CordVault Beta v1.0.0Clear history for your Discord server

Help in plain language

Help center

Follow clear, step-by-step guides for setup, investigations, recovery, exports, privacy, and everyday server management.

Public guide · no sign-in needed
/

Choose a task

What are you trying to do?

Jump directly to a complete walkthrough.

The basic workflow

Use CordVault in four steps

Walkthrough · about 5 minutes

Set up a server for the first time

Start atHome → Continue with Discord → Choose a serverSign in with Discord
  1. 1
    Sign in with Discord

    Use the Discord account that owns or manages the server. CordVault never receives your Discord password.

  2. 2
    Choose the correct server

    The Servers page shows every server where your account can manage apps. Select Add CordVault if it is not connected yet.

  3. 3
    Approve the requested bot permissions

    Keep View Audit Log, View Channels, and the permissions needed for the objects you want monitored. Restoration additionally requires Manage Roles or Manage Channels.

  4. 4
    Open Server settings

    Choose the display timezone and history length first. Then open the Recording tab and turn individual activity categories on or off.

  5. 5
    Configure alerts

    Open the Alerts tab, enter the Discord channel ID for notifications, and choose thresholds for repeated destructive or moderation actions.

  6. 6
    Perform a safe test

    Create a temporary role, change one harmless permission, then delete it. The Activity log should show confirmed admin-log activity and Deleted items should retain its final saved state.

Setup is working when…The Overview says recording is on, your test changes appear in Activity log, and the actor is confirmed when Discord supplies a matching admin-log entry.

Walkthrough · investigation

Find who changed a role, channel, or setting

Go toServer → Activity logSign in and choose a connected server first.
  1. 1
    Start with the identifier you know

    Paste a Discord user, role, channel, bot, webhook, or event ID into the search field. If you do not have an ID, begin with the event type and date range.

  2. 2
    Narrow the results

    Use event type, date range, risk, and attribution filters. Select Confirmed when you only want actions directly backed by Discord’s admin log.

  3. 3
    Open the matching activity

    Review the person ID, match strength, original source, before/after comparison, exact timestamps, and related activity.

  4. 4
    Follow the wider history

    Open History lookup and search the same person or object ID to see its full chronological timeline.

  5. 5
    Preserve it if action is needed

    Start a case from the activity page. This attaches that exact event only; unrelated events are not silently added.

Reading the person match

Confirmed means Discord directly backed the match. Highly likely and inferred are correlations. Unknown means CordVault does not have enough proof and will not invent an actor.

Walkthrough · security response

Respond to a security alert

Go toServer → AlertsSign in and choose a connected server first.
  1. 1
    Open the alert and read why it fired

    Check the severity, actor confidence, affected objects, related activity, and recommended response.

  2. 2
    Verify before accusing anyone

    Confirmed attribution is direct Discord evidence. Treat highly likely or inferred attribution as a lead that still needs review.

  3. 3
    Contain active risk in Discord

    For a suspected compromise, remove dangerous permissions, disable the affected account or bot, rotate exposed webhook tokens, and preserve the relevant IDs.

  4. 4
    Create or open the case

    Critical alerts may create one automatically. Attach only relevant events, add affected people and objects, record actions taken, and assign an investigator.

  5. 5
    Update both records

    Acknowledge or resolve the alert, then move the case through Open, Investigating, Contained, and Resolved as appropriate.

Do not use CordVault as the containment toolCordVault explains and preserves evidence. Use Discord’s own controls to remove access or stop an active attacker.

Walkthrough · controlled recovery

Restore a deleted role, channel, or category

Go toServer → Deleted items → Choose item → Review restoreSign in and choose a connected server first.
  1. 1
    Open the deleted item

    Check the object ID, deletion event, last known state, and all saved versions. Confirm you selected the intended object.

  2. 2
    Choose the exact saved version

    The newest version is not always the version you want. Select Preview restoration beside the correct historical version.

  3. 3
    Review proposed changes and dependencies

    Read every permission, position, category, overwrite, and missing-reference warning. No Discord change occurs during preview.

  4. 4
    Confirm the plan

    Type the exact confirmation phrase shown. CordVault queues the request and immediately checks its live permissions and role hierarchy.

  5. 5
    Wait for verification

    The status page advances through queued, executing, and verifying. Completed means CordVault read the result back from Discord and wrote a new audit event.

