Security
Always-on core protections and careful recovery.
Before you start
Dashboard changes are currently restricted to the configured Yume owner. Sign in with Discord and choose Yume. Public documentation is available to everyone.
Recovery controls remain restricted to the existing authorized owner workflow.
Set it up
- Read the recovery limits: Open Policy & permissions. Deleted message history and deleted role IDs cannot be restored.
- Check your backup: Open Latest backup & recovery access and inspect its age, channels and role definitions. A missing backup prevents channel restoration.
- Inspect incidents: Open Security incidents and review the affected resources. Only use a recovery action after checking its exact scope.
Check it works
Confirm backup information can load. Do not delete channels or trigger mass bans to test security in your live community.
How it works
Security is a core module and does not offer an off switch. Its implemented behavior includes server snapshots, destructive-action detection and owner recovery controls.
A snapshot is not a promise that every Discord action can be undone. Review what a recovery operation changes before using it.
The public website and documentation never expose private snapshots, security logs or recovery credentials.
Inspect before recovering
Open an incident and review the backup, affected channels, roles and bans. Restoration preserves backed-up access rules and stops when a required role or parent is missing. Discord cannot restore a deleted role ID. Unknown or uncertain outcomes require manual inspection; saved progress prevents automatic duplicate effects.
Staff actions, privacy and refresh
Staff actions require Discord sign-in and current authorized server access. Recovery sign-in supports settings only. Review the exact confirmation before submitting; changes and partial deliveries have a request receipt.
An uncertain outcome is not a confirmed failure. Check the receipt, record and Discord before acknowledging it. Acknowledgment does not retry an effect or remove the server’s duplicate-action protection. Safe notes and other records remain usable; unresolved effects require owner investigation.
Active workspace pages refresh every 30 seconds and Overview every minute while visible. Refresh pauses for drafts or focused controls. Manual refresh preserves edits; a changed staff record requires explicit review before keeping its draft. Private drafts remain in this tab and are not saved in browser storage.
Use Save after editing. If a change is marked as requiring a restart, it is stored but will only apply when Vault next starts. Refresh after the restart to check the pending indicator.
If something is not working
Check that the feature is enabled, that the selected channel or role still exists, and that Vault has the required Discord permissions. A higher role cannot be assigned or moderated by a bot below it.
If the dashboard cannot load or save, keep your edits on the page, check Status, then try again. An expired session requires signing in again. Do not repeatedly submit an action whose result is uncertain.