privacy, cybersecurity, Public Authority sensitivity, and public-benefit purpose.
22.11.9(e) The controlling rule shall be that Public Authority disposition must be provable by record and acknowledgment where appropriate.
22.11.10 Public Authority Disposition Register. 22.11.10(a) GCRI Canada shall maintain a Public Authority Disposition Register if dissolution, wind-up, material program closeout, or material Public Authority interface closeout is initiated.
22.11.10(b) The Register shall identify Public Authority entity, jurisdiction, participant, capacity classification, material type, data contribution, room participation, dashboard, map, report, evidence pack, public authority learning material, reference, authority, owner, custodian, classification, permitted use, disposition method, notice status, acknowledgment status, correction status, archive status, access revocation status, legal hold status, public-safe status, and closeout.
22.11.10(c) The Register shall link to the Public Authority Register, Public Authority Data Register, Data Disposition Register, Public Materials Closeout Register, Dashboard Register, Map Register, Evidence Register, Publication Register, Public Claims Register, Controlled Room Register, Contract Closeout Register, Nexus Interface Closeout Register, Incident Register, Corrective Action Register, and Final Assurance records.
22.11.10(d) The Register shall be access-controlled and protected according to confidentiality, Public Authority sensitivity, privacy, cybersecurity, infrastructure sensitivity, finance sensitivity, legal privilege, and public-safe requirements.
22.11.10(e) The controlling rule shall be that Public Authority disposition must be registered because public power, public data, and public reliance require final traceability.
22.12 Community-Protected Data and Protected Knowledge Disposition
22.12.1 Community-Protected and Protected Knowledge Materials Require Heightened Closeout. 22.12.1(a) Community-protected and Protected Knowledge materials shall require heightened closeout in dissolution, wind-up, dormancy, program closeout, technical asset retirement, data disposition, public materials closeout, or transfer.
22.12.1(b) Heightened closeout shall protect community dignity, cultural integrity, knowledge-holder rights, territorial interests, environmental context, data sovereignty where applicable, safety, privacy, public-safe publication, grievance rights, remedy pathways, non-retaliation, and public trust.
22.12.1(c) GCRI Canada shall identify affected communities, knowledge holders, protocols, consent and non-consent records where applicable, access restrictions, public-safe commitments, grievance records, remedy records, data classification, publication status, mapping status, AI-use status, and final disposition.
22.12.1(d) No closeout action shall expose, extract, commercialize, abandon, misdescribe, over-generalize, or erase community-protected or Protected Knowledge materials.
22.12.1(e) The controlling rule shall be that protected knowledge must be protected most carefully when institutional custody is ending.
22.12.2 Indigenous, Local, Territorial, Cultural, Environmental, Sacred, Sensitive-Site, Vulnerable-Community, and Protected Knowledge Materials. 22.12.2(a) Community-protected and Protected Knowledge disposition shall include Indigenous, Local, Territorial, Cultural, Environmental, sacred, sensitive-site, vulnerable-community, protected-person, traditional ecological, community vulnerability, community resilience, local observation, oral-history, and other protected knowledge materials.
22.12.2(b) Materials may include data, maps, geospatial layers, sensor outputs, environmental observations, community reports, interview materials, photographs, recordings, meeting notes, consent records, non-consent records, grievance records, remedy records, protocols, public-safe summaries, datasets, technical notes, AI prompts, AI outputs, embeddings, retrieval stores, dashboards, and publications.
22.12.2(c) Materials shall be classified according to legal requirements, community protocols, sensitivity, risk of misuse, cultural restrictions, location sensitivity, group harm risk, re-identification risk, public-safe status, and access class.
22.12.2(d) Materials shall not be treated as ordinary research data, ordinary public information, ordinary technical data, or ordinary public-good asset merely because they support GCRI Canada’s public-benefit work.
22.12.2(e) The controlling rule shall be that the nature and origin of protected knowledge determine its closeout controls.
22.12.3 Disposition Shall Respect Consent / Non-Consent, Withdrawal, Community Protocols, Indigenous Protocols, Knowledge-Holder Terms, Contractual Terms, Public-Safe Commitments, and Legal Obligations. 22.12.3(a) Disposition shall respect consent, non-consent, withdrawal rights where applicable, community protocols, Indigenous protocols, knowledge-holder terms, data sovereignty requirements where applicable, contractual terms, public-safe commitments, legal obligations, confidentiality obligations, research ethics, and remedy obligations.
