For the complete documentation index, see llms.txt. This page is also available as Markdown.

43. Publication Classes

43.1 Public

43.1.1 Public is the publication class for records, summaries, notices, dashboards, registries, reports, standards, educational materials, public-safe explanations, maturity states, public claims, and other outputs that have been approved for unrestricted public access under the applicable publication, safeguards, claims, legal, technical, public authority, data, and correction controls of the Nexus Rail.

43.1.2 Public does not mean informal, unreviewed, context-free, or unrestricted in meaning. A public record may be openly accessible, but its meaning remains bounded by its title, version, date, authority, scope, evidence basis, reliance limits, public claims permissions, and correction history. Public visibility does not expand the effect of the record.

43.1.3 A Public record may include public charters, public bylaws, public doctrine, public summaries, public standards, public-safe dashboards, registry entries, maturity summaries, approved press materials, educational explainers, open technical baselines, public-good software documentation, public notices, and correction notices. Each must be approved through the applicable publication workflow.

43.1.4 Public records must avoid overclaim. A public maturity record must not imply endorsement beyond the maturity state. A public routeability summary must not imply investment advice. A public technical note must not imply certification. A public authority reference must not imply approval unless approval exists. A public community reference must not imply consent unless consent is recorded.

43.1.5 Public records should be understandable. Where the subject is technical, legal, ecological, financial, AI-related, or institutional, public materials should communicate meaning without hiding limits behind jargon. Public trust depends not only on openness, but on intelligible openness.

43.1.6 Public records remain correctionable. A public output may be corrected, updated, superseded, withdrawn, archived, or reclassified where evidence changes, public authority capacity is clarified, safeguards require adjustment, technical findings change, claims are misread, or a publication defect is discovered. Public status is not permanence.

43.1.7 Public records may still carry restrictions on reuse of name, mark, status, association, or claims. Open access to a public record does not authorize a provider, sponsor, finance actor, public authority participant, host, project vehicle, or downstream actor to use the record as endorsement, certification, approval, investment support, procurement preference, or public authority backing.

43.1.8 The doctrine is direct:

Public records are openly visible records whose meaning remains governed by scope, authority, claims discipline, versioning, and correction. Public access does not create unrestricted public reliance.


43.2 Public-Safe Summary

43.2.1 Public-Safe Summary is the publication class for records or outputs that communicate the public meaning of a matter while withholding, generalizing, masking, aggregating, paraphrasing, or otherwise protecting sensitive details that should not be publicly disclosed. It is the primary transparency mechanism for high-consequence matters where full publication would create harm.

43.2.2 Public-Safe Summary exists because the Rail must avoid two failures: secrecy that destroys trust, and disclosure that creates harm. Many matters require public explanation but cannot safely release raw data, protected knowledge, cyber details, infrastructure vulnerabilities, public authority-sensitive records, personal data, finance-sensitive annexes, or community-sensitive information.

43.2.3 A Public-Safe Summary may be used for controlled evidence, restricted observatory records, TMD findings, public authority interface records, community evidence, incident-mode updates, proof-pack status, dashboard limitations, routeability states, technical baselines, ecological baselines, or correction notices. It allows the public to understand the governance state without exposing unsafe details.

43.2.4 A Public-Safe Summary should state what is known, what is uncertain, what authority exists, what authority does not exist, what evidence class supports the summary, what has been withheld for protection, what public claims are permitted, what public claims are prohibited, and how correction will occur. It should not be vague merely because it is protective.

43.2.5 Public-Safe Summary must preserve source dignity. It must not strip community evidence, Indigenous or protected knowledge, public authority records, or technical findings of context in ways that mislead. Protection must not become distortion.

43.2.6 Public-Safe Summary must be reviewed by the relevant functions. Depending on the matter, review may include safeguards, claims discipline, legal, data/AI/cyber, TMD, public authority interface, GRF, GRA, GCRI methods, community protocol, or Board-level review. Public-safe release is a governance act.

43.2.7 Public-Safe Summary must be dependency-linked. If the controlled record beneath the summary is corrected, superseded, restricted, withdrawn, or reclassified, the public-safe summary must be reviewed and updated where meaning changes.

43.2.8 The doctrine is direct:

Public-Safe Summary is the Rail’s disciplined method for telling the public enough truth to sustain trust while protecting people, knowledge, systems, authorities, and sensitive evidence from harm.


