Features
What it does.
The list, in plain words. Every line was checked against the code before it went up; where something's only half there, it says so. Nothing on this page is a plan; plans are on the roadmap.
It keeps to what you'd notice; the small switches and sliders didn't make the list. The app's own names for the comms bits are mapped on the Command nets page, and what operators get is on Running it.
Chat
Text channels · messages · files
24 entries
- Channels and categories
- Text channels under collapsible categories, each with a topic. Make one from its category's + button, edit or delete from a right-click, and drag a channel to reorder it — everyone's sidebar follows as you drop it. Categories don't nest.
- Markdown
- Bold, italic, strikethrough, code, quotes, lists, headings, links. 2,000 characters a message. No syntax highlighting in code blocks yet, and no spoiler text.
- Replies, edits, deletes
- Reply and readers see what you were answering. Fix your own message in place with an (edited) marker. Delete your own, or anyone's if you hold Manage Messages.
- Scrollback
- Scroll up and older messages load in behind you with your place kept. Sit at the bottom and new ones push into view, images included; scroll up and nothing jumps under you. A line marks each new day, and a run from one person sits under a single name and time.
- Reactions and pins
- Standard or server emoji, up to 20 a message, with eight common ones on the message itself and the full picker behind them. Hover a reaction to see who reacted, up to the first fifty. A moderator can take someone else's reaction off. Fifty pins a channel, and a pin jumps you to the message's place in history.
- Hold the yard until relieved — nobody wanders
- Move on the word, not before
b is the fallback.- Files and images partial
- Picker, drag-and-drop or paste, with a progress bar on each file and a cancel while it's still going up; on Linux, paste needs a Wayland session and an X11 one hasn't got it yet. 50 MiB a file, ten a message, both adjustable by whoever runs the server. Images tile into a gallery and open in a lightbox, video and audio play in place, and anything else arrives as a card with its kind, name and size.
- Files aren't public
- Nothing is served straight out of the file store. Every read comes back through the server, checked against the same rights as reading the channel it was posted in. The links the app uses are signed and lapse after an hour; until then anyone holding one can use it, so treat a link like the file.
- Spoilers, alt text, rename
- Blur an image behind a spoiler, add alt text, or change a file's name before you send it.
- Voice messages
- Tap to record, tap to stop, listen back, send. Five minutes tops.
- The player
- Video and audio start on the first press and jump when you drag the bar, without waiting for the whole file. Audio draws a waveform you can click through, with the time run against the total, voice messages included. Start one clip and anything else playing stops.
- GIFs and custom emoji
- A GIF picker that goes through your server, so nobody's client talks to the GIF people; it only appears once whoever runs the server has put in a key for it. Upload your own emoji, still or animated, a hundred of each per server, 128 px and 256 KiB, or 512 KiB if it moves. A message that's nothing but emoji comes out large.
- The emoji picker
- Category tabs, a search that reads names and tags, a skin tone you set once, and the ones you used lately kept to hand. Your server's own emoji get their own tab, and typing a colon and a few letters offers them inline. The whole set ships inside the app, so picking one doesn't call anybody.
- Link previews
- Paste a link and a card grows a moment later. Up to three a message. Thumbnails are re-hosted so clients never touch third-party hosts. Can be switched off for the whole instance.
- Typing, presence, status
- Who's typing. Online, Idle, Do Not Disturb or Invisible, plus a custom status with an expiry. Leave the keyboard a couple of minutes and it goes Idle on its own, then back the moment you move; Do Not Disturb and Invisible stay where you put them.
- Mentions
- Type @ and a few letters and the composer offers names. A mention lands as a pill, tints the whole message's row, and puts a red count on the channel and on the server's tile. It rings even in a channel you've muted. The tone is the same one every message gets.
- What you haven't read
- Channels with something new go bold with a dot, the server's tile gets a mark, and the feed drops a New line where you left off. Your own messages never count, whichever device you sent them from, and the line stays where it was when you opened the channel rather than chasing you down the page.
