HALLGuard
Moderation and management for Discord communities.
A Discord moderation and server-management system focused on security: automated protection against spam and raids, configurable rules, and an audit trail for every action.
hallguard.org(opens in a new tab)- Design and engineering — bot, rule engine, dashboard
- Discord + web panel
- Discord API, Gateway events, Python, REST APIs, Web dashboard
Overview
HALLGuard keeps Discord servers safe without requiring moderators to be online around the clock. It listens to server events, evaluates them against per-server rules, acts proportionally, and records everything so humans stay in control.
Problem
Community moderation breaks at the edges: raids at 3 a.m., spam waves faster than people can click, and permission setups so complex that admins accidentally lock themselves out.
Goals
- React to abuse in seconds, at any hour
- Avoid false positives that punish real members
- Make powerful configuration approachable
- Keep every automated decision explainable
My role
Design and engineering — bot, rule engine, dashboard.
- Bot architecture and Discord gateway event handling
- Rule engine design and detection heuristics
- Permission model and safety checks
- Dashboard and website
Technology
- Discord API / Gateway events / Python
- REST APIs / Persistent configuration store
- Dashboard / hallguard.org
Architecture
Events flow one way — observe, evaluate, act, record — which keeps the system predictable and auditable.
Gateway events
Messages, joins, role and channel changes stream in from Discord
Router
Normalises events and attaches per-server configuration
Rule engine
Sliding-window detectors for spam, raids, links and mentions
Actions
Proportional responses checked against role hierarchy before executing
Audit log
Every decision recorded with the reason, visible to moderators
Challenges & solutions
Raids arrive as bursts
Dozens of accounts can join and post within seconds; per-message rules miss the pattern.
Sliding-window detectors that reason about rates across the server, with a lockdown mode that engages and releases automatically.
False positives cost trust
An over-eager bot that bans real members is worse than no bot.
Graduated responses and per-server thresholds, so the first signal warns and only repeated or severe behaviour escalates.
Permission edge cases
Discord's role hierarchy means an action can silently fail — or succeed against the wrong person.
Pre-flight checks on every action against the bot's and target's role positions, with clear errors in the log.
Screens
- hallguard.org / dashboardHHALLGuardThe Hall▾OverviewProtectionRulesAudit logRolesSettingsThe Hall · 12,480 membersOverviewProtection activeThreats blocked · 24h142Raids stopped1Messages scanned38.2kFalse-positive appeals0Threat activitylast 24hRaid detected · lockdown 4mModulesAnti-raidAnti-spamLink filterJoin verificationMention limits
Server overview — protection status and recent activity - hallguard.org / logHHALLGuardThe Hall▾OverviewProtectionRulesAudit logRolesSettingsAudit logAllAutomatedManualTimeActionTargetReason03:14:22LOCKDOWNserverJoin rate 38 / 10s exceeded raid threshold03:14:25KICKuser#4471Raid wave · account age < 1h03:14:25KICKuser#9012Raid wave · identical message hash03:18:40RELEASEserverJoin rate normal for 4m · lockdown lifted09:02:11TIMEOUTuser#2208Spam · 7 messages / 5s (2nd offence)09:02:11DELETEuser#2208Duplicate content ×611:47:03WARNuser#7330Blocked link domain · first offence12:30:59SKIPmod#0001Target above bot in role hierarchy
Audit log — every action with its reason - hallguard.org

hallguard.org — the live product site
Results
- Live at hallguard.org
- Automated moderation that runs continuously without moderator presence
- An auditable trail that keeps human moderators in control
Lessons learned
“Security tooling lives or dies by its false-positive rate.”
“Proportional responses beat binary rules.”
“If an automated action can't explain itself, it shouldn't run.”