///An Indigenous Data Sovereignty Standard · Affiliated Tribes of Northwest Indians
Sovereignty forward, not an afterthought.
The Tiered Sovereign Data Framework gives Indigenous Nations a clear, enforceable mechanism for governing data in digital spaces; translating CARE, OCAP®, and UNDRIP from principle into practice through four tiers of escalating care.
The tiers are centered, not elevated; inward means heightened responsibility of care. Select a ring.
///The Four Tiers
Four tiers, one direction of care
Every piece of Indigenous data, from public press releases to ceremonial knowledge, is classified into one of four tiers. Each tier answers the same four questions: what is stored, how it moves, how it is accessed, and how it may be transformed.
When in doubt, classify as T3.
The harm is asymmetric: over-classification delays access until review, and that is correctable. Under-classification can publish sacred knowledge or disclose a burial site, and that is often irreversible. Only authorized human decision-makers may downgrade a classification. Systems may automate protective upgrades, never downgrades.
///Convergence Systems Architecture
Sovereignty across four domains, or extraction through the gap
Classifying data is not enough. Data governed at rest can still be extracted in motion, in storage, or in processing. TSDF traces the full lifecycle and requires governance authority at every stage, because gaps in any layer create openings for extraction.
Data Sovereignty
“What data is stored, and under whose authority?”
The governance layer: the inherent right to govern collection, ownership, classification, and application of data about Peoples, lands, and relations. This is where CARE, OCAP®, and the four tiers live.
Network Sovereignty
“Whose infrastructure carries our information, under whose terms?”
The transmission layer: fiber, spectrum, towers, mesh. Data legally held by a Tribe that travels through infrastructure that doesn’t recognize Tribal jurisdiction is sovereignty made precarious.
Digital Sovereignty
“Whose services hold our data, and whose jurisdiction governs access?”
The service layer: cloud platforms, storage, spectrum, interfaces. Data residency is where a server sits; data sovereignty is whose law governs it. The two are not the same.
Computational Sovereignty
“Who determines how our data is transformed, and toward what ends?”
The transformation layer: analysis, statistical inference, AI/ML. When Indigenous data enters a model it is transformed in ways that can escape governance entirely unless authority is asserted here too.
The four domains above are not a taxonomy; they are one argument, made across four layers, in a synthesis that reads the field's central scholars and finds the boundaries between data, network, digital, and computational sovereignty collapsing. The Standard is what that argument looks like as enforceable rules.
///Sharing as Relation, Not Extraction
Windows, not copies
When a Nation shares data under TSDF, it does not transfer assets. It opens a window that remains in its own house: partners see rendered views, run approved analyses that execute at the source, and receive results, while the underlying data never leaves its origin, and every derivative carries its provenance home.
| Extraction model | Relational model |
|---|---|
| Sharing = copying files | Sharing = opening windows |
| Access = possession | Access = participation |
| Value = accumulation | Value = relationship depth |
| Quality = single authoritative source | Quality = density of triangulation |
| Knowledge = data transferred | Knowledge = understanding co-created |
///Standing on Established Ground
Built to operationalize, not replace
TSDF does not invent new principles; it makes existing ones enforceable in software and infrastructure. It is not meant to replace any sovereign framework or cultural ways-of-knowing.
///Go Deeper
Three more rooms in this house
The tiers are the doorway. Behind them: the documented record the framework is built from, the standards work that makes “compliance” mean something, and the artifact that carries it all into practice.
Literature
Two systematic reviews and the Convergence Systems Architecture; the record of what has been documented, and the synthesis that turned it into architecture.
Read the foundations → Standards AlignmentIEEE Compliance
IEEE 2890-2025 provenance explicated functionally, the responsible-design 7000-series, and AI/LLM boundaries tier by tier.
See what conformance asks → From Standard to ArtifactATNI-GeoPackager
A data wrapper in development that carries classification, provenance, and an unerasable audit record inside the file itself.
Meet the wrapper →///TSDF Standard · v0.9.5 (pre-release)
The Standard, navigable
Every part of the Standard below, with a plain-language descriptor of what it does and the rules it carries. Dotted terms open a definition; the full glossary is at the bottom. For the authoritative text, read the standard document on GitHub. An official 1.0 will not be released without full authorization by resolution of ATNI.
01Theoretical Foundations
▶
What this part does
Names the problem and the response. Centuries of extractive research treated Indigenous knowledge as a resource to be mined rather than a relationship to be honored. The Standard responds by defining Indigenous Data Sovereignty, the inherent right of Indigenous Peoples to govern the collection, ownership, and application of their own data, and rejecting the colonial data paradigm.
