This document describes the Mutually Assured Accountability (MAA) framework implementation for the VAE Dataset Normalizer project.
MAA ensures that all participants in the project ecosystem—maintainers, contributors, users, and automated systems—are accountable to each other through transparent, verifiable mechanisms.
-
Every action is attributable to an identifiable actor
-
Every actor can verify others' compliance
-
Accountability flows in all directions (not just top-down)
-
Trust is earned through verifiable behavior, not assumed
-
All decisions are documented
-
All changes are traceable
-
All policies are publicly accessible
-
All enforcement is consistent
Reputation is earned through consistent, positive contributions:
| Level | Criteria | Privileges |
|---|---|---|
New |
First contribution |
Submit issues, MRs to Perimeter 3 |
Established |
5+ accepted contributions |
Perimeter 2 candidacy, priority review |
Trusted |
10+ contributions, 3+ months active |
Direct commit to dev branches |
Core |
Sustained excellence, security vetted |
Full maintainer access |
Merit is the objective quality of contributions:
-
Code Quality: Passes lints, tests, security scans
-
Documentation: Complete, accurate, helpful
-
Review Quality: Thorough, constructive, timely
-
Community: Helpful in discussions, welcoming to newcomers
Rights are granted based on reputation and merit:
| Right | Description |
|---|---|
Submit |
Create issues, MRs, discussions |
Review |
Provide code reviews (advisory) |
Approve |
Approve MRs for merge (Perimeter 2+) |
Merge |
Merge approved MRs (Perimeter 1) |
Release |
Create releases (Core maintainers) |
Govern |
Participate in governance decisions (Core) |
Each role has defined responsibilities:
-
Follow contribution guidelines
-
Respond to review feedback
-
Sign commits (DCO)
-
Respect code of conduct
-
All Perimeter 3 responsibilities, plus:
-
Provide quality reviews
-
Mentor new contributors
-
Report security issues privately
-
Maintain assigned components
Automated and manual monitoring ensures accountability:
# CI/CD pipeline checks
just validate # Full RSR compliance
just audit-licence # SPDX compliance
just security-scan # Vulnerability scan
just test # Test coverage-
Timely review of contributions (< 7 days initial response)
-
Clear feedback on rejections
-
Recognition for contributions
-
Safe, inclusive environment
-
Transparent governance
-
Quality contributions
-
Good faith engagement
-
Respect for others
-
Adherence to guidelines
-
Timely responses to feedback
All changes are tracked with full provenance:
-
Git history with signed commits
-
SPDX headers on all files
-
.well-known/provenance.jsonfor release attestation -
CI/CD logs for build verification
-
Git history is append-only (no force push to main)
-
Release artifacts are checksummed
-
SBOM generated for each release
Violations are addressed proportionally:
-
Informal reminder: Minor, first-time issues
-
Formal warning: Repeated minor or single moderate issues
-
Temporary restriction: Serious or repeated moderate issues
-
Permanent ban: Severe violations or pattern of harm
-
All enforcement decisions can be appealed
-
Appeals reviewed by uninvolved maintainers
-
Final appeal to governance body
This MAA framework satisfies RSR Category 11 requirements:
-
✓ MAA principles embedded in architecture
-
✓ RMR utilities defined
-
✓ RMO utilities defined
-
✓ Formal verification of accountability properties (via Isabelle proofs)
-
✓ Audit trails via Git + SPDX
-
✓ Provenance chains in
.well-known/provenance.json
| Component | Status | Notes |
|---|---|---|
RMR Tracking |
Partial |
Manual process, automation planned |
RMO Monitoring |
Active |
CI/CD integration complete |
Audit Trail |
Active |
Git + SPDX + provenance.json |
Enforcement |
Defined |
Process documented, rarely needed |
Verification |
Active |
|