# Community privacy and hashtag acceptance

24 September 2026. Local application verification completes the open checks in the community course alongside the [21 September public workflow rehearsal](community-workflow.md). No production deployment is required.

## Real policy checks

Created a separate private training page as the authenticated organization owner. Noah was an outsider and then a pending member; Pia was an outsider and then an invited active member. The owner was the page administrator.

| Action | Observed result |
| --- | --- |
| Anonymous/private page read | 404 |
| Signed-in outsider/private page read | 404 |
| Join Approval Required | Membership saved pending |
| Pending member reads page | 404 |
| Administrator invites separate member | Active membership; member page read200 |
| Active ordinary member posts under Admins Only | 403 |
| Administrator changes to Members + Pre-Approve | Policy persisted |
| Member posts | Saved pending; author can read it |
| Other member-facing reads of pending post | Administrator's member endpoint404; anonymous404; staff moderation remains a separate surface |
| Administrator posts | Active |
| Anonymous directory/member list | Private page omitted; member list404 |
| Active member directory | Private page included |

The first harness used type `community`, which is not a Studio page-type choice. This was corrected through Studio to **Group**, saved and reopened. The policy readback and anonymous/pending/member checks were repeated afterwards. No privacy result is inferred from the type selector alone.

[Initial API observations](assets/community-policy-local/01-policy-rehearsal.json) · [After Studio save](assets/community-policy-local/05-after-studio-save.json) · [Actual settings](assets/community-policy-local/03-settings-reopened.png).

Nine existing policy regression tests pass. The policy enforcement code was already present in the current source/runtime; this continuation verifies it rather than claiming to have authored those earlier fixes.

## Hashtag repair

Creating a post reproduced the generated hashtag record name in Studio. `community-post.service.ts` now stores the normalized tag in `data.name` and searches both canonical and legacy name fields before incrementing an existing record. Existing correctly named legacy entries gain the canonical field when reused. Unidentifiable old generated names are not guessed or rewritten.

Two new real posts with `#PolicyTrainingFixed` and `#policytrainingfixed` created one hashtag, `policytrainingfixed`, usage count2. Studio search returned that tag and the count. [API readback](assets/community-policy-local/02-hashtag-live.json) · [Studio screenshot](assets/community-policy-local/04-hashtag-fixed.png) · [Regression check](assets/community-policy-local/hashtag-tests.txt) · [Policy tests](assets/community-policy-local/policy-tests.txt).

## Course boundary

The actual course exercises public community setup, member API conversation/reactions/relationships, moderation removal and announcement draft save/reopen. The earlier rehearsal covers those. These policy/hashtag checks resolve its remaining defects.

Record Warning and Record Ban Decision intentionally record a moderation decision; the course already says they do not deliver a warning or suspend an account. That accurately labelled limitation is not an unfinished implementation promised by this course. Part5's Stories/Groups/Badges/Notifications table explicitly introduces possible next features without asking the learner to execute or verify them. Native member UI, timed story expiry, badge awarding, publication/push delivery and automatic event membership remain outside this course's demonstrated outcome. Completion does not claim those were tested.
