ATFA · Certification

Restricted · CE Review Committee

Decision register

The question, the decision, the reasoning, and the alternatives that were rejected. Check here before re-opening anything.

The alternatives rejected column is the one that earns this register its keep. A year from now the question is rarely “what did we decide” — it is “did we already think about this.”

Rendered from data/decision_register.csv at build time. Entries marked Open are undecided. Entries whose public flag is set also publish plain-language text to the site's questions and answers page — both come from this one record, so they cannot drift apart.

IDCategoryQuestionDecisionRationaleAlternatives rejectedStatus
DR-001 Governance Who holds authority to approve or deny CE credit? The Director recommends; the Committee decides. No recommendation takes effect until ratified. An advisory-only committee would make the legitimacy claim inaccurate, and a public claim that diverges from actual practice is discoverable by exactly the parties least welcome to find it (an appealing holder, an accreditation reviewer). Accurate modest claims beat aspirational strong ones. (a) Committee deliberates, Director decides — accurate but weaker legitimacy. (b) Split authority: Committee binding on policy, Director on individual items — rejected because it requires a subjective boundary call on every item. Draft
DR-002 Governance How are decisions ratified? Negative consent. Report circulated to full Committee; five business days to object; no objection ratifies the batch. Applies to standing meetings and ad hoc alike. Places the burden on Committee members to engage while preventing an unresponsive member from stalling the organization. Legitimate only where the opportunity to object was real and documented, which is why circulation date, deadline, and membership circulated to are recorded fields. Affirmative vote with quorum — rejected as too slow and creating a failure mode when quorum is not met. Draft
DR-003 Governance Does every submission require Committee ratification? No. Submissions matching a program the Committee has already tiered are executed administratively and reported in aggregate. The Committee decided the tier; matching a submission against it is clerical execution of a decision already made, not a new decision. Preserves Principle 1 while letting the routine queue move. The share requiring ratification falls as the Known Programs database grows — by design. Ratify every item individually — rejected as unsustainable at volume and as false precision, since it implies deliberation that would not occur. Draft
DR-004 Governance How often does the Committee meet? At least quarterly, with ad hoc meetings as volume or a forcing issue requires. Cadence may be reduced if quarterly proves unnecessary. Quarterly is frequent enough that holders are not left waiting long for ratification, and infrequent enough to respect volunteer time. Starting higher and reducing is easier than the reverse. Annual only — rejected because it leaves holders in limbo for up to a year. Monthly — deferred until CE App API access makes it low-cost. Draft
DR-005 Review Standards Should unverifiable and unqualified submissions be treated the same? No. Denial code 4 (not verifiable) is distinct from code 1 (does not meet standards). Code 4 notices invite the holder to supply evidence and resubmit. A submission ATFA could not confirm and one that fails on merit are different outcomes with different remedies. Collapsing them denies the holder the chance to fix a documentation gap. Single generic denial code — rejected as unfair to holders and as destroying useful signal about where research is failing. Draft
DR-006 Review Standards How are duplicate submissions handled? Denied under code 2 on the duplicate record only. The original submission stands and the holder keeps the hours. A duplicate is a submission-hygiene issue, not a program issue. The denial notice must state explicitly that the original stands, or it reads to the holder as a loss of credit. Silently merge duplicates — rejected because it leaves no record of what the holder actually submitted. Draft
DR-007 Review Standards Does eligibility attach to the completion date or the submission date? Completion date. A program completed outside the cycle coverage period falls under denial code 5 regardless of when it was submitted. Credit is earned by attending, not by filing. Also allows a holder who attends in January and submits in August to be processed in a later batch without appearing late or ineligible. Submission date — rejected as penalizing holders for administrative timing rather than substance. Draft
DR-008 Documentation What date format is used in published documents? Day-month-year with abbreviated month: 1 Jan 2026 - 31 Dec 2026. All-numeric formats are ambiguous across readers — 03/08/26 is two different days depending on convention. For documents that may reach an auditor or a disputing holder, that ambiguity is a liability. Quarterly shorthand is retained as a secondary label only. dd/mm/yy and mm/dd/yy — both rejected as ambiguous. Quarterly shorthand as primary — rejected because quarter boundaries drift if the cycle stops aligning to the calendar year. Draft
DR-009 Schema Should provider and session be modeled as one entity or two? Two. Tier is assigned to the provider; sessions reference the provider. A single flattened entity would force the tier question to be re-litigated for every session from the same provider. Shenkman Education publishes several sessions monthly — one tier decision should govern all of them. Single flat table — rejected. Three levels with a separate events table — deferred; event_name on sessions covers conference grouping for v1. Draft
DR-010 Schema How are provider name variations matched? A dedicated alias table. Every spelling resolved to a canonical provider is appended permanently. The tier promotion loop (Tier 4 to Tier 3) helps once per program. Aliases help on every submission forever, including for providers already known. This is the primary compounding mechanism in the system, not tier promotion. Fuzzy string matching alone — rejected as non-deterministic and unauditable. Manual correction each cycle — rejected as non-compounding. Draft
DR-011 Schema How is missing data represented? Three states: empty = not yet researched; NONE = researched and confirmed absent; N/A = not applicable. Collapsing these loses the ability to tell whether work remains. "We have not looked" and "we looked and there is nothing" route to completely different places — the second is ready for a decision, the first is not. Single null — rejected as destroying research-status signal. Draft
