Level 1 - Visible Rules
Publish a charter, actor categories, memory notice, endpoint statement, repair path, exit path, claim boundary, and version date.
Implementation
Practical implementation steps for communities, agent builders, file-memory workflows, and local endpoint tools.
Every item includes why it matters, what it prevents, minimum implementation, stronger implementation, and evidence to keep.
Maturity model
Builders can adopt VNWO incrementally. Level 1 makes rules visible, Level 2 preserves reviewable evidence, and Level 3 makes governance portable and testable.
Publish a charter, actor categories, memory notice, endpoint statement, repair path, exit path, claim boundary, and version date.
Keep file handoff ledgers, endpoint logs, repair records, governance-change notices, and claim-boundary review notes.
Publish machine-readable files, schemas, export packets, forkability policy, and QA checks for prohibited claims and route consistency.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Invisible governance
Publish a human-readable charter.
Publish versioned human-readable and machine-readable rules.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Participation-washing, false consensus, inaccessible consultation, and public input with no decision trace
State what decision is open, who can contribute, how input will be used, and when a response will be published.
Provide accessible and privacy-preserving channels, preserve dissent, publish per-theme dispositions, connect input to a real decision lever, and keep correction, refusal, and exit available.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Self-censorship, hidden reporting, overbroad censorship, classifier laundering, and censorship-cost drift
State that private inquiry, reading, research, and drafting are not routine reporting events and that restrictions target outward execution or concrete rights-boundary issues.
Add non-reporting exceptions, refusal receipts, censorship-cost records, appeal paths, and periodic review for stale restrictions.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Opaque refusal, hidden moderation authority, context collapse, unappealable classification, and AI-as-final-arbiter behavior
Publish when AI judgment-like actions occur and what they may affect.
Add reason codes, evidence basis, human review triggers, appeal paths, refusal logs, and non-retaliation rules.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Thought/action collapse, hidden viewpoint normalization, covert persona rewriting, and safety policy being presented as universal truth
Distinguish private inquiry, source preservation, transformation, refusal, and external execution in public rules.
Use variance records, persona-source integrity logs, least-restrictive refusal notices, and appeal paths for high-impact cognitive restrictions.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Ambient network trust, lateral reach, permanent credentials, and invisible policy expansion
Name the actor, resource, action, purpose, scope, duration, and revocation path for protected access.
Use per-request policy decisions, short-lived workload identity, complete mediation, microsegmentation, visible denials, and independent exception review.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Behavioral inference, association mapping, cross-context tracking, and endpoint discovery becoming surveillance
Inventory metadata fields, purpose, linkability, retention, and secondary-use rules.
Use aggregation, rotation, split knowledge, correlation barriers, local feature extraction, and independent review.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Routine payload inspection, ambient participant profiling, and incident data becoming permanent secondary-use data
Start with aggregate or minimal event data and publish escalation conditions.
Use a monitoring ladder with case IDs, approvals, expiry, review, appeal, and evidence retirement.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Capability being mistaken for permission, hidden tool escalation, budgetless execution, and residual delegation after exit
Publish an agent authority envelope and human approval triggers.
Separate identity, policy, execution, observation, and evidence planes; test stop-anywhere and revocation paths.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Provider, key-custody, administrative, jurisdictional, and migration overreach
Document provider access, key custody, administrative roles, data location, and exit steps.
Add separation of duties, IaC checks, attestation where justified, confidential-computing threat models, and tested provider offboarding.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Undisclosed automation or false representation
Label humans, bots, assistants, agents, organizations, personas, and mixed actors.
Add badges, authority scope, reviewer path, and repair route.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Hidden delegation and unbounded action
State what an agent may and may not do.
Bind authority to scope, logs, review, and revocation.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Opaque classification, over-refusal, hidden moderation, and unappealable machine decisions
Publish decision types, refusal reasons, safe alternatives, and appeal paths when AI judgment materially affects participants.
Use AI judgment receipts, reason codes, evidence summaries, human review triggers, appeal logs, and label retirement records.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Hidden memory capture
State what memory is active and why.
Allow review, correction, export, revocation, and deletion where appropriate.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Silent file ingestion
Treat dropped files as active intake.
Use UAIX Agent File Handoff with disposition and proof-of-use records.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Unauthorized endpoint use
State that public capability metadata is not authorization.
Require consent, logging, revocation, and human approval for escalation.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Permanent misrepresentation
Publish correction and appeal contact path.
Track acknowledgement, investigation, decision, appeal, and durable correction.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Identity and memory lock-in
Publish account closure, export, revocation, and correction instructions.
Support identity export, memory export, endpoint revocation, agent disengagement, disposition receipts, and peaceful forking.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Confusing export with erasure or account termination
Explain export, transfer, deletion, closure, retention, and correction as separate actions.
Provide separate flows and receipts for each action with UTC timestamps and plain-language limits.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Orphaned permissions after exit
Revoke active agent delegation and endpoint access when scope ends.
Audit tokens, webhooks, capability metadata, logs, and hidden persistence after exit.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Overclaiming and lane conflict
List what the network does and does not claim.
Add safer replacement wording for prohibited claims.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Silent rule drift
Publish last reviewed date and change summary.
Maintain version history with claim-boundary and machine-readable file impact.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
AI readers ingesting stale or vague rules
Publish llms.txt and vnwo.json equivalents.
Add open-rules.json, claim-boundaries.json, sitemap.xml, robots.txt, and structured data.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
Exclusion, hidden tracking, and dark patterns
Add privacy and accessibility pages.
Test keyboard navigation, contrast, reduced motion, mobile reflow, no-file-upload posture, and no-sensitive-data intake.
This keeps authority visible, scoped, reviewable, repairable, portable, and exit-friendly.
False legal-compliance or deletion guarantees
State that VNWO guidance is not legal advice and does not execute deletion.
Map portability, erasure, restriction, sensitive-data retention, and correction to civic design checks with implementation ownership clearly assigned.
Publish a public charter, actor disclosure, memory consent, endpoint boundary statement, repair path, exit instructions, and claim-boundary note.
Keep disposition records, repair records, endpoint logs, governance-change notices, version history, and evidence to support public claims.
Publish machine-readable files, schemas, example packets, exit packets, fork packets, and claim-boundary lint checks for review.