Docs/Information/Permissions
Permissions
The full permission matrix - what each command level lets a member run in Discord, what each dashboard role can see and change, and how the two line up.
HepBoat has two permission systems, and they are built to line up. Command levels decide what a member can run in Discord chat. Dashboard roles decide what a staff member can see and change on the dashboard. Give someone the matching pair and they can do the same things in both places - no more, no less.
The short version
| In Discord you have | On the dashboard you get | What that means |
|---|---|---|
level 0 (everyone) |
nothing, or viewer |
Run member commands. A viewer can also read the config, its history, and diagnostics. |
level 50 (moderator) |
mod |
Everything a moderator does: infractions and notes, tags, appeals and applications, stats, the blacklist and scam-image lists. |
level 100 (admin) |
editor |
Everything that changes how the bot behaves: every settings form, the raw config, slash opt-in, custom commands, XP and balance adjustments, forum posts. |
| server owner | admin |
The things nobody should get by accident: dashboard access itself, API keys, server networks, deleting infractions, the AppBot import. |
Both maps live in your config - levels: for Discord and web: for the
dashboard - and both are edited on Setup - Access & Permissions. They are
separate on purpose: a moderator can hold level 50 without a dashboard login,
and a trusted helper can hold viewer without any command level at all.
Command levels
A member's level is the highest their roles grant in levels:. A user
ID entry overrides that outright, up or down, so it is also how you demote
one person who holds a high-level role. Levels are just numbers, but every
built-in command sits on one of four tiers:
| Level | Name | What sits here |
|---|---|---|
0 |
everyone | Member features: games, rank cards, music, reminders, tag, apply, report, selfmute, info lookups. |
10 |
trusted | Creating and managing tags. |
50 |
moderator | Acting on members and reading moderation data: ban, kick, mute, warn, timeout, infraction and note lookups and edits, role add and remove, slowmode, cease, clean, starboard hides, scam-image teaching, economy arrests, and every applications command. |
100 |
admin | Rewriting the server's behaviour or acting with the bot's own authority: mute-role setup, modlog hush, custom commands, announce, the bot blacklist, XP and balance grants, archives, nukes, role sprays, hard deletes of infractions and notes. |
The rule behind the tiers: reading and reversible member-scoped actions are
moderator work; rewriting config, moving the economy by hand, posting as the
bot, and erasing audit history are admin work. A read-only command sits at
the lowest tier whose members could already learn the answer elsewhere - which
is why blacklist list is moderator while blacklist add is admin, and why
xp level (a calculator) is open to everyone.
Every plugin page lists its commands with their level, and the full list is at
the bottom of this page. To move one for your server, use commands.overrides
(see General Configuration) and
check the result with the Would it run? resolver on Access & Permissions.
A few commands add their own check on top of the level:
- Moderation commands never act on the server owner, on the bot, or on anyone whose level is equal to or higher than yours.
- Application reviews also accept the application's
staff_role, so a team can review one form without holding level50. - Server bets can be created and resolved by the bet's creator or by the roles
in
betting.creator_roles. - Tags carry their own per-function levels under
plugins.tags(create and remove at10, edit and owner changes at50by default), and removing someone else's tag always needs the moderator level.
Dashboard roles
Roles are ordered viewer < mod < editor < admin; a higher role can do
everything a lower one can. The server owner and whoever invited the bot
start as admin. Only an admin can change web:, and never their own entry.