Key ideas
- The colonial data paradigm. Dr. Maggie Walter’s “5D Data” critique: colonial statistics emphasize Disparity, Deprivation, Disadvantage, Dysfunction, and Difference, framing Peoples through deficit rather than strength.
- Data ABOUT vs. data FOR. Data about Indigenous Peoples is rooted in extraction; data for Indigenous Peoples is a tool of self-determination.
- The four-tier model as the mechanism that moves these principles from aspiration to enforceable policy.
02Foundational Principles & Distinctions
▶
What this part does
Establishes the political and conceptual ground rules before any classification happens.
Key rules
- Tribes are sovereigns, not stakeholders. All data exchange happens through government-to-government relations.
- Residency ≠ sovereignty. Where a server sits is not whose law governs the data. Authority remains with the Nation regardless of storage location.
- Scope is holistic. Collective & cultural data, individual & administrative data, and biophysical & relational data; the land itself is “the original knowledge organization system.” Data from Indigenous territories carries the same sovereignty claims as the territories themselves.
- The Convergence Systems Architecture. Four interdependent sovereignty domains (Data, Network, Digital, Computational) and the window architecture: view-only federated access where sharing opens windows rather than copying files, and computation travels to the data.
- Federated commons. A shared T0 base layer every network member holds locally (no single point of failure) with sovereign overlays that never leave each Nation’s infrastructure.
03The Four-Tier Data Classification System
▶
What this part does
The core of the Standard: precise definitions for T0–T3, the default rule, and minimum requirements in each sovereignty domain per tier.
| Tier | Definition | Critical principle |
|---|---|---|
| T0 OPEN | Formally and publicly released by the sovereign Indigenous entity for collective benefit | Release is an affirmative act of governance, never a default |
| T1 NETWORK | Shared among trusted Indigenous network members under reciprocal protocols | Reciprocity: relationships are mutual and ongoing, not transactional |
| T2 NEGOTIATED | Shared with specific external partners through explicit, documented agreements | FPIC as an ongoing, revocable relationship, not a one-time transaction |
| T3 SOVEREIGN | Complete Indigenous control; never leaves community-controlled systems | Architectural guarantees: external access technically impossible, not just prohibited |
Rules that travel with every tier
- Default to T3 when classification is uncertain or unassigned (the asymmetric-harm principle).
- Inward movement (toward T3) may be automated, triggered by agreement expiry, protocol violation, or provenance break. Outward movement requires an authorized human decision, documented with rationale. Automated downgrade is prohibited.
- T3 honors strategic invisibility; the choice to remain unseen is itself an exercise of sovereignty. T3 also carries internal protocols: the tier restricts external access; internal governance (clan, gender, ceremonial role) determines internal access.
- Each tier specifies requirements across all four domains (transmission pathways, storage platforms, access mechanisms, and AI/ML authorization) plus per-tier provenance requirements designed to support IEEE 2890-2025.
04Framework Alignment & Interoperability
▶
What this part does
Maps every tier to the established frameworks it operationalizes, so adopting TSDF is evidence of honoring them, not a parallel obligation.
- CARE alignment: tier-by-principle mapping with implementation requirements (benefit-sharing mandatory in T2 agreements; only Indigenous authorities downgrade; audit logging; consent records linked to all non-T0 data).
- OCAP® alignment: the window architecture operationalizes Possession: data stays in the source Nation’s custody while authorized parties see rendered views. Where OCAP® exceeds TSDF, OCAP® prevails for First Nations data.
- UNDRIP: Article 19 (FPIC) → T2 mechanism; Article 23 → T0 release decisions; Article 31 (cultural heritage) → T3 architectural guarantees.
- IEEE 2890-2025: adopted as the Standard’s provenance reference, with a Data Actor rule built on its treatment of data actors: every non-human actor (algorithm, database, AI system) must have a responsible human identified.
- FAIR reconciliation: “As open as possible, as closed as necessary.” FAIR applies only where CARE is satisfied first, and the window architecture lets data be findable, accessible, interoperable, and reusable without transferring possession.
- Local Contexts TK/BC Labels: labels provide cultural specificity; tiers provide governance enforcement. Both travel with the data.
05Governance & Partnership Model
▶
What this part does
Specifies what must be governed, never how a Nation must structure its governance, respecting the diversity of traditional and contemporary governance systems.
- Core functions: classification authority, consent mechanisms across all four domains, exclusive reclassification authority, infrastructure governance, and audit.
- The partnership spectrum (after David-Chavez 2024): Consultation → Collaboration → Knowledge Co-production → Indigenous-Determined. T2 agreements should name the level and build in progression toward Indigenous determination.
- Tribal research codes are enforceable law. Tribal IRBs and research codes form the primary legal basis of every T2 agreement and take precedence over external institutional requirements.
