Ontaym
Community & Group Organizing

A Code of Conduct Is an Exit Sign

Ontaym Editorial Team · · 16 min read

A group of colleagues in discussion around a desk in a bright office

A code of conduct is not read by the people it protects until the moment they need it, and by then it is too late to write one. It is infrastructure, in the same category as an exit sign: ignored on every ordinary night, and the only thing that matters on the one night it is not ordinary.

Quick answer

A 2026 study of open-source communities examined 158,735 repositories with a code of conduct, covering 93,501 unique documents and 126,203 commits - the largest empirical picture of what these documents actually look like in practice.

The headline finding for organisers: over 75 percent of sampled projects had only one code-of-conduct-related commit in their entire history. It gets adopted once and then never touched again.

Adoption correlated with more new contributors joining across every timeframe measured - one, three, six and twelve months - which is the closest thing to evidence that a code of conduct grows a community rather than merely policing it.

The document nobody reads on purpose

Ask a room of event attendees whether they have read the code of conduct and almost nobody has. Organisers take this as evidence that the document does not matter.

It is evidence of the opposite. An exit sign that everybody stopped to read would be a badly designed building. The function of these documents is not to be read in advance; it is to exist, unambiguously, at the moment someone needs to know whether what just happened to them is something this group considers acceptable, and who they can tell.

That moment is rare and it is not predictable. The entire value proposition is that the work was done before it was needed, by people who were calm, rather than during it, by people who are not.

You do not write a code of conduct for the ninety-nine evenings that go fine. You write it for the one that does not, and you cannot know in advance which one that is.

What these documents actually contain, at scale

There is now real empirical data on this rather than opinion. A study presented at ICSE 2026, examining code-of-conduct adoption across open-source software, assembled a dataset of 158,735 repositories containing a code of conduct - 93,501 unique documents and 126,203 commits - and then sampled 1,534 active and dormant projects for closer analysis.

Open-source projects are not events, but they are the closest large-scale analogue available: voluntary communities, distributed leadership, newcomers arriving continuously, and no formal employment relationship to fall back on. The structural findings transfer well.

Feature - Share of sampled projects

Included external links for further information - 97.3%

Included an email contact for reports - 72.1%

Hosted the document directly in the project - 58%

Linked to an externally hosted document - 42%

Had only one CoC-related commit ever - Over 75%

The 72.1 percent figure is the one worth pausing on. More than a quarter of these documents describe what is unacceptable without providing any mechanism for reporting it. That is an exit sign pointing at a wall.

The commit finding, and what it says about how to write one

Over three quarters of the projects in that sample touched their code of conduct exactly once - adopted it, and never revised it again.

There are two readings, and both are useful. The pessimistic one is that the document is largely ceremonial: added because a template existed, never engaged with afterwards. The practical one is that whatever you write on day one is, statistically, what your community will still be operating under in five years.

Take the second reading seriously and it changes the drafting priorities entirely. If this is a document you will realistically never revisit, then the parts that must be right are the durable ones - who to contact, what happens next, who decides - rather than an exhaustive enumeration of prohibited behaviour, which is the part most drafts spend all their energy on.

Statistically, the version you write this week is the version your group will still have in five years. Write the contact line as though that is true, because it is.

Does it actually do anything?

This is the question organisers actually have, usually unspoken: is this a real intervention or a box to tick.

The same study measured what happened to contributor activity after adoption, and found a positive correlation with new contributors joining across all four timeframes examined - one, three, six and twelve months. Communities that adopted a code of conduct saw more newcomers arrive, not fewer.

There is a more nuanced secondary finding worth reporting honestly: the study also observed a short-term uptick in disengaged contributors in the one-to-three-month window, with limited long-term effect. Read plainly, some people leave shortly after a code of conduct appears, and that effect does not persist.

Correlation is not causation and the authors are careful about this. But the direction is the opposite of the fear organisers usually express, which is that formalising conduct rules will make a friendly group feel bureaucratic and drive people away. The data does not support that fear.

The part that takes actual thought

Most of a code of conduct can be borrowed. The behavioural section - harassment, intimidation, unwelcome attention - has been written well many times, and adapting an established text is the correct move rather than a lazy one.

What cannot be borrowed is the reporting mechanism, because it depends on facts about your specific group that no template knows.

  • Who receives a report? A named person or a monitored address. Not "the organisers" as an abstraction - a specific inbox somebody actually reads.
  • What if the report is about that person? This is the question templates never answer and the one that matters most. A single-organiser group needs a second route, even an informal one.
  • What happens in the first 24 hours? Not the full process - just what the reporter can expect to hear back, and when.
  • Who can act alone, and who has to consult? Removing someone from a group is a permission, and a leadership team that has not divided permissions in advance will divide them badly during an incident.
  • What is written down afterwards? A group with no record will handle the same person's second incident as though it were their first.

