Guide · September 1, 2026 · 3 min read

Who can destroy your server today?

The question is not rhetorical, and the answer almost always surprises. On a two-year-old server, between the role created for an event, the bot installed once, and the moderator promoted “to help out”, the list is longer than expected.

Audit log — inside the OriusBot admin panel.
Audit log — inside the OriusBot admin panel.

The five permissions that matter

Discord offers about thirty. Five are enough to do irreversible damage; the others are, at worst, annoying.

  • Administrator — contains all the others and ignores channel restrictions. One tick box to lose everything.
  • Manage Server — name, region, invites, integrations.
  • Manage Roles — allows granting oneself rights, within the limit of one's position.
  • Manage Channels — allows deleting every channel.
  • Ban Members — allows emptying the server.

The check to run fits in one sentence: for each of those five permissions, list the roles that carry it, and ask yourself whether every person concerned should be able to do that tonight.

What the audit always finds

A forgotten administrator role. Created for an event, for a passing developer, or “to test”. It is always still there, and somebody always still has it.

An over-privileged bot. Many bots ask for the Administrator permission at install because it is simpler for them. A compromised bot with that permission is equivalent to a compromised administrator account — and you will have no password to change.

A colour role with rights. A decorative role handed out by a menu, to which somebody once added “manage messages” to help out. Two hundred people now hold it.

Channel permissions that contradict the roles. A private channel where @everyone was allowed by mistake stays invisible in the role list: only a channel-by-channel review shows it.

The hierarchy, as important as the permissions

A role can only act on roles positioned below its own. That rule protects effectively, provided the order matches the actual organisation.

Two checks: is the bot's role high enough to do its job — and no higher? And are the moderation roles above the member roles but below administration? A moderator placed above an administrator can penalise them, which is rarely the intention.

Running the audit without spending the day on it

A manual review of a server with forty roles and sixty channels takes two hours and still misses things. An automatic review lists in one command the roles carrying sensitive permissions, the number of members concerned, and the channels whose permissions contradict the roles.

The important point: an audit changes nothing. It gives a picture, and the decisions stay human. A tool that automatically corrected permissions would itself be the server's biggest risk.

A note on reading it: an Administrator role mechanically holds every other permission. A report that lists it in every category is unreadable; it must appear once, as what it is — the most serious case.

After the audit

  1. Remove Administrator from anything that does not absolutely need it. Precise permissions are almost always enough.
  2. Review the bots one by one: each needs only what its functions require.
  3. Delete empty or unused roles. A role that exists always ends up being granted.
  4. Enable two-factor authentication for moderation, at server level.
  5. Redo the audit every quarter, and after every change of team.

Frequently asked questions

How many administrators should there be?

Two, rarely three: the owner and one trusted person for when they are unavailable. Beyond that, the question is no longer trust but attack surface.

Can a bot do without Administrator?

Almost always. The request comes from installation convenience, not from a technical necessity. A bot that refuses to work without it is a bot to examine closely.

Does two-factor authentication really protect?

It blocks moderation actions from an account whose password has leaked. It is the least costly and most effective measure of the lot.

Should channel permissions be audited too?

Yes: that is where the inconsistencies hide. A correctly configured role can be contradicted by an allowance set on a single channel, and nobody notices.


Read next : Anti-nuke: protecting your server, Command permissions, Logging.