Enabling Sensitive Conversations with Consent Boundaries:
Moa, a Platform for Discussing PhD Advising Relationships
April 20, 2026
When an individual is harmed by someone in power, such as a workplace manager, it can help to identify allies—people who would offer advice or supportive action. However, ally discovery is fraught because the very people who might be most relevant—e.g., someone who reports to the same manager—might not be sympathetic and could exacerbate the harm. We examine this problem in the context of PhD students navigating advising challenges and present a social media platform called “Moa” that brings together a number of features for facilitating ally discovery. Moa’s most novel element is an audience selection process that uses what we call consent boundaries, which allow users to flexibly define each post or comment’s audience based on factors such as common social identity or lived experience, all while preserving mutual anonymity. A 3-week field study with 47 real-world users showed that Moa’s features in combination facilitated sensitive conversations about advising, with 7 out of 31 posters (22.6%) using consent boundaries. We discuss both our overall “recipe” for systems for ally discovery and the benefits of a consent-centered approach to design.
<ccs2012> <concept> <concept_id>10003120.10003130</concept_id> <concept_desc>Human-centered computing Collaborative and social computing</concept_desc> <concept_significance>500</concept_significance> </concept> </ccs2012>
Individuals who suffer from problematic power dynamics, such as mistreatment or abuse from someone in power, can benefit from identifying allies, whether it is to seek advice or remedial action. Here, we use the word “ally” to refer to any individual who is sympathetic and can offer some kind of help, ranging from sharing useful information to actively navigating the situation together. Example contexts include workplace bullying [1], political persecution [2], and sexual harassment [3]. In contexts where potential allies are initially unknown, however, someone must make at least a partial disclosure of their experience for what we call ally discovery1 to succeed. But, disclosure is risky because the exact conditions under which these situations arise heighten concerns of exposure and retaliation [6], [7]. That is, one cannot know whom to trust about an issue until one discloses being affected by it; yet one cannot disclose before knowing whom to trust.
Some of the most helpful information in navigating problematic power dynamics can come from individuals who share similar traits regarding the context, e.g., women working with the same manager. How can we facilitate the flow of information in such situations, so that individuals who need it most can discover allies while maintaining one’s anonymity? We consider this problem in the context of PhD students experiencing advising challenges. Because the advising relationship is fraught with power dynamics and ripe for exploitation [8]–[11], ally discovery is critical for enabling students to connect with peers who might offer advice or partnership toward remedial action. Yet, research shows that ally discovery within the same PhD program can be difficult [12], [13].
We conducted a three-phase study to build and evaluate a system that facilitates discussions among PhD students to enable ally discovery. In Phase 1, we conducted 19 interviews across nine R1 institutions, and found that participants had a strong desire for a social platform where they can share information about advising dynamics. Many pointed out advising challenges is a sensitive topic that is not easy to talk about, even with peers in the department. Furthermore, participants emphasized wanting to have control over who can see their posts based on a rich set of contextual factors, which existing social media platforms do not provide [14].
In Phase 2, we combined insights from Phase 1 interviews, prior work, and the affirmative consent framework [15], to develop Moa (모아),2 a fully functioning social media platform. Beyond features of existing social platforms for sensitive discussion, Moa includes a novel concept we call the consent boundary. Existing social media platforms tend to offer brittle controls for audience configuration [14], [16], or they provide mechanisms for selecting individual recipients on a one-on-one basis, which requires knowing users’ identities in advance. In contrast, consent boundaries allow users to demarcate who can view each post or comment based on dimensions such as social identity, lived experience, and interpersonal relationships, while maintaining all users’ anonymity—the sender does not need to know the recipients’ identities, nor must the sender reveal their own.
In Phase 3, we evaluated Moa in a 3-week field study with 47 PhD students from two departments at a public R1 university. Through system logging, a survey, and interviews, we found that overall, Moa met its goal of enabling ally discovery among PhD students. Out of 47 users, 31 posted or commented on advising-related topics, some of which were sensitive, such as whether to switch advisors. In post-hoc interviews, many commented on their ongoing interest in Moa; a few expressed interest in directly contacting other PhD students on the system or even meeting someone in person.
Out of 31 users who posted or commented, seven (22.6%) used consent boundaries, suggesting that while consent boundaries were not a critical element for ally discovery, they were useful to some. Those users who used consent boundaries had various reasons for doing so—for some, it was to restrict the audience size and reduce privacy risks; others used them to proactively curate an audience (as opposed to defensively setting a boundary) in order to reach those who were sympathetic, could provide useful input, or might find the content helpful.
While Moa is a basic social media prototype, its uniqueness lies in the combination of features designed to enable ally discovery. In all, this work makes the following contributions:
A recipe of socio-technical features for developing social platforms that facilitate ally discovery, informed by both our study and prior research.
Conceptualization and instantiation of consent boundaries as a way to address the issue of coarse audience configuration on social media systems.
Reflections on taking a consentful approach to developing systems, as compared to taking a privacy-centered approach.
We first review research on problematic power dynamics. Because ally discovery requires disclosure for others to take notice, we then discuss literature on audience configuration and identity management—key factors that impact users’ self-disclosures. We next give an overview of research on consent. Lastly, we discuss challenges in PhD advising relationships.
Rankism refers to “abusive, discriminatory, and/or exploitative behavior towards people because of their rank in a particular hierarchy” [17]. There is little work that studies how prevalent rankism is across contexts. For example, while research in both North American and European contexts show at least 10–15% of the workforce has been exposed to hostile, aggressive, or abusive behaviors, it is still unclear what percentage of instances are perpetuated by people in power [1], [18].
While not focused on problematic power dynamics in interpersonal relationships, a few HCI systems are relevant for enabling sensitive discussions in organizational contexts. For example, Abdulgalimov et al. [19] built OurVoice, a platform that helps employees discuss issues in the workplace. A deployment study showed that anonymity, strict identity verification, and moderation were important in enabling sensitive discussions about organizational justice (e.g., gender pay) among employees [19]. There has also been research on systems for collective action, such as Dynamo, a platform for Amazon Mechanical Turk workers to organize [20].
Compared to such prior work, we focus on a more interpersonal context of individuals navigating problematic power dynamics within an organization. Research shows that it is extremely hard to be the first person to disclose some kind of information for potential allies to notice in such situations [6]. This is fundamentally related to the difficulty of building trust—trust is about the willingness to be vulnerable with someone in a situation that assumes some kind of risk [21], [22].
Audience configuration and identity management are key factors that impact self-disclosures on social media systems [23].
While research shows that audience configuration plays a role in sensitive disclosures [23], less work has focused on enabling users to customize their audience more flexibly. Researchers have pointed out that this is likely due to the status quo of how social media platforms are designed, which often provide coarse-grained controls [16], [24].
Fundamentally, the form of a social media system impacts how users configure their audience. Zhang et al.’s Form-From framework [25] classifies three ways social media systems distribute content: networks—users create connections (e.g., friending, following) to exchange information, spaces—all users within a shared environment (e.g., channels, email threads) see the same information, and commons—users can receive content from anyone, without having to follow a user or join a space.
Many studies on audience management on social media have focused primarily on networks [26]–[28]. The coexistence of different types of social ties (e.g., family, co-workers) on many platforms, which is often called the “context collapse”, makes it difficult for users to carve out a precise audience [29]–[31]. A study showed that Facebook users actually tend to underestimate their posts’ audience size [28].
Some platforms that fall under commons recommend content and accounts by algorithmically inferring users’ interests, such as Snapchat’s Discover [14], [32]. However, research shows that users perceive them to be still ineffective in identifying the right audience [14].
There is a rich line of work on audience configuration in emails, which has the form of a space. Similar to social media platforms, people actively consider social affiliations when configuring an audience using the To and Cc fields [16]. Other studies have examined the impact of Ccing others in workplaces [33]–[35], as well as how people decide whether to reply or reply all [36]. However, emails require users to know who their audience is and how to reach them.
