DEV Community

Francis Oyakhire
Francis Oyakhire

Posted on • Originally published at asotele.apexgridapps.com

The CC-BY 4.0 we never had

The day started with the word "status."

I typed it into the model without qualification, hoping the answer would be short. The reply came back with the shape of a project dashboard: RAG index at 695,337 chunks, sector-audit halls at 13 out of 136, three advisors landed, port-activity ingest freshly wired the previous evening. The last item on the list was a follow-up bullet from yesterday's session: " Founder unblocked #3 HDX port activity — ingest/port\_activity\_to\_duckdb.py\ landed: imf\_portwatch\_daily\ 78,880 rows · 29 ports · 2019-01 → 2026-06 + 11 transport\_port\_activity\ narrative chunks. Kind added to NIGERIAN_KINDS. RAG: 695,326 → 695,337. DHS + IATI still pending founder call."

The port-activity note was written at yesterday's end. Two dataset decisions — DHS Subnational and IATI Nigeria, both flagged as HDX "Other" licence — had been left open. The intended plan was to address them, close them out, and move on.

I picked the DHS + IATI thread first. Both packages had been sitting in data/forecasts/hdx/\ since 2026-06-20, downloaded but not indexed, waiting for licence verification. The HDX API package\_show\ endpoint returned their real licence text, buried in a license\_other\ field that the summary listings don't surface. DHS came back as CC-BY-NoDerivatives 4.0 — a real CC licence, but not one on our whitelist, and — critically — a licence whose derivative-works clause makes any LLM-paraphrased briefing about the data legally ambiguous. IATI came back as " licence is delegated per publisher" — a mixed-licence pool where every activity carries whichever CC (or non-CC) terms its reporting organisation chose, with no per-activity field in the JSONL export to filter on.

Both firewalled. Tracker rows moved from ❌ pending to 🚫 firewalled. Two memory files written. The health-and-education blind spot that DHS was going to fill stays open; the fiscal-aid gap that IATI was going to fill is already partially covered by cleaner-licenced siblings in the same HDX batch (OCHA FTS, CBPF, CERF, IFRC — all under uniform terms).

That looked like the end of the story. It was actually the middle.

"That came from a government website — I didn't think that would have any issues"

The next message from the founder was casually declarative: let us double check port activity that came from the government website I did not think that would have any issues.

This is the discipline that produces the good catches — the reader who trusts nothing yet, including yesterday's confident bullet in yesterday's own notes. IMF PortWatch is not a Nigerian government website (it's the IMF's vessel-tracking dashboard for global port activity), but the founder's instinct read a deeper fact than the words: if we 've been quietly confident about a source, someone should look.

The HDX API for the port-activity package returned this, verbatim in license\_other\:

https://www.imf.org/en/about/copyright-and-terms\

Just a URL. No CC licence declared. Not CC-BY, not CC-BY-4.0, not CC-anything. A pointer to IMF's own copyright page — which, on retrieval (via Wayback, because www.imf.org\ is Akamai-blocked to our stack for reasons already documented), turns out to declare IMF 's own bespoke Data Terms, effective 2024-10-11. Not on any Creative Commons spectrum at all.

The Data Terms are substantively permissive for our use case — the "Use of IMF Data" section explicitly overrides IMF's general commercial-use prohibition and grants " download, extract, copy, create derivative works, publish, distribute, and use" subject to attribution and integrity. There's a genuinely ambiguous clause immediately following that says " For any potential commercial reuse of IMF Data, please email [email protected] to request permission," which reads either as a safety-belt-not-a-hard-gate or as a hard-gate depending on how conservatively you interpret the drafter. But the material fact remains: it is not CC-BY 4.0.

Yesterday's ingest note had said, with confidence: " HDX manifest flags 'Other' but the upstream IMF PortWatch (portwatch.imf.org) publishes CC-BY 4.0." That claim was unverified — I had assumed it based on context and phrasing that sounded reasonable. Three hardcoded strings in sources/ingest/port\_activity\_to\_duckdb.py\ carried the false CC-BY-4.0 declaration. Eleven narrative chunks in the RAG index each contained the sentence " Source: IMF PortWatch (portwatch.imf.org) via HDX. Licence: CC-BY 4.0." in their topline. The DuckDB imf\_portwatch\_daily\ catalog metadata had a "license": "CC-BY-4.0"\ field.

Any bank-facing brief that cited port-activity data would have shown that footer. Any lawyer reading the brief would have caught the mismatch — because IMF Data Terms have a fingerprint (they require the specific attribution string " Source: International Monetary Fund, Database <>") that a CC-BY 4.0 footer erases. The failure would not have been "we cited an unlicensed source"; it would have been "we cited the source under the wrong licence and mislead a reader about the terms of use." That's a different flavour of unforced error, and arguably a worse one for a fiduciary-facing product.

