Permissions & roles
Who can change what, the security role and diagnostics.
| Level | Can |
|---|---|
| Owner | Everything, including protected modules, security role, backups/restore, networks, webhooks and the Server Builder. |
| Security role | Protected modules, bot approvals, staff-guard decisions, backups and webhooks. Granted only by the owner. |
| Administrators (Administrator / Manage Server / configured admin roles) | Non-protected modules, panels, community tools, moderation. |
| Moderators (Ban/Kick/Timeout permission or configured mod roles) | Moderation actions, cases, reports, logs (read). |
| Ticket staff | Ticket handling and internal notes. |
Protected modules
Anti-raid, anti-nuke, anti-spam, anti-webhook, bot quarantine, coordinated raids and staff guard (including staff exemption roles) can only be changed by the owner or verified security-role holders.
The security role
The owner designates a role in the dashboard. Members holding it at that moment are confirmed. Later grants are checked against the audit log: a grant by the owner is confirmed; a grant by anyone else is removed and the owner is alerted. If the audit log cannot attribute the grant, the holder gets no protected access until the owner confirms — no one is accused without evidence.
