Governance
The specification is developed in the open: Draft 07 is the first public draft (earlier numbers were internal working drafts). Changes go through public issues and pull requests (see CONTRIBUTING.md in the repository) and a changelog, published drafts are never edited, and the design commitments below are part of the specification's charter: they change only through a public process with a stated rationale.
Design commitments against misuse (specification section 16)
- Subjects are agents and organizations, not individuals. A claim type whose subject is a natural person is out of scope for the core vocabulary.
- No global score. No aggregate rating, ranking or trust number. Claims are specific, independently issued and expire.
- No mandatory root. Verifiers choose their roots, may run several, and may drop any issuer at any time. Multiple independent logs are expected.
- Reputation stays out of the core. No mechanism to publish, exchange or aggregate track records across contexts.
- Transparency watches issuers, not subjects. The log is not a surveillance feed, and envelopes exchanged between agents are never submitted to it.
- Minimal disclosure. Claims carry what a verifier needs and no more; detail lives behind evidence hashes; Agent IDs are pseudonymous until bound.
- Right to retire. Any identity can retire itself by a self-signed claim that no issuer can block.
A registry that violates these commitments forfeits use of the ATEP name and root.
Process, honestly
Today the project has one steward and no independent members, working group or standards body. The intended path is to submit an Internet-Draft after the remaining implementation milestones, to seek a second implementer outside the project, and to register the provisional identifiers with IANA when the draft is stable. None of that has happened. The hosting arrangement for the public repository (one organization or two) is undecided.
Licensing
Code: Apache-2.0. Specification text: CC BY 4.0.