State the change
Define the exact problem, affected artifacts and domains, legal or institutional effects, alternatives and machine-readable projections that may need to change.
Exergism Commons · institutional control plane
The proposed system turns institutional authority into an explicit path: propose a change, classify it, determine who may decide, apply conflicts and thresholds, bind the result to evidence, validate the record, then delegate implementation.
Public by default. Strong stewardship without ownership. Machine validation without machine-made legitimacy.
The operating idea
A decision is not authority merely because somebody merged it.
01 · How governance works
A governance action moves through explicit stages. Human rules determine what authority is required; machine-readable records make the resulting state reconstructable and testable. Technical permissions never substitute for the required decision.
policy/governance-status.json remains operative: false, draft decisions, Members, Founding Steward assignments and delegations cannot be represented as operative merely because GitHub or CI accepted them.Define the exact problem, affected artifacts and domains, legal or institutional effects, alternatives and machine-readable projections that may need to change.
Editorial, descriptive, policy, constitutional, mission-locked, legal-instrument or adoption-state. If reasonable reviewers disagree, use the higher class.
Resolve Active Members, class-specific voting seasoning and conflicts at the voting-window opening date. GitHub access, funding and contribution history do not create a vote.
Open the vote or other required process, authenticate ballots, apply recusals, quorum and the exact approval threshold, plus any guardian or independent-review requirements.
Create an immutable GovernanceDecision record that identifies the rule, electorate, ballots, evidence, exact payload and outcome. A stored “approved” flag is not trusted on its own.
SHACL and deterministic validators test structural and temporal invariants, reconstruct eligibility and reject inconsistent or under-specified authority claims.
If execution requires an actor or role, create an explicit scoped delegation: source authority, resources, allowed actions, prohibitions, effective dates, expiry and revocation mechanism.
Funding, ID, repositories or another domain performs the authorized action in its own canonical system. Governance supplies authority; it does not silently rewrite domain facts.
Start here
Open a governance change only for organization-level institutional rules. If the proposal changes a project-specific canonical artifact, use that project's own process instead.
Say what is broken or missing, not merely what text you want edited.
Mission Lock, Membership, voting, delegation, contributor rights, treasury, persistent infrastructure, privacy or another institutional layer.
Do not bury constitutional, mission-locked, legal or adoption effects inside refactors.
If the concept exists in policy/**, ontology/** or the machine spec, update the projection or explain why it does not change.
Include alternatives, non-retroactivity consequences and any cross-domain implementation required.
Classification guide
| Class | Use when | Typical process consequence |
|---|---|---|
| Editorial | Wording, links, formatting or metadata with no policy effect. | No institutional authority change. |
| Descriptive architecture | Documents an existing boundary without changing rights or authority. | Review the description against canonical sources. |
| Policy | Changes an organization-level process or requirement inside the constitutional envelope. | Uses the applicable adopted decision rule. |
| Constitutional | Changes Membership, thresholds, roles, conflicts, delegation boundaries, persistent-infrastructure authority or amendment mechanics. | ConstitutionalAmendment. |
| Mission-locked | Weakens or bypasses a protected Mission Lock invariant or protected mission mechanism. | MissionLockedAmendment; cannot be downgraded by labeling. |
| Legal instrument | Changes CLA terms, grants, representations, governing law, signature mechanics or another legally consequential instrument. | Legal-instrument process and any required qualified review. |
| Adoption state | Changes whether governance, Membership, Founding Stewardship or a legal instrument is actually operative. | Isolated activation change with legal/adoption evidence and fail-closed checks. |
02 · Constitutional architecture
Organization governance owns cross-project institutional rules. Project-specific philosophical, evidentiary, legal and technical authority remains with the repository that owns that layer.
Protect institutional identity, authority separation, non-ownership membership, identifier integrity and anti-capture constraints without freezing every roadmap decision.
Repository access, DNS control, banking authority or technical permissions do not automatically become institutional authority.
Funding, donations, employment and economic relationships do not purchase organization-wide voting weight or institutional ownership.
Governance may constrain institutional process, but it does not silently rewrite Exergism releases, ECL artifacts, Funding records or patent grants.
03 · Membership + stewardship
Membership is governance status, not property. The electorate is derived from explicit Membership history and the applicable voting class, not from GitHub state or economic relationships.
Founding stewardship
The draft framework makes current founder dependence explicit. During F0, the Founding Steward can provide strong bootstrap coordination and a narrow negative Mission Veto. Founder authority is separate from the founder's ordinary Member vote and does not become weighted voting or automatic economic privilege.
High coordination concentration is acknowledged and bounded rather than disguised.
Requires an operative Member Registry, at least three Active Members and independent institutional capacity.
