Crimson Warden

Documentation

How Crimson Warden works

Accounts, organizations and ranks

You sign in with Discord. Signing in proves identity only. Access to a group's records comes from a membership in that organization, with a rank: Test Staff, Staff, Head Staff, Admin, Head Admin or Owner. Each rank grants specific capabilities (for example "view moderation cases" or "export records"), and an organization's Head Admins can adjust which rank gets what, within fixed minimums. Test Staff get no record access by default.

If you belong to several groups, you pick the active one; your rank is shown for that group only. Being Owner of one group gives nothing in any other group, and nothing on the platform itself.

Discord permissions

The bot never asks for Administrator. It asks for what the enabled features use:

PermissionUsed to
View Audit Logturn Discord moderation actions into cases
View Channels, Send Messages, Embed Links, Attach Files, Read Message History, Send Messages in Threadspost case logs, tickets, reports and charts in the channels you map
Manage Messagessecurity feature: remove spam bursts and new members' links
Manage Channels, Manage Rolessecurity feature: alert channel, slowmode/lockdown, first-48-hours role
Timeout Memberssecurity feature: a short automatic timeout for heavy repeated spam
Mention @everyone/rolessecurity feature: ping staff roles in alerts

Only the server owner, or a member with Administrator or Manage Server, can connect a server. Discord performs the bot authorization; Crimson Warden then confirms your permission with Discord directly.

VRChat connection

You never give Crimson Warden a VRChat password. Instead, you give Crimson Warden's dedicated audit account a role in your group that has only View Audit Log. The bot confirms it can read your group's audit log; until then the connection shows "Waiting for group access". You can remove the role at any time to disconnect.

VRChat doesn't publish an official API for this. Crimson Warden uses the same endpoints the VRChat website uses, read-only, at a deliberately slow pace, and backs off when VRChat asks it to. If VRChat changes those endpoints, the moderation log may pause until it's updated; the dashboard shows when data is stale.

What the records mean

Attendance is estimated

VRChat doesn't report who was in an instance or for how long. The bot checks, every few minutes, which linked staff accounts it can see in your group's instance. A session runs from the first check where someone was seen to the last. Short visits between checks can be missed, and time is rounded to the check interval. The dashboard always shows the method and the check interval next to these numbers.

Security model

No system is perfectly secure. If you find a problem, report it with the "security" topic.

Current limitations