Back to News & Insights
Artificial Intelligence August 16, 2026 · 6 min read

How do you form a group nobody can admit they're in?

Arun invoiced a design agency ₹1,20,000 in January. It's August. He is in a 4,000-member designers'...

How do you form a group nobody can admit they're in?

He is in a 4,000-member designers' Discord. He could post the agency's name right now and warn everyone. He won't, and you already know why: the freelancer who publicly names a client stops getting briefs. He'd pay for it alone, and everyone else would benefit.

Here's the part that makes it a systems problem rather than a sad story. Three other people in that same Discord are owed money by that same agency. None of them knows. Each one is running the same arithmetic Arun is, arriving at the same answer, and saying nothing.

Four people who together have real leverage. Individually, none of them can afford the first move.

I built an agent for this over a hackathon weekend. The interesting part wasn't the AI. It was that every obvious solution destroys the thing you're trying to protect.

To join, you say who burned you. Now the group knows. One screenshot and Arun is on a list.

Better. This is roughly how Callisto Vault handles assault reports, and it's a good pattern. But it reveals the group to its own members at the threshold. Four people now know each other's names and amounts. Four times the leak surface, arriving exactly when things get tense.

Nobody is exposed. Not to the channel, not to the accused, and not to each other — not even after it works.

Which sounds impossible, because how do four people coordinate if they can't know who they are?

One sentence Arun wrote himself. An amount band, not his figure. A counter. The agency's name is nowhere on it, in any state, ever.

That's the whole trick, and it's easy to misread as "we're being cautious". It isn't caution. The accused agency might be in that Discord. The board has to be safe to read for the very person it's about.

So the board can't tell you who it is. Which raises the obvious problem: how does a real fellow-victim recognise it?

You tap JOIN, and the agent DMs you the intake steps: email us, and name the client yourself.

That's the admission test. Not a password, not an invite code. It's the one thing only someone in the same situation would know. Get it right and your pip fills. Get it wrong and your claim is held, sealed, and nobody is told anything. Crucially you don't learn whether you guessed right, so nobody can use the system to fish for the name.

When you tap JOIN, the bot knows your Discord identity. When you email, it knows your address. Storing discordid → claimantid would be one line and would make a dozen features easier.

That line is the entire attack surface. One leaked table and every claimant is public.

So the bot never says who tapped, and the join reply is written to be impossible to personalise:

There's a side effect I like: you can tap JOIN twice and the bot won't remember you. It looks like a bug. It's the guarantee, visible. To recognise you, it would have to have stored the link it promised not to store.

At four matching claims, one email goes to the agency: four documented claims, the combined total, the age of the oldest. No names.

Want to discuss this further?

Book a free strategy call with our team to see how these insights apply to your specific business goals.

Book a consultation