Trust design: perhaps an invite link shouldn't always be trusted (maybe it's a good idea to ask the user?)

Mockup suggestion, including the default states. (If you want a paranoid UI, default to unchecked on both sides instead.)

Group codes should have no checkbox and behave as if unchecked.

Unchecked on either end = padlock icon. (Key changes still should cause a big alert, like current e2ee.)

Checked on both ends = verified checkmark.