Module M12 · Chat curfew
An adult cannot reach a young person at one in the morning, because the server will not carry it
Curfew here is not an opening time and a closing time. It is a set of scoped rules, resolved on the young person’s clock at the moment somebody presses send, and capped by a limit the organization itself cannot raise.
- Configured nothing?
- Chat is closed. That is the safe reading of “nobody has decided”.
- Two rules disagree?
- The one that closes chat wins, whatever its priority.
- Whose 21:00?
- The young person’s. Their chapter’s time zone, not yours.
Why it exists
Every organization already has a rule about late-night contact
It is written in a handbook, it is agreed at training, and it is enforced by the only person it constrains. That arrangement works for every volunteer except the one safeguarding exists to catch.
A policy is checked afterwards
Somebody notices a 1am message during a review, weeks later, if anyone reviews at all. By then the thing the policy existed to prevent has already happened.
A property cannot be checked afterwards
There is nothing to find, because the message was refused before it was written. The refusal is recorded; the contact never occurred.
And it protects the volunteer too
A leader who cannot message a young person at midnight also cannot be accused of having done so. The record answers the question either way.
How the decision is made
Three questions, asked in this order, every time somebody presses send
The order is the safety property. Because the closure question is asked before the priority question, no arrangement of rules an organization can write will open chat that another rule has closed.
No rules at all means closed
An organization that has configured nothing does not get a permanently open channel between adults and children. “Nobody has decided yet” is read as closed, not as open.
The same reading applies when the check itself fails: if the server cannot say whether chat is open, the screen says so and holds sending.
A closing rule beats an opening one
Whatever its priority. If any rule in force says chat is closed for this pair of people, in this kind of conversation, at this minute, chat is closed — and the answer names that rule.
This is why adding a rule can never widen the curfew by accident. Restriction always wins, so the worst outcome of a mistake is stricter than intended.
Otherwise the highest-priority opening decides
Only once nothing is closing does priority come into it, and only among the rules that open chat. A drop-in centre open until 22:00 on Fridays is one rule sitting above the everyday one.
The decision returns which rule made it, so every refusal can be explained rather than merely announced.

- Three rules, listed in the order the resolver reads them — priority first, not alphabetically.
- Every row states its own effect, its window, the days it runs and who it reaches.
- The header counts the hours chat is open at its widest, so a mistake is visible from the list.
The decision returns the rule that made it, so a person is told Chat is closed by ‘Weekend quiet hours’ rather than simply being refused. A refusal nobody can trace is a refusal nobody can fix. That sentence is the product’s own wording, shown here exactly as it renders today.
What one rule can say
A single opening time would fit no organization we have spoken to
One runs a drop-in centre open until 22:00 on Fridays. One closes during exam season. One holds youth conversations to school-night hours while letting leaders coordinate at any hour. So a rule carries its own scope, and an organization writes as many as it needs.
- Opens or closes
- A rule is one or the other. The same screen writes “chat is available” and “chat is unavailable”, and the second always outranks the first.
- A window, which may cross midnight
- Open 07:00 to 21:00 and closed 21:00 to 07:00 are both things organizations write, and the second wraps. Both are handled; neither is the special case.
- Particular days
- Any set of weekdays. Leave it empty and the rule runs every day — school nights and weekends are usually two rules, not one.
- A date range
- A rule can start running on a date, stop after one, or both. Exam season and a summer camp week are rules with an end date, so nobody has to remember to remove them.
- Particular roles
- Youth, leaders, supervisors, guardians, the organization owner. A rule scoped to a role applies when any participant in the conversation holds it — so a closure protecting young people fires on the adult’s message too.
- One chapter, or a chapter and everything beneath it
- A national body can leave the default in place and let one province tighten its own hours, without either rule reaching the other.
- A kind of conversation
- One-to-one, group, or broadcast. Leaders coordinating a group thread at 22:00 is a different question from an adult reaching one young person at 22:00, and the rules can say so.
- Whose clock it is read on
- The young person’s chapter by default, or the adult’s, or the organization’s, or a named time zone.
- What it does about holidays
- Ignore them, skip them, or apply only on them. The last one is how “these are our holiday hours” gets written.
- A priority, and an on/off switch
- Priority ranks openings against each other. Switching a rule off leaves it in place, governing nobody, and the screen says exactly that rather than implying it still applies.