In this work, rather than being constrained by a predefined network, space, or algorithmic configuration, we ask: “How does each individual user want to form an audience per post or comment, when they do not know the audience’s exact identity?”
Even with the same underlying structure, platforms could differ in respect to what are often called access, privacy, or permission controls [24], [37]. Privacy researchers tend to classify these controls into two categories: interpersonal and institutional [38]. Interpersonal controls regulate how other users access one’s personal information. Settings for audience curation fall under this category, and many general platforms offer coarse options, such as “Public”, “Friends”, and “Close Friends” [38], [39]. Institutional privacy controls manage what platforms collect about users, particularly in the context of online behavioral advertising [38], [40].
While the usable privacy community has advanced the design of access controls for users (e.g., [40]–[44]), much of the work tends to focus on increasing the controls’ usability, such as ensuring that they are easy to find [40]. Notably, Feng et al. [44] proposed a design space for privacy controls, introducing five dimensions—type, functionality, timing, channel, and modality.
The social computing community has particularly argued for more radical designs for audience configuration [14], [15], [24], [45]–[47]. Most recently, Kim et al. [14] articulated the value of viewing privacy management as a trust-driven process, and suggested concrete designs based on such reframing, such as contextual audience segmentation, intentional engagement signaling, and guided disclosure.
Anonymity is known to help with sensitive disclosures because the lack of identifiable ties lowers risks [23]. Because of this, major social platforms rely on anonymity for posting sensitive information. For example, users actively use throwaway accounts on Reddit [48], [49]. Blind, a platform launched in South Korea, enables anonymous sharing about employers, verifying users via corporate email addresses [50], [51].3
HCI system researchers have explored how anonymity, coupled with moderation, helps with sensitive conversations, along with new identity management mechanisms beyond anonymity. For instance, OurVoice supports sensitive workplace discussions by combining anonymity, strict identity verification, and moderation [19]. Meronymity, a set of traits that provide information about a person’s identity without revealing it completely, helped junior scholars participate in academic discourse on Twitter, mitigating the impact of social hierarchies [52]. The goal of meronymity is to enable users to present themselves more flexibly to give sufficient context to others, while preserving an adequate level of privacy [52].
However, identity management does not fully resolve users’ uncertainty around disclosing information or connecting with people online. For example, research shows that anonymity does not always translate into meaningful social connections, because it
does not ensure empathetic responses—an essential factor in sharing sensitive information [23]. This is likely one reason why many
discussions using throwaway accounts end as one-off disclosures [48]. And, even for participants who used meronymity, some
expressed hesitation or fear of revealing too much about themselves [52], which shows that audience control is a key factor for
enabling sensitive discussions.
In essence, consent is a grant of rights to another person to initiate some kind of interaction. This is especially important for high-risk contexts, such as sexual interactions [53] and medical procedures [54]. For example, in sexual contexts, asking for consent acknowledges that one person can only engage in sex if the other party explicitly grants that right. This is why consent clearly explains why sexual violence is morally wrong—it emphasizes respecting each person’s autonomy and decision-making power [55].
While consent is a powerful concept, defining it has not been straightforward. There have been debates on whether to view consent as a subjective or objective phenomenon [56]–[58]. Subjective consent is based on one’s internal sense of having granted permission, while performative consent is an indication of agreement based on behavioral signs or explicit verbalization [56], [59], [60].
Affirmative consent is a form of consent that values both subjective consent and performative consent. In essence, affirmative consent is an explicit indication of voluntariness and enthusiasm before an interaction is initiated [55]. Building on Una Lee’s work on “consentful technologies” [61], Im et al. [15] argued that affirmative consent is voluntary, informed, specific, revertible, and unburdensome, and to develop social computing systems based on these five properties.
In the field of computing, consent is often viewed as a concept for data control within the notice and choice model, in which users are given notice about how their information might be collected and used, and offered choices about it [62]. However, many scholars have criticized the model because it has failed to protect people’s privacy in practice [63]–[67]. In this work, instead of being confined to the notice and choice model, we view consent as a fundamental concept that give users the agency to carve out their online interactions.
PhD advisors play a significant role in their students’ mental health [12], [68]–[70] or success in the program [13]. In a worldwide survey by Nature, 23% of PhD student participants answered that they would switch advisors, if given the chance [71]. Another study from a European institution shows that 24% of PhD students perceived they have experienced some kind of abuse from faculty [72]. In HCI, a qualitative study showed that graduate students cite advising relationships as one main cause of stress in graduate school [73]. Other research shows the range of advisor behavior that can cause harm: incompetent advising, sudden dismissal of advisee, forcing advisor’s views, exploitation, bullying, encouraging fraud, authorship issues, misappropriating a student’s work, harassment, abuse, and dual relationships (e.g., friendship, romantic relationship) [9]–[11], [74]. Research also shows that even when PhD students realize they are experiencing harm from their advisor, they have few guidelines for what to do next [13], [75].
We conducted two rounds of semi-structured interviews with 19 PhD students in the United States. Our study was exempt-approved by our institution’s Institutional Review Board.
In the first round, we recruited 10 participants from 2 PhD programs within an R1 institution by contacting the student mailing lists. For the second round, we recruited 9 PhD students from 8 R1 institutions by publicizing the study on X and LinkedIn. We noticed that a few participants self-disclosed their experiences to an open-ended question in the sign-up form, and prioritized recruiting them, while accounting for year in PhD and PhD program. Participants were compensated $20/hour. All participants were in computing-related PhD programs, ranging from small (fewer than 40 students) to large (over 200 students). The average PhD year for first-round participants was 3.8, and 2.9 for the second round.
We showed participants a hypothetical scenario of a PhD student whose advisor persistently requested them to work on non-research tasks (see Supplementary Materials). We asked participants what they would do in the situation. Then, we presented participants with a high-level description of a system that lets students converse regarding advising and asked for their thoughts. Next, we showed participants low-fidelity designs of such a system, and asked them to think aloud. The interviews lasted between 1 to 1.5 hours.
First, we considered a posting and commenting format (Figure 7). However, the design was not a public forum—we wanted to give users control over each post’s audience, and considered two criteria: 1) types of PhD advising-related challenges and 2) faculty names. We also included a messaging feature because we hypothesized it would be helpful for PhD students to privately ask and answer sensitive questions.
The first author manually corrected the auto-generated transcripts. For sensitive personal experiences, we either redacted it or asked participants about inclusion. The first author conducted inductive coding and periodically discussed the themes with the second author.
We report the most salient findings from the Phase 1 interviews.
Almost all of the participants expressed interest in using a system that connects PhD students regarding advising relationships. Even the one participant (P12) who had mixed feelings acknowledged the sytem’s value, though they felt it did not address the root issue of faculty oversight: “I feel like overall, there just needs to be more oversight [of] faculty and PhD programs. [...] And I think this [system] could be a really great place for students to start doing that bottom-up type of accountability thing.”
When asked what they desired the most, almost all participants answered they wanted validation of their experiences. They wanted to know whether their interactions with their advisor were “normal” or problematic. For example, P17 said “Just knowing that other people’s experiences are either the same or different gives you courage to know that it’s OK or it’s not OK. It helps you figure out what’s a normal experience.”
Interviews also revealed why PhD students struggle to seek validation and advice about their advising experiences. Many participants found it was difficult to discuss their experiences with peers or mentors in their established social circles (e.g., research group) due to concerns about power imbalances—a key reason they wanted a system that could facilitate conversations beyond those circles. This contrasts with prior literature emphasizing the role of social ties in sensitive disclosures [23]. For example, some participants avoided discussing their advisor with labmates out of fear of retaliation. P16 explained “I think it can be hard to talk to other PhD students in your lab or your department because you don’t want that information to get out and get back to your advisor.”
