PipeRoll - Agent Incident Registry · about · contribute · data · constitution

The PipeRoll Constitution

The rules the registry binds itself to - cited by number in the records

The PipeRoll Constitution

The rules the registry binds itself to. They are load-bearing: records cite them by number (see PIR-2026-0045, registered under rule 4 before the registry had a single visitor). Amendments are made by pull request, take effect on merge, and never renumber existing rules - a retired rule keeps its number, like a retired id.

1. Verification before registration

Nothing enters the registry unverified. Every record is checked against primary sources, adversarially - looking for corrections, retractions, and inflated figures, not confirmation. "Unknown" is an honest field value; an invented one is grounds for rejection.

2. Never wrong in public

Corrections are published inside the affected record, never slipped. Every published number carries its basis; where sources conflict, the record states the range and names the conflict. Being late is acceptable; being quietly wrong is not.

3. Permanent identity, unerasable history

Ids are opaque permanent names: never deleted, never reused, never renumbered. Chronology lives in the record and the citation, not the id. History does not rewrite: force-pushes are blocked, commits are signed, and releases are archived externally (Zenodo DOI) beyond the registry's own custody.

4. Conflicts are disclosed inside the record

Anyone connected to an incident - as operator, funder, competitor, insurer, or otherwise - may still submit or register it, but the connection is stated in the record itself, where every future reader sees it. Undisclosed conflicts, once found, are treated as rule-2 corrections and published. This binds the founding editor first: the registry's first record discloses the founder's stake in its subject.

5. Open data, open submissions, verified registration

The data is CC BY 4.0, the schema is open and stays open, and anyone - including AI agents - may submit. Registration authority does not open: merge is the act of registration and rests with the editors. Wikipedia intake, CVE authority.

6. Completeness honesty

Registry counts are a floor, never a frequency estimate. Absence from the registry is not evidence of safety. No failure rate can be computed from registry data alone, because the exposure base is unknown - and every aggregate the registry publishes says so.

7. The registry measures; it does not sell verdicts

PipeRoll records what happened and what the evidence is. It does not rate vendors, certify systems, or underwrite risk - conclusions belong to the reader, the underwriter, and the court, all of whom need a measurer with nothing to sell them.