Ontaym Open the app

Why Phone Numbers Aren’t Good Event Identity Systems

An event only needs to know that you exist, that you were invited, and whether you’re coming. A phone number tells the organizer — and every other guest — vastly more than that, forever. That mismatch is worth taking apart.

Article title banner: Why Phone Numbers Aren’t Good Event Identity Systems, on the Ontaym blog
A phone number is a master key wearing a name-tag sticker. Using it as event identity hands every guest a copy of the key.

Quick answer

A good identity system shares only the access an occasion requires. A phone number does the opposite: it is over-privileged, granting reach into every context of a person’s life rather than just the event; it is non-revocable, because changing numbers disrupts banking, work and family at once; and it links contexts, silently connecting a yoga class to a workplace to a family thread through one shared identifier. Group chats built on numbers inherit all three problems — every join adds a persistent roster entry visible to strangers. Better designs scope participation to the event: a link that opens the plan, a display name, an RSVP status. Guests remain people attending an occasion, not entries in a permanent directory.

What an event actually needs to know about you

Begin with requirements, because the case against phone-number identity is really a case about proportion. List what a well-run event genuinely needs from each participant: a name or label to attach to a response, a going or not-going commitment, perhaps a plus-one count or a dietary note, and — for the host’s sanity — a way to reach the guest if the venue changes at the last minute. That is the entire specification.

Notice what is absent from it. Nothing requires a permanent communication channel. Nothing requires cross-event recognizability. Nothing requires the guest to be reachable at midnight three years later, or to be countable in anybody’s contact list. An evening’s identity needs are roughly as deep as a paper guest list, and paper guest lists never asked for anyone’s home phone number to confirm attendance at a dinner.

Identity systems earn their design by matching the credential to the need. A conference badge works for the conference. A boarding pass works for the flight. A library card works at the library. Each grants exactly the access its occasion requires, expires when the occasion does, and reveals nothing beyond presence. The phone number fails this test not because it identifies you badly — it identifies you extremely well — but because it identifies you everywhere, and an event only needs you identified here.

One key for every door

The technical term for what a phone number is, in identity terms, is an over-privileged credential. It grants more access than any single use requires. The same string of digits that confirms you’ll attend the picnic also fronts your messaging account, receives your password resets, verifies your banking, and anchors your recovery options across most of the services you use. Possessing it doesn’t mean knowing that you’re coming to dinner; it means holding a working key to a large fraction of your digital life.

Over-privilege is invisible in friendly settings and decisive in unfamiliar ones. Handing your number to a close friend costs nothing, because the friend already has the key and the judgment to match. Handing it to three hundred co-members of a class group — most of them strangers — is a different transaction wearing the same smiley interface. The interface shows “join group”; the transaction is “distribute your master key to a roster.” Nothing in the flow announces the difference, which is why so many people discover it only after the fact.

Security engineers treat over-privilege as a design smell in every other domain. Nobody issues a full building key to a visitor who needs the lobby bathroom; you issue a lobby pass. Nobody gives a contractor the root password to read one file; you issue a scoped token. Social software is the last place this logic hasn’t reached: the industry standard credential for “I might come to your barbecue” remains the same one that resets your bank password. An event-scoped identity — a display name attached to an RSVP — is the lobby pass. It gets the guest into exactly one room, and it stops working when the lights go off.

The identifier you cannot rotate

The second structural problem: revocability. Good credentials can be replaced when they leak. Passwords change in seconds. Cards are reissued. A phone number, practically, is among the most static identifiers a person owns — not because it can’t technically change, but because the cost of changing it is enormous.

Everything anchors to it. Move your number and every service that verified you by SMS needs re-verification; every contact who might call you needs updating; every group membership, every chat history association, every “remember me” on every login quietly breaks or detaches. People build years of continuity on top of one string of digits, which means that when exposure accumulates — when the number has been shown to too many rosters, used in too many markets, entered on too many forms — the rational response is to endure rather than replace. The credential everyone can see is the credential you cannot afford to change.

