# v2: platform, community and safety Accounts, safety, content policy and ratings, contributions and the mod hub, claiming houses, input and UI, and platforms. Index: `agents/world-format-v2.md` (PEGI 18 decision). Schemas: `agents/v2-formats.md` sections 5 (mods, lockfile), 12 (approvals), 13 (world rules), 15 (performer releases). Legal reads are owner tasks (index, "For the owner"). ## Accounts, safety and moderation (from day one) - **Accounts:** a real accounts system from the start, because claims, proposed edits, bans and moderation hang off identity. Sign-in starts with the Google auth g-system already has (redirect flow under cross-origin isolation); more providers later. - Kids contributing + multiplayer + eventually chat = a user-to-user service under the UK Online Safety Act. The layer model does most of the work: personal is private by default, canonical is curated, proposed is the review queue (agent-screened first). - **Claiming a real house can reveal where a child lives.** A claim never implies residence, claimant identity is hidden from strangers, and "this is my actual house" is never shown. - **Voice chat** off or friends-only for under-18s, which needs age assurance (Ofcom's children's codes, in force since July 2025). - **Telemetry and crash reporting** (WebGPU device-lost, WASM panics, perf data feeding the budgets) default off for children (ICO Children's Code). - **Real brands and liveries** (Greggs, named pubs, Northumbria Police) carry trademark and defamation risk: keep an "invented equivalent" layer that can replace them (vehicle brands: `vehicles.md`). - P2P and IP exposure: under-18s are relay-only (`networking.md`). ## Content policy and ratings **DECIDED 2026-09-27: the canonical world is PEGI 18 for now** (the owner's call; a PEGI 12 canonical world was the proposal). Consequences, all carried by the `rules` component so the choice is cheap to revisit: - Under-18s can't be in the canonical world. Accounts need highly effective age assurance from day one (OSA children's duties). - Kids and school groups get worlds on the 12-rated rule set, the `rules12` preset (`violence: "stylised", blood: "off", gore: false, weapons: [], pvp: "off", pedHarm: "down", language: "mild"`); contributions from under-18s go through those worlds. The canonical world is the `rules18` preset (realistic violence and blood, gore on, lethal ped harm, PvP opt-in). Schemas in formats section 13. - Limb detach is on in canonical (a world rule, `gore: true`). - Steam: the base game's survey declares 18 content; no separate adult package needed while canonical is 18. (This supersedes the proposal's "above 12 is private-world only, verified 18+" and "adult rules as a separate Steam package".) **Why the 12-rated preset exists** (the original proposal, now `rules12`): v1 is effectively 18-rated by content (shooting peds and cops, blood, dismemberment in `peds.js`, killing as the main way to raise wanted level). On real Newcastle streets everything reads as realistic, and shooting defenceless bystanders is PEGI 18's line. A 12-rated world is stylised, no blood (flash and stagger; ragdolls stay), no dismemberment, nothing rewarding attacks on bystanders; violence mostly against property, vehicles and destruction (Teardown's lane); car theft, chases and heists against property stay. **Mechanism:** - **World rules are a component on the world entity** (principle 7): `rules{violence: none|slapstick|stylised|realistic, blood: off|stylised|realistic, gore, weapons: [ids], pvp: off|opt_in|on, pedHarm: none|down|lethal, language: none|mild|strong}`. Systems read it; nothing hard-codes a rating. Roblox's light-vs-heavy realistic blood split is the `blood` scale. - **A world's rating is computed** as the max over its rules and its mods' declared IARC-style descriptors (violence, blood, fear, language, crime, user interaction, nudity, gambling), checked by the agent screen: the same bookkeeping as the lockfile. - Under-18 contributors can't publish missions whose goal is harming characters. **Law and ratings (UK):** a rating is not a legal gate for a free browser game (the Video Recordings Act covers physical supply; unverified). Steam uses its own Content Survey and counts content in the build **even if not accessible**. The OSA's children's duties cover *user-generated* content; provider content (s.55) is excluded, so the policy engine belongs at the mod and world boundary. s.62 lists realistic serious violence as priority content harmful to children, which needs highly effective age assurance. ## Contributions and the mod hub (design 2026-09-27) **Contributors never touch git.** Every way in produces the same `Submission` (files, a licence record, declared capture method, account id) into the proposed-layer pipeline. GitHub stays for engine code (its terms need 13+; PRs are the wrong tool for a voice line). - **Intake, three ways, one queue:** forge "submit" (the main route; forge output is already a mod package); a web upload portal per asset kind (splats, photos, voice, models); an upload-only Discord bot linked to a game account by one-time code, never allowing strangers to DM. - **Rights: licence, not assignment.