Profiles disclose only what the user enables
Profiles begin private. Exact-username access and direct-message requests do not expose optional email, company, biography, location, or website fields unless the user enables them.
Employees may find coworkers in their own company
Active internal employees may browse other active C!HATTED!-enabled employees in the exact same organization and start a direct chat. External accounts never receive the employee directory, and employees cannot browse another company.
Not shown: invited external contacts and every other company.
Membership controls visibility
Employees and external participants see only conversations they joined. An external participant appearing in three chats does not permit an employee to discover the other two. Company senior oversight covers internal-only company conversations; a chat containing an external or cross-company participant is visible to a company administrator only when that administrator is a participant. God Administration retains platform-wide oversight.
Live state is permission-scoped
A green dot means a recent authenticated C!HATTED! heartbeat; red means no current heartbeat. Typing state expires automatically and is available only in an authorized conversation or the same-company employee directory.
Classifications identify authority; they do not endorse speech
God Admin may assign platform classifications. A company may assign its own verification and flair to accounts within its authorized scope. Company authority never exposes unrelated conversations or another company's classifications.
Invitation links expire and bind the originating company
Links may expire, may be revoked, and become invalid after successful use. The accepted invitation records the originating company for company-specific identity controls without turning the invited account into an employee.
Senders may delete from chat; forensic records remain permanent
A sender may delete only their own message from participant-facing chat at any time. The original message, deletion actor, deletion timestamp, attachments, and links remain in an immutable forensic record available to authorized administrators.
Supported attachments remain inside conversation permissions
Images, video, audio, PDFs, and supported documents must comply with the Terms, Acceptable Use Policy, applicable law, and organization rules. Supported images are rendered inside generated chat PDF reports.
Visible only to authorized conversation participants and included in the conversation PDF.
Every chat URL opens in a protected new tab
Internal dashboard links and external URLs use new-tab browser isolation. Public destination metadata may create a preview card; private, local, reserved, credential-bearing, oversized, or unsafe destinations are not fetched.
A practical infrastructure guide represented from public page metadata.
joseph.anthony.campGroups are mandatory; direct chats are user-controlled
Group-chat read receipts cannot be disabled. In a one-on-one chat, each participant may disable publication of only their own receipts. Disabling removes that participant's previously published direct receipts and does not reconstruct reads from the disabled period.
PDF records preserve text, links, receipts, attachments, and images
Conversation reports convert browser markup into ReportLab-safe content. Supported image attachments are scaled and embedded beneath the related message. Attachment names, link previews, receipt summaries, message timestamps, participants, and optional senior diagnostics remain part of the report.
Administrative actions are server-authorized and immutable
God Admin and Company Admin actions are checked on the server and recorded in an immutable C!HATTED! administration audit record. Company administrators cannot modify another company's employees or external contacts.
| Actor | Action | Boundary |
|---|---|---|
| God Admin | Assign platform verification | Platform-wide |
| Company Admin | Assign company flair | Own company / own invited contact |