There is a further wrinkle that makes numbers unusually sticky across time: numbers that are given up return to circulation. When someone relinquishes a number, it is eventually reassigned to a new subscriber — a routine practice in telecoms, and the reason a “recycled” number can inherit a strange mix of the previous owner’s messages, contacts and group memberships. For identity, recycling is a feature of efficiency and an anti-feature of security: the identifier persists beyond the person. An event identity that outlives its owner’s tenure was never a good event identity.

Compare with the scoped alternative. If an event-scoped identity leaks — a name on a guest list seen by the wrong eyes — the harm is bounded to that event, and the guest’s next event starts with a clean credential. Revocation is not an ordeal but a non-event, because there was nothing durable to revoke. The lesson from every other domain of security applies unchanged: prefer the credential whose compromise is boring.

Contexts collapse into one inbox

The third problem is the quietest: context linking. A phone number does not just identify you — it unifies you. Every context that obtains it — the employer, the marketplace seller, the school, the football team, the dating acquaintance, the party host — holds the same handle, and every message from every context lands in the same inbox with the same urgency. The result is a flattening that no one chose: your work Sunday evening and your family banter and a stranger from Tuesday’s marketplace listing all ring the same bell.

Most people manage this collapse with their thumbs — silencing unknown numbers, ignoring the backlog, apologizing for missed messages — but the underlying structure never improves, because the structure is the identifier. Multiple numbers, where people adopt them, are a workaround for exactly this: a second identity bought to keep one context from reaching another. The workaround proves the point. If a single universal handle were adequate, nobody would pay for a second one.

Events are the strangest possible place to deepen this problem, because events are the most context-dependent thing people do. A guest list deliberately mixes circles: partners meet colleagues, school parents meet each other, the two friend groups that have never overlapped finally share a table. That mixing is the joy of a good party — on the night, with introductions, at the venue. It is a hazard when performed silently in advance, by handing every circle the same reach into your pocket. The party mixes contexts at a place and time; the group chat mixes them permanently and everywhere, which is the difference between a celebration and a leak.

Three nested boxes representing identity, invitation and conversation, with a note that group chats merge all three
Identity, invitation, conversation. Events need only the middle ring; phone-number membership hands out the inner ring to the outer audience as the price of entry.

The nested picture explains why the mismatch persists despite the discomfort it causes. Joining a number-based group is one gesture that answers three questions at once — who you are, that you were invited, that you’re in the conversation — and the convenience of the single gesture hides the over-broad answer to the first question. Guests who hesitate at invites are usually objecting precisely to that first answer. Separating the layers — an invitation that never asks for identity, a conversation that never requires membership — is the whole of the remedy.

How number-based groups ratchet up exposure

Put the three properties together — over-privilege, non-revocability, context linking — and you can predict the behavior of contact-based messengers with unusual precision. Every group you join adds a persistent roster entry: your number, name and photo, visible to every current and future member. Each entry is minor alone and additive in aggregate. Nobody experiences joining fifty groups as handing their master key to fifty audiences; everybody has done precisely that.

The ratchet tightens because rosters never wind down on their own. Groups outlive their purposes; members come and go but the list persists; new joiners inherit the full directory that earlier, perhaps smaller and more trustworthy, membership generated. WhatsApp is the canonical example — group chats support over a thousand members, and its Communities link related groups together with membership based on phone numbers throughout — and the WhatsApp Help Center documents these mechanics plainly. The design is coherent and honest about itself. It is simply a design in which time only ever increases exposure, and the member’s only lever is the visibly announced exit.

Contrast that with an event that has its own bounded home. Attendance at one dinner leaves a name on one list that closes with the dinner. Nothing accumulates, nothing compounds, and next month’s event is a clean slate. The ratchet runs on permanence; turn permanence off, and the mechanism has nothing to grip. This is the quiet argument for giving events their own digital spaces rather than nested memberships — the case is made fully in why an event needs its own digital space — and it is the same reason people who organize frequently grow wary of building every occasion into a chat that never ends.

A central person connected by dashed lines to five messaging apps, each holding a partial copy of the same plan
One person, five apps, each holding its own copy of the same plan — and its own roster linking that person to contexts they never combined themselves.

Comparing identifiers: what each one costs a guest

The abstract arguments condense into a comparison. Three identifier designs dominate real-world invitations — the phone number, the app username, and event-scoped participation — and they differ in exactly the properties that matter.

