Detailed research note

CCF policy as a public ROOST model input

Part of the research through 9 September 2026. This dated note preserves its original findings; later developments are discussed in the synthesis and linked profiles.

9 September2026. Bounded tool-governance acquisition closed. A named CCF contribution is now inspectable: a TVEC policy prompt pack in ROOST's Model Community repository. It is a template and accompanying evaluation/context documents, not proof that Coop, Osprey or a named platform deployed the policy, or that Canada accepted it under contribution26007. No model, API, underlying harmful-content dataset, account or submission was used.

What was actually released

The [pinned CCF pack](http[local research file] contains four files: a text-classification policy, an annex comparing definitions, an annex supplying actor context and an evaluation report. The repository [README](http[local research file] lines19–26, expressly describes this area as partner-contributed policy prompts organized by submitter for use with policy-following models. Annex2 expressly speaks as the Christchurch Call Foundation. This is stronger attribution than a directory name alone.

Inspected repository revision: 22b3bd48562616f9379eb6fa63abe131346a6de6, whose public API commit record is dated20August2026. This is the version pin, not the pack's initial-publication date. A path-scoped [27May2026 relocation commit](http[local research file] names Juliet Shen as author, credits Mackenzie as coauthor and describes relocation of the CCF policy from gpt-oss-safeguard/projects/tvec-policy with no content changes. That is repository attribution and a commit-message claim, not proof of each person's employer, drafting approval or independent verification of the rename. A finite five-result query of that stated earlier path returns7May2026 organization commits credited to Mackenzie. It was not an exhaustive history or proof of first publication. The evaluation's17April2026 update date is a document date, not a repository-release date.

The current [roadmap](http[local research file] describes the Model Community as a way to convert traditional policies into model-ready prompts and distribute implementation knowledge. The [11December2025 roadmap announcement](http[local research file] What We're Building, specifically planned2026 access to sample TVEC policies. Neither inspected roadmap nor these four pack files establishes a budget allocation, accepted Canadian milestone or CCF programme exclusivity. Root's ccf-programme.md owns that separate evidence. No generalized Coop/Osprey-to-CCF funding edge is supported.

Where the policy places judgment

The template defines terrorism and violent extremism, assigns eight categories to a removal heading, and supplies a separate permissible-content heading. Its credible-threat category adds an instruction to escalate to law enforcement and normally requires at least two listed indicators. The EDSA/newsworthiness category expressly calls for human review. These are desired labels/actions in a prompt template; no inspected execution path sends a report or removes content. Locators: tools-tvec-policy.txt lines5–15,25–43,101–123.

The categories extend beyond official branded material into material support, recruitment, praise/promotion and incitement. Annex2 recommends combining actor, content and behavior signals, warns that designations can be politicized and incomplete, and treats UN/EU/FiveEyes lists as contextual signals rather than an exclusive truth source. CCF supplies its own limited incident/perpetrator list, selected where it engaged its crisis protocol and/or an attack referenced the Christchurch attacker. It expressly says the list is not comprehensive and not every listed person faced a terrorism/violent-extremism charge or investigation. This is CCF selecting context for classification; it does not make each entry a legally certified terrorist. No individual incident/person nodes are warranted. Locators: annex2 lines3–31 and table32–65.

Annex1 compares legal and scholarly approaches and notes absence of a universally agreed definition. Its external legal references remain the author's comparison; this run did not independently verify the current laws, lists or incident entries. The policy text's chosen definition is not itself a statute or proof of mandatory government instructions.

Adaptation rights and correction limits

The repository carries a [CC-BY4.0 licence](http[local research file] Sections2–3 permit reproduction and adaptation of licensed material subject to attribution, notices and identifying changes; section2 excludes implied endorsement and preserves distinct noncopyright rights. Section5 supplies an as-is disclaimer. Section6 provides termination for noncompliance and restoration rules; stopping distribution does not itself terminate an otherwise valid licence. These are the published repository terms, not an acquired signed CCF agreement or permission to use external training data, hash databases or separately licensed model weights.

The README invites issue reports, discussions and iterative feedback to model creators, and supports configurable policy-following models. That makes independent adaptation and public feedback possible. It does not establish a required patch/adoption schedule, an affected user's appeal, or mandatory propagation of a corrected prompt into recipients' deployed systems. The precise project-maintainer/TDC rights belong to Linnaeus's governance lane. No case-specific model deployment, policy variant, update acknowledgement, enforcement adapter or restored item was acquired here.

What the evaluation supports

The74-line report is labelled17April2026 and names gpt-oss-safeguard without an exact checkpoint or complete reproducibility package. It reports170 examples:114 true positives,12 false negatives, zero false positives and44 true negatives against evaluator/team judgments. It reports90.5% recall and100% precision for that sample. This does not establish perfect general accuracy or legal ground truth. Recruitment recall is12/17, approximately71%, below its own85% target. The failure discussion explicitly says team experts disagreed with the model's threshold interpretation in four examples and suggests policy refinement; that is a disclosed source of classificatory judgment, not demonstrated political misuse. Locators: tools-tvec-evaluation.md lines3–62.

The report also gives72.2% precision for EDSA classification and explains that confusion concerns two permissible categories, rather than those errors admitting violative content. Preserve this alongside the binary zero-false-positive result. The raw examples, annotation/adjudication protocol, evaluation script, exact model checkpoint and run settings were not identified in the four-file pack; no performance test was run.

Two observable textual tensions deserve reconciliation before interpreting a deployment. TVEC0 references INCITE1, which is undefined within the policy. The EDSA section says its exception does not apply if content falls into any TVEC1–8 category, while the evaluation describes otherwise-TVEC content permitted for an EDSA purpose. The template's examples also include journalism and research. Context precedence and intended exception handling therefore require a version-specific interpretation/test; neither a concrete over-removal incident nor the impossibility of an exception follows from this text alone.

Forest implication and finite frontier

The new bridge is CCF-authored policy/context entering a public collection intended for direct model use. This is a concrete path by which an institution's definitions and judgments can travel, alongside meaningful freedom to adapt them. It is distinct from government financial acceptance, mandatory adoption, a model's actual output and a platform's action. A source contribution can shape defaults without giving its author universal enforcement authority.

The next discriminating records are a named adopter's exact prompt/model/configuration and review/enforcement route; a resolved interpretation of the exception text; and the matched CCF/Canada output schedule and acceptance record. For the claimed evaluation, a benign or suitably redacted reproducibility package would distinguish the documented finite test from general performance. No new branch is opened here.

Custody and read scope

tools-captures.json records14 successful original/API responses with hashes, exact URLs, commit and read scopes, plus two reader/access-history observations. All four CCF files were read completely: policy123lines, annex1 62lines, annex2 65lines, evaluation74lines. The92-line README was read completely. Licence scope is its title, selected definitions and sections2–6 with supplementary terms through line372; not every introductory/footer line. Roadmap and announcement substantive bodies were read; media and links were not automatically treated as read. Repository listings were discovery metadata only. All originals are public unauthenticated response bytes; derived text is separately labelled.

The roadmap reader failed with a cache miss; its sole normal GET substitute succeeded. The exact GitHub policy-directory reader returned429; after a pause, one ordinary public API route supplied the listing and pinned source URLs. No access restriction was bypassed. Previously closed CCF403 routes were not retried. Six targeted queries were used for CCF/Elevate/TVEC/roadmap discovery; irrelevant municipal and similarly named software results were discarded. No code installation, model inference, form, private dataset or outreach occurred. The candidate case, atlas and ZIP remain untouched.