Repository Use, Automated Access & Acceptable Conduct Policy

Keep access open. Keep the service dependable.

The JR Institute intends to support human readers, libraries, search engines, researchers, developers, and responsible automated systems while protecting repository availability, security, privacy, and the integrity of the scholarly record.

Developing Framework

This page presents a planned public standard. Final API terms, rate limits, account controls, security-reporting channels, automated-access methods, and enforcement procedures should be established before the repository becomes operational.

Policy Purpose

Open scholarship depends on both broad access and reliable infrastructure.

Automated discovery, indexing, preservation, citation analysis, and text mining can expand the value of a repository.

Uncontrolled traffic, credential misuse, deceptive automation, destructive testing, and attempts to bypass restrictions can impair access for everyone.

Core Principles

Open discovery, transparent automation, proportional controls, and accountable use.

01

Human Access First

Maintain dependable access for researchers, participants, authors, libraries, and the public.

02

Responsible Automation

Identify automated clients, follow published interfaces, and avoid unnecessary load.

03

Account Integrity

Protect credentials, use accurate identities, and do not impersonate authors, institutions, or services.

04

Security Respect

Do not interfere with systems, bypass controls, exploit vulnerabilities, or access restricted records.

05

Lawful Reuse

Follow licenses, privacy requirements, attribution duties, embargoes, and record-specific restrictions.

06

Proportionate Enforcement

Use warnings, rate controls, temporary restrictions, and appeals before permanent exclusion where practical.

Scope

This policy is intended to apply to public browsing, authenticated accounts, submissions, downloads, APIs, feeds, metadata harvesting, indexing, automated agents, bulk access, security testing, and other interaction with the future JR Research Archive.

User Accounts, Identity, and Credentials

Users should provide accurate information when identity or affiliation is required for submission, moderation, restricted access, or administrative activity.

Credentials should not be shared, sold, transferred, or used to conceal the person or organization responsible for repository activity.

Search Engines, Bots, Crawlers, and Automated Agents

Responsible automated access may be permitted for indexing, preservation, research, accessibility, citation analysis, metadata exchange, and other legitimate uses.

Automated clients should use descriptive user-agent information, respect published instructions, avoid excessive concurrency, and provide contact information when requested.

Public availability does not create an unlimited right to overwhelm the service, bypass controls, or ignore record-specific licenses.

APIs, Feeds, Metadata Harvesting, and Bulk Downloads

The Institute may provide APIs, feeds, export files, or scheduled bulk-access methods to reduce unnecessary scraping and improve consistency.

  • Use the published interface when one is available
  • Follow rate limits and pagination requirements
  • Cache responsibly and avoid repeated identical requests
  • Preserve identifiers, version information, rights, and withdrawal notices
  • Do not redistribute restricted or nonpublic material

AI Training, Machine Learning, and Automated Analysis

Repository content may be used for machine learning or automated analysis only when the record’s license, access conditions, privacy status, and applicable law permit that use.

Users should preserve attribution, version and withdrawal information, and should not imply that the Institute, authors, or repository endorse a resulting model, product, or analysis.

Security Research and Vulnerability Reporting

Security testing should occur only within published authorization, defined scope, and safe-harbor terms.

Researchers should avoid privacy harm, service disruption, destructive actions, persistent access, credential exposure, or public disclosure before reasonable remediation.

Prohibited Conduct

Users should not attempt to disrupt, degrade, deceive, compromise, or misuse the repository or its users.

  • Bypassing authentication, embargoes, or access restrictions
  • Uploading malware, malicious code, or deceptive files
  • Impersonating authors, reviewers, staff, or institutions
  • Manipulating downloads, citations, endorsements, or usage metrics
  • Overloading systems or evading reasonable rate controls
  • Harassing users or using repository data for unlawful targeting

Privacy, Personal Data, and Restricted Records

Public metadata should not be combined, enriched, or republished in ways that create unlawful, deceptive, discriminatory, or materially harmful profiles of individuals.

Restricted, embargoed, confidential, or accidentally exposed information should not be accessed, retained, redistributed, or used beyond authorized purposes.

Monitoring, Rate Controls, Suspension, and Enforcement

The Institute may monitor service health, authentication events, request patterns, abuse indicators, and security activity to protect the repository and its users.

Responses may include warnings, lower rate limits, revoked tokens, temporary account suspension, blocked traffic, content removal, preservation of evidence, or referral for legal or institutional review.

Notice, Appeals, and Restoration of Access

When practical and safe, affected users should receive notice of the restriction, principal reason, duration, and available corrective action.

Appeals may address mistaken identity, inaccurate detection, disproportionality, corrected technical behavior, or other relevant evidence.

Access may be restored with conditions such as lower limits, new credentials, verified contacts, monitoring, or an approved technical integration.

Framework date: July 2026

Responsible Access Lifecycle

Identify, access, limit, attribute, monitor, and correct.

  • Identify. Use accurate account information and descriptive automated-client credentials.
  • Access responsibly. Use published APIs, feeds, exports, and repository interfaces where available.
  • Respect limits and rights. Follow rate controls, licenses, embargoes, privacy, and record-specific restrictions.
  • Attribute and preserve context. Retain identifiers, versions, authorship, rights, and correction or withdrawal notices.
  • Correct harmful behavior. Respond to warnings, repair integrations, appeal errors, and restore access under appropriate safeguards.
Access or Integration Questions

Ask about APIs, indexing, bulk access, bots, AI use, rate limits, or security research.

Inquiries may concern automated harvesting, search indexing, preservation copies, machine learning, account restrictions, responsible disclosure, or technical integration.

Submit a Repository Access Inquiry

Identify the organization, intended use, data volume, access method, expected request rate, technical contact, and timeline.

Contact the Institute