Circle → Discourse
Move members, profiles, identities, and consent, spaces, categories, groups, and hierarchy, posts, topics, articles, and authorship, comments, replies, reactions, and mentions, images, uploads, video, and attachments, private messages and restricted content, roles, moderation, trust, bans, and permissions, courses, events, paywalls, and memberships from Circle to Discourse with a reversible cutover, explicit exception ledger, and evidence-backed verification.
Should you make this move?
Both platforms have a case. Compare what you gain with what you give up before scheduling the cutover.
Circle
- Polished spaces, events, courses, memberships, and mobile experiences serve creator-led communities well
- Membership, discussion, moderation, and events give an audience a persistent shared home
- Posts, media, member relationships, paywalls, and engagement data have uneven export coverage
- Identity, relationships, private content, and engagement history rarely transfer completely
Discourse
- Open-source discussion software offers excellent moderation, search, extensibility, and data ownership
- Membership, discussion, moderation, and events give an audience a persistent shared home
- Hosting, upgrades, plugins, email delivery, and community operations require more hands-on administration
- Identity, relationships, private content, and engagement history rarely transfer completely
Discourse: Open-source discussion software offers excellent moderation, search, extensibility, and data ownership. This removes a major source-side concern: Posts, media, member relationships, paywalls, and engagement data have uneven export coverage.
What you lose: Polished spaces, events, courses, memberships, and mobile experiences serve creator-led communities well. What you inherit: Hosting, upgrades, plugins, email delivery, and community operations require more hands-on administration.
Jump to a section
Know the shape of the move.
This timeline assumes
- Up to 250,000 members, five million posts, 20 million comments, and 5 TB of media
- Administrators control both Circle and Discourse, including billing, identity, APIs, integrations, and export permissions.
- Circle remains intact and recoverable until Discourse completes one representative operating cycle.
- A production-shaped pilot includes every object type, access class, edge case, and failure path.
- The migration team preserves stable source identifiers and records durable evidence for every blocking check.
What survives the move.
“Partial” and “manual” are not footnotes. They are work that must be scheduled and verified.
| Item | Outcome | Impact | What happens | Mitigation |
|---|---|---|---|---|
| Members, profiles, identities, and consent | partial | critical | Member IDs, usernames, custom fields, verification, consent, and account linking differ. A successful bulk job therefore does not prove semantic parity between Circle and Discourse. | Map members, profiles, identities, and consent explicitly, pilot every feature class, and reconcile accepted, changed, rejected, and excluded items. |
| Spaces, categories, groups, and hierarchy | partial | critical | Containers, nesting, visibility, membership, ordering, and archive behavior require mapping. A successful bulk job therefore does not prove semantic parity between Circle and Discourse. | Map spaces, categories, groups, and hierarchy explicitly, pilot every feature class, and reconcile accepted, changed, rejected, and excluded items. |
| Posts, topics, articles, and authorship | partial | critical | Post types, rich text, polls, events, attribution, timestamps, and canonical URLs transform differently. A successful bulk job therefore does not prove semantic parity between Circle and Discourse. | Map posts, topics, articles, and authorship explicitly, pilot every feature class, and reconcile accepted, changed, rejected, and excluded items. |
| Comments, replies, reactions, and mentions | partial | high | Thread depth, reaction types, mentions, accepted answers, and edit history can flatten. A successful bulk job therefore does not prove semantic parity between Circle and Discourse. | Map comments, replies, reactions, and mentions explicitly, pilot every feature class, and reconcile accepted, changed, rejected, and excluded items. |
| Images, uploads, video, and attachments | partial | critical | CSV exports often exclude uploaded media or retain authenticated source URLs. A successful bulk job therefore does not prove semantic parity between Circle and Discourse. | Map images, uploads, video, and attachments explicitly, pilot every feature class, and reconcile accepted, changed, rejected, and excluded items. |
| Private messages and restricted content | partial | critical | Legal authority, export coverage, recipient identity, and destination privacy require explicit approval. A successful bulk job therefore does not prove semantic parity between Circle and Discourse. | Map private messages and restricted content explicitly, pilot every feature class, and reconcile accepted, changed, rejected, and excluded items. |
| Roles, moderation, trust, bans, and permissions | manual | critical | Moderator powers, trust levels, badges, restrictions, bans, and inherited access use different models. A successful bulk job therefore does not prove semantic parity between Circle and Discourse. | Inventory and rebuild roles, moderation, trust, bans, and permissions, then test normal, edge, failure, and rollback behavior. |
| Courses, events, paywalls, and memberships | manual | critical | Adjacent learning, live events, subscriptions, entitlements, and payment flows require separate migration. A successful bulk job therefore does not prove semantic parity between Circle and Discourse. | Inventory and rebuild courses, events, paywalls, and memberships, then test normal, edge, failure, and rollback behavior. |
| Notifications, digests, integrations, and SSO | manual | high | Email settings, mobile notifications, bots, webhooks, SSO, and API clients need reconstruction. A successful bulk job therefore does not prove semantic parity between Circle and Discourse. | Inventory and rebuild notifications, digests, integrations, and sso, then test normal, edge, failure, and rollback behavior. |
| Analytics, search, reputation, and history | lost | high | Search ranking, member reputation, engagement analytics, moderation logs, and delivery history remain source-native. A successful bulk job therefore does not prove semantic parity between Circle and Discourse. | Archive analytics, search, reputation, and history as dated source evidence and define the new destination baseline. |
Where each thing goes.
