FREE 10-STEP CHECKLIST

How to audit a Discord server without guessing.

Use this owner-focused checklist for a manual review or let Oracle automate the configuration evidence it can safely retrieve. The goal is a prioritized baseline—not a false promise that every server risk fits in one scan.

Read-only firstAudit reads no messagesFree during beta

THE CHECKLIST

Work from authority and evidence to controlled verification

A small server can use this as a one-hour baseline. A complex community should treat it as the opening pass and assign specialist review where coverage is partial or unavailable.

  1. Confirm the auditor and owner authority

    Record who requested the review, who owns the server, and which administrators can authorize changes. Verify the bot role and exact permissions before treating any area as assessed.

  2. Capture the configuration baseline

    Save guild settings, roles, permission values, channel categories and overwrites, native AutoMod rules, onboarding configuration, and sanitized integration inventory before proposing work.

  3. Review @everyone first

    Check Administrator, elevated management grants, broad member capabilities, public channel overwrites, and whether default visibility matches the intended arrival model.

  4. Inspect powerful roles and hierarchy

    List Administrator and management-capable roles, distinguish managed bot roles, compare Discord hierarchy precisely, and separately review who actually holds each sensitive role.

  5. Resolve channel access by perspective

    Test public, member, moderator, and specialist-role perspectives across categories and channels. Note inherited overwrites, explicit exceptions, and any permission values that could not be parsed.

  6. Check guild safety and AutoMod

    Review verification level, explicit-content filtering, default notifications, MFA posture, harmful-content blocking, mention-spam controls, exemptions, and disabled rules.

  7. Inventory bots, webhooks, and integrations

    Identify incoming webhooks, installed applications, Administrator-granting bot roles, revoked or disabled integrations, ownership gaps, and channel capacity risks without exposing credentials.

  8. Validate onboarding and structure

    Check welcome and native onboarding configuration, arrival-channel clarity, channel/category references, role and channel headroom, and whether the server has accumulated duplicate structures.

  9. Separate evidence from unavailable coverage

    Mark every area assessed, partial, or unavailable. Do not interpret absent member, message, activity, or privileged integration data as proof that no risk exists.

  10. Prioritize, approve, and verify

    Put critical and high evidence first, distinguish safe automation from manual owner review, preview exact operations, capture a pre-change baseline, and rerun the audit after any change.

WHAT AUTOMATION CHANGES

Oracle collects the repeatable evidence; the owner keeps the judgment

AUTOMATED

Configuration inventory and rules

Oracle reads supported Discord configuration, applies deterministic findings, calculates rubric deductions, and preserves coverage limitations.

OWNER DECISION

Intent, people, and tradeoffs

You decide who should hold powerful roles, which rooms should be public, whether stricter verification fits the community, and what to change.

SEPARATE TOOLS

Real-time behavior and incidents

Messages, member activity, live scams, raids, and moderation performance need other evidence and controls; Oracle does not claim them in this audit.

FREE DURING BETA

Turn the checklist into a saved, repeatable baseline.

Run the configuration audit free, keep the report private, and schedule daily or weekly rescans during beta.

Run the free audit