- Home
- Server Configuration
- Hierarchy of Roles & Permissions
Hierarchy of Roles & Permissions
import { Card, CardGrid } from ‘@astrojs/starlight/components’;
Poor permission configuration is the primary cause behind over 80% of server compromise incidents (nuking). This module defines the architectural hierarchy necessary to bulletproof your server.
Principle of Least Privilege (PoLP)
Section titled “Principle of Least Privilege (PoLP)”Golden Rule: Grant each staff member only the exact permissions strictly required to execute their current duties—nothing more.
Critical Permissions (Extreme Risk 🔴)
Section titled “Critical Permissions (Extreme Risk 🔴)”These permissions must NEVER be assigned to daily operational roles (such as Junior Mods or Trials). Restrict them exclusively to Ownership and verified Administrators with mandatory 2FA:
- Administrator: Grants absolute permissions bypassing all channel overrides and protections.
- Manage Server: Allows modifying server name, invites, adding unvetted bots, and altering security settings.
- Manage Roles: An account with this permission can manipulate roles beneath them to escalate privileges.
- Manage Webhooks: A frequent vector used to spoof announcements and blast phishing links.
- Mention
@everyoneand@here: Must be explicitly disabled across all routine channels.
Visual Role Hierarchy
Section titled “Visual Role Hierarchy”In Discord, vertical position in the role list determines operational authority:
[▲ Highest] 👑 Server Owner (Root ownership) 🛡️ Administrator / Security (System architects) 🎖️ Staff Supervisor (Operational leaders) ⚔️ Senior Moderator (Escalated sanctions & appeals) 🗡️ Junior Moderator (Chat containment & timeouts) 🤖 Moderation Bots (Strategically positioned) 🌟 VIP / Server Booster (Cosmetic privileges) 👥 Verified Member (Default community access) ⚪ @everyone (Zero write access prior to screening)[▼ Lowest]