Skip to content
Haven
← Notes from building HavenPRODUCT

Why messaging is deliberately narrow

A teacher can message a student only if that student enrolled with them. That is the whole rule, and nearly everything uncomfortable about Haven Chat follows from keeping it.

K
Keshav · · 3 min read

The whole rule

A teacher can message a student only if that teacher is verified and that student is enrolled in one of their courses. There is nothing else.

Students cannot message each other. Teachers cannot message students who have not enrolled with them. Nobody can message a stranger. There is no user search, no way to look someone up and open a conversation, and no inbox that a person you have never met can appear in.

This is enforced by the database rather than by hiding a button. A request constructed by hand to reach a conversation it should not reach is refused by Postgres, not by the interface declining to render a link.

Why not more

Every messaging feature we have not built was rejected for the same reason: it would create a path between two people that no relationship on Haven justifies.

Student-to-student messaging is the clearest case. It is the feature learners ask for, it is obviously useful, and on a platform where minors are on both sides of every conversation it is a channel between two children with no adult accountable for either end. We would rather not have it than have it and moderate it badly.

Open teacher discovery through messaging is the same shape from the other direction. A teacher who can start a conversation with any student is a teacher who can start a conversation with a child who has never chosen them.

The group rooms Haven does have are bound to relationships that already exist — one room per course for the teacher and the students holding a place on it, and one room per subject for the people teaching or studying a published course in it. The subjects are rows in the catalogue rather than a list written into a migration, so the rooms follow what Haven actually teaches instead of what somebody once typed.

The part people find uncomfortable

Haven scans every message. Phone numbers, including numbers spelled out in words. Email addresses, including obfuscated ones. Links to external sites. The names of off-platform messaging and payment services. Matches are flagged for a moderator.

The reason is that most harm on learning platforms does not happen on the platform. It happens after a conversation moves somewhere nobody is watching, and the move itself is the observable moment.

The scanner errs towards flagging. A false positive costs a moderator a few seconds; a false negative is a conversation leaving. That balance is a choice and we would defend it, but it does mean a teacher sharing a legitimate resource link will sometimes be flagged, and that is not a bug in the scanner.

We do not hide any of this. It is on our Trust & Safety page and in the Privacy Policy. What we have not built yet is a standing notice on the chat screen itself — a flagged message is labelled, but the scanning is not announced before you start typing. That is a real gap and it is listed as one.

What narrow costs

It makes Haven worse at some things on purpose. A student who wants to ask a question of a teacher they have not enrolled with cannot. A teacher who wants to build an audience cannot use messaging to do it. People who would use a study-group feature do not have one.

It also means the rule has to hold everywhere, not just in the obvious place. Reporting is the example that took the most care: a report has to be possible for a live class or a course page with no conversation behind it, and the check for that case still has to confirm the reporter has a real relationship to the course and that the person being reported has one too. A reporting flow that accepted any pair of identifiers would be a way to learn that two people exist.

The rule survives because it is small enough to state in one sentence and enforce in one place. Every feature that would make it a paragraph is a feature we have not built.

More from Haven

How the product works, and the safety decisions behind it.

Haven uses Google Analytics to understand which courses people find and where they get stuck. It sets a cookie and never receives your name, email or payment details. Declining keeps everything on the site working. Privacy Policy