The fix landed in about twenty minutes: three source-string edits in the ingest script, a re-run that replaced-in-place the eleven chunks with the correct attribution (" Source: International Monetary Fund, IMF PortWatch Nigeria daily port activity … Terms: IMF Data Terms (imf.org/en/about/copyright-and-terms)"), and a tracker note that recorded the earlier-note-was-wrong finding openly.

The rule that made itself

The catch changed the shape of the rest of the day. Every remaining ❌ pending row on the coverage tracker went through the same verify-verbatim-first pass before being touched. HDX-published packages: pull license\_other\ directly from the API, don't trust the summary listing. Non-HDX Nigerian gov sites: read the actual /legal\ page and, if the artifacts are PDFs, sample the front matter for embedded engagement-letter clauses.

The next five items on the shortlist:

- HDX Nigeria health-care facilities (GRID3 publisher) — API returned license\_id: cc-by\, license\_title: Creative Commons Attribution International \(CC BY\)\, license\_url: http://www.opendefinition.org/licenses/cc-by\. Textbook CC-BY. On the whitelist. Ingested clean: 46,146 facilities across 37 states and 769 LGAs into DuckDB nga\_health\_facilities\, plus 38 per-state narrative RAG chunks. Every chunk carries the correct attribution string this time — no hardcoded CC-BY declaration written from memory. The data itself is bank-relevant: LGA-level facility inventory with ownership mix (public / private / mission), functional-status (74.3% functional, 25.5% unknown), and tier (95.3% primary, 2.9% secondary, 1.7% tertiary). Lagos state alone: 2,320 facilities across 20 LGAs, 49.6% private, 24.1% state PHCDA. This is the level of granularity that lets a bank underwrite a hospital-loan portfolio.

- Mozilla Common Voice — Nigerian languages. Licence verified verbatim from the common-voice/cv-dataset\ GitHub repository: CC-0 (public-domain dedication). Zero risk. But the Nigerian-language coverage tells its own honest story: Hausa 4.09 validated hours, Yoruba 5.57, Igbo 0.02, Pidgin absent from Common Voice entirely. The trajectory across releases v13 → v21 (2023-03 → 2025-03) shows Yoruba growing fastest, Hausa slow-steady, Igbo effectively stagnant. Metadata-landed as four RAG chunks; audio files not downloaded because we don't currently have a speech pipeline. This is future substrate for the accessibility workstream, catalogued honestly with the gaps stated.

- Nigerian Pidgin Bible (eBible.org, expected as a Pidgin-corpus filler). The details page for the only Pidgin translation on eBible reads: " Copyright © 2019 Wycliffe Bible Translators, Inc. … All rights reserved." Not CC-anything. Firewalled. The Pidgin gap has to close some other way — AfriSenti (CC-BY-4.0), WURA Pidgin split (Apache-2.0, partial already), NollySenti (CC-BY-SA-4.0) — all noted in an existing memory that the day's audit reaffirmed rather than replaced.

- NEITI — Nigeria Extractive Industries Transparency Initiative audit reports (row #99, oil-and-gas + solid-minerals + fiscal-allocation reconciliation audits). This one was subtle. The NEITI site was migrated to Next.js since our last probe, but SSR HTML still exposes all 55 audit-PDF URLs cleanly. The /legal\ page says " Content is protected by copyright and intellectual property laws." Traditional copyright — no CC grant. But the deeper distinction is on the PDFs themselves. Page 3 of the 2013 Oil and Gas audit report, embedded verbatim by the audit firm (Taju Audu & Co) before NEITI published the artifact: " Our report is solely for informing the NSWG on the matters set out in the Terms of Reference and is not to be used for any other purpose." NEITI publishes the reports under statutory mandate; they don't author them. The audit firms do — different firms in different years — and each firm attaches engagement-letter language that governs downstream use. Nigerian statutory-instrument no-copyright status (which unlocks tax laws and Presidency releases) does not extend to consulting deliverables published under statute. Catalog-only ingest : 55 audit-report titles with year + sector + URL, plus fair-use extraction of the three NEITI-authored press releases at /media/news/\*\. Seven RAG chunks total. Full-text ingest requires a written reuse licence from NEITI, which the founder can pursue via [\[email protected\]](/cdn-cgi/l/email-protection)\ if oil-transparency full-text becomes strategically critical later.