- Federated network governance for T1: membership criteria, reciprocal obligations, dispute resolution, protocol amendment, and commons management.
06AI/ML Governance
▶
What this part does
Draws hard boundaries for machine learning on Indigenous data: the domain where transformation most easily escapes governance.
| Tier | Training | Inference |
|---|---|---|
| T0 | Per release terms | Per release terms |
| T1 | Network approval required | Network scope only |
| T2 | Per agreement only | Per agreement only |
| T3 | Prohibited externally | Prohibited externally |
- Models inherit tiers. A model trained on T1 data carries T1 restrictions on its deployment and outputs. No T3 data may enter any AI/ML system, including “anonymized” derivatives.
- Attempted operations are logged even when denied (recorded as
tsdf:deniedin the Standard’s custody vocabulary) for audit. - The 5D problem in AI: T2 agreements involving AI/ML should require Indigenous-determined bias criteria, deficit-framing review, output oversight, and the right to require model modification or termination.
- The limits of computation: “Knowledge is embodied. Computation without relation is not knowledge.” AI can process; it cannot be accountable to kin.
07External Partner Accountability
▶
What this part does
Differentiated requirements for T2 partners, proportionate to extraction risk: Tribes set the terms; partners must qualify.
| Partner | Primary accountability | Highlights |
|---|---|---|
| Corporate (>$50M revenue, or data/AI business) | Contract + IEEE attestation | IEEE 7000/7001/7003/2890 certifications, designated compliance officer, consent to audit, binding arbitration recognizing Tribal jurisdiction, liquidated damages |
| Academic | Institutional policy + IRB | Institution-level (Provost/VPR) acknowledgment that IDSov supersedes university IP policy; publication review rights; Bayh-Dole handling; Tribal IRB primacy |
| Federal / governmental | Trust responsibility | EO 13175 consultation documentation, FOIA exemption strategy required in agreements, data return protocol; failures may breach trust responsibility |
| Small org / NGO (<$5M) | Relational, resolution-based | Tribal resolution grants trust; revocable by subsequent resolution without formal legal process; relationships, not contracts, are the primary governance mechanism |
The jurisdictional argument that resolves the academic IP conflict: Indigenous data originates under Tribal jurisdiction; university IP policies cannot retroactively claim what was never theirs.
08Adoption & Implementation
▶
What this part does
Step-by-step adoption paths for five audiences: Indigenous Nations (assess holdings, designate governance, default unclassified data to T3, update research codes), research partners (recognize the Standard, adapt IRB protocols, implement provenance), technology providers (tier-based access control, window architecture, Indigenous-controlled encryption keys), federal partners (consultation protocols, FOIA handling), and interTribal network operators (federated governance, T0 commons, graceful degradation when connectivity fails).
See the Use & Adapt tab for these paths in full.
09Compliance Checklists
▶
What this part does
Auditable checklists for each alignment: IEEE 2890-2025 (data-actor schema, custody chains, benefit-sharing documentation, denied-operation logging), CARE, OCAP®, Local Contexts, and one checklist per sovereignty domain, so “compliance” means something a reviewer can verify, not a vibe.
///Glossary
Terms, in plain language
Drawn from the Standard and its supporting documents.
///In Practice
What TSDF looks like in real work
Three generic walkthroughs drawn from the kinds of projects Tribal climate programs actually run. In each one, notice the same pattern: the work proceeds, partners get what they need, and the sensitive layer never leaves the Nation.
Infrastructure siting
An agency is evaluating corridors for new transmission lines and asks Tribes to “identify cultural resources and sensitive sites within the study area”; the classic extractive ask. Disclosed locations enter agency records, where public-records law and FOIA can reach them.
The TSDF pattern
Site locations, burial grounds, and gathering areas are classified T3 and never transmitted. Instead, the Nation runs the corridor screening inside its own systems (compute-at-source) and returns a constraint surface (“avoid these polygons, weighted by concern”) as a T2 rendered view under a formal agreement with FOIA-exemption strategy specified. The agency gets exactly what siting requires: where not to build, without ever holding coordinates of why.
Data inventory
| Public corridor alternatives | T0 |
| Regional habitat & hazard layers shared interTribally | T1 |
| Constraint surface delivered to agency | T2 |
| Sacred site & gathering locations | T3 |
Policy scanner
A climate program builds a tool that scans federal and state policy documents and generates per-Tribe advocacy briefs. The inputs look harmless (policy text is public) but the configuration is not: each Tribe’s priorities, vulnerabilities, and positions are strategy.
