Skip to main content
The questions we ask ourselves

How this breaks.

A structure that cannot answer how it breaks has not been designed; it has been hoped for. These are the failure modes we take most seriously — stated at full strength, answered without flinching, and flagged honestly where a risk is reduced rather than removed.

The objection, at full strength

Every “irrevocable” commitment in history has been revoked by people who controlled the instrument that was supposed to bind them. A covenant is words. A future Council, facing financial pressure or simply persuaded it knows better, amends the founding documents, reinterprets “perpetual,” and the protection evaporates — slowly, legally, with good intentions. Calling something unamendable does not make it so.

The answer

This is the risk we design against first, because it is the one that has killed comparable structures. Three things work together. The unamendability of the mission and the three refusals is not a Council policy — it is built into the foundation’s constituting documents at a level the Council does not have standing to alter; the Council governs within the Covenant, it does not govern the Covenant.

Second, the Council is composed to resist capture by any single actor: distributed across geographies and institution types, with fixed terms, a cap on consecutive service, and no permanent leadership or founder-in-residence — there is no seat from which a single person could steer an amendment through. Third, the entity that holds is structurally separated from the entity that builds and raises capital, so the financial pressure that usually drives mission drift never sits inside the body that holds the mission.

What we will not claim

No structure is proof against a sufficiently determined supermajority acting in concert over time. What a good structure does is raise the cost, slow the process, and make the betrayal visible — so that undoing the Covenant requires many independent actors to publicly defect from the thing they were appointed to protect, rather than one board passing a quiet resolution. We are designing for that asymmetry, not for an impossible guarantee.

The objection, at full strength

You connect 88,000 institutions onto shared rails, they come to depend on those rails, and now the thing that holds the rails has exactly the leverage every extractive platform started with. Benevolent today, indispensable tomorrow, repricing the day after. “Held in common” is what every utility says before it learns what its captive users will pay.

The answer

The leverage you describe is real — concentration of dependency is the precondition for extraction. What changes the outcome is who holds the concentration and whether they can extract. HAPPI holds the infrastructure but cannot pursue private profit: any surplus the infrastructure generates returns to the commons it serves, because there is no equity, no owner, and no shareholder to extract on behalf of.

The institutions that depend on the rails are also the constituency that governs them; pricing is not set by an owner across the table from users but by the users’ own representatives. And the infrastructure cannot be sold — so the classic capture move, where a benevolent commons is acquired by someone who is not benevolent, has no door to walk through.

What we will not claim

Removing the incentive to extract is not the same as removing the ability to govern badly. A non-profit can still be run poorly, price clumsily, or under-invest. The defence against that is not structural, it is the ordinary work of good governance and the fact that the members can hold their own representatives to account. We are claiming the extraction motive is designed out. We are not claiming HAPPI is immune to mediocrity.

The objection, at full strength

The whole model assumes institutions will co-specify and adopt shared infrastructure. But these are conservative, risk-averse, independently-run organisations with their own systems and no history of acting together at this scale. If enough of them don’t commit, you have a foundation, a covenant, and a beautifully argued website holding nothing.

The answer

This is the honest gating risk, and we treat it as the real test rather than a detail. It is why the model is sequenced the way it is: the infrastructure is specified with a First Cohort, not built first and sold to them — so adoption is not a later marketing problem, it is the precondition for building at all.

It is also why nothing is over-claimed before it exists: the build phase is funded to reach a working slice with the First Cohort, and the entity that builds is time-bound and capped, so capital is underwriting a defined build, not an open-ended bet on adoption. Institutions keep their licences, boards, and member relationships — the cost of participating is designed to be additive, not a rip-and-replace.

What we will not claim

We cannot claim the cohort is assured. It is the thing being assembled now, and if it does not form, the model does not proceed to build — which is the correct outcome, not a failure to hide. A structure that only works if the people it is for actually want it is not a weakness; pretending otherwise would be.

The objection, at full strength

Capital expects upside. You are asking investors to fund a build that dissolves into a non-profit they will never own, with returns capped by constitution. Either the cap is high enough that you have quietly reinvented the extraction you oppose, or it is low enough that no rational capital shows up and the build starves.

The answer

The two halves of the work are funded by two different logics, which is the point of separating them. The build is commercial and time-bound: investors underwrite a defined build with returns capped under Maslow’s constitution, with the cap stepping down at each successive raise — so capital is paid for the risk of building, not granted a perpetual claim on operating. That is a real, bounded return, attractive to capital that is aligned with the mission and wants exposure to the build without owning the commons forever.

The hold phase is funded as what it is — a commons — through the surplus the infrastructure generates returning to its upkeep, and through philanthropic and mission-aligned funding for the foundation itself. The cap is set to be high enough to clear the cost of capital for the build and low enough that it cannot become the extraction engine; that is a genuine tension we tune, not a problem we pretend away.

What we will not claim

This narrows the investor pool to capital that actively wants a capped, mission-bound structure. That is a smaller pool than the whole market, and we would rather say so than pretend the cap is free. The bet is that aligned capital exists in sufficient size — and the raise is the test of that, in the open.

The objection, at full strength

Build-phase entities never want to die. Given a long enough timeline and any discretion, the company that builds will find reasons it is still needed, still mid-mission, still the right steward “just for now.” Sunset clauses get extended. The dissolution is the part most likely to not happen.

The answer

You have named exactly the design principle, which is why the dissolution is not left to the build entity’s discretion. The transfer of the infrastructure into HAPPI’s holding and the wind-down of Maslow are written into Maslow’s own constituting documents as the terminal condition once capped returns are met — not a board decision to be taken in good faith later, but the structural endpoint the entity was incorporated to reach.

The hold entity exists from day one, in parallel, holding the Covenant the whole time — so there is no moment where dissolution requires standing up a successor from scratch under pressure, the usual excuse for delay.

What we will not claim

Documents are executed by people, and any terminal clause depends on the integrity of those administering it and the enforceability of the instrument in its jurisdiction. We are reducing the discretion, removing the “we’ll sort the successor later” excuse, and making the endpoint the default rather than a choice. We are not claiming a clause can enforce itself with no honest actors anywhere in the system.

The objection, at full strength

Right now this is prose. An elegant model, a foundation in formation, a covenant in draft — and nothing built. The most honest thing on the site is the line admitting the animations use simulated data. Why is this different from any other well-written promise that never ships?

The answer

It isn’t different yet, and we say so in those words on the site rather than implying otherwise. What exists today is the architecture, the intent, and the invitation — and the structure is built so that the next thing to exist is real: a working slice specified with and adopted by a First Cohort, funded by a bounded build.

We would rather be judged on whether that arrives than on a demo assembled to look further along than the work is. The claim we are making now is narrow and checkable: not “this is built,” but “this is the structure, this is who it is for, and this is the first step being taken in the open.”

What we will not claim

Belief, at this stage, is reasonable to withhold. The right posture toward a pre-build infrastructure claim is informed scepticism, and we are not asking anyone to suspend it. We are asking to be watched — and to be held to the difference between a direction announced and a destination reached.

This page runs deliberately harder than the FAQ, which answers the practical questions. How the structure is built to hold — the foundation, the Covenant, the dual-entity design — is on How HAPPI is held.