The second item is the one that quietly determines whether the whole document functions. A code of conduct that routes all reports to a single organiser has an unstated assumption baked into it, and the situations where that assumption fails are precisely the situations where a reporter is most vulnerable.

Hosted or linked

The study's split between projects that hosted the document directly (58 percent) and those that linked to an external one (42 percent) maps onto a real decision for event organisers.

Linking to a well-known external code has genuine advantages: it is maintained by someone else, it is recognisable to people who have encountered it elsewhere, and it signals alignment with a broader community. Hosting your own means it says exactly what your group means and cannot change without your knowing.

Approach - Advantage - Where it strains

Link to an established external code - Recognisable, maintained by others, fast to adopt - Reporting contacts are generic; it can change under you

Host your own adapted version - Says exactly what you mean; contacts are yours - Nobody maintains it; it dates quietly

Adapt an external code, host it yourself - Borrowed language plus your own reporting route - Requires you to actually do the adaptation

The third row is the one worth choosing, and it is what the 97.3 percent external-link figure suggests most projects half-do anyway: use established language for the behavioural section, host it under your own name, and replace the contact and process sections with real specifics about your group.

When to write it

Before you need it, obviously. The more useful answer is: before your group is large enough that you no longer know everyone in the room.

A group of eight friends does not need a formal document, and producing one would be strange. The threshold is not a headcount so much as a change in composition - the first event where a stranger can walk in without anybody vouching for them is the event that should already have had one.

Writing it early has a second benefit that has nothing to do with incidents. A code of conduct written during calm is a statement of what the group is for. Written during a crisis, it is inevitably read as a document about one specific person, which makes it both harder to write and less likely to be accepted.

Three questions before your next event

  • If something happened tonight, does the person it happened to know who to tell? If the answer requires them to guess, you do not have a reporting mechanism.
  • What if the report is about an organiser? More than a quarter of documents in the study had no contact at all; most of the rest have exactly one, which is the same problem in a better disguise.
  • Is the document reachable in the room, not just on a website? An exit sign in a filing cabinet is not an exit sign.

What to take from this

A code of conduct is infrastructure, and it is judged the way infrastructure is judged: not by how often it is used, but by whether it works the one time it is.

The empirical picture says most of these documents are written once and never revisited, that more than a quarter provide no way to report anything, and that communities which adopt one tend to gain newcomers rather than lose them. All three of those point at the same practical conclusion.

Borrow the behavioural language, spend your real effort on the reporting route, and answer the question about what happens when the report concerns an organiser. Then publish it, and accept that almost nobody will read it - which is exactly what a working exit sign looks like.

Frequently asked questions

Does a small meetup group really need a code of conduct?

The useful threshold is not headcount but composition: the first event where a stranger can attend without anyone vouching for them is the event that should already have had one.

What should a code of conduct actually contain?

Behavioural expectations, which can be adapted from established texts, and a reporting mechanism, which cannot. In one large study only 72.1 percent of documents included any email contact for reports at all.

Will adopting a code of conduct make my group feel bureaucratic?

The evidence points the other way. A study of 158,735 repositories found code-of-conduct adoption positively correlated with new contributors joining across one, three, six and twelve month timeframes.

Should I write my own or link to an existing one?

A practical middle path is to adapt established behavioural language but host it yourself, replacing the contact and process sections with specifics about your group. In the study, 58 percent hosted directly and 42 percent linked externally.

How often should a code of conduct be updated?

In practice, almost never - over 75 percent of sampled projects had only one code-of-conduct commit in their entire history. That is an argument for getting the durable parts right on the first attempt.

What happens if the complaint is about an organiser?

This is the question most templates fail to answer and the one that determines whether the document functions. A group with a single organiser needs a second reporting route, even an informal named one.

Does anyone actually read these documents?

Generally not, and that is fine. The function is to exist unambiguously at the moment someone needs to know what this group considers acceptable and who to tell - not to be read on an ordinary evening.

Should incidents be recorded after they are handled?

Yes. Without a record, a group will handle the same person's second incident as though it were their first, which is one of the more common ways repeated behaviour goes unaddressed.

Ontaym Editorial Team

Ontaym builds tools for organising real-world gatherings, so the team spends its days on the coordination problems this article describes. Articles are researched against primary sources, reviewed before publication, and revised when the underlying facts change rather than on a schedule.

Give your group one place where the rules and the plan both live.