The TSDF pattern
Source policy corpus is T0 (external public data). Each Tribe’s priority profile is T3 or T2, held by the Tribe or under agreement, never pooled. Generated briefs inherit the tier of their most restricted input (provenance inheritance): the brief belongs to the Tribe it was generated for, who alone decides whether to release it. And because tier restrictions govern AI/ML, no Tribe’s profile can be used to train models or generate another Tribe’s outputs.
Data inventory
| Federal/state policy documents | T0 |
| Shared scanning methodology & templates | T1 |
| Tribe-specific priority profiles | T3 |
| Generated advocacy briefs | inherit; released only by that Tribe’s decision |
Rapid-response information sharing
During flood or wildfire response, Tribes need to share conditions fast, but emergency data is exactly where sensitive information leaks: evacuation routes that reveal site locations, vulnerability maps that identify households.
The TSDF pattern
A federated T0 commons carries public alerts and baseline conditions; each Nation holds a local copy that syncs when connected and persists when the network fails. Real-time gauge readings and condition reports flow as T1 among verified network members under standing protocols; no per-incident negotiation when minutes matter. Coordination with FEMA or the state happens through T2 views. Household-level vulnerability data stays T3: responders inside the Nation’s systems see it; the network sees only aggregated need.
Data inventory
| Public emergency alerts, weather baselines | T0 |
| Live gauges, road status, condition reports | T1 |
| State/FEMA coordination views | T2 |
| Household vulnerability, routes near sites | T3 |
///Interactive · From the Tier Decision Guide
Which tier is my data?
QUESTION 1 OF 5
This tool walks the Standard’s published decision tree. It is guidance, not governance; classification authority rests exclusively with each Nation’s designated governance body. When in doubt: T3.
///Red Flags
Always T3 unless governance explicitly says otherwise
- Sacred site locations or descriptions
- Ceremonial information of any kind
- Individual health records
- Enrollment / citizenship records
- Financial records
- Traditional knowledge with any access restrictions
- Burial sites or funerary objects
- Clan-specific or gender-restricted knowledge
- Internal governance deliberations
- Specific resource harvest locations
- Data where consent is unclear or undocumented
///Evidence
Why a tiered standard, and why now
TSDF is not a preference; it is a response to a documented record. The evidence comes in three parts: the extractive history of asking Nations to disclose what is sensitive, the maturity of Indigenous Data Sovereignty as an operational discipline, and a policy landscape that requires consultation but under-protects what consultation reveals.
The extraction record
Peer-reviewed analysis of Indigenous community engagement in climate research.
///Claim 1 · Documented in peer review
Asking Nations to identify what is sensitive has been extractive
Vulnerability assessments, hazard mitigation plans, siting studies, and research projects routinely ask Tribes to disclose culturally sensitive sites, economically vulnerable assets, and TEK; the record of what happens next is documented.
///Claim 2 · Documented in peer review
IDSov is now a working discipline with clear metrics and processes
This is no longer aspirational language. Indigenous Data Sovereignty, network sovereignty, and computational sovereignty have published principles, assessment processes, institutional adoption, and, as of IEEE 2890-2025, an international standard.
///The Policy Landscape
Consultation is required. Protection is partial.
Federal and state law mandates consultation with Tribal Nations, and those same processes are where sensitive information is asked for. The protections that exist are exemption-by-exemption, not structural. TSDF is designed for exactly this gap.
Federal
State example: Washington
///Convergence Systems Architecture
A process exploring convergence
TSDF is one output of a broader theoretical synthesis. In mathematical terms, convergence describes lines that grow closer while never intersecting: different Peoples orient around a shared problem while each retains their identity, methods, and ways of knowing. Applied to sovereignty, the argument is that data, network, digital, and computational sovereignty are indivisible: “sovereignty must extend across all layers or gaps emerge where extraction enters.” Twelve principles guide the architecture:
Read the full synthesis: Convergence Systems Architecture (Freeland, ATNI).
///The Written Foundations
The literature beneath the framework
TSDF did not begin as a technical specification; it began as a reading of the record. Two systematic reviews establish what the peer-reviewed literature documents, and a theoretical synthesis draws those findings into the architecture the Standard enforces. All three are published in this repository, openly licensed, with their methods stated in full.
Convergence Systems Architecture: The Relationality of Indigenous, Network, and Digital Sovereignty
Academic and policy language treats Data Sovereignty, Network Sovereignty, and Digital Sovereignty as separate domains; separate conferences, separate funding streams, separate specialists. The synthesis reads the field’s central scholars (Dr. Dominique David-Chavez, Dr. Lydia Jennings, Dr. Stephanie Russo Carroll, Dr. Tahu Kukutai, Dr. Maggie Walter, Dr. Marisa Elena Duarte) and finds those distinctions collapsing: data flows through networks, networks depend on infrastructure, and infrastructure enables or constrains digital futures. Govern one layer and not the others, and the gap is where extraction enters.