Similarly, some participants who had switched advisors avoided discussing their experiences within their close networks due to concerns about repercussions and damage to their reputation. For example, a few participants said they avoided disclosing advising experiences to students in the same program to avoid burning bridges with former advisors. P15 said “If you’ve been through a negative advisor experience, I feel like not everyone is willing to be transparent about that with, say, people who reach out to them asking about how their experience in a particular group was so. And it’s because we know there are power hierarchies in academia.”
Additionally, some participants noted that even within the same institution, connecting with others who had faced the same kind of challenges could be difficult. P6 said “...let’s say it’s the same department, but [the PhD student is in] some other lab, and I’ve never interacted with the person before. The chances of us connecting over that experience is very low.” Similarly, P13 observed “So if they [specific PhD students] are not in the exact same scenario, their suggestions would be different.’
Regarding the platform structure, many participants wanted a form that enabled lightweight, distant interactions before mutual trust developed. Broadly, this meant they favored a post-and-comment structure over a messaging system. We initially hypothesized that PhD students would seek deeper connections when supporting one another, such as through a direct messaging. However, most participants did not want dyadic, deep interactions due to the uncertainty of the other person’s identity and the context’s sensitivity. Others noted that 1:1 messaging created an obligation to reply. As P16 explained: “I think it would be easy [to write a post], especially in a forum setting where maybe I wasn’t like obliged to respond back to people because other people are chiming in as well.”
At the same time, participants wanted something different from a traditional forum—many preferred the ability to set specific criteria for who could access their posts. Participants reacted positively to proposed audience control features and recognized that this structure differed from existing forums (see Section 3.1.2). For instance, P19 said “Kind of like forum style one can express their what they have to say about the situation, if they meet the criteria.” One participant (P16) explicitly used the word “consent” when describing how the discussions could have some kind of access control: “I guess people would have to like consent to this, but if you could be directed to a group with people that have been having similar issues, and you could see what people have been saying in threads of conversations, and then you could join in.”
Participants’ reasons for wanting granular levels of control included privacy concerns and fear of repercussions. For instance, P11 said: “I would have to feel more comfortable on the platform without revealing identity stuff. And I would want to know that they’re not like in the same lab as me or share the same advisor, you know.” Another reason was the importance of gradually developing trust before disclosing more information—something existing forums fail to support because they tend to be public. For example, P12 said “I think that’s one of the reasons why like platforms like Reddit don’t do so well in terms of forming like strong social support networks because everything is too public, if that makes sense, like you need some sense of like trust and privacy and intimacy to have to start building those relationship blocks to actually support someone.”
Participants found our proposed criteria of advising-related challenges and faculty names to be helpful (see Section 3.1.2). The interviews also revealed additional criteria that participants suggested.
One important finding was that some participants naturally brought up identities—such as gender, race, and being an international student—without being prompted. (We did not initially include social identities in our list of criteria.) For instance, P16 said “If I had one [difficulty in advising] with sexism, then maybe I’d want to limit it to like other female identifying students or maybe not men. So yeah, maybe depending on the issue, there would be other like demographic information like that.” Similarly, P18 highlighted the challenges international students face: “...as international students, the education system here is so different from the system that we grew up in. We have no idea for resources for harassment, you know, threats or anything.”
Many participants also wanted the ability to filter by PhD programs or even specific labs (e.g., avoiding labmates). For instance, P19 said “I really would not want to have that conversation with them [labmates] over this platform [...] But maybe that’s part of the criteria, right, like you say ‘Oh I don’t want anyone else who is being advised by X.’”
Some participants said they are fine with posting publicly. Their main reason was to get advice from a wide audience.
Nearly all participants preferred anonymous connections. When asked whether they would ever reveal their identity to another user on the platform, most participants said they would not. Many thought anonymity was important to reduce the risks of sharing sensitive information. P19 said “You can be more open with people if you’re anonymous.” Others noted that anonymity helps mitigate bias. For instance, P13 said “...because if I reveal my identity, other people think I’m some kind of vulnerable thing or I cannot progress on my research so that I want to quit.”
At the same time, participants acknowledged that the desire for anonymity gradually weakens as trust develops. For instance, P19 said “I don’t think identity has to be all or nothing, it can be parts of it and I would do it as the other person was opening up, like you would actually do, almost in a conversation.”
Many participants asked questions about the system creators’ affiliation and their access to users’ data. For instance, P15 said “I think the biggest thing I want is some kind of transparent security and privacy labels or like who is going to have access to this database? And I want to know that this is very much like student organized and not something coming from faculty.” Some participants commented on the importance of knowing the system creators’ motivation. P7 said “Maybe if there was a picture of you [first author] on the home page and it says yeah, man, like I had some fucked up shit happen to me, that might actually be persuasive to me. There are people who made this, not just because they wanted to write a paper, but because of what happened to them in their PhD.”
Many participants desired strong abuse prevention measures, so that they would know for sure a user is a student, and not a faculty member. Participants were also aware that students could abuse the system, such as by spreading false information about faculty. For example, P10 said “Sometimes the abuse can come from the advisee’s side, although that is rare. So, they [PhD students] need to be fair.” When informed that we plan on moderating the system, many participants emphasized wanting transparency behind moderation [76].
Based on the interview findings, we organized our design requirements as the following. The platform should:
REQ1: Follow a post-and-comment structure.
REQ2: Provide consentful controls for audience setting with respect to various contextual information, such as social identities, advising experiences, affiliation, and advising status.
REQ3: Ensure interactions remain anonymous; minimize risks of revealing one’s identity.
REQ4: Have strong privacy and security measures.
REQ5: Include moderation and community guidelines to prevent potential abuse.
Moa is designed according to insights gained from Phase 1, previously known features that enable sensitive discussion, and the principles of affirmative consent [15]—the value of the last being reinforced by the Phase 1 interviews.
Like many social platforms, on Moa, users can write text-based posts and comment in response to posts (REQ1).
Social media platforms are typically structured around a predefined network (e.g., followers) or space (e.g., group) [25]. In contrast, Moa focuses on the question: “How does each user want to design their audience per post or comment?” As a result, Moa does not implement any network model nor does it include user profile pages (REQ3).4 Furthermore, instead of letting users have access to the same content if they are in the same space, Moa’s users see different sets of posts (and comments) depending on their own and others’ consent boundaries (Section 4.2). In terms of the Form-From matrix [25], we believe Moa is closest to a Threaded Space, but consent boundaries considerably weaken both the threading and the space.
Because all Phase 1 participants strongly emphasized that they wanted a space of only PhD students, Moa has a strict identity verification process (REQ4). Users can only sign up using an institutional email address; email domains are verified by the system (Supplementary Materials).5 Furthermore, the moderator (the first author) reviews every sign-up, verifies email validity, enrollment in one of the two PhD programs, and personal traits (to the extent that can be publicly verified) as entered by the prospective user.
Phase 1 participants emphasized preserving users’ anonymity on Moa. A few participants said they wished there were multiple user identifiers on the system, so that it would be hard for others to infer their identity. Based on this finding and affirmative consent’s specific principle [15], we let users create different usernames per post or discussion (REQ3; Figures 2). Once a user takes a username, it cannot be used by others, even if they are in a different thread. Compared to other platforms, Moa provides this feature directly in the posting and commenting interface (unburdensome), which is not the default for major social media platforms.6
To prevent users from using multiple usernames to add weight to their point, once a user starts or participates in a thread, they can only use the name that they initially used. The username field becomes deactivated, so that the user can no longer make modifications to it.
Based on the Phase 1 findings and prior research [19], [77], Moa emphasizes community rules on a linked page from the navigation bar (REQ5), which are: 1) Be respectful and kind to others, 2) What is said on Moa, stays on Moa, 3) Do not spread false information, 4) Do not use discriminatory language, 5) Do not harass or attack others. Moa is moderated by the first author because adding others would heighten users’ privacy concerns. However, theoretically, Moa could be extended to recruit other moderators.
