# The Community Playbook > A resource for digital organizers — practical guides, toolkits, and strategies to help communities build power, mobilize, and act together online. Public Ghost content for AI and LLM tooling. This file includes a bounded export of public pages first, then recent public posts. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages ### About The Community Playbook URL: https://the-community-playbook.org/about/ Last updated: 2026-03-30T21:59:13.000Z The Community Playbook is an independent publication for people doing the work of digital organizing. Whether you're running a campaign, building community online, or trying to keep your group secure and connected, this is a place to find practical guides, toolkits, and strategies that actually apply to your situation. Subscriptions are free — but they come with a responsibility. In exchange for full access to our guides, resources, and analysis, we ask one thing: don't just read. Act. Use what you learn here to protect yourself, organize your neighbors, and build the resilient communities that autocracy cannot penetrate. Subscribe today for full access and email updates when new content is available — then get to work. ### Building a movement that can act URL: https://the-community-playbook.org/building-a-movement-that-can-act/ Last updated: 2026-06-12T18:33:34.000Z The pro-democracy movement faces a specific set of infrastructure problems: platforms that can be taken away, networks that are resilient but not fast enough to coordinate at scale, and a gap between the number of people who agree with the movement and the number who actively participate. This eight-part series addresses those problems directly — with practical frameworks and tools for organizers building for the long term. The series goal: provide a strategic and practical framework for growing the pro-democracy movement to 3.5% of the U.S. population — approximately 11.5 million active participants — and enabling the large-scale coordinated action that moment requires. ## [1\. The infrastructure you own](https://the-community-playbook.org/the-infrastructure-you-own/) Most digital organizing infrastructure is built on rented land. Here's what that means, why it matters more now than it ever has, and what to build before the landlord changes the locks. ## [2\. The activation problem: how movements respond at speed](https://the-community-playbook.org/the-activation-problem-how-movements-respond-at-speed/) The gap between having a network and being able to move it within 48 hours is the most dangerous gap in the current movement landscape. Here's how to close it. ## [3\. From supporter to organizer: building the commitment pipeline](https://the-community-playbook.org/from-supporter-to-organizer-building-the-commitment-pipeline/) Getting to 3.5% requires more than reaching 3.5% of the population with a message. It requires converting passive agreement into active, sustained participation. ## [4\. Digital security as organizing practice](https://the-community-playbook.org/digital-security-as-organizing-practice/) Security isn't a technical add-on — it's an organizing practice that has to be built into how the movement works at every level. ## [5\. Coordinating without a center](https://the-community-playbook.org/coordinating-without-a-center/) The movement's decentralization is a feature, not a bug — but it requires specific infrastructure to function as coordination rather than chaos. ## [6\. The strike card problem: building commitment infrastructure for large-scale action](https://the-community-playbook.org/the-strike-card-problem-building-commitment-infrastructure-for-large-scale-action/) A general strike cannot be called into existence by social media alone. It requires sector-organized, geographically anchored commitments held by trusted local networks — connected to a cascade activation system. ## [7\. Platform risk and the fediverse: building the infrastructure you can't be locked out of](https://the-community-playbook.org/platform-risk-and-the-fediverse-building-the-infrastructure-you-cant-be-locked-out-of/) Centralized platforms have owners. Those owners answer to governments, advertisers, and their own political instincts. Here's what the federated alternative looks like — and how to build it before you need it. ## 8\. Telling the truth when they control the megaphone Narrative power requires infrastructure, not just good messaging. How movements build media resilience: owned publications, documentation practices, rapid-response communications, and countering coordinated disinformation. Coming June 17. ## Posts ### Your calendar knows more than you think URL: https://the-community-playbook.org/your-calendar-knows-more-than-you-think/ Last updated: 2026-07-07T13:00:47.000Z Think about what lives on your calendar. Who you meet with, and when. Which coalitions you're coordinating with. When your chapter holds strategy sessions. Who's connected to whom. A calendar isn't just a scheduling tool — it's a map of your organizing relationships, and most organizers have handed that map to Google or Microsoft without a second thought. This isn't an argument against using those tools. For most organizing contexts, the convenience of Google Calendar is a reasonable trade-off. But it's worth understanding what you're trading, what the alternatives are, and — more practically — how to build shared calendar infrastructure that helps a distributed organizing network actually coordinate. This article covers two things: group shared calendars (for keeping a team or chapter synchronized) and scheduling tools (for coordinating meeting times across organizations or with the public). They're different problems with different solutions, and conflating them leads to choosing the wrong tool for the job. ## What your calendar platform knows When you use Google Calendar or Microsoft Outlook, those companies can see the metadata of your calendar — event titles, attendees, locations, times, and notes, depending on what you enter. This is different from the encryption-in-transit protection those platforms provide for data traveling between your device and their servers. Once your event data lands on their servers, they have access to it. For most meetings, that's not a meaningful concern. For organizing work — coalition building, legal strategy, direct action planning, anything that might attract government or corporate scrutiny — it's worth knowing that your calendar is a record, and it lives on someone else's infrastructure. The same US CLOUD Act that can compel American tech companies to hand over email or meeting content also applies to calendar data. If you've read our earlier pieces on communication infrastructure and secure video conferencing, the pattern is familiar: the default tools are convenient, but they're not neutral. ## Part one: shared group calendars A shared group calendar solves a specific problem: keeping everyone in an organization or chapter aware of what's happening, when, and who's responsible. It's distinct from your personal calendar. Its purpose is collective visibility — events that belong to the group, not just to the individual who scheduled them. Here's what actually matters when choosing one for an organizing context: **Who needs to see it, and do they need an account?** Some shared calendars require every viewer to have an account. Others can be shared via a public or semi-public link. For a chapter with active members who can all sign up for something, accounts are fine. For a public-facing event calendar embedded on a website, you need something link-accessible. **Who can edit, and what happens when someone leaves?** This is the infrastructure question that most organizers don't ask until it's a problem. If your shared calendar lives in one person's Google account and they leave the organization, you may lose admin access to it. Good shared calendar infrastructure is held by a role or organization account, not an individual. **What does it reveal?** Even internal shared calendars can expose sensitive information. An event titled "Legal strategy session — \[name\]" or "Debrief: \[action name\]" tells a story. Think about what you title events, especially on any calendar shared broadly. ### Google Calendar Google Calendar is the de facto standard for shared calendars in most volunteer organizations, and for good reason: it's free, nearly universal, and integrates with everything. If your organization already uses Gmail or Google Workspace, shared calendars are easy to set up and maintain. **Free tier:** Fully functional shared calendars with any Google account. Multiple shared calendars, granular permission controls (view-only, edit, or manage), and the ability to share via link or direct invite. **Paid:** Google Workspace plans start at around $6/user/month and add shared resources (meeting rooms, equipment), organizational-level calendar policies, and more granular admin controls. For most volunteer organizing groups, the free tier is sufficient. **Key features:** Excellent interface, strong mobile apps, easy integration with Google Meet for video links, and the ability to embed a public calendar on a website. Shared calendars can be overlaid in a single view, color-coded, and filtered. **Privacy:** Google can access your calendar data, including event titles, descriptions, attendees, and locations. Calendar data is part of Google's broader data ecosystem and is subject to US CLOUD Act jurisdiction. For most organizing calendars — chapter meetings, canvassing schedules, public events — this is an acceptable trade-off. For sensitive coordination, it warrants more thought. **Practical note:** Create shared organizational calendars under a dedicated Google account (something like yourchapter@gmail.com) rather than a personal account. This keeps the calendar institutional rather than personal, ensures access survives leadership transitions, and prevents your personal events from being visible to the whole team. --- ### Proton Calendar Proton Calendar is the privacy-first alternative for organizations that want shared calendar infrastructure without handing their schedule to Google. It's end-to-end encrypted by default — event titles, descriptions, locations, and attendees are all encrypted, and even Proton cannot read them. **Free tier:** Up to 3 calendars. Shared calendars (with E2EE) require a paid plan for full functionality. **Paid:** Proton plans start at around $3.99/month for individuals; Proton Workspace for teams starts at $13/month and includes shared calendar access, Proton Meet integration, encrypted email, and Drive. **Key features:** End-to-end encrypted event data, shared calendars with view or edit permissions (up to 49 members per shared calendar), public link sharing for broader visibility, and tight integration with Proton Meet for scheduling encrypted video calls. Can import from Google Calendar and sync with external calendar clients via CalDAV. **Privacy:** The strongest privacy story of any major calendar platform. Calendars shared between Proton users are fully end-to-end encrypted. Calendars shared via public link use zero-access encryption — Proton can't read the content, but the encryption model is slightly different. Based in Switzerland, outside US CLOUD Act jurisdiction. **Honest caveats:** The interface is capable but not as polished as Google Calendar. Shared calendar access is currently managed via the web app only (not mobile). For teams fully committed to the Proton ecosystem — Proton Mail, Proton Meet, Proton Drive — this is a natural fit and the pieces work well together. For organizations that are deeply embedded in Google Workspace, switching just the calendar adds friction without eliminating the underlying data exposure (since your contacts, emails, and documents are still on Google). **Best for:** Organizations already using or migrating to Proton's privacy suite; leadership calendars containing sensitive meeting information; any calendar where event titles and attendee lists could be sensitive. --- ### Teamup Teamup is a purpose-built shared calendar for groups and organizations — not a repurposed personal calendar with sharing tacked on. It's worth knowing about because it solves some organizational problems that Google Calendar handles awkwardly. **Free tier:** Basic shared calendar for up to 8 sub-calendars and limited users. Functional for small organizations. **Paid:** Plans from around $8/month for small teams up to $24/month for larger organizations. Pricing is per calendar, not per user — which matters for volunteer organizations with many members. **Key features:** Multiple sub-calendars within a single shared calendar (by team, event type, geography, etc.), granular permission controls by sub-calendar, access via link without requiring an account, the ability to share different views with different stakeholders, and embeddable calendar pages for websites. **Privacy:** US-based, standard encryption-in-transit. Not end-to-end encrypted. Teamup is a straightforward calendar service without a surveillance business model — no ads, no data harvesting for marketing — but your calendar data is accessible to them and subject to US law. **Best for:** Organizations that need to coordinate multiple teams or event types within a single shared view — a state coalition managing multiple chapters, or an organization running parallel workstreams. The per-calendar pricing model (rather than per-user) can be more economical for large volunteer networks. Also useful for public-facing event calendars embedded on websites. --- ## Part two: scheduling tools Scheduling tools solve a different problem than shared calendars. Where a shared calendar gives a team visibility into collective events, a scheduling tool answers the question: "When can we find a time that works for everyone?" There are two flavors worth distinguishing: **Appointment booking tools** (Calendly, Cal.com, Proton Calendar's booking page): You share a link; the other person picks from your available slots. Good for one-on-one meetings, constituent calls, coalition partner check-ins, or office hours. **Group availability polls** (Doodle, When2meet): You propose several time options; participants indicate which work. Good for finding a meeting time when you don't control everyone's calendar. ### Calendly Calendly is the dominant appointment booking tool and works well for its intended purpose. You connect it to your Google, Outlook, or other calendar; it reads your availability and lets others book open slots, generating a meeting link automatically. **Free tier:** One active event type (meeting format). Unlimited bookings within that type. **Paid:** Standard plan at around $10/user/month for multiple event types, team scheduling, and integrations. Teams plan at around $16/user/month adds round-robin routing and collective scheduling. **Key features:** Polished booking experience for the person scheduling with you, automatic calendar blocking, reminder emails, and integration with Zoom, Google Meet, and other video platforms for auto-generated meeting links. **Privacy:** Calendly is a US company subject to CLOUD Act jurisdiction. It collects your availability data and your contacts' booking data (names, email addresses, sometimes notes). This isn't sensitive in most contexts — but think about what a booking page reveals: if your Calendly shows "Coalition strategy call" or "Subpoena response planning" as event types, you've published a piece of your organizing structure. Use generic event type names for anything sensitive. **Best for:** One-on-one scheduling with coalition partners, constituent calls, or recurring external meetings where convenience matters. Not a group calendar; not appropriate for internal team scheduling with sensitive event types. --- ### Cal.com Cal.com is the open-source alternative to Calendly, and it's worth knowing about for privacy-conscious organizations. The code is publicly auditable, and organizations with technical capacity can self-host it — meaning your scheduling data stays on your own infrastructure. **Free tier:** Generous free cloud tier with unlimited bookings. The cloud-hosted version runs on US infrastructure. **Self-hosted:** Free if you have technical capacity to run it. Self-hosting gives you full data ownership and is the configuration that delivers the real privacy advantage. Requires DevOps capacity to set up and maintain. **Paid (cloud):** Plans start at $12/user/month for teams and advanced features. **Key features:** Comparable to Calendly for one-on-one and team scheduling, with strong API access and customization options. The self-hosted version is a full-featured platform with no per-seat licensing cost. **Best for:** Organizations with technical capacity who want open-source scheduling infrastructure they control. For organizations without that capacity, the cloud version offers Calendly-comparable functionality; the privacy advantage over Calendly is only realized through self-hosting. --- ### Proton Calendar booking pages Proton Calendar includes a built-in appointment scheduling feature — a public booking page where people can schedule time with you, with confirmed meetings added directly to your Proton Calendar and a Proton Meet link generated automatically. **Free/Paid:** Available with Proton plans. The booking page feature is included in paid Proton plans. **Key features:** Privacy-first booking that keeps the entire scheduling and meeting pipeline within the Proton ecosystem — encrypted calendar, encrypted meeting. The booking page itself collects the booker's name and email, which are handled according to Proton's privacy standards. **Best for:** Organizations already in the Proton ecosystem who want scheduling that connects directly to encrypted meetings. Fewer features than Calendly, but a cleaner privacy story for the whole chain: encrypted calendar → encrypted booking → encrypted meeting. --- ### Doodle Doodle is the go-to tool for group scheduling polls — when you need to find a time that works for several people who don't all share a calendar. **Free tier:** Basic polls with time slot voting. Ads on the free tier. **Paid:** Around $6.95/user/month for ad-free, calendar integration, and meeting booking features. **Key features:** Simple poll creation — you propose time slots, participants check which ones work, Doodle shows the best overlap. No account required for participants to vote (just a name and email). Calendar integration for hosts on paid plans. **Privacy:** Doodle is based in Switzerland (same jurisdiction as Proton), which gives it stronger privacy protections than US-based alternatives. Standard encryption-in-transit; not end-to-end encrypted. Participant names and email addresses are collected for poll invitations. **Best for:** Finding a time for a coalition call, a multi-organization planning session, or any meeting where participants don't share a calendar and you need a quick consensus on timing. Not a calendar; not an ongoing scheduling tool. --- ### When2meet When2meet is the stripped-down, free, no-account-required group availability tool. It's been around for years and remains useful precisely because of how simple it is. **Free:** Completely free. No account required for anyone. **Key features:** Create a grid of time slots, share a link, participants fill in their availability by clicking. Instantly shows where overlap exists. No calendar integration, no reminders, no bells or whistles. **Privacy:** Minimal data collection. Participants enter a name and fill in a grid — that's it. No email address required, no account. The simplest privacy story of anything in this article. **Best for:** Quick group scheduling for a single meeting with volunteers or chapter members who don't need to create accounts or share personal information. Not suitable for recurring scheduling needs or anything requiring reminders or follow-up. --- ## Putting it together The right calendar infrastructure for an organizing group isn't one tool — it's usually two or three, matched to different functions: **A shared team calendar** gives your chapter or coalition visibility into what's happening. Google Calendar is the practical default; Proton Calendar is the right choice if event content is sensitive or you're committed to a privacy-first stack. Teamup is worth considering if you're coordinating multiple teams or need a public-facing event calendar. **A personal scheduling tool** reduces the back-and-forth of booking individual meetings. Calendly handles this well for most purposes. For organizations invested in the Proton ecosystem, Proton Calendar's booking page keeps the whole pipeline encrypted. Cal.com is the option for organizations that want open-source infrastructure and have the technical capacity to self-host. **A group availability poll** — Doodle or When2meet — solves the specific problem of finding a time across a group that doesn't share a calendar. Keep a link handy; you'll use it more than you think. One structural note that applies to all of these: shared infrastructure should be held by the organization, not by an individual. Create accounts under a chapter email address, not a personal one. Document who has admin access and what the handoff process looks like. Your calendar infrastructure, like your email list, is part of what the organization owns — and it should survive any single person's departure. ## The bigger picture Your calendar is a record of your organizing relationships — and most of us have placed that record with companies whose business interests don't align with protecting it. For most organizing calendars, the convenience of Google Calendar is worth the trade-off, and naming your events thoughtfully goes a long way. For the calendars that contain sensitive information — who you're coordinating with, what you're planning, when you're meeting with legal counsel — the infrastructure choice matters more. The good news is that the options are better than they've ever been. Proton Calendar provides genuinely private shared calendar infrastructure at a reasonable cost. When2meet handles anonymous group availability polling at no cost and with no data collection. And a little intentionality about what you name your events and where you keep your most sensitive schedules goes further than any tool switch. ### Your brain on democracy: the physiology of threat response and why it's so hard to stop URL: https://the-community-playbook.org/your-brain-on-democracy-the-physiology-of-threat-response-and-why-its-so-hard-to-stop/ Last updated: 2026-06-30T13:02:05.000Z *For organizers who know they need balance but can't seem to find it* --- You know you should step away from the news. You've read the articles about self-care, rest, and sustainable activism. You have a list of practices that would help — meditation, journaling, breathing exercises — and you're not doing them. You're not doing them because you're busy monitoring threats, responding to alerts, reading the next dispatch, and thinking through the implications. This isn't a failure of willpower or discipline. It's your nervous system doing exactly what it was built to do. Understanding the machinery doesn't make the problem disappear, but it does change how you relate to it — and that turns out to matter. --- ## The threat system: built for a different world Deep in the center of your brain sits the amygdala, a small almond-shaped structure whose primary job is to scan for danger. It is extraordinarily good at this job, and it operates faster than conscious thought. When it detects a threat, it triggers a cascade of hormonal and physiological changes — elevated cortisol and adrenaline, increased heart rate, heightened alertness, suppressed digestion — before your prefrontal cortex, the seat of reasoning and judgment, has even registered what happened. This is the fight-or-flight response, and it evolved for a world of immediate, physical threats: the predator, the rival, the collapsing cliff edge. It is an elegant system for surviving acute danger. The problem is that the amygdala cannot distinguish between a physical threat and a political one. It cannot tell the difference between a predator in the brush and a hostile executive order. When you read about an ICE raid, a court ruling, or an arrest of organizers you know, your amygdala responds as if the danger is immediate and physical — because to it, *it is*. The threat is real. The response is appropriate. And unlike a predator, the political threat doesn't go away. Research confirms that chronic stress causes measurable changes in amygdala function. Under sustained threat, the normal regulatory relationship between the amygdala and the prefrontal cortex begins to shift: the amygdala becomes more reactive, and the cortex's capacity to modulate those reactions diminishes. In other words, the longer the threat goes on, the harder it becomes to calm down. --- ## The Autonomic Nervous System: your body's control panel The autonomic nervous system (ANS) operates below conscious awareness, regulating heart rate, breathing, digestion, and dozens of other functions. It has two primary branches that work in dynamic balance: The **sympathetic nervous system** governs activation — the fight-or-flight state. It accelerates the heart, sharpens attention, mobilizes energy, and prepares the body for action. The **parasympathetic nervous system** governs recovery — the rest-and-digest state. It slows the heart, facilitates digestion, promotes repair, and allows the body to restore resources. In a healthy system, these branches shift fluidly in response to circumstances. Threat activates sympathetic; safety restores parasympathetic. The measure of this balance is **heart rate variability (HRV)** — the natural fluctuation in the interval between heartbeats that reflects the ANS toggling between its two modes. High HRV generally indicates good autonomic flexibility; low HRV indicates a system stuck in one mode. Chronic stress — the kind that comes from months and years of sustained threat monitoring — tips the balance toward sympathetic dominance. The system doesn't get the recovery signals it needs to restore parasympathetic tone. Over time, this has consequences well beyond stress: sustained sympathetic overdrive is associated with systemic inflammation, immune dysregulation, cardiovascular risk, and impaired cognitive function. There is growing scientific interest in a related phenomenon: the possibility that aging itself involves a progressive deterioration of this balance, a gradual drift toward sympathetic dominance that contributes to the inflammatory state associated with age-related disease. If that's right — and the evidence is accumulating — then chronic political stress isn't just uncomfortable. It may be accelerating a biological process that good ANS regulation would otherwise slow. --- ## The Dopamine Loop: why the work feels necessary Here's the part that doesn't fit the usual narrative about burnout: the work isn't just exhausting. For many organizers, it's also genuinely engaging — sometimes the most engaging thing in their lives. That's not incidental. It's neurological. Dopamine, commonly described as a "pleasure chemical," is more precisely a signal about salience and anticipated reward. It's released not just when we experience something good, but when we *anticipate* something meaningful — and especially when the outcome is uncertain. This is why variable reward schedules (the same mechanism that makes slot machines compelling) are so effective: unpredictability maximizes dopamine release. The current political environment is a near-perfect dopamine delivery system. It combines: - **High stakes** — the outcomes genuinely matter - **Moral urgency** — acting feels right; not acting feels wrong - **Intellectual engagement** — the problems are complex and interesting - **Variable reward** — you never know what the next email, alert, or news cycle will bring - **Novelty** — there is always something new to process Each email opened, each breaking story followed, each strategic question worked through delivers a small dopamine hit. The brain learns to associate this stream of engagement with reward, and it begins to prefer it — not because you're addicted in a clinical sense, but because the engagement is genuinely activating in a way that cleaning the kitchen simply is not. This creates an asymmetry that no amount of good intentions can easily overcome: high-stimulation threat monitoring outcompetes low-stimulation necessary tasks on a neurological level, not just a motivational one. --- ## The Default Mode Network: when your brain won't rest Neuroscientists have identified a network of brain regions — the **default mode network** (DMN) — that becomes active when we're not focused on a specific external task. It was initially understood as a kind of background hum, the brain at rest. More recent research reveals it as something more active and purposeful: the network responsible for self-referential thinking, mental simulation, autobiographical memory, and imagined futures and conversations. The DMN is healthy and necessary. It's where we consolidate memories, make meaning, plan ahead, and understand ourselves in relation to others. The problem arises when it becomes dominant — when instead of toggling in and out during genuine rest, it runs more or less continuously, even when you're nominally engaged in something else. You can recognize this state: you're doing one thing while your mind is somewhere else entirely. You're in the kitchen but rehearsing a conversation that may never happen. You're watching something but simultaneously working through political scenarios. You're trying to be present with someone you love while half your attention is monitoring a situation you can't control. This is not a personal failing. Research shows that elevated DMN activity is closely associated with chronic stress, anxiety, and rumination. The imagined conversations, the mental rehearsal of difficult scenarios, the inability to stay present — these are signatures of a nervous system that has lost the ability to genuinely downshift. The DMN is meant to be a place the brain visits; under chronic stress, it becomes where the brain lives. --- ## Why the usual advice doesn't stick You know about meditation. You've heard about journaling, breathwork, time in nature, digital detoxes, boundaries with news consumption. None of this is news to you. And yet. Here's what the physiology explains: the practices that most reliably restore ANS balance and quiet the DMN are precisely the practices that require you to slow down, get quiet, and be present. They ask you to inhabit the state that your dysregulated nervous system is actively resisting. Meditation asks you to sit with what arises without immediately processing or responding to it. Your threat-sensitized amygdala finds this uncomfortable. Your dopamine-trained attention system keeps looking for the next thing. The practice feels hard not because you're doing it wrong, but because it's working against the grain of a system that has been reinforced in the opposite direction for months or years. There's a secondary dynamic worth naming: researching and compiling information *about* these practices is itself a high-engagement intellectual task. It delivers its own dopamine hit. It keeps you in the familiar loop while producing the feeling of progress. Many of us have beautifully organized notes about practices we rarely do. This isn't hypocrisy. It's the system working as designed. --- ## What actually works (and why) The research on ANS rebalancing converges on a few interventions that have measurable, reproducible effects on HRV and parasympathetic tone. None of them are complicated. All of them are hard to do consistently when you're stuck in sympathetic overdrive. **Slow, extended breathing.