Server Protection counts destructive actions one person takes in a short time: bans, kicks, channel deletions, role deletions. When the limit you set is exceeded, it stops that person and sends an alert to the log channel. It also backs up your server's structure so you can bring back what was deleted.

Above, Kai deletes four channels and two roles within five minutes. Since the channel deletion limit is 3, protection kicks in on the fourth deletion: all of Kai's roles are removed and an alert lands in the log channel. Because automatic repair is on, the deleted channels and roles then come back from the backup and the roles are given back to their previous owners.

Protection step by step

What does it watch?

ActionDefault limitWhen exceeded
Ban3Punishment is applied
Kick3Punishment is applied
Channel deletion3Punishment is applied
Role deletion3Punishment is applied
Channel edits (name, topic, permissions, category)0 (not counted)Punishment is applied
Webhook creation3Punishment is applied, and webhooks the person created are deleted
Mass role grants15Punishment is applied, and the given roles are reverted. Roles given by other bots are not counted.

Counting happens per person within the Time Window (5 minutes by default). Protection kicks in when the count goes over the limit: with a limit of 3, on the fourth action. Bot accounts are counted too; only Shufen Bot itself is exempt.

Instant protections

These two protections don't wait for a limit; the action is reverted immediately and the punishment you chose is applied to whoever did it. Both are on by default.

Privilege escalation protection

If Administrator, Manage Server, Manage Roles, Manage Channels, Manage Webhooks, Ban Members or Kick Members is added to a role, the permission is reverted. If a role carrying these permissions is given to a member, the role is taken back.

Unauthorized bot protection

If someone not on the safe list adds a bot to the server, the bot is kicked immediately.

Punishments

PunishmentWhat happens
Remove Roles (Quarantine)All of the person's roles are removed. If the attacker is a bot, it is kicked from the server since its role can't be removed. This is the default.
Kick from ServerThe person is kicked from the server.
Ban from ServerThe person is banned from the server.
No Punishment (Alert Only)Nobody is touched; only an alert is sent.

The bot's role must be at the top

If the bot's role is below the attacker's highest role, the punishment can't be applied. Move the bot's role as high as possible in the role list and give it View Audit Log, Manage Roles, Kick Members and Ban Members.

Setup

Step 1

In the dashboard, pick your server on the My Servers page and open the Server Protection card.

Step 2

Set the limits and the Time Window (Minutes), then choose the Punishment.

Step 3

Choose a Log Channel. Alerts, reverts and restore summaries go there; if you leave it empty, you won't see alerts.

Step 4

Add the admin roles you trust and the roles of bots you trust to Safe Roles (Whitelist).

Step 5

In the Backups section, turn on Take automatic backups and save. Then create your first backup with Back Up Now.

SettingDefaultWhat it does
Max Bans / Max Kicks3 / 3Bans and kicks allowed within the window (1–100)
Channel Deletion Limit / Role Deletion Limit3 / 3Deletions allowed within the window (1–100)
Channel Edit Limit00 = edits are not counted (0–100)
Webhook Creation Limit30 = not counted (0–50)
Mass Role Grant Limit150 = not counted (0–500)
Time Window (Minutes)5The period counts are made over (1–60)
PunishmentRemove Roles (Quarantine)What happens to someone who exceeds a limit or trips an instant protection
Log ChannelNoneThe channel alerts and summaries are sent to
Safe RolesNonePeople with these roles aren't subject to the limits or the instant protections

Before a big reorganization

If you're going to mass-delete channels and rearrange them, add your role to Safe Roles first or raise the limits temporarily. The server owner is always exempt anyway.

Backups

A backup stores categories, channels, channel permissions, roles and which member has which role. Messages, emojis, webhooks and threads are not backed up.

  • If the server's structure is the same as the last backup, no new automatic backup is created.
  • No automatic backup is taken within 1 hour after an attack. If the channel count has dropped by more than 20% compared to the last backup, the automatic backup is also skipped and a warning is sent to the log channel; this way a damaged state doesn't overwrite a healthy backup.
  • When protection punishes someone, the last backup before the attack is marked Pre-incident and can't be deleted for 7 days.
  • With Lock you can protect any backup you want. Only the server owner can delete a locked backup or remove the lock.
Backup settingDefaultWhat it does
Take automatic backupsOffTakes scheduled backups
Backup intervalOnce a dayHow often backups are taken (plan limits below)
Automatic backups to keep3The number of automatic backups kept
Automatic repair after an attackOffWhen protection punishes someone, the channels and roles they deleted are brought back automatically
Give deleted roles back to membersOnA restored role is given back to its previous owners; not to attackers or anyone who deleted, banned or kicked during the attack
Update other systems' settingsOnRestored channels and roles get new IDs; settings such as welcome, logs and support tickets are pointed to the new channel
PRO

Pro

Server Protection and backups. Automatic backups at most once a day, up to 3 automatic and 1 manual backup.

MAX

Max

Automatic backups at most every 6 hours, up to 10 automatic and 5 manual backups.

See plans

Restoring

In the dashboard, in the Server Protection card settings, click Preview & Restore next to a backup in the Backups list. The preview shows channels and roles that were deleted, changed or created after the backup; you can pick which ones to bring back one by one.

ModeWhat it does
Restore deleted itemsOnly creates missing channels, categories and roles. The safest option.
Revert changesReturns broken names, topics, permissions and categories to their state in the backup.
Full restoreDoes both. In the dashboard you can also select channels created after the backup and have them deleted; you're asked to type the server name to confirm.

Commands

/backup take [etiket]

Takes a manual backup right away. If your manual backup limit is full, you first need to delete an old manual backup in the dashboard.

/backup list

Shows the latest backups.

/backup restore backup tur [roller]

Shows a preview summary; if you confirm, it starts the restore. Only the server owner can start it.

The /backup commands are visible to members with Administrator by default, and replies are only visible to the person who used them. A full restore from the command doesn't delete channels created after the backup; that choice is only made in the dashboard. When the restore finishes, a summary is sent to the log channel.

Take a backup right after setup

Protection can only bring back what was deleted if you have a backup. As soon as you finish setting up, take a manual backup and lock it.

Frequently asked questions

Do messages come back too?

No. Only categories, channels, permissions, roles and role memberships are backed up.

Could my own admin team be punished by mistake?

If you add their roles to Safe Roles, they aren't subject to the limits or the instant protections. The server owner is always exempt.

I have another moderation bot. Does it count too?

Yes, actions by bot accounts are counted too. Add the role of the bot you trust to Safe Roles. Ordinary roles other bots give to members don't count toward mass role grants.

Why isn't a new automatic backup being created?

If the server's structure hasn't changed, no new backup is created. If there was an attack in the last hour, or the channel count dropped sharply, the backup is skipped on purpose.

Why can't I delete a backup?

Pre-incident backups can't be deleted for 7 days. Only the server owner can delete a locked backup.

The attacker wasn't punished

The bot's role must be higher than the attacker's role, and the bot needs View Audit Log, Manage Roles, Kick Members and Ban Members. The attacker's role must not be in Safe Roles.

No alerts arrive

Check that a Log Channel is selected, the bot can write in that channel and the system card is on.

Protect your server

Set your limits, choose a log channel and take your first backup.

Go to dashboard