Whenever a post is created, users within the post’s consent boundary are notified via email. Moa also notifies all users in a thread whenever a user adds a new comment. For both, the email shows the first 20 words of the post/comment.
Moa lets users mark their consent boundary, which means users can set an audience per post or comment based on a rich set of dimensions (REQ2; voluntary, specific).
A user can set a consent boundary while writing a post (or comment) and save it to their account setting (Figure 2). Or, a user can set a default, account-level consent boundary in the settings page. Whenever a user sets a consent boundary for a post/comment, it does not affect prior ones (specific). When a user visits a post they wrote (or a thread they participated in), Moa pulls up the recently used boundary for that post (unburdensome).
Below, we list possible consent boundary dimensions.
Moa lets users show their post or comment to others who share their gender, race, or international student status. We enabled users to select each category only when they have the corresponding identity.7 For example, only women can set their consent boundary so that their posts and comments are visible to women. We describe this more in Section 4.2.3.
Moa lets users show their post/comment to others who have experienced specific kinds of advising challenges (e.g., micromanagement, communication issue; Figure 2). The categories of challenges are based on research on PhD advising [9], [10] and Phase 1 interviews (full list included in Supplementary Materials). We also linked a survey in the interface so that users could suggest new categories they desired (voluntary). Users can also only show their post/comment to others who have experienced a change in their advising situation (Figure 2).
A user can make their post or comment only visible to PhD students from a specific PhD program (Figure 3). Moa also lets users avoid, or connect to, other users who are advised by certain faculty (Figure 3).
Moa lets users choose accounts they only want to show a post or comment to (Figure 3). For comments, users are only able to select users who participated in the thread.
Users can type in information uncaptured by provided dimensions in the “other information” textbox (Figure 3). When a user uses this, the post or comment is delayed until the moderator reviews it and chooses the right audience.
To make consent boundaries work, Moa has to know users’ identity traits and experiences. Users can voluntarily declare their traits for only the system to know (voluntary). Users are encouraged to submit information when signing up, but they can go to their account page to change it (revertible). To ensure a user does not falsify their account information after sign-up, the first author periodically checked for users’ account setting changes.
Moa lets users decide whether to show their consent boundary to others who can already see the post or comment (voluntary). That is, by default, when users see a post with a boundary applied, it looks the same as public posts. For example, in Figure 2, the poster consented to showing their boundary. Those who have access to the post can understand that the poster is an international student, has experienced communication issues and lack of feedback from their advisor, and wants to avoid students who are advised by John Smith. In contrast, if a user decides to not show their boundary, other users who have access can only see the content and username. Users can also change their boundary’s visibility after posting or commenting (revertible; Figure 4).
Moa applies the original post’s boundary to all of its comments. This is because research has shown that replies to a post can reveal its content, even if the post is deleted [78]. A comment to another comment also inherits their boundary rules.
Based on the affirmative consent’s revertible principle, Moa lets users restrict consent boundaries (Supplementary Materials). Users who already replied to the post but no longer fit the new boundary will lose access to it (without any notification).
There was one contradiction between the affirmative consent framework and how Moa’s consent boundary was implemented. The framework is conservative and implies that consent boundary rules should be enforced without exception [15], including when a user replies to a post or comment. For example, let’s say A is a woman. A set their default consent boundary so that their comments are visible to women. A is about to reply to B’s post. Based on the affirmative consent framework, Moa should enforce A’s consent boundary to B as well. This means B cannot see A’s comment if they did not indicate they are a woman in the account setting.
However, our pilot studies showed that this could be confusing. Thus, we changed it so that when a user leaves a reply, by default, Moa assumes they want to show their reply to the original poster. Users can always change the setting (see the bottom of Figure 2).
We built Moa using Django, MySQL, JavaScript, HTML, and CSS. We used Fly.io8 for deployment. For email notifications, we used SendGrid and configured it in Django’s settings.py. To ensure consent boundaries work robustly, the first author created test cases and conducted pilot studies.
We conducted pilot user studies with five participants, who were PhD students and a postdoc who recently graduated. All participants were compensated $20 per hour.
Participants found the consent boundary interface overwhelming because there were too many fields. Thus, instead of showing everything at once, we let users select a tab and only showed the relevant boundary dimensions (Figure 3).
We noticed that it took time for some participants to grasp the connection between their account settings and the visibility of posts and comments. For example, a woman participant did not understand that if they left their user information blank, they could not see posts from women who used a consent boundary of restricting their content to only women. Thus, we decided to include a short tutorial in Moa’s sign-up and account settings interfaces, which explains how account pages affect what users can see.
Some participants emphasized that knowing Moa was built by a student was important for them. We thus highlighted this on a separate page.
To evaluate Moa, we conducted a field study for almost 3 weeks with 47 PhD students in two computing-related PhD programs at a public R1 university.9 This study was exempt-approved by our institution’s Institutional Review Board.
We sent recruitment emails about Moa and the field study to all PhD students in the two PhD programs. The study was also publicized on PhD-student-only Slack channels. After participants gave their consent, successfully verified their identity, and signed up, they were sent an email that their sign-up was approved, and to start using Moa after reading a tutorial about Moa.
We wanted participants to use Moa in a natural setting. Participants were asked to log in at least twice per day, but this was a recommendation. Participants who completed the post-study survey were compensated $10. Those who participated in interviews were compensated $30/hour. Among participants who posted or commented at least once, five were selected to receive $100. The likelihood of winning increased based on number of posts and comments.
A major challenge was attracting users to a new online space [79]. To tackle this, the first author made 4 posts as seed content based on their experiences, and then nudged 5 early users to comment. Participants were not aware that the seed content were posted by the first author, which was an approach used by Reddit’s founders [80]. Once we recruited around 20 participants, we sent two follow-up emails about user activity and the first author’s motivation for developing the system.
After a week of using Moa, users were asked to complete a survey and invited to an interview. 31 participants filled out the survey, and we interviewed 14 of them. We also collected and analyzed log data, with users’ consent.
Using Likert-scale questions, we asked participants how they perceived their experience on Moa and the concept of consent boundaries. We also included one open-ended question about what, if anything, the participant wanted to change or keep about Moa. Lastly, we asked if participants were interested in a follow-up interview.
Half of the interview participants used consent boundaries (7/14; Table 2). 9 out of 14 participants posted at least once. Of the 5 participants who did not post, 4 commented at least once. All interview participants gave consent to the first author to access their posts and comments.
We asked interview participants how they decided to use, or not use, consent boundaries. For those who did not use consent boundaries but still posted or commented, we aimed to understand what enabled them to do so. The interviews lasted between 20 minutes and 45 minutes.
The first author conducted deductive and inductive coding of interview transcripts and answers to the survey’s open-ended question. During the process, the first author periodically discussed the themes with the second author.
We also analyzed the data of posts and comments, along with user activity. This was communicated to the participants in advance of the study, via the consent form and Moa’s interface.
Our field study’s limitation is that we focused on the context of the United States. Future work should explore how the findings from this work could be applied to other regions’ contexts. Another limitation is that we deployed Moa in two PhD programs. In the future, we aim to conduct a longitudinal study on a larger scale to report more robust findings.
We sought to make the terms of using Moa very clear to all users, given that our study setting is very sensitive. We indicated both on the platform and in recruiting emails that the moderator (first author) had access to all content and meta-data. No posts were excerpted verbatim from the paper, and all references to posts were paraphrased. We made it clear to users that the moderator was monitoring the platform on the backend in case harassment or trolling occurred.
We also took care in deciding methods for user disclosure and use of personal background and identity. We designed our system based on one set of best practices in consultation with several peers with diverse gender identities. No participant was forced to disclose any part of their identity. And, we allowed users to self-describe any consent boundaries as they felt were relevant in an open-ended text box (Figure 3).
