Time CapsuleUser handbook
Product siteOpen portal

Server owners

Set the policy. Share only the controls.

Install the app, choose the Discord and portal access boundary, establish destinations and safety policy, run a private acceptance test, then give members and moderators the guide that matches their role.

Discord server ownerInstallation + governancePlan management

Install

Add Time Capsule to the intended server.

  1. Open the official installation flow

    Input: Use the product site’s Add Time Capsule to Discord button. If you are already in a server with the bot, anyone can run /invite to retrieve the same official install route; the person completing installation needs Manage Server.

    Expected result: Discord opens an authorization screen naming Time Capsule and asks which server to install it in.

  2. Select and verify the server

    Input: Choose the intended server, review the requested bot/application-command permissions, and approve only if the app and server are correct.

    Expected result: Time Capsule joins that server and its slash commands become available after Discord completes command registration.

  3. Place the bot role for the channels you permit

    Input: In Discord server settings, make sure the Time Capsule role can view and send in the announcement, delivery, test, and staff-alert channels you intend to select. Keep it below roles it should not manage.

    Expected result: The bot can post in approved destinations without gaining unrelated server authority.

Least privilege: Grant only the Discord permissions and channel access required by the workflows you actually plan to use. Do not give the bot Administrator solely to bypass a failed configuration check.

Invite-use unlocks: The normal /invite installation link does not request Manage Server/Manage Guild for the bot. If you intentionally use the Plus invite-code condition, separately grant that bot permission so it can read invite-use data; do not grant it for unrelated workflows.

First configuration

Complete setup before public use.

The Discord setup route is available only when the server’s guided_setup feature is enabled. If the command says guided setup is unavailable, use the portal route or contact the server’s Time Capsule administrator.

  1. Run the guided setup

    /timecapsule setup

    Input: Choose a capsule/announcement channel, optional moderation-alert channel, language, Standard/NSFW moderation mode, audit setting, and media setting; then Finish.

    Expected result: The private setup controls are replaced by a localized ready message and completed summary. Select the main channel before Finish—setup currently records completion without it, but later sealing will fail.

  2. Review the full portal configuration

    Input: Sign in at platform.cuffdev.team/login, select the server, then review Server settings, Channel management, Safety, and Appearance.

    Expected result: Delivery/default settings, per-channel rules, staff roles and safety controls, and Discord-visible branding all match your policy or clearly show an entitlement requirement. From /timecapsule configure, All server settings returns to this server’s Delivery & media settings even when Discord sign-in is required first.

  3. Write down the server policy

    Input: Record who may create, which channels may receive, how files/anonymity are handled, who reviews reports, how long records are kept, and who owns billing/support follow-up.

    Expected result: Members and staff have a single policy to apply when the bot or portal asks them to choose.

The exact control-by-control sequence is in Setup & configuration.

Staff access

Delegate with a dedicated management role.

  1. Create or choose the staff role

    Input: In Discord, create a role such as Time Capsule Moderator and assign it only to staff who need these controls.

    Expected result: You have a narrow role that does not require granting broad Discord permissions solely for Time Capsule.

  2. Map the role from Discord or Safety

    /timecapsule configure

    Input: With Manage Server, open configuration and select up to 10 management roles, or manage portal roles in Safety.

    Expected result: The saved roles appear in the private panel/Safety view. Changing role access itself remains restricted to Manage Server.

  3. Test as one designated moderator

    Input: Ask a role holder to sign in to the portal and choose this server.

    Expected result: They see this server and their intended controls. Selecting a server triggers a fresh authorization check; an unrelated server should not become visible through this role.

  4. Remove access when duties change

    Input: Remove the Discord role from the person or remove the role mapping, then ask them to refresh or sign in again.

    Expected result: Current authorization no longer grants that server through the removed role.

Owner and moderator shortcuts

Keep management commands inside the approved role boundary.

Command Who can use it Expected result
/timecapsule portal Server owner or configured management role Opens this server’s moderator-portal Home page directly, preserving the destination through Discord OAuth.
/timecapsule upgrade Server owner or configured management role Shows this server’s eligible Discord purchase controls.
/timecapsule vault Server owner or configured management role; active Plus and the platform Vaults feature are required Opens the menu-driven vault manager.
/timecapsule version Available as a read-only runtime check Shows version, build, changelog, tier, and subscription status without exposing the internal billing source.

Governance

Assign one owner for every decision.

Decision Recommended owner Where to configure
Default destination, timezone, attachment behavior Server owner or lead admin Server settings
Blocked/premium-only channels and overrides Lead moderator + channel owners Channel management
Portal roles, reports, alerts, filters, bans, crisis destination, logging Safety/moderation lead Safety
Discord-visible bot name, description, avatar, banner Brand/community lead Appearance, when entitled
Subscription, add-on, invoice, cancellation Server owner/billing owner Plan & billing
Support request and security escalation Named operational owner Need help? → Contact support

Appearance is Discord-visible: Custom name, description, avatar, and banner settings change the selected server’s bot profile when the entitlement is active. Preview and verify them in Discord after saving.