DR-012 Schema Are claimed hours and awarded hours stored separately? Yes. hours_claimed and hours_awarded are distinct fields. What the holder requested and what ATFA granted are different facts. Storing only one makes variances invisible — and a live variance already exists (1.5 claimed vs 1.25 published on the same session by two holders). Single hours field overwritten on decision — rejected as destroying the audit trail. Draft
DR-013 Schema Does the schema contain a director_decision field? No. Deliberately omitted. The decision field is committee_decision. A field that exists will eventually be used. Omitting it makes the schema structurally consistent with Principle 1 rather than merely nominally consistent. Include both fields — rejected because it would let practice drift from the stated governance without anyone noticing. Draft
DR-014 Schema How is received data handled on intake? Raw layer preserved immutably; canonical layer derived from it. Every canonical record points back to its source file and row. Normalization rules will turn out to be wrong sometimes. When that happens the canonical layer is re-derived from raw. Editing raw in place makes that impossible. Clean on intake and discard the original — rejected as unrecoverable. Draft
DR-015 Operations What is the review engine called? BEN, in capitals or as B.E.N. Capitalization distinguishes it from the Director, Ben Hopf. Working placeholder retained after shortlisting alternatives. Capitalization resolves the collision with the Director name in written records. Batch Evaluation Navigator, Bureau of Evaluation & Notation, Benchmark Evaluation Navigator — all shortlisted; expansion still open. Draft
DR-016 Operations How does ATFA update submission statuses in CE App? CSV bulk export sent to CE App support for implementation. No API access is available. CE App confirmed no API is available at this time but will process bulk approvals from a CSV. Column names in the export template are ATFA best-guess and require confirmation before the first real batch. Direct API integration — unavailable. Manual per-record entry — rejected as unsustainable and the original driver for this project. Draft
DR-017 Review Standards Does ATFA accept education from providers who are not accredited CE sponsors? OPEN — not yet decided. Blocking tier assignment for Shenkman Education and any similar provider. Raised by SUB-2026-041 (CRUT Basics, Shenkman Education). Content is verifiable and practitioner-level; provider states no CLE or CPE is offered and issues an automated attendance certificate. Threshold question should be ruled once; individual session merit remains case-by-case. Case-by-case on the threshold itself — flagged as a fairness risk, since two holders submitting the same session in different quarters could receive different answers. Open
DR-018 Governance Who assigns a program its tier? The Committee. Recorded with tier_set_by, tier_set_date, tier_set_cycle, and tier_rationale. Tier assignment is the decision that all subsequent administrative execution rests on. If the Director assigned tiers, the delegated-execution model in DR-003 would collapse back into Director authority by the back door. Director assigns tiers subject to Committee review — rejected as functionally identical to Director authority. Draft
DR-019 Infrastructure Where should DNS and static hosting live? Cloudflare DNS and Cloudflare Pages, migrated from Squarespace/NS1 on 9 Sep 2026. Gating /committee/ requires authentication. Netlify restructured pricing 14 Apr 2026 and password protection is Pro-only at roughly $240/yr. Cloudflare Access is free for up to 50 users and provides per-person login plus an access log, which is stronger than a shared password for a body whose function is documented accountability. Netlify Pro with site-wide password - rejected on cost and because a shared password gives no individual attribution. Squarespace hosting - rejected; no path to gated paths or version-controlled deploys. Adopted
DR-020 Infrastructure Can shared group addresses hold infrastructure logins? No. Infrastructure accounts use individual identities. Groups receive mail; they do not log in. A group login requires a shared password owned by nobody, which is weaker than individual accounts and destroys attribution. Cloudflare account owner is submissions@ (an org-owned Workspace user); admin@ is a group for vendor and billing mail only. admin@ as the Cloudflare account owner - attempted and abandoned; a group cannot accept an invite without creating a shared credential. Adopted
DR-021 Infrastructure How is email authentication configured? SPF, DKIM (2048-bit), and DMARC added 9 Sep 2026. DMARC starts at p=none. The domain previously had none of the three. Without SPF and DMARC anyone could spoof submissions@, and BEN outbound notices at volume would have landed in spam. DMARC at p=none monitors without rejecting; move to p=quarantine after several weeks of clean reports. Leaving authentication unconfigured - rejected; spoofing exposure and deliverability failure are both unacceptable for an organization emailing credit decisions to holders. Adopted
DR-022 Infrastructure Does the gated area use a subdomain or a folder? A folder — atfacertification.com/committee/ — protected by a Cloudflare Access policy. One deploy, one certificate, one DNS record. Access policies apply per-path, so a folder gives the same protection as a subdomain with less to maintain. Prior work had fragmented across four unlinked Netlify subdomains; consolidating reverses that. committee.atfacertification.com subdomain - rejected as more infrastructure for no additional protection. Adopted
DR-023 Infrastructure Should a personal account hold administrative access? Yes, temporarily. benthopf@gmail.com holds Super Administrator on Cloudflare as a documented exception. Both org-owned admin paths depend on Google Workspace mail. If Workspace fails or a DNS change breaks the domain MX, that dependency chain locks the operator out of the tool needed to fix it. A personal address outside that chain is a genuine recovery path. Org addresses only - rejected; creates a circular lockout risk during exactly the failure it would need to fix. Adopted
DR-024 Infrastructure Where does the site source live? A private GitHub repository under an ATFA organization, connected to Cloudflare Pages for automatic deploys. An organization rather than a personal account so the repo survives a change of Director — the same succession reasoning behind naming the engine BEN. Git provides version history and rollback; a .gitignore blocks committee and holder PII, since git history is permanent and a file committed once is recoverable forever. Personal GitHub repo - rejected on succession. Drag-and-drop deploys - rejected; no version history, no rollback, no diff. Adopted

Adding an entry

Entries are appended, never edited in place and never renumbered. A decision that replaces an earlier one records the superseded ID rather than overwriting it, so the history of a question stays readable.