Howie is still in development. These docs describe how Howie works at launch. Details may change over time.
Permissions
Howie asks only for what it uses or plans to use. Here's every permission, why Howie needs it and what stops working without it.
Server permissions
| Permission | Why Howie needs it | Without it |
|---|---|---|
| View Channels | To see new messages so it can check them. | Channels Howie can't see aren't protected. |
| Read Message History | To find every copy of a scam when an account posts it across several channels. | Howie may miss earlier copies when it cleans up. |
| Manage Messages | To delete scam posts. | Scam posts stay up, even if Howie kicks the account or gives it a timeout. |
| Timeout Members | To give accounts a timeout. Timeouts are the default action. | The default action fails. |
| Kick Members | To kick accounts, if you choose that action. | The kick action fails. |
| Ban Members | To ban accounts, if you choose that action. | The ban action fails. |
| Manage Server | To create and update the AutoMod rules that block known scam links before they post. | No AutoMod rules. Howie still catches scams, but only after they post. |
| Send Messages | To post the welcome message and reports. | No welcome and no reports. |
| Embed Links | To format reports. | Reports can't be posted. |
| Attach Files | Reserved for future report features. Howie doesn't attach files today. | Nothing changes for now. |
About Manage Server
Manage Server is a broad permission, so here is exactly how Howie uses it:
- Howie only creates, updates and removes AutoMod rules whose names start with
Howie. - Howie never edits your server's name, settings, roles, channels or other AutoMod rules.
- If you'd rather not grant it, uncheck it when you add Howie. Everything except AutoMod keeps working, and
/setupnotes that AutoMod is off.
Message Content access
Separate from server permissions, Discord must approve Howie to read message text and attachments. This is called the Message Content intent. Howie uses it only to check messages for scams. It does not store messages that aren't scams. See the Privacy Policy for details.
What Howie never does
- Ask for Administrator.
- Delete channels, roles or your server.
- Prune members or ban people in bulk.
- Send direct messages to your members.
- Act on members whose roles are above Howie's role.
Howie's code blocks those requests before they reach Discord, so a bug can't trigger them.
Role position matters
Having a permission isn't enough on its own. Discord only lets Howie ban, kick or give timeouts to members whose highest role is below Howie's. See role positions.