Find risky Discord permissions before they become incidents
Shero reviews high-impact roles, exposed channels, server safeguards, and bot capability gaps inside Discord. Run one private command and get a prioritized permission audit without changing your server.
Free server health preview
- Roles checked
- 24
- High-impact roles
- 5
- Administrator roles
- 2
- Open @everyone channels
- 3
No roles, channels, or settings were changed.
Configuration health, not uptime
A focused Discord permission and safeguard audit
Shero turns role flags and server settings into a short list of findings a server owner can act on. It does not pretend to be a professional security assessment or an infrastructure monitor.
Role risk
High-impact permissions by role
See which roles hold Administrator, Manage Server, Manage Roles, Manage Channels, Manage Webhooks, moderation powers, or Mention Everyone.
Channel exposure
Channels where everyone can post
Count text, announcement, forum, and media channels where the default @everyone role can both view and send messages.
Server safeguards
Verification, moderator 2FA, and content filtering
Review the server verification level, two-factor requirement for moderation actions, and explicit-content filter in one private result.
Bot readiness
Missing Shero capability permissions
Identify unavailable Shero capabilities so you can grant only the permissions for features you intend to use.
From install to findings
Audit a Discord server in three steps
Add Shero without Administrator
Install the verified Discord app in a server you manage. Shero requests individual permissions for its active features.
Run /server-health privately
A member with Manage Server runs the command. The ephemeral snapshot stays between that operator and Shero.
Review the priority actions
Start with Administrator roles, broadly postable channels, weak safeguards, and missing bot capabilities.
Choose the right evidence
Discord permission snapshot, audit log, or daily monitoring?
Use a snapshot to see risky permissions now, Discord's Audit Log to investigate a recent administrative change, and Permission Watch to learn when a monitored current-state risk is newly introduced. These tools answer different questions and work best together.
| Method | Best for | Timing | What it shows | Important limit | Access |
|---|---|---|---|---|---|
| Shero /server-health | A private current-state permission check | On demand | Selected risky role permissions, broadly postable channels, safeguards, and missing Shero capabilities. | It is a point-in-time snapshot. It does not show who made a past change or monitor future changes. | Free preview |
| Discord Audit Log | Investigating who changed something | On demand | Discord's recorded administrative actions, including the action, time, and available actor or target details. | Discord retains audit-log entries for 45 days, and the log is not a complete current-state permission audit. | Native Discord feature |
| Shero Permission Watch | Finding newly introduced permission risk | One comparison per day | New monitored role, channel, safeguard, and Shero capability risks plus one weekly private digest. | It is not real-time, keeps one current baseline rather than a daily history, and never changes permissions automatically. | $4.99 Supporter |
See value before paying
Start with a useful preview. Upgrade for the complete breakdown.
Free preview
$0
Run the audit and see the highest-priority findings before you decide whether the complete role breakdown is useful.
- ✓ Role and channel counts
- ✓ Top three risky role findings
- ✓ Administrator-role count
- ✓ Channels where @everyone can post
- ✓ Verification, moderator 2FA, and content-filter status
- ✓ Prioritized remediation suggestions
Shero Supporter
$4.99/month
Purchase through Discord's native store and cover the server selected during checkout. The 1M shared-credit pool resets each billing period, and unused shared credits expire at period end. Purchased personal credits remain separate and do not expire.
- ✓ Everything in the free preview
- ✓ Up to 15 highest-risk roles in Discord
- ✓ Complete downloadable role breakdown
- ✓ Daily read-only Permission Watch comparisons
- ✓ Alerts only when a new high-impact permission risk appears
- ✓ Weekly digest in one selected private staff text channel
- ✓ 1M shared AI credits per subscribed server each billing period
- ✓ Unused shared credits expire at period end
- ✓ No sponsored placements in the covered server
Supporter Permission Watch
Know when a new permission risk appears
A server manager can explicitly opt in with an active Discord Supporter entitlement. Shero compares the current configuration once per day and reports only newly introduced monitored risks.