Targets broader membership, sustained governance records, independent review and reduced single-person operational concentration.
04 · Decision classes
Thresholds use exact integer ratios. Conflicted voters are excluded from the effective eligible denominator under the proposed rule, and abstentions count toward quorum but not toward the valid for/against approval denominator where the class uses that denominator.
Routine organization-level decisions inside existing authority.
Protected actions including persistent-domain transfer, identifier-authority transfer, legal-steward changes, organization-wide exclusive IP transfer, institutional merger/dissolution/succession and exceptional Endowment-principal withdrawal.
Changes to the ordinary constitutional framework.
Two successful votes at least 60 days apart, independent review and guardian consent during F0/F1. The proposal's label cannot downgrade this class.
05 · What happens during a vote
The draft machine contract is deliberately stricter than “count some comments on a PR”. It must be possible to reconstruct who was eligible, why anyone was recused, who cast each counted ballot and which exact decision payload they voted on.
Bind the decision ID, decision class, governing rule and voting-window opening date.
Reconstruct Membership history and class-specific seasoning at the opening date.
A denominator-changing recusal needs a content-addressed conflict determination for the same decision and person.
Each counted Member ballot binds decision ID, class, opening date, Member person ID and vote value, plus signature and verification evidence.
The validator recomputes quorum and approval. It does not trust a stored result: approved field.
Self-compensation and other direct private interests require recusal. Founder status does not override the conflict rule.
A bare {person_id, vote} or another participant's tally cannot establish that a Member actually cast the ballot.
Eligibility, Founding Steward authority and delegations are evaluated at the relevant decision/effective date so current-state edits cannot rewrite history.
06 · Worked example
exergism.org.Suppose EC wants to permanently transfer registrar recovery control or persistent-domain authority. Under the proposed rules this is not ordinary web administration: it is a protected institutional action.
https://id.exergism.org/governance/decision/{stable-id}Identify the exact domain authority being transferred, recipient, scope, permanence, risks, alternatives and implementation requirements.
Qualified Approval is mandatory for persistent-domain transfer and identifier-authority transfer. If the proposal also weakens a Mission Lock invariant, the higher Mission-Locked process applies.
Freeze eligible seasoned Members at the opening date and resolve any conflict determinations before computing the effective denominator.
Reach quorum ≥2/3 of effective eligible voters and approval ≥2/3 of valid for/against votes, with authenticated ballots for the exact payload.
Bind the result, electorate, recusals, ballots, rule version, payload digest and supporting evidence to an immutable GovernanceDecision record.
Machine checks recompute the threshold and verify structural, temporal and authority constraints. Passing validation confirms declared machine-checkable consistency, not legal validity by itself.
If a specific operator must perform the registrar action, the decision creates or authorizes a scoped delegation. The registrar/domain implementation then executes the approved transfer.
Defines the approval class and records the institutional decision.
States who may execute which action against which exact resource.
Registrar, ID resolver or repository performs the technical implementation.
Immutable evidence makes the authority chain reconstructable after current state changes.
07 · Machine-readable governance
Human constitutional and adopted policy text remains authoritative. JSON, RDF, OWL, SHACL and deterministic validation are projections and enforcement aids around that human authority model.
https://id.exergism.org/commons#Persistent identifier resolution does not itself make a policy operative.Authority hierarchy, ballot authentication, temporal state, evidence and validation boundaries.
Exact rational thresholds, protected subjects and conflict rules.
Explicit Member state; never inferred from GitHub, funding, employment or contribution count.
Scoped authority, source decision, resources, actions, expiry and revocation.
Reviewable graph constraints that reject inconsistent governance claims.
Fail-closed checks for Membership, ballots, Founding Stewardship, delegations, phase transitions and CLA state.
08 · Authority boundaries
Downstream repositories may reference EC approval concepts without copying their definitions. Governance remains authoritative for the organization-level decision concept; the downstream project remains authoritative for its own domain facts and implementation.
Canonical philosophy and formal analytical model.
Open repository ↗Software/copyright licensing and separate patent architecture retain their own authority boundaries.
Open ECL ↗Funding strategy and records can require an EC approval class while Funding remains authoritative for the funding facts that trigger it.
Open Funding ↗id.exergism.org resolves stable identifiers. It is not the semantic owner of every resource it resolves.
09 · Contributor rights
The proposed CLA architecture separates a submitted proposal from an Accepted Contribution. Contributors retain the rights they own; full project grants vest only at the defined acceptance boundary, and the CLA itself grants no patent rights.
Use the draft
The repository contains the constitutional text, proposal rules, Membership model, exact decision thresholds, machine projections and validators behind this workflow. It remains draft until a competent adoption process makes it operative.