Host approval for every session
A person joins a session after the host or an administrator approves the request. Someone without that approval does not reach the room.
Nobody reaches a RoomHex session by holding the address. An administrator creates the account, a host approves the person at the door, and the host keeps control while the session runs.
RoomHex is self-hosted end to end, with no paid third-party service. Your conversations, media, and records stay where your team puts them. There is no public signup: an administrator creates each account after reviewing the request. Defaults stay conservative and administrators review access on a regular basis.
These settings govern who can enter a session and how the platform behaves when it is under load.
A person joins a session after the host or an administrator approves the request. Someone without that approval does not reach the room.
Rate limits and load controls keep a busy period, or an unwanted flood of traffic, from disrupting the people already in a session.
When a security setting is missing or unclear, access stays closed. The cautious option is the default in every case of doubt.
The pages RoomHex serves are locked down in the browser. That cuts common web attacks and keeps the surface someone could abuse small.
When something fails, the user sees a short, general message. Internal detail stays in the server logs, where it gives no clue to someone probing the system.
These controls cover who administers what, which content a person may open, and what gets logged. Your own staff operate all of them.
| Control | What it covers |
|---|---|
| Role-based and delegated administration | A person's role sets what they can open and change. Owners hand parts of the administration to specific staff, so the whole organisation does not share one level of access. |
| Branch permissions | Your organisation's own rules decide who can join. Each branch has its own permissions and works within the policy the organisation set for it. |
| Content access policies | An access policy is attached to shared content. It names who may view or use the material, in line with the rights that apply to it. |
| Audit logging and evidence-aware exports | Meaningful actions are written to an audit log, and an administrator can export that log in a form suitable for presenting as evidence. |
| Data minimization | Each feature collects and stores only the fields it needs for the task. Less sensitive information is held, so there is less to protect. |
| Privacy and retention control | Your administrators set the privacy options and the retention period for each kind of data. They can change how long records are kept at any time. |