Start here
The dashboard
In short
The dashboard is where you change settings: press Dashboard, approve on Discord and pick your server. The owner and anyone with Administrator or Manage Server can get in, but only the owner and trusted people can change the protection settings.
Signing in
Press Dashboard on the website. There's no sign-in page. You go straight to Discord's own approval screen. The same happens if you open any dashboard link while signed out. After you approve, you land on the page you were heading for.
CarefulBefore you approve, check the address bar says discord.com. Bastion has no password of its own and never asks for your Discord password.
If you cancel on Discord, or the sign-in fails, you see a page called Sign in to Bastion that says what went wrong. Press Continue with Discord to try again. That's the only time the page appears.
Bastion never sees your Discord password. It receives your Discord ID, username, avatar and verified email address, and the list of servers you're in, so it can show you the ones you manage. See privacy and data.
Adding Bastion to a server
After signing in you see your servers. Ones that already have Bastion are listed first and open straight away. The others are under Add Bastion to another server, each with an Add button.
Press Add next to the server
Discord opens with that server already chosen.
Approve in Discord
Leave the permissions ticked. Each one is explained on the permissions page.
Discord sends you straight back
You land on that server's setup page, ready for the setup wizard. You don't need to find the server in the list again.
If you cancel in Discord, you go back to the server list with a note saying Bastion wasn't added. Press Add to try again. The list recognises a newly added server straight away, so there's no need to wait or refresh.
Switching between servers
If you manage more than one server, press Switch server next to the server's name at the top of the dashboard. It lists your other servers that have Bastion. Pick one to jump straight to it, or choose All servers to go back to the full list.
Who can access a server
- The server owner.
- Anyone with the Administrator permission.
- Anyone with the Manage Server permission.
Nobody else can open the dashboard for your server, including your moderators. Moderator roles let staff use commands in Discord. They don't give dashboard access.
Who can change what
Opening the dashboard and changing a setting are two different things. The settings that decide whether your server is protected can only be changed by the server owner and the people on the owner's trusted list. Everyone else who can open the dashboard sees those pages but can't save them.
| Page | Who can change it |
|---|---|
| Anti-Nuke, Join Gate, Anti-Raid, Verification, Logs, Backups | The owner and trusted people. |
| The security level and the setup wizard | The owner and trusted people. |
| People: moderator roles | The owner and trusted people. |
| People: the trusted list | The owner only. |
| Automod, Moderation | Anyone who can open the dashboard. |
| Moderation: Accept appeals, Where appeals go, Where reports go, Staff tiers | The owner and trusted people. |
| Lockdown: every lock and unlock button | The owner and trusted people. |
| Backups: Back up now, Restore and Delete | The owner and trusted people. |
| Appeals: Approve, Deny, Deny and block, Unblock | The owner and trusted people. |
| Discord AutoMod: adding, changing and deleting rules | The owner and trusted people. |
If you aren't allowed to change a page, it opens with a note at the top saying you can look but not change, and every control is greyed out. Having Administrator in Discord doesn't change this. Only being the owner, or being on the trusted list, does.
TipThis is on purpose. Without it, a rogue or hacked admin could switch protection off in the dashboard and then attack.
Alerts when protection is weakened
Bastion tells you when someone makes the server less protected from the dashboard. It posts an alert in your security log channel naming who did it, and sends the server owner a private message. The owner gets at most one of these messages every 5 minutes for a server. The alert in the channel is posted every time.
These changes raise the alert:
- Switching off Anti-Nuke, the Join Gate, Anti-Raid or Automod.
- Switching off Block dangerous permissions in Anti-Nuke.
- Switching off Bots added without permission in the Join Gate.
- Removing the Security alerts channel on the Logs page. The alert goes to the channel that was just removed.
- Adding someone to the trusted list.
- Switching off Block dangerous channel permissions or Keep quarantined people quarantined in Anti-Nuke.
- Removing every alert role on the Logs page.
- Adding a staff tier, or giving one another command or more roles.
Switching something on, or changing a number, doesn't raise an alert.
The overview
The first page for each server shows:
- Your security score out of 100.
- Your security level, with a Change level link that opens the setup wizard.
- A checklist of what to fix, with a link to the right page for each item.
- A card for each module. Anti-Nuke, Automod, Join Gate, Anti-Raid and Verification have a switch on the card.
- Recent security events, such as a spammer being timed out or a raid being stopped. These are kept for 90 days. The Activity page shows more of them, plus the full case history.
Quick switches
The switch on a module card turns that module on or off without opening its page. It saves the moment you press it. There's no Save button.
- The same rules apply as on the module's own page. Only the owner and trusted people can switch Anti-Nuke, the Join Gate, Anti-Raid or Verification. Anyone who can open the dashboard can switch Automod.
- If you aren't allowed, the switch goes back and a note says why.
- Switching off Anti-Nuke, the Join Gate, Anti-Raid or Automod raises the Protection was weakened alert, the same as doing it on the page.
- Pressing the rest of the card opens the module's page.
Modules
Bastion is split into modules. Each one does one job and has its own page.
| Module | What it does | Can be switched off |
|---|---|---|
| Anti-Nuke | Stops a rogue admin or hacked account wrecking the server. | Yes |
| Automod | Stops spam without punishing normal chat. | Yes |
| Join Gate | Checks every account at the door. | Yes |
| Anti-Raid | Spots a flood of joins and shuts it down. | Yes |
| Verification | Makes new members prove they're human. | Yes |
| Logs | A record of everything Bastion does. | No, but it needs a channel |
| Moderation | Ban, kick, timeout and warn, with a case history. | No |
| Backups | A saved copy of your roles and channels. Pro. | No |
Four more pages do things instead of holding settings: Backups, Lockdown, Appeals and Discord AutoMod. They're described under Pages that do something, below.