  6. 6
    Finish manual cleanup

    Rename the temporary object, reassign members to recreated roles, and reconnect integrations or references that Discord could not preserve.

New IDs are expected

Discord does not let CordVault recreate an object with its former ID. Names are not stored, so recreated objects receive an obvious temporary name. CordVault maps known restored dependencies where possible.

Walkthrough · evidence

Build a case and download a report

Go toServer → CasesSign in and choose a connected server first.
  1. 1
    Start from the strongest evidence

    Open an activity record and choose Start case so that exact event is attached. Or create an empty case from Cases when you do not yet have a starting event.

  2. 2
    Add exact evidence

    Use Copy event ID in Activity log, paste it into Add evidence, and repeat only for records relevant to the investigation.

  3. 3
    Define the scope

    Add affected users, roles, channels, bots, or webhooks by Discord ID. Add investigator notes explaining decisions and response actions.

  4. 4
    Keep the case state accurate

    Assign an investigator, choose severity, and update the status as the incident moves from discovery to containment and resolution.

  5. 5
    Check integrity and export

    Confirm the chain shows verified, then choose JSON for complete structured evidence, CSV for analysis, or PDF for a readable report.

RememberThe case time window is context only. Events appear in the case only when explicitly attached or linked by the alert that created it.

Where to go

Dashboard page map

After choosing a server, use the left sidebar to reach each part of CordVault.

OverviewHealth, counts, recent changes, alerts, saved objects, and a quick status check.
Activity logSearch every recorded change and open before/after details.
AlertsReview security detections, risk explanations, and recommended actions.
CasesCollect exact evidence, notes, people, objects, and exports for an investigation.
History lookupSee a chronological history for one user, role, channel, or object ID.
Message evidenceReview optional edit and deletion evidence if the server enabled it.
Deleted itemsInspect the last known state and earlier versions of deleted objects.
Proof checkVerify the per-server tamper-evident hash chain.
Safe restorationTrack queued, active, completed, and failed restoration jobs.
Server settingsChoose recording, retention, alerts, messages, and dashboard access.

Foundation

How collection works

CordVault begins building history after the bot joins your server. It cannot reconstruct activity or deleted objects that happened before installation.

Three ways CordVault learns about changes

Live Discord updates report a change. Discord’s admin log may identify an administrator. Regular saved-state checks can find differences after the fact. These are different kinds of evidence, even when they concern the same action.

  • Live server changesRole, channel, member, invite, webhook, emoji, sticker, and server changes.
  • Discord admin logOften confirms which person performed an admin action.
  • Regular state checksCompare Discord with saved state to find missed or repeated changes.

Discord may send the same action through more than one source. CordVault tries to combine matching records, but a saved-state difference cannot prove exactly when or why a change happened.

Activity reference

What actually triggers each record?

An Activity log row appears when CordVault receives a supported live update, receives a Discord admin-log entry, detects a difference during a saved-state check, or completes one of its own restoration jobs. A normal message being sent is not recorded as message evidence.

Server settings

GUILD_UPDATED follows a server update, such as verification or system-channel settings. The admin-log version, AUDIT_GUILD_UPDATE, may identify who made it.

Channels & categories

CHANNEL_* and CATEGORY_* follow creation, deletion, or a change to tracked settings such as topic, position, slowmode, voice settings, or permission overwrites.

Roles

ROLE_* follows creation, deletion, or a tracked change such as permissions, position, color, or mentionability. A member gaining a role can also create MEMBER_ROLES_UPDATED.

People & bots

MEMBER_JOINED or BOT_ADDED means an account joined. MEMBER_LEFT means an account was removed from the server; it might have left, been kicked, or been banned.

Member changes

A changed role list, nickname, or timeout creates MEMBER_ROLES_UPDATED, MEMBER_NICKNAME_UPDATED, or MEMBER_TIMEOUT_UPDATED. One Discord update may cause several records.

Bans

MEMBER_BANNED and MEMBER_UNBANNED follow Discord ban notifications. A matching admin-log entry may confirm the responsible person.

Emojis & stickers

Discord sends the revised collection. CordVault compares IDs and tracked properties to record an item created, updated, or deleted.

Invites & webhooks

Invite create/delete notifications produce INVITE_* records. WEBHOOKS_UPDATED only says webhooks changed in a channel; an admin-log entry may clarify create, update, or delete.

