# Privacy plugin that makes it more difficult for admins to read PMs

**URL:** https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059
**Category:** Feature
**Tags:** personal-messages
**Created:** [June 6, 2017, 9:00pm UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059 "2017-06-06T21:00:39Z")
**Posts on this page:** 17
**Page:** 3

<div class="post-metadata">

### Author: ![Azareal](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@Azareal](https://meta.discourse.org/u/Azareal)
#### Post date: [August 23, 2017, 5:55am UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/41 "2017-08-23T05:55:58Z")

</div>

I’ve seen restrictions on admins before in other software, it almost always comes in the form of administrator permissions (vB, MyBB, etc.).  
They have 40 or so permissions which lock down exactly what an admin can and can’t do. The folks over at MyBB don’t think it’s enough and want to add even more permissions.

They even have an “account protection” system which prevents admins from modifying the account of the super admin, just in case an admin goes rogue.  
They come up with all sorts of ways to restrict admins to create an illusion of safety for the site owner, but at the end of the day, if you can’t trust an admin, then they shouldn’t be an admin.

If you think admins reading PMs is a problematic feature which invites snooping around PMs out of curiosity, then the ability to disable this feature entirely might be preferable to another set of lock and keys.  
Admins would still be able to poke around the database, if they think an investigation is in order. Perhaps, it could be a plugin, it would also be easier to implement.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [September 5, 2017, 11:29am UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/42 "2017-09-05T11:29:22Z")

</div>

> [@hutchinsfairy](#):
>
> we are, after all, still calling a Private Message.

Incorrect, we call them Personal Messages. If there is any place where the copy still says Private, we should change those as well. I can sweep the codebase tomorrow to check.

---

<div class="post-metadata">

### Author: ![hutchinsfairy](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/hutchinsfairy/32/103475_2.png) [@hutchinsfairy](https://meta.discourse.org/u/hutchinsfairy)
#### Post date: [September 5, 2017, 1:12pm UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/43 "2017-09-05T13:12:08Z")

</div>

Discourse may call them personal messages but you are the first person to use the term on this thread by the look of it.

I’m not at all sure what value that semantic hair splitting has anyway when talking about UX. Calling them Personal rather than Private doesn’t make me feel any better about people reading them.

---

<div class="post-metadata">

### Author: ![jcoates](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jcoates/32/78029_2.png) [@jcoates](https://meta.discourse.org/u/jcoates)
#### Post date: [September 5, 2017, 1:19pm UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/44 "2017-09-05T13:19:05Z")

</div>

My two cents…

1. Nice idea with the logs.
2. Accessing PM seems as good a place as any to give admins a quick reminder that they are using logged admin functions and what kind of logs Discourse keeps. This should probably have “don’t show me again” tick box or automatically expire after being tripped X times.
3. It sounds like you have admins who really shouldn’t be admins. This can happen for organizational reasons (VP or key investor wants to be an admin). Perhaps you can just edit the masthead in the about section to read “our team” rather than “our admins” then just list everyone you need to list prominently rather than your actual admins. Maybe all you really need to give them is a spot on the about page and a cool title.

---

<div class="post-metadata">

### Author: ![downey](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/downey/32/166878_2.png) [@downey](https://meta.discourse.org/u/downey)
#### Post date: [September 5, 2017, 8:13pm UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/45 "2017-09-05T20:13:11Z")

</div>

> [@hutchinsfairy](#):
>
> you are the first person to use the term on this thread by the look of it.

FWIW, interestingly enough I just came across the post below, today. 😉

> [@\[Free\] I will help you move from Google Groups to Discourse](https://meta.discourse.org/t/free-i-will-help-you-move-from-google-groups-to-discourse/65449/1):
>
> please send me a personal message

---

<div class="post-metadata">

### Author: ![techAPJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/techapj/32/342990_2.png) [@techAPJ](https://meta.discourse.org/u/techAPJ)
#### Post date: [January 29, 2018, 3:26am UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/46 "2018-01-29T03:26:32Z")

</div>

> [@tophee](#):
>
> Improve the audit trail, i.e. add the reading of others PMs to /admin/logs/staff\_action\_logs

This feature is now available, disabled by default. The relevant site setting is `log personal messages views`.

---

<div class="post-metadata">

### Author: ![outofthebox](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/outofthebox/32/83708_2.png) [@outofthebox](https://meta.discourse.org/u/outofthebox)
#### Post date: [January 29, 2018, 8:20pm UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/47 "2018-01-29T20:20:19Z")

</div>

Hi @techAPJ, where do I find this setting?