** The most direct voluntary access to the autonomic nervous system is through the breath. During exhalation, the vagus nerve — the primary conduit of parasympathetic activity — increases its output, slowing the heart. Extended exhales, particularly those longer than the inhale, produce measurable increases in HRV and parasympathetic tone within minutes. At approximately five to six breaths per minute (a roughly equal five-to-six-second inhale and exhale), the cardiovascular and respiratory systems reach what researchers call resonance frequency — a state that maximally amplifies ANS flexibility. The **physiological sigh** is a particularly efficient version of this: two quick nasal inhales (the second "tops off" the lungs, reinflating small air sacs called alveoli that collapse under stress), followed by a long, slow exhale through the mouth. Researchers at Stanford found this technique outperformed other breathing practices for immediate mood improvement. It takes about thirty seconds. Your body already knows how to do it — you do it spontaneously every few minutes when awake and asleep. The difference is doing it intentionally, before the day's demands take over. **Aerobic exercise.** Exercise is the single most consistently supported intervention for improving vagal tone over time. During moderate aerobic activity, the sympathetic system appropriately dominates; in the recovery period that follows, parasympathetic rebound gradually shifts the autonomic set point toward higher resting vagal tone. This adaptation builds with consistency. Zone 2 cardio — a sustained, comfortable effort where you can hold a conversation — appears to produce particularly durable ANS benefits without the sympathetic overdrive that very high-intensity exercise induces. **Reducing input before adding practice.** Subtraction is underrated. Every notification, alert, and information stream is a potential amygdala trigger that keeps the sympathetic system active. Removing three email subscriptions may do more for your ANS than adding a ten-minute meditation — not because meditation doesn't work, but because you can't recover in an environment of continuous activation. **Starting absurdly small.** The research on habit formation is clear: new behaviors stick when they're attached to existing routines and kept small enough to be frictionless. Not a practice you aspire to — a practice you can actually do on the worst day of the week. One physiological sigh before you pick up the phone in the morning. One intentional breath before you open email. The goal isn't the technique. It's building the experience of choosing to pause, once, reliably. --- ## A note on the quiet There's one more thing worth naming, because it doesn't appear in the research literature but shows up reliably in conversations like this one. The threat response and the busy mind can function as protection — not from the political threat, but from what lives in the quiet. Grief about what is happening. Fear about what might. Anger, helplessness, the weight of caring about things you cannot fully control. For people doing this work, those feelings are not irrational. They're proportionate. The practices that restore nervous system balance also lower the defenses that keep those feelings at arm's length. For some people, that's part of why the practices are hard to start. Not because sitting still is uncomfortable in a general sense, but because of what becomes audible when everything else gets quiet. If that resonates, it's worth knowing that you don't have to process everything at once. The goal of nervous system regulation isn't to feel nothing or to achieve equanimity about genuinely terrible things. It's to create enough space between stimulus and response that you can choose how to act — rather than being driven by a threat-detection system that was designed for a world that no longer exists in quite this form. The movement needs people who can sustain this work over time. So do the people around you. So do you. --- *The Community Playbook covers digital tools and organizing infrastructure for the pro-democracy movement. This article is part of an ongoing conversation about what sustainable civic engagement actually requires.* ### Who's listening to your meetings? URL: https://the-community-playbook.org/whos-listening-to-your-meetings/ Last updated: 2026-06-23T13:00:57.000Z In 2023, Zoom quietly updated its terms of service to allow customer content — including audio and video from your meetings — to be used for AI training. The backlash was swift and loud. Within days, Zoom walked back the most explicit language and issued reassurances. But here's what didn't change: the architecture. Your audio, video, and chat still route through Zoom's servers, where Zoom retains the technical ability to access them. The policy changed. The infrastructure didn't. For a corporate team discussing quarterly projections, this is an acceptable trade-off. For an organizer coordinating a rapid-response action, building out a coalition structure, or discussing anything that could attract legal scrutiny, it's a different calculation entirely. Platforms have terms of service that can change. They have legal obligations to respond to government requests. And under the US CLOUD Act, American companies can be compelled to hand over data stored on their servers — regardless of where those servers physically sit. This article maps the major video conferencing platforms, what they actually do with your data, and how to choose the right tool for the right conversation. ## Why "encrypted" doesn't always mean private Most video platforms advertise encryption, and most of them are telling the truth — as far as it goes. The standard these platforms meet is *encryption in transit*: your data is scrambled as it travels between your device and their server. That protects against someone intercepting your traffic on the network. It does not protect against the platform itself. Once your audio and video arrive at the server, the platform can access them. This is called server-side access, and it's the norm for Zoom, Google Meet, and Microsoft Teams. The alternative is *end-to-end encryption* (E2EE): data is encrypted on your device and can only be decrypted by the other participants. The server is a relay, not a reader. Not every platform offers this, and not every platform that claims to offer it does so by default or for all call sizes. That distinction — who can access your call content, and under what circumstances — is the thread that runs through everything that follows. ## The platforms ### Zoom Zoom became the default meeting platform for a reason: it's polished, reliable, and nearly universal. For many organizing contexts, that familiarity is a genuine asset — lower friction means higher participation. **Free tier:** Group meetings capped at 40 minutes; unlimited one-on-one calls. Up to 100 participants. No account required to join (only to host). **Paid:** Pro plan starts at around $15.99/user/month and removes the time limit, raises participant caps, and adds cloud recording. Higher tiers add webinar features and larger participant counts. **Key features:** Excellent breakout rooms, robust recording and transcription, strong webinar mode for large one-way presentations, wide device support, and near-universal familiarity among participants. **Privacy:** Not end-to-end encrypted by default for group calls. Zoom's servers can access your meeting content. The 2023 terms-of-service controversy — where Zoom claimed broad rights to use customer content for AI training — was partially walked back, but the underlying server-access model remains unchanged. Zoom is a US company subject to the CLOUD Act. **Best for:** Public-facing events, new volunteer orientation, large chapter calls where content isn't sensitive and participation rates matter most. --- ### Google Meet Google Meet's advantage is zero friction for anyone already in the Google ecosystem — which, for many organizers, means most of their participants. No download, no separate account, just a link. **Free tier:** Up to 100 participants, with a 60-minute group call limit. Requires a Google account to host; guests can join without one via link. **Paid:** Included in Google Workspace plans starting around $6/user/month, which removes time limits and adds recording, attendance tracking, and noise cancellation features. **Key features:** Seamless Google Calendar integration, reliable browser-based performance, live captions, and compatibility with Google's broader collaboration tools (Docs, Slides, etc.). **Privacy:** Not end-to-end encrypted. Google's servers can access meeting content, and Meet is part of the broader Google data ecosystem. If your organization is already Google-dependent, Meet doesn't add new exposure — but it doesn't improve your privacy posture either. US company, subject to CLOUD Act. **Best for:** Routine coordination in organizations already on Google Workspace; meetings where content isn't sensitive and the convenience of Google Calendar integration is valuable. --- ### Microsoft Teams Teams is built for enterprise environments and shows it. If your organization lives in Microsoft 365, Teams is already there. If it doesn't, introducing Teams just for meetings adds overhead without corresponding benefit. **Free tier:** Available with a Microsoft account; group call limit of 60 minutes. Up to 100 participants. **Paid:** Included in Microsoft 365 plans from around $6/user/month, with higher tiers adding larger participant caps, recording, and advanced admin controls. **Key features:** Deep Office 365 integration (SharePoint, OneDrive, Outlook), persistent channels for team communication, strong admin and compliance tools, good for large organizations with complex permission structures. **Privacy:** Not end-to-end encrypted by default. Microsoft can access meeting content. US company, CLOUD Act applies. Microsoft has faced scrutiny over its AI Copilot features processing meeting transcripts, similar to the Zoom situation. **Best for:** Organizations already running Microsoft 365 who need meeting capabilities integrated with their existing tools. Not worth adopting as a standalone meeting platform. --- ### Jitsi Meet Jitsi is the open-source alternative that's been a favorite among privacy-conscious organizations for years. It runs directly in a browser — no download, no account required to join — and the software itself is free and auditable. **Free tier:** The public instance at meet.jit.si is completely free, with no time limits and no participant cap for basic use. Hosting on the public server requires a Google, GitHub, or Facebook account; joining requires nothing. **Paid:** Jitsi as a Service (JaaS), a cloud-hosted version run by 8x8, starts at around $12/month for up to 20 participants and is designed for organizations that want managed hosting without running their own server. **Key features:** Browser-based (no install required), lobby/waiting room, screen sharing, optional shared note-taking via Etherpad. Organizations with technical capacity can self-host a Jitsi instance for full control over infrastructure and branding. **Privacy:** This is where Jitsi requires honest nuance. End-to-end encryption is available but must be manually enabled, and it only works when all participants are using a supported desktop browser or the native app — not all mobile browsers support it. On the public meet.jit.si server, 8x8 operates the infrastructure and has server-level access to unencrypted calls. Self-hosting removes that dependency entirely and is the configuration that delivers the privacy Jitsi is known for — but it requires technical staff to set up and maintain. **Best for:** Tech-comfortable organizations willing to verify E2EE is actually active, or organizations with the capacity to self-host. An excellent choice if you can run your own instance. On the public server without E2EE enabled, the privacy advantage over Zoom is smaller than it might appear. --- ### Proton Meet Proton Meet launched on March 31, 2026, and it's worth paying attention to. Proton — the Swiss company behind ProtonMail and Proton VPN — has spent a decade building privacy-first alternatives to Google's tools. Meet is the last piece: a video conferencing platform with end-to-end encryption baked in at the architecture level, not bolted on as an option. **Free tier:** Up to 50 participants, 1-hour call limit. Requires a free Proton account to host. Guests can join without any account. **No-account option:** Up to 4 participants with no account required at all — just visit meet.proton.me. **Paid:** Meet Professional at $7.99/user/month supports calls up to 24 hours and up to 100 participants (higher-tier Proton Workspace plans support up to 250). Proton Workspace Standard bundles Meet with encrypted email, calendar, drive, and VPN starting at $13/month. **Key features:** Screen sharing, in-call encrypted chat, background blur, noise reduction, persistent named meeting rooms, and tight Proton Calendar integration. Meetings can also be added to Google or Microsoft calendars, so participants don't need to switch their whole setup. **Privacy:** End-to-end encrypted by default for all calls, using the MLS (Messaging Layer Security) protocol — an open-source standard that has been independently audited. Not even Proton can access call content. Meeting passwords are embedded as URL hash fragments, meaning Proton's servers never see them. Proton is based in Switzerland and falls outside the jurisdiction of the US CLOUD Act — a meaningful structural protection for organizations concerned about government access to data. **The honest caveat:** Proton Meet launched in March 2026 and is still early. Launch-day reviews were generally positive, but real-world experience — including ours — has surfaced bugs and inconsistent video quality. These are likely growing pains rather than structural limits, but it's worth testing before routing an important call through it. Feature parity with Zoom isn't the goal or the claim — privacy is. For now, treat it as the right tool for sensitive conversations where privacy outweighs polish, and keep Zoom or Google Meet as your fallback for large-group calls where reliability matters most. **Best for:** Sensitive strategy conversations, coalition coordination, any meeting where content could attract legal scrutiny. The free tier is generous enough for most organizing use cases, and the no-account-required joining removes the biggest friction barrier for participants. --- ### Signal Signal isn't primarily a meeting platform — it's an encrypted messaging app that also does video calls. But for organizations that are already using Signal (which, if you've read our earlier articles on communication infrastructure, you should be), it's worth knowing what it can do. **Free:** Entirely free, always. Signal is a nonprofit funded by donations and has no commercial interest in your data. **Paid:** None. **Key features:** Group video calls up to 75 participants (updated in February 2026), screen sharing, raise-hand, emoji reactions, call links for easy joining. Available on iOS, Android, and desktop (Windows, Mac, Linux). **Privacy:** End-to-end encrypted by default, for every call, always — this is Signal's foundational promise and the one it has never compromised. Signal cannot access your call content. No ads, no data collection, no AI training. The Signal Protocol, which underpins the encryption, is the gold standard that other apps have adopted. **The real limitation**: everyone in the call must have Signal installed and an account linked to a phone number. There's no browser-based joining and no guest access. This makes Signal excellent for established organizing teams where everyone's already connected, and less practical for calls with external participants, coalition partners, or new volunteers who haven't set it up yet. **Best for:** High-trust, established teams already on Signal — leadership calls, security-sensitive planning, coordination with people you'd trust with sensitive information. For those conversations, it's the strongest option available. --- ## At a glance | Platform | E2EE by default | Free participant limit | Join without account | Jurisdiction | Best for | | ------------------- | --------------- | ------------------------- | -------------------- | ---------------------- | -------------------------------------------- | | **Zoom** | No | 100 (40-min limit) | Yes | US | Large, low-stakes meetings | | **Google Meet** | No | 100 (60-min limit) | Yes (via link) | US | Google Workspace orgs | | **Microsoft Teams** | No | 100 (60-min limit) | No | US | Microsoft 365 orgs | | **Jitsi Meet** | Only if enabled | Unlimited (public server) | Yes | US (8x8) / self-hosted | Tech-comfortable orgs; best self-hosted | | **Proton Meet** | Yes | 50 (1-hr limit) | Yes | Switzerland | Sensitive meetings, privacy-first default | | **Signal** | Yes | 75 | No | US (nonprofit) | Established teams, highest-sensitivity calls | --- ## Choosing the right tool for the conversation The honest answer is that you probably don't need to pick one platform and use it for everything. A tiered approach — matching the tool to the sensitivity of the conversation — is more practical and more realistic than asking every volunteer to adopt new software overnight. **For low-stakes, large-group calls** — chapter updates, public webinars, new volunteer orientation — Zoom or Google Meet are fine. Content isn't sensitive, participation rates matter, and the friction of asking everyone to use an unfamiliar platform isn't worth it. **For internal organizing strategy, coalition coordination, and anything involving sensitive decisions** — switch to Proton Meet or Signal. Proton Meet has the lower barrier to entry: guests can join without an account, so you're not asking coalition partners or new participants to install anything. For groups already on Signal, Signal calls are the stronger choice. **For your highest-sensitivity conversations** — legal strategy, subpoena risk, security planning, discussions of specific individuals — Signal, with confirmation that E2EE is active, or Proton Meet with meeting lock enabled to prevent uninvited participants. The transition doesn't have to be all-at-once. Start by routing your most sensitive conversations to a more secure platform. Keep routine coordination where it is. As your team gets comfortable, expand from there. ## One clarification on scheduling tools A note worth making: Calendly is not a video conferencing platform. It's a scheduling tool — it collects availability, lets external contacts book time on your calendar, and generates a Zoom, Meet, or Teams link for the actual call. It's genuinely useful for one-on-one meeting booking, but it doesn't host meetings. Group calendars and scheduling infrastructure — including the privacy implications of calendar data — are a full topic in their own right, and we'll cover them in an upcoming article. ## The bottom line The platform you meet on is part of your organizing infrastructure. For most conversations, the convenience of Zoom or Google Meet is a reasonable trade. For conversations that matter — where you're planning, strategizing, or discussing anything that could invite scrutiny — the platform deserves the same deliberate choice you'd make about your email list or your contact database. Proton Meet's launch in early 2026 closes a real gap. For the first time, there's a polished, genuinely end-to-end encrypted video platform with a free tier generous enough for most organizing use cases and no barrier to joining for participants without an account. Combined with Signal for your highest-trust conversations, the toolkit is now complete. The question isn't whether secure options exist. They do. The question is whether you're using them for the conversations that warrant it. ### Telling the truth when they control the megaphone URL: https://the-community-playbook.org/telling-the-truth-when-they-control-the-megaphone/ Last updated: 2026-06-16T13:00:38.000Z In July 2024, the Venezuelan government announced that Nicolás Maduro had won re-election. The opposition had expected this. They had spent months preparing for it. What the government hadn't counted on was that the opposition had deployed more than 270,000 poll watchers across the country — one for nearly every voting machine — each authorized to receive an official paper printout called an *acta* directly from the machine after voting closed. These tally sheets, known as actas, had long been considered the ultimate proof of election results in Venezuela. The opposition knew that documentation collected before the regime could suppress it was the only evidence that would survive suppression. Opposition poll watchers collected actas from 80% of precincts; those showed challenger Edmundo González Urrutia carrying an overwhelming 67% of the vote. Within 24 hours of polls closing, that evidence was digitized, distributed, and in the hands of international observers. The government could claim victory. It could not erase the actas. What is rare — and powerful — is the ability to prove fraud, and to do so with data and democratic values. The Venezuelan opposition didn't win that battle because they had better messaging. They won it because they had built documentation infrastructure *before* they needed it — before the moment when those in power could prevent them from building it. That is the model this article is about. --- ## The information asymmetry problem Every movement operates inside an information environment it didn't design and largely doesn't control. Governments and well-funded opponents have communications infrastructure: press offices, media relationships, coordinated message distribution, the ability to flood the zone with counter-narrative at speed. Movements, especially decentralized ones, often have passion and numbers — but not the infrastructure to turn either into a durable narrative. The asymmetry isn't just about access to audiences. It's about speed, persistence, and the ability to document reality before opponents can reframe it. This is what narrative power actually means in practice: not the ability to craft a better message, but the infrastructure to get your account of events into circulation *first*, to document what happened before it can be denied, and to keep that documentation accessible after the news cycle has moved on. Movements that have lost narrative battles often lost them structurally, not rhetorically. They had good arguments and no place to put them. They documented abuses but couldn't distribute the documentation. They had a story and no owned channel to tell it through. --- ## Owned media as organizing infrastructure The most durable narrative asset a movement can build is a publication or newsletter it owns outright — not rented space on a platform someone else controls, but an owned channel with a subscriber list that belongs to the movement. This isn't a new idea. Movement publications have existed as long as movements have. What's changed is the accessibility of the tools and the stakes of not having them. A Ghost-based publication, a Substack newsletter, a self-hosted WordPress site — these are the contemporary equivalents of the movement press. They serve several functions that platform-dependent channels can't: **Subscriber portability.** A newsletter list is yours. You can export it, move it, and contact those subscribers through any platform. A Facebook page following or an Instagram audience belongs to Meta. When the platform changes its algorithm, restricts your account, or gets taken down, your audience doesn't come with you. **Editorial independence.** Owned publications can say things platforms might flag, restrict, or demote. During active suppression, this matters — content that challenges government narratives has been routinely throttled on centralized platforms. **Archival permanence.** Movement history lives in owned publications. Platform-dependent content disappears when platforms change policies, go down, or get acquired. The record of what happened, what was said, and what the movement did needs to live somewhere that won't be erased by a terms-of-service update. The practical floor here is an email newsletter with an exportable subscriber list. That alone gives a movement a communication channel that doesn't depend on platform access. Anything beyond that — a self-hosted publication, a documentation archive — is additional resilience. --- ## Documentation as a political act The Venezuelan acta operation wasn't just electoral strategy. It was a model for something broader: the systematic collection of evidence about reality before those in power can suppress or reframe it. Movements documenting police violence learned this the hard way during the 2020 uprising — that video evidence collected in the moment and distributed immediately created a factual record that was much harder to deny than accounts circulating days later. The speed of documentation wasn't just logistical. It was political. Documentation infrastructure means: - **Pre-assigned roles.** At every action, someone's job is to document — not as an afterthought, but as a function with a protocol. Who records, what format, where it goes immediately. - **Distributed backup.** Documentation uploaded only to one location — especially a centralized platform — can be taken down. The Venezuelan opposition understood this: the actas were physically distributed and digitally replicated across multiple locations before any central authority could intervene. - **Chain of custody.** Evidence that can be authenticated is more durable than evidence that can be questioned. Simple protocols — timestamps, GPS metadata, witness signatures — can make documentation legally and journalistically usable rather than just morally compelling. - **A permanent, accessible archive.** The movement's own record of what happened shouldn't live only in social media posts that will eventually be deleted, demoted, or made inaccessible by algorithm changes. Owned archives — even simple ones — create institutional memory that survives platform changes. The point isn't to build a perfect evidentiary apparatus. It's to make documentation a default practice rather than an afterthought. --- ## Rapid-response communications One of the most consistent patterns in how movements lose narrative ground is the lag between when something happens and when the movement communicates about it. Opponents fill that gap. Whatever frame gets established first tends to persist even after correction. Rapid-response communication isn't about being reckless or posting before you know what's happening. It's about having the infrastructure and roles in place so that when you do know what's happening, you can communicate it immediately through your owned channels. That requires a few things: **Pre-written templates for predictable scenarios.** Many movement communications crises are predictable in type if not in specifics: an organizer is arrested, a permitted action is met with disproportionate force, a government official mischaracterizes an event. Templates don't mean scripts — they mean the structural work has been done in advance so that communications in a crisis don't have to start from zero. **A clear internal decision chain.** Who approves rapid-response messaging? How many people need to sign off before something goes out? In a coalition setting, this question needs to be answered before a crisis, not during one. Speed requires pre-authorized decision-making. **Distributed send capacity.** If one person controls all external communications and they're unavailable, inaccessible, or arrested, communications stop. Rapid response requires distributed capacity — multiple people authorized to send through multiple channels. **Cross-channel coordination.