Messages, if enabled

MESSAGE_EDITED requires a content or attachment update. MESSAGE_DELETED follows a single deletion; MESSAGES_BULK_DELETED follows a bulk deletion. Sending or reacting to a message does not create one of these records.

Saved-state checks

SNAPSHOT_DRIFT_DETECTED means a tracked saved item now differs. SNAPSHOT_OBJECT_MISSING means it is no longer found. Neither tells us the exact action or person by itself.

CordVault actions

BOT_INSTALLED and BOT_REMOVED mark CordVault joining or leaving. RESTORATION_COMPLETED and RESTORATION_FAILED mark the outcome of a CordVault recovery request.

What does AUDIT_ mean?

Discord created an administrative log entry—for example, a role edit, channel deletion, kick, permission overwrite, webhook change, pin, thread change, or Auto Moderation action. CordVault can record other Discord admin-log action types too. These are controlled by the Discord admin-log source and, where applicable, an activity category. Message-deletion audit entries are used to enrich message evidence instead of creating a second independent deletion row.

Important limits

A member-removal notification does not distinguish leaving from kicking. A message-deletion notification contains message and channel IDs, not the deleting person; CordVault looks for a nearby matching admin-log entry. Names are not saved, so a name-only rename may appear through the admin log without a separate live-change row. Threads, voice activity, reactions, and other Discord notifications are not all captured as dedicated live records.

For the precise Discord-side definitions, see Discord Gateway events and Discord audit-log actions.

Activity log

Activity and changes

Each activity record describes one change CordVault saw. You can search it, open it, and download it later.

Type of changeWhat happened, such as AUDIT_ROLE_UPDATE.
Item involvedThe person, role, channel, or other item that changed.
Who did itThe Discord user ID tied to the action.
Before / afterThe structured state on each side of the change.
SourceWhere CordVault learned about the change.
Match strengthHow strongly the available proof supports the person match.

Use the Activity log to search by ID, type, date, risk, or person match. Open a result to see its before-and-after details.

Not sure why a record appeared? See what triggers each record before drawing a conclusion from its title.

Who did it

How CordVault matches a person

CordVault does not present a guess as fact. Each person match shows how certain the system is.

ConfirmedA Discord admin-log entry identifies the actor for this recorded action. For message deletions, review the matching details as well.
Highly likelyThe action, item, and time strongly match, but Discord did not directly confirm it.
InferredSurrounding activity points to this person.
UnknownThere is not enough proof to identify anyone safely.

“Unknown” is the honest result when Discord does not provide enough evidence. It is safer than assigning the wrong person.

State memory

Saved states and deleted items

CordVault regularly saves what roles, channels, and other items look like. If one is deleted, its last known settings remain available under Deleted items.

  • Latest saved stateThe newest settings CordVault saw.
  • Earlier versionsOlder settings and when they changed.
  • Before deletionThe final known settings, including permissions and relationships.
Snapshot limits

CordVault can only preserve information it observed while installed and authorized. A snapshot is evidence of known state, not magical recovery of unseen data.

Controlled recovery

Safe restoration

Owners and dashboard administrators can restore supported role and channel settings from a saved version. CordVault never treats this as a one-click rollback.

  1. 1
    Choose a saved version

    Open a role or channel history page and select the exact version you want.

  2. 2
    Review the plan

    Read the proposed changes, dependencies, required bot permission, and visible limits.

  3. 3
    Confirm it explicitly

    Type the displayed confirmation phrase. The bot then rechecks live permissions before acting.

  4. 4
    Verify the result

    CordVault reads the object back from Discord, reports differences, and records a new audit event.

Restoration has real limits

Recreated objects receive new IDs. Names are not stored, so recreated items use a temporary name. Members are not automatically reassigned to recreated roles, missing references may be skipped, integrations may not reconnect, and Discord role hierarchy can block a change.

Important activity

Alerts

Alerts bring risky changes to your attention. Each one explains what happened, why it matters, who may have acted, and what to do next.

CriticalImmediate review recommended; high-impact compromise or destructive activity.
HighDangerous change that should be investigated promptly.
MediumSuspicious or policy-relevant activity requiring review.
LowInformational risk signal worth retaining for context.

Alert status moves from Open to Acknowledged and then Resolved. A critical alert may also start a case automatically.

