Why chat is treated differently
Entering a gym gives you their admin surface, but it does not give you the contents of member conversations. Message bodies appear redacted to platform staff until you deliberately reveal them, and every reveal is logged where the gym can see it.
Who can reveal
Only three platform roles: Super Admin, Admin and Support Manager (manager_support). Other roles see the conversation list and metadata but never the text.
How a reveal works
- Open the conversation inside the gym. A banner explains the content is hidden.
- Choose Reveal and pick a reason category: member complaint, delivery fault, safeguarding, legal request, or other.
- Write a specific reason. "Investigating" is not a reason; "Member complaint #4821 — disputes what the coach agreed" is.
- A grant row is written to
chat_support_access_grantsand the messages become readable.
Limits
- The grant lasts 60 minutes and covers only that conversation. It cannot be extended — reveal again, with a fresh reason, if you need longer.
- Access is read-only. Platform staff never post into a member conversation as the gym.
- The gym sees the same record in their own activity log, in real time.
The Chat Access Log
Operations → Chat Access Log (/platform/chat-access-log) lists every reveal across every gym: which gym, which team member, the category, the written reason and the expiry. Review it periodically — a pattern of vague reasons is a training issue, and repeated reveals on one member usually means the underlying ticket was never resolved.
If a gym challenges a reveal
Do not explain it from memory. Open the log entry, quote the reason recorded at the time, and connect it to the ticket or complaint that prompted it. If no such link exists, escalate it internally rather than defending it to the customer.