# Ecosystem Governance Framework — primary document (stub)

**Status: draft for discussion. This is not yet a governance act.**

Structured per the ToIP Governance Metamodel. Each section below is a placeholder
to be completed by the governing authorities before publication.

## 1. Identifier

The framework is identified by the meta-list's authority identifier,
`did:web:trustedlistoftrustedlists.org` (upgrade path: `did:webvh`).

## 2. Governing authority and administering authority

The metamodel distinguishes the **governing authority** — the stewards, who set
the rules — from the **administering authority** — whoever operates the machinery
under mandate. Operating the meta-list confers no say over it.

- Governing authorities: *to be recorded on charter.*
- Administering authority: *to be recorded on mandate.*

## 2a. Separation of artifacts

Governance and technology are separate artifacts with separate lifecycles, and
neither substitutes for the other. This document and its decision records are
authored and amended by the governing authority. The Meta-List Profile, the
schemas and the conformance suite live in open community process and are
versioned independently.

## 3. Glossary

"Authority", never "root of trust". "Recognised", not "approved". Regulatory
lists are "referenced as authoritative", never "admitted". A mirrored list has a
single source of truth, which is always the framework that publishes it.

## 4. Recognition criteria

The criteria begin deliberately light and are meant to tighten as the layer
proves itself: a heavy gate at the start would exclude exactly the registries
this layer most needs — sovereign registers first among them.

A framework seeking recognition demonstrates, among other things:

1. **Published governance and accreditation criteria** — the rules by which it
   accredits issuers are public and reviewable.
2. **Identified legal accountability** — the framework and the issuers on its
   list are identifiable, and the assurance level of that identification is
   stated. Sovereign and national organisation identifiers come first; the LEI
   is one accepted option among others and is **not a precondition**. Identifier
   schemes compete on assurance level, not by being the single named
   specification.

   > Diverges from whitepaper v0.8, which names the LEI as a requirement. A
   > sovereign will not accept an external identifier scheme as equivalent to
   > its own, and a hard LEI requirement would exclude the government registries
   > this layer most needs. Raised from the Ayra perspective; the whitepaper
   > needs the same correction.
3. **Conformance testing of issuers** against the relevant credential
   specifications, rather than self-declaration.
4. **Supervision and revocation procedures** — accreditation is continuous and
   can be withdrawn.
5. **Machine-readable publication of its own trusted list.**

Admission is criteria-based and appealable: no incumbent veto, no exclusivity
demanded of members, and the accreditor role itself open — new frameworks and
new accreditation bodies can qualify at any time.

Regulatory lists are referenced as authoritative and are not assessed against
these criteria — this framework has no authority over them.

## 4a. The legal spine

Criteria alone would make this a directory. The enforceable process is rebuilt
on the legal architecture the iSHARE Foundation operates in production:

- **Accession agreements** binding every listed framework to the published
  criteria.
- **Continuous supervision** carrying eIDAS-style status, so trouble is visible
  before it is terminal.
- **Defined procedures** for suspension, removal and incident handling.
- **An appeal path** for admission and status decisions, so the governing
  authorities' own judgment is accountable.

Openness without this spine would make the meta-list a directory; the spine
without openness would make it a cartel. The design requires both.

## 5. Status procedures

Status vocabulary: `granted`, `undersupervision`, `suspended`, `withdrawn`,
`supervision ceased`. Only `granted` and `undersupervision` may be relied upon.
Withdrawn and ceased entries remain published for at least the validity period of
credentials issued under them.

## 6. Conflict of interest

Stewards that also appear on the meta-list as member frameworks take no part in
decisions on their own framework's admission or status. Their framework is
assessed against the same published criteria by the remaining stewards or an
independent assessor. Recusals are recorded in the decision record.

## 7. Appeals

Admission and status decisions are appealable within 30 days. Appeals and their
outcomes are published as decision records in `governance/decisions/`.

## 8. Legal agreements

Accession terms, supervision, liability allocation and exit. Recognition
transfers no liability: each framework remains fully accountable for its own
accreditations under its own legal regime.

## Decision records

Every status change references a record in [`decisions/`](decisions/), named
`YYYY-MM-DD-<framework>-<status>.md`, with reason, decision-makers, recusals and
the appeal window. CI refuses a status change without one.
