---
name: code-of-conduct-enforcement
description: Apply a code of conduct consistently, with a reporting path, proportionate responses, and records, so it protects people rather than decorating the repository. Use when adopting a code of conduct or handling a report.
---

# Code of conduct enforcement

A code of conduct that is never enforced is worse than none, because it
promises protection that does not exist. The document is the easy part;
the process for what happens after a report is the substance.

## Method

1. **Name who receives reports and how.** A specific contact that is not
   a public issue, with at least two people so a report about one of
   them has somewhere to go.
2. **Acknowledge and protect the reporter.** Confirm receipt, explain
   the process, and keep their identity to the smallest group necessary.
   Reporters take a real risk.
3. **Gather facts before deciding.** Read the actual exchange, ask both
   sides where appropriate, and separate what happened from how it felt
   to each party.
4. **Respond proportionately with a ladder.** Private warning,
   moderation, temporary suspension, permanent ban. Jumping to the
   extreme for a first minor incident is as damaging as ignoring
   repetition.
5. **Record decisions privately and consistently.** A short record of
   what was reported, decided, and communicated is what makes the second
   incident handleable and the process defensible.
6. **Communicate the outcome to those who need it.** The reporter learns
   what happened; the community learns only what is necessary, since
   public detail often re-victimises.

## Boundaries

- Enforcement addresses conduct in project spaces; it is not a general
  arbiter of disputes between people elsewhere.
- Serious matters such as threats or illegal behaviour go to the
  appropriate authorities and platform, not to a maintainer process.
- Enforcers need support and rotation, because handling reports is
  draining work (see maintainer-sustainability).