43.3 Controlled

43.3.1 Controlled is the publication class for records that may be shared only with authorized actors under defined purpose, role, access, confidentiality, data-use, AI-use, export, onward-sharing, retention, and correction conditions. Controlled records are not public, but they are not absolutely restricted. They are usable within a governed room, workflow, docket, review, or handoff.

43.3.2 Controlled status is necessary because many records must be reviewed by competent actors before public-safe release, technical determination, routeability, public authority learning, Board decision, safeguards review, or downstream handoff. A record may be too sensitive for public release but necessary for governance.

43.3.3 Controlled records may include technical annexes, AEP materials, proof-pack annexes, public authority records, TMD review files, model evaluation materials, data cards, baseline evidence, controlled-room materials, finance-reader diligence materials, public-safe draft reports, community-sensitive summaries, cyber-relevant but not security-critical details, and internal decision packs.

43.3.4 Controlled access must be purpose-bound. A person may be authorized to view a controlled record for TMD review, but not for finance use. Another may view for safeguards review, but not export. Another may receive a public authority copy, but not publish. Controlled status requires precise role-keying.

43.3.5 Controlled records must carry reliance limits. A controlled proof-pack annex may support internal GRA review but not public fundraising. A controlled technical note may support a release gate but not certification. A controlled public authority note may support capacity classification but not approval. A controlled record must state what use is permitted.

43.3.6 Controlled records must include auditability. Access, export, AI processing, annotation, sharing, release, and correction should be logged where material. The Rail must know who saw controlled records and for what purpose.

43.3.7 Controlled records may transition to Public-Safe Summary, Public, Restricted, Security-Sensitive, Finance-Sensitive, Public Authority Sensitive, Community-Sensitive, or Protected Knowledge depending on review. Classification must be revisable when the record’s risk or purpose changes.

43.3.8 The doctrine is direct:

Controlled records are usable under conditions. They allow governance review and lawful reliance without public disclosure, unrestricted access, uncontrolled export, or unbounded downstream use.


43.4 Restricted

43.4.1 Restricted is the publication class for records that require highly limited access because disclosure, misuse, copying, AI processing, export, or even broad internal visibility may create serious harm, legal exposure, public authority conflict, community risk, cyber risk, protected knowledge exposure, financial misuse, or institutional compromise.

43.4.2 Restricted records are not simply confidential. They are records whose access must be exceptional, justified, logged, time-bound where appropriate, and connected to a specific competent function. Restricted classification should be used where ordinary controlled access is insufficient.

43.4.3 Restricted records may include legal privileged materials, sensitive incident records, breach investigations, protected participant identities, whistleblower materials, high-risk public authority records, sensitive technical vulnerabilities, certain controlled-room records, high-consequence AI model-risk records, certain protected knowledge references, and records whose disclosure could create retaliation, panic, security harm, market distortion, or public authority confusion.

43.4.4 Restricted access must be least-privilege. Seniority alone does not justify access. Board role, executive title, technical expertise, platform administration, sponsor status, public authority presence, or finance-reader status does not create access unless the restricted purpose requires it.

43.4.5 Restricted records must prohibit unauthorized AI processing unless specifically approved through a higher-order review. A restricted record available to a human reviewer must not be automatically available for summarization, embedding, translation, retrieval, training, or agentic processing.

43.4.6 Restricted records must have a named steward or responsible function. The steward should manage access, review, retention, reclassification, correction, and public-safe transformation where possible. A restricted record without stewardship becomes hidden risk.

43.4.7 Restricted classification must not be misused to hide embarrassment, avoid accountability, suppress dissent, block public-safe correction, or protect powerful actors. Restricted status protects legitimate sensitive interests; it is not a secrecy weapon.

43.4.8 The doctrine is direct:

Restricted records are highly protected records whose access is exceptional, purpose-bound, logged, stewarded, and correctionable, with protection used for safety and legality rather than institutional concealment.


43.5 Security-Sensitive

43.5.1 Security-Sensitive is the publication class for records whose disclosure or misuse may create cyber, physical, infrastructure, operational, national security, facility security, personal safety, system integrity, network resilience, or emergency-response risk. Security-Sensitive records require special handling because their exposure can create direct vulnerability.

