Logbook Beta on Sui Testnet. Learn more →
Documentation

Learn Logbook

Everything you need to create blockchain-verified surveys, understand the technology, and get the most out of Logbook.

DocsWho Counts Once
7 min read

Who Counts Once

A campaign takes one response per account. An account is not a person: someone can sign in with two Google accounts or two wallets. "Who counts once" is the rule of a community that closes this gap.

#The Rule Belongs to the Community

A community is a top group with every group created inside it. The top group sets who counts once, and every group inside has exactly that rule. A subgroup does not choose its own, and is neither weaker nor stricter than the top group. If flats respond in the house, flats respond in Tower A.

The rule holds across the whole community: one seat is one address in every group of it. Someone who is in two subgroups is still one participant of a campaign over both.

A group page states its rule under the name, and a subgroup adds "Inherited from" with a link to the top group.

#The Choices

Who counts onceWhat it meansAvailable
Nothing is checkedEveryone you let in counts, even if one person has several accountsYes
One response per seat on the listEach member takes a different seat on the list the admins keep, with a personal linkYes
One response per unit, such as a flatEach unit has one response, however many people stand behind it. The units are the seats of the listYes
One response per person (World ID)Each member proves with a World ID check that they are a distinct personNot yet
One response per mailbox of the organisationEach member signs in with a different mailbox of the organisationNot yet
The last two cannot be used today. A check shows that an address stands for one person or one mailbox, without saying who, and it has to be made by a Logbook check server. That server is not running, and the contract has no key for it, so the contract accepts no such check. The forms show both options switched off. Only seats on a list work now.

Whom you trust differs by rule. With a list you trust whoever keeps the list, the admins: no Logbook server takes part. With nothing checked you trust the admins to let in the right people.

#Lists and Seats

A list is what the admins of a community upload: one line per member, per flat or per other unit. Each line is a seat.

  • A seat has a name that the admins choose, such as "flat-17" or a staff number, and optionally the name and email of the person expected to take it
  • For each seat the admins hand out a personal link. Whoever opens the link with their account takes the seat (see Joining a Group)
  • A taken seat is tied to one address in the whole community, and nobody else can take it. A campaign with this rule takes at most one response per seat

#A Unit and Its Word

With "one response per unit" a seat stands for something that gets one response whoever speaks for it: a flat, a household, a company, an account. The community picks the word, and the pages then say "One response per flat". The form offers flat, household, member, employee, company and account, or you type your own.

#What Is Stored Where

The blockchain holds only a fingerprint of the list (one hash), and for each taken seat the address that holds it. The names of the seats are never on-chain.

The list itself is stored encrypted for the owner and the admins of the group. Logbook stores it and cannot read it. A second, public file holds one hash per seat, which holders need to take their seats; it tells the number of seats and nothing about them. See Data Storage.

#Uploading and Changing a List

Under Manage, People, List, the admins upload a CSV file with the columns seat,holder,email (holder and email optional), or paste it. Before anything is written, the page shows what would change:

  • Add: a new seat, free until its holder takes it with a personal link
  • Remove: the seat leaves the list. If an address holds it, that address is removed from every group it holds the seat in. It stays counted in campaigns created before
  • Move: the seat stays and its holder changes. The old address is removed, the seat is released from it, and a new personal link is made. The old link stops working
  • Edit: a name or an email changed. Only the admins' copy changes
A list holds at most 10,000 seats. "Download the list" saves the names as a CSV file, without the links.

#When a Seat Changes Hands

A flat is sold, or a representative changes. The owner of the community releases the seat (List, the menu of the seat):

  • The address that holds it is removed from every group of the community it holds the seat in
  • The seat gets a new personal link, which the owner hands to the next holder. The old link stops working
  • The old address cannot take this seat again, unless the owner lifts that bar
  • Campaigns that are running keep their participants: the old holder keeps their response in campaigns created before, the new holder responds in campaigns created after
The old holder does not have to cooperate.

#The List of a Subgroup Is a Filter

A subgroup inside a community can also let people in by a list. Its list is not a second set of seats. It names which seats of the community's list belong to it: "Tower A is flats 1 to 40".

  • No personal links are made for a subgroup. A person takes their seat once, in the community, and the subgroup then lets in the holder of a seat it names
  • Naming a seat in a subgroup takes nothing and blocks nothing: only the holder of that seat of the community can join with it
  • Which seats a subgroup names is public once those seats are taken, also for a private subgroup (see Privacy in Groups)
A group that needs a list of its own, with its own seats, is the top group of its own community.

#Changing the Rule

The owner or an admin of the top group changes who counts once under Settings.

  • The change holds in every group of the community from the next transaction on
  • Members who were let in without the new check stay members. They do not count in a campaign created with the new rule until they join again with it
  • Campaigns that are running keep the rule and the participants they were created with

#Two Communities

A campaign can name groups of more than one community. Each community checks its members its own way, so such a campaign guarantees nothing beyond one response per account, and its page says so.

Two communities can be linked, top group under top group, only while neither checks who counts once.

#What the Rule Does Not Do

  • It does not check that the right person holds a seat. Whoever opened the personal link first took it; the admins see who holds which seat and can release it
  • It does not hide who holds a seat: the address is public, the name of the seat is not
  • "Nothing is checked" promises nothing: one person with several accounts can be several members