Connected Places
by Laurens Hof

Understanding how the new social web works

Hi {name},

 

Ever since I started diving deeper into the Matrix protocol one question kept intriguing me: Why did Matrix end up being deployed largely by European governments and militaries? And what does that say about the various projects for private data and communities on atproto and ActivityPub?

 

Thanks for reading!
-Laurens

Decrypting Matrix – Where Do Rooms Go?
June 18, 2026 - Laurens Hof
Detail of the city Luik

In the first piece of this series I made the argument that the open social web is converging towards rooms. Some examples are that Bluesky is building out permission spaces as an adjacent protocol, Blacksky shipped Acorn so people can spin up their own communities, there is an ongoing effort to get end-to-end encryption working over ActivityPub, and Lemmy has private communities in open beta, close to release. The shape that keeps re-emerging across all of these is the room: a bounded space, with members, with some set of rules about who is inside and what happens there. In the first few years after Musk's acquisition of Twitter, and the renewed focus on building open social networks, the focus has been towards building open timelines for the whole world to shout into, and now the open social web is rediscovering the value of having bounded spaces.

Matrix has been building rooms this whole time. A Matrix room is the thing the entire protocol is organised around, with a piece of shared state, replicated across the servers of everyone who is in it. So if you want to know where rooms actually go, where this architecture ends up once a network commits to it fully, Matrix is an obvious place to look, as it has been doing this for over a decade.

And the answer turns out to be that Matrix's rooms went towards European states.

I mean this quite literally, as all the largest ongoing deployments of Matrix are governmental institutions, largely European ones. France runs Tchap, the messenger for its public administration, on Matrix, with over half a million accounts. Germany's healthcare messenger, the TI-Messenger, is built to reach up to 74 million insured citizens. The European Commission is "looking into using Matrix as a complement and backup solution to existing internal communications software" The UN's International Criminal Court is using Matrix as well, an organisation that is pointedly aware of the need for sovereign control over communication software.

It is on the military side too: The German armed forces run their own Matrix-based messenger, the BwMessenger, which has been rolled out across the whole of the Bundeswehr, with around 100k daily active users. The French army relies on Matrix too, and both Luxembourg's army and police for use a system for Matrix as well. And NATO has gone past piloting into actual operations: its Allied Command Transformation ran Matrix as the coordination layer for a live exercise in the Baltic last year, tying more than a hundred external partners from industry together across some thirty rooms, on top of the airgapped, NATO-only deployment it keeps internally. When several national militaries and an alliance like NATO are willing to put operational communication on a protocol, that is a different order of endorsement than a pilot in a ministry.

The tempting reading here is that Matrix is doing something completely different from the rest of the open social web. The fediverse and the atmosphere are over there trying to build a better public square, and Matrix is over here wiring up governments, so surely these are separate stories. I don't think that's right. This is the same architecture, the same room, followed all the way to one of its possible conclusions. The open social web is adopting rooms right now, and one of the places a room can end up is the inside of a government. That just intrigues me, how did these protocols end up in such different places, especially since Matrix used to focus on the decentralised social networking as well.

Matrix, to its credit, says this about itself out loud. In his State of the Union talk at the 2025 Matrix conference, co-founder Matthew Hodgson described the goal as "being the best decentralized secure comms platform in the world," and then followed it up with "we are not going to pursue decentralized social, good luck to Bluesky and atproto, Mastodon, ActivityPub and nostr." So the open protocol that started in the decentralised social world, is deliberately moving away from it. The interesting question is: why?


If you half-remember Matrix, you probably remember it as an encrypted-chat protocol with some poorly-moderated public rooms and the ever-present "unable to decrypt message" jank. That picture is a few years out of date, at least on where the action for Matrix is. (I set up a new Matrix server for myself to test a few things recently, and don't worry, the jank is still there). What has actually been happening is that entire national administrations have been building private federations on Matrix, where the network is real but almost none of it is visible from the outside.

