Guide · September 1, 2026 · 3 min read
Every command in its place
A freshly installed bot offers a hundred commands to everybody, everywhere, all at once. Most servers do not want half of them, and not in every channel. The setup takes ten minutes and saves months of telling people off.
Contents
Two permission systems overlap
This is the most frequent source of confusion. Discord has its own application-command setting, reachable in the server settings: it decides who sees a command in the menu.
The bot decides who can run it. The two do not do the same job, and one does not replace the other.
Hiding a command without forbidding its execution leaves a hole: somebody who knows its name can still run it. Forbidding execution without hiding it produces the opposite: the command appears and refuses to work — confusing, but harmless.
The combination that works: commands stay visible to everyone, and the bot refuses those that are not allowed, saying why. A member then understands that a function exists and is not open to them, which beats a different menu for each person.
The three useful restrictions
By role. The most common: reserving moderation commands for the team, configuration commands for administration. To be set on roles, never on people — somebody who loses their role loses their rights, and there is nothing to remember to remove.
By channel. Economy and game commands in the channel meant for them, and nowhere else. It is the restriction with the most visible effect on the server's readability, and the one most often forgotten.
Plain disabling. A function the server does not use does not need to exist. Fewer active commands means fewer things to explain to newcomers and fewer unexpected behaviours.
A starting point in ten minutes
- Moderation — reserved for the team's role. No exceptions.
- Configuration — reserved for administration, and nobody else.
- Games, economy, images — limited to the dedicated channel.
- The rest — open, except what you do not use.
The cooldown
A delay between two uses of the same command serves two distinct goals. The first is obvious: stopping a command from being run forty times in a row to flood a channel.
The second less so: some commands are expensive to run — generating an image, analysing a file, querying an external service. Without a delay, a handful of members is enough to slow the bot down for the whole server.
A delay per command and per person, from a few seconds for light commands to a minute for the heaviest, settles both cases without anyone noticing in normal use.
The moderation role and its pass
One point to decide explicitly: does the moderation role bypass the automatic filters? A moderator who posts a link and has their message deleted by the link filter has an unpleasant experience, and false positives on the team undermine trust in the whole system.
Common practice is for the moderation role to be exempt from content filters, but not from the logs: what a moderator does stays on record, even if nothing stops them. It is an exemption from automation, not a blind spot.
Check rather than assume
A restriction that has been set is not a restriction that has been checked. Two checks are worth the time they take: trying a moderation command with an account that has no role, and looking at the list of actually active commands to spot the ones nobody has ever used.
The second check is the one that surprises most. On most servers, a third of the enabled functions has never been used; disabling them costs nothing and simplifies everything else.
Frequently asked questions
Should reserved commands be hidden?
No. A command that is visible and refused with an explanation teaches the member how the server works. An invisible command gives the impression it does not exist, until the day somebody discovers it elsewhere.
Does a restriction apply to administrators?
Discord's Administrator permission overrides almost everything: one more reason to grant it to very few people.
Can a specific subcommand be restricted?
Restrictions apply to the command. For a special case, it is often simpler to limit the channel it can be used in than to look for finer granularity.
What happens if a restricted role is deleted?
The restriction becomes moot and the command goes back to being open under the default rule. It is a case to check after any reorganisation of the roles.
Read next : Permission audit, Logging, The web panel.
