Roles and permissions

How roles, rank and channel overrides decide what each member of a TACENZA Chat group can do, and what the server enforces.

Groups in TACENZA Chat use roles to decide who can do what. The owner and admins can do everything; everyone else gets what @everyone allows, plus what their roles add, adjusted per channel. Every member’s app and the server work this out with the same rules. This page explains those rules.

Owner, admins and members

  • Owner – can do everything, including deleting the group and transferring ownership. There’s one owner.
  • Admins – can do everything except what only the owner can. Only the owner makes or removes admins (Make admin / Remove admin in the member list) and removes admins from the group.
  • Members – start from what @everyone can do, and gain more from roles.

Roles

Manage roles in Manage group › Roles.

  1. Choose New role, or start from the Moderator or Helper template.
  2. Give it a Name and, optionally, a Colour.
  3. Tick the permissions it gives.
  4. Choose Save.

Use Rank higher and Rank lower to order roles. Turn on Members can pick it themselves for interest or pronoun roles offered during onboarding, and give such roles no permissions.

Role names and colours are encrypted with the group’s info. The server stores only role ids, rank, permission bits and who holds them, so it can enforce them.

Permissions

Permission What it allows
View See the channel and its messages
Send messages Write messages, voice messages and replies
Send photos and files Photos, files, voice messages, locations
React Reactions and answers to events
Start threads Replies in threads
Pin messages Keep messages at the top of a chat
Delete others’ messages Also skips slow mode
Add members Add people directly
Manage invite links Create and revoke links, approve join requests
Remove, time out and ban Only members ranked lower
Manage channels Create, edit, order and delete channels
Manage roles Only roles below your own, with permissions you have
Change group settings Disappearing messages, protection, slow mode, onboarding, appearance
Edit name, photo and description The group’s name, photo and description

How permissions are worked out

For each member, in this order:

  1. The owner has every permission.
  2. An admin has every permission.
  3. Everyone else starts from @everyone, combined with all their roles.
  4. Channel overrides apply: first for @everyone, then for the member’s roles together, then for the member. At each step, denies apply before allows.
  5. A timeout, or unfinished onboarding, removes sending, media, reactions, threads and pins.

Without View, nothing else applies in that channel.

Rank

The owner ranks above admins, who rank above everyone else. Other members rank by their highest role.

  • You can only act on members ranked strictly lower than you.
  • You can only give or edit roles below your own, and only with permissions you hold yourself.

If you try otherwise, the app says “You can only do that to members below your highest role.”

Channel overrides

When you edit a channel, Who can do what lets you change permissions in that channel only:

  • Allow (✓) or Deny (✕) a permission for @everyone, a role or a member.
  • As in the group keeps what the role has in the group.
  • A member’s own setting wins over their roles.

To make a channel only some people can see, deny View to @everyone and allow it for a role. For keys of its own, make it a Private channel – see Groups.

What the server enforces

The server enforces everything it can see: sending, media, reactions, pins, channel access and delivery, invites, roles, overrides and moderation. Who may edit a message is inside the encrypted content, so every member’s app checks that with the same rules. A modified app could skip a check the server can’t see, but it can’t get past what the server enforces.