There's also a People page for trusted people and moderator roles, an Activity page for security events and cases, and an Upgrade to Pro button that opens the checkout for that server. Billing is not under a server: the menu under your name has a Billing page that lists every Pro subscription you pay for, even for a server Bastion is no longer in.
Pages that do something
Most dashboard pages hold settings. These four act on your server.
| Page | What you can do there | Read more |
|---|---|---|
| Backups | Back up now, see your saved backups, restore one or delete one. The automatic backup settings are here too. Pro. | Backups |
| Lockdown | Lock every channel, lock staff powers, kick or ban everyone who joins, and unlock again. See what's locked right now. | Lockdown |
| Appeals | Read appeals, filter them, approve or deny them, and unblock people. | Appeals |
| Discord AutoMod | Add, switch off and delete Discord's own AutoMod rules. | Discord AutoMod |
How Backups, Lockdown and Appeals work
The website never touches your Discord server for these. It leaves a request for the bot, and the bot carries it out.
You press a button
For anything serious, such as a restore or a lock, the dashboard asks you to confirm first.
The button says Working on it
The request is waiting for the bot. On an appeal it says Decision sent to Bastion. The bot checks for itself that you're the owner or a trusted person before it does anything.
The result appears
Within a few seconds the page shows what happened in plain words, such as how many channels were locked. On the Backups and Lockdown pages it's also listed under Recent requests as Done or Failed.
- Who can press the buttons. The server owner and trusted people only. Everyone else who can open the dashboard sees the page with a note and no buttons. Having Administrator doesn't change this.
- If nothing happens. After about 30 seconds the page says Bastion has not answered yet. That means the bot is offline or restarting. Try again in a minute.
- Pressing twice. A second request of the same kind within a minute is refused with a note that Bastion is already working on it.
- In your log. Locks, unlocks and restores are posted in your log channel, the same as if you'd used the command.
Discord AutoMod is the exception. Those rules live in Discord, so Bastion changes them there the moment you press the button.
The Activity page
Activity has two lists:
- Security events. The 30 most recent things Bastion did or noticed. Kept for 90 days.
- Cases. Every ban, kick, timeout and warning, with its number.
At the top it shows how many appeals are waiting, with a button to open the Appeals page. Appeals used to be listed here. They have their own page now, with filters and the list of blocked people.
Simple and Advanced
Every module page opens in the simple view. It shows the on and off switch and the few settings most people need.
Below that is a section called Advanced settings. It holds the exact numbers: limits per minute, timeout lengths, time windows. You never have to open it. The security level you chose in the wizard already filled those in sensibly.
Settings marked Pro need Bastion Pro. You can see them on the free plan but not switch them on. Press a locked setting and a prompt opens. It explains what Pro includes, shows the price and has the buttons to buy it for that server.
TipMany settings have a small help icon. It gives a one-line explanation in plain words. The same explanations are in the glossary.
Saving
Change a setting
Flip a switch or type a number. Nothing changes yet.
Press Save
The change is checked, then stored. Bastion also checks that you're allowed to change that page. If a number is outside the allowed range, the dashboard tells you which one and saves nothing.
It takes effect
The bot picks up the new settings on its own. You don't need to restart anything or run a command.
My server isn't in the list.
You need to be the owner, or have Administrator or Manage Server in that server. If you were only just given the permission, wait a minute and refresh the page. A server you've just added Bastion to shows up straight away.
I pressed Dashboard and Discord opened.
That's how signing in works. There's no Bastion sign-in page. Check the address bar says discord.com, then approve.
A setting is locked and a Pro prompt opened.
That setting is part of Pro. The prompt shows the price and the buttons to buy it. Press Not now to close it. Nothing is changed or charged.
The page is greyed out and I can't change anything.
That page is limited to the server owner and trusted people. You can read it but not save it. Ask the owner to make the change, or to add you to the trusted list if you truly need it.
I changed a setting and nothing happened.
Check that you pressed Save. If you leave the page first, the change is lost. Your browser warns you before that happens.
Can my moderators use the dashboard?
Only if they have Manage Server or Administrator. Even then they can only change Automod and Moderation, and not whether appeals are on or where appeals and reports go. Otherwise they use slash commands. See the command list.
A button says Working on it and nothing happens.
The dashboard is waiting for the bot. If it then says Bastion has not answered yet, the bot is offline or restarting. Wait a minute and press it again. Nothing was done twice.
I can't see the lock or backup buttons.
Only the server owner and trusted people can use the Lockdown and Backups pages. You can still see what's locked and which backups exist. In Discord, anyone with Administrator can run /lockdown start and the /backup commands.
The switch on an overview card flipped back.
You aren't allowed to change that module. Only the owner and trusted people can switch Anti-Nuke, the Join Gate, Anti-Raid and Verification.
I can't see the buttons to decide an appeal.
Only the server owner and trusted people can decide appeals from the dashboard, because approving lifts a ban. Use the Approve and Deny buttons on the appeal in your Discord staff channel. A moderator can't approve there either if Bastion, the owner or a trusted person placed the ban or timeout. See appeals.
Can I undo a change?
Change it back and press Save. There's no undo button.
Last updated