| Source | Destination | Method | Notes |
|---|---|---|---|
| Circle: Members, profiles, identities, and consent | Discourse: approved members, profiles, identities, and consent representation | transform | Preserve source IDs, ownership, timestamps, access intent, and an explicit exception status for members, profiles, identities, and consent. |
| Circle: Spaces, categories, groups, and hierarchy | Discourse: approved spaces, categories, groups, and hierarchy representation | transform | Preserve source IDs, ownership, timestamps, access intent, and an explicit exception status for spaces, categories, groups, and hierarchy. |
| Circle: Posts, topics, articles, and authorship | Discourse: approved posts, topics, articles, and authorship representation | transform | Preserve source IDs, ownership, timestamps, access intent, and an explicit exception status for posts, topics, articles, and authorship. |
| Circle: Comments, replies, reactions, and mentions | Discourse: approved comments, replies, reactions, and mentions representation | transform | Preserve source IDs, ownership, timestamps, access intent, and an explicit exception status for comments, replies, reactions, and mentions. |
| Circle: Images, uploads, video, and attachments | Discourse: approved images, uploads, video, and attachments representation | transform | Preserve source IDs, ownership, timestamps, access intent, and an explicit exception status for images, uploads, video, and attachments. |
| Circle: Private messages and restricted content | Discourse: approved private messages and restricted content representation | transform | Preserve source IDs, ownership, timestamps, access intent, and an explicit exception status for private messages and restricted content. |
| Circle: Roles, moderation, trust, bans, and permissions | Discourse: approved roles, moderation, trust, bans, and permissions representation | manual | Preserve source IDs, ownership, timestamps, access intent, and an explicit exception status for roles, moderation, trust, bans, and permissions. |
| Circle: Courses, events, paywalls, and memberships | Discourse: approved courses, events, paywalls, and memberships representation | manual | Preserve source IDs, ownership, timestamps, access intent, and an explicit exception status for courses, events, paywalls, and memberships. |
| Circle: Notifications, digests, integrations, and SSO | Discourse: approved notifications, digests, integrations, and sso representation | manual | Preserve source IDs, ownership, timestamps, access intent, and an explicit exception status for notifications, digests, integrations, and sso. |
Make the move recoverable.
Create the source-of-truth backup
Preserve Circle data, configuration, access, and operating evidence before any destination write.
- Export every available Circle object and binary in scope, including members, profiles, identities, and consent, spaces, categories, groups, and hierarchy, posts, topics, articles, and authorship, comments, replies, reactions, and mentions.
- Capture configuration and runtime dependencies for images, uploads, video, and attachments, private messages and restricted content, roles, moderation, trust, bans, and permissions, courses, events, paywalls, and memberships.
- Record counts, sizes, owners, timestamps, access classes, financial totals where applicable, and known exceptions.
- Hash immutable exports, record tool versions and commands, and transform working copies only.
Proof to capture: A signed manifest accounts for every scoped record class, configuration object, binary, count, total, exception, and hash.
Identity, schema, and disposition registry
Preserve stable identity and make every mapping or exclusion reviewable.
- Inventory source types, identifiers, owners, states, and access.
- Define one approved destination representation or explicit archive decision.
- Reject unmapped critical items and produce an exception ledger.
Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.
Dependency-ordered migration package
Load prerequisite identities and configuration before dependent records and runtime actions.
- Normalize encoding, timestamps, identifiers, nulls, and destination limits.
- Run a representative pilot and retain request, response, and rejection evidence.
- Reconcile the final delta before enabling destination production writers.
