# Governance

## Maintainer authority

Dominique Devereaux is the founding maintainer. Repository access is granted by explicit invitation and may be limited by role.

## Change process

- `main` is the published record.
- Changes should enter through a pull request.
- At least one approving review is required.
- Conversations must be resolved before merge.
- Force pushes and branch deletion should be blocked.
- Status checks become required when automated validation is added.
- Administrator bypass should be used only for urgent safety or security repair and documented afterward.

`CODEOWNERS` identifies review responsibility but does not itself enforce protection. GitHub branch protection or a repository ruleset must be enabled in repository settings.

## Evidence changes

Changes that identify a person, add health information, alter an evidence label, or claim provider endorsement require a provenance and consent review in the pull request.

## Provider positions

Responses from platform providers are recorded with the date, speaker, claimed capacity, exact public source, and whether the statement is official, personal, or unclear. The project may quote short portions necessary for commentary and link to the complete source.

## Conflicts of interest

Reviewers disclose employment, funding, sponsorship, litigation, caregiving, clinical, or close personal relationships that could materially affect a decision. Disclosure does not automatically disqualify participation; it informs review assignment.