First, we report user activity on Moa and how users perceived the platform. Then, we discuss findings on consent boundaries and on features that enabled users’ participation.
Over 19 days, a total of 47 PhD students created accounts and logged onto Moa at least once. All users submitted at least some kind of user information when signing up, and most did not make changes to it.10 72.3% of the users submitted their current advisors’ names and 21.3% submitted their prior advisors’ names. 36.2% indicated that they were from PhD program A and 55.3% indicated they were from program B. We report participant demographics in Appendix.
15 users created 18 posts and 31 users left a total of 139 comments11 and users viewed posts on Moa 1,866 times (Figure 5). Moa’s users overall engaged with each other. On average, posts had 7.7 comments, and at most, one post received 17 comments. The comments had 98.5 words on average (Figure 5). Posts that asked for advice about their advising situation especially received comments with detailed advice—the longest was 757 words. Users tended to thank each other for the advice.



Figure 5: The first graph shows Moa’s daily post and comment volume, the second shows daily post views, and the last shows comment length distribution. On average, posts had 7.7 comments, with a maximum of 17. The daily post views averaged 98.2. Comments averaged 98.5 words, with the longest at 757 words..
With respect to the kinds of interactions that occurred, among the 18 original posts, 9 asked for advice (see Table 1).12 These included a range of sensitive posts where users asked for advice. The most sensitive posts were about seeking guidance on whether to switch advisors or add a co-advisor, as well as dealing with mental health struggles after switching advisors due to harm from a prior advisor. Other topics also included navigating gender dynamics with another advisee, seeking to diagnose reasons behind communication issues, how to cope when advisor is not receptive to feedback, and how to better work with their advisor given their mentoring style. In three posts, some users proactively shared personal experiences, such as how they switched advisors.
Overall, users’ reactions showed that they received real benefit from Moa. For example, P14 reached out to the first author on Slack saying “Thank you for making this system. I was in deep need for it.” In interviews, participants often commented that Moa enabled them to learn what good advising looks like and what “is not normal.” Survey results (Figure 6) also showed that many participants strongly agreed that Moa made it easier to have conversations around PhD advising relationships (average=4.45; median=5).
| # of posts | |
|---|---|
| Asking for advice about PhD advising relationships | 9 (50%) |
| Sharing prior experiences | 3 (16.7%) |
| Sharing positive stories | 2 (11.1%) |
| Sharing high-level opinion about PhD advising | 1 (5.6%) |
| Discussing PhD-related topics in general | 3 (16.7%) |
| Activity on Moa | Consent Boundaries Used | Set Default Consent Boundary | |
|---|---|---|---|
| P1 | posted/commented | advising challenge | no |
| P2 | posted/commented | none | - |
| P3 | commented | none | - |
| P4 | posted/commented | none | - |
| P5 | posted/commented | advising challenge | no |
| P6 | commented | advising challenge, advising status, race | yes + customized per comment |
| P7 | posted/commented | PhD program | no |
| P8 | none | none | - |
| P9 | posted/commented | none | - |
| P10 | posted/commented | none | - |
| P11 | commented | gender | yes |
| P12 | commented | advising challenge | no |
| P13 | posted/commented | gender | no |
| P14 | posted/commented | none | - |
7 out of 31 users who posted or/and commented (22.6%) set consent boundaries for at least one post or comment (Table 2). 3 out of 7 users used it for posting and 4 used it when commenting. For the three posts, they were sensitive in nature, although the degree of sensitiveness differed—one was about their advisor not being receptive to feedback, another was about gender dynamics in their advisor’s group, and the last one shared their experience of switching advisors. In the comments, users asked questions, shared one’s experience (e.g., having difficult conversations with one’s prior advisor), and expressed agreement or sympathy.
Contrary to what we expected, almost all users set a distinct consent boundary per comment or post. The majority (5/7) did not touch their account-level consent boundary at all, and only P11 used their account boundary setting as it is (Table 2). Users mentioned they found the consent boundary being “right there” and found it easy to apply them for each comment. More interestingly, some interview participants compared consent boundaries against existing privacy settings, which they noted were binary (public versus private). In contrast, participants thought consent boundaries are more contextual and thus wanted to apply them per post or comment.
“I kind of felt like I have so many different types of experiences that are for different groups that I don’t want to put something and then have to go back and undo it. So I felt like per post was nice. That way I can choose who sees what when I make the post...”-P13
The survey results showed that most users found the consent boundary features easy to understand (Figure 6). However, three out of the 31 survey participants commented that they found consent boundaries difficult to understand. Some interview participants also wished the feature was less overwhelming, although they understood why we included each dimension.
The feature for restricting consent boundaries was not used frequently, although one participant used it twice. P6’s comment was public at first, but they later made it visible to users who are Asian. Then, they updated the boundary so that the comment is visible to those who are Asian and have switched advisors.
The interviews showed that users tended to use consent boundaries differently. For some, consent boundaries were used to filter out specific kinds of users for privacy; for others, they served as a mechanism to proactively curate an audience for various reasons.
Specifically, three participants (3/7) used consent boundaries to protect their privacy by not making their post public. These participants posted or commented to ask or share personal experiences about their advising relationship, but did not want to increase the chances of revealing their identity—not just because of their privacy, but also because of their advisor’s. For example, P5, who used boundaries about certain kinds of PhD advising dynamics when posting a question, said:
“I wasn’t sure if I wanted everybody on on the platform to be able to see the post, mostly because it is kind of like a personal issue. And then I was also worried that people could identify me from it, and honestly, I think I didn’t want it to reflect badly on my advisor.”-P5
Interestingly, the rest of the interview participants who used consent boundaries viewed it as a way to proactively reach certain groups of people, rather than preventing some people from viewing their post. Their reasons included wanting to reach people who would better understand them, provide accurate responses, or find the content helpful. For example, P1 used boundaries related to certain kinds of advising challenges. To them, privacy concerns were not a reason for using consent boundaries, because they refrained from writing sensitive content. But, P1 still wanted to interact with people who could provide the most accurate insights.
” So I think I mostly used it [consent boundaries] to try to make sure that my comment reached the people that I wanted it to reach as opposed to avoiding people I didn’t want it to reach, if that makes sense.”-P1
In particular, two consent boundary setters emphasized wanting to interact with those who could understand them. For example, P6 wanted to help other PhD students by sharing their experiences, but in a way that minimizes chances of getting hurt by reactions from people who cannot understand them. This participant was the most active in using different kinds of boundaries. P6 explicitly said it was due to the desire to have an audience who could understand them, rather than reducing privacy risks.
“I think privacy in this specific experience might be less relevant because I feel like whatever consent boundary I set, I can be identified by sharing my experiences. [...] Or another way to put this is that I don’t expect or really want to be understood by all people.”-P6
Users showed mixed behaviors when deciding whether to display consent boundaries on posts or comments. Of the seven users who used consent boundaries, four displayed them, two kept them entirely invisible, and one alternated between showing and hiding their boundary.
Those who used and showed consent boundaries thought there was value in signaling whether a post was a “closed thread” for specific kinds of users. They noted that without visible boundaries, others might assume the post is public or be unsure about its visibility, making them hesitant to respond. For example, P5, used and showed boundaries of limiting their post to those who have experienced specific advising challenges, thinking that it would ease users to respond, since their comments will be viewed by those who had the same experience.
“I sort of just wanted to give some transparency to anyone who felt like they want to respond to this with a personal story. [...] I felt like if I were to set the standard in the first post, then maybe people would be more comfortable knowing that it had a limited audience to begin with.” -P5
In contrast, some tended to think that once the intended audience sees the post or comment, then the consent boundary itself is unnecessary information. That is, they used consent boundaries for audience selection, rather than for showing bits of their identity. P6, who was the most active in using consent boundaries, said:
“I feel like in reality, when a person sees a post or a reply, whatever the consent boundary is visible to them, doesn’t change the fact that they can see this reply. So I think [shown consent boundaries] is unnecessary information from that point.” -P6
Finally, a few interview participants did not want to show their consent boundaries because they thought it was a private information they wanted to keep to themselves.
