Server Protection counts destructive actions one person takes in a short time: bans, kicks, channel deletions, role deletions. When the limit you set is exceeded, it stops that person and sends an alert to the log channel. It also backs up your server's structure so you can bring back what was deleted.
Above, Kai deletes four channels and two roles within five minutes. Since the channel deletion limit is 3, protection kicks in on the fourth deletion: all of Kai's roles are removed and an alert lands in the log channel. Because automatic repair is on, the deleted channels and roles then come back from the backup and the roles are given back to their previous owners.
Protection step by step
What does it watch?
| Action | Default limit | When exceeded |
|---|---|---|
| Ban | 3 | Punishment is applied |
| Kick | 3 | Punishment is applied |
| Channel deletion | 3 | Punishment is applied |
| Role deletion | 3 | Punishment is applied |
| Channel edits (name, topic, permissions, category) | 0 (not counted) | Punishment is applied |
| Webhook creation | 3 | Punishment is applied, and webhooks the person created are deleted |
| Mass role grants | 15 | Punishment is applied, and the given roles are reverted. Roles given by other bots are not counted. |
Counting happens per person within the Time Window (5 minutes by default). Protection kicks in when the count goes over the limit: with a limit of 3, on the fourth action. Bot accounts are counted too; only Shufen Bot itself is exempt.
Instant protections
These two protections don't wait for a limit; the action is reverted immediately and the punishment you chose is applied to whoever did it. Both are on by default.
Privilege escalation protection
If Administrator, Manage Server, Manage Roles, Manage Channels, Manage Webhooks, Ban Members or Kick Members is added to a role, the permission is reverted. If a role carrying these permissions is given to a member, the role is taken back.
Unauthorized bot protection
If someone not on the safe list adds a bot to the server, the bot is kicked immediately.
Punishments
| Punishment | What happens |
|---|---|
| Remove Roles (Quarantine) | All of the person's roles are removed. If the attacker is a bot, it is kicked from the server since its role can't be removed. This is the default. |
| Kick from Server | The person is kicked from the server. |
| Ban from Server | The person is banned from the server. |
| No Punishment (Alert Only) | Nobody is touched; only an alert is sent. |
The bot's role must be at the top
If the bot's role is below the attacker's highest role, the punishment can't be applied. Move the bot's role as high as possible in the role list and give it View Audit Log, Manage Roles, Kick Members and Ban Members.
Setup
Step 1
In the dashboard, pick your server on the My Servers page and open the Server Protection card.
Step 2
Set the limits and the Time Window (Minutes), then choose the Punishment.
Step 3
Choose a Log Channel. Alerts, reverts and restore summaries go there; if you leave it empty, you won't see alerts.
Step 4
Add the admin roles you trust and the roles of bots you trust to Safe Roles (Whitelist).
Step 5
In the Backups section, turn on Take automatic backups and save. Then create your first backup with Back Up Now.
| Setting | Default | What it does |
|---|---|---|
| Max Bans / Max Kicks | 3 / 3 | Bans and kicks allowed within the window (1–100) |
| Channel Deletion Limit / Role Deletion Limit | 3 / 3 | Deletions allowed within the window (1–100) |
| Channel Edit Limit | 0 | 0 = edits are not counted (0–100) |
| Webhook Creation Limit | 3 | 0 = not counted (0–50) |
| Mass Role Grant Limit | 15 | 0 = not counted (0–500) |
| Time Window (Minutes) | 5 | The period counts are made over (1–60) |
| Punishment | Remove Roles (Quarantine) | What happens to someone who exceeds a limit or trips an instant protection |
| Log Channel | None | The channel alerts and summaries are sent to |
| Safe Roles | None | People with these roles aren't subject to the limits or the instant protections |
Before a big reorganization
If you're going to mass-delete channels and rearrange them, add your role to Safe Roles first or raise the limits temporarily. The server owner is always exempt anyway.
Backups
A backup stores categories, channels, channel permissions, roles and which member has which role. Messages, emojis, webhooks and threads are not backed up.
- If the server's structure is the same as the last backup, no new automatic backup is created.
- No automatic backup is taken within 1 hour after an attack. If the channel count has dropped by more than 20% compared to the last backup, the automatic backup is also skipped and a warning is sent to the log channel; this way a damaged state doesn't overwrite a healthy backup.
- When protection punishes someone, the last backup before the attack is marked Pre-incident and can't be deleted for 7 days.
- With Lock you can protect any backup you want. Only the server owner can delete a locked backup or remove the lock.
| Backup setting | Default | What it does |
|---|---|---|
| Take automatic backups | Off | Takes scheduled backups |
| Backup interval | Once a day | How often backups are taken (plan limits below) |
| Automatic backups to keep | 3 | The number of automatic backups kept |
| Automatic repair after an attack | Off | When protection punishes someone, the channels and roles they deleted are brought back automatically |
| Give deleted roles back to members | On | A restored role is given back to its previous owners; not to attackers or anyone who deleted, banned or kicked during the attack |
| Update other systems' settings | On | Restored channels and roles get new IDs; settings such as welcome, logs and support tickets are pointed to the new channel |
Pro
Server Protection and backups. Automatic backups at most once a day, up to 3 automatic and 1 manual backup.
Restoring
In the dashboard, in the Server Protection card settings, click Preview & Restore next to a backup in the Backups list. The preview shows channels and roles that were deleted, changed or created after the backup; you can pick which ones to bring back one by one.
| Mode | What it does |
|---|---|
| Restore deleted items | Only creates missing channels, categories and roles. The safest option. |
| Revert changes | Returns broken names, topics, permissions and categories to their state in the backup. |
| Full restore | Does both. In the dashboard you can also select channels created after the backup and have them deleted; you're asked to type the server name to confirm. |
Commands
/backup take [etiket]
Takes a manual backup right away. If your manual backup limit is full, you first need to delete an old manual backup in the dashboard.
/backup list
Shows the latest backups.
/backup restore backup tur [roller]
Shows a preview summary; if you confirm, it starts the restore. Only the server owner can start it.
The /backup commands are visible to members with Administrator by default, and replies are only visible to the person who used them. A full restore from the command doesn't delete channels created after the backup; that choice is only made in the dashboard. When the restore finishes, a summary is sent to the log channel.
Take a backup right after setup
Protection can only bring back what was deleted if you have a backup. As soon as you finish setting up, take a manual backup and lock it.
Frequently asked questions
Do messages come back too?
No. Only categories, channels, permissions, roles and role memberships are backed up.
Could my own admin team be punished by mistake?
If you add their roles to Safe Roles, they aren't subject to the limits or the instant protections. The server owner is always exempt.
I have another moderation bot. Does it count too?
Yes, actions by bot accounts are counted too. Add the role of the bot you trust to Safe Roles. Ordinary roles other bots give to members don't count toward mass role grants.
Why isn't a new automatic backup being created?
If the server's structure hasn't changed, no new backup is created. If there was an attack in the last hour, or the channel count dropped sharply, the backup is skipped on purpose.
Why can't I delete a backup?
Pre-incident backups can't be deleted for 7 days. Only the server owner can delete a locked backup.
The attacker wasn't punished
The bot's role must be higher than the attacker's role, and the bot needs View Audit Log, Manage Roles, Kick Members and Ban Members. The attacker's role must not be in Safe Roles.
No alerts arrive
Check that a Log Channel is selected, the bot can write in that channel and the system card is on.
Sign in to comment
You can sign in with your Discord account in seconds.