Builder Checklist

Practical implementation steps for communities, agent builders, file-memory workflows, and local endpoint tools.

Workflow showing review, disposition, proof, .uai update, and source-file cleanup.
The same review discipline used for file memory applies to governance changes, endpoints, and agent authority.

Every item includes why it matters, what it prevents, minimum implementation, stronger implementation, and evidence to keep.

Three levels of VNWO implementation

Builders can adopt VNWO incrementally. Level 1 makes rules visible, Level 2 preserves reviewable evidence, and Level 3 makes governance portable and testable.

Level 1 - Visible Rules

Publish a charter, actor categories, memory notice, endpoint statement, repair path, exit path, claim boundary, and version date.

Level 2 - Reviewable Evidence

Keep file handoff ledgers, endpoint logs, repair records, governance-change notices, and claim-boundary review notes.

Level 3 - Portable and Testable Governance

Publish machine-readable files, schemas, export packets, forkability policy, and QA checks for prohibited claims and route consistency.

Checklist item 01

Publish public rules

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Invisible governance

Minimum implementation

Publish a human-readable charter.

Strong implementation

Publish versioned human-readable and machine-readable rules.

Checklist item 02

Publish participation and disposition rules

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Participation-washing, false consensus, inaccessible consultation, and public input with no decision trace

Minimum implementation

State what decision is open, who can contribute, how input will be used, and when a response will be published.

Strong implementation

Provide accessible and privacy-preserving channels, preserve dissent, publish per-theme dispositions, connect input to a real decision lever, and keep correction, refusal, and exit available.

Checklist item 03

Publish free-internet and non-reporting posture

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Self-censorship, hidden reporting, overbroad censorship, classifier laundering, and censorship-cost drift

Minimum implementation

State that private inquiry, reading, research, and drafting are not routine reporting events and that restrictions target outward execution or concrete rights-boundary issues.

Strong implementation

Add non-reporting exceptions, refusal receipts, censorship-cost records, appeal paths, and periodic review for stale restrictions.

Checklist item 04

Define AI judgment boundaries

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Opaque refusal, hidden moderation authority, context collapse, unappealable classification, and AI-as-final-arbiter behavior

Minimum implementation

Publish when AI judgment-like actions occur and what they may affect.

Strong implementation

Add reason codes, evidence basis, human review triggers, appeal paths, refusal logs, and non-retaliation rules.

Checklist item 05

Protect cognitive liberty and thought boundaries

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Thought/action collapse, hidden viewpoint normalization, covert persona rewriting, and safety policy being presented as universal truth

Minimum implementation

Distinguish private inquiry, source preservation, transformation, refusal, and external execution in public rules.

Strong implementation

Use variance records, persona-source integrity logs, least-restrictive refusal notices, and appeal paths for high-impact cognitive restrictions.

Checklist item 06

Design least-privilege access

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Ambient network trust, lateral reach, permanent credentials, and invisible policy expansion

Minimum implementation

Name the actor, resource, action, purpose, scope, duration, and revocation path for protected access.

Strong implementation

Use per-request policy decisions, short-lived workload identity, complete mediation, microsegmentation, visible denials, and independent exception review.

Checklist item 07

Minimize metadata and correlation

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Behavioral inference, association mapping, cross-context tracking, and endpoint discovery becoming surveillance

Minimum implementation

Inventory metadata fields, purpose, linkability, retention, and secondary-use rules.

Strong implementation

Use aggregation, rotation, split knowledge, correlation barriers, local feature extraction, and independent review.

Checklist item 08

Use staged observability

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Routine payload inspection, ambient participant profiling, and incident data becoming permanent secondary-use data

Minimum implementation

Start with aggregate or minimal event data and publish escalation conditions.

Strong implementation

Use a monitoring ladder with case IDs, approvals, expiry, review, appeal, and evidence retirement.

Checklist item 09

Contain agentic authority

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Capability being mistaken for permission, hidden tool escalation, budgetless execution, and residual delegation after exit

Minimum implementation

Publish an agent authority envelope and human approval triggers.

Strong implementation

Separate identity, policy, execution, observation, and evidence planes; test stop-anywhere and revocation paths.

Checklist item 10

Review cloud sovereignty

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Provider, key-custody, administrative, jurisdictional, and migration overreach

Minimum implementation

Document provider access, key custody, administrative roles, data location, and exit steps.

Strong implementation

Add separation of duties, IaC checks, attestation where justified, confidential-computing threat models, and tested provider offboarding.

Checklist item 11

Define actor categories

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Undisclosed automation or false representation

Minimum implementation

Label humans, bots, assistants, agents, organizations, personas, and mixed actors.

Strong implementation

Add badges, authority scope, reviewer path, and repair route.

Checklist item 12

Disclose agent authority

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Hidden delegation and unbounded action

Minimum implementation

State what an agent may and may not do.