Some interview participants thought seeing consent boundaries was helpful, because it provides more context on why the poster is reaching out to a specific group of users. For example, P11 noted that seeing a a women-only boundary on a post about gender dynamics made them want to engage with it.
“Like since they are showing a woman-only boundary, I will be very likely to respond to this post in a very, very honest way and support this woman student.”-P11
A few participants also raised ideas on making it possible for users to share parts of their identities in comments, regardless of setting a particular audience. For example, P13 said that this can be useful when a user finds a post that resonates with them because it is about a similar experience they have had, and wants to signal the connection to the poster.
Most posters and commenters did not ultimately set consent boundaries, and they also cited several reasons for not doing so.
One major reason was that they wanted to enable their post to reach the broadest audience, and thus made their content public. For example, P4, who publicly wrote about advice regarding advising relationships, said they wanted it to reach a lot of people. This was also the case for three interview participants who asked questions about the advising challenges they faced. These participants, however, were not posting publicly out of comfort. They disguised their content—e.g., by altering the gender of their advisor—so that readers could not identify them, especially given that they are from the same institution or program.
“I intended that (i.e., set their post to public) because I want to get advice from everyone who can be related and I don’t know who they are.[...] Moa’s users are highly related to me, so they can give me more direct and valuable advice. But at the same time, it makes me conceal myself more because I feel like they can easily guess it’s me.” -P10
For some users, anonymity through usernames, combined with the strict identity verification imposed by the system, were sufficient.
“For me personally, I’m an international student and I am kind of in fear of authority, but at the same time, I kind of trust you. Everyone on here is a student, so I don’t mind if everyone is a student, I don’t think they will do anything.”-P3
The multiple username feature was popular—20 users (64.5% of posters/commenters) created 54 distinct usernames, aside from their default username, when posting or commenting (average=2.7). 23.4% of all users changed their default usernames at least once, as well. The interviews and survey showed that this feature helped users feel reassured that others would not learn their identity.
Even for participants who did not know the first author well, Moa being developed by researchers in the same institution and detailed explanations of how we treat users’ consent increased Moa’s credibility. The first author’s revelation (in a recruiting email) of having switched advisors also helped. For example, P13 said:
“I think one was how much you were respecting our anonymity and our consent boundaries and things like that. I kind of felt it empowered me to post about things that maybe I wouldn’t have otherwise. [...] The description was part of it, where it was like, ‘We’re making this platform for this purpose, and it’s made by people who have had experiences that they’ve wanted to talk to other people about.’”-P13
Users’ credibility also incentivized some users to post. Interview participants said they could get more trustworthy advice because they knew the users were from the same institution, and not just a random person on the internet. For example, when asked what enabled them to post, P14, whose post asked for advice about navigating advising challenges, said:
“I think several factors. One is, well, the first thing I can seek advice. The second thing I was looking for something where I am anonymous. On social media and everything you’re mostly known, or if I go to my lab mates or anything they know who I am. The third thing is I know it’s within [institution name], so I’m sure where they are but I’m not sure who they are. It’s like I’m sure the people who reply to me are actually PhD students.”-P14
Some participants refrained from writing sensitive content (and did not use consent boundaries) because they needed more time to build trust in the system.
A few interview participants mentioned the possibility of directly reaching out to other users on Moa or wanting to meet in-person. That users wanted closer interactions was surprising to us, because it contradicted what the majority of our Phase 1 participants said.13 For example, a few Phase 3 interview participants said they wished Moa had a chat interface so they could more easily message others, while another said there was one particular user who wrote a post that made them want to connect in-person. These show that through Moa, some users developed trust in others, to the extent of wanting to take the risk to further interact with them.
“I guess if I know that only people with that consent boundary are now seeing the post and they replied, after the initial post, I would rather have a conversation with them. [...] I believe another feature that could help for very sensitive situations where I’m really not comfortable sharing it as a post would be having some kind of a private messaging.” -P4
When asked why, participants mentioned wanting to get more advice because they desperately needed to resolve their advising situation, and to obtain accurate signals about a person [81].
“There is a really impactful post [on Moa]. If I see an impactful post [like that], then I really want to reach out and get advice from them. [...] I want to meet in-person, and talk sincerely because their post is very sincere, and I’m touched by that.” -P10
It seems that while some risk-averse participants considered Moa to be useful, they believed that giving or getting more sensitive information should happen outside the platform, with discussions on Moa being a basis for such connections. For example, P1 pointed out that Moa could be a starting point for in-person meet-ups.
“If there was like, okay, based on all of these topics that we’ve discussed, there’s going to be these in-person meetings based on these conversations, and we’ll sit there and have a safe space of being able to talk in a non-technology facilitated way, but using this [Moa] as a way to filter what those topics would be, that’s something I would probably use more.”-P1
We describe the most interesting feedback on improving Moa.
One interview participant said while they were not so sure how it should happen, they thought it would be worthwhile to invite faculty to Moa, as they could gain exposure to students’ experiences and learn about mentoring.
Some interview participants wished there were more users, and not just from two PhD programs. However, even these participants perceived benefits of interacting only with those from the same program, and said the consent boundary could be a way to easily show their post to them.
Multiple interview participants wished the consent boundary interface was more usable. One participant suggested a feature that gives users a sense of the audience size when applying a consent boundary. Related to the flexibility of applying different consent boundaries, one participant recommended using a computational modeling approach so that the system could recommend consent boundary settings based on each post.
Moa enabled a range of sensitive discussions, with a quarter of participants using consent boundaries—typically a separate boundary per post or comment. Users tended to use consent boundaries differently—some used them to simply remove users to reduce privacy risks; others used them for proactive audience curation, to reach those who are sympathetic, could provide useful input, or find the content helpful. Some participants valued displaying their consent boundaries, while others chose not to, because they used them solely for audience configuration. Finally, a few participants expressed interest in directly contacting another user on Moa or meeting them in person, which was surprising compared to the results from Phase 1.
Combined, the existing literature on enabling sensitive conversations makes many recommendations, but they are scattered across multiple papers [19], [23], [48]. Here, we pull them together to provide a state-of-the-art, socio-technical “recipe” for such systems. We present it in two layers: One layer mentions the high-level objectives sought (indicated by the boldface headings below); the second contains specific features that enable elements of the first layer (boldface, in parentheses).
As prior literature shows [19], [23], and our Phase 1 study confirmed, providing users anonymity is important. Complete anonymity, however, can make discussion threads difficult to follow. A good compromise is to allow users to create pseudonymous usernames—many of Moa’s users created multiple pseudonyms. Avoiding profile pages, as Whisper does, also enhances anonymity. None of our field study participants said they wanted a profile page, and one participant explicitly said they liked not having them.
System credibility requires technical privacy and security protections as a baseline, and Moa assured users of that, but there is also a social element. Confirming findings from online systems in general [82], Phase 1 study showed that they would use Moa more if it were run by people they trusted, especially a PhD student peer. A few participants of Phase 3 also noted that Moa’s emphasis on consent was intriguing to them, and enhanced the system’s credibility.
Credibility of users is also critical, as prior work has noted [19]. One important factor is for the user base to be limited to some sort of affinity group. In Moa’s case, all users were PhD students at the same university. Phase 3 participants noted that one reason they found Moa more useful than, say, Reddit, was because they could expect more relevant responses from peers who shared a lot of context. We also believe that it was easier to trust other users because it was a limited, familiar, and moderated community. In the future, we anticipate Moa could be opened to various institutions, but users would still be able to post to others within the same institution using consent boundaries.
