RE:NODE

Operations11 min read

Discord for a game server: channels and roles

Set up a Discord for your game server: a channel layout, roles and permission overrides, verification against raids, bots, and linking roles to the game.

0 readers

A game server's Discord needs fewer channels than you think, a role list built around permissions rather than prestige, verification set high enough to stop throwaway accounts, and one or two integrations that tie Discord roles to what people can do in the game. In practice: five to eight channels in three categories, roles for members, verified players, staff and bots, the verification level at Medium or High, AutoMod switched on, and moderator two-factor required. Then link it to the game - a whitelist that checks a Discord role, a chat or status bridge, a webhook for restarts - so that Discord is the front door rather than a separate place people forget to check.

The broader question of why a Discord matters for retention is covered in growing a game server community. This post is the build: what to click, what to grant, and what to leave off.

A channel layout that does not look abandoned#

Thirty empty channels read as a dead server. Start with categories that match what people actually do, and give each channel a clear rule about who may post there. Discord permissions are set per category and inherited by the channels inside it unless you break the sync, so organising by category also organises your permissions.

CategoryChannelWho postsPurpose
Infostart-hereStaff onlyOne-sentence pitch, address, rules, how to get roles
InfoannouncementsStaff onlyRestarts, events, updates. Low volume
Infoserver-statusA bot or webhookOnline, offline, player count
CommunitychatMembersEverything
CommunityscreenshotsMembersThe channel that makes a server feel alive
CommunitysupportMembersProblems, with a pinned FAQ
Staffstaff-chatStaffDecisions, disagreements
Staffmod-logBotsBans, kicks, deleted messages

Add channels when one is genuinely too busy, not in advance. A game-specific channel for each server only makes sense once you run more than one. Voice channels follow the same rule: one general voice channel and one for staff, plus more when people are actually in them.

start-here does the most work and gets the least attention. Put the address in a format people can copy, the version, whether mods are needed, and the three rules that matter most, then link to the full rules. Lock it so only staff can post, and keep it short enough to read without scrolling.

Roles and the permission model#

Discord permissions are evaluated in a fixed order, and most broken setups come from not knowing it:

  1. The server-wide permissions of @everyone.
  2. Added to by the server-wide permissions of every role the member has.
  3. Overridden by category or channel overrides for @everyone, then for each role (allows win over denies when two roles disagree), then for the individual member.
  4. Administrator skips all of it. A role with Administrator can see and do everything, including in channels it is denied.

The practical consequence: start from @everyone with almost nothing, grant through roles, and use channel overrides to deny or allow per channel. Do not give anyone Administrator except the owner and, if you must, one co-owner. Moderators get the specific permissions they need.

A role plan that scales
Owner            Administrator (one or two people)Admin            Manage Roles, Manage Channels, Ban, Kick, Timeout, View Audit LogModerator        Kick, Timeout, Manage Messages, View Audit LogSupport          Manage Messages in support only (channel override)Bots             only what each bot documents, nothing moreVerified Player  Send Messages, Connect to voice, Attach FilesMember           Read start-here and announcements only@everyone        View start-here only

Role order matters too. A member can only manage roles below their own highest role, and a bot can only assign roles below its own. When a reaction-role or verification bot says it lacks permission, the cause is almost always that its role sits below the role it is trying to hand out. Drag the bot's role above the roles it manages, and keep staff roles above the bot.

Colour and hoisting (showing a role separately in the member list) are cosmetic. Hoist staff so people can find someone to ask; leave the rest unhoisted or the member list becomes a wall of rank names.

Verification: keeping throwaway accounts out#

Raids, spam waves and ban evasion all rely on accounts that are seconds old. Discord's built-in verification level is the cheapest defence, set under Server Settings, Safety Setup.

