Understand Owner delegations and protections

Distinguish delegated access from actions reserved exclusively for Luméo's primary owner.

Principle of least privilege

A delegation should grant only the functions required for the assigned responsibility. It does not turn the recipient into the bot's primary owner.

Delegated access

Delegations may allow someone to view or use specific Owner sections depending on the permissions granted. They should be removed as soon as they are no longer needed.

Exclusively reserved actions

Some high-impact decisions remain tied to the exact identifier configured in OWNER_ID. This notably includes globally blocking or unblocking a server and coordinating the purge of an archived server.

Required protections

  • strong confirmation using the target's exact identifier;
  • an internal reason for blocking decisions;
  • refusal to block or purge the official server;
  • refusal to purge a server where Luméo is still present;
  • logging of accepted actions and rejected attempts.

Reports and decisions

An accusation alone does not automatically trigger a block. The available information must be reviewed by a person. When a serious case is confirmed, Luméo protects its own service, leaves the server, refuses reinvitation, and forwards the report to Discord without storing illegal content.

Revocation

After responsibilities change, review the remaining delegations and immediately remove any access that is no longer required.

Contribute to the Wiki Help improve this article Report an error or suggest an improvement

Report an error or suggest an improvement

Your feedback will be sent to the Wiki team without directly changing the article.