43.5.2 Security-Sensitive records may include cyber vulnerabilities, network diagrams, access-control details, node locations, sensor configurations, incident logs, penetration findings, encryption or key-management details, facility layouts, critical infrastructure dependencies, industrial control information, energy-grid details, data-centre security materials, nuclear-adjacent security information, emergency communication channels, and certain platform administration records.

43.5.3 Security-Sensitive classification applies to both technical and contextual information. A map, dashboard, photograph, timestamp, access log, routing table, maintenance schedule, telemetry pattern, or public-safe note may become security-sensitive when combined with other information. Classification must consider aggregation risk.

43.5.4 Security-Sensitive records may require controlled-room access, restricted export, redaction, delayed publication, aggregation, masking, compartmentalization, security review, TMD review, legal review, public authority review, or incident-mode handling. Access must be role-keyed and logged.

43.5.5 Security-Sensitive does not mean no public communication. Where public trust or safety requires communication, public-safe summaries should explain relevant status without exposing vulnerabilities. A community may need to know that a system is under review, that a public-safe correction occurred, or that a service is affected, without receiving exploit-relevant details.

43.5.6 Security-Sensitive records must be protected against platform and vendor exposure. Hosting providers, cloud operators, contractors, platform administrators, AI providers, and technical vendors must not receive security-sensitive access beyond strict need and contractual controls. Provider convenience is not security authority.

43.5.7 Security-Sensitive records must be corrected and reclassified as risk changes. A vulnerability may be restricted before remediation and public-safe after remediation. An incident record may remain controlled for investigation and later become public-safe. Reclassification must be recorded.

43.5.8 The doctrine is direct:

Security-Sensitive records protect the Rail, communities, infrastructure, platforms, networks, and public systems from harm by limiting exposure of information that could be used to compromise safety or resilience.


43.6 Community-Sensitive

43.6.1 Community-Sensitive is the publication class for records whose disclosure, misuse, misinterpretation, extraction, mapping, AI processing, or downstream use may harm a community, vulnerable group, neighbourhood, workers, local institution, cultural group, displaced population, rural area, informal settlement, territorial community, or other affected group.

43.6.2 Community-Sensitive records may include community testimony, grievance records, local risk reports, public service failures, vulnerability maps, local conflict histories, displacement risks, household-level conditions, community observatory data, local public-health concerns, worker reports, community network records, social trust indicators, and records involving vulnerable participants.

43.6.3 Community-Sensitive classification is necessary because public-good evidence can still harm communities if released without care. A map may stigmatize a place. A report may expose dissenters. A dashboard may affect land values. A proof pack may attract capital pressure. A public authority record may trigger retaliation. A community statement may be misrepresented as consent.

43.6.4 Community-Sensitive records must be governed by protected participation, non-retaliation, accessibility, representation discipline, public-safe mapping review, grievance routes, and correction rights. The affected community’s ability to challenge interpretation is central to the classification.

43.6.5 Community-Sensitive records must distinguish community evidence from community consent. Community data, testimony, participation, or hosting does not authorize public claims of support, consent, approval, or acceptance unless the proper consent or authority record exists.

43.6.6 Community-Sensitive records may be transformed into Public-Safe Summary where appropriate. Such summaries should preserve meaning while protecting identity, location, vulnerability, cultural context, and dissent. Summaries should not sanitize harm or erase community agency.

43.6.7 Community-Sensitive classification must include downstream-use controls. Finance readers, public authorities, providers, hosts, researchers, and project vehicles may not use community-sensitive records beyond the recorded purpose. Community vulnerability must not become transaction intelligence without safeguards.

43.6.8 The doctrine is direct:

Community-Sensitive records protect communities from being exposed, misrepresented, stigmatized, extracted, or converted into consent or finance-readable risk without safeguards and correction rights.


43.7 Protected Knowledge

43.7.1 Protected Knowledge is the publication class for Indigenous, cultural, sacred, territorial, ecological, local, traditional, community-held, restricted, relational, ceremonial, biodiversity-sensitive, site-specific, or otherwise protected knowledge that cannot be treated as ordinary data or ordinary evidence. It is the highest knowledge-specific protection class within the Rail.