Organized follow-up

Cases

A case contains only the activity you attach. Its time range is a reference and does not automatically add everything that happened during that time.

  1. 1
    Start the case

    Begin from an activity record or create an empty case.

  2. 2
    Add related activity

    Add event IDs and the people or items involved.

  3. 3
    Record your response

    Add notes, assign someone, and update the risk and status.

  4. 4
    Close and download

    Resolve or archive the case, then create a report when needed.

A case started from an activity record includes that one record. A case started from the Cases page begins empty.

Trust your history

Proof checks and downloads

CordVault links original records together with SHA-256 proof values. A proof check recalculates them and reports anything that no longer matches.

Original recordThe data saved when CordVault first saw the change.
Details added laterThe person match and related activity added afterward.
Proof checkChecks each record and its link to the next one.
Download proofRecords the file’s proof value, date, format, and check result.
JSONComplete structured evidence for machines or technical review.
CSVTabular event data for analysis in spreadsheet tools.
PDFA readable incident report for sharing and review.
Tamper evidence is not legal immutability

Integrity checks show whether stored or exported bytes differ from the hashed records. They do not prove CordVault observed every Discord event, and they do not make a record legally immutable.

Configuration

Server settings

The server owner and approved dashboard administrators can change these settings. Changes apply only to the selected server.

Go toServer → Server settingsSign in and choose a connected server first.
  • TimezoneChanges how dates appear on the dashboard.
  • History lengthControls how long old records are kept.
  • Recording sourcesTurn live Discord updates and Discord’s admin log on or off.
  • Activity categoriesChoose server settings, channels, roles, members, moderation, invites, webhooks, emojis and stickers, or bots and integrations separately.
  • Alert deliveryChooses a Discord channel and when repeated actions trigger a warning.
  1. 1
    General

    Set the timezone used for display and how long audit history is retained.

  2. 2
    Recording

    Keep both live changes and Discord admin-log collection enabled for the best coverage and actor attribution. Disable only the individual categories you do not need.

  3. 3
    Alerts

    Paste a Discord text-channel ID and adjust the mass-action and rapid-action thresholds.

  4. 4
    Messages

    Leave off unless needed. If enabled, choose the narrowest mode and shortest useful retention.

  5. 5
    Access

    Owners can grant Admin, Investigator, or Viewer dashboard access using Discord user IDs.

  6. 6
    Save changes

    The save bar appears at the bottom. Settings affect new collection; they do not erase existing evidence.

Turning a category off stops new activity records and new saved states for it. History already stored is not deleted.

Categories are broad rather than a switch for every Discord action. Some admin-log actions do not have a dedicated category; they depend on the main Discord admin-log switch. Message evidence has its own separate controls. See the trigger guide for examples.

Optional module

Message evidence

Message evidence is separate from normal server history and stays off until an owner or administrator enables it. Basic details and message text have separate time limits.

Go toServer → Server settings → MessagesSign in and choose a connected server first.
OffNo message edit or deletion records are created.
Basic details onlySaves IDs, dates, change type, and file details—never message text.
Moderation cases onlySaves encrypted text only for a channel or author included in an active case.
Selected channelsSaves encrypted text only for the exact channel IDs you choose.
  • Encrypted while savedSaved message text is protected and does not appear in normal activity data.
  • Restricted accessOnly approved owners, admins, and investigators can view message evidence.
  • Access loggingList views, detail views, content reveals, policy changes, and deletions are recorded.
  • Deletion workflowsOwners can clear all content or delete evidence by author, channel, message, or server.
  1. 1
    Publish your disclosure

    Tell members what is collected, why, who can see it, and when it is deleted before enabling the feature.

  2. 2
    Choose the narrowest capture mode

    Start with Basic details only. Use Moderation cases or Selected channels only when retaining encrypted text is necessary.

  3. 3
    Set separate time limits

    Message text should expire sooner than metadata. Use the shortest period that still supports your moderation purpose.

  4. 4
    Add channel IDs when required

    For Selected channels, enable Discord Developer Mode, right-click each channel, choose Copy Channel ID, and paste the IDs into settings.

  5. 5
    Acknowledge and save

    Confirm the disclosure checkbox and save. Content modes will remain unavailable if the server encryption key or Message Content intent is not configured.

  6. 6
    Test with a harmless message

    Post, edit, and delete a test message in an allowed channel. Then open Message evidence and confirm the record matches your chosen mode.