The synthesis lands in twelve principles, from “Sovereignty is Indivisible” to “No Neutral Ground,” that the Standard carries into enforceable requirements: the four sovereignty domains every tier must satisfy, the rule that every non-human actor answers to a responsible human, and the AI/ML boundaries that keep transformation governed. It closes with a sixteen-entry annotated bibliography of the field’s foundational texts, from Indigenous Data Sovereignty: Toward an Agenda (2016) to Indigenous AI position papers.
Indigenous Data Sovereignty in Climate Research
The question: what does the peer-reviewed literature establish about IDSov frameworks for climate and environmental data sharing across jurisdictions and institutions?
What the record shows: the CARE Principles are the most-referenced framework across fire, forestry, water, and climate contexts, and the field is generating its own instruments: the Indigenous Fire Data Sovereignty framework, the WAMPUM adaptation framework for sea level rise, the Piikani Well-being Index, the Four Rs, and Tribally specific protocols such as the Karuk Tribe’s Practicing Pikyav. Five themes recur: the collision between open science and sovereignty, colonial legacies in land-management institutions, Indigenous Knowledge as the foundation of adaptation, research fatigue in heavily studied communities, and the consistent call for Indigenous leadership over data governance.
Honest limits: citation-impact data proved scarce across this literature; the review measures influence through policy adoption, framework uptake, and funding instead, and says so plainly.
Indigenous Data Governance Frameworks
The question: what governance frameworks exist for Indigenous-controlled environmental data repositories in partnership with federal, state, or academic institutions?
What the record shows: working governance combines three components. Formal sovereignty standards (CARE, OCAP®, UNDRIP) supply the principles; legal and statutory mandates (Treatment as State, land-claim agreements, environmental statutes) supply the leverage; and community-based review structures (Tribal Research Review Boards, advisory councils) keep decisions about collection, storage, and use accountable to the community. Academic partners appear in 27 of the 40 studies and federal institutions in 18; power-sharing varies widely, and the arrangements that work are the ones where Indigenous authority is formal, resourced, and recognized.
///From the Record to the Rule
Every mechanism answers a documented finding
The Standard’s rules are not preferences. Each one traces to something the literature documents; a few of the load-bearing connections:
| What the literature documents | What the Standard does about it |
|---|---|
| 87% of climate studies engaged Indigenous communities extractively (David-Chavez & Gavin, 2018) | The partnership spectrum: T2 agreements name their level and build progression toward Indigenous-determined research |
| The “confidentiality catch-22”: consultation compels disclosure that public-records law can then reach | T2 agreements must specify a FOIA-exemption strategy; T3 site data never transmits at all, constraint surfaces travel instead |
| University open-research policies conflict with Tribal data ownership, delaying and derailing partnerships (Wick et al., 2024) | Institution-level acknowledgment that IDSov supersedes university IP policy, before any data moves |
| Research fatigue: communities pressed by constant, misaligned research demands (Brewer et al., 2023) | T1 standing reciprocal protocols replace per-project renegotiation among trusted network members |
| Tribal Research Review Boards and research codes operating as working governance (Kuhn et al., 2024) | Tribal research codes recognized as enforceable law; the primary legal basis of every T2 agreement (§5.3) |
| AI as a new extraction frontier: Indigenous Knowledge scraped into training corpora without consent | Tier-based AI/ML boundaries; models inherit the tier of their training data; denied operations still logged (§6) |
///Standards Alignment
IEEE compliance, made explicit
TSDF adopts IEEE 2890-2025 as its provenance reference and uses the IEEE 7000-series as partner-qualification infrastructure. This page explains what those standards are, what a system holding Indigenous data must be able to do, and where the boundary sits: IEEE compliance is evidence of technical capacity; it is never a substitute for Indigenous governance approval.
IEEE 2890-2025 · Recommended Practice for Provenance of Indigenous Peoples’ Data
The first standard developed for Indigenous Peoples’ data. Approved and published by the IEEE Standards Association in November 2025, developed as project P2890 with Indigenous leadership at every stage: an Indigenous Caucus, consultation with Indigenous Peoples supported by the Global Indigenous Data Alliance, and open access as a condition of the work. The text is available free of charge, with registration, from IEEE.
What it answers: the proliferation of unreliable data about Indigenous Peoples; the exclusion of Indigenous Peoples from participation, control, and governance over the circulation of their own data; and the misappropriation and misuse of Indigenous data and information. What it provides: a common set of parameters for describing and recording the provenance of data about or related to Indigenous Peoples and their cultures, lands, and Knowledge systems, recorded so that Indigenous governance, decision-making, participation, collaboration, and engagement are facilitated rather than foreclosed.