** Rapid response isn't just one platform. It's the newsletter blast, the social posts, the text message to the core list, and the media release going out in coordinated sequence. The infrastructure for that coordination — the lists, the drafts, the contacts — needs to exist before it's needed. --- ## Countering coordinated disinformation Movements increasingly operate inside information environments where they are not just competing for attention but actively being targeted with coordinated disinformation — false or misleading content designed to undermine movement credibility, sow internal division, or suppress participation. This is worth naming directly because the response to coordinated disinformation is different from the response to ordinary misinformation. Ordinary misinformation spreads because something is confusing or compelling. Coordinated disinformation is engineered — it has specific targets, uses specific platforms and amplification mechanisms, and often exploits authentic grievances to make false claims more plausible. The practical toolkit for dealing with this: **Monitor, don't just react.** Tools like CrowdTangle (where still accessible), Brandwatch, and open-source social listening tools can help movements identify when disinformation about them is spreading before it reaches critical mass. Waiting until a false narrative has gone viral to respond is almost always too late. **Document the pattern, not just the instance.** A single false claim looks like a mistake. A pattern of similar false claims, with identifiable amplification networks, is evidence of a coordinated operation. Documenting the pattern makes it possible to respond at that level — to name the operation, not just refute the claim. **Inoculation over refutation.** Research on disinformation consistently finds that refuting a false claim amplifies it — repetition of the false claim, even in the context of debunking, makes it more familiar and thus more credible. Inoculation — warning your audience in advance that certain types of false claims will be made about you, and why — is more effective than point-by-point refutation. **Build relationships with journalists who cover disinformation.** Movements that have cultivated relationships with reporters who cover information operations are better positioned to get coordinated disinformation exposed as what it is, not just corrected. --- ## The role of local storytelling One of the most underused narrative assets in a national movement is the local story told well. National movements often communicate at national scale — about policy, about systemic problems, about what needs to change at the federal level. These are important. They are also abstract, and abstraction is one of the main reasons people don't feel that political action is connected to their own lives. Local stories — a tenant facing eviction because of a specific policy, a worker whose employer is violating a specific labor standard, a family navigating a specific healthcare failure — make structural problems legible in human terms. They create the emotional connection that motivates sustained engagement. They are also, by definition, harder for opponents to deny, because they are specific, verifiable, and involve real people. The infrastructure question here is about collection and distribution. Local stories need to be gathered systematically — not just featured when they surface organically, but actively sought through local organizer networks — and they need distribution channels capable of reaching both movement audiences and press. This is where the connection between documentation infrastructure and narrative infrastructure becomes most concrete. The people living with a problem are the most important storytellers about that problem. Building the infrastructure to collect, verify, archive, and distribute their stories is both a documentation function and a communications function. --- ## Putting it together: the movement media stack The practical version of everything above fits into a coherent architecture that doesn't require a communications department or a large budget: **Owned publication layer** — An email newsletter with an exportable list, published through a self-hosted platform (Ghost, WordPress) or a platform with strong export capabilities (Substack). This is the baseline. Everything else builds on it. **Documentation layer** — Pre-assigned roles for documentation at all actions and events; a simple protocol for backup and distribution; a permanent archive (even a shared folder with clear naming conventions) for the movement's record. **Rapid-response layer** — Pre-written templates for predictable scenarios; a clear decision chain for approval; distributed send capacity across multiple channels; up-to-date media contacts. **Monitoring layer** — Social listening tools appropriate to the movement's scale; a documented protocol for escalating identified disinformation; relationships with journalists who cover information operations. **Storytelling layer** — A process for actively collecting local stories from organizer networks; a place to publish them; distribution channels capable of reaching both movement audiences and media. None of these require professional communications staff. They require thought, preparation, and the organizational discipline to maintain them when there isn't an immediate crisis — which is the only time they can actually be built. --- ## What this series has been building toward Every article in this series has circled the same underlying problem: the movement has people and passion and a cause, but it keeps having to rebuild the same infrastructure from scratch, on platforms it doesn't control, without the institutional memory to learn from what's been tried before. The answer isn't a single tool or platform. It's the discipline of building infrastructure before you need it — owned channels before you're locked out, documentation systems before evidence disappears, communication capacity before a crisis forces improvisation. Venezuela's opposition didn't collect those actas on election night because they had a good idea in the moment. They collected them because they had spent months building the infrastructure to do it — training the people, establishing the protocols, and creating the distribution network before anyone could stop them. That's the model. Build the infrastructure now. Use it continuously. It will be there when you need it. --- *This article is part of* [*Building a Movement*](https://the-community-playbook.org/building-a-movement-that-can-act/)*, an eight-part series on digital infrastructure for the pro-democracy movement.* ### Platform risk and the fediverse: building the infrastructure you can't be locked out of URL: https://the-community-playbook.org/platform-risk-and-the-fediverse-building-the-infrastructure-you-cant-be-locked-out-of/ Last updated: 2026-06-12T19:02:57.000Z In December 2025, Meta restricted access to the Instagram account of Maria Sarungi-Tsehai, a prominent Tanzanian activist who had been documenting alleged human rights violations and organizing anti-government protests. Meta confirmed the action in a statement: it had received a legal order from Tanzanian regulators, and it complied. Sarungi called it state repression laundered through a platform's terms of service. She was right — and the mechanism is the point. This is the scenario that the 2020 Facebook suspensions of Greenpeace USA and dozens of Indigenous organizations — covered in the first article in this series — foreshadowed but didn't fully complete. Those suspensions were, by Facebook's account, an accident. The Tanzania action was deliberate: a government identified an activist it wanted silenced, issued an order to a platform it knew would comply, and the platform complied. No hack, no infiltration, no dramatic intervention. Just a legal process and a company that made a business decision. The U.S. pro-democracy movement is not Tanzania. But the mechanism — government pressure on platforms, platforms complying — is not geographically limited. And organizers building their communications infrastructure on platforms that answer to legal orders from whoever holds power in the relevant jurisdiction are building on land they may not always control. ## What the fediverse actually is The word “fediverse” — a portmanteau of “federated” and “universe” — refers to a network of interconnected platforms that all speak a common language. The most widely used version of that language is ActivityPub, an open protocol that lets users on different servers and different platforms interact with each other. Think of it the way email works: you can have a Gmail address, your organization can run its own mail server, and a colleague can use ProtonMail, and all of you can still exchange messages. No single company owns email. No single company can shut it down. The fediverse works the same way for social media. Mastodon is the most prominent platform built on ActivityPub, but it's not the only one. Pixelfed (photo sharing), PeerTube (video), and Lemmy (discussion forums) all connect through the same protocol. A Mastodon user can follow and reply to someone on a different Mastodon instance, or on Pixelfed, or on any other ActivityPub platform. One protocol, many applications, no central point of control. This is the structural fact that matters for organizers: no single entity can suspend the fediverse. There is no button to push. ## The trade-off that's worth being honest about Mastodon has roughly 750,000 to 1 million monthly active users as of early 2026, against hundreds of millions on Instagram and billions across Meta's platforms. The fediverse has grown significantly since 2022, but that growth has been wave-driven — surges following Twitter acquisition controversies and Meta policy changes — rather than steady. The mainstream audience your organizing needs to reach is still primarily on platforms you don't control. That's the real trade-off, and it's worth being direct about it. Federated platforms are not a substitute for mainstream social media reach. They're insurance against losing that reach entirely, and they're where the infrastructure layer of your communications should live. The strategic frame isn't “leave the centralized platforms.” It's: build your presence on both, with different purposes. Centralized platforms are where you find new people. Federated infrastructure is where you keep your ability to communicate, regardless of what any platform decides. ## Bluesky and the AT Protocol: a different kind of portability Bluesky, which reached over 41 million users by the end of 2025, operates on a different architecture than ActivityPub — the AT Protocol — but pursues a related goal: making your audience portable. On Bluesky, your identity is tied to a Decentralized Identifier (DID), not to a specific server. Your followers follow your DID. If you migrate to a different server, they come with you, because they were never following a server — they were following you. Bluesky describes this as giving users a “passport” for social media: you carry your relationships with you. In practice, most Bluesky users still depend on Bluesky's own infrastructure — a caveat worth acknowledging, since the portability is architectural but hasn't been widely exercised. But the design principle is meaningful. The at-risk scenario on Bluesky isn't “the company suspends your account and you lose everything.” It's something closer to “you can move if you need to.” That's different from Facebook, where your audience is the platform's asset, not yours. AT Protocol and ActivityPub aren't interoperable with each other in the way that different ActivityPub platforms are interoperable with each other — but bridging tools are in active development, and the two communities share a federated philosophy even where the technical implementations differ. ## What Matrix/Element solves that Mastodon doesn't Public social media — federated or otherwise — is for visibility. It's where you broadcast, recruit, and build an external audience. It's not where your internal organizing happens. For internal coordination, the federated alternative is Matrix, an open protocol for encrypted messaging that works something like email for team communication. The most widely used application built on Matrix is Element. Your Matrix identity follows the same pattern as a Mastodon handle: it includes both your username and the server it lives on (@username:server.org). That server can be run by your organization, by a trusted host, or by anyone — and federation means Matrix users on different servers can still communicate with each other. The security properties matter here too. Matrix conversations are end-to-end encrypted by default. No company can be subpoenaed for messages it doesn't have. No platform can revoke your access to conversations that live on your own server. Matrix has gained significant adoption among organizations with serious digital sovereignty requirements — it's in use across European governments, adopted by Germany's national healthcare federation, used by the International Criminal Court after the Trump administration's sanctions disrupted the court's Microsoft-dependent infrastructure. These aren't organizations with casual security concerns. They chose Matrix because they need communications infrastructure that no outside party can shut down or access. For an organizing network operating under active suppression, that's the relevant reference class. ## Ghost as the publishing layer The same logic applies to publishing. Substack is a centralized platform — it can ban publications, change monetization terms, or face regulatory pressure in the same way any centralized platform can. Ghost, by contrast, is open-source software you can self-host. When you publish on a Ghost instance you control, you own the content, the subscriber list, and the delivery infrastructure. No one can take that from you. For organizers who have been building newsletters on centralized platforms, this is the same argument as email list ownership: the relationship with your readers is only as durable as the platform that mediates it, unless you own the infrastructure. Ghost's RSS and email delivery capabilities also mean your content feeds naturally into the fediverse through ActivityPub — Ghost instances can federate with Mastodon and other ActivityPub platforms, so your newsletter subscribers and your fediverse followers can converge on the same owned publishing layer. ## The “both/and” strategy The practical framework here isn't a migration plan — it's a redundancy plan. Most of your audience is on centralized platforms, and you should be there too. But your organizing infrastructure shouldn't depend on those platforms remaining available, cooperative, or indifferent to your politics. Here's how to think about the layers: **For public reach**: Maintain your presence on Instagram, Facebook, and wherever your audience is. Also build and maintain a presence on Mastodon and Bluesky. When Meta suspends your Instagram account, you need somewhere to direct people — and that somewhere needs to already exist and already have an audience. **For internal coordination**: If your organization is using Slack or WhatsApp for internal organizing, build a parallel Matrix/Element presence. You don't have to migrate everyone immediately. But you need a functional fallback that people have already used at least once, because the moment you need it urgently is not the moment to be explaining how to set up a new app. **For publishing**: Own your subscriber list. If you're on Substack, export your list regularly and maintain a backup delivery mechanism. If you're building a new publication or newsletter infrastructure, Ghost is worth the additional setup cost. **For your contacts and relationships**: This is the subject of the first article in this series, and it remains the most critical: your contact database needs to live somewhere you control, not in a CRM whose terms of service can be revised or whose access can be revoked. ## Migration readiness, not migration The failure mode to avoid here is the one that's already happened to too many organizations: the platform changes, the suspension comes, and there's no backup. The organizers who survived the 2020 Facebook suspensions intact were the ones who had email lists they owned, secondary communication channels that already existed, and audiences they'd been building on multiple platforms. The goal isn't to be on the fediverse instead of Instagram. It's to be on the fediverse before you need it to be your primary channel — so that if that moment comes, it's a transition rather than a crisis. Build the backup while the primary still works. That's not a contingency plan. That's what infrastructure looks like. ## Tools at a glance **Mastodon** — Federated microblogging on ActivityPub. Find a public instance or host your own. Use for public-facing movement communication and as a destination when centralized platforms fail. joinmastodon.org **Bluesky** — AT Protocol-based platform with 41+ million users. Strong audience portability by design. Currently the best federated option for reach alongside infrastructure resilience. bsky.social **Matrix/Element** — Federated, end-to-end encrypted messaging for internal coordination. Self-hostable. The right alternative to Slack or WhatsApp for sensitive organizing conversations. element.io / matrix.org **Ghost** — Open-source publishing platform for owned newsletters and publications. Self-hostable, ActivityPub-compatible, RSS-native. The right alternative to Substack for organizers who need to own their publishing infrastructure. ghost.org --- *This article is part of* [*Building a Movement*](https://the-community-playbook.org/building-a-movement-that-can-act/)*, an eight-part series on digital infrastructure for the pro-democracy movement.* ### The strike card problem: building commitment infrastructure for large-scale action URL: https://the-community-playbook.org/the-strike-card-problem-building-commitment-infrastructure-for-large-scale-action/ Last updated: 2026-06-12T19:20:58.000Z There's a meaningful difference between signing a petition and stopping work. Both are acts of political will, but only one requires you to risk something — your paycheck, your job, your relationship with your employer. That difference is the organizing gap that every strike card, every pledge form, and every "economic blackout" campaign is trying to close. The U.S. pro-democracy movement has spent the last year running repeated experiments in large-scale coordinated action. Some have worked. Many haven't — or have worked partially, at local scale, while failing to replicate nationally. The lessons from those experiments are now visible, and they point toward a clear conclusion: a true general strike doesn't get called into existence by social media momentum. It requires a specific kind of infrastructure that most of the current movement is still building. This article is about what that infrastructure looks like, why it's harder to build than it appears, and what the movement's most successful recent experiments can teach us about how to get there. ## The petition problem General Strike US has framed its strike card as a commitment mechanism: sign a card, receive SMS and email updates, and be counted toward the 11 million — roughly 3.5% of the U.S. population — that the organization has set as its threshold for calling a strike. The theory is coherent: build a database of committed participants large enough that the action becomes self-executing when the threshold is reached. The problem is that a signature, even one accompanied by a phone number, is not the same thing as a commitment. Petition signing is a low-friction act that happens in an emotional moment and requires no follow-through. The gap between "I signed a strike card six months ago" and "I am not going to work today" is enormous, and no amount of email follow-up fully closes it. Kim Moody, one of the leading writers about mass strikes in the U.S., puts it plainly: "General strikes or mass strikes are seldom simply 'called' from above — and those that are tend to be called off just as easily." The strike card model is built on the premise that commitment can be aggregated nationally and then activated centrally. History suggests that's the wrong architecture. The January 30, 2026 national strike attempt proved the point in real time. A labor stoppage was called for January 30, but it never materialized to any significant extent. Some cities saw localized strikes, including school district closures in Colorado, but the national action did not cohere. One week earlier, something very different had happened in Minnesota. ## What Minnesota actually did The mobilization of approximately 50,000 people across Minneapolis on January 23, 2026 represented the first large-scale general strike in the United States in nearly 80 years. What began as a coordinated labor response to escalating federal immigration enforcement operations transformed into a complex exercise in multi-sector labor organizing, coalition building across institutional and grassroots boundaries, and strategic use of economic disruption to challenge federal authority. The organizing timeline was short — weeks, not months. The action was organized by a local chapter of Indivisible, a grassroots group of volunteers dedicated to civic engagement, alongside labor unions and community organizations. What made it work was not a national database of pledges. It was pre-existing relationships between organizations that already knew how to move their people. Labor unions, community organizations, and faith leaders came together to call for a general strike and statewide demonstrations. Hundreds of small businesses, community organizations, and cultural institutions across the Twin Cities and greater Minnesota pledged to close or adjust operations in solidarity with the strike, many citing concerns over the impact of ICE operations on immigrant communities and local civil liberties. That's the structural difference. Minnesota had what the national movement lacked: accountability structures. When a union calls on its members to walk out, a faith community asks its congregation to stay home, or a local business network commits to closing — those are commitments embedded in relationships with real social consequences for non-compliance. The person who signed a national strike card in October and then quietly went to work in January faced no such accountability. The Minneapolis worker whose union steward was watching the picket line faced a very different calculus. An ICE official noted ahead of the action: "What we've seen that's a bit different here \[from immigration raids in other cities\] is the organization of some of the groups. The groups are a bit better organized. They've got some excellent communications." Excellent communications built on pre-existing organizing relationships, not a sign-up form. ## The three components of commitment infrastructure The Minnesota experience points toward what commitment infrastructure actually requires. It has three distinct components, and national-scale general strike organizing tends to underinvest in all three. **Geographic anchoring.** The unit of accountability in a strike is local. Workers show up or don't show up in a specific workplace in a specific city. Businesses close or stay open on a specific block. The organizing that makes those decisions happen is relational and local — it cannot be substituted for by national communications infrastructure. This means that commitment infrastructure has to be built at the neighborhood, workplace, and district level first, with national coordination layered on top. **Sector organization.** A tiny centralized group calling a general strike rarely has the capacity to echo across a country with nearly 350 million people. What creates economic disruption is participation by workers in sectors that are economically central: transportation, logistics, healthcare, education, hospitality, food service. Organizing those sectors requires working through existing labor institutions — unions, worker centers, trade associations — because those are the organizations that already have relationships with workers and mechanisms for collective decision-making. A pledge database that bypasses existing labor organizations isn't a strike infrastructure; it's a contact list. **The cascade activation problem.** Even with geographic anchoring and sector organization, a truly national simultaneous action requires a reliable activation mechanism — a way to move a signal from the decision to act to hundreds of local networks within hours. This is the piece the movement has talked about least and built the least. Minnesota succeeded in part because the organizing was local enough that activation could happen through pre-existing communication channels. A national action requires something more: a tested, redundant communication cascade that organizers at every level have practiced in advance. ## The subpoena problem no one wants to talk about There's a fourth component of commitment infrastructure that is rarely discussed publicly because it's uncomfortable: data security for commitment databases. A database of people who have pledged to participate in a strike is a legally sensitive document. General Strike US's strike card page notes that participant data will never be shared or sold. That's a privacy policy, not a legal protection. A federal grand jury subpoena seeking the names and contact information of committed strike participants is a real possibility, particularly in the current enforcement environment — and a privacy policy provides no protection against one. This isn't a hypothetical. Labor organizers have faced subpoenas for organizing records throughout U.S. history. Digital commitment databases make those records easier to subpoena and harder to protect than the paper files of earlier eras. The General Strike US organization has been notably thoughtful about this in their public-facing process documentation — establishing transparency about what they hold and how it's handled. But most local commitment infrastructure is being built without any consideration of subpoena risk. The practical implication: commitment databases should be designed with data minimization principles from the start. Collect the minimum information needed to maintain the commitment relationship. Use encrypted storage. Establish and document clear data retention policies. Understand that anything you collect about who has committed to strike action could be compelled in discovery, and design your data practices accordingly. ([Article 4 in this series, on digital security as organizing practice](https://the-community-playbook.org/digital-security-as-organizing-practice/), covers these principles in more detail for organizers who want to apply them.) ## What the South Korean model adds The December 2024 South Korean response to President Yoon Suk-yeol's martial law declaration offers a useful comparison case — not because the political contexts are identical, but because the coordination architecture was distinctive. The response was rapid and massive, with hundreds of thousands mobilizing within hours to surround the National Assembly and effectively reverse the martial law declaration. What enabled that speed was not a pledge database or a social media campaign. It was a combination of pre-existing labor infrastructure through the Korean Confederation of Trade Unions, established communication protocols among civil society organizations that had been maintained over years, and a clear, geographically specific objective (get to the National Assembly) that allowed autonomous local action to converge without requiring central coordination. The lesson is not that the U.S. movement needs to replicate South Korean conditions — it doesn't, and the political contexts are different enough that direct comparison is limited. The lesson is that rapid large-scale mobilization depends on infrastructure built before it's needed: trained networks, established communication channels, and autonomous local capacity to act within a shared framework. ## Building toward it The gap between where U.S. general strike organizing is now and where it needs to be is large, and it won't close through any single organizational initiative. But it can close through sustained, distributed infrastructure-building at the level where commitment is actually made and honored: locally, sectorally, relationally. May Day Strong, which organized the May 1, 2026 national day of action, explicitly positioned it as a "tactical escalation" and "economic show of force" — and organizers described it as a rehearsal for broader power-building ahead of the midterms. That framing is exactly right. Some organizers view May Day events as a dress rehearsal for something closer to a general strike in 2028 — but acknowledge that would require participation by large unions whose members may not yet feel prepared for such action or its potential political and employment consequences. That's an honest assessment of where the movement is. The infrastructure that would make a true general strike possible in 2028 has to be built between now and then. Here's what that building actually looks like in practice: **At the local level:** Build and maintain a list of organizations in your area — unions, faith communities, worker centers, business associations — that have committed to participate in coordinated action. Maintain that list actively, not just at moments of crisis. Establish and test communication protocols with each of those organizations so you know how to reach them when you have hours, not days. **At the sector level:** Identify the economic sectors in your area where participation would matter most and begin building relationships with worker organizations in those sectors now. This is slow, relationship-intensive work that can't be compressed into a crisis window. **On activation:** Design and practice your communication cascade before you need it. Know who calls whom, in what order, through what channels, with what backup if the primary channel fails. Run drills. The Minnesota organizers who were praised for their "excellent communications" didn't develop them in January 2026. **On data security:** Build your commitment infrastructure with the assumption that it could become a legal target. Minimize what you collect, encrypt what you store, document your data practices, and consult with legal support organizations before a crisis rather than after one. The strike card is a useful tool for building public momentum and tracking intent. It is not, by itself, commitment infrastructure. The difference between the two is relationships — and relationships are built through the slow, unglamorous work that makes action possible when a spark finally lands where there is fuel. --- *This article is part of* [*Building a Movement*](https://the-community-playbook.org/building-a-movement-that-can-act/)*, an eight-part series on digital infrastructure for the pro-democracy movement.