Server owners
Set the policy. Share only the controls.
Install the app, choose the Discord and portal access boundary, establish destinations and safety policy, run a private acceptance test, then give members and moderators the guide that matches their role.
Install
Add Time Capsule to the intended server.
-
Open the official installation flow
Input: Use the product site’s Add Time Capsule to Discord button. If you are already in a server with the bot, anyone can run
/inviteto retrieve the same official install route; the person completing installation needs Manage Server.Expected result: Discord opens an authorization screen naming Time Capsule and asks which server to install it in.
-
Select and verify the server
Input: Choose the intended server, review the requested bot/application-command permissions, and approve only if the app and server are correct.
Expected result: Time Capsule joins that server and its slash commands become available after Discord completes command registration.
-
Place the bot role for the channels you permit
Input: In Discord server settings, make sure the Time Capsule role can view and send in the announcement, delivery, test, and staff-alert channels you intend to select. Keep it below roles it should not manage.
Expected result: The bot can post in approved destinations without gaining unrelated server authority.
Least privilege: Grant only the Discord permissions and channel access required by the workflows you actually plan to use. Do not give the bot Administrator solely to bypass a failed configuration check.
Invite-use unlocks: The normal
/invite installation link does not request Manage
Server/Manage Guild for the bot. If you intentionally use the
Plus invite-code condition, separately grant that bot
permission so it can read invite-use data; do not grant it for
unrelated workflows.
First configuration
Complete setup before public use.
The Discord setup route is available only when the server’s
guided_setup feature is enabled. If the command
says guided setup is unavailable, use the portal route or
contact the server’s Time Capsule administrator.
-
Run the guided setup
/timecapsule setupInput: Choose a capsule/announcement channel, optional moderation-alert channel, language, Standard/NSFW moderation mode, audit setting, and media setting; then Finish.
Expected result: The private setup controls are replaced by a localized ready message and completed summary. Select the main channel before Finish—setup currently records completion without it, but later sealing will fail.
-
Review the full portal configuration
Input: Sign in at platform.cuffdev.team/login, select the server, then review Server settings, Channel management, Safety, and Appearance.
Expected result: Delivery/default settings, per-channel rules, staff roles and safety controls, and Discord-visible branding all match your policy or clearly show an entitlement requirement. From
/timecapsule configure, All server settings returns to this server’s Delivery & media settings even when Discord sign-in is required first. -
Write down the server policy
Input: Record who may create, which channels may receive, how files/anonymity are handled, who reviews reports, how long records are kept, and who owns billing/support follow-up.
Expected result: Members and staff have a single policy to apply when the bot or portal asks them to choose.
The exact control-by-control sequence is in Setup & configuration.
Staff access
Delegate with a dedicated management role.
-
Create or choose the staff role
Input: In Discord, create a role such as
Time Capsule Moderatorand assign it only to staff who need these controls.Expected result: You have a narrow role that does not require granting broad Discord permissions solely for Time Capsule.
-
Map the role from Discord or Safety
/timecapsule configureInput: With Manage Server, open configuration and select up to 10 management roles, or manage portal roles in Safety.
Expected result: The saved roles appear in the private panel/Safety view. Changing role access itself remains restricted to Manage Server.
-
Test as one designated moderator
Input: Ask a role holder to sign in to the portal and choose this server.
Expected result: They see this server and their intended controls. Selecting a server triggers a fresh authorization check; an unrelated server should not become visible through this role.
-
Remove access when duties change
Input: Remove the Discord role from the person or remove the role mapping, then ask them to refresh or sign in again.
Expected result: Current authorization no longer grants that server through the removed role.
Owner and moderator shortcuts
Keep management commands inside the approved role boundary.
| Command | Who can use it | Expected result |
|---|---|---|
/timecapsule portal |
Server owner or configured management role | Opens this server’s moderator-portal Home page directly, preserving the destination through Discord OAuth. |
/timecapsule upgrade |
Server owner or configured management role | Shows this server’s eligible Discord purchase controls. |
/timecapsule vault |
Server owner or configured management role; active Plus and the platform Vaults feature are required | Opens the menu-driven vault manager. |
/timecapsule version |
Available as a read-only runtime check | Shows version, build, changelog, tier, and subscription status without exposing the internal billing source. |
Governance
Assign one owner for every decision.
| Decision | Recommended owner | Where to configure |
|---|---|---|
| Default destination, timezone, attachment behavior | Server owner or lead admin | Server settings |
| Blocked/premium-only channels and overrides | Lead moderator + channel owners | Channel management |
| Portal roles, reports, alerts, filters, bans, crisis destination, logging | Safety/moderation lead | Safety |
| Discord-visible bot name, description, avatar, banner | Brand/community lead | Appearance, when entitled |
| Subscription, add-on, invoice, cancellation | Server owner/billing owner | Plan & billing |
| Support request and security escalation | Named operational owner | Need help? → Contact support |
Appearance is Discord-visible: Custom name, description, avatar, and banner settings change the selected server’s bot profile when the entitlement is active. Preview and verify them in Discord after saving.
