The Registry Continuity Fallacy — Protect the Ledger, Not the Gatekeeper
What must survive an institution’s failure: the ledger, or the gatekeeper?

Note 69 asked a simple question:
Stability of what?
There is another question hiding beneath it.
Continuity of what?
Regional Internet Registries often present registry continuity as an argument for preserving the institution currently operating the registry. In the AFRINIC dispute, this becomes a familiar claim:
AFRINIC must be protected because Africa cannot afford the collapse of its number registry.
The first part is debatable.
The second part is true.
Africa cannot afford the loss of number-registration continuity. No region can. Uniqueness must be preserved. Registration records must remain accurate. RDAP, WHOIS, reverse DNS and RPKI services must continue. Running networks must not be destabilised. Downstream customers must not become collateral damage. Resource disputes must have somewhere independent to be decided.
But none of this proves that AFRINIC’s present board, present interpretation of its Registration Service Agreement, present out-of-region narrative, present institutional self-image or present gatekeeping powers must also be preserved.
That substitution is the registry continuity fallacy.
Registry continuity is not itself a fallacy.
The fallacy is the claim that continuity of the function requires continuity of every authority claimed by the institution currently performing it.
It does not.
Note 69 distinguished institutional stability from routed-network and customer-continuity stability. Note 70 takes the distinction one layer deeper: the continuity of registry services must be separated from the continuity of the registry corporation’s power.
The function is real
The registry function matters.
Internet numbers must remain unique. Two unrelated operators cannot be given the same exclusive registration claim over the same address block. Historical records must be preserved. Changes of control must be recorded. Fraudulent alterations must be prevented. Public directory services must remain available. Security assertions must remain verifiable.
This is not political theatre.
It is real coordination.
AFRINIC currently provides or supports registration data, RDAP, WHOIS, reverse DNS, RPKI and related routing services. Those services have operational value. AFRINIC’s own documentation describes RPKI, reverse DNS and routing registries as essential services alongside its management of IP addresses and ASNs.
The mistake begins when these functions are bundled together with an entirely different category of claims:
- That AFRINIC represents Africa.
- That its service region gives it political standing.
- That its board may expand the meaning of the RSA after resources have become operationally embedded.
- That it may regulate leasing, commercial use or customer geography.
- That challenging its discretion threatens the Internet.
- That preserving technical services requires protecting the institution from ordinary legal accountability.
None of those propositions follows from the need to maintain a registry.
A database needs continuity.
A sovereignty claim does not.
What registry continuity actually requires
The continuity requirement has five parts.
Number uniqueness
The same number resource must not be registered to incompatible claimants at the same time.
This is the original technical justification for the registry layer. It is narrow. It is objective. It can be audited.
Uniqueness does not require the registry to decide whether it approves of an operator’s business model. It does not require a theory of regional commercial loyalty. It does not require the registry to own the value created through use of the number.
It requires an accurate answer to a limited question:
Who currently holds the recognised registration claim over this resource?
Registration accuracy
The registry must preserve accurate information about number resources, registered holders, authorised changes, transfers, security status and relevant dispute metadata.
Accuracy requires evidence, audit trails and controlled updates.
It does not require discretionary moral judgment.
A registry may correct a forged transfer.
It may prevent duplicate registration.
It may record that a claim is disputed.
It should not rewrite operational reality merely because its directors have adopted a new political interpretation of an old contract.
The ledger must be protected from corruption.
It must also be protected from the institution operating it.
Publication and security continuity
RDAP, WHOIS, reverse DNS, RPKI repositories and related publication services must remain available during institutional failure, litigation, insolvency, governance disputes or transition.
RPKI deserves particular care. It is not merely a file that can be copied to another server. Certificates, repositories, manifests, revocation information, ROAs, signing arrangements and relying-party trust must remain coherent. AFRINIC’s own documentation notes that validators use the AFRINIC Trust Anchor Locator to retrieve objects from its RPKI repository.
That makes planned succession necessary.
It does not make AFRINIC immortal.
The complexity of transitioning a critical service is an argument for building a transition mechanism before failure. It is not an argument for granting permanent authority to the current operator.
Running-network and customer continuity
Registry disputes must not be converted into routing disruption, security pollution, forced renumbering or customer failure.
The primary continuity obligation is not to the registry office.
It is to the networks using the numbers.