///Functional Walkthrough
Seven questions provenance must answer
Provenance in this setting is more than technical lineage; a lineage graph that records software steps but loses the originating Nation, the governing authority, and the conditions of use is not Indigenous-data provenance. Read functionally, a system holding Indigenous data should be able to answer seven questions at any moment, for any object it holds. Each maps to a mechanism the Standard specifies.
Origin: whose data is this?
Which Nation, community, lands, and relations does this data come from, and who supplied that attribution? Multi-Nation, disputed, and deliberately withheld origins must all be representable; a repository or researcher can never be silently substituted as the source.
Actors: who has touched it?
Every actor that collects, holds, transforms, or discloses the data is identified, and the actors are not only human: devices, applications, algorithms, AI systems, databases, and repositories act on data too.
Custody: where has it been?
An ordered, timestamped chain of custody: who held it, who received it, under what basis, with hand-offs matched to receipts, so a reviewer can reconstruct the object’s history from collection to current state.
Authority & consent: under whose decision does it move?
Every authorized use links to the Indigenous authority and consent records that permit it: issuer, scope, purpose, conditions, expiry, and current status. Community authorization and individual consent are distinct records; neither substitutes for the other, and consent can be withdrawn.
Transformation: what has been derived?
Subsets, aggregates, maps, embeddings, and models are all derivatives, and obligations must survive the transformation; provenance that stops at the first derivative is an invitation to launder data through processing.
AI operations: has it entered a model?
Whether governed data was embedded, trained on, or used in inference must be answerable, and refusals leave records too: an attempted operation that was denied is still an event in the data’s history.
tsdf:embedded, tsdf:trained_on, tsdf:inference_used, tsdf:denied), with denied attempts logged even where the operation is prohibited (§4.5.4).Benefit: what was promised, and what was delivered?
Benefit-sharing commitments are provenance, not marketing: the types of benefit, the recipient communities, what has been delivered with verification, and what remains pending with expected dates.
The TSDF provenance profile, tier by tier
The Standard turns those obligations into per-tier requirements. This table is TSDF’s own implementation profile, designed to support IEEE 2890-2025:
| Tier | Provenance visibility | Chain of custody | AI/ML logging | Benefit sharing |
|---|---|---|---|---|
| T0 | Public | Recommended | Optional | Not applicable |
| T1 | Network members | Required | Required | Network-determined |
| T2 | Agreement parties | Required, no gaps | Required | Required in agreement |
| T3 | Sovereign authority only | Mandatory, no gaps; all locations Indigenous-controlled | Required even when the operation is denied | Not applicable |
///Responsible Design
The 7000-series as partner qualification
TSDF does not ask partners to be virtuous; it asks them to show their work. For corporate partners, who carry the highest extraction risk, documented responsible-design practice is a prerequisite of T2 access, written into agreements as material terms whose breach carries consequences (§7.3).
| Standard | Subject | What TSDF asks partners to evidence | Applies to |
|---|---|---|---|
| IEEE 7000-2021 | Model process for addressing ethical concerns during system design | Documented value-based engineering that identified Indigenous data sovereignty as a core value, with engagement with the Indigenous governing authority: value registers, risk registers, requirements traceable to values | Corporate: required |
| IEEE 7001-2021 | Transparency of autonomous systems | Transparency documentation for any autonomous or semi-autonomous system, with explainability documentation available on request; transparency scoped so it never discloses T3 data or culturally restricted rationale | Corporate: required |
| IEEE 7002 | Data privacy process | Privacy engineering across the data lifecycle wherever Tribal data can identify persons, households, or places; individual de-identification alone does not resolve collective, territorial, or cultural harms | Any partner handling personal data |
| IEEE 7003-2024 | Algorithmic bias considerations | Bias assessment for AI/ML systems processing Indigenous data, audited specifically for deficit-framing (“5D”) patterns against criteria the Indigenous partner determines | Corporate: required · Academic: supplementary |
| Generative-AI standards work | IEEE’s emerging generative-AI security and governance projects | Controls for prompt and retrieval leakage, provider retention and training settings, and output disclosure; conduct TSDF requires regardless of which standard finally names it | Any partner using generative AI |
The critical distinction
IEEE standards address technical ethics and provenance; TSDF addresses Sovereignty. A partner’s IEEE documentation is evidence of technical capacity and seriousness. It does not grant authority, cure missing consent, override Tribal law, or substitute for the approval of an Indigenous governing body. Nothing certifies a partner into a relationship.