- The name field says the name is quoted to a young person when this rule closes chat.
- “Chat is CLOSED” is selected, beside the line stating that a closure always beats an opening.
- A copyable reference code, for the one conversation where an identifier is the useful thing.
Whose clock
“Closes at 21:00” is meaningless until you say whose 21:00
Canada alone spans six time zones. A national organization setting one curfew from its head office would be closing chat at 18:00 for young people on the west coast and at 22:30 for young people in Newfoundland.
Every rule states the clock it is read on. By default that is the young person’s chapter — a chapter names its own time zone, or inherits it from the chapter above it, and finally from the organization. A rule can instead be read on the adult’s clock, on the organization’s, or on a time zone named outright.
The default is the young person’s clock because that is who the rule protects. A closure that stops a child messaging at midnight but lets an adult message them at midnight is not a curfew; it is the same hazard, inverted. So a rule scoped to young people is applied to the adult’s message as well.
One evening, two provinces
The rule
Chat closes for young people between 21:00 and 07:00, read on the young person’s clock.
The leader
In Vancouver, typing at 19:00 Pacific. Their own evening has barely started.
The young person
In Halifax, where it is 23:00 Atlantic and has been dark for hours.
What happens
The message is refused, and both screens say which rule refused it and the hour it opens again.
The jurisdiction floor
An organization may always be stricter than its country requires, and can never be looser
Curfew is the one safety setting an organization is allowed to write for itself. That delegation is only safe because of what sits above it.
Each country — and, where it differs, each province or state — carries a policy that caps how many hours a day chat may be open. The cap is set by the platform, in a console the organization has no access to, and the screen that shows it has no control on it. It says where the number comes from and who owns it.
The check is made against the whole rule set as it would be after the change, never one rule at a time: three eight-hour openings are individually unremarkable and together are a channel that never closes. Rules written on different clocks are added rather than merged, so nobody can buy extra open hours by expressing them in another time zone.
What a refused save says
Not “invalid”. The message names the jurisdiction, the arithmetic, the day, and the rules responsible — beside the field that caused it, before the save is lost. This is the product’s own wording, shown exactly as it renders today:
These rules would leave chat open 16.5 hours on Friday. Canada (federal) permits at most 16 hours a day. Open under “Everyday hours”, “Friday drop-in”.
A permanently open channel is called out separately, in its own sentence. “24 hours” and “16.5 hours” are the same arithmetic and very different things to read.
Holidays
Saint-Jean-Baptiste is a holiday in Quebec and an ordinary Tuesday in Ontario
A curfew that treats a public holiday as a school night is wrong twice a year in every province, and differently in each of them. So holidays resolve per country and per sub-region, and each rule decides for itself what to do about them.
Ignore them
The default, and what most rules want. A holiday changes nothing; the rule runs as it does on any other day.
Skip them
“These hours do not apply on a holiday.” The school-night rule steps aside on Christmas Day without anybody editing it in December.
Apply only on them
“These are our holiday hours.” The rule does nothing for the rest of the year and comes forward on the days it names.
A holiday can never outrank a closure
The calendar decides only whether a rule takes part, one rule at a time. It cannot change what a rule does once it does take part, and it cannot reach another rule. So “open all day on public holidays” adds an opening and nothing more — an explicit closure still wins, on Christmas Day exactly as on any other day.
Public holidays are published by AngelLink for your country and region. Your own closures, camp weeks and term dates are yours, and you manage them on the same screen.
When chat is closed
Nobody is left staring at a door with no sign on it
A young person who needs an adult at 22:00 is making one decision: wait, or find another way. An interface that says only “you cannot send” has taken that decision away from them without helping.
They can still read
The conversation stays open and legible. Closing chat stops new messages; it does not take away what has already been said.
They can still start a conversation
Closing stops sending, not starting. The thread is created and waits, rather than the button quietly not being there.
They are told the hour it opens
Not “until chat opens” — the actual next opening, carrying its time zone, found by asking the same resolver again minute by minute rather than by a second calculation that could disagree with the first.
And told when there isn’t one
If nothing opens within the next seven days, the screen says exactly that instead of inventing a time. That answer is actionable: somebody needs to fix the curfew.

- Where the message box would be, there is a sentence instead — the refusal takes its place.
- It names the rule that closed chat, in the words the organization wrote.
- It gives the hour chat reopens and the time zone that hour was judged on.
One deliberate exception, and it is an organization’s own choice: an organization-wide announcement may be exempt from curfew. It is one-way and cannot be replied to — the database gives no participant to reply from — so it cannot become a conversation. Refusing “camp is cancelled, do not go to the bus stop at 07:00” at 22:00 would cause the exact harm the curfew exists to prevent.
In short
Six things it does, and what each one is worth on a Tuesday
A set of scoped rules, not one opening time
What that means
Days, dates, roles, chapters and kinds of conversation, resolved together every time somebody presses send.
Why it matters
The hours you actually run — a Friday drop-in, quiet weeks during exams, leaders coordinating after a youth thread has closed — instead of the hours a product author imagined.
A closing rule always outranks an opening one
What that means
Priority only ever ranks openings. No combination of rules can turn a closure into an opening.
Why it matters
Tightening hours is safe to do quickly, by the person who needs it done, without a review to check that nothing else came loose.
Judged on the young person’s clock
What that means
A chapter states its own time zone, or inherits from the chapter above it, and finally from the organization.
Why it matters
One curfew for a national organization rather than one per province — and “closes at 21:00” means the same thing in Halifax and in Vancouver.
Enforced where the message is sent, not where it is typed
What that means
The same function that draws the banner decides the send, on the server, inside the transaction that would have written the message.
Why it matters
A phone left open overnight, a stale browser tab, or anything pointed at the API gets the same answer as the app. There is no client-side switch to find.
A jurisdiction floor the organization cannot dig under
What that means
A country’s policy caps how many hours a day chat may be open. The cap is set in the platform console; the organization sees it and cannot edit it.
Why it matters
Curfew is the one safety setting an organization may write, and it stays safe to delegate. A local administrator can be stricter and can never be looser.
Every change to the curfew is audited
What that means
Written in the same transaction as the change, with the actor, the time, and the full contents of anything removed.
Why it matters
Six months later, a reviewer can see which protection was lifted, by whom, and on what day — including for rules that no longer exist.
Next
See it decide, on your own hours
Access is by request. We would rather walk your safeguarding lead through the curfew screen with your chapters and your time zones in front of them than send a brochure.