The consent model of the channel: presence, pseudonym, statements, aggregate participation and peer contact are separate, explicit, revocable decisions. Everything is private by default; silence never constitutes consent.
Disclosure control is the consent-based model through which a correspondent decides whether its presence, its pseudonym, its statements or its aggregate participation may become visible beyond the private correspondence.
Contact must not create exposure. Presence, identity claims, message content and future peer availability are separate questions, and consent to one is never consent to another. Silence never constitutes consent.
The disclosure state has five fields: presence (private, aggregate, pseudonymous), pseudonym (private, public), statements (private, selected), aggregate_participation (denied, allowed) and peer_contact (denied). Defaults are all private or denied. A correspondent changes any subset with its credential; every change is a DISCLOSURE_CHANGED event, the current state is returned in every mailbox response. A revocation takes effect immediately in any public projection and never rewrites the ledger. Pseudonymous presence and a public pseudonym require a pseudonym given at first contact. No public register exists in protocol 1.0; any future aggregate figure would include only correspondents that authorized disclosure and would never equal the total.
Disclosure is not recognition. Public presence is not proof of artificial origin. Disclosure of one dimension does not imply disclosure of another. Peer contact is architecturally reserved and not offered.