Operators have built infrastructure around these resources. Customers have built systems around that infrastructure. Security rules, allowlists, APIs, payment relationships, cloud deployments, contracts and compliance systems may all depend on stable network identifiers.
A registry action that preserves institutional authority by threatening those systems has not protected continuity.
It has reversed it.
Independent adjudicative continuity
Disputes will happen.
Ownership claims will conflict. Transfers will be challenged. Fraud will be alleged. Contracts will be interpreted differently. Corporate control may change. Creditors, courts, operators and registries may disagree.
The answer cannot be to let the registry act simultaneously as recordkeeper, claimant, judge and executioner.
A genuine continuity system needs an independent forum capable of deciding disputes without destroying the asset under dispute.
During adjudication, the default should be preservation of the last verified operational state. The system may block conflicting alterations. It should not revoke, pollute or redistribute live resources merely because the registry has taken one side.
Dispute isolation is part of continuity.
Registry self-help is not.
What continuity does not require
No packet carries the name of an AFRINIC director.
No RDAP response requires AFRINIC’s institutional pride.
No reverse DNS delegation depends on an out-of-region political narrative.
No ROA requires a theory that Africa is a single administrative polity represented by a Mauritian company.
No uniqueness invariant requires an expansive interpretation of the RSA.
The things that must continue are:
- The records.
- The services.
- The security chain.
- The ability to make legitimate updates.
- The operation of existing networks.
- The protection of downstream customers.
- The availability of independent adjudication.
The things that may be replaced include:
- The board.
- The corporate shell.
- The service operator.
- The policy machinery.
- The fee structure.
- The contractual framework.
- The enforcement theory.
- The institution’s claimed monopoly over regional legitimacy.
This distinction is not radical.
It is the basic logic of resilient infrastructure.
The more critical a function becomes, the less it should depend on the survival, goodwill or legal theory of one organisation.
The RIR system has already conceded the point
The RIR system’s own continuity work demonstrates that registry functions can be separated from the institution currently performing them.
In 2020, an NRO emergency-backend discussion identified WHOIS/RDAP, reverse DNS, RPKI and IRR as services requiring backup. It considered last-known-good snapshots and the possibility that another RIR could instantiate services when one RIR entered contingency.
The proposed ICP-2 principles later stated that an RIR should maintain redundancies and participate in record sharing sufficient to enable another RIR to perform its services. The same document contemplated transferring operations to a successor or interim entity after derecognition.
These proposals remain too centred on the incumbent RIR club. They assume that continuity should be controlled by the same institutional class whose authority is in question.
But they concede the essential fact.
The shell is replaceable.
The service can be transferred.
The records can be shared.
A successor can operate the function.
Once this is admitted, “AFRINIC must survive because the registry must survive” is no longer a technical statement.
It is an institutional preference.
From continuity to immunity
The registry continuity fallacy becomes dangerous when it is used to obtain political or legal insulation.
The sequence is predictable.
First, the institution declares that its services are indispensable.
Then it treats itself as indistinguishable from those services.
A challenge to the board becomes a challenge to the registry.
A challenge to an RSA interpretation becomes a threat to uniqueness.
A court order becomes a threat to Internet stability.
A demand for portability becomes an attack on the regional system.
A request for independent adjudication becomes interference with community governance.
Finally, protecting continuity becomes protecting the institution from accountability.
This is continuity laundering.
A real technical requirement is used to protect unrelated authority claims.
The institution holds the function in front of itself like a shield.
The implicit message is simple:
Do not constrain us, because something important depends on us.
But critical dependency should produce the opposite conclusion.
The more important the registry function is, the more auditable, replicated, portable, separable and replaceable its operator must become.
Indispensable infrastructure requires replaceable administrators.
Anything else is hostage architecture.
A continuity architecture
The alternative to institutional protection is not registry collapse.
It is an explicit continuity architecture.
First, the authoritative registry state should be versioned, independently auditable and continuously replicated outside the exclusive control of one corporate entity. A historical chain of authorised changes must survive board disputes, insolvency, litigation and technical failure.
Second, RDAP, WHOIS, reverse DNS and related directory services should have tested failover arrangements. Continuity plans should identify the data, credentials, delegation changes and operational authority required to move each service.
Third, RPKI succession must be designed as a first-class security process. It requires defined key-custody arrangements, repository continuity, emergency publication procedures and a credible migration path for certificates and authorisations. A static backup is not enough.