22.12.3(b) Where consent or authorization was limited to a particular purpose, program, custodian, geography, audience, publication class, or time period, dissolution shall not expand that authorization.
22.12.3(c) Where consent is withdrawn or authorization ends, GCRI Canada shall determine lawful disposition, including return, deletion, sealing, restricted archive, redaction, withdrawal, or public-safe correction, subject to legal hold and other legally controlling obligations.
22.12.3(d) Where community protocols or Indigenous protocols require consultation, notice, co-determination, return, restricted transfer, or non-public archive, GCRI Canada shall follow such requirements to the maximum lawful extent.
22.12.3(e) The controlling rule shall be that protected knowledge disposition follows the authority under which the knowledge was entrusted, not GCRI Canada’s convenience.
22.12.4 No Transfer to Recipient Without Capability and Authority to Protect the Materials. 22.12.4(a) Community-protected and Protected Knowledge materials shall not be transferred to any recipient without lawful authority and demonstrated capability to protect the materials.
22.12.4(b) Recipient capability review shall assess legal authority, mission compatibility, community trust, cultural safety, confidentiality, data protection, cybersecurity, access controls, public-safe publication discipline, protected knowledge protocols, correction capacity, grievance capacity, remedy capacity, archive capacity, and retransfer restrictions.
22.12.4(c) Transfers to sponsors, providers, vendors, National Companies, Project SPVs, capital actors, private entities, public repositories, public archives, AI providers, data brokers, or commercially oriented recipients shall be prohibited unless lawful, expressly authorized, safeguard-compliant, mission-compatible, and approved through heightened review.
22.12.4(d) Transfer instruments shall include use restrictions, access restrictions, publication restrictions, AI-use restrictions, commercial-use restrictions, mapping restrictions, retransfer restrictions, correction duties, notice duties, and remedy duties where applicable.
22.12.4(e) The controlling rule shall be that protected knowledge shall not move to custody that cannot protect it.
22.12.5 No Open Release by Default. 22.12.5(a) Community-protected and Protected Knowledge materials shall not be open-released by default.
22.12.5(b) Open release shall require lawful authority, community or knowledge-holder authorization where required, public-safe review, re-identification review, group harm review, sensitive-site review, protected-person review, cultural safety review, and records.
22.12.5(c) A material shall not become open-release eligible merely because GCRI Canada dissolves, a repository is archived, a technical baseline is public, a research output is published, a funder prefers openness, or a public-good rationale exists.
22.12.5(d) Where public communication is appropriate but open release is unsafe or unauthorized, GCRI Canada may prepare a public-safe summary, generalized note, redacted description, controlled notice, or archive note.
22.12.5(e) The controlling rule shall be that public-good purpose does not override protected knowledge restrictions.
22.12.6 No AI Training, Embedding, Model Improvement, Repository Inclusion, Public Mapping, Dataset Release, or Public Archive by Default. 22.12.6(a) Community-protected and Protected Knowledge materials shall not be used for AI training, fine-tuning, embedding, retrieval indexing, model improvement, repository inclusion, public mapping, dataset release, public archive, public dashboard, benchmark creation, synthetic data creation, or public technical release by default.
22.12.6(b) Any such use shall require lawful authority, consent or community authorization where required, protected knowledge review, AI review, cybersecurity review, public-safe review, re-identification review, group harm review, and records.
22.12.6(c) Existing embeddings, retrieval stores, logs, model inputs, model outputs, prompts, derived data, metadata, public maps, public datasets, and technical artifacts containing or derived from protected knowledge shall be identified and dispositioned according to protection requirements.
22.12.6(d) Unauthorized AI use, mapping, release, archive, or repository inclusion shall be treated as an incident requiring containment, correction, deletion or sealing where lawful, notice where required, and remedy.
22.12.6(e) The controlling rule shall be that protected knowledge shall not be converted into machine-readable or public technical infrastructure without proper authority and safeguards.
