Skip to content
Docs menu: Staff PIN

Moderation

Staff PIN

In short

With the staff PIN on, Bastion asks a moderator for their own 6 digit PIN before dangerous commands, then leaves them alone for 30 minutes. A stolen Discord account doesn't know the PIN. It's part of Bastion Pro and only the owner can switch it on.

Why use it

Most servers that get wrecked are wrecked through a moderator's stolen account. The thief has the account but not what's in the moderator's head. A PIN puts one more thing between them and your ban button.

Switch it on

  1. Open Moderation

    On the dashboard, open Moderation and scroll to Staff PIN. Only the server owner can change it.

  2. Choose the commands

    Tick which commands ask for the PIN. There are 14. All are ticked to begin with except Quarantine someone and Timeout longer than 1 day.

  3. Choose how often

    After a correct PIN, Bastion doesn't ask that moderator again for 30 minutes. You can set 5 to 240.

  4. Tell your staff

    Each moderator runs /pin set once. Until they do, the protected commands won't run for them. A first PIN starts working 24 hours later, unless you approve it. See below.

Commands it can protect

  • /ban, with or without a length, Ban from the right-click menu, and the Ban button on a second-account alert
  • /kick, Kick from the right-click menu, and the Kick button on a second-account alert
  • /softban
  • /quarantine remove, and the Let in button on a second-account alert
  • /lockdown, every part of it: start, end, one channel, hiding and /lockdown update
  • /backup restore
  • /purge of more than 50 messages, and Delete newer messages
  • /cleanup, the mass kick or ban
  • /raid cleanup
  • /unban
  • Editing, closing or reopening a case, and clearing someone's warnings
  • A /warn that would kick or ban automatically because of your warn steps
  • /quarantine add. Off until you tick it
  • /timeout for longer than 1 day. Off until you tick it

Where a command asks Are you sure first, the PIN is checked again when you press Confirm or Yes. Cancel never asks.

For moderators

/pin set

Set your PIN, or change it. A form opens that only you can see. To change a PIN you need the current one.

Example

/pin set

When a command needs your PIN, a small form opens. Type the 6 digits. If it's right, a slash command runs straight away. For a right-click action or a button, do it once more and it goes through.

  • A PIN is exactly 6 digits. Repeats like 111111 and runs like 123456 are refused.
  • Your PIN is for one server. Set one in each server that asks.
  • Don't reuse a PIN from your bank or your phone.

A new PIN waits 24 hours

A moderator's first PIN starts working 24 hours after they set it, and Bastion tells your security log straight away. Until then the protected commands won't run for them. A thief who sets a PIN on a stolen account gains nothing that day, and you hear about it at once. The same wait applies to a new PIN set after a reset. Changing a PIN you already have needs the old one and has no wait.

/pin approve

Makes someone's new PIN work now. For the owner and trusted people. Nobody can approve their own.

Example

/pin approve user:@Sam

From the dashboard

Lockdowns, restoring a backup and raid cleanups started from the dashboard ask for the PIN as well. The page shows Confirm this in Discord with your PIN, and Bastion messages you a button. You have 5 minutes. A PIN you typed earlier for a command doesn't count here. The owner on Discord is never asked.

Wrong PINs

Five wrong tries lock that moderator out of the protected commands for 15 minutes. Bastion posts a warning in the security log, because five wrong PINs usually means someone else is at the keyboard.

For the owner

/pin reset

Clear a moderator's PIN and any lockout, so they can set a new one. For the owner and trusted people. Nobody can reset their own PIN, and a recovery owner can't reset or approve PINs in their first 7 days.

Example

/pin reset user:@Sam

The owner is never asked for a PIN. Nobody, including the owner and Bastion's own team, can read a PIN: only a scrambled copy is stored.

A moderator forgot their PIN.

Run /pin reset on them, then they run /pin set again. The new PIN waits 24 hours unless you run /pin approve.

A moderator deleted their Bastion account.

Their PIN is erased, and they can't set a new one or use the protected commands until you run /pin reset on them. That stops someone with a stolen account from wiping the PIN and choosing their own.

Does it stop a moderator who has gone rogue?

No. They know their own PIN. That's what the Anti-Nuke limits are for. The PIN is for stolen accounts.

Bastion asked again before 30 minutes were up.

Bastion restarted. It forgets who has typed their PIN when it restarts, which only means being asked once more.

What happens if Pro ends?

The staff PIN switches off and commands run without it. Saved PINs are kept, so switching it back on needs no new setup.

Last updated