Rootwall

Version history

Every published version of the rulebook, the schedule of fees, the survey, the disputes page and the privacy notice, with the date it took effect and what changed in it.

Last updated 3 September 2026

Why this page exists

A clause that cannot be cited to a fixed version is not a rule. It is an opinion that may have moved since you read it.

The intended end state for these rules is that they get named in contracts between members. That is only possible if a party can point at a numbered clause, in a numbered version, on a fixed date, and be sure the text it read then is the text that will be there later.

So three commitments are made here and are meant to be relied on.

The rulebook

Version 1.3 15 September 2026 Current

One clause added and one widened, made before the scheme had any members and therefore requiring no notice under clause 34.2. New clause 15.6: a member is answerable for every interaction conducted with a credential issued to it, or a key it has registered, as if it had conducted it itself — whoever in fact did. A stolen or leaked credential is not an explanation admitted against a determination; prompt disclosure is a mitigating factor and nothing more.

Why: a member protects its credentials because a misuse of them costs it, whoever carried it out. A rule that excused a member whose credentials were taken would remove that reason. Clause 25.1(a) is widened to reach a compromise of any credential a counterparty issued to the member, not only the signing key, and clause 27.5 gains the matching breach. No obligation removed, no period or sum changed, no number reused.

Version 1.2 2 September 2026 Superseded

No clause changed. One entry added to Known limitations. The scheme is operated by one person, clause 22.1 obliges it to hold assertions for six years and Part 8 to release them throughout, and no escrow, custodian or successor arrangement presently stands behind either obligation.

Storage is not the constraint — six years of a busy relationship costs the scheme about $14 a year. Continuity is. The position taken is to state it plainly now and to put a named custodian in place before the first member is admitted, rather than publish a promise the scheme cannot presently keep. A member is entitled to ask what the arrangement is before it signs, and to be told.

In force from 2 to 15 September 2026, and still readable at its own address. Superseded by 1.3.

Version 1.1 2 September 2026 Superseded

One amendment, to clause 8.2, made before the scheme had any members and therefore requiring no notice under clause 34.2. Under 1.0 a member in the receiving role stopped accepting a revoked counterparty only from the time the scheme notified it, which made a member's protection depend on the scheme being reachable on a particular day.

1.1 moves the guarantee to the published register. The register is updated with effect from the change itself and is authoritative; a member must stop accepting from the earlier of notification and the register entry; and a member that relied on the register as it stood at the time of a session does not breach. The one-business-day notification duty survives as a discipline on the scheme rather than as the mechanism members depend on. New clause 8.2A explains why, and Schedule 4 is updated to match. No other clause and no other schedule changed. Superseded the same day by 1.2, which changed no clause and remains readable at its own address.

Version 1.0 27 August 2026 Superseded

In force from 27 August to 2 September 2026, and still readable at its own address. The rules as they stood for citation. Complete text of parts 1 to 9, clauses 1 to 37, and schedules 1 to 5, with the known limitations stated in the document rather than left for the reader to discover.

Two schedules are completed per member rather than in advance, and that is the design rather than an omission. Schedule 3, the scope classes, describes operations against a specific interface — permitted method kinds, ceilings, what must be asserted — so a generic one would describe nothing. Schedule 2, the liquidated sums, is set with the class it belongs to, because a sum that is not proportionate to what its class permits is not a deterrent, it is a number. Both are written with the member on admission. The structure each must take is fully specified in the text, and what a member signs names the completed schedules for its own interface.

Clauses 6 and 27.7 are marked [Reserved]. Their numbers are retired and will not be reused.

Version 0.7 24 August 2026 Superseded

The first text published at a public address. Superseded by 1.0 on 27 August 2026, which changed no clause and no schedule structure: the differences are the version designation, the removal of the draft status line, and the description of how schedules 2 and 3 are completed.

Versions 0.1 to 0.6 were drafted before the rules were published and were never available at a public address. They are not listed here, because listing versions nobody could have read or cited would be a version history in appearance only. The public record starts at 0.7.

From here on, published documents carry whole version numbers. A published standard is either fit to be named in a contract or it is not, and a decimal in front of it is not a substitute for saying which.