43.7.2 Protected Knowledge may include sacred site information, cultural practices, Indigenous knowledge, traditional ecological knowledge, protected species locations, community-held resource knowledge, territorial knowledge, ceremonial knowledge, cultural heritage records, sensitive ecological relationships, local knowledge shared under restriction, or knowledge governed by community or Indigenous protocols.

43.7.3 Protected Knowledge classification is necessary because ordinary transparency, open data, technical review, AI processing, mapping, public-safe reporting, proof-pack preparation, and routeability can harm knowledge systems if not constrained. Some knowledge should not be digitized. Some should not be mapped. Some should not be translated. Some should not be processed by AI. Some should not leave community custody.

43.7.4 Protected Knowledge must be governed by the relevant authority, protocol, permission, or restriction. Where Indigenous governance applies, Indigenous authority, law, protocol, and data sovereignty must be respected. Where community protocols apply, the Rail must not override them for convenience, public interest storytelling, technical completeness, or finance-readability.

43.7.5 Protected Knowledge controls may include non-collection, local-only custody, no public release, no AI processing, no export, no mapping, location masking, seasonal restrictions, controlled-room review, community or Indigenous authority review, public-safe summary only, no finance-reader access, no downstream handoff, attribution restrictions, and withdrawal or correction rights where applicable.

43.7.6 Protected Knowledge must not be forced into AEPs or proof packs as raw evidence. The Rail may record that protected review occurred, that knowledge exists under restriction, that a public-safe summary has been authorized, or that a matter cannot proceed because protected knowledge concerns remain unresolved, without exposing the knowledge itself.

43.7.7 Protected Knowledge exposure must trigger urgent correction. Unauthorized publication, mapping, AI processing, translation, transfer, citation, dashboard display, or downstream use may require takedown, access revocation, public-safe correction, notice to affected knowledge holders, investigation, remedy, and reclassification of dependent records.

43.7.8 The doctrine is direct:

Protected Knowledge is not ordinary data. The Rail may learn from protected knowledge only through the permissions, limits, protocols, and protections that make such learning legitimate.


43.8 Finance-Sensitive

43.8.1 Finance-Sensitive is the publication class for records whose disclosure, misuse, selective release, misinterpretation, or premature circulation may affect finance-readiness, capital-reader diligence, insurance review, public finance discussion, procurement neutrality, market perception, project negotiation, credit analysis, routeability, guarantee consideration, donor engagement, or downstream transaction behaviour.

43.8.2 Finance-Sensitive records may include proof-pack annexes, routeability notes, cost assumptions, resilience-value models, public finance discussion records, insurance diligence questions, capital-reader feedback, procurement-sensitive materials, risk allocation assumptions, site-truth finance annexes, financing pathway drafts, guarantee or donor review materials, and commercially sensitive implementation records.

43.8.3 Finance-Sensitive classification is necessary because routeability can be misused. A controlled proof pack may become fundraising material. A routeability note may be marketed as investment readiness. Public authority discussion may be framed as funding approval. Community risk may be converted into transaction risk pricing. Finance-Sensitive records require strict claims and access controls.

43.8.4 Finance-Sensitive records must carry no-advice and no-execution boundaries. They do not constitute investment advice, credit advice, lending approval, underwriting, insurance approval, rating, guarantee, procurement award, public finance commitment, or recommendation unless issued by a competent licensed or lawful actor outside the public-good rail.

43.8.5 Access to Finance-Sensitive records must be role-keyed. GRA staff, authorized capital readers, public finance actors, insurers, procurement authorities, TMDs, public authorities, or downstream actors may receive different views. Access must be purpose-bound, logged, time-limited where appropriate, and subject to onward-sharing limits.

43.8.6 Finance-Sensitive records must not override safeguards, community restrictions, public authority capacity, data-zone rules, or protected knowledge controls. Capital interest does not justify broader access to sensitive truth.

43.8.7 Finance-Sensitive records must be corrected when underlying evidence changes. If an AEP, Baseline, public authority capacity record, safeguards record, TMD finding, or routeability determination is corrected, Finance-Sensitive materials relying on it must be revised, suspended, or withdrawn.

43.8.8 The doctrine is direct:

Finance-Sensitive records allow lawful financial and adoption actors to review public-value pathways under strict reliance limits, without turning routeability into advice, promotion, procurement preference, or capital capture.


