Skip to content

Permission System

Armory Bot provides a flexible permission override system so you can control who can use administrative commands.

Overview

The permission system uses command categories to organize related commands. You can grant or deny access to a whole category for specific users or roles.

Permission Check Order

The first rule that applies wins:

  1. Manage Server permission - Universal bypass (server admins always have access, and nothing below can take it away)
  2. User override - an ALLOW or DENY set for that exact member in this category
  3. Role overrides - ALLOW/DENY rules on the member's roles in this category. If two roles disagree, DENY wins
  4. Bot Manager user override - an ALLOW/DENY set for the member on All commands (Bot Manager)
  5. Bot Manager role overrides - the same, on the member's roles
  6. Default Deny - if nothing applies, access is denied

A specific rule always beats the Bot Manager rule: a moderation DENY on a role still applies to a member whose Bot Manager role would otherwise let them in. That makes "everything except this category" easy to build.

Command Categories

Category Commands it governs
admin /server, /permissions list and /permissions check, /role create, /role edit, /role delete, /setup
economy /economy-admin
shop /shop-admin
operations /bounty create, cancel, release, history and setforum; the /operations settings, history and retract; /campaign setprompt; /work config (see the note below for /deploy and /campaign)
leveling /levels
moderation /mod, /cases
roles /role add, /role remove, /role massadd, /role massremove, /autorole, /rolelink, /rolemenu
tags every /trigger command, plus /tag create, /tag export and /tag import_tags (other /tag commands follow tag ownership and moderator rules, see Custom Commands)
timers /timer-admin, /event-admin, /timer templates
suggestions /suggestion approve, deny, consider, implemented
welcome /welcome
announcements /announce
polls /poll create, /poll end
logging no commands; opens the Logging Dashboard page
voice no commands; opens the Voice Channels Dashboard page

There is also one special scope, All commands (Bot Manager), written * when you type it: a single override that covers every category above. It is meant for senior staff who should reach the whole bot without a grant per category.

Economy Admin Groups

/economy-admin and /shop-admin require Manage Server and are hidden from non-managers in Discord's slash-command picker. /economy (banking) and /shop (items) are visible to all members.

Operations roles

Deployments and Campaigns (/deploy, and launching, starting, assigning and wagering on /campaign) are gated by the role lists in the Dashboard's Operations page (Access Control), not by the operations category. See Bounties & Campaigns.

Dashboard-only categories

logging and voice govern no slash commands. They exist so you can hand someone the Logging or Voice Channels page (see Dashboard Access). /automod follows Discord's Manage Server permission.

Managing Permissions

/permissions grant, /permissions deny and /permissions revoke need Manage Server itself. They cannot be delegated, because that would let a member grant themselves more access. /permissions list and /permissions check are read-only and can be delegated through the admin category.

Grant Permission

Give a user or role access to a command category:

/permissions grant command_group:<category> [user] [role] [roles] [reason]

Name one user, or one or more roles: the role picker for a single role, or roles for several at once (mention them, paste IDs, or type names, separated by spaces or commas). You cannot combine a user and roles in one command, and @everyone is never accepted as a target.

Examples:

/permissions grant command_group:economy role:@TrustedModerator reason:"Can manage economy"
/permissions grant command_group:shop role:@ShopKeeper reason:"Manages the server shop"
/permissions grant command_group:moderation roles:@ModTeam @HeadMod

If the target had a DENY for that category, the grant replaces it, and the reply says so ("Replaced a DENY", with who set it).

Deny Permission

Block a category for a user or roles, even when another role would allow it:

/permissions deny command_group:<category> [user] [role] [roles] [reason]

Targets work exactly as they do for grant. A DENY on a member beats every role ALLOW, and a DENY on a role beats an ALLOW on another role, so it is the tool for carve-outs.

Examples:

/permissions deny command_group:moderation role:@Suspended reason:"Under review"
/permissions deny command_group:economy user:@Trainee

Replacing an ALLOW with a DENY is reported the same way ("Replaced an ALLOW").

Revoke Permission

Remove a stored rule, ALLOW or DENY, so the target falls back to whatever else applies:

/permissions revoke command_group:<category> [user] [role] [roles] [reason]

The reply lists what was removed and by whom it had been set, and names any target that had no override.

Example:

/permissions revoke command_group:economy role:@FormerMod reason:"No longer a moderator"

List Permissions

View the active permission overrides (each shown as Allowed or Denied):

/permissions list [command_group] [user] [role]

Examples:

/permissions list
/permissions list command_group:economy
/permissions list user:@Moderator

Runtime Behavior Notes

  • User/role target validation is strict; invalid Discord IDs are rejected.
  • Changes take effect immediately for commands: the permission cache is cleared on every write. The Dashboard picks them up within 30 seconds.