- Mute a channel, or a server
- Right-click a channel or open the server's menu. A muted row greys out, never goes bold and never makes a sound. The messages still arrive; muted is quiet, not gone. Someone saying your name still gets through, and a separate switch stops @everyone counting as your name.
- Search partial
- A search box in the channel header that reads the whole server, or one channel, or one person's messages, and only ever the channels you could open yourself. It runs when you press Enter, pages back as far as history goes, and can't see direct messages yet. One server at a time.
- Jump to a message
- Open a search result or a pin and the view lands on that message with what came around it, lit for a moment, and a bar back to the present. Nothing gets marked read while you're back there.
- Direct messages partial
- Message a person straight from their card, outside any channel. The conversations live behind the home tile with their own unread counts. Two people only for now. No group conversation, no voice call in one, and search doesn't reach them.
- Notification sound
- A short tone for a message in a channel you're not reading, on or off. Never for your own message, the channel in front of you, someone you've blocked or anything you've muted. Nothing pops up outside the window, and nothing reads messages aloud.
- Slow mode
- Limit how often people can post in a channel. Mods are exempt.
- Blocked users partial
- Their messages collapse to a stub, though only on your screen; the server still delivers them. Voice is the half that's enforced properly.
- Threads and bulk delete no button yet
- Both exist in the server. The app has no button for either, so no threads and no multi-select delete yet; the nearest thing is a ban taking a member's recent messages with it.
Voice
The call itself · our own voice server underneath
17 entries
- Voice channels
- Click to join. One seat per account, so joining from a second device replaces the first, and the first is told why. A room can be capped at up to 99 seats, with the count on the row; full is full, unless you hold the right to move people.
- Audio without a room
- You don't have to pick a voice channel, or even have one. The comms list has its own connect and the server works out where the audio goes, so a group that only ever uses nets never has to make a room.
- Who's in the room
- Everyone in a voice channel sits under it in the sidebar with a count, and as a tile in the call. A ring lights round whoever's talking, and someone you've blocked never gets one, because you never get their audio. A tone when somebody joins and another when they leave, which you can switch off.
- Rights the server decides
- Who may speak and who may hear comes from the same permissions as chat. A timeout, a lockdown or a server mute cuts audio on the next frame. No rejoin.
- Push-to-talk
- A global hotkey (backtick by default) that works while a game has focus. Rebind it, and the net keys beside it, from settings on each device. A key-only switch closes the mic to everything but the key, so voice activity can't open it underneath you.
- Voice activity with a live meter
- A sensitivity slider and a level bar that goes green past the trigger, so you set it by talking.
- Mute, deafen, per-person volume
- Deafen also mutes you, and everyone sees the badge. Right-click anyone and set them from 0 to 200%; remembered on this device.
- Devices
- Separate mic and speaker gain with a test tone. Swap devices mid-call. Unplug something and it falls back to the OS default and tells you.
- One mixer, one output
- Voice, the nets and a shared screen's audio all mix in one place and come out of one device. One set of volume controls covers the lot, and only one thing ever holds your headset.
- Noise suppression
- On by default, toggle without rejoining. If the model can't load, voice carries on without it and says so.
- The fade
- When a higher-ranked net lights up, the rest fade down rather than being gated shut.
- Bad links
- The buffer adapts on its own, missing frames get smoothed over instead of clicking, and the bitrate steps down when your uplink strains and back up when it calms. Or set any of it by hand.
- Why it sounds bad
- Whoever runs the instance gets a Debug tab: the live numbers off a call, a plain verdict line under them, and a warning row when the fault is your devices rather than the network. One button copies the lot, scrubbed of anything identifying, to paste to whoever's helping.
Copies everything above, scrubbed of anything identifying — paste it to whoever's helping.
- Reconnects on its own
- A server restart or a network blip gets a toast and three attempts with a fresh token. Gives up if voice has flapped three times in a minute.
