Documentation
How Crimson Warden works
Accounts, organizations and ranks
You sign in with Discord. Signing in proves identity only. Access to a group's records comes from a membership in that organization, with a rank: Test Staff, Staff, Head Staff, Admin, Head Admin or Owner. Each rank grants specific capabilities (for example "view moderation cases" or "export records"), and an organization's Head Admins can adjust which rank gets what, within fixed minimums. Test Staff get no record access by default.
If you belong to several groups, you pick the active one; your rank is shown for that group only. Being Owner of one group gives nothing in any other group, and nothing on the platform itself.
Discord permissions
The bot never asks for Administrator. It asks for what the enabled features use:
| Permission | Used to |
|---|---|
| View Audit Log | turn Discord moderation actions into cases |
| View Channels, Send Messages, Embed Links, Attach Files, Read Message History, Send Messages in Threads | post case logs, tickets, reports and charts in the channels you map |
| Manage Messages | security feature: remove spam bursts and new members' links |
| Manage Channels, Manage Roles | security feature: alert channel, slowmode/lockdown, first-48-hours role |
| Timeout Members | security feature: a short automatic timeout for heavy repeated spam |
| Mention @everyone/roles | security feature: ping staff roles in alerts |
Only the server owner, or a member with Administrator or Manage Server, can connect a server. Discord performs the bot authorization; Crimson Warden then confirms your permission with Discord directly.
VRChat connection
You never give Crimson Warden a VRChat password. Instead, you give Crimson Warden's dedicated audit account a role in your group that has only View Audit Log. The bot confirms it can read your group's audit log; until then the connection shows "Waiting for group access". You can remove the role at any time to disconnect.
VRChat doesn't publish an official API for this. Crimson Warden uses the same endpoints the VRChat website uses, read-only, at a deliberately slow pace, and backs off when VRChat asks it to. If VRChat changes those endpoints, the moderation log may pause until it's updated; the dashboard shows when data is stale.
What the records mean
- From VRChat / From Discord: facts read from the platform's audit log.
- Staff entered: reasons and notes your staff wrote. Every change is kept in the case history.
- A moderator is only shown as the person who acted when the platform's own log names them.
- When VRChat logs an instance kick as part of a group ban (same person, same moderator, within seconds), the kick is shown inside the ban rather than as a second action. Unrelated kicks are never hidden.
- People are matched by account ID. Display names are shown but never used to combine histories.
Attendance is estimated
VRChat doesn't report who was in an instance or for how long. The bot checks, every few minutes, which linked staff accounts it can see in your group's instance. A session runs from the first check where someone was seen to the last. Short visits between checks can be missed, and time is rounded to the check interval. The dashboard always shows the method and the check interval next to these numbers.
Security model
- Each organization's records are separated in the database by row-level security, enforced by PostgreSQL itself, in addition to the application's own checks.
- Sessions are server-side, with secure HttpOnly cookies, idle and absolute timeouts, and you can end them.
- Sensitive actions (integrations, staff access, license, deletion) need a sign-in within the last 10 minutes.
- Platform administrators must use a passkey/security key or authenticator app.
- Platform support can only read your dashboard if your Owner grants time-limited access; every view is audited and you can revoke it.
- Exports are generated per organization, downloadable for 15 minutes, and audited.
No system is perfectly secure. If you find a problem, report it with the "security" topic.
Current limitations
- One Discord server and one VRChat group per organization.
- The website shows and annotates records; it doesn't kick, ban or otherwise act in VRChat or Discord.
- Evidence is text and links only; file uploads aren't supported yet.
- Charts only cover the time since your group was connected: no history is back-filled or estimated.