Shift cover and rota alerts

Setting this up takes about a minute. The slow part is not the software — it is deciding what to call yourself, because the handle ends up on a poster and cannot be changed afterwards.

What this actually looks like

One sealed channel for the team turns eleven phone calls into one message and a first reply. Nobody outside the rota can find the channel, join it, or read a word of it, and a member who leaves loses access the same afternoon.

How you would set it up

  1. Create a private channel for the team and send each member an invite link.
  2. Post the open shift with the date, the hours and who to answer. Important priority is enough.
  3. Restrict sending to the people who run the rota; everybody else reads.

Private means sealed, not merely unlisted

A private channel is not one that is simply missing from a directory. It requires an invite code both to subscribe AND to read anything about it, and a request without one gets exactly the same “not found” as a handle that never existed — because a different answer would let anybody confirm that a school’s or an ops team’s channel exists by guessing its name. Invite codes can carry a use limit and can be revoked; revoking is a timestamp and by default removes nobody who already joined.

More than one person, without sharing a password

A workspace holds the channels; people are invited into it with a role — owner, admin, editor, analyst or billing. An editor can compose and send; an analyst can read the numbers and nothing else; billing sees invoices and not subscribers. A member can also be restricted to a single channel, which is what a large organisation needs when the communications team and the facilities team should not be able to speak as each other.

Draft, schedule, send — and what cancelling cannot undo

Composing and sending are deliberately different permissions, so the person or script that writes an alert can be forbidden from publishing it. A scheduled alert becomes visible at its time without anything having to run at that minute, which means a server that was briefly down delivers late rather than never. Cancelling is honest about its limits: it stops an alert reaching phones that have not fetched it yet and does nothing at all to the phones that already have it. An alert cannot be unsent.

Questions, answered plainly

Can somebody find my private channel by guessing the name?

No. A sealed channel answers a request without an invite code with exactly the same “not found” that a nonexistent handle gets. There is no response that distinguishes “this exists but you may not see it” from “this does not exist”, because that difference is itself a leak.

Can I let somebody send without giving them everything?

Yes. Roles separate composing, sending, reading the numbers and seeing invoices, and a member can be restricted to a single channel. The same split exists for API keys, so a script can be allowed to send and forbidden from deleting.

Can I unsend an alert?

No. Cancelling stops it reaching phones that have not fetched it yet, and does nothing to the ones that already have it. Compose as a draft and read it back before you send; that habit is worth more than any undo button we could offer.

Do subscribers need an account?

No. They install the app, subscribe to a handle, and that is the whole of it. Only the person running the channel signs up for anything.

Say it once. Every subscribed phone gets it.

Free up to 100 subscribers, no card to start, and the handle is yours permanently.

Start a channel