///AI & LLM Usage Along the Tiers
Where machine learning may touch the data, and where it may never
Transformation is the domain where governance most easily escapes; a model trained on data can outlive every agreement about the data. The Standard draws the boundaries by tier and makes them travel with the models themselves.
| Tier | Training | Inference | In practice |
|---|---|---|---|
| T0 | Permitted under the release terms | Permitted under the release terms | Release is an affirmative sovereign act, and the release decision with its license and label terms defines what “public” authorizes, including AI use. Public availability alone is never the authorization; the sovereign release is. |
| T1 | Network approval required | Network scope only | Models, embeddings, and outputs inherit T1 and remain under network governance; no submission of T1 material to public model APIs. |
| T2 | Per agreement only | Per agreement only | Agreements must name the AI use specifically (a generic “analysis” clause is not consent to train), specify compute location, and preserve the right to require model modification or termination. |
| T3 | Prohibited | Prohibited | No T3 data may enter any external AI system, including “anonymized” derivatives; computational processing of any kind occurs only within on-Nation infrastructure, and even denied attempts are logged for audit. |
- Models inherit tiers. A model trained on T1 data is a T1 artifact; its deployment, outputs, embeddings, and checkpoints carry the restriction, and model provenance documents every Indigenous data source.
- Refusal leaves a record. Attempted operations are logged even when denied, so audit can see not only what happened but what was attempted.
- The 5D problem rides into AI. Systems trained on colonial statistics reproduce deficit framing; T2 agreements involving AI/ML should require Indigenous-determined bias criteria, deficit-framing review, and output oversight (§6.3).
- Generative caution. Web-trained LLMs may already hold Indigenous Knowledge harvested without consent; inference involving Indigenous contexts requires review, and generated content derived from Indigenous data carries provenance markers naming it as AI-generated (§6.4).
AI systems can process information, identify patterns, and generate predictions. They cannot know in the relational sense Indigenous epistemologies recognize; they cannot be accountable to kin. That limit informs every boundary above.
///Auditable, Not Aspirational
Compliance means something a reviewer can verify
Section 9 of the Standard carries checklists for provenance, CARE, OCAP®, Local Contexts, and each sovereignty domain, so a claim of alignment can be examined item by item rather than taken on faith. And the next layer is already in development: ATNI-GeoPackager builds these requirements into the data artifact itself.
///From Standard to Artifact · In Development
ATNI-GeoPackager: governance that travels with the file
A standard is only as strong as the artifacts that carry it. ATNI-GeoPackager is a data wrapper in development at ATNI: an exchange profile and enforcement envelope around the open OGC GeoPackage format that embeds TSDF classification, provenance designed to support IEEE 2890-2025, and an append-only audit record inside the file itself. When the data moves, its governance moves with it.
Why a wrapper
Most geospatial data leaves home as bare files (a shapefile, a CSV, a GeoTIFF) while its governance lives somewhere else: an email thread, an agreement PDF, a colleague’s memory. Downstream tools strip metadata, derivatives lose their origins, and by the third hand-off nobody can answer the questions that matter. Whose data is this? Under what authority does it move? What may be done with it, and what may never be? ATNI-GeoPackager answers by making the artifact itself carry the record; classification, provenance, and audit ride inside the container, in the format’s own standard metadata mechanism.
Built on open ground
The wrapper extends the OGC GeoPackage standard: a SQLite-based container readable by QGIS, ArcGIS, GDAL, and nearly every modern GIS. Choosing an open format is itself a sovereignty decision; an artifact only one vendor can read is a dependency, not an asset. A Nation’s data staff can open the packages it produces with the tools they already use, and the sovereignty layer rides in the standard’s own metadata tables rather than a proprietary annex.
///Anatomy
What the wrapper adds
Classification that travels
Every layer carries a TSDF tag (tier, framework version, who classified it, and the basis for the classification) in standard GeoPackage metadata tables. The whole artifact carries a roll-up tag equal to the most restrictive tier present; the roll-up may raise the effective tier and may never lower it. The Standard’s asymmetric-harm rule, expressed as schema.
Provenance built for IEEE 2890-2025
Source attribution, content hashes, and derivation records ride with the artifact, structured to support the provenance parameters the Standard adopts; AI/ML operations are logged in the Standard’s custody vocabulary, including operations that were attempted and tsdf:denied.
An audit trail that cannot be quietly edited
Access and custody events append to a ledger inside the artifact, enforced by database triggers: updates and deletes abort. Mechanism, not convention. The record of who did what is architectural, and corrections append rather than erase.
Ceremony before egress
No export leaves a governed node without passing a sovereign authorization seam, and the authorization record is written into the audit trail, where a verifier asserts its presence; an export path that skips the seam fails loudly. T3 is refused unconditionally. No code path exports sovereign data.
