What arrives

The post, word for word, and who it came from

She repeats a broadcast post into a group and labels it. She does not summarise it, and no model sees it.

What the group sees

The post text arrives verbatim, and under it the application writes the attribution. She does not summarise, introduce or comment on a post, and there is no model anywhere on the path, so the only transformation is a trailing blank line trimmed.

An edit at the source updates her message in place; a deletion at the source removes her copy for everyone. Members have no commands here at all, because the bridge is not something a member asks for.

The attribution the application writes 1 lines · 37 characters
📣 From the channel {channel}, {when}
Source site material Block 4 section 3 · the Channel Bridge plugin, and Block 4b section 4 on what a second protocol would need
What a digest says about the rest 1 lines · 44 characters
📣 Also new in {channel}: {n} earlier posts.
Source site material Block 4 section 3 · the Channel Bridge plugin, and Block 4b section 4 on what a second protocol would need
What having no model on the path buys 1 lines · 46 characters
nothing for a hostile channel post to instruct
Source site material Block 4 section 3 · the Channel Bridge plugin, and Block 4b section 4 on what a second protocol would need
Where confidentiality ends

A bridge is only as private as the far side

The sentence that belongs next to this feature rather than under it, and what the product actually does today.

The hop where it is lost

A bridge to a network without end-to-end encryption loses confidentiality at that hop. Whatever crosses is readable by that network's servers the moment it arrives, and no amount of care on this side changes it. That sentence belongs next to the feature rather than in a footnote, because somebody deciding whether to bridge needs it before they decide, not after.

What exists today crosses no such boundary: it is a broadcast channel to a chat group on the same network, one deployment, no model on the path. There is no bridge to another network in the product, and this page is not announcing one. Every way in, and what state it is in

The line the product already prints about its own channels 1 lines · 44 characters
Channel content is not end-to-end encrypted.
Source site material Block 4 section 3 · the Channel Bridge plugin, and Block 4b section 4 on what a second protocol would need

Extensible by shape, which is not the same claim

The planning half of the bridge, the cadence, the digest, the budgets and the suppression records, holds nothing network-specific and would carry over unchanged. The origin it records is versioned and carries a source field, which today holds one value. That makes it extensible by shape. It does not make this an extensible product, and the page will not imply one until something has actually been built on that seam.

The cadence

Whichever comes first, and what a digest is for

A tick that books its successor before doing the work, so a failure cannot end the rhythm.

QuestionAnswer
What triggers a post Per mapping, every N minutes or every N member messages, whichever comes first, measured from the last send. How far back keeps stale posts from ever announcing, repeats per post limits how often one is said, and Dismiss stops a post at the next tick. A post retired with zero announcements always writes a suppression record
When a digest happens Whenever more than one post is pending on a due tick: one message with the newest in full and up to 4 older as excerpts, oldest first so nothing starves, and everything beyond counted in the remainder line. Remainder posts spend no repeat and stay pending
The rhythm A self-chaining queue job every 60 seconds with a minute-bucket key, so boot seeds collapse into the live chain; the successor is booked before the work, so a failing tick cannot kill the cadence
Publishable to the web, exactly A row publishes on the per-channel switch alone, default OFF, derived on every read, so switching off unpublishes on the next request. Publishing unnamed strips the name from the column, the text, the search index and the attribution. Whether announcements also stand in the activity stream is a separate switch, and all of it is keyed on the link-derived channel key, so a rejoin cannot silently unpublish
Media Re-hosted at intake because relays expire files after about 48 hours and a repeat can outlive that; plaintext, since it is the operator own public broadcast and encryption would buy nothing. Oversize forwards as text with the omission stated on the console
Reaches outside, and the model The SimpleX network only. No model anywhere on the path: posts forward verbatim, and the only transformation is a trailing blank line trim
Publishing

Per channel, off by default, and named or not

Putting announcements on the public website is a separate decision, taken per channel and reversible on the next request.

Derived, so switching off is enough

Publishing an announcement to the public website is a separate switch per channel, off by default, and it is derived on every read rather than stamped onto a row. So switching it off unpublishes on the next request, with nothing to re-run.

Publishing a channel unnamed strips the name from the column, the text, the search index and the attribution, and the whole arrangement is keyed on a value derived from the channel link, so leaving and rejoining cannot silently unpublish.

What replaces a name when a channel is published unnamed 1 lines · 11 characters
(not named)
Source site material Block 4 section 3 · the Channel Bridge plugin, and Block 4b section 4 on what a second protocol would need
One real incident

Everything succeeded, and an hour was lost

No exception, no failed job, no member affected. A list that was merely out of date, and somebody acting on it.

The channel list went on offering a channel whose group had just been cleared elsewhere in the console, so the operator picked a dead source for a mapping and waited an hour for posts that could never arrive. Nothing failed, which is what made it expensive.

What the record said 1 lines · 49 characters
The tick ran 1516 times and succeeded every time.
Source site material Block 4 section 3 · the Channel Bridge plugin, and Block 4b section 4 on what a second protocol would need

The standing rule it produced

This is the incident behind a standing rule: an action taken in one surface must reach every surface that shows it. A list that is merely out of date is not a cosmetic fault, because somebody will act on it.