Permission Audit
The Permission Audit shows what every role and every bot in your Discord server can do in every channel β on one screen, with the reason behind each answer. It replaces switching roles one at a time in Discord's View Server As Role, and it flags the mistakes that are easy to make and hard to spot: a staff channel that @everyone can read, a bot with Administrator, a channel that quietly stopped matching its category.
It is read-only. Nothing you do here changes your server; when something needs fixing, the page links you to the right channel in Discord.
Permission Audit is part of the Lite plan and above.
Until 28 October 2026 the Permission Audit is free for every server, whatever its plan β try it on your own server and see what it finds. After that date it needs the Lite plan.
Opening itβ
- Go to tektools.app and open your community's dashboard.
- Select Permission Audit in the sidebar.
The page reads your server the moment you open it. The snapshot is kept for a minute, so reopening the page is instant; use Refresh snapshot after you've changed something in Discord and want to see the result.
Only community admins can open the dashboard, so only they can see the audit.
Findingsβ
The strip at the top answers "is anything wrong?" before you look at anything else. Findings are grouped by kind β one card says "3 bot roles have Administrator" rather than showing three cards β and each card has a severity. A card with one finding takes you straight to it; a card with several opens the list, and each item takes you to its role or channel. Wherever you land, the row or cell you clicked flashes so you can see it.
| Finding | What it means | What to do |
|---|---|---|
| @everyone has a dangerous permission (high) | @everyone holds Administrator, Manage Roles, Manage Webhooks, Manage Server, Manage Channels or Mention @everyone β server-wide, or in one channel through an override. | Remove it from the @everyone role (Server Settings β Roles) or from the channel's permission overrides. |
| TekTools can't do its job somewhere (high) | The TekTools bot is missing View Channel, Send Messages, Embed Links or Manage Messages in a channel you configured a feature to use, or a role it hands out sits above its own role. | Give the bot the missing permission in that channel, or move the TekTools role above the roles it manages. |
| A bot has Administrator (low, or medium when that bot's role sits above TekTools) | A bot's role grants Administrator, which bypasses every channel override. Most bots ship that way, so on its own it is only worth a look β but a bot placed above TekTools could also touch the roles TekTools manages for you. | Replace Administrator with the specific permissions the bot documents, and keep bot roles below TekTools in the role list. |
| A channel is out of sync with its category (medium) | The channel has its own permission overrides and no longer inherits the category's. That is fine when intentional β and the usual cause of an accidental leak. | Open the channel's permissions in Discord; Sync Now restores the category's overrides. |
| @everyone can see a staff-looking channel (medium) | A channel whose name (or category) contains mod, admin, staff, team or log is visible to @everyone. This one goes by the name, so it can be wrong. | If the channel is really private, deny View Channel to @everyone on it or on its category. |
When nothing is flagged, the strip says so and lists what was checked.
The matrixβ
Rows are your channels, grouped by category the way Discord's sidebar shows them. Columns are your roles: @everyone first β highlighted, and kept in view when you scroll sideways, because it is the baseline every member gets β then the rest from highest to lowest. Bot roles are tagged BOT (and the TekTools bot TEKTOOLS).
Each cell shows one permission β pick which with the chips above the grid: View channel, Send messages, Manage messages, Mention @everyone, Manage webhooks or Administrator.
| Cell | Meaning |
|---|---|
| Green β | The role has the permission in that channel. |
| Dark β | It doesn't. |
| Purple β | The role has Administrator, which grants everything and ignores channel overrides. |
| Gold corner | The value was set by a channel or category override, not by the role's own permissions. This is what to look at when a cell surprises you. |
A red dot next to a channel name means a finding points at that channel. Type in Filter channels to narrow the rows, tick Only channels with a finding, or click a category header to collapse it.
Comparing rolesβ
Every role header except @everyone has a checkbox. Untick any role and the matrix shows only the ticked ones β so to answer "what does Holder get that @everyone doesn't?", untick everything but Holder. Two switches help:
- Only channels where these roles differ hides every row where the ticked roles agree, leaving just the differences.
- Hide bots drops bot columns, which are usually all-β and add noise.
Show all roles puts everything back. The permission you picked, the roles you ticked and the categories you collapsed are remembered per server, so a reload doesn't undo a comparison you set up.
Why this cell?β
Click any cell and the panel on the right walks through how Discord arrived at the answer, step by step:
- Base permissions β what @everyone plus this role grant server-wide.
- Category override β what the channel's category says for @everyone and for this role. If the channel isn't synced with its category, this step is shown struck through: it doesn't apply.
- Channel override β what the channel itself says.
- No View Channel β if the role can't see the channel, every other permission is removed, whatever the steps above said.
The verdict at the top calls out the case that matters most: "Allowed β but the category says no" is a channel override undoing what the category was set up to protect.
From the panel you can open the channel in Discord to fix it, or switch to One channel to see every role's access to that channel side by side.
One role, one channelβ
The toggle above the matrix switches between three views of the same data:
- Matrix β everything at once, one permission at a time.
- One role β pick a role and see, channel by channel, whether it can view, send, react, create threads, attach files and mention @everyone. Four tiles summarise it (how many channels it can see and type in, how many it unlocks compared with the baseline, where it can @everyone). The Compared withβ¦ column says what this role adds or loses in each channel against a baseline role β @everyone unless you pick another in compared with, so "what does Whale get that Holder doesn't?" is one pick away β and the filter hides channels where the two have exactly the same access. A role that holds Administrator gets a banner instead: it has everything everywhere, so the table would say nothing.
- One channel β pick a channel and see every role's access to it, with a note on whether the channel is synced with its category.
How roles are evaluatedβ
Each cell answers "what can a member with only this role do?" β exactly what Discord's View Server As Role shows. Two things follow from that:
- Members with several roles can do more than any single column shows: Discord combines all their roles.
- Channels that members opt into through Onboarding aren't reflected: the audit shows whether a role may see a channel, not whether the channel is in a given member's list.
Threads aren't listed; they follow their parent channel's permissions.