SECURITY & PERMISSIONS

Designed to inspect first and earn every write.

Oracle separates authentication, live Discord inspection, planning, approval, and execution. It requests no Administrator permission and keeps unsupported or unavailable evidence visible.

No AdministratorEncrypted Discord tokensExact operation approval

THE CONTROL MODEL

Protection comes from boundaries, not a safety slogan

01 · IDENTITY

Authenticated owner context

Oracle uses the configured Identity tenant for product sessions and Discord OAuth for linked account and guild access. Protected routes verify the tenant-aware access token.

02 · AUDIT

Read-only before planning

An Improve audit reads supported configuration and creates a private report. Audit generation does not mutate Discord or pretend unavailable sections were assessed.

03 · APPLY

Selected findings and operations

Only supported findings can become a plan. The owner reviews and individually approves exact operations before Oracle performs any Discord write.

DISCORD INSTALL DIALOG

The exact bot permissions—and why Oracle requests them

Discord shows write-capable permissions because the same shared bot can build a new server and execute narrow approved fixes after the read-only audit. Installing the bot grants those capabilities to its role; it does not grant permission for Oracle to perform unreviewed operations.

CONFIGURATION

Manage Server, Channels, and Roles

Manage Server supports guild safety and Oracle AutoMod operations. Manage Channels and Roles support the explicit new-server build. In Improve mode, role and channel findings remain advisory and are not mass-edited.

INVENTORY

Manage Webhooks and View Channels

Discord requires Manage Webhooks even to list guild webhooks. Oracle strips webhook tokens and executable URLs before returning or storing the credential-free inventory. View Channels supports configuration and access review.

NEW-SERVER BASELINE

Send/Manage Messages, Read History, and Timeout Members

These permissions let the approved new-server plan create starter content and grant the reviewed moderator role its message-management and timeout abilities. During starter-message execution—including the first attempt and any retry or recovery—Oracle may inspect up to 50 recent messages in the approved destination channel only to find the exact marker authored by its own bot; it does not persist unrelated content. Improve audits do not read conversations or inventory timed-out members.

Never requested: Administrator. Keep Oracle’s bot role only as high as required for the resources in an approved plan.

DATA & EXECUTION

What the current standalone product does

STORAGE

Encrypted linked-Discord tokens

Discord OAuth tokens are encrypted before PostgreSQL storage with a deployment-specific encryption key. Bot credentials and encryption keys belong in Railway environment variables, never public browser code.

PRE-WRITE EVIDENCE

Snapshot, live recheck, and checkpoints

Immediately before an approved write, Oracle rechecks authority and live state, saves a pre-change evidence snapshot, and checkpoints operations for retry and verification.

DISCORD LIMITS

Rate-limit aware requests

Discord 429 responses are translated into visible wait states and retries. Persisted rate-limit gates help avoid repeatedly sending an operation before Discord’s retry window.

REPORT PRIVACY

Private authenticated reports

Saved reports, histories, and exports are reached through protected application routes. Public sample content is fictional and contains no customer guild data.

CURRENT LIMITATIONS

Important boundaries before you authorize Oracle

NO SURVEILLANCE

No behavioral monitoring

Improve audits and scheduled checks do not read message content or inventory members. The narrow new-server starter-message reconciliation described above is not used to score behavior. Oracle does not claim live spam, raid, scam, toxicity, or engagement detection.

NO AUTOMATIC RESTORE

The snapshot is evidence, not one-click rollback

The product records the pre-change baseline but does not currently offer automatic full-server restoration. Exports and snapshots should not be mistaken for a complete backup product.

NARROW WRITES

Roles and channels stay advisory

Improve mode currently applies only selected guild-safety settings and Oracle-owned AutoMod operations. It does not mass-edit roles or channels.

REPORT A PROBLEM

Security reports should reach the operator privately

Deployment notice: a security contact has not been configured. The operator must set SITE_SUPPORT_EMAIL before broad promotion so researchers and customers have a private reporting channel.

Responsible reporting

Do not access another user’s data, disrupt Discord or Oracle services, or perform destructive testing. Acknowledgement timelines and bounty payments are not promised during beta.

FREE DURING BETA

Audit the server without granting a blank check.

Review Oracle’s permissions and product boundaries, then connect through Discord’s official authorization flow.

Run the free audit