Community disclosure is required

Before enabling collection, clearly tell administrators and members what is collected, why it is needed, who can access it, and how long it is retained.

Why might the deleting person be unknown?

Discord’s live message-deletion notice does not include who deleted it. CordVault checks for a nearby matching admin-log entry, but Discord may not provide one. Message author and attachment details may also be unavailable when the deleted message was not in the bot’s cache. Do not treat an unknown actor as proof that the message author deleted it.

Data handling

Privacy and stored data

CordVault stores Discord IDs instead of user, role, channel, or server names in its audit database. IDs keep records correlatable without retaining display names that can change over time.

  • IDs onlyActor, subject, guild, member, role, and channel references use Discord IDs.
  • No conversation archive by defaultThe core audit platform does not depend on storing every message.
  • Purpose-limited retentionEvidence is retained according to the configured server policy.

Names and icons shown on the website come from your current Discord session or a live Discord response. CordVault does not need to keep them in the audit database.

Problem solving

Fix common problems

Does “Member left” mean they chose to leave?+

No. Discord’s member-removal notification can mean a voluntary leave, kick, or ban. Check for a matching admin-log action before deciding which happened.

Why did editing or deleting a message create a record, but sending it did not?+

The optional message module records edits and deletions, not every message sent. It must be enabled in Server settings → Messages. Content or attachment details depend on your chosen mode, Discord permissions, and what the bot had available.

Why did a rename show an admin-log entry but no separate live-change record?+

CordVault does not save names. A name-only change may leave its tracked before/after state identical, while Discord still creates a separate administrative audit entry for the rename.

Why is the person listed as unknown?+

Wait briefly and refresh first because Discord’s admin-log entry can arrive after the live event. If it stays unknown, confirm the bot has View Audit Log and that Discord actually records an actor for that action. CordVault will not guess when proof is missing.

A change is missing from Activity log. What should I check?+

Open Server settings → Recording and confirm both the source and that activity category are enabled. Check the bot is online and can view the affected channel or object. Widen the date range and remove search filters. Changes from before installation cannot appear.

Why can’t I see an event from before installation?+

CordVault starts observing when the bot is installed. It cannot reconstruct changes it never received.

Why does an old deleted item still appear?+

That is intentional. CordVault keeps the last known settings so you can review what existed before deletion.

Why is the displayed time wrong?+

Open Server settings → General and choose the correct timezone, such as America/New_York, then save. This changes display only; stored evidence remains in UTC.

Why did collection stop?+

Confirm the bot is online and still in the server. In Discord, check its role still has View Audit Log and can view the relevant channels. Then check Server settings → Recording to ensure the source and categories are enabled.

Why does a case start empty?+

A case you create manually starts empty on purpose. Add exact event IDs so unrelated activity is never included without your choice.

Why did a restoration fail?+

Open Safe restoration and select the failed job. Read the last activity entry. Common causes are missing Manage Roles or Manage Channels, CordVault’s role being too low, a Discord-managed role, a missing dependency, or Discord rejecting a saved setting. Fix the stated cause and create a new preview; failed jobs are never silently retried.

Why does a restored item have a temporary name and new ID?+

Discord creates a new object with a new ID, and CordVault intentionally stores IDs instead of names. Rename the restored item in Discord and update any external references after verification completes.

How do I copy a Discord ID?+

In Discord, open User Settings → Advanced → enable Developer Mode. Right-click a user, role, channel, message, or server and choose Copy ID. On mobile, press and hold the item after Developer Mode is enabled.

Why can’t I enable retained message text?+

The site must have a message-content encryption key and the bot must have Discord’s Message Content intent enabled. The dashboard shows readiness. Basic details only does not require message text retention.

Reference

Glossary

Gateway event
A real-time notification sent by Discord when server state changes.
Audit-log entry
Discord’s administrative record of an action, often including the responsible user.
Snapshot
A structured copy of a Discord object’s known configuration at a point in time.
Reconciliation
A comparison between Discord’s current state and CordVault’s stored state.
Correlation
Matching related Gateway, audit-log, and surrounding events into a coherent action.
Canonical record
The consistently serialized original evidence used for integrity hashing.
Hash chain
A sequence where every record’s hash depends on the record before it.
Manifest
A signed summary describing an export, its file hash, and verification status.