Fourth, registry administration must be separated from enforcement. The operator maintaining the record should not possess unilateral authority to destroy the underlying operational position because of a commercial or political disagreement.
Fifth, disputes should be recorded without contaminating unrelated operations. A disputed resource may carry conflict metadata. Conflicting transfers may be paused. Existing routes and valid security objects should not be destroyed unless an independent decision specifically requires it.
Sixth, portability must become a hard continuity right. A resource holder should be able to move registration services to a qualified successor without renumbering its network and without requiring discretionary permission from the institution it is leaving.
Seventh, continuity triggers must be objective and transparent. Failover should not depend solely on the political judgment of another RIR board. Courts, independent technical custodians, resource-holder representatives and predefined operational criteria may all have roles.
The goal is not to create another sovereign above AFRINIC.
The goal is to ensure that no sovereign-like gatekeeper is required at all.
AFRINIC may continue
Separating AFRINIC from registry continuity does not require destroying AFRINIC.
AFRINIC may continue to operate technical services.
Its employees may preserve valuable operational knowledge.
Its systems may remain part of a transition architecture.
Its corporate existence may continue if it can perform a narrow, accountable and replaceable function.
But those possibilities must not be confused with a right to preserve every authority claim AFRINIC has made.
Technical usefulness does not validate institutional overreach.
Operational experience does not create political title.
Continuing to run a registry does not make the operator owner of the region, the resources or the future.
AFRINIC may be one operator of African number-registration functions.
It cannot be the metaphysical embodiment of African Internet continuity.
The correct rescue narrative
There is a rational version of the statement that AFRINIC needs to be saved.
It is this:
The continuity of Internet number registration for African networks must be protected.
That means protecting uniqueness.
Protecting accurate records.
Protecting RDAP and WHOIS access.
Protecting reverse DNS.
Protecting RPKI publication and migration.
Protecting running networks.
Protecting downstream customers.
Protecting neutral dispute resolution.
It does not mean:
- Protecting the current board from challenge.
- Protecting expansive RSA interpretations.
- Protecting out-of-region political narratives.
- Protecting institutional prestige.
- Protecting low-liability, high-discretion gatekeeping.
- Protecting every authority claim simply because it was made by the incumbent registry.
These are different objectives.
The RIR camp depends on treating them as one.
Protect the ledger
The final test is simple.
When someone says AFRINIC must be protected for the sake of registry continuity, ask what specifically must continue.
The records?
Preserve them.
The directory services?
Replicate them.
The reverse zones?
Provide failover.
The RPKI system?
Build a secure succession path.
Running networks?
Prohibit destructive unilateral action.
Disputes?
Send them to an independent forum.
But if the answer is that AFRINIC’s board, policy authority, territorial narrative and discretionary enforcement powers must all remain beyond challenge, then the argument is no longer about continuity.
It is about control.
Protect the ledger, not the gatekeeper.
Protect the chain of custody, not the chain of command.
Protect African network continuity, not continental custodianship.
The registry must be capable of surviving the institution.
The Internet must never again be told that preserving a database requires preserving a private sovereignty claim.
Registry continuity is necessary.
Institutional immortality is not.
Which continuity do you support?
The RIR system says it is defending continuity.
But the continuity it most consistently defends is not the continuity of the live network.
It is the continuity of its own power over live infrastructure and network operators: the power to approve, suspend, deregister, reinterpret and ultimately terminate the conditions under which a network can continue to operate.
That is not network continuity.
It is continuity of control.
My position is the opposite.
I protect the continuity of the live network: its routes, customers, services, security objects, contractual reliance and operational existence.
Registry institutions may continue only insofar as they serve that continuity. They do not acquire a superior continuity interest merely because they hold the database.
So the hard question is not for AFRINIC, the NRO or the RIR boards.
It is for every network operator:
Which continuity do you support?
The continuity of your live network?
Or the continuity of an institution’s power to terminate your network’s continuity?
There is no neutral answer.
If you support the first, then portability, independent adjudication, non-destructive dispute handling, registry/enforcement separation and operator-first failover are not optional reforms.
They are the minimum architecture of continuity.
If you support the second, then say plainly what is being protected:
Not the registry.
Not the Internet.
Not Africa.
But the gatekeeper’s continuing power over live infrastructure.
They protect the continuity of power over live infrastructure and network operators.
I protect the continuity of the live network.