Governance¶
The canonical governance doc is GOVERNANCE.md; maintainers are in MAINTAINERS.md.
- Roles: Contributor → Reviewer → Maintainer → Project Lead (currently Imran Siddique). Contributions are DCO-signed.
- Decisions: routine changes merge on one Maintainer approval; breaking spec or guarantee-scope changes need an issue, a comment period, and Project Lead sign-off. No change may strengthen a security claim beyond what the hardware and protocol deliver.
- Publication: public release is a deliberate decision by the Project Lead. It is not gated on the key-extraction half of open question 8.8, which is documented as an honest residual rather than a release blocker.
- Family: WCM is part of the agentrust-io family (TRACE, cMCP, Agent Manifest, cA2A) - open spec, independent implementations, shared conventions.
- Sponsors: support is recognized separately from governance. Sponsorship does not confer ownership, decision rights, conformance preference, or an endorsement of a sponsor's implementation.
See also the Code of Conduct, Antitrust Policy, and Sponsors.