- One encrypted connection
- Control and audio on one port. Nothing else to open on a firewall. The voice server mints its own certificate; you see its fingerprint on first connect and a red dialog if it ever changes.
The server minted its own certificate — nothing to buy, nothing else to open on a firewall. Check this fingerprint with whoever runs it; you only see this once.
- Not end to end
- Audio isn't encrypted end to end. The link is encrypted and the voice server never opens what it carries — no mixing, no transcript, the fades all happen on your own machine — but it holds the keys, so it could. On your own box that's you.
- Server mute, deafen, move
- On a person's volume card, for moderators holding the matching right. A moved person changes rooms and the audio follows on its own.
Push-to-talk holds ` and works while a game has the focus.
Set it by talking — the bar goes green past the marker, and that's where the mic opens.
Command nets
Ranked radio channels · keys, fades, a live editor
15 entries
Command.- Nets
- Named radio channels with a rank, separate from voice channels. Each has a colour, a rank from 0 to 9, a fade depth, a suggested key and a fixed place in the list.
- Every voice channel is a net partial
- A voice room gets a row like any net, so you can listen in on it from outside. The editor can't change a room's colour, rank or key yet.
- The comms list
- Every net you can reach, in a fixed order.
LIVEon the one you're talking on,MONon the ones you're listening in on. - Talk on one, listen to 24
- Click a net and your key goes there, one at a time, remembered per server. Listen to up to 24 at once; each one is either in your ears or muted. When more want you than fit, the lowest rank loses and the list says which, in amber.
- Mute a net, or drop it
- Mute keeps its place; drop frees it for a net that was waiting. Both remembered per server.
- Higher ranks fade the rest
- While someone senior talks, the lower nets turn down by the amount set on the net, so a command call reads by ear.
- Report-up, all-call, emergency
- Three keys past your own net. Emergency turns the room down, not off, lasts only while it's held, and every one goes in the audit log with who, where and how long.
- The cut-in banner
- Audio you didn't ask for puts
↑ REPORT — name,◎ ALL-CALL — nameor! EMERGENCY — nameat the top of the list for a moment.
- A structure that can't loop
- Nets report up to other nets. A link that would close a loop is refused before it exists.
- Connect two nets partial
- Join two nets for a while, with an optional expiry and a countdown. One hop only. Not routed yet when one end is a voice channel.
- One-click setups
- Small team, squad and lead, or multi-level: nets, links, keys and colours in one go, with a preview first.
- Who may hear, who may speak
- Per role, per net. A net can only take away from what the channel already allows, and the grid marks a clamped cell amber with a link to the role that's blocking it.
- The editor and the board
- A panel beside the list for changing the whole structure while it's live, and a board showing every net, everyone on it, and any emergency in progress.
- Changes land without reconnecting
- Rename a net, pull a right, time someone out. The list refreshes and running calls re-route live.
- Nothing shown to the unadmitted
- Someone still in screening gets no nets, no rosters, no board.
Moderation and permissions
Roles · overrides · the tools for a bad night
18 entries
- Roles
- Colour, hoist, position. Members group under their highest hoisted role. A small badge per role shows beside names in net rosters. Hand a role out or take it back from the Members tab, and the change lands on everyone's screen as it's made. Groupings, badges and what a member may do flip without a reconnect.
- Hierarchy that holds
- A moderator can't touch anyone at or above their own top role, and can't hand out a permission they don't hold.
- One rulebook everywhere
- One permission set drives chat, voice, apps and comms, resolved by one piece of code, so they can't disagree.
- Overrides and the inspector
- Allow or deny specific bits per channel or category, for a role or one person, over the floor every member starts on. Thirty-eight separate rights in all. Then pick a member and the inspector shows what they end up with and where each bit came from.
- Live feeds stop when the right does
- Take a channel away from someone and messages stop reaching them that second, rather than at their next reconnect. Even who's typing is checked against the same view right before it leaves the server.
- Invites
- Expiry from 30 minutes to never, 1 to unlimited uses, tied to a channel, revocable. The list shows how many times each one has been used, against its cap. A preview shows the server and its requirements before anyone joins.