Collaborative vaults · Plus
Give several capsules one shared release policy.
Use the menu-driven /timecapsule vault flow for
quick creation and management, or open
Vaults in the moderator portal
for contributor roles, destination, unlock settings, and the
timezone choice: Server default (showing the
current server timezone) or UTC.
Vaults use the same opening events as capsules. Staff can post Create capsule and Quick contribution buttons. The Discord vault manager can move up to 25 eligible sealed server or member capsules. In the portal, Add existing capsule moves one; selecting eligible rows in Capsules and choosing Move to vault moves one or several into an existing vault or carries them into a new-vault form. Staff can also edit the vault or manually open it.
Every configured vault shows one explicit state: Entries Closed, Capsules Locked, Entries Open, Capsules Locked, or Sealed, Capsule/Vault locked.
Confirm before moving: the capsule inherits the vault’s unlock settings. Its previous event condition and backup release time are ignored after the atomic move. If one selection is invalid, none are moved.
When Vaults or a capsule type is disabled by a platform feature flag, existing data remains safe and visible with an IN MAINTENANCE notice; creation and reconfiguration remain unavailable until maintenance ends.
Reusable operations · Plus
Control Recipes, bulk transfer, and member editing.
The main Recipes tab beside Vaults stores capsule and vault templates with settings and automation. Staff may create a recipe from an existing item, export one or a selected bundle, bulk import up to 100 recipes, and retain the newest three versions. The Capsules bulk tool imports or exports at most 100 records in CSV, YAML, or JSON; start from the provided format template and review validation first.
The member-edit setting controls short-lived, one-time links to a navigation-free capsule editor. Disabling it revokes member edit access. The default channel fills only a missing destination; if an explicit channel is deleted, the capsule pauses for permission/destination review instead of falling back.
Acceptance test
Prove the path before inviting members.
-
Seal one private test capsule
Input: Run
/timecapsule compose; choose a short time, harmless message, one staff recipient, and a private test channel that is the configured Free-plan announcement/allowed channel or another destination permitted by the server’s entitlement and Channel management policy; Preview and Seal.Expected result: The confirmation includes a capsule code, recipient, time, destination, and file count.
-
Verify management and activity visibility
Input: Open the capsule in the portal and review Overview, Content & delivery, Automation, and Activity.
Expected result: Authorized staff can find the test and see its current lifecycle context.
-
Unlock and confirm delivery once
Input: Carefully run
/timecapsule unlock id:CAPSULE-CODE. This direct action has no separate confirmation and is irreversible.Expected result: The test reveal reaches the selected destination once and Activity reflects the change.
-
Test support and handoff
Input: Open Need help? → Contact support far enough to verify the form fields, then close it without submitting a fake case. Share the member and moderator guides in your staff resources.
Expected result: Staff know where to submit a real request and which guide to use during an incident.
Owner-only commerce
Manage plans from the current purchase source.
-
Review the current entitlement
Input: Open Plan & billing in the selected server for entitlements and management controls. Separately,
/timecapsule versionshows the bot version/build/changelog plus tier and subscription status. It does not expose the internal billing source.Expected result: The portal shows current access and available management actions; the bot command provides a read-only deployment/subscription summary.
-
Open the correct management flow
Input: Use Manage Plan. For a Stripe subscription, use Manage Billing. For Discord-billed access, follow the Discord purchase/subscription route shown by Time Capsule.
Expected result: Billing and cancellation remain with the source that owns the subscription.
-
Keep receipts and verify the effective state
Input: After purchase, transfer, add-on change, or cancellation, return to Plan & billing and refresh.
Expected result: Entitlements, invoice/renewal details when available, and eligible controls reflect the server’s effective access.
Follow the complete Plans & billing guide before purchasing, transferring, or cancelling.
Offboarding
Remove the service in a controlled order.
-
Resolve capsules and vaults your community must keep
Input: Review pending capsules, delivery failures, vaults, and any retention/export needs with staff.
Expected result: You have handled community obligations before access disappears.
-
Stop future behavior and address billing
Input: Pause server delivery if needed, disable relevant automation, and use Plan & billing to cancel/manage active paid access at its source.
Expected result: No avoidable future deliveries or charges are left unexplained.
-
Submit deletion/support needs before removal
Input: Use Need help? → Contact support with the server and relevant references. Keep the request code.
Expected result: Support has an authenticated, server-scoped request before the app is removed.
-
Remove the Discord app
Input: Remove Time Capsule from Discord server settings after the preceding steps are complete.
Expected result: The bot leaves the server and slash commands stop being available there.