How we share

Publishing our own sharing rules is the constitution’s move: instead of “trust us with your access request,” the answer is “here is exactly what we publish, what we hold, and why” — which is the strongest possible answer to “what are you hiding?”

Two stable states, not three

A “friends and collaborators” tier that’s more open than private but less than public sounds reasonable and doesn’t survive contact with how sharing actually works. Trust doesn’t survive forwarding, and a copy of a folder is permanent — ten trusted readers means the eleventh reader is whoever any one of the ten forwards to. There are only two states that hold: private, and published. Everything in between drifts toward public, on someone else’s timeline, without any of the discipline publishing deserves. So when something is good enough to hand a trusted friend, our rule is: it’s good enough to publish, or it stays private. No side door.

What can’t move, and why

Almost everything this project builds is written to survive a hostile reader, on the theory that a strategy that only works while hidden isn’t a strategy worth having. What’s actually held back is narrow and principled: records that would identify specific people (attendance, private conversations, contact details beyond what a signature form needs), anything not yet finished or ruled on, and machinery whose only job is coordinating outreach to specific people or organizations before that outreach happens. That’s the whole list. Screening a claim to publish it costs about the same as screening it to hand a friend — so there’s no efficient middle tier, only the discipline of doing the screening once, in public.

The public repos

The pattern we actually use: separate, public, org-owned repositories, each with fresh history and a clear license, holding only what’s cleared to leave:

Nothing crosses into either repository automatically. Every export runs through a screen: local paths and identity-bearing text are hard-blocked; anything that looks like internal process language is flagged for a human read before it ships; and a second, independent pass checks the exported files themselves, not just the sources they came from. Copy-out only — never a fork or a filtered copy of anything private, since that would carry private history along with it.

How collaboration comes in

The honest answer to “can I get access to your private files?” is no — but that turns out to matter less than it sounds, because nobody actually needs estate-wide access to collaborate on a real project. What works better:

Why publish this page at all

Publishing our own sharing rules is the same move as everything else on this shelf: instead of “trust us with your access request,” the answer is “here is exactly what we publish, what we hold back, and why — check it yourself.” A commons that can explain its own boundaries in public is more trustworthy than one that grants access case by case behind closed doors, and it’s also just less work: the rule is the same for everyone, including us.