- PEBEC — Presidential Enabling Business Environment Council (row #91, 200 MB of reform reports harvested via Wayback since the live site was moved behind Clerk authentication). PEBEC is a Presidency body; its reports are self-authored federal-government public output. Same author class as State House policy releases already in the corpus, distinct from the NEITI audit-firm class. Fifteen text-extractable PDFs ingested: Executive Order 1 on Ease of Doing Business (2017), National Action Plans NAP-60 / 2.0 / 5.0 / 7.0, three EO1 compliance reports (2021, 2022, 2024-H1), the Business Facilitation Act 2022 text plus its 2023 compliance report, and the biggest single artifact: the January 2021 Subnational Ease of Doing Business Baseline Survey — 156 pages scoring all 36 states plus FCT on regulatory-friction metrics. 759 new RAG chunks. Two scanned PDFs deferred to the OCR backlog. One duplicate skipped.

The five decisions in sequence: catch-and-correct, firewall, land-clean, land-metadata-only, firewall, catalog-only, land-clean. The RAG index moved from 695,337 chunks at the start of the day to 696,145 at the end. Not dramatic. Two of the five items were bigger conversation-changers than any raw-chunk-count would suggest.

The distinction the audit made explicit

At the beginning of the day, the mental model was " Nigerian federal-government content is default safe to ingest with cite-with-attribution." That model was mostly right — it correctly handled State House releases, tax laws, the CBN corpus, the NAICOM insurance corpus, the NDIC bank-stability corpus, the NUPRC gas-sector rows.

What today's arc surfaced is that the model was too coarse. The load-bearing question isn't who published this? — it's who authored the specific artifact?

- Self-authored by the federal-government body: State House releases, tax laws, NAICOM guidelines, NDIC quarterly reports, PEBEC reform reports. Cite-with-attribution safe. - Third-party-authored, government-published under statute : NEITI audit reports (authored by Taju Audu & Co and other consulting firms), similar future items likely including NNPCL audits, DPR/NUPRC commissioned consultancy reports, and the AMCON annual reports (whose author-class we still need to verify before promising a date on that ingest). These carry the authoring firm's engagement-letter terms even when the government publishes them under a public-disclosure mandate. - Third-party-published under a bespoke non-CC licence : IMF PortWatch (IMF Data Terms), USAID DHS Program via HDX (CC-BY-ND), most WFP HDX packages (need per-package check because "usually CC-BY-IGO" was the assumption class that just broke on PortWatch). - Third-party-published under whitelist CC : Grid3 health facilities (CC-BY), Mozilla Common Voice (CC-0), WB WDI (CC-BY-4.0), Africa's Pulse (CC-BY-IGO).

The distinction changes what each remaining ❌ row on the tracker requires. It's no longer a licence audit on the publisher — it's a licence audit on the author of the artifact. That's a slower but more honest posture, and it's the one a fiduciary-facing product needs.

What this is not about

The Asotele product is a data product for Nigerian banks. Banks trust it — the intent is that they eventually will trust it — to inform credit committees and treasury decisions. The stack we're building is the stack such a bank would build itself if it had the time.

Nothing about today's arc was a licence-crisis story. No bank has been harmed. No brief was shipped with a false attribution — the CC-BY-4.0 fabrication was caught before it appeared on any advisor-facing surface, let alone a bank-facing one. The chunks were replaced in-place with the correct attribution about ninety minutes after the founder's initial " let us double check" message.

But the near-miss is the point. In eleven months of building this system, the failure mode I have come to trust least is the confident line in yesterday's own notes. Today it was licence text; earlier this week it was a hardcoded oil-benchmark constant; last month it was a WHO relevance-classifier that lifted country mentions into country-cases. Each of those was caught by the same shape of behaviour: someone reading a system output and refusing to accept the sentence just because the system produced it.

The audit-yesterday's-notes discipline compounds in a way that adding data does not. Four new ingests today added 808 chunks. The catch removed one class of latent failure that would have been embedded in every future bank-facing citation of a large recurring dataset.

The rule that came out of the day is not going to sound novel. Every HDX package with license\_id == hdx-other\ needs license\_other\ pulled verbatim before ingest. Every non-HDX Nigerian federal-government artifact needs the author of the specific document verified — not just the publisher. Every commit that hardcodes a licence string in an ingest script requires a citation to the verbatim source that the string came from.

None of that is beautiful engineering. It's tax on shipping. But it's exactly the tax a bank pays when it does its own version of this work, and it's exactly the tax that makes the difference between "a project someone built quickly" and "a system someone can rely on."

We didn't move the sector-audit needle today. Halls at 13 out of 136 this morning; halls likely at 13 tomorrow, until the next audit run comes in overnight. The compounded improvement is in the moving parts you don't see — the memory that now records why DHS is blocked, the ingest script that now emits the correct IMF attribution, the tracker row that now notes the audit-firm engagement-letter distinction that will apply to a dozen future items.

The CC-BY 4.0 that we never had is not in the system any more. That's the win.

— founder note, 2026-07-03

Top comments (0)