Collaborative vaults · Plus

Give several capsules one shared release policy.

Use the menu-driven /timecapsule vault flow for quick creation and management, or open Vaults in the moderator portal for contributor roles, destination, unlock settings, and the timezone choice: Server default (showing the current server timezone) or UTC.

Vaults use the same opening events as capsules. Staff can post Create capsule and Quick contribution buttons. The Discord vault manager can move up to 25 eligible sealed server or member capsules. In the portal, Add existing capsule moves one; selecting eligible rows in Capsules and choosing Move to vault moves one or several into an existing vault or carries them into a new-vault form. Staff can also edit the vault or manually open it.

Every configured vault shows one explicit state: Entries Closed, Capsules Locked, Entries Open, Capsules Locked, or Sealed, Capsule/Vault locked.

Confirm before moving: the capsule inherits the vault’s unlock settings. Its previous event condition and backup release time are ignored after the atomic move. If one selection is invalid, none are moved.

When Vaults or a capsule type is disabled by a platform feature flag, existing data remains safe and visible with an IN MAINTENANCE notice; creation and reconfiguration remain unavailable until maintenance ends.

Reusable operations · Plus

Control Recipes, bulk transfer, and member editing.

The main Recipes tab beside Vaults stores capsule and vault templates with settings and automation. Staff may create a recipe from an existing item, export one or a selected bundle, bulk import up to 100 recipes, and retain the newest three versions. The Capsules bulk tool imports or exports at most 100 records in CSV, YAML, or JSON; start from the provided format template and review validation first.

The member-edit setting controls short-lived, one-time links to a navigation-free capsule editor. Disabling it revokes member edit access. The default channel fills only a missing destination; if an explicit channel is deleted, the capsule pauses for permission/destination review instead of falling back.

Acceptance test

Prove the path before inviting members.

  1. Seal one private test capsule

    Input: Run /timecapsule compose; choose a short time, harmless message, one staff recipient, and a private test channel that is the configured Free-plan announcement/allowed channel or another destination permitted by the server’s entitlement and Channel management policy; Preview and Seal.

    Expected result: The confirmation includes a capsule code, recipient, time, destination, and file count.

  2. Verify management and activity visibility

    Input: Open the capsule in the portal and review Overview, Content & delivery, Automation, and Activity.

    Expected result: Authorized staff can find the test and see its current lifecycle context.

  3. Unlock and confirm delivery once

    Input: Carefully run /timecapsule unlock id:CAPSULE-CODE. This direct action has no separate confirmation and is irreversible.

    Expected result: The test reveal reaches the selected destination once and Activity reflects the change.

  4. Test support and handoff

    Input: Open Need help?Contact support far enough to verify the form fields, then close it without submitting a fake case. Share the member and moderator guides in your staff resources.

    Expected result: Staff know where to submit a real request and which guide to use during an incident.

Owner-only commerce

Manage plans from the current purchase source.

  1. Review the current entitlement

    Input: Open Plan & billing in the selected server for entitlements and management controls. Separately, /timecapsule version shows the bot version/build/changelog plus tier and subscription status. It does not expose the internal billing source.

    Expected result: The portal shows current access and available management actions; the bot command provides a read-only deployment/subscription summary.

  2. Open the correct management flow

    Input: Use Manage Plan. For a Stripe subscription, use Manage Billing. For Discord-billed access, follow the Discord purchase/subscription route shown by Time Capsule.

    Expected result: Billing and cancellation remain with the source that owns the subscription.

  3. Keep receipts and verify the effective state

    Input: After purchase, transfer, add-on change, or cancellation, return to Plan & billing and refresh.

    Expected result: Entitlements, invoice/renewal details when available, and eligible controls reflect the server’s effective access.

Follow the complete Plans & billing guide before purchasing, transferring, or cancelling.

Offboarding

Remove the service in a controlled order.

  1. Resolve capsules and vaults your community must keep

    Input: Review pending capsules, delivery failures, vaults, and any retention/export needs with staff.

    Expected result: You have handled community obligations before access disappears.

  2. Stop future behavior and address billing

    Input: Pause server delivery if needed, disable relevant automation, and use Plan & billing to cancel/manage active paid access at its source.

    Expected result: No avoidable future deliveries or charges are left unexplained.

  3. Submit deletion/support needs before removal

    Input: Use Need help?Contact support with the server and relevant references. Keep the request code.

    Expected result: Support has an authenticated, server-scoped request before the app is removed.

  4. Remove the Discord app

    Input: Remove Time Capsule from Discord server settings after the preceding steps are complete.

    Expected result: The bot leaves the server and slash commands stop being available there.

Keep ownership, safety, and billing responsibilities explicit.