PULSORT TIMES
Which Discord permissions are dangerous to grant — and how to audit your server
Servers aren't taken over by hackers — they're taken over by someone you granted access to. The permissions that equal admin, the role-hierarchy mistakes, and why access outlives the role. Plus a five-minute checklist.
Servers rarely get taken over by hackers. They get taken over by someone you handed permissions to yourself — a moderator, a helper, a bot you trusted. Usually with no bad intent: someone clicked the wrong thing, someone lost their account, someone left the team and the access stayed behind.
The good news is that almost all of it is caught by one five-minute check. Here's which Discord permissions are genuinely dangerous, why "just don't give out admin" isn't enough, and how to audit your own server.
One note up front: everything below can be done by hand, and the checklist at the end is written that way. But if repeating it every month isn't realistic, the audit can be automated — PULSORT walks every role and channel for you, lists what looks dangerous and offers a one-click fix. Links to the specific tools appear as we go.
Administrator isn't "more permissions". It's all of them at once
Administrator works differently from how it reads. It isn't a bigger bundle of rights — it bypasses the permission system entirely.
A member holding it:
- sees every channel, including ones explicitly hidden from them — channel settings simply don't apply;
- can grant themselves and anyone else any role below their own;
- deletes channels, roles and messages without limits;
- bans anyone ranked below them.
The part people miss: denies don't apply to them. You can deny an administrator access to a private channel all you like — they'll still be in it. Discord won't even evaluate the deny.
Granting it temporarily is a legitimate move and sometimes the sensible one: setting up a server's structure in one pass beats hand-placing two dozen permissions. The risk isn't the grant — it's forgetting about it. The permission stays for months and nobody remembers why.
So temporary access needs a definite end: job done, permission removed right away. It helps when the tool reminds you — after an operation that needed elevated permissions, PULSORT offers to take Administrator back in one click rather than leaving it to the owner's memory.
As a rule: permanent Administrator belongs to the owner alone. A moderator needs three or four specific permissions, not the full set.
Four permissions that quietly hand over the server
Some permissions look harmless but are effectively admin. They get handed out without a second thought.
Manage Roles. Lets someone create roles and assign them — any role below their own. A moderator with this can build a role carrying whatever permissions they want and give it to themselves. Formally you never granted admin. In practice you did.
Manage Webhooks. A webhook posts to a channel under any name and avatar. Someone with this permission creates one, then posts as "Staff": a fake announcement, a phishing link. In the audit log it reads as a bot message rather than their action. And a webhook keeps working after the person leaves the server — until you delete it by hand.
Manage Channels. Not just renaming. It also means deleting a channel along with its entire history, and rewriting channel permissions so that you stop seeing things.
Mention @everyone. Not destructive on its own, but it's a megaphone. Paired with a compromised account it reaches your whole server instantly.
Role hierarchy — where it breaks most often
In Discord a role only affects people below it in the role list. That single rule produces two classic failures.
The bot sits below the troublemakers. You configure moderation, and the bot can't ban a raider — because the bot's role is listed under theirs. Everything is set up correctly and still doesn't work. Quick to check: the bot's role must sit above every role it manages.
Moderators level with each other. Two people on the same role can't act on one another. Not a problem — until the day one account is compromised and the other can't stop it.
Permissions don't leave with the role
The most underestimated part. You take someone's role away and consider it handled. But some access lives separately:
- webhooks they created keep working;
- bots they invited stay, with their permissions intact;
- per-user channel overrides — if access was granted to the person rather than to a role, removing the role changes nothing;
- third-party panels and integrations often keep their own copy of who has access, and refresh it on their own schedule.
That last one applies to us too. We recently fixed exactly this on our side: our dashboard decided access from its own stored snapshot, so a role removed in Discord didn't revoke it automatically. The panel now re-checks with Discord instead of trusting its own record. If you use any external dashboard, it's worth testing how quickly it reacts when you take a role away.
The five-minute audit
Walk through this now:
- Server Settings → Roles. Who has
Administrator? If it isn't you, it's probably a mistake. - Who holds Manage Roles and Manage Webhooks? Keep those two to an absolute minimum.
- Integrations → Webhooks. Anything you don't recognise? Delete it — legitimate ones are trivial to recreate.
- Role list. Is the bot's role above the roles it manages?
- Private channels. Open channel permissions and check the members tab: anyone added individually and long forgotten?
- Bots. Is each one still needed? An unused bot with permissions is an open door.
Separately: turn on logging. It prevents nothing, but without it you won't know who did what and when — which is precisely what you need once something has happened.
How to stop doing this by hand every month
The checklist works, but it has to be repeated: roles change, people come and go. We automated it in PULSORT — with the caveat that it's useful without us too, if you run the checklist yourself.
- Role permission audit — walks every role and channel and surfaces dangerous combinations: who has needless admin, who ended up with role or webhook management, where
@everyonecan do more than it should. Each finding comes with a one-click fix. - Logging — records who granted a role, deleted a channel, banned a member. With names, timestamps, and what it looked like before.
- Verification and anti-raid — so it never gets as far as handing out permissions: mass joins and suspicious accounts are stopped at the door.
- Dashboard access grants — if a helper only needs to run one module, they don't need server permissions at all. Access is granted narrowly, and only to the panel.
Auditing your server is free: the base plan has no time limit, and the permission audit is part of PRO. Start at pulsort.gg.
In short
It isn't hackers, it's forgotten permissions. Keep permanent Administrator to yourself, and remove temporary grants the moment the job is done. Keep role and webhook management to people you trust as yourself. Remember that webhooks and invited bots outlive the role that created them. And switch logging on early — you need it before things go wrong, not after.
What is PULSORT, and why is it worth a look?
PULSORT is a Discord bot and a server control panel in one. Over 30 modules, all configured on the website by clicking — no chat commands, no config files, no reading docs for every small change. The permission audit discussed above is just one of them.
The base plan is free with no time limit, so there's nothing to commit to. Here's what else it does.
Events
Announcements with sign-ups & reminders
Giveaways
Fair giveaways with conditions
Tournaments
Brackets & registration, cross-server
Message Builder
Beautiful embeds, no code
Welcomes
Banners for newcomers
Streamers
Twitch, YouTube, Telegram
Voice rooms
Created on demand
Moderation
Anti-spam, profanity, mutes
Verification
Bot protection at the door
Logging
Action log with moderator
Tickets
Private tickets with transcripts
Role assignment
By reaction or button
Auto-reactions
The bot reacts itself
Stats
Counters in channel names
Economy
Currency, shop, leaderboards
Leveling
XP for activity & role rewards
AI Journalist
Gaming news & freebies
Birthdays
Role & bonus on the day
Starboard
Best messages by reactions
Silence Breaker
Revives a quiet chat
Word Chain
A mini-game in Discord
Mafia
Roles, nights and voting
Auto Role Style
Gradient & holographic roles
Gallery Channel
Images only, talk in threads
User Notes
Private moderation notes
Emoji
Manage from the dashboard
Bulk setup
Roles & channels in bulk
Panel access
Permissions for your team
Billing & coupons
Subscriptions & bonus days
Backups
Server-structure snapshot
Branding
The bot's name & avatar
Server metrics
Activity analytics
Permission check
Can the bot do everything
Member win-back
Brings people back