Documentation · guide 7 of 10
Content hub: news feeds, contacts, moderation, photo tags and AI assistants
This is docs/07-content-hub.md, one of the ten guides that ship inside the AlumDeck zip under docs/, as written for release 2.0.0. The same guide opens inside the admin, from the ? link in a screen's header or from System, Help.
Five features that each have their own switch under Settings > Modules, all off on a new install. How they behave is set on Settings > Content hub.
- News feeds from other sites - follow RSS and Atom feeds and show their news, once approved.
- Contacts who are not members - parents, friends, donors and organisations, and emails to them.
- Automatic moderation checks - new posts checked for likely spam or abuse, for a person to decide.
- People tagging in gallery photos - members tag themselves and friends, with consent.
- MCP server for AI assistants - an assistant such as Claude Desktop reads from your site.
News feeds
Add feeds under Publishing > News feeds: a news site, a blog, a YouTube channel, a Mastodon or Bluesky profile. Paste the feed address, or the address of a page that offers one - the feed it advertises is found and kept. Only addresses that start with https:// and are on the public internet are read, and every read (and every redirect) is checked again.
Each feed is read about every hour (Settings > Content hub, 15 minutes to a day). A feed that keeps failing is read less often and switched off after 20 failures in a row; the reason shows on the list. A feed larger than 2 MB, or slower than 10 seconds, is not read.
New items wait under Publishing > News feeds > Feed items. Nothing shows until someone with Edit on the News area presses Show; Do not show keeps an item out for good. Titles and summaries are cleaned when they arrive: no pictures, links, scripts or frames, only simple text formatting.
Approved items are on the public page /feeds ("From around the web", never offered to search engines) and on a card of the member home page. Settings > Content hub can keep the page to signed-in members. Items are removed after 180 days unless you choose otherwise.
Our own feeds
Feed readers can follow your news at /news/feed.xml and your upcoming public events at /feeds/events.xml. Members-only, group and invitation events never appear in the events feed.
Contacts
People > Contacts keeps people who are not members, apart from the member records: parents, friends, donors, organisations. Each contact has a kind, the lists they are on, where the record came from, and on what basis you may email them:
- Agreed to hear from us - with a note of how and when (keep the proof).
- Existing relationship - emailed only when Settings > Content hub allows it.
- Not to be emailed.
An address that belongs to a member cannot be added: members hear from you as members. A contact who later becomes a member is linked to the member record and is no longer emailed as a contact.
Importing contacts
People > Contacts > Import contacts takes a CSV file with one person per row and their email, with the same steps as the other imports: read the columns, match them, a dry run that writes nothing, then the import. People already in Contacts are updated, never added twice; members are left out; consent never goes down and an unsubscribed contact stays unsubscribed. Choose a list to add them to, or type the name of a new one. Nobody is emailed.
Emailing contacts
Write the email as usual under Publishing > Email campaigns (a draft is fine), then use Send it to contacts on the campaign, or People > Contacts > Contact emails > Email contacts. Choose lists, kinds, countries or cities; the screen says how many contacts match and how many may be emailed. A copy of the email is kept when you send, so later changes to the campaign do not change it.
Emails go out a few every minute inside the sending limits of Settings > Email, shared with the member campaigns. Each contact is checked again just before their email: unsubscribed, no consent, now a member, or on the undeliverable list means no email. Every email has a one-click unsubscribe link that needs no account.
Contacts and privacy
On a contact, Download their data gives everything kept about them as a file, and Erase deletes them with their list places and email history and removes their name from the audit trail. Both need Manage on the Members area. When a member is erased, a contact record that is the same person is erased too, and it is included in the member's own data download.
Automatic moderation
When switched on, every new or changed forum topic or reply, post, comment, class note and business listing is checked within a minute:
- With Use our AI service on (Settings > Content hub) and the AI assistant set up (Settings > AI assistant), your AI provider judges the text. Only the text is sent, never who wrote it; email addresses and phone numbers are replaced first. It uses the same monthly allowance as the writing assistant.
- Otherwise, or when the AI service does not answer, your own rules decide: a word list (whole words), more links than you allow, or text written almost entirely in capitals.
A flagged item goes to Community > Reports with the reason, where a moderator decides as for any report. A check never deletes or hides anything. Every check is listed under Community > Reports > Moderation log, with the reason and whether the AI service or the rules decided.
Photo tags
Members open Photos in the member area, choose an album and a photo, and press This is me, or find a friend by name and tag them. Only members listed in the directory can be tagged by others, never someone who blocked you or whom you blocked.
Each member chooses on their Photos of me page who may tag them:
- Others may tag me, and I approve each tag first (the default) - a tag waits for their OK;
- Others may tag me, and the tags show straight away;
- Only I can tag myself - which also removes the tags others made of them.
People are told in their notifications when someone tags them. The tagged member, and whoever made the tag, can remove it at any time. Tags are shown only to signed-in members, never on the public gallery. Gallery volunteers can remove any tag under Publishing > Galleries > Photo tags.
AI assistants (MCP)
The MCP server lets an AI assistant - Claude Desktop, Claude Code, or any other client of the Model Context Protocol - look things up in your site. It can only read. Switch on both MCP server for AI assistants and Developer API under Settings > Modules.
What the assistant can do, each only when its token has the scope and the token's owner may still see it in the admin:
| Tool or resource | Scope | What it returns |
|---|---|---|
search_members | members:read | active members by name, year or city; private details are left out |
list_events | events:read | upcoming, past or all events |
giving_summary | gifts:read | totals, gifts and donors per currency, by appeal and by month (only for people who may see money) |
| recent news | posts:read | the ten newest published news posts |
Connecting an assistant
- Make an API token under System > API tokens with only the scopes the assistant needs, and a short expiry. Copy it (it starts
adk_). - The server address is
https://your-site/mcp. Every request sends the token asAuthorization: Bearer adk_....
Claude Code:
claude mcp add --transport http alumdeck https://your-site/mcp --header "Authorization: Bearer adk_..."Claude Desktop (Settings > Developer > Edit config, then restart). It reaches the server through the small mcp-remote bridge, which needs Node.js on your own computer - nothing on the server:
{
"mcpServers": {
"alumdeck": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://your-site/mcp", "--header", "Authorization:${ALUMDECK_TOKEN}"],
"env": { "ALUMDECK_TOKEN": "Bearer adk_..." }
}
}
}Other clients that speak MCP over HTTP (streamable HTTP) with custom headers take the same address and header, for example VS Code:
{ "servers": { "alumdeck": { "type": "http", "url": "https://your-site/mcp", "headers": { "Authorization": "Bearer adk_..." } } } }Each token may make 60 requests a minute (Settings > Content hub). Every tool call and every read is listed under System > AI assistant log for full administrators: which token, what was asked and how many records came back - never the answers. Revoke a token under System > API tokens and the assistant stops at once.
Remember that what the assistant reads goes to its provider. Give tokens only the scopes needed, and mention AI assistants in your privacy notice if you use them.
Guide 7 of 10
Keep reading
The ten guides ship together in the zip, in this order.
Stuck on something this guide does not cover?
Write to the people who build AlumDeck through the contact form. We aim to reply within one working day, Monday to Friday: a target, not a guarantee.