* ### Coordinating without a center URL: https://the-community-playbook.org/coordinating-without-a-center/ Last updated: 2026-06-12T19:21:27.000Z Decentralization is a choice many movements make instinctively — and for good reason. A movement with no single headquarters has no single throat to choke. You can't take down a network by arresting its leader or deplatforming its main account if the network doesn't have one. Under the conditions of active suppression that this series has been addressing, resilience through distribution isn't just a preference — it's a survival strategy. But decentralization creates its own problem. A network that can't be taken down can also fail to move. Thousands of autonomous local groups, each doing their own thing, aren't a movement — they're a lot of people who agree with each other. The difference between a distributed network and a coordinated movement is the infrastructure that connects them: shared protocols, communication channels that cross organizational boundaries, and a common understanding of what "acting together" means even when no one is in charge. This article examines what that infrastructure looks like in practice, through three cases that have worked it out in very different contexts: the No Kings coalition in the United States today, the Indivisible/50501/MaydayStrong coordination model, and the historical Solidarity movement in Poland. Each offers a different lesson about the relationship between decentralization and coordination — and all three point toward the same core principle: the goal isn't to eliminate the center, it's to make the center unnecessary. --- ## **The decentralization paradox** The tension is real and worth naming directly. A centralized organization is efficient — decisions get made, resources get deployed, everyone knows who to call. It's also fragile. A centralized organization can be decapitated, infiltrated, legally attacked, or simply exhausted. Movement history is full of organizations that fell apart when their leader was imprisoned, discredited, or burned out. Decentralized networks distribute that vulnerability. No single point of failure means no single point of attack. But they're genuinely harder to coordinate. If every local group decides for itself when to act, what to demand, and how to communicate, the result is noise — or worse, internal conflict that consumes energy that should be going outward. The way through this paradox isn't to pick one side or the other. It's to think carefully about what needs to be centralized and what doesn't. The answer, in every successful case: what needs to be shared is infrastructure and protocol, not control. --- ### **Case study: The No Kings coalition** The No Kings coalition didn't start as an organization. The 50501 Movement coined the "No Kings" brand and traces its origins to Reddit, where grassroots organizers began coordinating in late 2024\. From that informal beginning, it grew into something that has no clear precedent in American political history: a sustained, escalating, geographically distributed mass movement that grew with each iteration, reaching an estimated eight to nine million participants on March 28, 2026. What makes it instructive isn't the size — it's the structure. The movement's official pages and publicly distributed host toolkit frame No Kings as a people-powered, decentralized set of actions, providing guidance on safety, messaging, and event planning for local hosts rather than listing central leaders or a single organizing committee. That toolkit is the key artifact: a document that enables consistent action without requiring a chain of command. Its decentralized model — national branding and coordination, local execution and permit-holding — has proven resilient and scalable across three protest cycles. The branding is shared. The toolkit is shared. The date is shared. Everything else is local. The nokings.org platform functions as a national coordination tool for autonomous local chapters and activist groups to list events, share resources, and connect participants without requiring hierarchical organization. This is what digital infrastructure for a decentralized movement looks like in practice: a platform that makes it easy to join, easy to act, and easy to see that you're part of something larger — without routing everything through a bottleneck. The No Kings model shows what "coordinating without a center" means at the action level. The shared elements — brand, toolkit, platform, date — create enough coherence that millions of people can act simultaneously without requiring a single decision-maker to authorize each event. The local groups retain autonomy over everything that matters locally: who speaks, what the specific demands are, how the event is run. What they give up is very little. --- ### **Case study: Indivisible, 50501, and MaydayStrong** The No Kings coalition isn't a single organization — it's a coalition of coalitions, and how those organizations coordinate with each other is its own lesson. 50501 was born from social media rather than established organizations, but it's not leaderless. By the April 5 "Hands Off" protests — which drew an estimated 5.2 million people at 1,200 locations — the coalition included MoveOn, Indivisible, Women's March, labor unions, and environmental groups. But this coalition operates differently than traditional organizing structures: there's less top-down control and more working side-by-side. That distinction — side-by-side rather than top-down — is crucial. These organizations don't merge. They don't subordinate themselves to a central authority. They align on shared goals, coordinate on shared dates and messaging, and then each bring their own infrastructure, relationships, and capacity to bear. Different groups in different states emphasize distinct priorities, and 50501 commits to not telling "people what their demands should be." MaydayStrong, which organized around May 1, 2026, demonstrates the same principle extended to the labor dimension: millions of workers, students, and families taking coordinated action across the country, demanding a nation that puts workers over billionaires, refusing business as usual through "No School. No Work. No Shopping." Multiple organizations, multiple constituent bases, one day, aligned messaging — achieved without a unified command structure. What makes this coordination possible isn't a shared organizational chart. It's shared infrastructure: common platforms for listing and finding events, shared messaging frameworks that different organizations adapt to their audiences, and — crucially — relationships between organizers built up over time through repeated coordination. The infrastructure enables the relationships; the relationships make the coordination work. The practical lesson here is about what organizers sometimes call "connective tissue" — the organizations and individuals whose primary function is to span boundaries. Every large coalition has people whose job is essentially to be on everyone else's calls, translate between different organizational cultures, and surface conflicts before they become crises. This role is rarely glamorous and often underfunded, but without it, coordination collapses into parallel tracks that never actually intersect. --- ### **Case study: Solidarity in Poland** The historical Solidarity movement in Poland offers a different kind of lesson — what decentralized coordination looks like under conditions of active state suppression, without the digital tools that today's organizers take for granted. Solidarity was an extraordinary mobilization of citizens from all walks of life united in protest against living in a communist lie — a massive societal polity organized independently outside the realm of the state that encompassed a number of historical, cultural, philosophical and human experiences. At its peak it had ten million members. It survived martial law. It ultimately won. What held it together under suppression was not a hierarchy that could be maintained when leaders were imprisoned — it was a culture of decentralized self-organization. When hundreds of Solidarity leaders were rounded up and detained, the opposition movement survived: arrested leaders found themselves replaced by other activists who avoided detention and by a number of female organizers who took leadership positions in the underground press and other Solidarity structures. That resilience wasn't accidental. It was the product of a deliberate choice to build organizing capacity throughout the network rather than concentrate it at the top. It was the self-organizing experience gained during underground civil resistance, the well-developed underground press, and the extensive network of volunteers that gave Solidarity an important advantage over the communists. The Solidarity case also illustrates a failure mode worth noting: coordination without a mechanism for resolving conflict. By 1981, as the movement grew and the economic situation deteriorated, isolated strikes broke out across the country — but the Solidarity leadership made no attempt to coordinate them or unify demands. A decentralized network that lacks conflict resolution infrastructure can find itself moving in multiple directions at once, dissipating energy that might otherwise have been focused. Decentralization is not a substitute for governance; it's a different form of it. More recently, Poland has offered a contemporary lesson in digital coalition coordination. When half a million people converged on Warsaw in June 2023 to resist democratic backsliding, digital forms were used to survey participants on their motivations — women's health, education, immigrant rights, economic concerns — and that information was used to create campaign materials that reached different individuals while unifying them behind a shared opportunity. Digital platforms allowed participants to book seats on organized buses or carpool, while also preparing attendees for anticipated police action and helping them navigate quickly. Different organizations with different constituent bases, aligned on a shared moment, using digital infrastructure to coordinate logistics while preserving message diversity. --- ## **What these cases share** Three cases, three contexts, three different answers to the coordination problem — but the same underlying architecture. In each case, what enables coordination without a center is a combination of: **Shared infrastructure, not shared control.** The toolkit, the platform, the date, the communications channel — these are things that organizations and individuals can use without giving up their autonomy. The No Kings host toolkit doesn't tell local organizers what to demand. It tells them how to run a safe, effective event. That's the right division of labor. **Protocols, not permission.** In each of these cases, local groups don't ask for permission to act — they follow a protocol that tells them how to act in alignment with others. The difference is significant. Permission systems require a center; protocols distribute the decision-making. **Relationships as infrastructure.** The connective tissue between organizations — the people whose job is to span boundaries, translate, and surface conflicts early — is infrastructure as much as any piece of software. It's slower to build and harder to maintain, but without it, the tools don't matter. **Redundancy at every layer.** Solidarity survived martial law because organizing capacity was distributed throughout the network, not concentrated at the top. The No Kings coalition can lose its central platform and local chapters can still find each other. Redundancy isn't a backup plan — it's the design. --- ## **The tools that make this possible** The principles above require infrastructure to implement. A few categories of tools are doing most of the work in contemporary decentralized coordination: **Event aggregation platforms.** The nokings.org model — a platform where autonomous local groups can register and list events, making the whole visible without centralizing the parts — is the most important category for mass mobilization. Action Network offers similar functionality for coalition organizing, allowing affiliated organizations to share lists and coordinate actions without fully merging their data. **Coalition communication channels.** When organizations need to coordinate with each other rather than just run parallel actions, they need communication infrastructure that crosses organizational boundaries. Slack and Discord both work for this at the coalition level, though both carry the platform dependency risks covered in Article 1 of this series. For more sensitive coordination, Matrix/Element provides federated, self-hostable channels that don't route through a single corporate server. **Shared calendaring and action tracking.** Knowing what other organizations are planning — and when — is prerequisite to genuine coordination. Google Calendar's shared calendar feature handles this for many coalitions; Movement Calendar (movementcalendar.com) was built specifically for this purpose in the progressive organizing ecosystem. **Shared data standards.** The deeper form of interoperability — the ability for different organizations' systems to actually talk to each other — requires common data standards. In the progressive tech ecosystem, this is still underdeveloped. Action Network's open API allows some integration; the Movement Cooperative provides shared technical infrastructure for a consortium of organizations. But most coalitions still coordinate primarily through human relationships rather than system integration, which means the connective tissue problem never fully goes away. --- ## **Building for coordination before you need it** The hardest lesson from all three case studies is also the most actionable: coordination infrastructure has to be built during calm periods to function under pressure. The protocols have to be established, the relationships have to be formed, the platforms have to be tested, before the moment arrives when you need to move quickly. For any coalition or local group, this means a few concrete things. Have a communication channel with peer organizations in your coalition that isn't dependent on any single platform — and that you use regularly enough that people actually check it. Have a shared understanding with your closest coalition partners about what "coordinating on a day of action" means operationally: who contacts whom, how quickly, with what information. Know which of your members and staff serve connective tissue roles — and make sure they're supported rather than quietly burning out on all that relationship maintenance. And have a way to list your actions and find others' that doesn't require anyone's permission. The ability to say "here's what we're doing, here's when, here's how to join" — publicly, findably, in a way that aggregates with other groups' actions into something that looks like a movement — is one of the most basic functions of coordination infrastructure. It's also one of the easiest to build. The goal isn't a movement that acts because someone told it to. It's a movement that acts because the infrastructure made it easy for autonomous groups to align — and because the people in those groups trusted each other enough to do it. --- *This article is part of* [*Building a Movement*](https://the-community-playbook.org/building-a-movement-that-can-act/)*, an eight-part series on digital infrastructure for the pro-democracy movement.* ### Digital security as organizing practice URL: https://the-community-playbook.org/digital-security-as-organizing-practice/ Last updated: 2026-06-12T19:21:49.000Z *The movement is being watched. This is not paranoia — it is the operating environment.* In April 2025, Attorney General Pam Bondi rescinded the Justice Department's longstanding policy protecting journalists from subpoenas, clearing the way for federal prosecutors to demand records from news organizations and their service providers. In January 2026, FBI agents executed a search warrant at the home of a Washington Post reporter. The message was explicit: the government will use legal process to identify and expose people it considers threats, and the protections that once constrained that process have been removed. Journalists are not the only targets. Organizers, activists, and the organizations they build are equally exposed — often more so, because they have fewer legal resources and less institutional protection. The question facing every group working to build the pro-democracy movement is not whether to take security seriously. It is whether to build security into the movement's DNA before it's needed, or to scramble to address it after something goes wrong. The answer is before. But security done badly — as a checklist distributed at the beginning of a training and never integrated into how the organization actually works — is almost as dangerous as no security at all. What the movement needs is not a security checklist. It is a security culture. ## The threat model Security decisions start with understanding who you're protecting against and what they're after. This is called threat modeling, and it sounds more technical than it is. It's simply the practice of asking: what do we have that someone would want, who would want it, and what could they do to get it? For a U.S. pro-democracy organization operating in 2026, the realistic threat landscape includes: **Legal process.** Subpoenas, search warrants, and National Security Letters can compel organizations and their service providers to hand over data. This is not theoretical. The DOJ has demonstrated its willingness to use these tools against journalists; organizers should assume they are also in scope. What makes legal process particularly dangerous is that it reaches not just what you hold, but what your vendors hold — your email provider, your CRM, your messaging platform. **Platform exposure.** Every piece of organizing data stored on a commercial platform is subject to that platform's policies and legal obligations. When law enforcement requests data from Google, Meta, or a major CRM provider, those companies generally comply. Your contact lists, your message history, your event attendee records — all of it is accessible if the government asks for it and the platform cooperates. **Infiltration and social engineering.** Historically, the most effective attacks on social movements have come not from technical exploits but from human ones — informants, infiltrators, and people who misrepresent their intentions to gain access to sensitive information. Technical security cannot fully protect against this, but organizational security culture can limit how much damage any single compromise can do. **Data breaches.** Organizations that collect and store large amounts of personal data — contact databases, donor records, volunteer lists — are targets for theft as well as legal demands. A breach that exposes your members' information is a serious harm to those people and a potentially devastating blow to organizational trust. The good news is that the most effective security practices address all of these threats simultaneously, and they are not as technically demanding as most people fear. ## The most important security principle: don't collect what you don't need The data that causes you the most legal and security risk is data you've already collected. The most powerful security practice available to most organizations costs nothing and requires no technical expertise: collect less. General Strike US has built this principle into the architecture of their Strike Card program. They explicitly limit personally identifiable information to name and phone number — not address, not employer, not income, not political affiliation. Their reasoning is direct: they consulted with labor lawyers to develop a subpoena policy, and they've structured their data collection around the assumption that the government may one day demand their records. By minimizing what they hold, they limit what can be seized. This is called **data minimization**, and it should be the first question any organizing group asks when designing a new program, tool, or database: do we actually need this information? If someone doesn't need to know a volunteer's home address to assign them to a phone bank, don't collect it. If a petition doesn't need to capture occupation to serve its purpose, remove the field. If meeting notes don't need to name the people present, don't include names. The principle extends to retention. Data you no longer need is data that can still be subpoenaed, stolen, or leaked. Organizations should establish and practice data retention policies: how long do we keep contact records for people who never engaged further? How long do we keep communications records? The answer doesn't need to be "forever." ## Tiered security: not everything needs the same level of protection One reason security culture fails in most organizations is that it's presented as binary — either you're secure or you're not — which makes the whole enterprise feel overwhelming. The more useful frame is tiered: different information requires different levels of protection, and the goal is to match the protection to the sensitivity. Think about it in three tiers: **Public information** — anything the organization intends to make publicly available, including public statements, event announcements, published materials, and general organizational information. This needs basic security hygiene (strong passwords, two-factor authentication on publishing accounts) but doesn't require encrypted communications. **Organizational information** — internal communications, member databases, financial records, volunteer lists, meeting notes, strategy documents. This is the layer that most organizations leave underprotected. It doesn't need to be treated with the same care as highly sensitive information, but it absolutely should not live unprotected in personal Gmail inboxes or shared Google Drives with broad access permissions. Use organizational email rather than personal accounts, limit access to databases on a need-to-know basis, and use strong passwords and two-factor authentication everywhere. **Sensitive information** — anything that could put individuals at risk if disclosed: the identity of undocumented participants, whistleblower communications, direct action plans, information about people who are targets of surveillance or harassment. This tier requires genuinely secure communications tools and practices. It should be shared only with people who need to know it, and ideally not retained in writing at all. Most organizations over-protect their public information and under-protect their organizational information. The goal is to get the match right. ## Secure communication tools: what to use and when The most important communication security tool for organizers is **Signal**. Signal is an end-to-end encrypted messaging app that encrypts the contents of messages so that only the sender and recipient can read them — not Signal, not your phone carrier, not the government. It also retains very little metadata about who you communicate with. Signal should be the default for any organizational conversation that rises above the tier of fully public information. Set it as the standard for your team's internal communications. Not because every conversation is sensitive, but because making it the default means you don't have to make a judgment call about which conversations to protect. A few important Signal practices: - **Enable disappearing messages** for sensitive conversations. For a direct action, set messages to disappear within an hour or a day. For general organizing conversations, a week or a month is reasonable. Messages that no longer exist cannot be subpoenaed. - **Use it for calls as well as messages.** Signal's voice and video calls are also encrypted. - **Don't use it as a substitute for organizational security.** Signal protects message content, but it doesn't protect you if the person you're talking to is an informant or has their phone physically seized. **What about WhatsApp?** WhatsApp uses Signal's encryption protocol, so the contents of messages are secure. But Meta — WhatsApp's owner — collects extensive metadata about who you communicate with, how often, and what groups you're in. In 2024, Meta complied with 78% of government data requests. The content of your messages is protected; your social graph is not. If the people you're organizing with are unlikely to move to Signal, WhatsApp is significantly better than regular SMS or Facebook Messenger — but it is not a full substitute for Signal for sensitive work. **Email.** Standard email is not secure. It passes through multiple servers, is stored by your provider, and is accessible to law enforcement with a subpoena. For sensitive communications, use **ProtonMail** — an end-to-end encrypted email service based in Switzerland. Critically, ProtonMail's encryption only protects messages between ProtonMail users. Sending a ProtonMail message to a Gmail address is not encrypted end-to-end. For truly sensitive email, both parties need to use ProtonMail or a compatible encrypted email tool. **For documents and files.** Google Docs and Microsoft 365 are convenient, but they store your data on servers that are subject to legal requests. For highly sensitive documents, consider **CryptPad** — an encrypted, open-source alternative to Google Docs that cannot hand over your data because it cannot read it. For less sensitive organizational documents, the more important practice is access control: limit who can view and edit documents, don't leave broad sharing permissions open indefinitely, and remove access when people leave the organization. **Password management.** Weak passwords and password reuse are responsible for a significant share of organizational security breaches. Every person in your organization should use a password manager — **Bitwarden** (open-source, free for individuals) or **1Password** are the most widely recommended options. Every account should have a unique, strong password. Every account that supports it should have two-factor authentication enabled. ## The subpoena problem and what General Strike US got right The General Strike US subpoena policy is worth examining in detail, because it represents exactly the kind of organizational security thinking that most groups don't do. Their position is transparent and public: they collect only name and phone number, they store it encrypted, they have consulted with labor lawyers, and they have a published policy explaining what they will do if the government demands their data — including notifying Strike Card signers before complying. They also offer mail-in and in-person alternatives for people who don't want to submit information digitally at all. This is security as organizing practice. It's not just a technical configuration — it's an organizational commitment made visible to the people who need to trust the organization with their information. It answers the question that every potential member implicitly asks: what happens to my information if things go wrong? Every organizing group should be able to answer that question. If you can't answer it, that's a gap worth closing. The practical questions to work through: - What data do we hold about our members and participants? - Where is it stored, and who has access? - What would happen if we received a subpoena for it? - What would we tell the people affected? - What can we do now to minimize the risk? ## Organizational security culture vs. individual security checklists The reason most security training fails is that it treats security as a set of individual behaviors rather than an organizational culture. You can train every person in your organization on Signal, password managers, and data minimization — and six months later, most of them will have drifted back to their habits, because the organization's systems and norms haven't changed. Security culture means security is built into how the organization operates, not added as an individual responsibility on top of everything else. Some practical markers of security culture: **Organizational defaults, not individual choices.** Your organization uses Signal for internal communications, not because people remember to use it, but because that's what the team channel is. Your shared documents have controlled access, not because individuals think to restrict them, but because that's how your shared drive is configured. Defaults are more reliable than decisions. **Least privilege access.** People should have access to the information they need to do their work, and not more. A volunteer coordinator doesn't need access to the full financial database. A regional organizer doesn't need access to the contact records for every chapter nationally. This isn't distrust — it's limiting the blast radius of any single compromise. **Offboarding protocols.** When someone leaves your organization — for any reason — their access to organizational systems should be revoked promptly. Dormant accounts with active credentials are a common security vulnerability. **Regular review.** Once a year, someone should review who has access to what, whether all current tools are still appropriate, and whether there's information being retained that no longer needs to be. This doesn't need to be a technical audit — it can be a two-hour organizational review. **Security fatigue is real.