22.12.7 Community Notice, Consultation, Grievance, Remedy, and Correction Where Required or Appropriate. 22.12.7(a) GCRI Canada shall provide community notice, consultation, grievance pathways, remedy pathways, and correction where required or appropriate in community-protected and Protected Knowledge disposition.
22.12.7(b) Notice and consultation shall be accessible, culturally appropriate where relevant, language-appropriate where relevant, non-retaliatory, timely, records-valid, and clear about affected materials, proposed disposition, options, rights, restrictions, timeline, and contact path.
22.12.7(c) Grievance and remedy pathways shall address concerns about exposure, misuse, misdescription, mapping, AI use, publication, transfer, archive, deletion, sealing, return, community harm, cultural harm, environmental harm, or non-consent.
22.12.7(d) Correction may include public-safe correction, controlled notice, withdrawal, retraction, dataset correction, map correction, dashboard correction, repository correction, AI-output correction, archive restriction, deletion, sealing, return, or transfer to appropriate custodian.
22.12.7(e) The controlling rule shall be that affected communities shall not discover after the fact that protected materials were disposed contrary to safeguards.
22.12.8 Sealing, Deletion, Return, Restricted Transfer, Protected Archive, or Public-Safe Summary. 22.12.8(a) Community-protected and Protected Knowledge materials may be sealed, deleted, returned, restricted-transferred, placed in protected archive, or summarized in public-safe form according to law, protocols, authorization, public-safe review, and records.
22.12.8(b) Sealing shall identify custodian, access restrictions, authority, duration, reopening conditions, correction path, and legal hold status.
22.12.8(c) Deletion or destruction shall be secure, documented, and applied to active systems, repositories, exports, devices, backups where feasible and lawful, embeddings where feasible and lawful, retrieval indexes, logs where appropriate, and third-party systems where applicable.
22.12.8(d) Return shall be made to an authorized community, knowledge holder, Public Authority, institution, archive, or custodian according to protocol and receipt.
22.12.8(e) Restricted transfer and protected archive shall include enforceable or records-valid safeguards, access controls, public claims limits, no-AI-use limits, no-open-release limits, correction duties, retransfer restrictions, and remedy pathways.
22.12.8(f) Public-safe summaries shall avoid over-disclosure, misdescription, sensitive-location exposure, re-identification, cultural harm, extraction, or community harm.
22.12.8(g) The controlling rule shall be that disposition method shall protect the knowledge, the community, and the record.
22.12.9 Protected Knowledge Disposition Records and Acknowledgments. 22.12.9(a) GCRI Canada shall maintain protected knowledge disposition records and acknowledgments.
22.12.9(b) Records shall identify material, community, knowledge holder where appropriate, authority, consent or non-consent status where applicable, protocol, classification, owner, custodian, location, AI-use status, publication status, mapping status, repository status, disposition method, notice, consultation, grievance, remedy, approval, acknowledgment, receipt, deletion evidence, sealing record, archive record, transfer record, public-safe summary, correction, and closeout.
22.12.9(c) Acknowledgments shall be obtained where appropriate for return, restricted transfer, protected archive, deletion, sealing, receipt, notice, or agreed disposition.
22.12.9(d) Records shall themselves be classified and access-controlled to avoid exposing the protected knowledge they document.
22.12.9(e) The controlling rule shall be that protected knowledge disposition must be evidenced without creating a new exposure risk.
22.12.10 Community-Protected and Protected Knowledge Disposition Register. 22.12.10(a) GCRI Canada shall maintain a Community-Protected and Protected Knowledge Disposition Register if dissolution, wind-up, material program closeout, or protected knowledge disposition is initiated.
22.12.10(b) The Register shall identify material category, community or knowledge holder reference where appropriate and safe, authority source, protocol, classification, custodian, consent or non-consent status where applicable, public-safe status, AI-use status, mapping status, repository status, publication status, disposition method, recipient where applicable, notice status, consultation status, grievance status, remedy status, acknowledgment status, correction status, archive status, legal hold status, and closeout.
22.12.10(c) The Register shall link to Data Disposition Register, Community Safeguards Register, Protected Knowledge Register, Public Materials Closeout Register, Map Register, Dataset Register, AI Register, Repository Register, Contract Closeout Register, Public Authority Disposition Register, Incident Register, Corrective Action Register, and Final Assurance records where applicable.