Proof to capture: Save the input, output, command or tool settings, warnings, and final item counts.
The things most likely to hurt.
These are operating limits. Treat every “Stop if” condition as a blocked migration, not a suggestion.
A completed migration hides missing or altered members, profiles, identities, and consent
Headline counts look plausible while semantic, access, or relationship checks fail.
- Consequence
- The destination becomes authoritative with incomplete or misleading business data.
- Mitigation
- Reconcile by type, state, owner, access class, and representative record rather than total count alone.
Stop if: Any critical item lacks a verified destination, approved transformation, explicit exclusion, or recoverable archive.
Circle and Discourse both perform production actions
Users, schedules, webhooks, integrations, or traffic continue changing both systems.
- Consequence
- State diverges or customers receive duplicate, contradictory, or unsafe actions.
- Mitigation
- Freeze source writers and transfer one production owner at a time with an approved rollback.
Stop if: An unapproved source writer or destination duplicate action appears after the freeze.
Destination access or security is broader than approved
A representative restricted user can read, change, export, or trigger an unauthorized item.
- Consequence
- Confidential, regulated, financial, or security-sensitive data is exposed or changed.
- Mitigation
- Apply least privilege before bulk loading and test every access class using ordinary identities.
Stop if: Any unauthorized read, write, export, administrative action, or secret access succeeds.
Do the work in this order.
- Days 1–4 · inventory
Inventory and decisions
8–16 hours active2–4 days elapsedOwner, legal, security, and finance review waiting- Inventory Circle data, configuration, identities, integrations, limits, and billing.
- Approve scope, owners, mappings, exclusions, acceptance thresholds, and rollback authority.
Depends on: Circle and Discourse administrator access
Stop / go checkpointExport?
Go when: Every critical item and production action has an owner and disposition.
Stop when: Authority, retention, billing, access, or system ownership is unclear.
- Days 3–8 · backup
Backup and reconcile
8–20 hours active2–5 days elapsedProvider export processing waiting- Create immutable data, configuration, binary, and audit exports.
- Reconcile source counts, totals, sizes, access classes, and hashes.
Depends on: Approved inventory and retention location
Stop / go checkpointTransform?
Go when: The signed source manifest and exports agree.
Stop when: Any critical dataset, binary, configuration, or recovery path is absent.
- Days 6–20 · pilot
Map, transform, and pilot
25–70 hours active5–12 days elapsedDestination processing and owner review waiting- Configure Discourse and transform a production-shaped pilot.
- Test normal records, every feature class, edge cases, permissions, failures, and rollback.
Depends on: Verified source backup and approved mapping registry
Stop / go checkpointScale?
Go when: Every pilot mapping and blocking verification check passes.
Stop when: Any critical invariant, access boundary, or production action lacks a safe destination.
- Days 18–35 · cutover
Bulk load, final delta, and switch
20–55 hours active2–8 days elapsedImports, propagation, indexing, or synchronization waiting- Freeze production writes and automated actions in Circle.
- Apply and reconcile the final delta, switch ownership to Discourse, and run all blocking checks.
Depends on: Passed pilot, stakeholder go decision, and rehearsed rollback
Stop / go checkpointOpen production?
Go when: Discourse is the sole production owner and every critical exception is resolved.
Stop when: A source writer remains active, a blocking check fails, or rollback is unavailable.
- Days 25–45 · observe
Observe and close
9–19 hours active7–14 days elapsedRepresentative operating-cycle evidence waiting- Monitor correctness, access, failures, latency, delivery, cost, and user outcomes.
- Sign the verification report and close rollback only after stable evidence.
Depends on: Verified cutover
Stop / go checkpointClose rollback?
Go when: No trigger occurs during the approved observation period.
Stop when: Data, access, delivery, routing, cost, or business results regress.
Cut over with a way back.
Cutover
Make Discourse the only production system without losing the final Circle delta.
- Freeze user, integration, schedule, and API writes in Circle.
- Capture and reconcile the final source delta against the last verified checkpoint.
- Apply the approved delta and configuration changes to Discourse.
- Switch traffic, domains, integrations, credentials, automation, and user entry points in dependency order.
- Run every blocking verification check and keep the source intact.
Proof to capture: Discourse alone owns production, totals reconcile, exceptions are signed, and every blocking check has durable evidence.
Rollback
Return production ownership to Circle without losing destination-era changes.
- Stop new user, integration, schedule, and API writes in Discourse.
- Restore prior Circle traffic, domains, credentials, automation, and integration ownership.