Schedule of fees

Version 1.2 3 September 2026 Current

The one-off fees return to where 1.0 set them. Admission is $350 on both sides and assessment $1,200 per scope class in the Emitting Role. Membership stays at $6,000 a year in the Receiving Role and $1,000 in the Emitting Role, reassessment stays at $600, and the conduct and retention extension heads stay at nil. The recurring fees have never moved.

Why, and it is a judgement about who pays rather than about the price being wrong. Version 1.1 raised both one-off fees against a comparable published schedule, and that comparison stands — a body of this kind charges a company of this size several times more to join and to be certified. This scheme is knowingly priced below it.

What the increase did was fall almost entirely on one side. An agent operator is usually admitted because an organisation it wants to reach made admission a condition of access, rather than because it went looking. Under 1.1 its first-year total rose by more than half; the API owner's rose by a tenth. A scheme that grows by one member requiring admission of another should not make that requirement expensive to impose.

The schedule is also explicit that amounts are exclusive of VAT. No member existed on the date of either change, so no member's price moved.

Version 1.1 3 September 2026 Superseded

In force for part of one day, and still readable at its own address. Raised admission from $350 to $1,000 on both sides and assessment from $1,200 to $2,000 per scope class, against a comparable published schedule. Superseded by 1.2 the same day.

It is listed rather than removed for the same reason every other superseded version is. A version that lasted hours is still a version that was published, and a schedule that quietly loses the ones it would rather forget is not a version history.

Version 1.0 27 August 2026 Superseded

First publication, in force from 27 August to 3 September 2026, and still readable at its own address. Its figures are the figures in force again from version 1.2. Membership priced by role at $6,000 a year in the Receiving Role and $1,000 in the Emitting Role, admission at $350 on both sides covering entry and exit, assessment at $1,200 per scope class in the Emitting Role with renewal at $600, and the conduct and retention extension heads declared at nil.

No change to this schedule applies inside a period already paid for, and a member that will not accept a change may withdraw rather than be bound by it.

The survey

Version 1.0 2 September 2026 Current

What a hundred UK and EU software platforms require of the third parties calling their APIs. First publication. Roughly one hundred companies across six sectors, read from primary source on 28 August 2026: what each one requires of a third party calling its API, how many publish rules, and how far the strongest of those rules go.

The survey is a dated snapshot and says so in its own text. One of the documents in it was replaced by its author while it was being written, and the clauses that had been recorded were not in the replacement. Every document quoted is linked both to its live address and to an archived copy taken on 28 August 2026, so a reader can see what was read even after the author changes it.

Numbered points are stable and separately citable, for example rootwall.ai/hundred-platforms#p63. Corrections are welcome and will be published with the correction noted and dated, and the original left visible rather than quietly amended.

Privacy notice

Version 1.0 3 September 2026 Current

First publication. What this website does with personal data: no cookies, no account, no form, and page statistics that cannot identify an individual visitor. The only personal data deliberately collected is correspondence sent to the contact address.

The three processors are named rather than described generically — Cloudflare for page statistics, GitHub for hosting, Microsoft for email — and the controller, company number and registered office are stated.

The notice covers the website only. The scheme is not operating and has no members. What it will hold once it does is fixed by the rulebook rather than by that page, and the notice will be extended before the first member is admitted.

Example scope class

Illustrative 3 September 2026 Current

First publication. A worked example of a scope class — permitted method kinds, ceilings and windows, the delegation requirement, what must be asserted, and the sum attached to each breach.

It is illustrative and carries no version number for that reason. It binds nobody, no member is admitted into it, and it will not be superseded — it will be replaced when a real published class makes it redundant.

When the records do not match

Version 1.0 3 September 2026 Current

First publication. What happens when two members’ accounts of the same session disagree — the process and its clocks, what the scheme determines, and what it is forbidden from determining.

It exists because the answer was spread across four parts of the rulebook and nowhere as a single chain. Every clause cited on it is referenced, and the page carries a scope table stating in and out on one screen.

How a change gets made

The rulebook's own amendment provisions govern, and this page does not add to them or soften them. In outline, and without replacing the text of the rules themselves:

How these documents are written

Rootwall's documents are drafted by its founder with AI assistance and published under his review. Every citation is verified against primary sources and dated.

It is stated here because a scheme that accredits other organisations should be willing to say how its own documents are produced, and because being found not to have said it would cost more than saying it.