Sign in
P-13ProposedTier 0 operations, Gelhaus Solutions (Tier 0)

Approvals and solo mode

Version
v1
In force since
Not yet
Next review
At adoption
Snapshot
None yet
Adopted by
Proposed for founding adoption
Signature
At adoption
Log entry
Not appended yet
Binding text
English

Proposed, not in force

Open for comment until 28 October 2026, 00:00 UTC. Nothing here binds anyone until it is adopted.

1

Scope

1.1
Bindingp13-c1

This policy sets who approves root changes and how, the one exception while a single person holds a root role, and what Tier 0 may do in an emergency.

2

Four eyes

2.1
Enforced rulep13-c2

Every root zone change and key event, every TLD delegation and withdrawal, every root role grant, every blocklist override, every manual DNSSEC step and every policy version Tier 0 adopts waits for a second authorised person. Nobody decides their own request.

Rule approval.four_eyes. Limits: A non-negotiable, which the database enforces by comparing decider and requester.

2.2
Enforced rulep13-c3

The approver confirms with a passkey at the moment of approval, within the window of P-7 4.2, and sees the exact change. Its hash is fixed when it is requested and checked again before it runs; a change to it voids the approval.

Rule approval.integrity.

2.3
Enforced settingp13-c4

A request nobody decides expires after 72 hoursfixed.

3

Solo mode

3.1
Enforced rulep13-c5

Until two distinct accounts have ever held a root role, the one root person may approve any four-eyes action alone. Solo mode ends for good once a second root person exists, even if that person's role is later taken away.

Rule approval.solo.

3.2
Enforced rulep13-c6

A solo approval is confirmed with a passkey at the moment of approval and applies at once. A stolen session holds no passkey, so it can neither propose nor approve. Every solo approval is flagged as decided alone, for good, in the audit log and the transparency log.

Rule approval.solo_passkey. Limits: The passkey confirmation belongs to the rule and is not a setting.

4

Emergencies

4.1
Bindingp13-c7

In an emergency, Tier 0 may suspend a clause or tighten a setting, never loosen one, for reasons of security, stability or a collision with the IANA namespace. It acts narrowly, with reasons and an end date, and the regular change opens the same day.

4.2
Enforced settingp13-c8Not enforced yet

An emergency measure applies at once, in solo mode too, where it is flagged. It goes through public comment within 30 daysfixed, lapses after 90 daysfixed unless the owning council reaffirms it, and ends after 1 yearfixed at the latest. It is published like a veto.