** The organizations with the strongest security cultures are the ones that have made security the path of least resistance, not the ones that have made the strongest demands on individual behavior. If your security practices require heroic ongoing effort from every member, they will fail. The goal is sustainable habits. ## Where to start If your organization is starting from scratch on security, here is a prioritized sequence: **First, do these immediately:** Enable two-factor authentication on every organizational account. Set Signal as your team's default communication channel. Make sure everyone uses a password manager. These three steps take less than an hour and close the most common vulnerabilities. **Second, do these this month:** Audit what data you're collecting and where it's stored. Implement access controls on your databases and shared documents — not everyone needs access to everything. Establish a data retention policy: decide how long you keep different categories of information and stick to it. **Third, do these this quarter:** Develop an incident response plan — what do you do if you receive a subpoena, if someone's account is compromised, if a member's data is exposed? Run a tabletop exercise where you talk through a scenario. Brief your board or leadership on your security posture. Make sure people who handle sensitive information have received basic security training. **Resources that go deeper:** The Freedom of the Press Foundation's digital security guides are written for journalists but directly applicable to organizers. The Electronic Frontier Foundation's Surveillance Self-Defense (ssd.eff.org) is a comprehensive, accessible reference. Activistchecklist.org offers a prioritized, practical guide specifically for activists and organizers. Access Now runs a 24/7 Digital Security Helpline (accessnow.org/help) that provides direct support to civil society organizations facing threats. --- The movement cannot afford to treat security as someone else's problem, or as a technical specialty that requires a specialist, or as something to address after something goes wrong. The infrastructure of the movement — its contact databases, its communication channels, its relationships, its institutional knowledge — is exactly what hostile actors want access to. Protecting it is not a distraction from organizing. It is organizing. The DOJ has made clear it will use every legal tool available to identify and expose people it considers threats to the current order. The movement's response is not to go dark or go silent — public organizing, public protest, and public advocacy are not only legal but essential. The response is to be deliberate about what information exists, where it lives, who can access it, and how it is protected. To make security a practice, not a policy. To build it into the movement before the movement needs it. Because by the time you need it, it will be too late to build it. --- *This article is part of* [*Building a Movement*](https://the-community-playbook.org/building-a-movement-that-can-act/)*, an eight-part series on digital infrastructure for the pro-democracy movement.* ### From supporter to organizer: building the commitment pipeline URL: https://the-community-playbook.org/from-supporter-to-organizer-building-the-commitment-pipeline/ Last updated: 2026-06-12T19:22:08.000Z *The 3.5% threshold isn't a broadcast problem. It's a pipeline problem.* Erica Chenoweth's research on nonviolent movements is frequently cited as evidence that protest works — that if enough people show up, change follows. But the 3.5% figure describes *peak active participation*, not social media followers, not petition signers, not people who agree with you in a poll. It means people who are doing something: showing up, taking action, recruiting others, sustaining effort over time. The United States currently has tens of millions of people who oppose what is happening to their democracy. It does not have anywhere near 3.5% — roughly 11.5 million people — in active, sustained participation. The June 2025 No Kings protests drew an estimated 4 to 6 million people. The October wave reached close to 7 million. Both were historic. Neither crossed the threshold. The gap between where the movement is and where it needs to be is not primarily a messaging gap. It is a pipeline gap: the gap between the people who agree with you and the people who are with you. Closing that gap requires understanding that agreement does not produce action, and that action does not automatically produce organizers. There are three meaningfully different stages on the path from bystander to movement builder — and each transition requires something different from you, from your tools, and from your organization. ## Three stages, three transitions The language of "supporter" is used loosely in most organizing contexts, often to mean anyone who has expressed sympathy with the cause. That's too broad to be useful. A more precise framework distinguishes three roles: A **supporter** agrees. They follow your social accounts, open your emails, maybe sign a petition. They're with you in spirit, and their numbers are large. But their relationship to the movement is passive — they receive information; they don't produce action. An **activist** shows up. They attend events, respond to calls to action, write letters, phone bank, participate in rallies. They have crossed from passive agreement into active participation. This is the layer that Chenoweth is actually counting. Getting someone here is the first major transition. An **organizer** takes ownership. They recruit others, lead meetings, own a piece of the infrastructure. They are not just participating in the movement — they are responsible for it. They are the ones who make the movement durable, scalable, and able to function under pressure. Most organizing groups have supporters. Many have activists. Far fewer have developed the organizer layer that makes a movement self-sustaining. And the reason, in most cases, is that they're trying to jump directly from supporter to organizer — skipping the activist middle entirely, or asking too much too soon and losing people in the gap. The commitment pipeline is the system by which you manage all three of these transitions deliberately: moving people from passive agreement to active participation, and from participation to leadership. ## The first transition: supporter to activist The supporter-to-activist transition is primarily a friction problem. People who agree with you don't automatically show up — not because they don't care, but because the path from "I support this" to "I am doing something" involves real costs: time, uncertainty about what to do, unfamiliarity with the organization, social awkwardness about entering a new community. The first ask has to be small enough to be easy and specific enough to feel real. "Get involved" is not an ask. "Join us at our next meeting" is an ask, but it's a big one for someone who doesn't know anyone in the room. "Text your zip code to this number to find your nearest chapter" is a step. "Sign up here to get our weekly action alert with one concrete thing to do" is a step. This is the logic behind the **ladder of engagement**: a structured pathway of escalating asks that moves people up gradually rather than demanding immediate commitment. The Obama 2012 campaign, often cited as a model, used this framework extensively — beginning with Facebook follows and email sign-ups, then moving to low-stakes actions like signing a birthday card for the President, before eventually asking for volunteer time and donations. The idea was to never ask for more than the relationship had earned. For movement organizing, the same principle applies. Your ladder should be designed intentionally — not as a bureaucratic exercise but as a genuine theory of how you bring people in. What's the easiest thing someone can do to take their first step? What's the next thing after that? What does it look like when someone has crossed from supporter to activist, and what do you do to recognize and reinforce that crossing? **What digital tools support this transition:** *Email with segmentation.* The single most important tool for the supporter-to-activist transition is an email list — but not treated as a broadcast channel. Email becomes organizing infrastructure when you use it to segment: to know who opened your last three action alerts, who clicked the RSVP link, who has never engaged beyond the initial sign-up. Those are different people, and they should receive different asks. Every major email platform (Mailchimp, Action Network, EveryAction) supports basic segmentation; the question is whether you're using it. *Low-barrier action pages.* Digital action tools — petition platforms, letter-to-legislators tools, simple RSVP forms — serve a specific function at this stage: they provide easy first steps that also generate data. When someone completes an action, you learn they're willing to act. That's information you need to make the next ask. *Peer-to-peer texting.* Peer-to-peer texting — where volunteers send individually personalized messages rather than automated blasts — achieves response rates around 45%, compared to single-digit percentages for mass email. The major tools in the progressive organizing space include **Hustle**, **ThruText**, and **CallHub**, each of which lets volunteers send and respond to messages from a centralized platform without exposing their personal phone numbers. ## The second transition: activist to organizer This is the harder transition, and it's where most groups lose people who could become leaders. The activist-to-organizer transition requires a fundamentally different kind of ask. You're not asking someone to show up — you're asking them to be responsible for a piece of the movement. That requires trust in both directions: you need to trust them with real responsibility, and they need to trust that the organization will support them when things get complicated. The most common failure mode is what organizers sometimes call the "super-volunteer trap": a highly engaged activist is given more and more tasks without being given authority, training, or a clear role. They burn out and disengage, precisely because the organization valued their labor without investing in their development. Turning an activist into an organizer means deliberately developing them — giving them ownership of something real, connecting them to training and mentorship, and making their success visible to the organization. Peer-to-peer recruitment is at the core of this transition. The most effective organizers are people who recruit from their own networks — who bring in friends, family, and colleagues, not strangers. When you help an activist understand their social network as an organizing asset, and give them the tools and support to do relational recruitment, you've begun the transition to organizer. They're no longer just participating; they're responsible for someone else's participation. This is also where **structured onboarding** matters. The activist who shows up three times and then drifts away often does so because no one ever made explicit what the organization needed from them, what growth was available to them, or how to deepen their involvement. A structured pathway — a welcome call, a new-member orientation, a clearly described set of roles at different commitment levels — signals that the organization is serious about developing people, not just using them. **What digital tools support this transition:** *Organizing CRMs.* Contact relationship management software is the infrastructure that makes deliberate pipeline management possible. The difference between an organizing CRM and a generic email list is that a CRM tracks the relationship over time: when someone first joined, what actions they've taken, who their recruiter was, what role they play, whether they've been contacted recently and by whom. This is the data that lets you identify who is ready for the next ask and what that ask should be. The major options in the progressive organizing space each have distinct strengths. **Action Network** is free for basic use, open to progressive causes, and widely used by smaller groups and coalitions. It handles email, petitions, and event RSVPs well, with reasonable list management. It's not a full CRM — it doesn't track contact history the way dedicated organizing tools do — but for groups early in their infrastructure development, it's a practical starting point. **NationBuilder** is a more complete system: it combines a CRM, website builder, email and texting tools, and fundraising in one platform, which makes it popular with campaigns and larger advocacy organizations. The trade-off is cost and complexity. **Bonterra EveryAction** (formerly EveryAction, now part of the Bonterra family) is the enterprise-tier option, used by large nonprofits and national organizations; it has deep integration with NGP VAN and is built for organizations with dedicated data staff. For most grassroots groups, Action Network or NationBuilder is the right starting point; EveryAction makes sense when you've grown into needing its capabilities. | Tool | Best for | Trade-off | | ------------------------ | ------------------------------------------------- | ----------------------------------------------------------- | | **Action Network** | Smaller groups and coalitions; free for basic use | Not a full CRM — limited contact history tracking | | **NationBuilder** | Campaigns and larger advocacy organizations | Cost and complexity | | **Bonterra EveryAction** | Large nonprofits with dedicated data staff | Enterprise pricing; most powerful when you've grown into it | What all of these tools share — and what matters for this stage — is the ability to tag and track contacts by engagement level, assign follow-up tasks, and see who in your network has gone quiet and might need re-engagement. *Mobilize and event management tools.* **Mobilize** (now part of the broader progressive tech ecosystem) specializes in volunteer and event management: matching volunteers to opportunities, tracking attendance, and making it easy for people to find ways to plug in. It's particularly useful for organizations with multiple chapters or distributed events, where a single coordinator can't track every point of contact. Attendance at events is one of the clearest behavioral signals you have that someone is crossing from supporter to activist — and consistent attendance is often the precursor to an organizer conversation. *Structured onboarding workflows.* Most CRMs allow you to build automated email sequences triggered by a specific action — someone signing up as a volunteer, attending their first event, completing a training. These sequences don't replace human follow-up; they supplement it. A new volunteer who attends their first phone bank should receive an automated thank-you within an hour and a personal follow-up from their team leader within a day. The combination of digital systems and human contact is what makes onboarding feel like the beginning of a relationship rather than the processing of a form submission. ## The third layer: organizers who develop organizers A movement that requires staff to develop every new organizer will never scale. The multiplier effect — the thing that makes movements grow exponentially rather than linearly — comes when organizers develop other organizers. This is the hardest thing to systematize with digital tools, because at its core it's relational. But technology can support it. CRMs that track who recruited whom create a visible network of relationships; those records help you understand where your organizational density is and where the gaps are. Peer-to-peer texting and communication tools that let organizers reach out personally to their own recruits — rather than routing everything through a central communications team — reinforce the relational model at scale. The key digital infrastructure at this stage is whatever makes the organizer's job easier: tools that reduce the administrative overhead of managing a team so they can spend their time on relationship-building rather than logistics. Calendar and scheduling tools that handle meeting coordination, shared communication spaces (Slack, Signal groups) that keep teams connected between events, and simple tracking systems that make it easy to record conversations and follow-ups — all of these reduce friction for the organizer and make the work more sustainable. Re-engagement matters here too. People fall away from movements — not always because they've stopped caring, but because life intervenes, or because no one reached out when they went quiet. A simple CRM practice — reviewing who hasn't engaged in 60 days and reaching out personally — recovers people who would otherwise drift out of the pipeline. The organizer who checks in on someone who's gone quiet is doing one of the most valuable things in the movement. ## Building your pipeline The supporter-to-organizer pipeline isn't a technology problem. The tools support it; they don't create it. What creates it is a deliberate organizational decision: that developing people is as important as deploying them. That decision has some practical implications: **Map where people are.** Before you can move people along a pipeline, you need to know where they are. This doesn't require sophisticated software — it requires the discipline to track engagement. Who are your activists? Who among them might be ready for a bigger ask? Who has been active but has gone quiet? These questions should be answerable by your organization at any given time. **Design your asks intentionally.** Every communication your organization sends is an ask of some kind. Are your asks calibrated to where people are in the pipeline? Are you giving new contacts easy first steps, or asking for more than the relationship supports? Are you making the next step clear to people who are ready to go deeper? **Close the loop on every action.** Every time someone takes an action — attends an event, completes a phone bank shift, recruits a friend — someone in your organization should notice and acknowledge it. This sounds obvious; it happens surprisingly rarely. The acknowledgment doesn't need to be elaborate. It needs to be personal and prompt. **Treat re-engagement as normal operations.** People falling away from movements is not a failure — it's a normal feature of any large organization. The failure is not having a system for bringing them back. A monthly review of who has gone quiet, followed by personal outreach from someone who knows them, recovers more people than any broadcast campaign. --- The No Kings protests demonstrated that millions of Americans are willing to show up when the moment is clear and the ask is simple. That's the supporter-to-activist transition happening at scale. What the movement is still building is the activist-to-organizer transition: the layer of people who are responsible for others, who develop new organizers from their own networks, who hold the infrastructure together between the visible moments of mobilization. The 3.5% threshold is not just a number to hit on a single day. It describes a movement with enough organized depth to sustain pressure over time — enough people who are with you not just when it's easy, but when it's hard, when the cameras are gone, and when the next action needs to be built from scratch. Building that depth is pipeline work. And it starts with knowing where everyone is and what they need next. --- *This article is part of* [*Building a Movement*](https://the-community-playbook.org/building-a-movement-that-can-act/)*, an eight-part series on digital infrastructure for the pro-democracy movement.* ### The activation problem: how movements respond at speed URL: https://the-community-playbook.org/the-activation-problem-how-movements-respond-at-speed/ Last updated: 2026-06-12T19:22:45.000Z In the early weeks of December 2025, Operation Metro Surge descended on the Twin Cities. Federal agents — thousands of them — fanned out across Minneapolis and Saint Paul, detaining workers, breaking into homes, and circling schools. The Department of Homeland Security called it "the largest immigration enforcement operation ever." What they didn't account for was what had been quietly built in the years before they arrived. Within twelve minutes of an ICE operation being reported at a manufacturing facility in St. Paul, trained community observers were on site. Within days, a coalition of over ninety immigrant, labor, faith, and legal organizations was coordinating a unified response. Within weeks, labor unions, community groups, and faith institutions had organized the largest coordinated work stoppage in Minnesota since the 1930s — what they called a "Day of Truth and Freedom" — drawing tens of thousands into the streets in temperatures as low as twenty below zero. This didn't happen because Minnesotans got lucky with the timing. It happened because they had built the infrastructure for it — patiently, deliberately, over years — before they needed it. That gap — between *having a network* and *being able to move that network within 48 hours* — is the activation problem. And it is the most dangerous gap in the current movement landscape. ## **The difference between a network and a deployable network** Most organizing groups have a network. They have email lists, contact databases, group chats, and social media followings. They have people who care and have said so. What most groups don't have is activation infrastructure: the systems, roles, and practiced workflows that allow a network to move together — quickly, clearly, and without improvising everything from scratch in the middle of a crisis. The distinction matters because crises don't wait for you to build capacity. Federal enforcement actions happen at dawn. Legislation advances on short timelines. The window for effective response to a breaking situation is rarely longer than 48 to 72 hours. If your infrastructure doesn't exist and function *before* a crisis, it won't function *during* one. Think of it as muscle memory. The workflows, communication channels, and role assignments that are practiced in ordinary times are the ones that hold together under pressure. The ones built in a hurry, in the middle of an emergency, are the ones that fail at exactly the wrong moment. ## **What Minnesota had built** The rapid response network that mobilized against Operation Metro Surge didn't emerge in December 2025\. The foundation it rested on had been under construction since the early 2010s. **Years of coalition alignment.** Beginning in the 1990s and early 2000s, during a period of conservative governance in Minnesota, unions and community organizations started asking a different question: not "how do we win our individual campaigns?" but "who are our long-term allies, and what are we trying to build together?" That alignment was formalized in 2011 as Minnesotans for a Fair Economy, a collaboration of labor, faith, and community organizations large enough to want to fight for significant change but honest enough to recognize they couldn't do it alone. The same relationships were activated in December 2025 — now operating under new names and with new urgency, but built on fifteen years of trust and shared practice. **Trained observer networks.** MONARCA — an arm of Unidos Minnesota — had been training community members as legal observers long before Operation Metro Surge. By the time the surge began, MONARCA had trained over 20,000 Minnesotans to observe federal immigration enforcement activities: when to document, how to de-escalate, what constitutional protections apply, and how to get information to families and legal teams quickly. When the rapid response line received a report of ICE activity, trained observers could arrive on-site in minutes — not because they improvised it, but because they had rehearsed it. **A coordinating network, not a single organization.** The Immigrant Defense Network (IDN) didn't try to run every response itself. It functioned as an umbrella and coordination layer for ninety-plus organizations, each with their own relationships, resources, and geographic reach. When the surge escalated, IDN didn't have to stand up new organizations from scratch — it activated existing ones. The signal moved through pre-existing channels to groups that already knew their role. **Practiced communication protocols.** Observers were equipped with secure, toll-free phone and texting options. Multilingual capacity was built into the network, not bolted on after the fact. Information flowed through communication channels that had been established and tested before the emergency. When the call for a Day of Truth and Freedom went out on January 13, 2026 — with ten days' notice, in the middle of winter — it was boosted by the same networks and channels that had been carrying information for months. Phone banking and canvassing immediately began in communities across the state. Ninety organizations had endorsed the call. The Minneapolis Regional Labor Federation, representing 175 unions and 80,000 members, formally endorsed the action two days later. The Minnesota AFL-CIO, with over a thousand affiliated locals, followed. Tens of thousands came out in -20°F temperatures. ## **The anatomy of activation infrastructure** What Minnesota built — deliberately, over time — can be understood as a set of interlocking components. Each is achievable at smaller scales. Taken together, they are what separates a network that can move from one that can't. **Pre-assigned roles.** Someone is always the first caller. Someone is always the coordinator who receives the report and initiates the chain. Someone is always responsible for the communication that goes out to the broader network. These roles don't need to be rigid, but they need to exist before the emergency, not be improvised during it. When the IDN rapid response team got to the Bro-Tex facility in twelve minutes, that speed was possible because the roles were already assigned and practiced. **Tiered cascade structure.** Information and activation signals don't travel from a single center to every member simultaneously — at scale, that doesn't work. Instead, they move in tiers: from a coordinating body to regional hubs, from regional hubs to local chapters or neighborhood networks, from local nodes to individual members. Each tier has clear responsibility and clear communication channels. The Day of Truth and Freedom moved through exactly this kind of structure, with unions and organizations taking responsibility for mobilizing their own members while the coordinating coalition held the overall frame. **Redundant communication paths.** What happens when your primary channel goes down, gets compromised, or is deliberately disrupted? Every activation system needs a backup — and the backup needs to be known and tested before it's needed. Minnesota's rapid response network used secure phone and texting options alongside email and organizational channels. When the situation escalated and communication became more fraught, the redundancy was already there. **Rehearsal as organizing.** MONARCA's training sessions weren't just education — they were practice runs for the real thing. The moment a thousand people filled a church in Roseville to train as legal observers, they weren't just learning skills; they were rehearsing activation. They were practicing the experience of showing up quickly, in numbers, in response to a signal. That rehearsal was part of what made the Day of Truth and Freedom possible. The movement had already practiced moving together. **Clear signal protocols.** How does an activation actually get triggered? Who has the authority to call it? What does a message look like that everyone recognizes as an activation call versus routine communication? Minnesota's organizers used a dedicated rapid response line. The call for January 23rd was issued by a named coalition with organizational authority. There was no ambiguity about what was being asked or who was asking. That clarity is itself infrastructure. ## **Building this at your scale** You don't need ninety organizations and fifteen years to begin building activation infrastructure. You need to start somewhere, and you need to start before you need it. **Map your existing network honestly.** Not who's on your email list — who would actually show up within 24 hours if you called? Who has the relationships to bring five more people? Where are the nodes in your network that have genuine reach, and where are the gaps? This mapping exercise, done honestly, tells you where your real activation capacity is. **Assign roles explicitly.** Who is your first responder — the person who gets notified first and initiates the chain? Who owns communication to different segments of your network? Who has relationships with coalition partners who could amplify an action? Write these down. Make sure the people in those roles know they're in them and have agreed to be. **Test your communication channels before you need them.** Send a test message through your emergency channel and see who responds, in how long. Run a practice activation — "if we needed to notify everyone in our network right now, how would we do it?" — and measure where it breaks down. The failure modes you discover in a drill are much less costly than the ones you discover in a crisis. **Build relationships across organizational lines before the emergency.** Minnesota's response worked because unions trusted community organizations and vice versa — and that trust came from years of working together on overlapping campaigns. The time to build those relationships is before you need them for something high-stakes. If you don't know the other organizations in your coalition well enough to call them at 6am, you don't have a coalition — you have a list of endorsers. **Make rehearsal part of your regular organizing.