Skip to content

Bulk member-role changes

Keep bulk member-role authority independent from single-member role authority. Require its own capability plus nonempty exact guild and role allowlists, the shared protected-user denylist, pinned application and bot identities, one exact role, and 2-25 unique exact member IDs. Canonicalize the complete target set numerically and bind its digest. Never infer batch authority from a single-member allowlist, a role name, member search, a shared guild, a toolset, or Discord's MANAGE_ROLES grant.

Reuse the complete single-member hierarchy and permission-impact planner for every target through an unforgeable internal batch path. Require all target plans to share one keyed common-evidence digest over the pinned identity, guild, complete roles, bot authority, layout, and trusted direct-channel snapshots. Reject protected and special members, unsafe roles, unsafe unknown or excessive permission impact, obfuscated channels, mixed evidence, and any incomplete or mismatched child checkpoint before approval.

Bind signed MCP request state to the exact action, guild, role, canonical member set, target-set digest, audit reason, parent operation-key hash, and aggregate plan digest. After approval, recheck the complete plan, durably claim the guild member collection, selected role, and every exact member, reserve a pending content-free parent receipt, then execute only the reviewed frontier sequentially by canonical user ID. Each child keeps every single-member pending-audit, one-shot key, non-retried exact PUT or DELETE, and readback gate. Stop at the first failed, uncertain, drifting, or incomplete child; never continue best-effort, retry automatically, replace a complete role array, or roll back a completed target.

Allow resumption only from the original exact request and parent key after a verified pause, a fresh aggregate plan, and a new signed approval. Keep the parent request binding restart-stable through a domain-separated HMAC keyed by the caller-retained raw parent key, while keeping every aggregate review digest process-bound. Accept a child checkpoint only when its content-free receipt is terminal and verified and fresh exact state still matches. Final checkpoint drift, terminal failure, or terminal uncertainty must make the parent terminal and retain coordination for operator review. An interrupted process with a pending claim must remain review-required until the operator checks exact Discord state and resolves that claim. Parent and child records may contain only exact Discord IDs, domain-separated digests, timestamps, fixed outcomes, activity IDs, and sanitized error categories; never persist member, guild, role, or channel names, role sets, permission evidence, audit reasons, raw keys, payloads, or transport causes.

Canonical source: SECURITY.md

Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.