Your organization
If this deployment has its organization directory turned on, the app can show you the shape of the organization it belongs to: the divisions, departments, teams and offices it is made of, who is in each of them, and where you sit in it yourself.
What it shows
- The chart. An indented tree you can open and close. Each box is a unit, with its label, how many people are in it, and who leads it.
- A unit. Its description, the path down to it from the top, its leads, and — if this deployment allows it — everyone in it with their job title there.
- A person. Which units they are in, which one is their main one, and their reporting line: the leads above them, nearest first.
- Search. Over usernames, display names, job titles and unit labels.
That last list is the whole of what can be searched here, and the reason is the same one there is no message search: there is nothing readable to index. A name, a place and a job title are all the directory holds about you — the same three kinds of thing a display name and a profile picture already are, and kept as openly.
What it cannot show
Anything anybody said. The directory is built from who is in which unit, which is a fact an administrator typed in. It has no connection to your conversations, and it could not have one.
Mentioning a whole team
Where the directory is on, the composer understands four handles:
| Handle | Reaches |
|---|---|
@team:roads | everyone in that unit |
@unit:roads | the same thing, if you prefer the word |
@all:roads | everyone in that unit and every unit under it |
@lead:roads | whoever leads it |
These are expanded by your app, before the message is sealed, into a list of people. That is not a detail: what a message is sealed to is what decides who can open it, so the expansion has to happen on your side of the encryption. The server publishes who is in which unit; your app decides who to seal to.
The consequence is worth knowing. If somebody joins the team a minute after you send, they are not a recipient of that message and cannot be made one — the same as if you had typed the names by hand. They will see everything sent after they arrive.
Job titles on cards
If the deployment turns it on, a profile card says "Head of Roads, Public Works" under the display name. It is read from the directory, so it cannot disagree with it, and it is as public as the chart is.
Who can see the membership
Two settings, and your operator has chosen between them:
- Everyone signed in can open a unit and read its roster. This is the usual answer for a company.
- Only whoever maintains the directory can read a roster. Everybody else sees the tree, the labels and the counts. This is the answer for an organization with a security-cleared team, a safeguarding team or a unit whose membership is itself sensitive.
The counts stay visible either way, deliberately: a box on a chart with no number in it invites the question far more loudly than a number does.
Last changed 2026-10-06