NCE Feature Update (2026-04-01)
APRIL 1ST, 2026

Redacted posts are live — gated content visible in the feed with the access context right on the card. Posts can travel outside the forest via public links. Spaces now control post modes — short, long, and image-only. Access control is collapsing down to one primitive (groups), clearing the final path for money. Here's everything that's shipped since the last update.
[Redacted] posts and view gating
Posts can now be partially visible. A space runner or group admin sets view access on a topic — or overrides it on a single post — and non-entitled members see the post in their timeline but can't read it. The card shows the author, the timestamp, and a redacted treatment: a visual signal that something's there, behind glass, with the access context — which group, what it unlocks, how to get in. The mechanic works at every level: topic-wide defaults, per-post overrides that punch holes or hide individual posts, and it composes with the group access system so gated content and free content live side by side in the same feed.
This works today — no money required. Set a group-bound topic's view access to group-members and non-members see redacted cards in their feed. Per-post overrides let you punch holes or restrict individual posts regardless of topic settings. When paid access passes go live, the same mechanic becomes the purchase surface — the redacted card is where the CTA will live.
Public posts
Posts in DFOS can now be viewed outside the app via shareable links. This isn't a new toggle or a publishing action — a post is publicly viewable when the structural conditions are already met:
- The space has a public profile enabled
- The space join mode is open
- The post isn't deleted, moderated, or hidden
- The post isn't in a view-gated topic
- The post doesn't have a restrictive view access override
If all of those are true, the post has a public URL. Full formatting, images, metadata, and a call to action to join the space. Three-state rendering: members see the post inline, logged-in non-members see a join prompt, logged-out visitors see the post with a signup CTA. Viewing a public post doesn't grant any access to the space — commenting, chatting, browsing other content all still require membership.
Control over dark forest content is a core part of this platform. Posts in public spaces with open membership were already publicly accessible — anyone could join and read them. This formalizes that into a clean external surface and a distribution funnel for spaces. We're tracking public post views, space joins, and signups attributed to public posts, and we'll surface that data for space admins as the system matures. Further controls are coming — per-post and space/group-wide toggles to opt content in or out of public visibility — and we're open to feedback on this approach as it develops.
The forest has windows now. Spaces that want to be discoverable have a way to let their best content travel.
Post modes
Space runners now control what kind of posts members can make. The post mode setting supports three options — short posts, long posts, and image-only — and the composer and card rendering adapt accordingly. Image-only mode renders posts as clean visual cards with no title or body, just the image filling the frame. The timeline cards shift to match, giving spaces that want a visual-first feed a distinct look.
Money: where it stands
The full commerce stack is built and tested — double-entry ledger, Stripe checkout, subscription lifecycle, settlement, disputes, revenue splits, treasuries, payout onboarding across 22 countries. The access pass state machine has been burning in for weeks: grants, revocations, entitlement sync, the full lifecycle. What's been in progress is the access control surface that ties it all together.
The original design had two entitlement layers — space access passes and group access passes. Space-level permissions and group-level permissions compose, which sounds elegant until you put all the combinations in a settings screen. Two systems, two mental models for an admin to hold simultaneously to understand why someone can or can't see a post. If you can't explain it in a settings panel, it shouldn't exist.
One machine, not two. Groups are becoming the sole primitive for access control and monetization. The simplification is happening now — space and topic settings are collapsing to binary toggles (admins-only or all-members) and the space access pass layer is unwinding entirely. All the nuance lives at the group level, where it's more expressive and more tested. The "paid space" case still works — a new toggle requires holding any group access pass to join. Same outcome, one system.
Multiple groups give you multiple tiers, different pricing, different topic bindings — more expressive than a flat space-level pass. The surface area gets smaller and the capability stays the same. Real dollars are next — through one clean path.
Search and sidebar
Search overhaul. The search results page got a full redesign — new card layout, a FROM filter that scopes results to a specific member (click someone's post count on their profile and it takes you straight there), parent context on comments and replies so you can see what a result is responding to, and profile-to-search linking throughout the app.
Sidebar sorts by activity. Spaces in the sidebar now reorder in realtime as new activity comes in — the space you were just active in floats to the top.
The protocol
Yancey wrote about antienshittification last week — the DFOS Protocol is how we make that real. The protocol site documents the full spec: Ed25519 identity, content-addressed proof chains, W3C DIDs, and a web relay specification that any platform can implement.
What's new: a multi-region relay mesh is live and already peering with third-party nodes. Ryan at Imajin stood up an independent relay implementation — Brandon sent a signed artifact from the DFOS relay and it landed on Imajin's node. Two independent systems, same protocol, content replicating between them. Only public proof content travels the relay network — dark forest content stays dark.
This is the substrate for what comes next: personal sync nodes, dfosbox, run-your-own-relay, portable identity across platforms that all speak the same protocol. The relay spec is designed bidirectional — your content chains, signatures, and proofs stay live-synced and independently verifiable, not a ZIP export you download and hope ages well. More implementations means a stronger proof network. The protocol gets more valuable the less we're the only ones running it.
The clear.txt community has been deep in this — protocol hacking, relay convergence, builder dispatches. If the infrastructure layer interests you, that's where the conversation lives.
Auth hardening
Addressed several bugs related to early logout — sessions should be much stickier overall.
What's next: access config panels simplified to binary toggles this week, money wired through the one primitive, a cross-space global inbox for DMs and notifications, continued public post rollout, and first experiments with email notifications — DM pings and post-to-email for space admins.
And if you haven't yet — the Ask Us Anything thread is still open.
More soon.