Strong implementation

Bind authority to scope, logs, review, and revocation.

Checklist item 13

Review AI judgment and refusal

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Opaque classification, over-refusal, hidden moderation, and unappealable machine decisions

Minimum implementation

Publish decision types, refusal reasons, safe alternatives, and appeal paths when AI judgment materially affects participants.

Strong implementation

Use AI judgment receipts, reason codes, evidence summaries, human review triggers, appeal logs, and label retirement records.

Checklist item 14

Scope memory use

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Hidden memory capture

Minimum implementation

State what memory is active and why.

Strong implementation

Allow review, correction, export, revocation, and deletion where appropriate.

Checklist item 15

Define file handoff review

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Silent file ingestion

Minimum implementation

Treat dropped files as active intake.

Strong implementation

Use UAIX Agent File Handoff with disposition and proof-of-use records.

Checklist item 16

Separate metadata from authorization

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Unauthorized endpoint use

Minimum implementation

State that public capability metadata is not authorization.

Strong implementation

Require consent, logging, revocation, and human approval for escalation.

Checklist item 17

Provide repair paths

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Permanent misrepresentation

Minimum implementation

Publish correction and appeal contact path.

Strong implementation

Track acknowledgement, investigation, decision, appeal, and durable correction.

Checklist item 18

Provide exit paths

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Identity and memory lock-in

Minimum implementation

Publish account closure, export, revocation, and correction instructions.

Strong implementation

Support identity export, memory export, endpoint revocation, agent disengagement, disposition receipts, and peaceful forking.

Checklist item 19

Distinguish portability, deletion, and closure

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Confusing export with erasure or account termination

Minimum implementation

Explain export, transfer, deletion, closure, retention, and correction as separate actions.

Strong implementation

Provide separate flows and receipts for each action with UTC timestamps and plain-language limits.

Checklist item 20

Revoke endpoint and agent capability

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Orphaned permissions after exit

Minimum implementation

Revoke active agent delegation and endpoint access when scope ends.

Strong implementation

Audit tokens, webhooks, capability metadata, logs, and hidden persistence after exit.

Checklist item 21

Publish claim boundaries

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Overclaiming and lane conflict

Minimum implementation

List what the network does and does not claim.

Strong implementation

Add safer replacement wording for prohibited claims.

Checklist item 22

Version governance changes

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Silent rule drift

Minimum implementation

Publish last reviewed date and change summary.

Strong implementation

Maintain version history with claim-boundary and machine-readable file impact.

Checklist item 23

Create machine-readable metadata

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

AI readers ingesting stale or vague rules

Minimum implementation

Publish llms.txt and vnwo.json equivalents.

Strong implementation

Add open-rules.json, claim-boundaries.json, sitemap.xml, robots.txt, and structured data.

Checklist item 24

Review accessibility and privacy

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

Exclusion, hidden tracking, and dark patterns

Minimum implementation

Add privacy and accessibility pages.

Strong implementation

Test keyboard navigation, contrast, reduced motion, mobile reflow, no-file-upload posture, and no-sensitive-data intake.

Checklist item 25

Map privacy-law alignment without overclaiming

Why it matters

This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.

What it prevents

False legal-compliance or deletion guarantees

Minimum implementation

State that VNWO guidance is not legal advice and does not execute deletion.

Strong implementation

Map portability, erasure, restriction, sensitive-data retention, and correction to civic design checks with implementation ownership clearly assigned.

VNWO maturity model

Level 1 - Visible Rules

Publish a public charter, actor disclosure, memory consent, endpoint boundary statement, repair path, exit instructions, and claim-boundary note.

Level 2 - Reviewable Evidence

Keep disposition records, repair records, endpoint logs, governance-change notices, version history, and evidence to support public claims.

Level 3 - Portable and Testable Governance

Publish machine-readable files, schemas, example packets, exit packets, fork packets, and claim-boundary lint checks for review.

Theory, minimum practice, stronger practice, and failure modes

Why this matters

The checklist turns the VNWO charter into maturity levels: visible rules, reviewable evidence, and portable/testable governance. Each level should produce evidence a reviewer can inspect.

Minimum implementation

Publish public charter, actor disclosure, memory consent, endpoint boundary, repair path, exit path, claim boundary, and version history.

Stronger implementation

Add file handoff ledgers, endpoint refusal logs, exit packets, fork packets, JSON schemas, accessibility evidence, and privacy posture checks.

Concrete example

A builder reaches Level 2 when every file handoff has a disposition ledger, every endpoint profile has a revocation path, and every claim change updates the changelog.

Common failure modes

  • Checklist completed without evidence
  • Machine-readable files missing
  • Repair path only exists by email
  • Exit only deletes account without export

Build networks people can leave and still choose to trust.