# Bastion documentation

> Bastion keeps leakers, cheaters and scammers out of your Discord. A shared blacklist, honeypot channels, member verification and five escalating actions you control from one dashboard.

Source: https://www.bastionsecurity.app/docs

## About Bastion

Bastion is a moderation platform for Discord communities built around games. It combines a shared blacklist of known leakers, cheaters, scammers and resellers with honeypot channels, and lets every server decide for itself how hard to respond.

### Why it exists

Game communities lose money and trust to the same small group of people: the ones who leak paid content, sell cheats, scam buyers or resell stolen work. Those people move from server to server, and every server has to discover them all over again.

Bastion turns that discovery into a shared effort. Once an account is listed with evidence, every protected server knows about it the moment that account shows up, or the moment it gets listed while already inside.

### How it fits together

The bot lives in your server and watches joins and the honeypot channel. The dashboard is where server owners configure the modules, review flagged members and read the logs. The account page is where listed users see their own entry, the evidence and the outcome of their appeal. Bastion staff curate the list from the staff panel.

### Principles

- You decide the response. Bastion never punishes anyone on its own; it applies the action your server chose.
- Evidence for every entry. Nobody is listed on a hunch, and every listed person can see what was collected.
- Local exceptions. A server can whitelist an account for itself without touching the global list.
- Everything is logged. Every action, its outcome and the reason it was taken, per server.

### Where to go next

Pick a chapter in the sidebar. Quick start gets a server protected in five minutes; the module chapters explain every setting in detail.

## Quick start

From invite to protected in five minutes. (https://www.bastionsecurity.app/docs/quick-start)

### 1. Invite the bot

Use the Add to Discord button on the website. The invite asks for Kick Members, Ban Members, Moderate Members, Manage Messages, View Channels and Send Messages. Every action the bot can take needs one of these.

After joining, Bastion posts a welcome message in your system channel with a link to the dashboard. Nothing is enforced yet.

### 2. Fix the role order

Discord only lets a bot kick, timeout or ban members whose highest role is below the bot's own role. Open Server Settings, Roles, and drag the Bastion role above your regular member roles. Leave it below your admin roles if you like.

> Most failed actions in the logs are caused by role order, not by missing permissions.

### 3. Open the dashboard

Log in with Discord and choose Manage my server. Pick your server. Under Settings, choose a log channel: every report lands there.

### 4. Configure the modules

1. Blacklist: turn the module on, choose the action, decide whether to act on members already inside.
2. Honeypot: create a bait channel, select it, choose the action and add exempt roles for staff.
3. Run /status in your server to double check what is active.

## Blacklist module

How the shared blacklist works and how joins, flags and sweeps are handled. (https://www.bastionsecurity.app/docs/blacklist)

### What is on the list

The Bastion blacklist is a single database of Discord accounts, maintained by Bastion staff. Each entry has a category (leaker, cheater, scammer, reseller, other), a severity from 1 to 5, a public reason and evidence.

Server owners never edit the global list. They decide what their own server does with it, and can whitelist accounts for their own server.

### Three ways a match is found

Rejoins are always enforced again. Flag and sweep enforcement happen once per entry per server, so nobody gets punished twice for the same listing.

- Join: when a listed account joins, the action runs instantly.
- Flag queue: when staff list an account, the bot checks every server it is in within seconds and acts where the account is already a member.
- Sweep: on a schedule (default every 6 hours) the bot walks all members of all servers and enforces anything it missed, for example after downtime.

### Filters

Categories: uncheck the categories you do not care about. Minimum severity: ignore low severity entries. Both filters apply to joins, flags and sweeps.

### Whitelist

Under Flagged members you see every listed account Bastion has seen in your server, with the public reason. From there you can whitelist an account for your server only. The whitelist is checked before any action, and you can lift a ban or timeout Bastion applied at the same time.

## Honeypot module

Set a trap for self-bots, raids and people who ignore the rules. (https://www.bastionsecurity.app/docs/honeypot)

### The idea

A honeypot is a channel nobody should post in. Real members read the pinned warning and move on. Automated accounts and spammers post in every channel they can see, and trip the trap.

### Setting it up

1. Create a text channel, visible to everyone, with a pinned message saying not to post there.
2. In the dashboard, open Honeypot, enable the module and select the channel. Or run /honeypot set #channel.
3. Choose the action. Softban is a good default: it purges the spam and lets a real person come back.
4. Add your staff roles under Exempt roles. Members with Manage Server are always exempt.