Architectural guarantees for T3
Sovereign-tier data is encrypted at rest, with keys under the Nation’s control; external access is made technically impossible rather than policy-prohibited, which is exactly what the Standard requires of T3 (§3). Encryption protects confidentiality; the ledger and manifests protect integrity; the two are distinct guarantees, deliberately.
Zero-source-disclosure products
When a derived product is shared (a constraint surface for a siting agency, for instance), the export pipeline re-opens its own output and refuses release unless it contains only the product: whitelisted fields, the geometries that were drawn, and nothing that republishes a source feature. The guarantee is a verifier, not a promise.
Honest sidecars for legacy formats
Formats without an in-band metadata channel (a shapefile, for instance) receive a .tsdf.json sidecar carrying tier and provenance for human readers; the ledger remains the authoritative record. A format’s weakness is documented, never papered over.
Tamper evidence, stated plainly
Hashes and manifests make alteration detectable; they do not make it impossible. The wrapper’s integrity claims are verifiable evidence for the relationships and agreements that govern the exchange, not a substitute for them.
What a wrapper cannot do
A tier tag does not enforce itself on someone else’s laptop. Once bytes leave governed infrastructure, markings are only as strong as the agreements and relationships behind them. That is why the Standard’s window architecture prefers rendered views and compute-at-source over copies; why T3 never crosses an external boundary in any format; and why the wrapper’s job is to make governance legible, auditable, and provable. Within governed infrastructure the guarantees are mechanical. Beyond it, they are evidence.
Status
ATNI-GeoPackager is working software in active development at ATNI, maturing alongside the Standard’s v0.9 series as part of a broader sovereign geospatial platform. The sovereign ceremony process and clause-level IEEE 2890-2025 verification are the current front of the work, and design details will continue to be refined with the Nations the tooling serves. Conformance language here follows the same honesty rule as the rest of this site: designed to support IEEE 2890-2025, with verification underway. Questions and interest: climate@atniTribes.org.
///Use & Adapt
Openly licensed, deliberately conditioned
Everything in this repository is released under Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0). The conditions are not fine print; they are the license doing sovereignty work.
Share & adapt
Copy and redistribute in any medium or format. Remix, transform, and build upon the material: adopt the tiers whole, or adapt components into your Nation’s or institution’s own governance documents.
Attribution & ShareAlike
Credit ATNI and the author, link the license, note changes, and release anything you build on it under the same license, so downstream versions stay open on the same terms.
Commercial use
No commercial use without separate arrangement. A framework written to prevent extraction is not raw material for a product.
Indigenous Governance Notice
While this document is openly licensed, implementations that govern Indigenous community data must be developed in partnership with those communities and in accordance with applicable Indigenous data governance and provenance principles (CARE, OCAP®, IEEE 2890-2025, community-specific protocols). The license grants permission to use the text; it does not grant authority over any community’s data.
Adoption paths
Indigenous Nations
Review data holdings against the tier definitions · default everything unclassified to T3 · designate a governance body for classification · update your Tribal research code to reference the tiers · determine partner requirements (Standard §7) · assess infrastructure for window-architecture sharing.
Research partners
Recognize the Standard as authoritative for partner Nations · incorporate tiers into IRB protocols and data-management plans · obtain institution-level acknowledgment that IDSov supersedes university IP policy · implement IEEE 2890-2025-aligned provenance · return or destroy data per agreement.
Technology providers
Implement tier-based access control in architecture · support rendered views and compute-at-source · audit logging aligned with IEEE 2890-2025 · community-authorized Local Contexts Labels in metadata schemas · Indigenous-controlled encryption keys for T2/T3 · explicit approval before any AI/ML use.
Federal & state partners
Honor government-to-government consultation protocols · address FOIA/public-records exposure in every T2 agreement · document sovereignty-domain compliance · data return protocols with certification of destruction.
InterTribal network operators
Establish federated governance (membership, reciprocity, dispute resolution) · implement the T0 commons with resilience · deploy window architecture for T1 sharing · network-wide provenance · graceful degradation when connectivity fails.
Cite the framework
Pre-release, v0.9.5. Comment and proposed amendments are welcomed at climate@atniTribes.org. An official 1.0 release will not occur without full authorization by resolution of the Affiliated Tribes of Northwest Indians.
Related work
This repository is Part 1: the governance standard. A companion technical specification, the Federated Indigenous Data Protocol, provides implementation details for federated data infrastructure, licensed separately under Apache 2.0.
Related frameworks: CARE Principles · OCAP® (FNIGC) · Local Contexts · UNDRIP · IEEE 2890-2025