- have encrypted group state
- with permission (role-/user based) overrides
- where permission overrides and other metadata are not known to the server
- but the group state is stored on the server in an encrypted manner
@star@amazonawaws.com