You can see the shape of it even in the public crawl data. The number of discoverable, federatable Matrix servers went up by something like 76% between the end of 2024 and early 2026, from around 10,000 to over 18,000. But over that same period the number of public rooms stayed essentially flat, and the share of servers that bother publishing a public room directory at all fell from about 30% to 23%. The growth, in other words, is happening behind closed doors. More and more servers, less and less of it open to the public. That is indication of institutional adoption: a lot of new infrastructure, but in closed networks, not open to the whole internet.

Why did states go looking for this in the first place? Broadly, a sovereignty moment in Europe, from Snowden, to the rupture of the Trump period and the growing sense that American infrastructure is no longer politically safe to depend on, Salt Typhoon's compromise of US lawful-intercept systems in 2024, and the Russian interception of German government WebEx calls that same year. Out of all of that comes a clear demand, especially in Europe, for communication infrastructure that is not owned by an American company. That explains the demand, but why Matrix?

Part of the answer is that in that same timeframe, the Matrix organisation spent the preceding years getting pushed toward exactly this kind of customer. The very short version is that Element, the company that does most of the work on Matrix, went through a rough funding stretch and rounds of layoffs in 2022 and 2023, and came out of it pointed much more firmly at the commercial and public-sector market. Around the same time Matrix 2.0 landed, with native single-sign-on and identity management, sliding sync that finally made the clients fast, and built-in calls, and that was roughly the point at which Matrix became credible enough for a government to actually deploy. The company settled into serving governments because that is where the money was, and, as I'll get to, because it was the one kind of customer whose needs Matrix could meet without building the part it never built.


So far this is a story about timing and circumstance, contingent things that happened to line up, which makes sense but isn't really notable: States need sovereign communication services at the same time that the organisation building Matrix is looking for funding, sure. But underneath that there is a structural reason rooms led to this, which is the part that really interests me.

A room is not just a data structure. The moment you draw a boundary around a social space and say "these people are in, these are the rules," you have made something that needs governing. Someone has to make the rules, and more crucially, someone has to do the actual labour of the enforcement of the rules. I wrote in an earlier piece that a functioning community institution needs rules people understand. It also needs a monitoring system, and graduated sanctions for when things go wrong. The room is just a container, it needs governance to turn it from a container into a place.

And there are really only two ways a room gets that governance.

The first is that you import it from outside. An institution already has all the parts a governance system needs: an identity for every member as well as a hierarchy and a disciplinary process. The room just has to map onto the org chart that already exists. The ministry already knows who works there and what happens if they misbehave, and the room inherits all of it for free.

The second is that governance grows inside the room itself. The community can also generate its own governance, by working out its norms in practice. It finds moderators, and over time develops practices how to handle conflict. This is how a good subreddit or a healthy Discord server works. But growing governance inside a room only works if the room gives you the tools to do it. You need a way to do the moderation, as well as setting policy etc. So when Germany put a messenger into its healthcare system, it did not grow a community that worked out how to run the thing. It simply passed a law that the statutory health insurers were obliged to provide the messenger to the people they insure, and so every single one of them connected, to the point that someone involved could simply describe the market as "settled." That is governance imported in its purest form, legislation via the state.


One of Matrix's biggest ongoing problems is that it built an impressive protocol for private room, but with almost none of the tools you would need to grow governance inside it.

For most of its history, what Matrix gave you for governing a room was power levels, plus the ability to kick and ban, and that is essentially it. A power level is a number that says who outranks whom. The actual toolkit you would want, such as moderation pipelines, a reporting API, or just the ability to suspend an account is only really arriving in the last few releases from 2024 onwards. This is a decade into the protocol's life and still underfunded. For almost the entire time Matrix has existed, the only governance you could actually run in a Matrix room was a system imported from outside. And if there is one thing institutions such as governments are good at, it is running complex internal governance systems.

So that Matrix ended up with European governments is not the logical endpoint of private rooms on open prototocols, it was a consequence of a missing toolset. Rooms drifted to the only people who could govern them without the tools Matrix never made, and those people were governments.

