Governance
A short summary of how the African DSI DataBank platform itself is governed — who can add a new node to the federation, who has final say over a node's standing, and how disputes get resolved. This covers platform governance only; who formally operates the Continental Hub, funding oversight, and steering-committee composition are decisions for that operating institution, not something this page sets out to answer.
Roles
- Continental Infrastructure Admin— holds override authority over every node's administrative status, at any depth, and can grant that same authority to other trusted people. More than one admin is expected in practice, so the platform is never dependent on a single person.
- Node operator— a person responsible for one or more nodes (e.g. " operates the Kenya Spoke"). Reviews applications from the nodes under them, and decides what their own node offers or requests via data transfers.
- Anyone — most of the platform is open to read without an account; only write actions and administrative decisions require one.
How a new node joins
Two independent questions, each reviewed by a human before anything is granted, and each able to happen in either order:
- Does the node exist at all? An institution applies to register as a Sub-regional Hub, National Hub, or Spoke. This is a delegated decision by default — whoever administers the tier above reviews it, not necessarily the Continental Admin.
- Is this person allowed to operate it? A separate application for the account that actually lets someone manage a specific node day to day, reviewed by the Continental Admin.
Continental override
Delegated approval is the default, but the Continental Admin retains override authority over every node's administrative status — approve, reject, suspend, or reinstate — no matter how deep in the federation it sits. Every such action is recorded in a permanent audit log: who did what, to which node, and when, so "who suspended what" always has an answer.
What Continental override does not reach
Whether a node sends its data upward at all is a separate decision, and it is never something anyone outside that node's own operators can override. This exists specifically so a node's own national regulatory and consent obligations are honored by that node's own institution, not overridden from outside. Suspending a misbehaving node's administrative standing never forces it to share data it has chosen to keep local.
Access and consent decisions
Two further categories of decision are kept deliberately separate from node admission: requests to access a specific data record (gated by that record's own access tier — see Terms of Use), and node<->Hub data transfers, which require both sides' explicit consent before any bytes move — neither side can be forced to give or take data by the other.
Disputes
If a node operator disputes an administrative action taken against their node, the audit log is the starting point — it records the actor, action, target, and outcome for every decision made. From there, resolving a dispute is a direct conversation between the affected node operator and the Continental Hub operator.
See also: Terms of use & citation policy, Node operator handbook, Security.