Safety on CRAFT.
Most athletes on this platform are minors. That fact shaped the architecture from the first schema, not as a feature added later.
Coaches are verified by a person
Nobody becomes a coach by signing up. Every applicant submits their coaching history, playing background, certifications and references, and a human reviews it before they can appear in the marketplace or take a single athlete. Verification levels — Verified, Elite, College, Professional — are granted by CRAFT, never self-selected.
Guardians are built into the structure, not bolted on
Athletes under 18 must have a linked parent or guardian who grants consent before any coaching relationship can start. That guardian is added as a real participant on every coach conversation, so oversight is enforced by how the data is stored rather than by a policy someone has to remember to follow.
Parents control purchasing and permissions
Parents create and manage their athletes' accounts, hold the payment relationship, and control per-athlete permissions: who can purchase, who can start and end coaching relationships, and what the guardian can see.
Messages are screened and auditable
Every message passes a moderation screen before it is stored, and messages that suggest an attempt to move a young athlete off-platform are flagged for review. Conversations are retained so that they can be audited where that is appropriate and lawful.
Reporting and blocking
Any user can report another user, a message, a review or a submission, and can block someone from contacting them. Reports go to a moderation queue with a full audit trail of what action was taken and by whom.
Admin oversight is logged
Every consequential admin action — approving a coach, granting or revoking verification, suspending an account, issuing a refund, removing a review — is written to an immutable audit log with the acting admin, the target and the reason.
What this is not
The presence of these systems is not a claim of legal compliance. COPPA, state youth-athlete protection laws, SafeSport obligations, background-check requirements and data-retention rules all require legal review, operational process and, in several cases, third-party services. This platform is built so those requirements can be implemented properly — it does not assert that they already have been.