LevelRequirement before a new member can talk
NoneNothing
LowA verified email on the Discord account
MediumLow, plus the account registered for more than 5 minutes
HighMedium, plus a member of this server for more than 10 minutes
HighestA verified phone number on the account

Medium is the right default for most game servers. High adds a ten-minute wait that stops most hit-and-run spam at the cost of mildly annoying genuine joiners. Highest is effective and also excludes a real share of legitimate players who will not attach a phone number to Discord; switch to it during an active raid, then back.

On top of the level:

  • Rules screening (available once the server is set up as a Community server) makes new members accept the rules before they can talk. It is not a security measure - anyone can click accept - but it removes "I did not know".
  • AutoMod has rules for spam content, mention spam, commonly flagged words and your own keyword lists, with actions to block the message, alert a channel or time the member out. Turn on mention spam and spam content on day one. Add a keyword rule for your server's address being posted in other contexts if impersonation becomes a problem.
  • Require two-factor authentication for moderator actions. With this on, anyone with moderation permissions must have 2FA on their Discord account to use them. A compromised moderator account is the usual way a server gets wiped, so it is worth the friction. The owner needs 2FA on their own account before the option can be enabled.
  • Slow mode on busy channels, a few seconds, stops one person flooding without stopping conversation.

Third-party verification bots that make members solve a captcha or link an account add another layer and another dependency. They are worth it for large public servers that get raided; for a whitelisted community of fifty they are mostly friction.

Onboarding: letting people choose what they see#

Community servers can use Discord's Onboarding: new members answer a few questions you write ("Which server do you play on?", "Do you want event pings?") and each answer grants roles or shows channels. It replaces the old reaction-role message and it is the best way to keep notifications relevant.

The rule that matters is about pings. Every announcement that pings @everyone for something routine trains people to mute the server. Make opt-in roles for the things people care about - events, restarts, a specific game server - and ping those roles instead. Keep @everyone for things that affect every player: a wipe date, a breach, a move.

Disable @everyone and @here mentions for everyone except staff. A member who can ping a few thousand people will, eventually, do it by accident or on purpose.

Linking Discord to the game server#

A link between the two is what turns Discord from a chat room into the community's front door. The common integrations, by what they do:

  • Whitelist by Discord role. The game checks whether a joining player holds a role in your Discord. On FiveM, txAdmin's whitelist can require Discord server membership or specific Discord roles; that makes the application process in Discord the actual gate. Discord permissions and whitelist for FiveM covers the setup.
  • Permissions from Discord roles. The same idea one step further: a Discord role becomes an in-game group. Useful for staff, so removing someone's staff role in Discord removes their powers in game at the same time.
  • Chat and console bridges. For Minecraft, DiscordSRV links game chat and a Discord channel, can post the console to a staff channel, and can link accounts so roles sync. DiscordSRV has the configuration.
  • Status and alerts. A webhook that posts when the server stops and starts, or a bot that edits one status message with the player count. Discord webhooks for server status covers both.
verify, applyrole grantedallowed to joinstarted, stoppedstatus channelNew playerjoins DiscordDiscord serverroles and channelsBot or frameworkreads rolesGame serverwhitelist checkWebhookstatus and restarts
Discord as the front door to the game server

Two cautions. A console bridge into Discord is a remote shell into your server for anyone who can type in that channel: lock it to the owner and admins, and remember that a moderator who should not be able to run stop probably can. And every bridge bot needs a token, which is a password - keep it in the server's startup variables or a config file, never in a repository. Environment variables and secrets explains why.

If the bot runs on your own hosting rather than as a public service, it needs a process that stays up. A Node.js or Python app plan is the usual home for a small bot; hosting a Discord bot 24/7 covers keeping one online.

Bots: fewer than you think, with narrow permissions#

Most servers need three kinds of bot, and one well-known general bot often covers two of them:

JobWhat it doesPermissions it needs
Moderation and loggingLogs deletes, edits, joins, bans to mod-logView channels, Send Messages in the log, View Audit Log
RolesAssigns roles from reactions, buttons or applicationsManage Roles, and a role placed above the ones it assigns
TicketsOpens a private channel per support request or applicationManage Channels in one category
Game linkStatus, chat bridge, whitelistWhatever the integration documents

Before inviting a bot, read the permission list on its invite screen and untick anything it does not need. Many public bots request Administrator by default because it is easier for their support team; most will work fine without it. Remove bots you stopped using - each one is a token that can leak.

