Privacy is not free
Making a room private feels like a safe choice. It is reversible, it protects information, and nobody ever got in trouble for restricting access.
But it has a cost that is invisible at the moment you make the decision. Everyone outside the room loses the context inside it, and they lose it silently. They do not know what they are missing, so they cannot ask for it. Decisions get made that other people are then expected to act on without knowing the reasoning.
That cost accumulates. A team where most conversation happens in private rooms is a team where most people are working from partial information, and where a handful of people spend their time relaying context that would have been free if the conversation had been open.
The default
Open unless there is a specific reason to close it.
Note the word specific. "This is sensitive" is not a reason, because almost everything can be described as sensitive if you are looking for a justification. A specific reason names who would be harmed by seeing this and how.
The reason to default open is asymmetry. If a room is open and it turns out something private needs discussing, you can move that conversation. If a room is closed, the context never reaches the people who needed it and you will not find out.
Four cases where private is right
1. Information about a specific person
Performance, pay, disciplinary matters, someone's medical or personal circumstances. This is the clearest case and it needs no debate. It also should not be in a room at all if it is genuinely formal; some conversations belong in a direct message or in an HR system rather than in any team space.
2. Legal or commercial matters with real confidentiality
A dispute with a supplier, terms of an acquisition, anything covered by an NDA. The test is whether disclosure would cause actual harm, not whether it feels awkward.
3. Contractors and external parties
Here the logic inverts. The room is not private to keep information from your team; it is scoped so an outside party sees only their engagement. A freelancer working on one project should be in a room about that project, not in your general operations. This is the most common legitimate use in a small store, and it is worth setting up before the contractor arrives rather than after.
4. Work in progress that would be misread
The weakest of the four and the most abused. Sometimes a genuine case: modelling a price rise, or considering whether to drop a product line, where a half-formed conversation would cause alarm if read as a decision.
Be honest about how often this actually applies. In most teams it is invoked far more than it is justified, and it shades into "I do not want to explain myself", which is not a confidentiality requirement.
Three bad reasons that look good
"It would be noise for everyone else." This is an argument for a separate room, not a private one. Let people choose what to follow rather than deciding for them. Noise is a filtering problem, not an access problem.
"Only three people work on this." Today. Someone will cover next month, and they will start from nothing. Rooms outlive the people currently in them.
"We might discuss something sensitive at some point." Then discuss that thing elsewhere when it arises. Closing a room in advance against a hypothetical costs you context every day in exchange for a problem you have not had yet.
The visibility question people forget
Separate from who can read a room: can people outside it see that it exists?
Most of the time you want them to. A visible-but-closed room tells the team that a conversation exists and they can ask to join, which preserves trust. Someone discovering that entire areas of discussion were invisible to them tends to react badly, and reasonably so.
Fully hidden makes sense in a narrow set of cases: the existence of the room is itself the sensitive part. A room named for an acquisition target, or one about a specific employee. Outside those, hidden rooms cost more in trust than they save in confidentiality.
In Store Huddle this is why rooms, private rooms and private categories are distinguished. A private category stays invisible to anyone outside it, which is the right tool for the narrow case and the wrong tool for the common one.
The review nobody does
Private rooms accumulate. Each one was justified when created, and nobody revisits them, so a team ends up with a dozen closed rooms where three were needed.
Twice a year, list them and ask two questions of each: does the original reason still apply, and is anyone in it who should not be?
The second question is where the real finding usually is. Someone who joined for a project two years ago is still there, still able to read everything, and nobody has thought about it since. That is the same lingering-access problem that shows up with Shopify staff accounts, arriving through a different door.
Rooms are easy to create and socially awkward to close, so they only ever accumulate. Twice a year, make closing them somebody's job.
Opening a room back up
Rooms almost never travel in this direction, and it is worth knowing how because the option existing changes how readily you close one in the first place.
The obstacle is history. Making a room open exposes everything previously said in it, and people wrote those messages believing the audience was smaller. Even where nothing is sensitive, the tone was calibrated for a different room.
So do not retroactively open a room. Instead, create a new open room, post a short summary of where things stand, and archive the old one. It takes ten minutes and it avoids the situation where someone discovers a candid remark about them from eight months ago.
The exception is a room that was closed for a reason that has simply expired: a project that has shipped, a contractor engagement that has ended. Skim it first, then open it. Skimming is the whole safeguard, and it is quick.
The naming problem
A room name is visible to more people than the room's contents, and names leak.
A private room called "hiring-replacement-for-sam" tells anyone who can see the room list exactly what is happening, which entirely defeats the privacy you set up. The same applies to supplier disputes, acquisitions, and anything concerning a named person.
Where the subject is sensitive, name the room for its function rather than its subject, or make the category itself private so the name is not visible at all. This is the narrow case where full invisibility is genuinely the right tool, and it is worth deciding at creation time, because renaming later does not un-tell anyone.
What to do when someone asks to join
A visible-but-closed room will produce requests, and how you handle them sets the tone for whether people trust the whole arrangement.
Answer quickly, whatever the answer is. A request left hanging reads as a no delivered rudely, and people stop asking, which is the outcome you least want.
When the answer is yes, which it usually should be, just add them. When it is no, give the actual reason in a sentence. "That one has payroll discussion in it" is fine and lands well. "It is not relevant to your role" is a non-answer that people correctly hear as a brush-off.
If you find yourself declining regularly for the same room, look at whether the room is doing two jobs: a sensitive core and a lot of ordinary operational chat that would be better off open. Splitting it usually costs nothing and removes the friction entirely.
Direct messages are not the answer either
Teams that resist private rooms often end up somewhere worse: the conversation moves into direct messages between two people.
That has every downside of a private room and one more. A private room has a membership that someone can review, and a record that outlives the people in it. A direct message thread is invisible to everyone, is not reviewable, and disappears from the organisation entirely when either person leaves.
If a conversation needs restricting rather than avoiding, a small private room is the right shape. Direct messages are for things that are genuinely between two people, not for work that happens to be sensitive.
Common questions
Should team channels be private by default?
No. Default to open and close specific rooms for specific reasons. Defaulting closed costs the whole team context every day in exchange for protection you usually do not need.
What genuinely belongs in a private room?
Information about a specific person, matters with real legal or commercial confidentiality, and scoped rooms for contractors. Beyond those, the case is usually weaker than it first appears.
Should people know a private room exists?
Usually yes. Visible-but-closed preserves trust, because people can ask to join. Fully hidden is right only when the existence of the room is itself the sensitive part.
How do we handle contractor access?
Give them a scoped room for their engagement rather than adding them to general operations, and set it up before they start. Retrofitting access controls after someone has joined rarely happens.
How often should private rooms be reviewed?
Twice a year. Check whether the original reason still holds and whether anyone is in there who should not be. The second question almost always turns something up.