Permission Setup Guide¶
This guide explains how to control who can use each command category.
Prerequisites¶
- permission (or Manage Server)
How Permission Overrides Work¶
Armory Bot adds role/user permission overrides on top of Discord permissions.
Check Order¶
When someone runs a command, checks happen in this order:
- Manage Server permission — always allowed
- User override — explicit allow/deny for that member in this category
- Role override — allow/deny on the member's roles; if two roles disagree, deny wins
- Bot Manager override — an allow/deny on All commands (Bot Manager), user first, then roles
- Default — denied
The first rule that applies wins. A rule on the specific category always beats the Bot Manager rule, so you can hand someone the whole bot and still carve out one category with a deny. The full ladder is in Permission System.
Command Categories¶
Permissions are set by category, not by individual command.
The slash command parameter is named command_group, but in this guide we refer to it as a command category.
| Category Key | Commands Covered |
|---|---|
shop |
/shop-admin |
economy |
/economy-admin |
moderation |
/mod, /cases |
admin |
/server, /permissions list, /permissions check, /role create, /role edit, /role delete, /setup |
leveling |
/levels admin XP commands |
welcome |
/welcome |
timers |
/timer-admin, /event-admin, and /timer templates (public command, gates its own contents) |
roles |
/rolemenu, /autorole, /rolelink, and /role add, remove, massadd, massremove |
operations |
/bounty create, cancel, release, history, setforum; /operations settings, history, retract; /campaign setprompt; /work config |
tags |
every /trigger command, plus /tag create, /tag export, /tag import_tags |
polls |
/poll create, /poll end |
announcements |
/announce |
suggestions |
/suggestion approve, deny, consider, implemented |
logging |
no commands; opens the Logging Dashboard page |
voice |
no commands; opens the Voice Channels Dashboard page |
A grant also opens its category's Dashboard pages, so staff can run those pages without Manage Server. See Dashboard Access for which pages each category opens. /deploy and the /campaign launch and wager commands use the role lists on the Dashboard's Operations page instead (see Operations Roles).
Grant Access¶
Grant to a Role¶
Name either a user or role(s) in one command, not both. To grant to several roles at once use the roles option (mentions, IDs or names).
Grant to a User¶
View Current Overrides¶
Deny Access¶
A deny blocks a category even when another role would allow it:
/permissions deny command_group:economy role:@Suspended reason:"Under review"
/permissions deny command_group:moderation user:@Trainee
Granting over a deny replaces it (and the reply says so), and the other way round.
Revoke Access¶
Revoking removes the stored rule, allow or deny:
/permissions revoke command_group:economy role:@Treasurer reason:"No longer needed"
/permissions revoke command_group:moderation user:@TrustedHelper
Name either a user or role(s) in one command, not both. To pass several roles at once use the roles option (mentions, IDs or names).
Example Setup¶
# Moderators
/permissions grant command_group:moderation role:@Moderator
# Economy team
/permissions grant command_group:economy role:@Treasurer
# Operations team
/permissions grant command_group:operations role:@EventTeam
# Role team
/permissions grant command_group:roles role:@RoleTeam
Update Timing¶
Permission checks are actively invalidated after writes, so changes are typically visible immediately. If you are troubleshooting a stale result across multiple instances, wait up to a few minutes for all caches to settle.
Operations Roles¶
Operations launch/campaign/wager roles are configured separately from /permissions, in the Access Control section of the Dashboard's Operations page. See Bounties & Campaigns.
Troubleshooting¶
| Problem | Solution |
|---|---|
| "Permission denied" for an admin | Confirm the user has Manage Server and the bot role is high enough |
| Override not taking effect | Wait a few minutes, then run the command again |
| Can't grant to a category | Pick a category from the list; unknown categories are refused |
| Staff can't see a page on the Dashboard | Check their grant has Dashboard access ticked, and that the page is not one kept for Manage Server (see Dashboard Access) |