Amovera

← The Chatroom

APP-04 · S.T.A.M.P. · Governance

How the Chatroom Governs Itself


There is no quiet centre here that decides who may speak. Nobody can remove a post by themselves — not a moderator, not the Foundation, not whoever runs the server. Removal happens when enough qualifying people flag the same post, and every removal is written to a log anyone can read. This page is how all of that actually works.

Four properties are built into the database, not into a policy. A policy is a promise; these are constraints that hold against everyone, including the people who operate the site.

  • The record is whole. No post is ever deleted, and the moderation log can never be edited.
  • The quorum is honest. Nobody can pad a count by flagging twice or with a throwaway account.
  • Identity is sound. A flag or a post can only ever be recorded as its actual author.
  • Region stays private. There is no way to enumerate people by where they are, and that absence is deliberate.

1 · Reading and posting

  • Reading is open to anyone, signed in or not — the room, the standings and the moderation log alike.
  • An account is needed to post or flag, and a handle before posting. Your handle is the only thing others see.
  • Four channels: organising, building, media, general.
  • A post may carry an optional coarse region — a province or an area, never an address. It is typed by the author and used for nothing but the filter.

2 · Flagging

  • Any signed-in account may flag a post as spam, abuse, or off-topic.
  • Raw flags are unreadable to everyone. Not to other members, not to the author of the post, not through any page or endpoint on this site. The only thing anyone can see is the aggregate, and only once it results in a removal. This is an explicit rule in the database rather than a feature nobody built.
  • A flag cannot be withdrawn, and flagging the same post twice does nothing: duplicates collapse, so a count cannot be padded by repeat-flagging.

3 · Who counts toward a removal

Only qualifying accounts count. An account qualifies when it is

  • at least seven days old, and
  • has made at least one contribution — a post of its own.

Anyone may flag; the flags of accounts below that floor simply do not count toward removing anything. It is the same floor used for carrying a stalled technic in the manual, so one bar governs both.

4 · Removal by quorum

A post is removed when the number of distinct qualifying accounts that have flagged it reaches the threshold. The threshold moves with the size of the room:

about 10% of the people who have posted in the last 30 days
— never fewer than 3, and never more than 8.

A small room needs at least three qualifying flaggers; a large one needs roughly a tenth of its recent participants, but never more than eight. The count and the threshold are both recorded on the log entry, so a removal can always be checked afterwards.

The flag that crosses the threshold removes the post and writes its log entry in the same instant — one transaction, so a removal can never happen without its record, and a record can never describe a removal that did not.

5 · No post is ever deleted

Removal marks a post removed and hides it from the room. The row and its history survive. This holds against every writer, including the service role that operates the site — it is enforced by a database trigger rather than by permissions, so there is no account anywhere that can hard-delete a post.

The one exception is the author erasing their own account, which is described at the end of this page. That is the person deleting their own words, not the room deleting them.

6 · The open moderation log

Every moderation action lands in a public log: automatic removals with their flag count, and every grant or recall of standing with its stated reason.

  • It is append-only and immutable. Updates and deletes are blocked for everyone, the service role included. Corrections are new entries, never edits.
  • An entry with no actor named is one no single human took — that is what a quorum removal looks like on the record.
  • Vetoes cast on technic submissions are logged here too, with their stated grounds. The log covers both apps.

Read the live log →

7 · Standing

Standing is the one power in the system, and it is deliberately hard to hold.

  • It is peer-granted through the OPS-007 process. It is never self-assigned, and there is no button anywhere on this site that grants it — ordinary accounts cannot invoke the function at all, and even reaching it would fail.
  • It runs a six-month term and then expires.
  • It is recallable by the same process, and both the grant and the recall are logged in the open with a reason.
  • An expired term is not standing, even if nobody has got round to marking it inactive.

What standing does not do. It confers no power to remove a post. Removal is by quorum only, and a standing holder's flag counts exactly as much as anyone else's. What standing carries is the vote on admitting technics to the manual, and the right to grade them — described on the manual's governance page.

Being old enough to grade is not the same as holding standing, and the site keeps the two apart on purpose: an account's own record and a person's standing are separate things, stored separately, so one can never quietly become the other.

8 · Region, and a deliberate absence

The coarse region on a post is set by its author and by nobody else. It is never inferred from your address, your device, your headers, or what you wrote. Leaving it blank is the normal case.

There is no way to list people by region, and there never will be one. No page, no endpoint, no view. The regional filter reads what a post says about itself; it cannot enumerate, map, or count people. The absence is the feature — a room that can tell you who is nearby can tell anyone else too.

9 · Leaving

An account can be deleted at any time, from the account page, and it happens immediately. There is no waiting period, nobody is notified, and no reason is asked for or recorded.

  • Deleted outright: everything you posted, every flag you made, your handle, your profile, and the account itself. Your posts are removed, not hidden. Your email address is freed, so you can register again later.
  • Left behind, with your name taken off: any grade you signed on someone else's technic, any vote you cast, any seat you held on an electorate, and any moderation action you took. These stay as anonymous records so other people's entries do not silently lose a data point. They carry nothing that identifies you.
  • A technic of yours already admitted to the manual stays, with your name removed. It is published under an irrevocable licence, so deleting the row would unpublish nothing — it would only make the manual lie about what it holds. A submission still in progress, or one that was refused, is deleted with everything else.

Erasure can anonymise the moderation log but can never remove a row from it, and that limit is enforced in the database rather than promised. The action stays on the record; the person stops being named. Otherwise anyone could erase the record of a removal by erasing themselves.

A body may be thick, but it may not trap. Until the erasure path existed, an account that had posted could not be deleted at all — that was a fault, and it was fixed rather than explained.


Open the chatroom → · How the manual governs itself →

Provisional · Revisable