Skip to main content
Righteous

How Righteous decides who may run what

The five gates every command passes: Discord permissions, fake permissions, server-owner commands, channel and role rules, and premium tiers.

A command runs only if it clears every gate in front of it. There are five, they are checked in the same order on both the prefix and the slash surface, and each one refuses for a different reason, which is why a refusal is worth reading rather than retrying.

This page is the model. It is also the answer to the question the support server gets most: why can I see a command I am not allowed to run?

Gate 1: the Discord permission the command names

Almost every command declares the Discord permission it needs, and it is the permission that matches what the command does: ,ban wants Ban Members, ,prefix set wants Manage Server, ,config wants Administrator.

A refusal names what was missing, for example Missing permissions: MANAGE_GUILD, so you never have to guess which one it wanted.

Two things this gate does not answer:

  • Whether the bot can act. Your permission and the bot's are separate. If the bot lacks the permission, it refuses with I'm missing permissions: … instead.
  • Whether you may act on that person. Role hierarchy is its own check. A member whose highest role sits above yours is out of reach however many permissions you hold, and the server owner is out of reach regardless of role position.

Gate 2: fake permissions

,fakepermissions (,fp) grants a role a permission on Righteous only. Running it is reserved for the server owner: handing out permissions is exactly the power you would not delegate. A role with fake BAN_MEMBERS can run ,ban without holding Ban Members in Discord, and cannot ban anyone through Discord's own UI, because Discord knows nothing about it.

This exists so a moderator can moderate through the bot, where every action is logged and hierarchy is enforced, without being handed a real permission that works everywhere else in the server.

Every gate above resolves through the same fake-permission-aware check, so a fake permission works identically on prefix and on slash. Two details catch people out:

  • Fake permissions are server-wide. They are not scoped to a channel, even when you are looking at a channel-scoped view of somebody's real permissions.
  • Fake ADMINISTRATOR is not real Administrator. It satisfies every gate on Righteous and nothing outside it, and it does not stand in for a narrower permission such as MANAGE_ROLES, because the two are different bits.

Setup, the full grant model and the ways this can go wrong are in Fake permissions.

Gate 3: server-owner-only commands

A small set of commands is reserved for the server owner (the Discord account that owns the guild) and cannot be delegated with a permission or a fake permission.

,antinuke is the one you will meet first, and every leaf under it inherits the gate. That is the point: a compromised or malicious staffer holding Manage Roles has no business being able to turn the server's own nuke protection off. ,fakepermissions sits here too, for the same reason: it is the command that hands out access to everything else.

Server owner is not bot owner

These are different people. "Server owner only" means the owner of your server, and is different in every server. A handful of developer commands are reserved for the bot's owner instead. Those refuse with Owner only, and no server setting opens them.

Gate 4: where and by whom the command may be run

The first three gates are about who you are. This one is about what your server has configured. Everything here is written with ,command, which needs Manage Server.

Turn a command off in a channel

Syntax

,command disable <#channel|all> <command> [subcommand]

Example

,command disable #general snipe

The channel comes first, then the command. all in that slot writes a single rule meaning every channel, including channels created later, which is why it is not the same as disabling the command in each channel one at a time.

,command enable takes the same shape and undoes it. Using all there clears every rule for that command, per-channel rules included.

Syntax

,command enable <#channel|all> <command> [subcommand]

Example

,command enable all snipe

,command list shows every rule the server holds, with server-wide ones rendered as All channels. ,command reset clears the lot.

Restrict a command to a role

Syntax

,restrict <role> <command> [subcommand]

Example

,restrict Moderator lf wk

A restricted command answers only for members holding that role. Restrictions stack: several roles against one command means any one of them is enough. ,unrestrict removes one, and ,restrict list shows them all.

On the slash surface these live under /command, as /command restrict add and /command unrestrict, because Discord's 100-command cap made two root slots too expensive. The prefix spellings are unchanged.

Professional Mode

Syntax

,command professional <on|off>

Example

,command professional on

,command professional on bulk-disables the whole unprofessional and NSFW set in one go. It is not a separate mode with its own switch: it writes ordinary disable rules, one per command, with the server-wide marker. Three things follow from that, and all three are the reason it works this way:

  • You can carve one command back out. ,command enable all <command> re-enables a single command and leaves the rest disabled. The old all-or-nothing flag could not do that.
  • A channel created next month is still covered, because the rules are server-wide rather than per-channel.
  • The rules are visible. They show up in ,command list like any other rule, and ,command reset clears them along with everything else.

The set is derived from the commands themselves rather than a fixed list, so it tracks the bot.

Administrators and the bot owner bypass Gate 4 entirely

Channel disables, role restrictions and Professional Mode all skip anyone holding Administrator, and the bot owner. This is deliberate: these are guardrails against accident and noise, not a security boundary, but it does mean testing them from an admin account will show you nothing. Test from a second account without Administrator.

Gate 5: the premium tier

The last gate asks whether you, or the server, hold the tier the command needs. Righteous has four paid products with confusable names, and which one a command wants is not always the one you would guess. Premium tiers is the whole story.

Two things worth carrying here:

  • A member of a Server Premium server passes the Boosting Premium gates too. Wherever a command asks only for "premium", it accepts personal premium or the server's.
  • Some features are gated at run time and carry no badge anywhere. They refuse when you use them rather than when you look them up. Those are collected in Features that need premium but don't say so.

See what somebody actually holds

Syntax

,permissions [user]

Example

,permissions @someone

,permissions prints real Discord permissions and fake permissions in one embed, in the same spelling every refusal uses, so what you read here is exactly what the gate reads. A real Administrator collapses to the single word ADMINISTRATOR, since listing every bit would be noise.

/permissions all lists every permission name the bot understands, which is the reference to reach for when ,fp add refuses a spelling.

You can see commands you cannot run

This is the single most reported non-bug in the product, so it is worth stating plainly.

Righteous does not hide gated slash commands from the picker. Every command is visible to @everyone, and a member without the permission gets a private refusal when they run it, not a greyed-out entry, and not an empty menu.

That is a deliberate trade. Discord's own way of hiding a command works against a member's real permissions, before the interaction ever reaches the bot, which would make fake permissions impossible on slash, since the bot never gets asked. Fake permissions are worth more than a tidy picker, so nothing is hidden and everything is checked.

The same logic applies to the config panel: its controls are drawn for everyone who can see the message, and permission is checked when a control is used. Somebody without the right permission gets a private refusal rather than a disabled button.

Common issues

A command refuses with "Missing permissions" and you have Administrator. Check that it is not Server owner only instead: the two refusals are different sentences. ,antinuke and its leaves are the usual case.

A moderator can run a command in Discord's UI but not through the bot. They hold the real permission but the command is restricted to a role they lack, or disabled in that channel. Run ,command list and ,restrict list.

A fake permission does nothing. Fake permissions apply to Righteous only. If the action is refused by Discord rather than by the bot, no fake permission will change it, and if the refusal names the bot's missing permission, the fix is the bot's role, not the member's.

Professional Mode is on but a command still works for you. You hold Administrator, and administrators bypass every channel and restriction rule. Test with an account that does not.

A slash command appears for members who cannot use it. Expected. See You can see commands you cannot run.

The refusal mentions a tier you thought you had. Boosting Premium, Self Premium, Server Premium and the bot purchase are four different things. See Premium tiers.