You can see the mechanism most clearly in the one place Matrix tried to run an open, vaguely social space itself, which is matrix.org. That is the room where governance and moderation had to be run internally, without important an outside system. And it is exactly the room that strains the organisation, eating something close to half of the Matrix Foundation's budget on trust and safety, with the open-social ambition being the part that got cut first. Everywhere governance is imported instead, things run smoothly. Identity always comes from outside, such as the German eID and BundID, France's government SSO, or the European Commission's eIDAS login. Federation is always closed, and BundesMessenger team said it pretty clearly at a Matrix conference, that federating with the public network is technically no problem at all, but for now they have decided not to. And trust and safety, in these deployments, means controlling the boundary, deciding who is allowed in, rather than running moderation queues inside. Internal moderation, as one of the BundesMessenger people put it, is "another can of worms" you would have to go to the Foundation about.

Another illustration is ePost, Swiss Post's Matrix-based system. It uses company-to-end encryption with server-side keys, explicitly for compliance reasons, and it handles abuse entirely at the public boundary. You need a verified Swiss ID to get in, and with designs like an address-book gate and limits on mass-messaging ePost handles governance and moderation at the boundery again. There is no Matrix-based moderation queue or something, because there does not need to be one. The institution imports every part of the governance and moderation with their own system, and Matrix just supplies the technical infrastructure.

This is the distinction the whole thing comes down to. There is access governance, deciding who gets in and proving they are who they say they are, and there is behaviour governance, dealing with what people do once they are inside. Institutions need access governance, and they pay for it, because it is how they hold the boundary. Behaviour governance, the messy ongoing moderation work that an actual social network lives and dies on, is precisely the thing they do not need, because they deal with conduct through HR and the law and the org chart instead. And behaviour governance is precisely the thing Matrix had not good enough tools for.


The open social web is adopting rooms, and they need governance and moderation tooling. If the projects building these rooms repeat Matrix's mistake and ship the room without these tools, then the only governance that is possible is the imported, institutional kind. If instead they build the in-room governance and moderation tooling that Matrix never fully committed to, then a room can be used for real community building, where communities can governs themselves.

And this is exactly what the most interesting projects on the open social web are reaching for right now. When Blacksky builds its own moderation and community tooling, so people can form communities on Blacksky itself, that is a recognition that the room software is only part of the work. "Community is the only moat," as Blacksky's Rudy Fraser puts it, and in that framing, the best way to build durable places online is building the tools and softwares that communities can use to govern themselves.

Meanwhile, organisations like Roost (Robust Online Open Safety Tools) are building exactly these type of tools, in a way that can be used by anyone. Their tool Ospey is a "a high-performance investigation and rules engine for detecting and responding to real-time abuses at scale." It released in January of this year, and it is already by Bluesky, Discord, and Matrix. So the governance and moderation system for Matrix did arrive after all, in a slightly different form: as an external open software that any room, including Matrix, can use.

That leaves this article in a somewhat strange situation. I wrote it because I had this question for myself, where I found it strange and intriguing why multiple different projects on the open social web are working towards private rooms, while the protocol known for private rooms is explicitly pivoting away from the social side to focus decentralised comms for governmental institutions. For me the answer turns out to have two parts: it is partially contingent, right-place-right-time for the Matrix Foundation that urgently needed financial stability, and partially the result of Matrix having sub-par governance and moderation tooling. But the open social web is a dynamic place, as the ROOST organisation shows. Because for the next generation of projects that are building private rooms on the open social web, the question has shifted slightly: from 'do you have good governance and moderation tooling', to 'do you have, or can you integrate with, good governance and moderation tooling'.

Read more...


QR code for donation to Connected Places

Liked this newsletter? Help keep it alive!

If this newsletter adds value to your week, consider supporting its creation. Your contribution keeps the ideas flowing. Click or scan the QR to donate securely.

Unsubscribe   |   Manage your subscription   |   View online