** Contributors keep copyright and grant a worldwide, royalty-free, non-exclusive, perpetual licence **with the right to sublicense** (needed to mirror content to Steam Workshop); the asset is public under CC BY 4.0 by default (CC0 optional). OSM's lock: we may relicense only to free/open licences. One tick box at submit (Wikipedia's model). No DCO. - **Minors:** contracts with under-18s are generally voidable (verify with a solicitor) and under-13s need parental consent for data (UK GDPR Art 8). So every under-18 account has a **linked parent account** confirming the licence grant; one flow solves both. Revocation is a republish through the alias table. - **Voice:** a separate performer release (performers' rights, CDPA Part II) scoped to game, trailers and Steam. **Voice cloning or TTS training excluded** unless separately and revocably opted in. Children's voices need parental countersignature; names not published by default. - **Capture rules:** buildings and sculptures in public places are fine (CDPA s62 freedom of panorama). **Flat art isn't** (murals, graffiti, posters, shop signage): a detector swaps them for invented equivalents. Faces and plates blurred at ingest, EXIF/GPS stripped, raw files private and short-lived. Public highway only; no real home interiors, nothing over garden fences. A public **"remove my house"** form swaps in a generic facade. - **Mod hub:** Workshop-like search, tags, per-item age rating (from the computed world rating); thumbs up/down; no public comments for under-18s; immutable content-addressed versions pinned by lockfiles; an item report button. **Takedowns:** the UK hosting defence (E-Commerce Regs 2002 reg 19) means a notice form, fast removal, counter-notices, three-strike repeat infringers; a US DMCA agent once on Steam. **Curating content into canonical arguably makes it our publication** and loses reg 19, so promotion to canonical needs a stricter provenance check than private mods. - **Moderation:** tier 0 automatic at upload (sandbox caps, hash and size, image and text classifiers, speech-to-text slur and PII scan, face/plate detector, flat-art check); tier 1 an agent with reasons that can quarantine but never ban; tier 2 Gabriel plus a few trusted adults weekly for appeals, bans and anything about a child's safety. No adult-to-child DMs anywhere. **The OSA applies at any size:** write the illegal-content risk assessment and the children's access assessment before public upload opens. CSAM hash matching (IWF or a vendor) once images are user-supplied. - **Credits:** in-game plaques on buildings someone made, handle only, opt-in. **Never on claimed houses** (that recreates the child-location leak). A credits roll in the forge. - **Money:** no creator payouts in v2 (DevEx and UEFN-style payouts need KYC, tax and compliance staff a hobby doesn't have, and DevEx draws child-labour criticism). Donations to the project only; income over the trading allowance means Self Assessment. If payouts ever happen: through Steam, 18+ only. - **Steam Workshop:** 13+; uploaders grant Valve a licence; community mods from authors' own accounts, the curated canonical set from the project account. ## Claiming houses - A claim binds a player to a registry building id. The claimed building's interior and plot are a personal layer they own; they choose who sees it (just me / friends / public once proposed). - Simplest model (GTA Online): exterior stays shared, interior is instanced per owner, so two players can "own" the same house without contention. Scarcity (Second Life parcels) or team territories (Build The Earth) are options layered on top, not needed first. - Open (index): one claim per real address? Do we verify anything? (No: it's a game; but claiming someone's real home and decorating it offensively is the abuse case.) ## Input, UI and accessibility - **Action map, not keys:** actions bound per device with rebinding, and a touch scheme (kids play on iPads and Chromebooks; v1's `pad.js` targets a DualShock 3 and there is no touch play). Forge touch controls: `missions-and-forge.md`. - **Mod UI through a sandboxed, declarative widget API**, never raw DOM (gmod's Derma is the lesson). - **Accessibility:** subtitles for the Geordie voice lines, colour-blind-safe police red/blue, toggles for camera shake, motion blur and depth of field. - **UI strings in a string table from day one**, with Geordie as an optional dialect locale. ## Platforms: web now, Steam later Decided: web first; a Steam port eventually. The decoupling makes the port cheap: - **The Steam build wraps the web build** (Tauri/Electron + Steamworks; decided with the renderer, 2026-09-26). Workshop, achievements and overlay work that way. - **The Rust simulation core** targets WASM and native; the server runs it natively too. - **The renderer reads the snapshot.** A wgpu renderer (same Rust and WGSL on WebGPU and on Vulkan/Metal/DX12) stays possible through that seam but is deferred indefinitely. - **Platform services sit behind thin interfaces:** storage (OPFS vs files), networking (WebRTC vs Steam Networking Sockets), input, audio output, accounts (Google vs Steam), mod delivery (our CDN vs **Steam Workshop**, which maps directly onto mod packages and lockfiles). Nothing above those interfaces knows which platform it is on.