---

<div class="post-metadata">

### Author: ![downey](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/downey/32/166878_2.png) [@downey](https://meta.discourse.org/u/downey)
#### Post date: [January 29, 2018, 8:38pm UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/48 "2018-01-29T20:38:56Z")

</div>

Just go to the admin settings page and do a search for the option “log personal messages”.

---

<div class="post-metadata">

### Author: ![outofthebox](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/outofthebox/32/83708_2.png) [@outofthebox](https://meta.discourse.org/u/outofthebox)
#### Post date: [January 29, 2018, 8:53pm UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/49 "2018-01-29T20:53:44Z")

</div>

What am I doing wrong? 🙂

 ![log%20personal%20messages](https://global.discourse-cdn.com/meta/original/3X/b/b/bbf4898ae8a581939702bf99678f552f1a86d38a.png)

---

<div class="post-metadata">

### Author: ![vinothkannans](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/vinothkannans/32/86465_2.png) [@vinothkannans](https://meta.discourse.org/u/vinothkannans)
#### Post date: [January 29, 2018, 9:29pm UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/50 "2018-01-29T21:29:19Z")

</div>

You need to be in latest version of Discourse.

---

<div class="post-metadata">

### Author: ![tophee](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tophee/32/73406_2.png) [@tophee](https://meta.discourse.org/u/tophee)
#### Post date: [January 29, 2018, 10:51pm UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/51 "2018-01-29T22:51:13Z")

</div>

> [@techAPJ](#):
>
> disabled by default

Any specific reason why it’s not on by default, like all other logging of staff activity?

---

<div class="post-metadata">

### Author: ![techAPJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/techapj/32/342990_2.png) [@techAPJ](https://meta.discourse.org/u/techAPJ)
#### Post date: [January 30, 2018, 2:21am UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/52 "2018-01-30T02:21:07Z")

</div>

Hi Carson, this setting is now available on your Discourse instance. 🙂

---

<div class="post-metadata">

### Author: ![Mittineague](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mittineague/32/114259_2.png) [@Mittineague](https://meta.discourse.org/u/Mittineague)
#### Post date: [January 30, 2018, 3:41am UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/53 "2018-01-30T03:41:28Z")

</div>

> [@tophee](#):
>
> Any specific reason why it’s not on by default, like all other logging of staff activity?

An interesting question that I don’t know the answer to.

However, most Staff Actions are more or less non-routine. _But If_ looking at any message they look at is logged - including messages Staff would routinely read (eg. Flag, Staff group messages) - the Staff Actions Log would quickly fill up and bump the more rare actions off of the list thereby making it less useful. If only looking at messages where they normally wouldn’t be a topic user is logged, then I agree, logging the action could be a good thing.

---

<div class="post-metadata">

### Author: ![downey](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/downey/32/166878_2.png) [@downey](https://meta.discourse.org/u/downey)
#### Post date: [January 30, 2018, 4:31pm UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/54 "2018-01-30T16:31:13Z")

</div>

> [@Mittineague](#):
>
> including messages Staff would routinely read (eg. Flag, Staff group messages)

Right … I guess it turns on the actual definition of logging message reads “for **other** users/groups”. Hopefully it wouldn’t include stuff that the admin already has direct access or membership to.

---

<div class="post-metadata">

### Author: ![Cozdabuch](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/cozdabuch/32/139120_2.png) [@Cozdabuch](https://meta.discourse.org/u/Cozdabuch)
#### Post date: [February 6, 2018, 2:48am UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/55 "2018-02-06T02:48:10Z")

</div>

@jomaxro @sam @techAPJ  
Is there any way to get an option added to webhooks to secondary service or site mailing option that can be used to notify immediately selected users if this “logged action” happens, and if the logging setting is toggled off/on.

I’d like it for immediate accountability to other admins/staff.

This would be used in a business/elected representative group, so there’s no way to boot someone from staff role, but if it can be actively monitored it would prevent unnecessary temptation

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [February 6, 2018, 4:17pm UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/56 "2018-02-06T16:17:58Z")

</div>

> [@Cozdabuch](#):
>
> I’d like it for immediate accountability to other admins/staff.

This is going to require a plugin, I do not see this as something I would like to introduce into core right now.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [July 24, 2018, 7:37pm UTC](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059/57 "2018-07-24T19:37:43Z")

</div>



[Previous page](https://meta.discourse.org/t/privacy-plugin-that-makes-it-more-difficult-for-admins-to-read-pms/64059.md?page=2)
