Risk and safety

How Assistance identifies potentially risky member and verification activity without making automatic moderation decisions.

Risk indicators help staff decide where to look first. They are not proof that a member has done anything wrong, and Assistance does not ban, kick, timeout, or otherwise moderate a member from a risk score alone.

If you are rejected from joining a server by Assistance, ask the server's staff to run /verification force-verify <your-username>, and you'll automatically be verified and granted access.

If you're consistently being rejected, join our support server and open a ticket.

Each score is a number from 0 to 100. A higher score means more signals worth reviewing; a lower score means the available signals look less concerning. Read the listed reasons and the surrounding server context before taking action.

Member behavior risk

Assistance builds an aggregate, per-server profile as members join and send messages. The profile can raise a score for signals that are often associated with scam delivery:

  • A recently created Discord account
  • A recent join to the server
  • No custom profile avatar or no local message history yet
  • A message containing both a link and a scam-like phrase, such as a claim or giveaway prompt
  • A suspicious message accompanied by an image attachment

The system also recognizes positive history. Sustained ordinary conversation, activity across several days, and long-standing membership reduce the score. That keeps a new member from being treated the same as an established member with normal participation.

A score is a prompt to review, not a verdict. Legitimate new members can have several of the same characteristics as a malicious account. Do not use a score as the only basis for a moderation action.

What counts as a suspicious message

The detector looks for a link together with a limited set of scam-like phrases. It does not attempt to judge every message, infer intent, or classify ordinary links as suspicious. An image attachment only increases the score when that same message already matches the link-and-phrase indicator.

Verification risk

During a verification journey, Assistance can compare short-lived signals from the same server to identify patterns that may indicate coordinated or automated verification. These signals can include:

  • A browser identity recently used for another account
  • A network recently used for another account
  • Several accounts verifying in a short window
  • A verification journey completing unusually quickly
  • Repeated rejected CAPTCHA checks

An IP match by itself is not a conclusion about a member. Shared networks are common in schools, homes, workplaces, and mobile carriers. Treat verification risk as one part of the review, alongside your server's membership and access rules.

What Assistance stores

Risk data is intentionally minimized:

  • Member behavior: profile metadata and counters, such as message count, active days, and the number of matching messages
  • Verification: per-server, hashed network and browser values, a timestamp, score, and reasons

Assistance does not retain message bodies, URLs, attachment names, attachment contents, raw IP addresses, or raw browser fingerprints for these systems. Verification signals expire after their configured retention period and are scoped to the server that recorded them.

Reviewing an indicator

When a score needs attention, use it to begin a review:

  1. Read the stated reasons and confirm they make sense for the member.
  2. Check the relevant server context, such as recent activity and verification outcomes.
  3. Apply your existing moderation policy rather than creating a policy from the score.
  4. If a credential, verification rule, or destination changes, update it and rotate any affected secrets.

How is this guide?

On this page