Skip to main content
Pup observes Discord audit-log events for bans, kicks, channel and role deletion, dangerous role-permission grants, webhook creation, and server identity changes. Each server chooses its own protected-resource scope (an empty list means all resources), short detection window, thresholds, and trusted actor exemptions within Pup’s fixed safety ceilings. Configure these controls under Protection overview → Administrative anti-nuke. An incident is durable: it records the audit reference, policy revision, event count, containment result, and staged recovery state. Audit-log reasons and webhook secrets are never copied into the record. Containment is intentionally narrow. Pup only removes mutable roles from the suspected actor after its threshold is reached. It never acts on the guild owner, exempt actors, managed roles, or roles at or above Pup’s own hierarchy. When hierarchy prevents containment, the incident stays open for review. The same Administrative anti-nuke page includes incident review. A security approver other than the suspected actor can mark a false positive, begin recovery after independently reviewing Discord state, and complete recovery. Recovery does not recreate deleted resources or restore permissions automatically.

Emergency containment

Open Protection overview → Emergency containment to restrict a specific Discord resource during an incident. Enter its ID, a clear reason, and a duration. Review the preview before explicitly activating containment. The dashboard handles one resource at a time; the security API accepts at most 25 specific resources per plan. Broad server-wide targets are not accepted. Activation queues the Discord change. Pup checks ownership and hierarchy before applying it. Supported reversible actions suspend permissions on a Pup-owned containment role below the bot, apply six-hour slowmode to a specific channel, deny that channel’s @everyone message sending, or remove invite creation from the server’s @everyone role. Managed bot roles and other roles Pup does not own cannot be suspended through this workflow. Pup records the original value and restores it only if it still matches the value Pup set. A manual change made during the incident is preserved. Repair must be staged and approved by a different authorized operator before restoration is queued. Check the incident’s result: approval alone does not confirm that Discord has applied or restored a restriction. Deleting a confirmed-compromised webhook is permanent and requires a separate irreversible-action acknowledgement. Pup checks that the webhook belongs to the server and never stores its URL or token. Expiry or repair cannot recreate it.