Daily comparison
Compare one current snapshot each day
Shero checks monitored role permissions, channels where @everyone can post, server safeguards, and its own capability gaps against the last successful snapshot.
New-risk alerts
Alert only when risk increases
The selected channel receives an alert for a new high-impact role permission, a newly @everyone-postable channel, a weakened safeguard, or a new Shero capability gap.
Private weekly digest
Keep the operating summary with staff
Shero posts one weekly digest to the private staff text channel selected during setup. Permission Watch never sends these reports by DM.
/permission-watch enable channel:#staff-security
Setup accepts only a standard private text channel where @everyone is denied View Channel and both the configuring manager and Shero can access the channel. Shero stores one current snapshot only. Use /permission-watch disable to delete the saved baseline and schedule; removing Shero from the server deletes it too. Permission Watch sends no DMs and makes no automatic changes.
Read the Permission Watch command guide →Safe by scope
Read-only findings with explicit boundaries
The health command reads the current Discord configuration and reports what it finds. It does not automatically remove roles, close channels, or rewrite permissions.
Private response
The command result is ephemeral and visible only to the operator who requested it.
No automatic changes
The snapshot does not edit roles, channels, safeguards, or bot permissions.
No Administrator request
Shero uses an audited set of individual Discord permissions for its active features.
Actionable limits
The result states that it is a focused snapshot, not a replacement for a professional security audit.
FAQ
Discord permission audit questions
Can a Discord bot audit role permissions?
Yes. Shero reads the server's current role, channel, and safeguard configuration, then returns a private risk summary. The audit is read-only and does not change roles, channels, or settings.
What risky Discord permissions does Shero check?
Shero checks selected high-impact permissions including Administrator, Manage Server, Manage Roles, Manage Channels, Manage Webhooks, Ban Members, Kick Members, Timeout Members, and Mention Everyone.
Does Shero need Administrator permission?
No. Shero does not request Discord's Administrator permission. Discord role hierarchy and the individual permissions granted to Shero still determine which features can operate.
Who can run the Discord permission audit?
The /server-health command is available to the server owner and members with Manage Server permission. Results are delivered privately through an ephemeral Discord response.
What is included in the free server-health preview?
The free preview includes server totals, the top three risky role findings, Administrator-role and open-channel counts, safeguard status, Shero capability gaps, and priority actions.
What does Shero Supporter add to the audit?
Shero Supporter adds the 15 highest-risk roles in Discord plus a downloadable complete role breakdown. It also unlocks daily read-only Permission Watch with new-risk alerts and a weekly private digest, adds 1 million shared AI credits to the subscribed server for each billing period, and removes sponsored placements. Unused shared credits expire at period end; purchased personal credits do not expire.
How does Shero Permission Watch work?
A server manager with an active Discord Supporter entitlement explicitly enables Permission Watch and selects a standard private staff text channel. Shero saves the current permission baseline, compares it once per day, alerts only when a monitored high-impact risk is newly introduced, and posts one weekly digest. It never changes permissions automatically.
What does Permission Watch store?
Shero stores one current snapshot, not a daily snapshot history. It includes role IDs with selected high-impact permission labels, IDs of channels where @everyone can post, aggregate safeguard values, Shero capability gaps, the selected delivery channel, schedule state, and bounded weekly counts. Role names are not saved. Disabling Permission Watch or removing Shero from the server deletes the saved baseline and schedule.
Does Permission Watch DM server members?
No. Permission Watch is guild-only and sends setup confirmation, new-risk alerts, and weekly digests only to the private staff text channel selected by a server manager. It does not send direct messages or make automatic server changes.
Is this a Discord uptime monitor?
No. Shero checks Discord configuration health: permissions, roles, channel exposure, safeguards, and bot capability gaps. It does not monitor infrastructure uptime or network availability.
Need help interpreting a finding? Use the Shero AI command guide to ask about one role or permission family at a time.
Your first audit is free
Find the permissions worth reviewing first.
Add Shero, run /server-health, and get a private read-only preview before choosing the $4.99 Supporter plan.