| Page or action | viewer | mod | editor | admin |
|---|---|---|---|---|
| Read the config, config history, diagnostics | yes | yes | yes | yes |
| Save any settings form or the raw config; restore a version | yes | yes | ||
| Command levels, overrides, lockdowns (Access & Permissions) | yes | yes | ||
| Infractions and notes: view, edit reason or expiry, expire now | yes | yes | yes | |
| Infractions and notes: delete | yes | |||
| Tags: view, create, edit, delete | yes | yes | yes | |
| Custom commands: view | yes | yes | yes | |
| Custom commands: create, edit, delete | yes | yes | ||
| Stats; Levels and Games tabs (read, member lookups, ledger) | yes | yes | yes | |
| Adjust XP or balances, give items, set the market index | yes | yes | ||
| Blacklist: view | yes | yes | yes | |
| Blacklist: add or remove | yes | yes | ||
| Scam images: view, teach, forget | yes | yes | yes | |
| Appeals: review the queue | yes | yes | yes | |
| Appeals: form settings | yes | yes | ||
| Applications: builder, questions, apply posts, blacklist, queue | yes | yes | yes | |
| Applications: import from AppBot | yes | |||
| Slash command opt-in | yes | yes | ||
| Forum posts (created as the bot) | yes | yes | ||
| Networks: view | yes | yes | yes | |
| Networks: create, join, leave, policy, sync | yes | |||
| API keys | yes | |||
Dashboard access (web:) |
yes | |||
| Wipe the config | server owner only |
Two things follow from the way this is built:
- Anything stored in your config can never need more than
editor, because an editor can already change it on the Config page. The forms are just friendlier ways to edit the same document. - Anything that mirrors a chat command takes that command's tier. Editing an
infraction reason is
infractions reasonin Discord (level50), so it ismodon the dashboard.
Suggested setups
- Small server: owner as
admin, your moderator role at level50, andmoddashboard access for whichever moderators want the queue and the infraction pages. - Staff team with a config lead: the config lead at
editorand level100; moderators atmodand level50; aviewerlogin for anyone who should be able to read the rules but not touch them. - Never hand out
adminfor convenience. It is the only role that can add more logins, issue API keys, and join ban-sharing networks.
Every command by level
| Level | Commands |
|---|---|
| 0 (everyone) | about, apply, avatar, balance, bank-heist, bet cancel, bet create, bet list, bet lock, bet resolve, bird, blackjack, blep, bunny, canadagoose, cat, channel, coinflip, crash, crime, custcmd list, daily, dashboard, dice, docs, dog, duck, emoji, fish aquarium, fish collection, fish profile, fish sell, fish shop, fish trophies, fish, flair set, flair, floof, fox, help, highlow, horserace, icebreaker, info, invest, jumbo, leaderboard, leave, lily, nowplaying, pause, pay, ping, pizza, pizzacredit, play, profile, quests, queue, r add, r clear, r list, random coin, random number, rank, rankcard background, rankcard bio, rankcard color, rankcard message, rankcard reset, rankcard title, remind, report, resume, rewards, richest, rob, roulette, rps, seen, selfmute, server, shibe, shield, shop, skip, slots, stop, tag, timeleft, todo, todos, volume, work, xp level |
| 10 (trusted) | tag create, tag manage, tags |
| 50 (moderator) | antiraid, app blacklist, app cooldown, app create, app delete, app disable, app edit, app enable, app list, app messages, app post, app questions, app show, apps ban, apps delete-warn, apps kick, apps mod-panel, apps timeout, apps warn, arrest, arrested, ban, blacklist list, cease, clean all, clean bots, clean user, cleanban, global-ping, infractions active, infractions bans, infractions duration, infractions info, infractions mutes, infractions reason, infractions recent, infractions search, infractions warnings, kick, mban, mention channel, mention disable, mention enable, mention here, mention, minfo, mkick, mmute, mtimeout, munban, munmute, mute, mwarn, nick change, nick remove, note info, note search, note, pardon, rankcard modreset, rankcard view, reactions clean, record, role add, role info, role list, role locked, role none, role remove, role search, scamimage add, scamimage list, scamimage remove, scamimage test, search, shut, slowmode channel, slowmode here, slowmode, softban, stars block, stars check, stars hidden, stars hide, stars show, stars stats, stars unblock, stars unhide, stats, tempban, timeout, track app, track response, unban, uncease, unmute, unshut, untimeout, v-log, v-snap, warn, xp show |
| 100 (admin) | announce, archive all, archive channel, archive here, archive user, blacklist add, blacklist remove, custcmd create-listen, custcmd create, custcmd edit, custcmd remove, eco give, eco item, eco reset, eco set, eco take, infractions clearall, infractions delete, invites prune, modlog hush, modlog unhush, muterole, note delete, nuke cancel, nuke channel, nuke here, nuke, relock, role cancel, role kick-none, role nuke, role spray, stars lock, stars unlock, stars update, unlock, webconfig show, xp give, xp reset, xp set, xp sync-roles, xp take |