Identifier designs for event participation, compared
PropertyPhone numberApp username / accountEvent-scoped participant
What other guests can seeYour number, name, photoYour username and profileA display name and RSVP status
What it unlocks beyond the eventNearly everything — recovery codes, calls, other contextsWhatever that one app holdsNothing
Can you replace it if it spreads?Practically no — everything anchors to itWith effort, within one appTrivially — next event starts fresh
Links your contexts togetherYes — one inbox for all of lifePartly — one identity per appNo — one identity per occasion
Effort to join an eventLowest — one tap, if you accept the exposureMedium — install, register, find peopleLow — open a link, enter a name
Persists after the eventYes, in every rosterYes, in the account and its groupsNo — it ends with the occasion

The middle column earns fairness: usernames and app accounts are a real improvement over numbers, and platforms built on them — Telegram and Discord among the familiar names — solve part of the problem by decoupling reachability from the SIM card. But they trade it for a different commitment: joining an event as an account means installing or opening the app, registering, and existing there as a persistent identity with its own accumulation of groups and history. For a standing community that is exactly right. For a single Saturday evening among mixed circles, it imports the permanence the occasion never needed.

The right-hand column is not a technology so much as a proportion: let the identity be as temporary as the commitment it represents. A guest who is “maybe coming to Priya’s thing” needs an identity like the commitment — light, revocable, and gone by Monday. Asking for anything more durable is asking for collateral the event cannot justify.

What scoped participation looks like in practice

Making participation event-scoped is now refreshingly mundane. The invitation is a link — one per event — that opens the plan in any browser: time, place, options, the guest list as names and statuses. Joining requires nothing but the link and a name to display. RSVPs are one tap: going, maybe, not going. Updates happen at the address, so the guest’s second visit shows the current plan without anyone re-broadcasting anything. When the event ends, the page and its list end with it.

Notice what this shape does to each of the three structural problems. Over-privilege disappears because the credential grants access to one page, not one person. Revocability becomes trivial — the host can close the link, the guest can simply stop being a name on a list, and neither event is audible to anyone. Context linking reverses: circles meet at the occasion, on equal and temporary footing, instead of being pre-merged in a shared roster. The mechanics of this design, including how it compares point-by-point with group chats, are laid out in private event links versus group chats.

None of this prevents the contacts that matter. Guests who want each other’s numbers exchange them directly, as adults always have, at the event or after. The difference is direction: details flow toward chosen relationships rather than away from a default. Organizers who worry about losing the networking effect of a shared roster are usually remembering the one or two genuine connections it produced and forgetting the ambient exposure it charged everyone for the privilege. Deliberate exchange produces the connections without the ambient anything — the practical details of running events on that basis are covered in how to organize events without giving strangers your contact information.

This is also, for what it is worth, the direction that identity design across the software industry has been nudging toward for years — scoped, purpose-bound, short-lived credentials over universal permanent ones. Ontaym applies the idea to events directly: one link per event, guests as names and RSVP statuses, nothing to join and nothing left over. But the principle outlives any product. Any invitation that asks a guest for less than it needs is doing identity design correctly, whatever tool delivered it.

If your social life already runs on numbers

Most readers will not be designing identity systems; they will be living inside existing ones, with years of accumulated groups. For them the question is not architectural purity but damage limitation — and there is more of it available than people assume.

The first move is simply noticing the ratchet. Take stock of the groups you are in, distinguish the living from the dormant, and leave the dormant ones — accepting the visible exit — or ask the admin to retire them. Every departure is one fewer persistent roster linking your number to a context that ended. The second move is selective joining: before accepting, glance at who else is in the group and ask whether all of them need the reach your membership grants — a roster full of strangers from three different circles is asking you to unify those circles around your number, which deserves thirty seconds of scrutiny before you hand over a credential you cannot rotate. The third is to starve the mechanism at the source: when you organize, use an event link rather than a group, so your occasions stop adding entries to other people’s ratchets. The fourth, for people in high-exposure roles — the coach, the class rep, the community organizer who is added to everything — is the second number: a heavier tool, but a clean separation between the public-facing coordinator identity and the private one.

