Skip to content

Governance: enforce one-member voting authority and revocation lifecycle (TRR-03, TRR-05, TRR-22) #307

Description

@NeaBouli

Parent audit register: #303
Related future ballot epic: #232
Rollout tracker: #29

Objective

Close the current one-member-many-keys and stale-authority paths without silently destroying anonymity. This is a current permission-register and reward-integrity problem, not an implementation of the deferred ballot engine.

Acceptance criteria

  • Approve a versioned rule for active permission keys and identity commitments per member.
  • Remove the direct onboarding bypass or make AnyoneCanJoin and admin approval semantics explicit and enforced.
  • Prevent one member from obtaining multiple votes or multiple RateToEarn payouts for one suggestion through multiple keys or commitments.
  • Revoke or invalidate voting authority when membership is removed, with an explicit privacy-preserving design.
  • Confirm and test Big Purge re-registration and re-vote semantics.
  • Add replay, rotation, exclusion, purge, payout and export/import tests.
  • Keep Governance: implement the domain-configurable ballot engine after rollout stabilization #232 deferred; link only the approved invariants needed by its later ballot stages.

Safety boundary

No new ballot engine, production identity, ceremony, migration or rollout credit.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingdesigngoPull requests that update go code

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions