Authorize your team pro
Three levels, nothing in between to misconfigure. You are the owner. Co-owners get the dashboard and every command. Authorized users - added per person or per Discord role - get the day-to-day commands and nothing else.
Revoking
- Access is checked on every command press and every page request, never cached in a session - someone you remove is stopped on their very next action.
- /authorize and /deauthorize work from Discord; the Access tab does the same on the site.
Staff can
- Bump, post vouches, send confirmation DMs, watch threads, check /status
- See the private #zorabot and #zorabot-logs channels
Staff cannot
- Open your dashboard or change any setting
- Edit vouch or DM templates
- See stored credentials - they are encrypted and never displayed to anyone, you included