43.9 Public Authority Sensitive

43.9.1 Public Authority Sensitive is the publication class for records involving public authorities, public officials, regulators, municipalities, Indigenous governments where applicable, public agencies, emergency authorities, public finance bodies, procurement authorities, courts or tribunals, utilities commissions, or other public actors where disclosure, misstatement, timing, or misuse may create public authority confusion, legal risk, political sensitivity, procedural unfairness, public reliance, or institutional harm.

43.9.2 Public Authority Sensitive records may include draft public authority capacity records, non-public public authority communications, regulatory interface notes, procurement-related materials, public finance discussions, emergency coordination records, public authority data submissions, legal mandate analysis, intergovernmental materials, public decision-preparation records, and public authority participation records not approved for public reference.

43.9.3 Public Authority Sensitive classification is necessary because public authority meaning must be precise. Public authority participation can easily be misrepresented as approval, endorsement, funding, procurement decision, regulatory clearance, public warning, or official support. Sensitive classification protects both the public authority and the Rail.

43.9.4 Public Authority Sensitive records must record capacity. The record should state whether the public actor participated as observer, learner, data provider, technical reviewer, regulator, funder, procurement authority, emergency authority, host, policy body, or lawful decision-maker. Public claims must not exceed that capacity.

43.9.5 Public Authority Sensitive records may require public-reference permission. A public actor may share information for internal learning without authorizing public citation. The Rail must not name, quote, cite, or imply support from a public authority unless the publication record permits it.

43.9.6 Public Authority Sensitive records must respect legal process. Procurement, regulatory, emergency, judicial, tribunal, public finance, or statutory processes may have procedural requirements. Nexus records must not interfere with, pre-judge, or publicly distort those processes.

43.9.7 Public Authority Sensitive records must be corrected when capacity is misstated. If a public-safe output, dashboard, proof pack, media statement, or downstream actor misrepresents public authority capacity, correction should be prompt and visible enough to prevent reliance.

43.9.8 The doctrine is direct:

Public Authority Sensitive records protect the lawful meaning of public authority participation, ensuring that the Rail supports public bodies without borrowing, distorting, or manufacturing their authority.


43.10 Publication Class Records

43.10.1 Publication Class Records are the official records that identify the publication class assigned to a record, dataset, evidence item, dashboard, report, proof pack, technical finding, public authority record, community submission, protected knowledge item, model output, platform state, or handoff material. They make classification visible, reviewable, and correctionable.

43.10.2 A Publication Class Record should identify the record title or ID, Case ID, class assigned, classification reason, source data classes, sensitivity factors, affected actors, reviewing function, approval authority, date, version, access rules, AI-use rules, export rules, onward-sharing rules, public claims permissions, review date, and correction path.

43.10.3 Publication Class Records are necessary because classification affects power. A public record can create reliance. A controlled record can shape decisions. A restricted record can hide risk if abused. A finance-sensitive record can affect downstream behaviour. A protected knowledge classification can prevent extraction. Classification must not be informal.

43.10.4 Publication Class Records must identify mixed-class records. A single AEP, dashboard, proof pack, or decision pack may include public, public-safe, controlled, restricted, security-sensitive, community-sensitive, protected knowledge, finance-sensitive, and public authority-sensitive components. The record must classify components, not only the whole package.

43.10.5 Publication Class Records must include role-key effects. Classification should determine who can view, edit, annotate, export, cite, publish, process with AI, summarize, hand off, or correct the record. A class label without permission effects is incomplete.

43.10.6 Publication Class Records must include review and reclassification triggers. A record may change class when an incident is resolved, a public authority permits citation, protected knowledge restrictions change, a vulnerability is remediated, a public-safe summary is approved, a proof pack is withdrawn, or a correction is issued.

43.10.7 Publication Class Records must be auditable. It should be possible to know who classified a record, whether the classification was reviewed, whether access followed the class, and whether the class was changed. Classification errors must be correctable.

43.10.8 The doctrine is direct:

Publication Class Records make information governance operational by recording what class applies, why it applies, who may access or use the record, and how classification can change or be corrected.


43.11 Publication Class Transitions

43.11.1 Publication Class Transitions are the governed movements of records from one publication class to another. A record may move from Restricted to Controlled, Controlled to Public-Safe Summary, Public-Safe Summary to Public, Public to Corrected Public, Controlled to Finance-Sensitive, Public Authority Sensitive to Public-Safe Summary, or Protected Knowledge to non-public reference only. Each transition is a governance act.