- Verification and screening
- Require an email your identity provider has already marked verified — we don't send that email ourselves — or an account a day or a week old. New members read and accept your rules before they can post or speak; until then they see nothing of your comms. Whoever's on the door works a Pending list in the Members tab.
- Lockdown switches
- Pause invites, freeze joins, freeze sends, each on its own switch. Every flip is audited.
- Raid detection
- Off until you turn it on. Then a join spike freezes joins on its own and files an alert, and you can kick or ban everyone who joined in the last N seconds in one action, with up to a week of their messages.
- AutoMod
- Keyword lists with wildcards, spam by rate or repeats, link filters with an allowlist, invite filters, and your own match patterns (regular expressions, up to ten a rule, always case-insensitive). Each rule blocks, alerts, or times someone out for up to 28 days. Twenty-five rules a server.
- Reports
- Members report a message, a person, or the whole server. A server report goes to whoever runs the instance, not the moderators it's about. Mods work an open, resolved, dismissed queue, and AutoMod and raid alerts land in the same one.
- Personal blocks partial
- One block covers every server you're in. In voice it cuts both ways, so neither of you hears the other, and it's the last check on every frame, after rank — no priority key gets past it. A block you make on one machine doesn't reach another you're signed in on until the app restarts there.
- Blocks follow you in
- Block someone and it reaches past chat and voice. Their comments on a board's cards hide, their cursor leaves your whiteboard, and their screen share never fills your view unless you click it yourself.
- The audit log only ever grows
- Every moderation action, lockdown flip and emergency call lands as a line, and nothing in the product can edit or remove one. The only way a line leaves is whoever runs the instance pruning old ones, and that shows what it would remove before it removes it.
- Sign-in partial
- A form inside the app that drives your own identity provider, one-time codes and backup codes included, no browser window. Someone without an account can start one from the same screen, and your provider decides whether that's allowed. An account that can only answer with a security key or a passkey can't get in yet.
- Where your password goes
- Your password goes from the sign-in form to your identity provider and nowhere else. The server never sees it; it only ever receives the short-lived code that comes back, and trades that for your session.
- Kick, ban, timeouts, nicknames, prune
- All of it from the Members tab, which searches the whole membership, with the same quick actions on a person's card. A timeout counts down live on the row. A ban can take up to a week of that member's messages with it, and the Bans tab searches by name and puts people back. Prune shows who would go before anyone does. Anyone can set their own nickname from the server menu.
- The audit log, in the app
- A tab in server settings for anyone allowed to read it: who did what, to whom, why, and what changed, filtered by action or by person. It reads fresh when you open it rather than following along live. The operator app still reads it across every server.
Apps
Boards and a whiteboard, inside the server
13 entries
- Boards and a whiteboard
- Two apps ship in the binary. Install per server; each board or whiteboard sits beside your channels with its own link.
- Make your own source
- Boards and the whiteboard are plugins behind one seam, and yours goes through the same door.
- Install, turn off, remove
- Installing an app on a server, switching one off and taking it out again all sit behind Manage Apps. A switched-off app leaves its boards in the sidebar, greyed and unopenable, until it's switched back on. Take the app out and its boards go with it.
- Rename, archive, put it back
- A server can carry as many boards and whiteboards as it needs, and one can be renamed or moved to another category at any point. Archive one when the op's over and it drops out of the sidebar until you restore it. Delete one and it can still be brought back for thirty days, adjustable by whoever runs the server.
- Webhooks
- Give a text channel a webhook and anything that can reach its address can post there — a build server, a script, a scoreboard. Each one posts under its own name, managed from an Integrations tab behind its own permission. Text only, 2,000 characters a post, thirty posts a minute, it can never ping @everyone, and AutoMod reads its messages like anyone else's.
- Kanban boards
- Backlog, In Progress, Done out of the box. Cards carry title, description, due date, tags, assignee and a comment thread. Drag between columns.