### What gets logged

The report shows who posted, what they wrote (if the bot has the Message Content intent), how many attachments, and whether the action succeeded. Delete the message is on by default so the bait never spreads.

## Verification module

Let members verify through Discord and keep out accounts that hang around in the wrong servers. (https://www.bastionsecurity.app/docs/verification)

### The idea

A member clicks the Verify button in your server, logs in with Discord on the Bastion website and gets your verified role. During that one click Bastion checks two things: whether the account itself is on the blacklist, and whether any server the member is in is on the Bastion server blacklist, a list of servers built around leaking, cheating or scamming that is curated by Bastion management.

Only the account identity and the server list are read. Messages, friends and other data are never touched.

### Setting it up

1. Create the role members should get. Drag the Bastion role above it in Server Settings, Roles, otherwise the bot cannot hand it out.
2. In the dashboard, open Verification, enable the module and pick that role. Only roles the bot can assign are listed.
3. Choose what happens to a member who is clean but sits in a blacklisted server: notify only, kick, timeout, softban or ban. With notify only or timeout you can decide to still give the role.
4. Pick a channel and post the panel. It is a message with a Verify button that links to https://bastionsecurity.app/verify/<serverId>. You can also share that link directly.

### What the member sees

- Clean: a confirmation and the role right away.
- In a blacklisted server: verification refused (or a note, if you chose to still give the role). The page never names the server.
- Blacklisted account: refused, with a link to their account page to file an appeal.

### What gets logged

Every attempt lands in your log channel and under Logs in the dashboard, filterable as Verification: who verified, whether the role was given, which action ran, and which blacklisted servers were found. If you enabled the DM, the member gets it before a kick, softban or ban.

## Actions

What each of the five responses does exactly. (https://www.bastionsecurity.app/docs/actions)

### The five actions

- Notify only: a report in the log channel, nothing else.
- Kick: removes the member. They can rejoin with an invite, and will be checked again.
- Timeout: Discord's built-in mute for a number of minutes you choose, up to 28 days.
- Softban: ban with a 7 day message purge, followed by an immediate unban. Cleans up the mess without a permanent lockout.
- Permanent ban: ban with a 7 day message purge. Stays until someone unbans.

### Requirements

Kick needs Kick Members. Timeout needs Moderate Members. Softban and ban need Ban Members. On top of that, the bot role must be above the member's highest role. When an action fails, the log shows why.

### Direct messages

Both modules can DM the user before acting. The blacklist DM includes a link to the account page so the person can see the evidence and appeal. Closed DMs fail silently.

## Account check and appeals

What listed users can see and how appeals work. (https://www.bastionsecurity.app/docs/account-check)

### Checking your account

Anyone can log in with Discord on the website and choose Check my account. The page shows whether the account is listed, the category, severity, the public reason and all evidence that staff made visible.

### Appeals

A listed user can file one appeal at a time. Bastion staff review it and either accept (the entry is removed and every server sees the account as clear) or reject with a note. The user sees the outcome on their account page.

## Slash commands

Everything you can do without leaving Discord. (https://www.bastionsecurity.app/docs/commands)

### Commands

- /check user: is this account on the blacklist? Needs Moderate Members.
- /scan [enforce]: scan every member against the blacklist. With enforce:true the configured action is applied to matches. Needs Manage Server.
- /status: show the current configuration for this server.
- /honeypot set #channel and /honeypot clear: quick honeypot setup.
- /language: language of the bot in this server (English, Dutch, French, Turkish, Polish, Czech or German).
- /report: points you to the report page on the website. Reports are submitted there after logging in with Discord, so evidence and categories are always complete.

### Messages

All bot messages use Discord's component layout with the Bastion accent colour, and include a button to the relevant dashboard page.

## FAQ

Short answers to common questions. (https://www.bastionsecurity.app/docs/faq)

### Why did an action fail?

Nine times out of ten the Bastion role is below the member's role. Drag it up in Server Settings, Roles. The log entry tells you whether it was hierarchy or a missing permission.

### Can I add someone to the blacklist myself?

No. The global list is curated by Bastion staff with evidence, so that servers can trust it. Report accounts or servers via Submit a report on this site (log in with Discord first) or type /report in Discord.

### Does the bot read all my messages?

The bot only looks at messages in the honeypot channel. Message content is stored for those messages only, so your staff can see what was posted.

### Which languages are supported?

English, Dutch, French, Turkish, Polish, Czech and German, for the website, the dashboard and the bot. Set the site language with the switch in the header and the bot language per server under Settings.
