Keep the bot's role at the top
A bot can only act on members and roles below its highest role. Attackers with higher roles cannot be stopped.
No bot can guarantee complete protection. These practices meaningfully reduce risk.
A bot can only act on members and roles below its highest role. Attackers with higher roles cannot be stopped.
Give specific permissions instead of Administrator. Every Administrator account is a potential nuke if compromised.
Require 2FA for moderation (Server Settings → Safety Setup) so a stolen password alone cannot perform moderation actions.
Security-role members can change protected settings. Only the owner can grant it; unauthorised grants are removed and reported.
New bots join quarantined. Approve only bots you added intentionally and still trust.
Point alerts to a private staff channel and keep owner DMs enabled for critical incidents.
Automatic backups run every 10 minutes. Check Diagnostics if the last backup is old.
Use the Report to platform context menu for phishing you see elsewhere; reviewers decide, reports alone never punish anyone.