An engaged atmosphere is essential for any thriving online community [79], but for sensitive discussions, the culture must additionally be empathetic. To enable this, we believe appropriate seed content, community rules, and moderation are critical, especially at the beginning. Because many Phase 1 participants said they would lurk first before deciding they could trust the system, the first author seeded posts based on their personal experience. Two Phase 3 interview participants noted that one of the seed posts was memorable. Furthermore, Moa’s community rules emphasized Moa being an supportive community for PhD students. And, we believe in-group moderation is essential. Moa’s users seemed comfortable with moderation, likely because Moa’s moderator was a member of the user base. This is in contrast with prior work, in which participants raised questions about moderation, because an external research team handled it for the study [19].
For users who want to discuss topics or share experiences that are highly sensitive, granular control over who can see their posts seems to increase chances of engagement. For Moa, this was enabled by consent boundaries. The Phase 3 evaluation showed that consent boundaries lowered the barrier to posting for some users, especially for risk-averse ones. Even for users who had less privacy concerns, consent boundaries still provided benefits of reaching out to the right audience. We also note that there was arguably an implicit consent boundary of all users being PhD students from the same institution. Furthermore, the users also consented to the moderator seeing their posts, which could be seen as another implicit consent boundary due to the study design. These could explain why the consent boundary’s usage rate was 22.6%—the default, implicit consent boundaries already provided an audience that made most users comfortable enough to post.
Finally, it is important for all of the above to be visible to users. Messaging on the system should highlight key system features repeatedly. In Moa’s case, the goals and features of the platform were noted on the landing page, emphasized in recruitment emails, and scattered throughout the platform’s interface.
While many of Moa’s features are drawn from known social media designs, consent boundaries are a novel design contribution. Two Phase 3 participants (P11 and P13) mentioned explicitly that they had never seen anything like consent boundaries. Below, we discuss the values and novelty of consent boundaries, and then outline how to further improve them.
First, as participants noted, consent boundaries offer highly relevant, context-focused dimensions for audience selection. In the case of PhD students discussing advising challenges, the dimensions were related to social identity, academic experience, granular information about the institution, etc.—such dimensions are not offered by existing platform structures [25] or access control systems, most of which offer simple subsets such as “private / friends / public” or technically defined groups such as “administrator, editor, viewer.”
Second and related to the point above is that Moa’s consent boundaries offer finer-grained dimensions than existing social media or access-control systems. Based on Phase 1’s findings, the types of boundary dimensions span the full range of unions and intersections of various groups. And, Phase 3 participants who used consent boundaries leveraged different kinds of dimensions.
Third, our design of the implementation of consent boundaries carefully attends to the process of setting them. In contrast, most platforms treat audience selection as a rarely adjusted element that requires users to navigate complex “Settings” features. Our implementation honors the principles of affirmative consent [15], by ensuring that every step of consent-boundary-setting respects user consent. For instance, to ensure consent specificity, users can select a boundary for each post and comment; and indeed, Phase 3 participants tended to do so.
Despite the potential value of consent boundaries, there is a tradeoff with usability. With advancements in AI, one could imagine a system could learn how a user uses consent boundaries, and then make suggestions [15]. Or, a user could type their consent-granting preferences in natural language, and the system automatically suggests boundary dimensions. (Of course, such an approach might have to wait until AI models are perfect with respect to interpreting user requests in order to adhere to the principles of affirmative consent.)
Another challenge is that for some consent boundaries, whether a user is inside of them may not be readily verifiable. For example, users can ask to have a post be visible only to others who have experienced bullying by their advisors, but whether a user has had such experiences cannot be easily confirmed. It is therefore possible that a user reports their experiences inaccurately and gains access to discussions. Strict fidelity to affirmative consent would not allow such leakage; maybe such dimensions should not be implemented. It is also possible, however, that compromises should be made to facilitate the desired communication. Future work should explore these tradeoffs.
Taking a consent-centered approach was essential to developing Moa. While consent and privacy are closely related, there is a subtle difference in emphasis. Speaking strictly from an engineering standpoint, consent boundaries are like privacy settings—they give different permissions to different sets of users. But, they differ from traditional privacy settings with respect to the categories of user-sets that can be formed, the granularity of control, and most importantly, the way the categories align with users’ own preferences for control. Below, we reflect further on how consent differs from privacy, and what consent means for system development.
To begin, privacy is a fuzzy concept—scholars disagree on how exactly to define it, though definitions cluster around themes such as the right to be left alone, restriction of access, secrecy, control over personal information, personhood, and intimacy [83]. One relevant ambiguity in the context of computing is about who provides privacy: Privacy can be conferred to a user by the user themselves, or by a privacy-protecting system.
In contrast, the essence of consent is that it is strictly user-determined. The only entity who can grant an individual’s consent is the individual herself; there is no definition of “consent” in which a system can grant itself consent to do something to a user that the user does not herself wish to allow. Thus, relying on the term “privacy” can obscure the central role of the user, as privacy encompasses multiple, often ambiguous meanings. Arguably, the reason why "user-centered privacy" is a term distinct from general privacy is because the user-centeredness of privacy is not a given. Yet, even within the usable privacy and security community, discussions of consent have been limited to the notice-and-choice paradigm [63]. Consent is not cast as a foundational principle for system design. Based on this view, systems frequently define privacy options in advance (i.e., the system is conferring some privacy), with users only able to accept or decline them. In practice, these options are often difficult to find or understand, further limiting true user consent. For instance, many of Facebook’s privacy settings are often hidden [84].
As the feminist affirmative consent framework recommends [15],14 consent should not merely be a mechanism for relaxing privacy constraints, but a foundational principle of design: individuals affected by an action should have the agency to define exactly what their consent boundary is, in the way that they conceive as relevant to a particular context.
Originally, Moa was conceived to help students resolve their advising challenges, but we recognized the problem space was very large, and narrowed our scope to ally discovery. But as reported, some users were considering next steps beyond ally discovery. A few Phase 3 participants mentioned wanting to meet another user in-person or wished it was easier to have a 1:1 interaction on Moa.
How could a system like Moa be extended in future research? One line of work might involve developing mechanisms that enable non-anonymous connections for collective action. While Moa has allowed PhD students to have conversations around advising relationships, nobody revealed their identity to other users. To make consentful non-anonymous connections easier, future work could explore embedding an information escrow into Moa so that users can gradually build trust in each other, to the point of revealing their identities to one another. Information escrows are systems that connect two parties or enable information exchange, only if both provide information (to the system) that both agree would be sufficient for trust [6].15
However, one drawback of escrows is that they are private until the match happens—users cannot observe others, which is important for developing enough trust to submit information to escrows in the first place. We suspect it is possible to provide a middle ground by embedding information escrows within a platform like Moa, so that users can give and receive signals for reciprocal self-disclosures [86]. For instance, users can observe each other’s comments on Moa, and then decide to submit information after building a sufficient level of trust.
Another interesting direction is supporting users working together to arrive at a plan for action—especially in order to communicate with those in power. For a consent-based intervention to provide agency to those with less power, it helps to communicate with, or have the agreement of, parties in power—in Moa’s context, faculty. We noticed some participants were thinking about this. Unprompted, some participants from both Phase 1 and 3 mentioned that Moa could be extended to convey PhD students’ experiences to faculty. This requires a group of users to collectively plan and act [20], [87]. In particular, there are interesting questions around whether revelations about the identities of group members seem necessary, and if so, how that can be accomplished.
Some users showed consent boundaries to signal that the audience shares a common identity trait, in order for other users to chime in more comfortably. This was the most pronounced for a post that was about gender dynamics, where the poster used a women-only boundary. Most of the commenters also decided to use the same boundary for their comments and chose to display them.
Relatedly, a few of Phase 3 interview participants also noted that the commenting feature could be designed so that it is easier to display parts of one’s identity when responding, which resembles meronymity [52]. Moa could potentially be extended to provide users with such features, so that once an audience restriction has happened, users within the thread could more freely express parts of their identity if they wanted to, separately from using consent boundaries.