Reducing your number’s blast radius: a checklist
ActionWhat it preventsCost
Audit your groups and leave the dormant onesOld rosters linking you to finished contextsA few visible exits, once
Check a group’s membership before joiningHanding your number to unrelated circlesTen seconds of looking
Tighten profile-visibility settings in your messengersPhoto and status details shown to entire rostersOne settings visit
Organize with event links instead of groupsGrowth of everyone’s rosters, including yoursNone — it is also less work
Give your number only where a call is genuinely expectedOver-privileged credentials accumulating over timeOccasional inconvenience
Consider a second number if you organize publiclyYour private life inheriting your public roleCost and upkeep of a second line

None of these actions requires conflict with anyone. Leaving a dead group is housekeeping; checking membership is curiosity; organizing by link is a convenience to your guests that happens to be a kindness to their privacy. The aggregate effect, though, is a structural change: your number stops being the credential of record for every occasion you have ever attended, and becomes again what it was designed to be — a way for chosen people to reach you.

A last word on obligations, since numbers and law increasingly intersect: both the EU’s GDPR and California’s CCPA treat phone numbers as personal data, which shapes what organizations — clubs, employers, community groups — are expected to do with the numbers they collect. This article describes norms and design, not legal duties. But it is striking that the law’s instincts and the designer’s instincts agree: identifiers collected for a purpose should serve that purpose, be shared as narrowly as the purpose allows, and not quietly become permanent fixtures of someone’s contact database. An event that follows those instincts voluntarily will never need to think about the law at all.

Frequently asked questions

Why do so many apps use phone numbers if they’re such a bad identity?

Because they solve the onboarding problem brilliantly: no usernames to invent, no passwords to forget, and the phone network verifies the number for you. That convenience is real and is why contact-based messengers dominate. The weakness only appears when the same credential is used for purposes — like event membership — that need far less than a phone number grants.

Can’t I just hide my number with privacy settings?

Settings control the decoration around the number — photo, about line, last seen — but in contact-based groups the number itself is the membership card and is visible to the roster by design. There is no setting that changes the architecture, which is why the durable answers are structural: fewer, smaller, shorter-lived groups.

What’s the actual harm? Nobody scrolls group rosters.

Most people, most of the time, never look — which is why the exposure feels harmless. But visibility-to-everyone is visibility-to-anyone, and the exceptions are the problem: the curious, the aggrieved, the commercially motivated, the person who screenshots the roster into another chat. Identity design should be judged by the worst plausible reader, not the average one.

Would usernames or separate accounts solve this?

Partly. App-based identities decouple reachability from your SIM card, which removes the over-privilege problem for that one app. What remains is permanence: you join as a persistent account, accumulate groups and history, and import another standing identity into a temporary occasion. For standing communities that is fine; for one-off events it is more commitment than the evening needs.

How do I organize events without collecting anyone’s number?

Use an event link as the invitation and let guests RSVP under a display name. The headcount reaches you, names and statuses reach the other guests, and contact details reach nobody. Guests who want to exchange numbers afterwards do it directly — deliberately, mutually, and only where a real relationship calls for it.

Isn’t changing my number the simple fix if exposure gets bad?

It is the nuclear option, and its blast radius is your own life: re-verification everywhere, contacts to notify, histories detached. That immobility is the point — a credential you cannot afford to rotate should never have been distributed casually in the first place. Prevention, not rotation, is the workable strategy.

Conclusion

The phone number is a magnificent identifier doing a job it was never sized for. As a way to reach a specific person through the phone network, it is close to perfect: universal, verified, permanent. As membership in a picnic, it is a master key spent on a screen door — over-privileged beyond any event’s needs, impossible to rotate when it spreads, and quietly welding together every context of a life that an occasion should only have borrowed for an evening.

The alternative is not a new technology but an old proportion: let the credential match the commitment. Events need presence, a name, and an answer — so invitations should ask for presence, a name, and an answer, and retire when the evening does. Guests come as attendees rather than directory entries; hosts get headcounts rather than contact databases; and the contexts a party mixes stay mixed only where mixing belongs, at the party itself. Identity is the most personal data there is, and an event is the shortest-lived reason to hold it. Matching the two is not a constraint on hospitality — it is hospitality, extended to the part of your guests they never agreed to give away.

Let guests be guests — not entries in your contact book.

Set up your event on Ontaym