- Export and classify the Discourse post-cutover delta.
- Apply safe destination-era changes back to Circle without duplicating actions.
- Run the same blocking checks against the restored source.
Proof to capture: Circle again owns production with current data and no duplicate destination action.
- Unexplained critical count, value, relationship, or checksum variance
- Missing, corrupted, or exposed critical data
- Duplicate production action or unresolved split-brain state
- Failed access, security, delivery, routing, performance, or integration check
- A critical feature has no safe destination replacement or rollback path
Prove the migration worked.
Every blocking check must pass. Capture the evidence before cleanup begins.
| Pass | ID | Check | Method | Expected result | Evidence |
|---|---|---|---|---|---|
V-01Blocking | Members, profiles, identities, and consent reconciliation | Compare source inventory, transformed output, destination results, and a stratified sample for members, profiles, identities, and consent. | Every in-scope item is present, intentionally transformed, explicitly excluded, or retained in the signed source archive. | Members, profiles, identities, and consent ledger with counts, exceptions, sample IDs, and owner sign-off. | |
V-02Blocking | Spaces, categories, groups, and hierarchy reconciliation | Compare source inventory, transformed output, destination results, and a stratified sample for spaces, categories, groups, and hierarchy. | Every in-scope item is present, intentionally transformed, explicitly excluded, or retained in the signed source archive. | Spaces, categories, groups, and hierarchy ledger with counts, exceptions, sample IDs, and owner sign-off. | |
V-03Blocking | Posts, topics, articles, and authorship reconciliation | Compare source inventory, transformed output, destination results, and a stratified sample for posts, topics, articles, and authorship. | Every in-scope item is present, intentionally transformed, explicitly excluded, or retained in the signed source archive. | Posts, topics, articles, and authorship ledger with counts, exceptions, sample IDs, and owner sign-off. | |
V-04Blocking | Comments, replies, reactions, and mentions reconciliation | Compare source inventory, transformed output, destination results, and a stratified sample for comments, replies, reactions, and mentions. | Every in-scope item is present, intentionally transformed, explicitly excluded, or retained in the signed source archive. | Comments, replies, reactions, and mentions ledger with counts, exceptions, sample IDs, and owner sign-off. | |
V-05Blocking | Images, uploads, video, and attachments reconciliation | Compare source inventory, transformed output, destination results, and a stratified sample for images, uploads, video, and attachments. | Every in-scope item is present, intentionally transformed, explicitly excluded, or retained in the signed source archive. | Images, uploads, video, and attachments ledger with counts, exceptions, sample IDs, and owner sign-off. | |
V-06Blocking | Private messages and restricted content reconciliation | Compare source inventory, transformed output, destination results, and a stratified sample for private messages and restricted content. | Every in-scope item is present, intentionally transformed, explicitly excluded, or retained in the signed source archive. | Private messages and restricted content ledger with counts, exceptions, sample IDs, and owner sign-off. | |
V-07Blocking | Roles, moderation, trust, bans, and permissions reconciliation | Compare source inventory, transformed output, destination results, and a stratified sample for roles, moderation, trust, bans, and permissions. | Every in-scope item is present, intentionally transformed, explicitly excluded, or retained in the signed source archive. | Roles, moderation, trust, bans, and permissions ledger with counts, exceptions, sample IDs, and owner sign-off. | |
V-08Blocking | Courses, events, paywalls, and memberships reconciliation | Compare source inventory, transformed output, destination results, and a stratified sample for courses, events, paywalls, and memberships. | Every in-scope item is present, intentionally transformed, explicitly excluded, or retained in the signed source archive. | Courses, events, paywalls, and memberships ledger with counts, exceptions, sample IDs, and owner sign-off. |
Remove the scaffolding safely.
Safe after: One complete operating cycle, at least seven stable days, and owner sign-off on every blocking check and exception.
- Create final Circle exports and archive verification, access, financial, and rollback evidence.
- Revoke temporary credentials, API keys, webhooks, elevated roles, and migration network access.
- Remove obsolete jobs, embeds, domains, integrations, collectors, routes, and DNS records.
- Keep the source intact and read-only through the approved legal and operational retention window.
- Cancel paid plans only after billing, legal, security, evidence, and recovery review.
- Schedule the next Discourse backup, restore test, access review, and migration-playbook review.
Verify against the primary material.
Platform behavior changes. Check these sources and the review dates above before executing a production migration.
- Circle: official portability and migration documentationAccessed 2026-07-20
- Discourse: official portability and migration documentationAccessed 2026-07-20