43.11.2 Transitions are necessary because record sensitivity changes over time. A vulnerability may become less sensitive after remediation. A public authority may authorize citation. A community may approve a public-safe summary. A proof pack may become finance-sensitive after routeability review. An incident record may move from restricted investigation to public-safe correction. A draft may become public. A public record may need withdrawal.

43.11.3 A Publication Class Transition should identify original class, proposed class, reason, reviewing authority, required checks, safeguards review, claims review, legal review where needed, data/AI/cyber review where needed, public authority review where needed, community or protected knowledge review where needed, effective date, version change, public claims effect, and correction implications.

43.11.4 Transitions must not be automatic. Uploading a controlled record to a platform does not make it public. Including a restricted record in a Board pack does not broaden access. Creating a public-safe summary does not make underlying evidence public. Sharing a proof pack with a finance reader does not permit onward sharing. Transition requires recorded approval.

43.11.5 Transitions must preserve derivative restrictions. A public-safe summary may be public, while the underlying record remains restricted. A zero-knowledge proof may be public-safe, while the source data remains protected. A dashboard aggregate may be public, while node-level data remains security-sensitive. Transition of one artifact does not transition all dependencies.

43.11.6 Transitions must include notification where reliance is affected. If a public record becomes withdrawn, a controlled record becomes public-safe, a finance-sensitive record is corrected, or a public authority-sensitive record is reclassified, affected users may need notice. Reclassification without notice can create reliance errors.

43.11.7 Transitions must support downgrade as well as release. Publication governance is not only about making records more public. It also includes restricting records when risk is discovered, withdrawing public materials, suspending dashboards, or reclassifying outputs after harm or correction.

43.11.8 The doctrine is direct:

Publication Class Transitions control how records move between openness and protection, ensuring that visibility changes only through review, authority, safeguards, claims discipline, and correction.


43.12 Public-Safe Transparency

43.12.1 Public-Safe Transparency is the final doctrine of publication classes. It means that the Rail must be as transparent as it safely and lawfully can be, while refusing the false choice between total secrecy and reckless disclosure. Public trust requires visibility; public protection requires classification.

43.12.2 Public-Safe Transparency exists because compound-risk governance needs legitimacy in conditions where raw openness may harm people, systems, ecosystems, public authorities, communities, or security. The Rail must therefore disclose meaning, status, process, authority, limitations, uncertainty, and correction without exposing sensitive evidence unnecessarily.

43.12.3 Public-Safe Transparency should make at least the following visible where safe: what matter is being governed, what stage it is in, what authority exists, what authority does not exist, what evidence class supports the record, what uncertainty remains, what safeguards apply, what public authority capacity exists, what claims are permitted, what claims are prohibited, what correction route exists, and whether the record is current or superseded.

43.12.4 Public-Safe Transparency must resist secrecy abuse. Classification must not be used to hide error, avoid public accountability, protect sponsors, shield providers, suppress communities, prevent public authority correction, conceal finance overclaim, or avoid reputational difficulty. Protection must have reason and review.

43.12.5 Public-Safe Transparency must resist disclosure abuse. Open publication must not be used to expose protected knowledge, identify vulnerable participants, disclose cyber vulnerabilities, reveal sensitive infrastructure, create panic, distort public authority process, influence procurement unfairly, or provide finance actors with restricted site truth.

43.12.6 Public-Safe Transparency must be designed into platforms and records. Dashboards should show public-safe status without exposing restricted layers. Registries should show maturity without overclaim. Proof packs should have controlled annexes and public-safe summaries. Correction notices should be visible where reliance exists. Publication class should travel with every artifact.

43.12.7 Public-Safe Transparency must be correctionable. If a public-safe summary omits material uncertainty, overprotects information in ways that mislead, exposes too much, or is interpreted as approval, it must be corrected. Transparency itself is a living governance practice.

43.12.8 The final doctrine of this chapter is direct:

Publication Classes make Public-Safe Transparency possible. They allow Planetary Nexus Governance to disclose enough to earn trust, protect enough to prevent harm, and correct enough to remain legitimate when evidence, authority, or risk changes.

Last updated

Was this helpful?