Discord's own audit log (Server Settings, Audit Log) records role changes, bans, kicks, channel edits and permission changes, with who did them. It is the first place to look when something changes and nobody admits to it, and it is why giving staff individual accounts with individual roles matters more than it seems.

Staff channels, tickets and the paper trail#

Moderation decisions belong in writing, somewhere private and searchable. A staff channel for discussion, a mod-log channel for automatic records, and a ticket system for anything involving a specific player is enough for most communities. Tickets beat direct messages because the next moderator on shift can read them, and because a player cannot later claim a staff member promised something in private.

Keep the in-game logs and the Discord records joined up: when you ban someone in game, note the Discord user and the in-game ID in the ticket. Ban evasion is usually caught by matching those two, not by any clever tooling. Server rules, moderation and staff covers the warning-to-ban ladder and appeals; handling cheaters and ban lists covers evidence.

Staff who manage the game server itself, not just Discord, need panel access too. On RE:NODE that is subusers with granular permissions - console only, files only, no billing - organised into roles and teams, with time-boxed access and a per-server activity log. Keep Discord roles and panel access as two separate decisions: plenty of good Discord moderators should never be able to stop the server. The panel side is in subusers and least privilege.

Protecting the Discord itself#

The most common way a game community's Discord is destroyed is not a raid. It is one staff account taken over through a fake "verify your account" QR code, a malicious download sent by a "game developer" asking for a test, or a password reused from a breach. Once in, the attacker uses that account's permissions to delete channels, ban members and post scam links to everyone.

  • Owner and every staff member on 2FA, with moderator 2FA required at server level.
  • Nobody but the owner has Administrator.
  • Staff are told, in writing, that no legitimate verification asks them to scan a QR code.
  • Webhook URLs are treated as passwords: anyone holding one can post as it. Rotate one that leaks.
  • The server's ownership is not transferred casually. Ownership cannot be taken from the owner by anyone else, which is the one protection you get for free.

If the worst happens, the audit log shows what was done and by whom. Discord does not restore deleted channels, so a list of your channel layout and role permissions, saved somewhere outside Discord, makes rebuilding an evening rather than a week. Some server template features can copy the structure, but not messages.

FAQ#

What verification level should a game server Discord use?

Medium for most servers: a verified email and an account older than five minutes. Move to High if spam waves keep arriving, and to Highest temporarily during a raid. Highest requires a phone number on the account and will turn some genuine players away.

How do I make a channel only staff can see?

Deny View Channel for @everyone on that channel or its category, then allow View Channel for the staff roles. Do not rely on Administrator to give staff access; give them the role and the override, so the setup still works if you later remove Administrator.

Why can my bot not assign a role?

Its own role is below the role it is trying to assign in the role list. Move the bot's role higher in Server Settings, Roles, and make sure it has Manage Roles. Bots can never assign roles above themselves.

Can I require players to be in my Discord to join the game server?

For some games, yes. FiveM's txAdmin can whitelist by Discord membership or role, Minecraft can do it through account-linking plugins, and many other games can do it with a bot that edits the server's whitelist file. It works best when joining Discord is also how players apply.

Should game chat be bridged into Discord?

For a small, quiet server it makes the community feel bigger. On a busy server it floods the channel and people mute it. Bridge into a dedicated channel rather than general chat, and never give a console bridge to anyone you would not give the server's password.

How many bots does a game server Discord need?

Usually two or three: one for moderation logging and roles, one for tickets if the first does not do it, and one for the game link. Every extra bot is another token that can leak and another permission list to audit.


Comments

Completely anonymous: no account, no email, no cookie. We store the name you type, the text and the time - nothing else. Links are limited and markup is not rendered.

0/2000