** Every training, every turnout operation, every rapid-response drill is also a rehearsal for activation. The muscle memory you're building in ordinary times is the muscle memory that will function under pressure. ## **The Minnesota lesson** By February 2026, Operation Metro Surge had ended — federal agents began withdrawing from Minnesota, and the Trump administration cited a need to "turn down the temperature." The sustained, escalating resistance from below had forced a retreat. That outcome wasn't guaranteed by the size of the state or the strength of its institutions. It was produced by the combination of community rage and organized infrastructure. The rage was the fuel. The infrastructure was what made it directional. The lesson isn't that Minnesota is special. It's that Minnesota built something over time that most states and most movements haven't built yet. The tools were not sophisticated. The technology was not cutting-edge. What made the difference was the patient work of coalition building, the deliberate practice of showing up together, and the insistence on building activation capacity before the crisis arrived. Every group working for change right now faces some version of the activation problem. The question isn't whether you'll need to move your network quickly — it's whether you'll have built the infrastructure to do it when the moment comes. The answer to that question is being determined right now, in the organizing you're doing or not doing today. --- *This article is part of* [*Building a Movement*](https://the-community-playbook.org/building-a-movement-that-can-act/)*, an eight-part series on digital infrastructure for the pro-democracy movement.* ### The infrastructure you own URL: https://the-community-playbook.org/the-infrastructure-you-own/ Last updated: 2026-06-12T19:23:10.000Z In September 2020, Facebook suspended the accounts of hundreds of organizations and individuals — days before a planned online action targeting the funders of the Coastal GasLink pipeline. The groups locked out included Greenpeace USA, Rainforest Action Network, Climate Hawks Vote, and dozens of Indigenous-led organizations involved in the Wet'suwet'en land defense. They were told the suspensions were the result of copyright violations. Facebook later called it a system error and restored most accounts. Whether it was an error, an automated enforcement cascade, or something else, the effect was the same: hundreds of organizers lost access to their primary communication infrastructure at the exact moment they needed it most. This wasn't an isolated incident. Progressive and social justice organizations have experienced page removals, algorithmic suppression, and account restrictions across every major platform — often without warning, often without explanation, and often at the worst possible time. The pattern is consistent enough that treating it as bad luck is no longer reasonable. The structural problem is this: most digital organizing infrastructure is built on rented land. And most organizers don't fully realize it until the landlord changes the locks. --- ## Rented vs. owned: what the distinction actually means When organizers talk about their digital presence, they tend to describe it in terms of what they have: a Facebook group with 4,000 members, an Instagram following, a YouTube channel with years of archived video. These feel like assets. In an important sense, they're not. **Rented infrastructure** is anything that exists at the discretion of a platform. You have access until you don't. The followers you've built, the group members you've cultivated, the content you've posted — none of it is yours in any meaningful sense. The platform can restrict your reach, suspend your account, change its terms, raise its prices, get acquired, or simply shut down. When that happens, you don't get a warning. You don't get a transition period. You get a notification, if you're lucky, and a process for appeal that may or may not result in restoration. **Owned infrastructure** is anything where you control the data and the access. You can export it. You can take it somewhere else. No third party can revoke it. Your email list is owned infrastructure — assuming you're on a platform that lets you export it, and assuming you actually do. Your domain name is owned. Your website, if it's on a platform you control, is owned. The relationship data you've collected and stored outside of any single platform is owned. The line isn't always obvious. Some tools feel owned but aren't. A Mailchimp list where your export is locked behind a paid tier you're not on is closer to rented than you might think. A Slack workspace on the free plan, where message history disappears after 90 days, is rented history. A Google Group is owned by Google. The test is always the same: *Can you take your data and leave?* If the answer is no, or not easily, you're renting. This distinction matters more right now than it ever has. Platform policies are shifting. Algorithms are increasingly opaque. Ownership structures at major tech companies have changed in ways that are not neutral for progressive organizing. The risk calculus has moved, and organizing infrastructure decisions made three or four years ago deserve a fresh look. --- ## What you should own There are three things every organizing operation — regardless of size or budget — should treat as non-negotiable owned infrastructure. **Your email list.** This is the single most important owned asset in digital organizing. An email address you've collected is a direct relationship with a supporter that no platform can take away. Unlike social media followers, your email subscribers opted in to hear from you specifically. Unlike algorithmic reach, email delivery doesn't depend on a platform deciding whether your content is worth showing. The critical word is *export*. An email list you can't export is not really owned. Before you invest further in building your list, verify that your email platform allows you to download a full subscriber export in a standard format (CSV is the universal standard). If it doesn't — or if that capability is locked behind a pricing tier you're not on — that's a risk worth addressing now, not when you need the list. **Your domain.** Owning yourgroup.org or yourmovement.net means your web presence isn't hostage to any platform. If you're operating primarily through a Facebook page or a Linktree, you don't have a web presence you own — you have a presence on someone else's property. A domain costs roughly $15 a year and is the foundation everything else can be built on. It's the lowest-cost, highest-leverage infrastructure investment available to a small group. **Your contact and member database.** The relationships your organization has built — volunteers, donors, advocates, coalition partners — represent years of work. That data belongs to your movement, not to whatever platform currently holds it. Even a simple, regularly updated spreadsheet stored somewhere you control is better than contact data that lives only inside a CRM you might not always have access to. The principle is basic: keep a copy you own of every relationship that matters. --- ## Platform redundancy: escape hatches, not exits None of this means you should abandon the platforms where your supporters and potential supporters actually are. Facebook groups remain one of the primary organizing spaces for many progressive communities. Instagram reaches audiences that don't read newsletters. YouTube hosts video content that organizers have spent years building. Leaving these platforms wholesale would mean abandoning real reach that took real work to build. The goal isn't to exit rented infrastructure. It's to make sure that losing any one platform doesn't end your capacity to organize. That requires building escape hatches — habits and structures that reduce your exposure before you need them. **Collect email before you count on a follower.** Every event, every action, every new point of contact is an opportunity to get an email address. If someone engages with your content on social media, invite them onto your list. If someone shows up to an action, capture their email. A social media follower is a relationship you're renting. An email subscriber is a relationship you own. **Establish a secondary presence on at least one alternative platform.** You don't need to be active everywhere. But having a presence on a platform outside the main commercial ecosystem — even a modest one — means you have somewhere to direct people if a primary platform fails. The federated social web (a topic for a future article in this series) exists precisely because centralized platforms are single points of failure. A presence there doesn't have to be large to be useful. **Keep institutional memory out of platform-only spaces.** If your organization's decision history lives in a Facebook group, your meeting notes are in Messenger threads, and your event planning exists only in platform event tools — you've made your institutional memory dependent on continued platform access. Move it somewhere you own: a shared document folder, a simple wiki, a note-taking system with export capability. The content doesn't have to be elaborate. It has to be somewhere you control. --- ## Data portability as a practice Owning your infrastructure isn't a one-time setup task. It's an ongoing practice. Data that isn't backed up recently isn't really backed up. A few specific habits make the difference: **Export your email list regularly.** Once a month is a reasonable minimum. Before any major action or campaign, do it again. An export that's six months old is better than nothing, but it's not a real safety net. **Know where your exports live and who can access them.** An export that lives only in one person's personal Google Drive is a single point of failure of a different kind. Organizational data should be in organizational storage — somewhere at least two people can reach independently. **Test your backups.** This sounds obvious and almost nobody does it. Open the export file. Confirm it contains what you think it contains. A corrupted or incomplete export discovered after a crisis is worse than no backup at all because it generates false confidence. **Use standard formats.** CSV files are readable by virtually every email platform, CRM, and spreadsheet tool. Proprietary export formats — files that only open in the platform that created them — create lock-in even after you've technically exported your data. When evaluating any tool, ask not just whether you can export, but whether you can export in a format that's usable elsewhere. --- ## Starting from where you are If you're reading this as the leader of a small volunteer-run group, the infrastructure gap might feel overwhelming. The answer is not to fix everything at once. It's to make one good decision this week. For most small groups, that decision is the email list. If you don't have one, start one. If you have one but can't export it, move to a platform that lets you. If you have one and can export it but haven't recently, export it today and set a reminder to do it again next month. That single change meaningfully reduces your exposure. The domain is the other high-leverage, low-cost step. If your group doesn't own its domain, that's a $15 fix with outsized protective value. For larger operations with staff and established infrastructure, the right starting point is an audit. Map what you own versus what you rent. Identify your single points of failure — the platforms where losing access would most damage your capacity to organize. Prioritize building redundancy in those places first. The goal isn't a perfectly resilient digital operation. It's an operation that can absorb a platform failure and keep moving. In the current environment, that's not a theoretical concern — it's a practical one. --- ## What comes next Ownership is the foundation. The articles that follow in this series go deeper into the specific tool categories that make up a full organizing infrastructure — communication platforms, mobilization tools, coordination systems, and more. In each case, the ownership question will be an explicit part of the evaluation: not just what a tool does, but whether you can leave it with your data intact. The infrastructure you build should belong to your movement. Build accordingly. --- *This article is part of [Building a Movement](https://the-community-playbook.org/building-a-movement-that-can-act/), an eight-part series on digital infrastructure for the pro-democracy movement.* ### The activist's digital toolkit: functions first, tools second URL: https://the-community-playbook.org/the-activists-digital-toolkit-functions-first-tools-second/ Last updated: 2026-04-08T12:00:08.000Z Every few months, a new platform launches with a promise to transform how activists organize. Every few months, someone shares a list of tools every movement needs. And every few months, organizers — already stretched thin — find themselves wondering whether they're using the wrong things, missing something essential, or simply falling behind. This is the wrong problem to be solving. Before the question of *which tools* comes the question of *what you need to do*. Functions are durable. Tools come and go, get acquired, change their pricing, shut down, or get banned. A movement that understands what it needs to accomplish can evaluate any tool — now or in the future — against a stable standard. A movement that just adopts tools because other movements are using them builds on sand. This article maps the core functions that digital organizing infrastructure needs to serve. It's the foundation for a series of articles in the Digital Tools section of The Community Playbook — each of which will go deep on a specific category of tools. The goal of this piece is not to tell you what to install. It's to give you a framework for thinking clearly about what you're building. If you haven't read [What is digital organizing — and why it's the infrastructure democracy needs right now](https://the-community-playbook.org/what-is-digital-organizing-and-why-its-the-infrastructure-democracy-needs-right-now/), that piece establishes why this infrastructure matters; this one maps what it needs to do. --- ## Scale is a lens, not a structure Activism exists on a spectrum. At one end: a single person with a cause and a phone. At the other: a national coalition moving millions of people across thousands of local chapters. Most movements live somewhere in between, and most movements grow — which means the digital infrastructure that works at one size eventually needs to work at another. The functions identified in this article apply across that entire spectrum. What changes with scale is not the *what* but the *how* — the complexity of the tools, the formality of the systems, and the resources required to maintain them. A coordination system for five people looks very different from a coordination system for five thousand, but both are doing coordination. Future articles in this series will note where tool choices differ meaningfully by scale. For now, the goal is to name the functions clearly — because clarity about function is what makes good tool decisions possible, at any scale. --- ## The core functions ### Communication Every organized effort requires communication — and communication does two distinct things that are easy to conflate and important to keep separate. **Broadcast** moves information from the center to the group: updates, calls to action, urgent alerts, event announcements. It's one-to-many, and its primary job is reach and consistency. Everyone needs to hear the same thing, in time to act on it. **Dialogue** moves information laterally: discussion, deliberation, feedback, questions, and the kind of horizontal connection that builds culture and trust. It's many-to-many, and its primary job is engagement and belonging. People who only receive broadcasts don't stay; people who are in conversation do. At small scale, a group text handles both. At large scale, you need systems capable of segmented messaging — reaching the right people with the right message — alongside channels that give members a place to talk to each other. The tools are different. The need to do both never goes away. --- ### Coordination Shared purpose doesn't automatically produce shared action. Coordination is the function that turns individual commitments into collective, organized effort: who is doing what, by when, and how do the pieces fit together? This includes scheduling, task assignment, workflow documentation, and the ongoing alignment that keeps people from duplicating effort or working at cross-purposes. It is less visible than communication and less dramatic than mobilization, but coordination failure is how movements lose winnable fights. The call-to-action that goes out to the wrong people. The volunteers who show up to the wrong place. The decision that three different people made differently because no one documented the first one. At small scale, a shared calendar and a group chat can carry most of this. At large scale, movements need explicit role definitions, documented workflows, and project management infrastructure that doesn't live inside one person's head. --- ### Mobilization Mobilization is the function that converts passive support into active participation — and then sustains it. This means recruiting new people into the work: finding them, making the ask, and getting them through a door. It also means turning out the people who are already with you: activating existing supporters for specific actions, events, campaigns, or moments that require numbers. And it means retention — because a movement that is always recruiting but never keeping anyone has a leaky bucket, not a growing base. At small scale, mobilization looks like personal outreach, word of mouth, and relationship-by-relationship recruitment. At large scale, it requires structured pipelines: systems for tracking who has been contacted, what they've committed to, whether they followed through, and how to re-engage those who fell away. The relational core doesn't disappear at scale — but it needs infrastructure to function at scale. --- ### Tracking & intelligence You cannot respond to what you don't see coming. Tracking and intelligence is the function of monitoring the information environment: legislation moving through committee, regulatory actions being drafted, opponents making moves, media narratives forming, disinformation spreading. It is about knowing what is happening — not after the fact, but in time to do something about it. At small scale, this can look like a handful of RSS feeds, some Google Alerts, and a habit of reading. At large scale, it requires coordinated monitoring across multiple people and channels, shared repositories for research findings, and rapid response protocols that connect what is seen to who needs to act on it. This function is often informal in small organizations and neglected in large ones. It shouldn't be either. Movements that are consistently surprised by their opponents are movements that are perpetually playing defense. --- ### Records & learning Every decision a movement makes, every event it runs, every campaign it wins or loses contains information that could improve the next one. Records and learning is the function of capturing that information — and actually using it. This includes meeting notes and decision logs, contact history and volunteer records, after-action reviews, and the accumulated institutional knowledge that allows an organization to function even as its membership changes. It is the function that prevents movements from starting over every election cycle, every new cohort of leaders, every time someone burns out and leaves. At small scale, a shared folder and consistent meeting notes can do a lot. At large scale, this function requires databases, formal knowledge management systems, and cultural practices — not just tools — that make documentation a habit rather than an afterthought. The political cost of neglecting this function is enormous and largely invisible. You can't see the decisions that weren't made well because no one remembered what had been tried before. --- ### Fundraising Movements run on relationships and commitment — and also on money. Fundraising is included here not because it's more important than the other functions, but because it is more often omitted from digital organizing frameworks, and because the consequences of that omission tend to be slow-moving and catastrophic. Without sustainable financial infrastructure, the other functions eventually collapse. Staff disappear. Tools go unpaid. Events don't happen. The work that was being done by paid people gets piled onto volunteers who are already stretched. At small scale, fundraising may be a donation link and a request. At large scale, it involves donor databases, recurring giving programs, fundraising campaigns integrated with other communications, and systems for acknowledging and retaining donors the way you acknowledge and retain volunteers. The relational principles are the same; the infrastructure is different. --- ### Storytelling & visibility Movements that can't tell their own story cede that ground to someone else — and in most political environments, that someone else is an opponent with more resources and fewer constraints on accuracy. Storytelling and visibility is the function of shaping public narrative: what your movement is, what it stands for, what it has accomplished, and why it matters. It includes press relationships, social media presence, owned media (your own website, newsletter, or publication), and the capacity to produce content that moves people — not just informs them. At small scale, this might be a social media account, a contact form for media inquiries, and someone who answers emails. At large scale, it requires coordinated content strategy across platforms, media relations infrastructure, and the capacity to respond quickly when a story breaks that intersects with your work. Visibility without substance is noise. Substance without visibility is silence. The goal is both: a movement that is doing real work and has the capacity to make that work legible to the audiences who need to see it. --- ## The tool-category matrix The table below maps each function to the categories of tools that serve it. This is a map, not a shopping list — the goal is to understand the landscape, not to adopt every category. Future articles in this series will go deep on each tool category, with enough detail to help you evaluate specific options and make decisions that fit your context and your scale. | Function | Tool categories | | ------------------------- | ------------------------------------------------------------------------------------------- | | Communication | Email platforms, SMS/text tools, messaging apps, broadcast channels | | Coordination | Shared calendars, task and project management, team messaging, document collaboration | | Mobilization | Organizing CRMs, event management, peer-to-peer texting, phone banking tools | | Tracking & intelligence | News aggregators, legislative trackers, social listening tools, alert services | | Records & learning | Note-taking and wiki tools, file storage, contact databases, after-action templates | | Fundraising | Donation platforms, donor CRMs, crowdfunding tools | | Storytelling & visibility | Social media platforms, website and publishing tools, graphic design tools, media databases | --- ## A note on tool fatigue The proliferation of tools marketed to activists is real, and it creates its own burden. New platforms arrive constantly. Established ones change their terms, raise their prices, or get acquired by owners whose values don't align with yours. Keeping up feels like a part-time job on top of the actual work. The answer is not to avoid tools — it's to adopt intentionally, starting from function. A movement that knows it has a coordination problem can evaluate project management tools against that specific need. A movement that doesn't know what it needs will adopt whatever is recommended by the loudest voice in the room, and wonder later why it didn't help. The articles that follow in this series are built around that principle. Each one focuses on a tool category, explains what it does and doesn't do, and offers a framework for deciding whether it belongs in your infrastructure — and if so, which option fits your situation. The goal is to help you choose, not to help you add. --- ## Building from function outward The goal is not a fully-equipped digital operation. It's a functional one — built around what you actually need to do. The framework above — seven functions, mapped to tool categories, applicable across the full range of activist scale — is a starting point. It won't tell you which tools to use. It will tell you what questions to ask before you decide. And in a landscape that changes as fast as this one does, knowing the right questions is more durable than knowing any particular answer. Infrastructure built from function outward tends to hold. Infrastructure built from tools inward tends to sprawl. Start with what you need to do. Everything else follows from there. ### What is digital organizing — and why it's the infrastructure democracy needs right now URL: https://the-community-playbook.org/what-is-digital-organizing-and-why-its-the-infrastructure-democracy-needs-right-now/ Last updated: 2026-05-10T21:55:20.000Z ## The asymmetry problem Authoritarian power has one decisive structural advantage over democratic movements: it doesn't need consensus to act. A regime can surveil, suppress, arrest, flood the information space with lies, and consolidate control — all before a democratic opposition has finished its first planning meeting. This isn't a flaw in democracy. The deliberation, the coalition-building, the respect for dissent — these are features. But they come at a cost: speed. The movements that have successfully defended or reclaimed democratic ground in the modern era have found ways to close that gap — to build infrastructure that is fast enough, distributed enough, and resilient enough to match the pace of authoritarian action. Increasingly, that infrastructure is digital. This article is about what that means, why it matters, and what it takes to build it. --- ## What digital organizing actually is > Digital organizing is the deliberate use of digital tools, platforms, and methods to build power, coordinate collective action, and sustain a movement over time. That definition has three parts worth examining separately. **Deliberate.** Digital organizing is not accidental. It is not the sum of everyone in a coalition posting their own content, maintaining their own contacts, and hoping the algorithm does the rest. It requires intention, strategy, and structure — decisions made in advance about what tools to use, how to use them, who is responsible for maintaining them, and what success looks like. **Power-building.** The goal of organizing — digital or otherwise — is power: the collective capacity to make change. Digital organizing that doesn't contribute to that capacity isn't organizing. It's activity. Follower counts, post impressions, viral moments — these can be useful signals, but they are not power. Power is what happens when coordinated people take coordinated action that produces real-world results. **Sustained over time.** Movements are not events. Digital organizing infrastructure must be built to last — to function during lulls as well as crises, to onboard new people continuously, and to preserve institutional memory when individuals burn out or move on. It's equally important to say what digital organizing is *not*. It is not "clicktivism" — the shallow substitution of online gestures for real action. It is not a social media strategy. It is not the province of tech experts. And it does not replace the relational, person-to-person work that has always been at the heart of organizing. What it does is extend and amplify that work — across distances, across time zones, and at a scale no field operation alone can reach. --- ## What it takes to build and maintain it One of the most common mistakes movements make is treating digital organizing as a single role — the job of whoever is youngest, or most comfortable with technology, or willing to do it. In reality, a functional digital organizing structure draws on at least three distinct layers of knowledge and skill, and no single person is likely to have all of them. **The strategic layer** is about power and purpose. Who are we trying to move, and how? What is our theory of change? How do our digital efforts connect to our campaign goals? This layer requires people who understand political context, message framing, and the difference between noise and signal. It's the layer that keeps digital activity tethered to real-world outcomes. **The technical layer** is about systems and security. Which platforms and tools do we use, and why? How do we manage our data responsibly? What are our digital security practices? Who maintains the infrastructure when something breaks? This layer doesn't require a software engineer — but it does require people who are curious, detail-oriented, and willing to learn. **The relational layer** is about people. How do we recruit, onboard, and retain volunteers in digital spaces? How do we make our digital organizing accessible to people with different levels of technical comfort? How do we maintain culture and connection across a distributed network? This layer is the most often overlooked and the most consequential. Digital infrastructure without people is just software. Good digital organizing structure distributes these roles deliberately and maintains them over time. It also grapples honestly with the equity question: not everyone has equal access to devices, connectivity, or the digital literacy these roles require. A movement that doesn't account for those barriers will replicate the exclusions of the broader society it's trying to change. --- ## Why it's essential for a pro-democracy movement The argument for digital organizing isn't primarily about efficiency, though it is efficient. It's about what is required to build power at the scale and speed that the current moment demands. **Scale.