Check Permissions

Debug why a user has or doesn't have access:

/permissions check command_group:<category> user:<user>

Example:

/permissions check command_group:economy user:@User

This shows:

  • Whether the member has Manage Server
  • The user-specific override
  • The role-based overrides
  • The final decision and which rule made it

The Permissions Dashboard Page

Everything above is also on the Permissions page of the Dashboard (open it with /dashboard). It has three tabs:

Global - server-wide access rules:

  • Allowed Bot Channels - if set, the bot only responds in these channels
  • Ignored Channels - the bot ignores commands in these channels
  • Moderator Roles, Blacklisted Roles (blocked from using the bot), Ignore Role Overwrites and Ignore Channel Overwrites
  • Restrict Entire Bot to Mods Only and Allow Elevated Role Assignment

To let a role run the whole bot, grant it All commands (Bot Manager) on the Overrides tab.

Commands - pick any slash command and tune it: required roles, blacklisted roles, bypass roles, allowed and blacklisted channels, and behavior switches (Mod Only, Restricted, Bypass Discord Perms, Ephemeral Reply, Delete Invocation, cooldown and per-user cooldown). An Effective Access summary shows what the settings add up to.

Overrides - the same ALLOW/DENY rules as /permissions, as a list you can edit. Pick a command category (or All commands (Bot Manager)), pick one or more roles, or a single user ID, choose Allow Access or leave it off to deny, and save. Picking several roles creates one rule per role. A grant also carries Dashboard access, ticked by default; untick it to keep the grant to slash commands, and the list marks it Discord only (see Dashboard Access). If Discord refuses a change, a banner stays on screen naming the command and the reason, so a grant that did not apply is never silent.

Admins and Server Owners always have implicit full permission, whatever these pages say.

Dashboard Access

A grant covers its category's slash commands and the category's pages on the Dashboard, unless you untick Dashboard access when you make it. That way you can hand a team the pages they run without giving them Manage Server.

Category Dashboard pages it opens
economy Economy, Work
shop Economy
operations Operations
leveling Leveling
welcome Welcome
timers Timers
roles Role Menus
suggestions Suggestions
tags Tags & Triggers
moderation Mod Cases
logging Logging
voice Voice Channels
admin or All commands (Bot Manager) every page above

announcements and polls open no pages.

Some things stay with Manage Server, whatever the grants say:

  • The Permissions, Premium, Moderation, Automod and Activity Log pages.
  • Server-wide settings: the module On / Off switches on the overview, the Server Profile and the bot's name.
  • Turning any feature on or off, including the switches inside a page such as Enable Leveling System, Enable XP Decay or Enable Goodbye Messages. A member using a grant sees these switches locked; their other changes on the page save as usual.

How it behaves:

  • A member with Dashboard access sees the Server in their server list and only their pages in the sidebar. Opening any other page sends them back to the overview.
  • A DENY counts on both sides: a role denied tags cannot open Tags & Triggers, even if another role grants it or they hold All commands (Bot Manager).
  • Grants made with /permissions grant include Dashboard access. To make one Discord-only, untick Dashboard access on the Overrides tab.

Best Practices

Recommended Setup

  1. Create dedicated roles for different admin levels (Moderator, Admin, Specialist)
  2. Grant command categories to roles rather than individual users
  3. Use user overrides only for exceptions
  4. Always provide a reason when granting, denying or revoking permissions
  5. Regularly audit permissions with /permissions list

Example: Setting Up Moderators

# Create a Moderator role in Discord

# Grant moderation permissions
/permissions grant command_group:moderation role:@Moderator reason:"Mod team permissions"

# Let them manage tags and triggers too
/permissions grant command_group:tags role:@Moderator reason:"Can manage tags"

# ...but never the economy
/permissions deny command_group:economy role:@Moderator reason:"Mods do not touch balances"

Audit Logging

All permission changes are logged to the audit system (permission.grant, permission.deny, permission.revoke), including:

  • Who changed the permission
  • What it was before and what it is now
  • The reason provided
  • Target user or role

Read them on the Dashboard's Activity Log page (/dashboard > Modules > Recent Activity > View all).


Important

Users with Manage Server permission always have full access to all commands, regardless of permission overrides. This cannot be revoked.

Default Behavior

By default, all administrative commands require Manage Server permission or an explicit permission grant. This is a secure "deny by default" model.