- Everyone sees the same board
- Add a card, drag one, rename a column. Each lands for everyone who has the board open, without a refresh. Lose the right to a board and its live feed cuts with it, there and then.
- Whiteboard
- Shapes, arrows, freehand, text, images, everyone drawing at once, with named live cursors. The fonts and icons ship inside the app, so nothing loads off the internet.
- Two people, one shape
- Two people changing the same shape at the same moment don't overwrite each other. The server takes one change at a time and keeps the newer version of each shape, so both screens end up the same.
- Images stay on your server
- An image dropped on a whiteboard is stored by your own server and handed back through it, checked the same way as opening the board. There's no link to hand round at all, and each board's files sit under its own name, so one can't reach into another's.
- Moderation reaches in
- Timed out, still in screening, or under lockdown: you can read a board, you can't change it.
- Who can edit, out of the box partial
- A new board or whiteboard is readable by everyone who can see it and editable by your moderators. Opening it to the rest of the members means setting the per-board rights, and there is no screen for that yet.
- Per-board permissions, columns, attachments no button yet
- View, edit and manage per board, extra columns, file attachments and an activity log all exist in the server. No editor for them in the app yet.
- Who has it open, who changed it no button yet
- The server keeps a live list of who's viewing each board, counted once a person however many windows they have, and a record of who installed, renamed, archived or removed one. Nothing in the app shows either yet.
The desktop app
Linux and Windows
12 entries
Signing the other sessions out signs this one out with them.
- Linux and Windows
- One app, both platforms. Voice and the share run in the app's own code rather than the system's web browser, so they behave the same on both. macOS hasn't been built.
- Any server by address
- Nothing baked in. Type the address at login; everything else comes from the server.
- Make one, or join one
- Create a server from the app and it arrives with a role covering everyone, a General category and a general channel already in it. It's one action on the server, so a half-made server can't exist. The same window takes an invite code, and one instance holds as many servers as you make.
- Server name, icon and description
- Set from server settings. The icon becomes the server's tile in the list, initials if you don't upload one. No server banner.
- Delete a server
- Owners only, from the bottom of server settings. You type the server's name to confirm, so a slip can't do it. Everything in it goes with it.
No image yet, so the tile shows initials. No server banner.
Owners only. Type 453rd Expeditionary to confirm — everything in it goes with it.
The name doesn't match yet, so the button stays dead.
- Themes, density, scale
- Three dark themes. Cozy, Compact or Spacious. Chat text from 12 to 24 px, the whole window from 50 to 200%. No light theme yet.
- Settings follow you
- Theme, sizes, sounds and voice preferences live on the server and come with you. Keybinds and the server address stay per device.
- Member list
- Grouped by role with counts, presence dots, custom statuses.
- Account and sessions partial
- Display name, avatar, About Me, and every signed-in session with device and last active. Revoke one on its own; revoking the rest signs this device out with them, and no row is marked as the one you're sitting at. A new avatar reaches other people the next time their app loads it, not the moment you set it.
- Staying signed in
- On by default, with a box to turn it off on a machine that isn't yours; turning it off clears what's already stored. Your sign-in goes into the credential store the operating system already has, never a file beside the app, and where there's none to reach it stays in memory and you sign in again next launch. It renews itself in the background, so a long night doesn't end at a login screen.
- Two overlays
- F3 puts frame rate and the state of your voice link over the window: round trip, buffer, dropouts, clock drift. F9 does the same for the shares you're watching, a line each with who it's from, the size and the frame rate. Both are fixed keys; there's no screen to rebind them.
- Leave a server
- From the server's menu, with a confirm. If you're in voice there it hangs up first. The owner can't leave — deleting the server is theirs instead.
That's all the app knows. Everything else comes from the server.
Turn it off on a machine that isn't yours.
One app holds as many servers as you make.
The other half
What's missing has its own page.
Everything above is built. What's wanted and not built is on the roadmap, straight off the work board. The ranked-voice system most of this exists to serve has its own page.