** Traditional field organizing is powerful — and irreplaceable. But it is geographically bounded and resource-intensive. A well-built digital organizing structure can reach thousands of people simultaneously across cities, states, and jurisdictions that no single field team can cover. It allows a movement to be everywhere at once. **Speed.** Modern threats to democracy move fast. Legislation is introduced and passed before communities have organized a response. Disinformation spreads before corrections can catch up. Arrests happen before networks can mobilize legal support. Digital infrastructure compresses the time between knowing about a threat and responding to it. **Resilience.** Centralized organizations are vulnerable. A distributed digital organizing structure — with many nodes, many leaders, and many redundant systems — is much harder to suppress. No single arrest, no single platform ban, no single infrastructure failure takes the whole network down. **Narrative power.** In the modern information environment, who tells the story first and how it spreads matters enormously. Digital organizing gives movements the capacity to shape narratives — to get their framing into circulation before authoritarian actors can define the terms. This is not spin. It is the difference between being heard and being drowned out. **Coordination.** Perhaps most importantly, digital organizing turns individual outrage into collective, strategic action. Anger is not power. Anger plus coordination is. Digital infrastructure is the connective tissue that makes coordination possible at scale. --- ## The urgency argument: time, scale, and the Venezuelan lesson Authoritarians understand something that democratic movements are still learning: the window between the moment harm is done and the moment organized resistance can respond is where they live. The goal is not just to suppress opposition — it's to act so quickly, and on so many fronts at once, that organized response is always a step behind. This is why the timing of infrastructure-building matters so much. Tools, relationships, and workflows that are built and practiced in calm times are the ones that function under pressure. A movement that tries to build its digital organizing capacity in the middle of a crisis will fail — not because the tools don't exist, but because the trust, the training, and the muscle memory don't. The Venezuelan opposition's experience in the July 2024 presidential election is a case study in what happens when a democratic movement builds that infrastructure in advance — and what it means when it works. Facing a regime that controlled the electoral council, the courts, the state media, and the security forces, opposition leader María Corina Machado built what became known as Operation 600K: a network of 600,000 volunteers organized into 60,000 groups of ten, stationed at polling places across the country. Their mission was to collect, photograph, and upload the official tally sheets — called *actas* — that each voting machine prints at the close of polls. These sheets, which carry a unique QR code and digital signature, are the official record of each precinct's vote. On election night, when the Maduro regime announced results claiming a narrow victory for the incumbent — results that contradicted what the opposition volunteers had seen and documented — the network activated. Volunteers transmitted, digitized, and uploaded tally sheets from more than 83 percent of the country's polling stations. The opposition published the results online, showing their candidate had won by a more than two-to-one margin. Independent observers, including the Carter Center and United Nations monitors, confirmed that the tally sheets published by the opposition were legitimate. > The regime controlled everything except the will of the people — and a distributed digital infrastructure built before the crisis that the people used to document it. The regime's response was to claim the electoral system had been hacked, then to launch a wave of repression against those who had made the documentation effort possible. More than 2,000 people were arrested. Machado went into hiding. But the evidence was already on the internet, in the hands of international observers, and beyond the regime's ability to suppress. Operation 600K succeeded not because the technology was sophisticated — it wasn't. It succeeded because the organizing was. The infrastructure existed before it was needed. The volunteers were trained. The workflows were practiced. The trust was built. When the moment came, the network moved with the speed and discipline of a system that had been ready. That is the standard. That is what digital organizing, at its best, makes possible. --- ## Digital organizing is not a substitute for offline organizing It needs to be said clearly: digital organizing does not replace field organizing, relational organizing, or any other form of movement-building that requires human presence and human connection. The mistake of conflating digital activity with organizing power is seductive and common, and it has cost movements dearly. The right frame is not digital *versus* offline. It's digital — and what it produces. A well-run digital organizing program drives real-world turnout. It recruits and sustains volunteers who show up. It raises the money that funds on-the-ground operations. It maintains the communication infrastructure that makes coordinated action possible. It documents injustice in ways that move people to act. None of that is an end in itself — it's infrastructure in service of power. The inverse is also true: offline organizing is stronger with digital infrastructure behind it. The phone banker who has a well-maintained contact list. The field organizer whose volunteers receive consistent, timely information through a shared channel. The legal observer who can upload documentation the moment an incident occurs. Digital organizing amplifies what people are already doing on the ground. These two forms of organizing are not in competition. They are components of the same system, and the system is weaker without either one. --- ## What this looks like in practice A functional digital organizing structure is not a single tool or platform. It is a system of interconnected capacities: ways to communicate, ways to mobilize, ways to manage data, ways to tell stories, and ways to do all of those things securely. What those capacities look like in practice — the specific tools, the frameworks for building them, the decisions that every movement needs to make — is the subject of the articles that follow in this publication. The Community Playbook exists to be a living resource for that work: practical, specific, and updated as the landscape changes. What this article has argued is the foundational premise: digital organizing is not a nice-to-have feature of a modern pro-democracy movement. It is load-bearing infrastructure. Build it before you need it. Maintain it when you do. The movements that have, have had a fighting chance. The ones that haven't have found themselves outpaced by the very forces they set out to resist. --- ## The work ahead None of this is easy. Digital organizing requires sustained investment — of time, attention, and resources — in systems that often feel invisible until they are needed. It requires building skills that many organizers don't yet have, and creating cultures of security and accountability that take real effort to maintain. It requires doing all of that equitably, in movements that are often stretched thin. But the alternative — continuing to fight a modern, digitally-empowered authoritarianism with the organizing infrastructure of a previous era — is not really an alternative at all. It is a concession. The tools exist. The knowledge exists. The examples of what is possible exist. What remains is the work of building, and the commitment to begin. ### Getting off Facebook: A practical guide to Bluesky URL: https://the-community-playbook.org/getting-off-facebook-a-practical-guide-to-bluesky/ Last updated: 2026-06-30T14:38:52.000Z **Bluesky: the Twitter rebuild that learned from Twitter's mistakes — including the algorithm.** *This is the second in a two-part series on leaving Facebook.* [*Part One covers setting up a Mastodon account.*](https://the-community-playbook.org/getting-off-facebook-a-practical-guide-to-mastodon/) --- Facebook has become harder to love. The algorithmic manipulation, the surveillance business model, the role it plays in spreading misinformation — many of us have been thinking about leaving for years. The problem is always the same: everyone we know is still there. This guide is for people who want to leave Facebook — or at least reduce their dependence on it — and want to bring their communities with them. It focuses on **Bluesky**, one of the two leading alternatives to Facebook and Twitter. (The other, Mastodon, is covered in Part One.) ## Bluesky vs. Mastodon: Which One Is Right for You? Before diving into setup, it helps to understand what makes these platforms different — and why you might want both. **Bluesky** feels like Twitter rebuilt from scratch. It's fast-moving, highly customizable, and has attracted a large, politically engaged user base — particularly among progressives who left Twitter after Elon Musk's takeover. If you want to reach a broad audience quickly and are comfortable with a social media feed that resembles what you already know, Bluesky is the easier on-ramp. **Mastodon** is something different. It's part of the "Fediverse" — a decentralized network of servers that talk to each other using open standards. There's no single company running it, no algorithm pushing content for engagement, and no venture capital looking for a return. It's slower, more intentional, and rewards a different kind of participation: thoughtful threads, genuine conversation, and community-building over follower counts. The two platforms don't connect to each other, so you can use both. Many organizers do. But if you're going to invest seriously in one, read on — this guide will walk you through Bluesky from account creation to your first week. --- ## Part One: Creating Your Account ### Step 1: Go to bsky.app Visit [https://bsky.app](https://bsky.app/?ref=the-community-playbook.org) and click **"Sign up."** You'll provide an email address, create a password, and choose a username. Bluesky will suggest a handle in the format **@yourname.bsky.social** — that's fine for most people. (Advanced users can later attach a custom domain as their handle, but that's optional and not something to worry about at the start.) **On usernames:** Choose something recognizable — ideally matching your handle on other platforms. Unlike Mastodon, you *can* change your Bluesky handle later, but starting with something consistent saves confusion. ### Step 2: Verify Your Email Check your inbox and click the confirmation link before doing anything else. ### Step 3: Set Up Your Profile Click your avatar in the bottom left corner (on mobile) or the left sidebar (on desktop), then select **Edit profile.** The fields that matter most: **Display name** — This can be different from your handle and can include spaces. It's what people see in timelines and replies. **Bio** — Two to four sentences about who you are and what you post about. Set expectations clearly. Something like: > *"Organizer and democracy advocate based in Phoenix. Here for the conversations that matter. I post about civic power, local politics, and building movements that last."* **Profile picture** — Upload something clear and recognizable, even at small sizes. Use an image at least 400×400 pixels. This is what people see in feeds and replies, so it matters more than your header image. **Banner image** — Optional but worth doing. Bluesky uses a 3:1 ratio — 1500×500 pixels works well. A photo, a simple pattern, or a plain color all look fine. ### Step 4: Privacy and Notification Settings Before you start following people, visit **Settings** (gear icon) and review: - **Who can reply to your posts:** Default is "Anybody." You can restrict this to people you follow if you want less noise early on. - **Direct messages:** Set who can send you DMs. "People I follow" is a reasonable default. - **Notifications:** Turn off email notifications immediately — they become overwhelming quickly. --- ## Part Two: The Follow Problem — and How to Avoid It This is the lesson most guides skip, and it's the most important one in this article. When you're new to Bluesky, you'll start getting followers quickly — especially if you've posted an introduction. The instinct is to follow back. **Resist it.** Here's why: Bluesky's default "Following" feed is strictly chronological — it shows every post from every account you follow, in the order they were posted. There's no algorithm filtering it down to what's most relevant to you. That means every account you follow adds direct volume to your feed. Follow 500 people — including the accounts that post 20 times a day — and your feed becomes a blur. Follow back indiscriminately, and within weeks you'll have a feed full of strangers whose content you didn't seek out, drowning out the people you actually want to hear from. The better approach: **Follow people because you want to read their posts** — not as a social courtesy. Bluesky culture is not Instagram. People do not generally expect a follow-back. Following someone is a statement about whose voice you want in your timeline, not a transaction. **Before following someone back, look at their profile.** Do they post frequently? Is the content relevant to your interests? If you're not sure, don't follow — you can always come back later. **Unfollow freely.** If someone you followed turns out to post too frequently or off-topic, unfollow. No notification is sent. No feelings are hurt. Your feed is yours to curate. **Use Lists instead of follows for accounts you want to monitor but not feature in your main feed.** Lists let you track what someone posts without adding them to your Following feed. More on this in Part Four. > **Already followed too many people?** Don't worry — you can recover. Go through your Following list and unfollow liberally. It feels awkward at first, but a clean, intentional feed is worth it. Alternatively, some users start fresh with a new account, being more deliberate the second time around. You're not alone in learning this the hard way. --- ## Part Three: One Account or Two? If you're using Bluesky both personally and for organizing work, you'll face a choice: one account for everything, or separate accounts? **For most people: one personal account.** Bluesky culture, like Mastodon's, expects whole humans. Users post about organizing, personal updates, what they're reading, and whatever else is on their minds — all from the same account. Trying to maintain two personal accounts gets exhausting and splits your audience. What does make sense is a **separate organizational account** for any group you lead or coordinate. An Indivisible chapter, a mutual aid network, a campaign — these need their own voice, separate from any individual. Organizational accounts should be: - Strictly for announcements, events, and calls to action - Accessible to multiple people in leadership (use a shared password manager) - Clearly distinct from your personal voice and opinions On your personal account, mention the org in your bio and repost their posts to amplify reach. **The exception:** Create a second personal account if you need a space for close friends and family, separate from your public organizing presence. --- ## Part Four: Building Your Feed Intentionally Bluesky's real power is in how much control you have over what you see. Used well, it's significantly better than any algorithmic feed. Here's the toolkit: ### The Following Feed This is your default timeline — a chronological list of posts from everyone you follow. Keep it manageable by being selective about who you follow. Think of it as your inner circle: the voices you genuinely want to hear every day. ### Custom Feeds This is Bluesky's best feature. Any user can create a feed — a curated timeline built around specific hashtags, keywords, or accounts — and share it publicly. You can subscribe to other people's feeds and pin them alongside your Following feed. To find feeds: tap the **Feeds** icon (or the # symbol on mobile) and browse or search. A few useful ones for organizers and activists to start with: - **Discover** — Bluesky's own feed of popular posts from outside your network. Good for finding new people to follow. - **Quiet Posters** — Surfaces posts from people you follow who post infrequently. Useful for not losing the voices that get buried. - **News** — Posts from news organizations and journalists. You can also search for feeds built around your specific interests — local community, issue areas, or professional topics. ### Starter Packs Starter Packs are curated collections of accounts (up to 150) grouped around a theme, often with recommended feeds included. They're one of the fastest ways to populate a new account with interesting people to follow. Find starter packs through the Bluesky Directory (bsky.directory) or when someone shares a link. When you open a starter pack, you can follow all accounts at once or browse and follow selectively. **Browse selectively** — following all 150 accounts from a starter pack carries the same feed-dilution risk as following back indiscriminately. ### Lists Lists are collections of accounts that generate their own chronological feed — separate from your Following feed. They're ideal for: - Tracking accounts you want to monitor but not follow (local elected officials, opposition groups, news outlets) - Creating a focused view for a specific topic or community - Organizing your follows into categories you can switch between To create a list: go to your profile, tap the **Lists** tab, and tap **New list.** --- ## Part Five: Making Your First Post Once your profile is set up, write a simple introduction post. Bluesky users use the **#Introduction** hashtag for this, and it's a genuine way for new arrivals to get discovered. Something like: > *"New to Bluesky. Organizer and democracy advocate from Arizona. Here to connect with people working on civic power, voting rights, and building movements outside surveillance platforms. Still finding my feet — say hello. #Introduction"* Don't overthink it. First posts are low-stakes. --- ## Part Six: Learning Bluesky Culture Bluesky has its own norms. Arriving aware of them helps. **Things that work here:** - Direct, conversational posts — Bluesky rewards clarity over performance - Replying to people and having actual back-and-forth conversations - Sharing links (unlike some platforms, Bluesky does not penalize posts with external links) - Using hashtags selectively — they're useful for discovery, but Bluesky isn't as hashtag-dependent as Mastodon - Reposting (boosting) with a comment to add context **Things that don't land well:** - Engagement bait ("Repost this if you agree!") - Automatic cross-posting from other platforms with no adaptation — people can tell, and it signals you're not really present - Expecting rapid follower growth from passive posting - Treating follows as social obligations **A note on content warnings:** Unlike Mastodon, Bluesky does not have a built-in content warning system for text posts. You can add a content warning to images and videos. For sensitive text topics, the common practice is simply to be clear in your first sentence — something like "Strong take on the immigration situation:" — so people know what they're getting before reading further. --- ## Part Seven: Your First Week Keep it light. Here's a simple framework: **Day 1:** Make your introduction post. Find one or two relevant starter packs and follow accounts selectively. Subscribe to two or three custom feeds. **Days 2–7:** Post two or three things — a link to something interesting, a short thought, a reaction to something in the news. Reply to a few people. See what the culture feels like. **Don't do yet:** Announce your Facebook departure. Import all your Twitter follows at once. Stress about follower counts. You're in what might be called "parallel play" mode — low pressure, just learning. Give it room to develop before you make any decisions about how much to invest here. --- ## A Note on Migration Strategy No one moves their social world overnight. A realistic timeline looks something like this: **Months 1–3:** Set up your account, learn the culture, post lightly, build a small following. Stay on Facebook in parallel. **Months 4–9:** Begin inviting your Facebook contacts to find you on Bluesky. Start cross-posting major announcements manually. Observe which communities form where. **Months 9–15:** Shift more of your organizing energy to Bluesky. Reduce Facebook activity. Evaluate what's working. **Month 15+:** You'll know whether Bluesky is your primary platform, a secondary one, or part of a multi-platform strategy. You don't need to decide that now. The goal isn't to delete Facebook tomorrow. It's to build something outside their walls so that when you're ready to leave — or if Facebook makes the decision for you — you have somewhere to go, and your community is there waiting. --- ## Sharing Your Bluesky Handle Your Bluesky handle looks like this: ``` @yourname.bsky.social ``` Share it in your email signature, on Facebook while you're still there, in newsletters, and anywhere else people might want to find you. Your profile is also accessible as a direct link: ``` https://bsky.app/profile/yourname.bsky.social ``` --- ## Go Deeper - [**Bluesky's official guide**](https://bsky.social/about?ref=the-community-playbook.org) — The basics, straight from the platform. - [**Clearsky**](https://clearsky.app/?ref=the-community-playbook.org) — A tool for understanding your account and your followers more deeply. - [**Deck.blue**](https://deck.blue/?ref=the-community-playbook.org) — A TweetDeck-style multi-column interface for Bluesky, useful once you're managing multiple feeds and lists. --- *Part One of this series covers creating a Mastodon account — how it differs from Bluesky, when to use each, and how to manage both during your Facebook migration.* ### The Facebook effect: Why Mastodon feels different — and why it matters for organizers URL: https://the-community-playbook.org/notes-from-the-editor-the-facebook-effect/ Last updated: 2026-05-10T22:20:24.000Z If you've recently made the move to Mastodon — or if you're thinking about it — you may have noticed something unexpected: you don't know what to say. It's not that you lack opinions. You have plenty. It's that something about the blank text field feels different, even a little disorienting. You might find yourself staring at it, unsure where to start. That's not a personal failing. It's the Facebook effect. ## What the Facebook Effect Is Platforms like Facebook were deliberately engineered to trigger rapid emotional responses — outrage, validation, fear, nostalgia — in quick succession. Every scroll was designed to pull you into reaction mode, not reflection mode. Over time, your brain adapted. It learned to expect that kind of fragmented, high-stimulation experience, and it rewired itself accordingly. The result? Many of us arrive on calmer platforms like Mastodon feeling scattered and unsure of ourselves. We're waiting for something to react *to*, because that's what years of algorithmic feeding trained us to do. When nothing comes — when the platform simply waits for *us* to show up with intention — it can feel almost unsettling. ## Why Mastodon Feels Different Facebook handed you content. Mastodon asks you to bring some. That's a much higher cognitive load than it sounds, especially when your attention is already fragmented. Mastodon doesn't have an algorithm curating outrage on your behalf. It doesn't serve you content designed to keep you scrolling. What it offers instead is something rarer and harder: a space where you actually have to decide what you want to say, who you want to talk to, and what conversations you want to join. That's the good news, even if it doesn't feel like it at first. ## It Gets Easier The disorientation tends to ease as Mastodon starts to feel like *your* space rather than a foreign one. Many people find that after a few weeks of intentional engagement, it actually helps restore a sense of calm and focus that years of Facebook eroded. A few things that help with the transition: **Start small.** Give yourself permission to post low-stakes observations — something you noticed, a question you're sitting with, a link you found interesting. You don't have to arrive with a manifesto. **Think conversation, not broadcast.** Facebook trained us to perform for an audience. Mastodon works more like joining a neighborhood conversation. The energy is different, and once you feel it, it's a relief. **Be patient with yourself.** The fragmentation you're feeling isn't permanent. It's withdrawal from a system that was designed to be hard to leave. Naming it helps. ## Why This Matters for Organizers If you're here because you care about community, democracy, or resistance to authoritarianism, the platform you use to communicate matters. Corporate social media platforms are not neutral infrastructure — they are owned by people with interests, and those interests don't always align with yours. Moving to decentralized, community-governed spaces like Mastodon is itself an act of organizing. It's choosing to build on ground you have more control over. It's practicing the kind of intentionality that resilient communities require. So if you're staring at that blank text field and wondering where to start — start there. Tell people you just arrived. Tell them you're finding your footing. That kind of honesty is exactly what Mastodon tends to reward. ### Getting off Facebook: A practical guide to Mastodon URL: https://the-community-playbook.org/getting-off-facebook-a-practical-guide-to-mastodon/ Last updated: 2026-06-30T14:42:10.000Z *This is the first in a two-part series on leaving Facebook.* [*Part Two covers setting up a Bluesky account*](https://the-community-playbook.org/getting-off-facebook-a-practical-guide-to-bluesky/)*.* --- Facebook has become harder to love. The algorithmic manipulation, the surveillance business model, the role it plays in spreading misinformation — many of us have been thinking about leaving for years. The problem is always the same: everyone we know is still there. This guide is for people who want to leave Facebook — or at least reduce their dependence on it — and want to bring their communities with them. It focuses on **Mastodon**, one of the two leading alternatives to Facebook and Twitter. (The other, Bluesky, is covered in Part Two.) ## Mastodon vs. Bluesky: Which One Is Right for You? Before diving into setup, it helps to understand what makes these platforms different — and why you might want both. **Bluesky** feels like Twitter rebuilt from scratch. It's fast-moving, algorithmically optional, and has attracted a large, politically engaged user base, particularly among progressives who left Twitter after Elon Musk's takeover. If you want to reach a broad audience quickly and are comfortable with a social media feed that resembles what you already know, Bluesky is the easier on-ramp. **Mastodon** is something different. It's part of the "Fediverse" — a decentralized network of servers that talk to each other using open standards. There's no single company running it, no algorithm pushing content for engagement, and no venture capital looking for a return. It's slower, more intentional, and rewards a different kind of participation: thoughtful threads, genuine conversation, and community-building over follower counts. For people migrating from Facebook specifically, Mastodon has a lot to offer. It's built around communities rather than viral moments. The culture values context and care. And the fact that no corporation owns it means you're not building your community on someone else's land — again. The two platforms don't connect to each other, so you can use both. Many organizers do. But if you're going to invest seriously in one, read on — this guide will walk you through Mastodon from account creation to your first week. --- ## Part One: Creating Your Account ### Step 1: Go to mastodon.social Visit [https://mastodon.social](https://mastodon.social/?ref=the-community-playbook.org) and click **"Create account."** You'll need to choose a username, provide an email address, and create a password. **On usernames:** Your handle will be @username@mastodon.social. Choose something recognizable — ideally something that matches your handles on other platforms. You can't change it later without creating a new account. ### Step 2: Verify Your Email Check your inbox and click the confirmation link before doing anything else. ### Step 3: Set Up Your Profile Click your profile picture, then select **Edit profile.** The fields that matter most: **Display name** — This can be different from your username and can include spaces or emoji. It's what people see in timelines. **Bio** — Two to four sentences about who you are and what you post about. Set expectations clearly. Something like: > *"Retired organizer in Los Angeles. Interested in community power, platform independence, and building resilient movements. Reader, writer, troublemaker."