The audit log
Every time a moderator acts, Server Assistant writes it down. That audit trail answers the questions that come up later: who removed that member, when the channel was locked, why someone was banned. It runs on every plan, nothing to switch on.
FREE The audit log is part of every plan.
Three parts work together:
- A permanent moderation log in your web dashboard: always on, every plan. It records every action on our servers, so it can’t be edited or deleted from within Discord; admins read it by signing in. It’s there even if you never set up a Discord log channel.
- A visible log channel in your server (optional, pick one during
/setup), where each action also lands as a tidy embed your team can read at a glance. - A separate, encrypted record that staff cannot read, edit, or erase, so the underlying trail survives whatever happens to the visible channel.
In short: the log channel is the window; the dashboard log and encrypted record are the safe behind the glass. You can break the window, you can’t open the safe.
What gets logged
Server Assistant records what matters for accountability:
- Moderation actions: warnings, notes, mutes, kicks, bans, soft-bans, temp-bans, locks, lockdowns and the rest, each logged with who did it, what they did, to whom, and the reason.
- Actions taken directly in Discord: ban or kick someone via Discord’s own menus (not a Server Assistant command) and the bot logs it anyway, marked as a native action.
- Command usage: a compact one-line entry each time a command is run, so you can see who’s driving the bot even when nothing changes.
- Minecraft moderation: a Kick or Ban in-game taken from a Minecraft chat-flag alert is recorded like any other moderation action — log channel, dashboard log and encrypted record — marked via MCDC enforce and naming the player and their Minecraft UUID. See the Minecraft bridge guide.
- Changes to SAi: when someone reconfigures your AI assistant, the change is written down. That covers the Discord side (AI mode, provider, model, image provider, the Reception persona and greeting) and the in-game @sai Studio (who may ask, the assistant’s name, tone, greeting, knowledge pack, and the in-world companion toggles).
How an SAi change is recorded
These entries answer “who changed the assistant, and when” without ever copying what was written. They record the shape of a change, not its text:
knowledge updated (412 → 980 chars)
greeting cleared (86 chars removed)
access: staff → everyone
companion: off → on
The prose fields — the assistant’s name, greeting, persona and the server knowledge pack — are owner-authored writing, so only their length is measured and stored. The wording itself never enters the audit trail, and it is never sent to the dashboard log. On/off and either/or settings record the old and new value, because those are the fact worth keeping.
Where these land. SAi-configuration entries go to the dashboard log and the encrypted record, not to your Discord log channel, so reconfiguring the assistant doesn’t spam
#mod-log. Everything else on this page behaves as described above.
A moderation action in the log
When a command like /ban runs, the action lands in your log channel as a full
embed, the same one the command author sees, mirrored to the team:

An action taken directly in Discord
Moderate with Discord’s built-in tools and the trail stays complete: the bot mirrors the action into the log channel, marked so you can tell it apart, with a nudge to use the bot next time (which keeps the one-tap undo):

Native bans, unbans, kicks, timeouts, role changes and channel deletions are all picked up this way.
A command-usage entry
Every command leaves a light footprint too, a single grey line naming who ran what, and where. Commands that already produce a detailed entry (like the ban above) are skipped, so you never see the same thing twice:

You can turn these compact command-usage lines on or off in /settings →
Behaviour: the detailed moderation entries above always log regardless.
What’s recorded, and what isn’t
The dashboard moderation log is deliberately minimal. Each entry keeps only:
- The affected member’s Discord user ID
- The action type (ban, kick, timeout, delete, flag, …)
- Who did it: a staff member, or an automated system such as ThreatNet (for an automatic scam-image removal)
- A timestamp and a short reason
It does not store the message content, or any image that triggered the action, only the fields above. Entries are automatically removed after 180 days. (The full detail lives in our Privacy Policy.)
Decision cards have their own clock
A decision card is the pending item your team is asked to act on — an AutoMod review, a Minecraft chat flag, a ban appeal, a raid alert. Unlike a finished log entry, some of these still hold context (a short extract of the flagged message, a player’s name and Minecraft UUID), so an unactioned card doesn’t sit around forever:
| Decision | Kept until |
|---|---|
| AutoMod review, Minecraft chat flag | 14 days — these are the cards carrying a message extract |
| Ban appeal, Minecraft ban appeal, raid alert | 30 days — deliberately generous, someone is waiting on an outcome |
| Owner approval | No expiry — a question put to a specific person, it waits until it’s answered |
Anything not listed gets the 30-day default. Reaching the window doesn’t delete anything on the spot: staff are warned first, the card closes after a 24-hour grace period, and it’s deleted 90 days after it closes.
This is an outer bound on how long an ignored card is kept. It doesn’t change how long a card stays in front of your team in practice — the nudging for an unactioned card is the escalation ladder, which starts DMing after about an hour. Decisions raised before this clock shipped have no expiry set and aren’t swept by it.
Why it’s tamper-proof
An audit trail has to stay trustworthy even when someone would rather it didn’t, so the record can’t be quietly wiped:
- A separate, encrypted record. Alongside the visible channel, the bot keeps its own encrypted log of every action, outside Discord. Staff cannot read, edit or erase it, there’s no command, button or permission that reaches in.
- Deleting log messages doesn’t delete the truth. Someone can delete a message from the visible log channel, but that changes only the window, not the safe. The encrypted record is untouched.
- And you’ll know if they try. If a message is deleted from your log channel, Server Assistant spots it and alerts your log channel and the server owner, naming who did it:

If the log channel itself is deleted, the bot notices, clears the setting so you can pick a fresh one, and the encrypted record carries on untouched.
Setting your log channel
A Discord log channel is optional, the dashboard log is always on either way.
For the Discord mirror too, choose it during the /setup wizard on the
Channels step: the bot detects a likely candidate (often #mod-log), or you
can pick another from the dropdown, have it Create for me a fresh locked-down
one, or choose Portal only to skip the Discord channel entirely.

To change it later, open /settings → Behaviour → Log channel to pick a
different channel or switch to Portal only (your dashboard log stays on).
Re-running /setup works too. The same /settings → Behaviour section
holds the finer controls: how chatty the log is, and whether the compact
command-usage lines appear.
See also
- The
/setupwizard, choose your log channel and staff roles in about a minute - Moderation & safety, every command that writes to your audit trail