instance policy to restrict community creation to selected users (closed education instances)
Use case
We run a closed self-hosted instance for a language school whose members include minors. Desired model:
Teachers/staff can create and run their own communities (classrooms, clubs)
Students can join communities they are invited to, but cannot create communities, and this must be enforced server-side (hiding client buttons is not enforcement for a child-safety posture)
Current options are all-or-nothing
single_community_enabled blocks community creation for everyone and limits the instance to one community — too restrictive for the teacher-communities model
Otherwise, any claimed, email-verified user can create communities up to max_guilds
Observation
The limits system already resolves max_guilds through trait-matched rules (LimitMatcher / createLimitMatchContext with user traits), and GuildOperationsService.createGuild already consults it. What seems missing is an admin-manageable way to segment users so a rule like "default 0 owned communities, elevated for staff/teacher accounts" can be expressed.
Suggested shapes (any would work for us)
An instance policy default of max_owned_guilds: 0 plus a per-user admin override (count or trait/badge assignable from the admin dashboard)
Admin-assignable user traits that participate in limit rule matching
An explicit "may create communities" user flag checked in createGuild
We are happy to contribute a PR if maintainers indicate a preferred direction.