Some users who did not show their consent boundaries thought they did not add much information, since the post will be delivered to the right audience anyway. These Phase 3 participants were less concerned with expressing identity and more focused on audience control, possibly because Moa’s context centers on sensitive power dynamics, unlike prior work (e.g., [23], [52]). For example, while meronymity [52] was evaluated where different levels of seniority exist, the focus was on academic research discourse, rather than power hierarchies.
Currently, Moa is maintained by the lead author in order to minimize privacy risks. Running the platform with 47 users turned out to be feasible—the lead author was diligent in moderating and seeking user feedback, and no incidents of abuse or negative feedback occurred. However, how could Moa and the concept of consent boundaries scale?
One way to scale is having multiple instances of Moa, one per organization or group, each with its own administrator, similar to Mastodon. This approach reflects an important assumption that local system admins are important for earning users’ trust, which was confirmed by our Phase 3 study. And, just as research shows that Reddit’s moderators have their own network of giving each other support [88], we imagine that there should be a support network for Moa’s administrators and moderators. This would ensure that each instance is not entirely isolated, and that when sensitive incidents happen, there would be cross-instance resources on how to resolve them.
It is possible to imagine building Moa as a larger, monolithic platform such as Facebook or Reddit, but we imagine even on such a platform, communities would have their own moderators—each trusted by their respective communities—who are empowered to provide the kind of meaningful oversight over identity that the Moa prototype included. For this study, it was easy for users to verify and understand that the moderator was also a PhD student in the same institution. At larger scale, there would need to be a process for selecting such moderators, and proving their identity to other members of the community.
In terms of consent boundaries, they are likely to be applicable to other contexts beyond PhD advising, such as among workplace employees [89], [90], survivors of sexual misbehavior by one group of people [91], [92], or potential whistleblowers at the same organization [93]. One aspect of the Moa prototype described in this paper was that there was an implicit consent boundary formed by the community of PhD students from the same institution—no user needed to consider whether their content would be revealed to non-students. Communities could be formed much like Slack’s channels around different topics, though additional mechanisms such as member-sponsored invitations to join or formal background checks would be required to ensure that community members satisfy membership requirements.
We also imagine consent boundaries could be used in general platforms such as Facebook or Reddit, likely in less sensitive contexts. Consent boundaries could help users carve out a group of people they want to interact with, without having to designate a particular space or network [25]. This would resemble the “social circles” features on platforms such as Close Friends,16 but it would not require individual enumeration of members or knowledge of other users’ identities. For example, users who were exchanging comments under a post on a subreddit could use consent boundaries to easily create a space within the thread for users that meet particular criteria. At the same time, when consent boundaries are used within a large-scale commercial platform, there might be a bigger hesitation for users to use the feature. It may take a longer time for users to build trust in consent boundaries, as failures could result in unintended exposure of posts to a broad audience. Because of this, the usage rate could be much lower in the beginning.
When individuals experience harm from someone in power, finding allies—people who are sympathetic or willing to navigate an issue together—is important. To understand how to develop a social platform that supports sensitive conversations for ally discovery, we conducted interviews with 19 PhD students, which revealed a strong desire for a platform that connects peers to discuss PhD advising relationships, and reinforced the importance of consent in enabling these connections. Building on these findings and the affirmative consent framework, we developed a social platform called Moa. One of Moa’s core features is the “consent boundary,” which allow users to fluidly demarcate who can view each post or comment based on dimensions such as social identity, lived experience, and interpersonal relationships—while preserving mutual anonymity. The sender and recipient do not learn of each other’s identity, even as the post reaches the intended audience. We conducted a three-week field study with 47 PhD students that showed Moa successfully facilitated ally discovery. Consent boundaries lowered barriers for some users, enabling them to ask sensitive questions and provide authentic advice. In all, this work presents insights on how to develop a social platform for ally discovery and instantiates a consent-centered approach to system design.
We sincerely thank all participants. A big thank you to Vikram Mohanty for being a sounding board throughout the system development. Chaerin Im deserves a very special shout-out for encouraging Im to build a new social media platform in 2021. We also thank Jiyoon Kim, Shwetha Rajaram, and Yulin Yu for their immensely kind support and great feedback. Yunseok Jang gave much needed suggestions for the tutorial. Im also thanks Amy Ko, Mark Ackerman, and Emily Mower Provost for their very helpful comments. Im was supported by a Meta Research PhD Fellowship.
55.3% were international students, 38.3% were domestic, and 6.4% did not submit any relevant information. 48.9% of the users were women, 31.9% were men, 2.1% were non-binary, and 17% did not submit gender information. 65.9% were Asian, 14.9% were Caucasian, 8.51% were Middle Eastern or North African, 4.26% were of Hispanic, Latinx, or Spanish origin, and 2.13% were Black or African American. 4.2% had mixed race and 6.4% did not submit information.



Figure 7: Example designs that show a system for enabling PhD students to connect around advising challenges..



Figure 10: Moa’s sign-up page. Users are asked to voluntarily submit identity-related information, PhD program, advisor names, and challenges experienced in advising relationships..


Figure 12: Moa’s posting interface. Users are prompted to think about the goal of why they are posting, and can set a different username. The rest of the posting interface is shown in Figure 13..


Figure 13: Moa’s posting interface (continued from Figure 12). A user can set a specific consent boundary per post and also decide whether to show the boundary to those who can see the post..
We have coined this phrase because literature in political science, collective action, and social movements does not appear to have a phrase representing individuals searching for and finding previously unknown allies. Related terms include “coalition formation” [4] and “boundary activation” [5] but these tend to focus on the building of group solidarity, not the initial person-to-person identification. We also note that while the connotations of “allyship” often imply support across power asymmetries, our usage is more general and does not assume differences in power or influence.↩︎
“Moa” is a transliteration of “모아,” which is the conjugated form of the Korean verb “모으다” (to gather).↩︎
Among existing platforms, Whisper also does not provide profile pages.↩︎
For users who did not feel comfortable leaving their institution email address in the database, Moa lets them change to a personal one after signing up.↩︎
On Blind, a user has to go to their account setting to change their username. Since August 2023, Blind allows users to change their username once per day. Previously, it was allowed 5 times per month. https://www.teamblind.com/post/New-More-username-changes-7CXLWNB4↩︎
We note that was a deliberate design choice among several options. For example, a platform could let users set boundaries that they are not themselves within, perhaps to seek opinions from groups they are not members of. However, that can open the door to misuse without additional safeguards, so for this work, we opted for the more conservative option.↩︎
One PhD program has over 100 PhD students, and the other has over 200 PhD students.↩︎
8 users (17%) submitted more information afterwards, and all updates seemed valid (i.e., users did not falsify information). The updates consisted of submitting advisor name, advising dynamic experiences, whether one is an international student, gender, race, year in PhD, and PhD program.↩︎
These numbers exclude the seed content the first author created.↩︎
Four posts were deleted; we did not include these in the final dataset.↩︎
Many Phase 1 participants did not want conversation on Moa to be too private and some also emphasized that they would never reveal their identity (Section 3.2.4).↩︎
Of course, how people express consent can be different, and there is an abundant literature on understanding such a range of expressions regarding demographic factors. Feminist scholarship on consent is a major example of this (e.g., [60]). However, these differences in expression do not diminish what consent fundamentally does.↩︎
Bad actors could try to submit false information to information escrows. We believe the most feasible approach to address such issues is to have human moderators. While there could be scalability issues, systems like Callisto [85], show that it is feasible for escrow systems to be implemented with moderators on a scale of spanning multiple campuses. https://www.projectcallisto.org/callistovault↩︎
https://www.facebook.com/help/200538509990389?helpref=faq_content↩︎