* **Profile picture** — Upload something clear and recognizable, even at small sizes. This is what people see in timelines and replies, so it matters more than your header image. **Header image** — Optional, but it makes your profile feel complete. Mastodon uses a 3:1 ratio — 1500×500 pixels works well. A landscape photo, a simple pattern, or even a plain color all look fine. Don't stress about this when you're starting out; your profile picture is more important. ### Step 4: Add Profile Metadata Mastodon lets you add up to four custom fields that appear as a table on your profile. This is a great place for: - **Pronouns:** she/her (or whatever applies) - **Location:** \[your city, state\] - **Link:** Your website or newsletter, if you have one This keeps your bio text clean while still giving people the context they want. ### Step 5: Privacy Settings to Consider - **Posting privacy:** Default to "Public" so your posts appear in timelines and searches. - **Suggest account to others:** Yes — this helps people find you. - **Require follow requests:** Probably not, unless you want to vet everyone who follows you. --- ## Part Two: One Account or Two? If you're using Mastodon both personally and for organizing work, you'll face a choice: one account for everything, or separate accounts? **For most people: one personal account.** Mastodon culture expects whole humans. Users here post about organizing, personal updates, books they're reading, and whatever else is on their mind — all from the same account. Your aunt can follow you and mute political hashtags if she wants; Mastodon makes that easy. Trying to maintain two personal accounts gets exhausting and splits your audience. What does make sense is a **separate organizational account** for any group you lead or coordinate. An Indivisible chapter, a mutual aid network, a campaign — these need their own voice, separate from any individual. Organizational accounts should be: - Strictly for announcements, events, and calls to action - Accessible to multiple people in leadership (use a shared password manager) - Clearly distinct from your personal voice and opinions On your personal account, mention the org in your bio and boost their posts to amplify reach. That relationship — you as an individual connected to but distinct from the organization — is exactly how it should work. **The exception:** Create a second personal account if you need a locked/private space for close friends and family separate from your public organizing presence. This is common for people with safety concerns or high-profile public roles. --- ## Part Three: Making Your First Post Once your profile is set up, write a simple introduction post. Mastodon culture uses the **#Introduction** hashtag for this, and it's one of the most-watched tags on the platform — a genuine way for new people to get discovered. Something like: > *"New to Mastodon. Still figuring out the culture here, but looking forward to conversations about organizing, community power, and building outside surveillance platforms. Based in Los Angeles. #Introduction"* Don't overthink it. First posts are low-stakes. --- ## Part Four: Finding People and Building Your Timeline Your timeline will be quiet at first. That's normal and expected. Here's how to build it up: **Follow hashtags** — this is one of Mastodon's best features, and it actually works. To follow a hashtag, click on it in any post, then hit the Follow button. A few to start with: - **#Organizing** — community and political organizing - **#MutualAid** — mutual aid networks and resources - **#CivicEngagement** — civic participation and democracy - **#FediTips** — tips for navigating Mastodon culture - **#Introduction** — find new people who are just arriving - **#\[your city\]** or **#\[your state\]** — local connections 💡 Start with five to ten hashtags. Too many will flood your timeline. **Search for people you already know** — journalists, activists, and writers you followed on Twitter or Facebook often have Mastodon accounts. Search their names or handles. **Reply to people** — engagement on Mastodon is built through conversation, not virality. If someone posts something interesting, respond thoughtfully. --- ## Part Five: Learning Mastodon Culture Mastodon has a distinct culture. Coming in aware of it will save you some stumbles. **Things that work here:** - Thoughtful posts with context and nuance - Using hashtags (they're genuinely useful for discovery) - Adding alt text to images (widely expected) - Using content warnings (labeled "CW") for politics, heavy news, or anything that might catch someone off guard — label them clearly, like "US Politics" or "Trump administration" - Replying to people and having actual conversations 🏷️ On Mastodon, using content warnings for politics and heavy news is genuinely expected, not just polite. Content warnings are built right into the post composer. When you're writing a post, look for a ****CW** button (sometimes labeled as a warning icon) in the toolbar below the text box. Clicking it adds a second text field above your post — that's the warning label. You type your brief descriptor there (like "US Politics" or "Trump regime") and your actual post content goes in the main box below. **Things that don't land well:** - Engagement bait ("Boost this if you agree!") - Cross-posting automatically from Twitter or Facebook (people can tell, and it signals you're not really here) - Announcing "I'm leaving Facebook!" before you've actually built anything here - Expecting Twitter-style rapid follower growth --- ## Part Six: Your First Week Keep it light. Here's a simple framework: **Day 1:** Make your introduction post. Follow 10–15 hashtags. Follow a few people whose work you know. **Days 2–7:** Post two or three things — a link to something interesting, a short thought, a reaction to something in the news. Reply to a few people. See what the culture feels like. **Don't do yet:** Announce your Facebook departure. Import all your Twitter or Bluesky follows at once. Stress about engagement numbers. You're in what might be called "parallel play" mode — low pressure, just learning. Your Mastodon conversations won't appear in your Facebook history; this is its own space. Give it room to develop. --- ## A Note on Migration Strategy No one moves their social world overnight. A realistic timeline looks something like this: **Months 1–3:** Set up your account, learn the culture, post lightly, build a small following. Stay on Facebook in parallel. **Months 4–9:** Begin inviting your Facebook contacts to find you on Mastodon. Start cross-posting major announcements manually. Observe which communities form where. **Months 9–15:** Shift more of your organizing energy to Mastodon. Reduce Facebook activity. Evaluate what's working. **Month 15+:** You'll know whether Mastodon is your primary platform, a secondary one, or part of a multi-platform strategy. You don't need to decide that now. The goal isn't to delete Facebook tomorrow. It's to build something outside their walls so that when you're ready to leave — or if Facebook makes the decision for you — you have somewhere to go, and your community is there waiting. --- ## Sharing Your Mastodon Handle Your full Mastodon address includes both your username and your server: ``` @yourusername@mastodon.social ``` Always share the full address — not just @yourusername. Because Mastodon runs on thousands of different servers, the server name is part of how people find you. Your profile is also accessible as a direct link: ``` https://mastodon.social/@yourusername ``` Use this link in email signatures, on Facebook while you're still there, in newsletters, and anywhere else you want people to find you. --- ## Go Deeper Mastodon has a learning curve, and this guide only covers the essentials. These resources will take you further: - [**Fedi.Tips**](https://fedi.tips/?ref=the-community-playbook.org) — An unofficial, human-written guide to Mastodon and the Fediverse. The best single resource for understanding the culture and unwritten rules. - [**An Increasingly Less-Brief Guide to Mastodon**](https://github.com/joyeusenoelle/GuideToMastodon/?ref=the-community-playbook.org) — A thorough community-written guide covering the philosophy and mechanics of the platform in plain language. Good for when you're ready to go beyond the basics. - [**Mastodon Quick Start Guide**](https://blog.joinmastodon.org/2018/08/mastodon-quick-start-guide/?ref=the-community-playbook.org) — The official guide from the Mastodon team. Covers account setup, hashtag strategy, and settings worth revisiting after your first week. - [**joinmastodon.org**](https://joinmastodon.org/?ref=the-community-playbook.org) — The official Mastodon home page. Most useful when you start inviting others to join — it helps people find the right server for their interests. --- *Part Two of this series will cover creating a Bluesky account — how it differs from Mastodon, when to use each, and how to manage both during your Facebook migration.* ### AI and chatbots in organizing: Using the tools we have to fight for the future we need URL: https://the-community-playbook.org/ai-and-chatbots-in-organizing-using-the-tools-we-have-to-fight-for-the-future-we-need/ Last updated: 2026-05-12T13:40:38.000Z 🔄 ****Editor’s Update — March 7, 2026** Since this article was published, a significant confrontation erupted between the Trump administration and Anthropic. At issue: Anthropic refused to allow Claude to be used for domestic mass surveillance or autonomous weapons systems. Defense Secretary Hegseth demanded unfettered Pentagon access, threatening to cancel Anthropic’s $200M contract and designate it a national security supply chain risk. When Anthropic held firm, President Trump directed all federal agencies to cease using its technology. Anthropic called the move “legally unsound” and pledged to challenge it in court. Despite the backlash, Claude surpassed ChatGPT and Gemini as the top AI app in over 20 countries. Meanwhile, OpenAI CEO Sam Altman rushed a deal to replace Anthropic on military networks — later admitting it “looked opportunistic and sloppy.” For organizers choosing an AI tool, this matters: Anthropic held to concrete ethical lines at real financial and political cost. We recommend using ****Claude**. The concerns about artificial intelligence are real and serious. AI systems amplify biases, threaten jobs and livelihoods, concentrate power in the hands of tech monopolies, enable unprecedented surveillance, and raise profound questions about creativity, labor, and what it means to be human. These are not problems to dismiss or minimize—they demand systemic solutions, democratic governance, and a fundamental reimagining of how technology serves society. But here's the uncomfortable truth we must confront: we cannot address these concerns while an authoritarian movement is dismantling the very institutions and protections that could regulate AI, protect workers, and ensure democratic control over technology. We need a functioning democracy to solve the problems AI creates. And right now, that democracy is under direct threat. This creates a strategic dilemma for organizers. Should we refuse to use AI tools on principle while our opponents use every available technology to suppress votes, spread disinformation, and consolidate power? Or should we pragmatically deploy these same tools to organize, mobilize, and fight back—while maintaining our commitment to eventually creating a more just and equitable technological future? I believe we must choose the latter. Not because AI is good, but because the alternative is worse. This article explores how organizers can thoughtfully use AI and chatbot tools while addressing legitimate concerns about surveillance and digital security. ## The Case for Using AI in Organizing **Capacity and Scale.** Organizing movements are almost always resource-constrained. We have fewer staff, less money, and less time than we need. AI tools can multiply our capacity—drafting social media posts, creating outreach materials, analyzing voter data, generating talking points, and automating routine communications. This isn't about replacing human organizers; it's about freeing them to do the work only humans can do: building relationships, having difficult conversations, and making strategic decisions. **Speed and Responsiveness.** Political moments move fast. A news cycle that once lasted days now lasts hours. AI allows us to respond quickly—generating rapid response materials, analyzing breaking developments, and adapting our messaging in real-time. When your opponents are using these tools to flood the zone with content, refusing to use them yourself is strategic disarmament. **Accessibility and Democratization.** Not everyone has the privilege of formal training in communications, policy analysis, or graphic design. AI tools lower the barriers to entry, allowing passionate volunteers to contribute meaningfully even without specialized skills. This democratizes the work of organizing and allows movements to tap into broader pools of talent and energy. **The Pragmatic Reality.** Whether we like it or not, AI is already embedded in the tools we use every day—email platforms, social media algorithms, donor databases, phone banking systems. The question isn't whether we'll use AI, but whether we'll use it consciously and strategically, or simply be subject to its effects without agency or awareness. --- ## Addressing the Concerns Using AI tools doesn't mean we abandon our values or ignore the harms these systems can cause. It means we use them thoughtfully, with clear-eyed awareness of their limitations and risks. **On Job Displacement:** Yes, AI threatens jobs, including in organizing and advocacy. The solution isn't to refuse to use AI—that won't stop the displacement. The solution is political: fighting for worker protections, universal basic income, strong unions, and democratic control over technology deployment. We need a government that regulates how corporations use AI, not one that accelerates corporate power. That's why defeating authoritarianism comes first. **On Bias and Accuracy:** AI systems do reproduce biases from their training data. That's why we never outsource judgment to AI. Use AI for drafting, research, and routine tasks—but always have humans review, edit, and make final decisions. Think of AI as an assistant, not an authority. And advocate for transparency, auditing, and accountability in AI systems, which requires democratic governance. **On Corporate Control:** Most AI tools are controlled by massive corporations with their own interests and agendas. This is a legitimate concern. But refusing to use these tools doesn't diminish corporate power—it just handicaps our movements. We must use available tools while fighting for public AI infrastructure, open-source alternatives, and regulation that serves the public interest. Again, this requires political power we currently lack. **On Environmental Impact:** AI training and deployment consumes enormous amounts of energy and resources. This is deeply problematic in a climate crisis. But the same logic applies: individual refusal doesn't solve the problem. We need political power to regulate AI energy use, mandate renewable energy, and transition our economy. We can't get there from a position of political defeat. --- ## Recommended AI Tools for Organizers Not all AI tools are created equal. Some prioritize user privacy and security more than others. Here are recommendations based on current capabilities, with attention to digital security concerns. ### **For General Purpose Text Work: Claude (Anthropic)** Claude (claude.ai) is currently the strongest choice for organizing work that involves writing, research, and analysis. Key advantages: - Strong capabilities for drafting communications, policy analysis, and strategic thinking - Better at following complex instructions and maintaining context through long conversations - Can work with documents, create spreadsheets, and handle multiple file formats - Anthropic has committed to responsible AI development, though all corporate commitments should be viewed skeptically - Paid plans offer better privacy protections and higher usage limits ### **Alternative: ChatGPT (OpenAI)** ChatGPT remains a viable option, especially the GPT-4 models. It's widely used and has a large ecosystem of integrations. However, OpenAI's close relationship with Microsoft and its aggressive commercialization raise some concerns. If you use ChatGPT: - Use the Plus or Team plans for better privacy - Be aware that conversations may be used for training unless you opt out - Don't input sensitive personal information or organizing plans ### **For Image Generation: Adobe Firefly or Midjourney** For creating graphics, social media images, and visual materials: - **Adobe Firefly** is trained on licensed content and Adobe Stock, reducing copyright concerns. Integrated with Adobe's creative suite. - **Midjourney** produces high-quality images but operates through Discord, which may raise security concerns for sensitive organizing work. ### **For Data Analysis: Claude or GPT-4 with Code Interpreter** Both Claude and ChatGPT can now analyze spreadsheets, run statistical analyses, and create visualizations. Claude's interface for working with data is generally cleaner, but ChatGPT's Code Interpreter has more advanced capabilities for technical users. Never upload sensitive voter data, donor information, or personal details to any AI system. ### **Tools to Avoid or Use with Extreme Caution:** - **Grok (X/Twitter):** Given the platform's current ownership and political alignment, this is not recommended for organizing work. - **Free or obscure chatbots:** Many have unknown security practices and data handling policies. - **Any chatbot for sensitive operational details:** Never input information about specific individuals, security plans, or tactical organizing details. ## Surveillance and Digital Security Concerns This is perhaps the most serious concern for organizers. We operate in an increasingly hostile surveillance environment, and AI tools create new vulnerabilities. Here's how to think about this: ### **Understand the Threat Model** Different organizing contexts require different security levels: - **Low sensitivity:** Public communications, general education, mainstream electoral work. AI tools are generally fine here. - **Medium sensitivity:** Coordinating protests, working with vulnerable communities, handling personal stories. Use AI tools but be very careful about what information you input. Never use real names or identifying details. - **High sensitivity:** Direct action planning, working with undocumented people, anything involving legal risk. Do not use commercial AI tools at all. Use encrypted communications and assume you're under surveillance. ### **Operational Security Best Practices** - **Use separate accounts.** Don't use your personal email or accounts for organizing work. Create dedicated accounts for movement work. - **Never input identifying information.** Don't enter real names, addresses, phone numbers, or other PII into AI systems. Use pseudonyms and generic descriptions. - **Understand data retention.** Most AI companies retain your conversations, even on paid plans. Assume anything you input could eventually be accessed by law enforcement through subpoena. - **Review and sanitize outputs.** AI-generated content may inadvertently include information you didn't intend to share. Always review before publishing. - **Use paid plans when possible.** Paid plans generally have better privacy protections and clearer terms of service. Free plans often explicitly use your data for training. - **Keep sensitive work offline.** For highly sensitive organizing, do not use any cloud-based tools. Use encrypted local storage and air-gapped devices where appropriate. (An air-gapped device is a computer or device that is completely isolated from the internet and other networks. It has no wireless connections and no physical network cables connected to it.) - **Know your rights.** Understand what legal protections exist for digital organizing in your jurisdiction. Consult with legal support organizations like the Electronic Frontier Foundation or National Lawyers Guild. ### **The Broader Digital Security Stack** AI tools are just one piece of digital security. Organizers should also: - Use Signal for sensitive one-on-one and small group communications - Enable two-factor authentication on all accounts - Use a password manager (Bitwarden, Proton Pass or KeePassXC) - Regularly update devices and software - Consider using a VPN for sensitive browsing (Mullvad or ProtonVPN recommended) - Encrypt hard drives and use full-disk encryption - Get training from organizations like EFF, Access Now, or local tech solidarity groups --- ## Practical Guidelines for AI Use in Organizing Here's a framework for deciding when and how to use AI tools: ### **Good Uses of AI:** - Drafting social media posts, emails, and public communications - Creating educational materials and explainers - Generating talking points and FAQ responses - Researching policy positions and analyzing legislation - Brainstorming campaign strategies and messaging approaches - Creating graphics and visual content for public campaigns - Analyzing aggregated, anonymized data ### **Bad Uses of AI:** - Inputting names, addresses, or identifying information about individuals - Planning or discussing tactics that could lead to legal jeopardy - Storing sensitive voter or donor data - Making final decisions without human review - Replacing genuine relationship-building and organizing conversations - Using AI to make decisions about people without their knowledge or consent > **The Human-in-the-Loop Principle:** Always remember: AI is a tool for augmenting human organizers, not replacing them. Every piece of AI-generated content should be reviewed, edited, and approved by a person who understands the context and stakes. AI can help you work faster and smarter, but it cannot replace the judgment, creativity, empathy, and strategic thinking that humans bring to organizing work. ## Conclusion: Fighting with What We Have The rise of AI is one of the defining challenges of our time. It will reshape work, creativity, power, and society in profound ways. We need strong democratic institutions to guide that transformation in service of justice and human flourishing, not corporate profit and authoritarian control. But we cannot build those institutions from a position of defeat. We cannot regulate AI if we've lost our democracy. We cannot protect workers if labor rights are dismantled. We cannot ensure equitable access to technology if wealth continues to concentrate in the hands of oligarchs. We cannot hold corporations accountable if government becomes their instrument rather than their check. So we face a choice: We can refuse to use AI tools on principle and watch our movements get outpaced by opponents who have no such scruples. Or we can use these tools strategically and thoughtfully—with clear awareness of their limitations and dangers—to build the power necessary to eventually create a better technological future. This is not a comfortable position. It requires us to hold two truths simultaneously: that AI is deeply problematic, and that we need to use it anyway. It demands both *pragmatism* and *principle*, both tactical flexibility and strategic clarity about our ultimate goals. But discomfort is where organizers live. We operate in the space between the world as it is and the world as it should be. We use imperfect tools to pursue a more perfect union. We make difficult compromises in service of larger victories. The question before us is not whether AI is good or bad. It's whether we will use every tool at our disposal to fight for a future where we have the democratic power to decide how AI and other technologies are developed, deployed, and governed. A future where technology serves human needs rather than extracting value from human labor. A future where the gains from automation are shared broadly rather than concentrated narrowly. A future where surveillance is limited, rights are protected, and power is distributed. That future is still possible. But we can only reach it by winning the immediate battles before us. And winning those battles means using the tools we have—including AI chatbots—with both strategic intelligence and moral clarity about why we're fighting in the first place. The future is not yet written. Let's use every tool we have to write it ourselves. ### Email recommendations for privacy & security URL: https://the-community-playbook.org/email-recommendations-for-privacy-security/ Last updated: 2026-05-10T22:34:32.000Z Email is the backbone of almost everything we do online — organizing, banking, volunteering, account recovery notices, and day-to-day communication. Because of that, **email privacy and security matter far more than most people realize**. For many of us, an email account isn’t just a mailbox. It’s the key that unlocks dozens (or hundreds) of other services. That makes choosing the right email provider one of the most important — and often overlooked — privacy decisions we make. This guide explains what to look for in a privacy-respecting email service, compares common options, and offers practical recommendations based on different needs. --- ## Why Email Privacy Matters Email accounts often contain: - Password reset links for other services - Sensitive personal or organizational communications - Attachments with private or identifying information - Long-term records that reveal patterns about your life or work If an email provider scans messages, monetizes user data, or has weak security practices, that information can be exposed — through advertising, internal access, data breaches, or legal requests. Strong email privacy isn’t about hiding wrongdoing. It’s about **reducing unnecessary access to your personal and organizational data**. --- ## What to Look for in a Secure Email Provider ### Strong Security Basics (Non-Negotiable) Any email service you use should support: - **Two-factor authentication (2FA)** - **Encrypted connections** (TLS) - **Account activity alerts** and clear recovery options If a provider doesn’t offer these, it’s not suitable — full stop. ### Privacy Protections That Actually Matter Beyond basic security, look for providers that: - **Do not scan email content for advertising** - **Encrypt email at rest** on their servers - Offer **end-to-end encryption** (E2EE), at least as an option - Are transparent about how they respond to legal requests These features determine whether your provider *can* read your email — not just whether they promise not to. ### Jurisdiction and Business Model Where a company is based — and how it makes money — affects privacy more than branding language does. - Advertising-based services are incentivized to analyze user data - Subscription-based services are usually more aligned with user privacy - Some countries have stronger privacy protections than others No provider is immune to law enforcement requests, but the **default level of access matters**. --- ## Recommended Email Providers (By Use Case) ### Best Overall for Privacy & Security **Proton Mail** **Why it’s recommended** - End-to-end encryption between Proton users - Zero-access encryption (Proton cannot read your mail) - No ads, no tracking - Strong reputation in privacy and security communities - Based in Switzerland, with strong privacy protections **Good to know** - The free tier is limited - Some advanced features require a paid plan - Searching encrypted mail is slower (a trade-off for privacy) **Best for:** People who prioritize privacy, activists, organizers, and anyone reducing exposure to large tech platforms. 👉 **Proton Mail Zero-Access Encryption (official support page)** — explains how Proton encrypts stored email so *even Proton can’t read your messages*. [Proton Mail Zero‑Access Encryption (security page)](https://proton.me/security/zero-access-encryption?utm%5Fsource=chatgpt.com) --- ### Mainstream but Less Private Options **Gmail** - Excellent spam filtering and reliability - Deep integration with Google services - Emails and metadata are scanned - Strong security, weaker privacy **Best for:** Convenience and ecosystem integration, not privacy-first use. **Outlook** - Solid security features and enterprise support - Less aggressive ad targeting than Google - Still cloud-scanned and subject to Microsoft policies **Best for:** Workplace use or Microsoft-centric setups that prioritize reliability. --- ### Apple Users **Apple Mail (with iCloud Mail)** - Strong device-level security - Features like Mail Privacy Protection - Standard email is not end-to-end encrypted - Best paired with a privacy-focused provider for sensitive communication **Best for:** Apple ecosystem users who want better privacy than Google with minimal setup. 👉 **Apple Mail Privacy Protection (official Apple privacy/legal page)** — Apple’s description of how Mail Privacy Protection works. [Apple Mail Privacy Protection (official Apple legal page)](https://www.apple.com/legal/privacy/data/en/mail-privacy-protection/?utm%5Fsource=chatgpt.com) --- ## Email for Groups and Organizations If you manage email for a group or organization, privacy and continuity matter even more. ### Use Role-Based Addresses Instead of personal emails, use addresses like: - info@ - admin@ - organizing@ This improves continuity and reduces dependence on any one person. ### Use a Shared Password Manager Store: - Email passwords - Recovery codes - 2FA backup keys This prevents lockouts when leadership or volunteers change. ### Avoid Personal Accounts for Group Email Using someone’s personal Gmail for group business creates: - Continuity risks - Privacy issues - Ownership confusion A dedicated account is safer and more professional. --- ## Practical Security Tips (No Matter What You Use) - **Turn on 2FA everywhere.** Use an authenticator app instead of SMS when possible. - **Use a unique password.** Never reuse your email password anywhere else. - **Review recovery settings.** Make sure recovery emails and phone numbers are current and controlled. - **Be careful with forwarding.** Auto-forwarding can silently leak sensitive information. --- ## Final Thought No email system is perfect — but **your choice affects how much data you give up by default**. For people and groups who care about privacy, civil liberties, or minimizing corporate and government access to personal communications, choosing a **privacy-first email provider** is one of the most impactful steps you can take.