Governance Operator Guide

Governance authorities define admission, transition, recognition, appeal and redress rules. Registry operators execute only the delegated administrative scope. Assurance providers evaluate controls but do not grant operational authority. For Profile D, the appeal function must be organizationally independent from the authority that made the contested consequential decision.

Administrative authority

High-impact Profile C/D operations require threshold approval, dual control, or an equivalently independent multi-party authorization mechanism. This includes accountable-entity changes, ownership-like transfers, restoration after compromise, recovery-key replacement, governance-framework changes, broad authority issuance, removal of critical prohibitions, and deletion or redaction of evidence.

Operators should maintain an explicit administrative authority matrix recording the permitted operation, approver class, minimum approval count, emergency path, expiry, and revocation mechanism. A successful registry write is not evidence that the writer was competent to make that governance decision.

Recovery and emergency action

Emergency suspension may be deliberately faster than ordinary governance, but restoration after confirmed compromise must not be the inverse of that one-person emergency path. Restoration requires fresh security evidence and independent authorization sufficient for the claimed profile. Recovery actions must be included in the tamper-evident audit trail.

Appeals and redress

Profile B-D deployments must define notice, opportunity to respond, emergency exceptions, evidence standards, decision authority, time limits, publication rules, restoration/correction, and available remediation. Consequential decisions must resolve to a Redress Record or equivalent machine-resolvable route.

Controlled protocol registries

Controlled registries of relationship types, event types, errors and extensions are governed artifacts. Changes require interoperability, security, privacy, migration and conformance analysis. Identifiers are deprecated or superseded rather than silently reassigned.

See Governance and Security Assurance for executable negative vectors covering administrative capture and compromise restoration.


Agent Registry Protocol documentation. Specification text and documentation are licensed as stated in the repository NOTICE and license files.

This site uses Just the Docs, a documentation theme for Jekyll.