Philosophy Architecture Threat Model Security & Identity Roadmap FAQ
Web Control Plane v1 · Foundation Active

Discord administration,
outside Discord.

MMS establishes a web-first identity and security control plane for Discord communities. Enforce passkey step-up authentication, maintain strict cryptographic session isolation, and preserve immutable audit records—independent of Discord account compromise.

Web-First Control Plane Isolated browser boundary
WebAuthn / Passkeys Hardware token verification
Step-Up Authentication Re-auth for sensitive actions
Structured Audit Trail Immutable security ledger
console.mms.gripe / tenant: guild_ops_main
Session Active (Operator)
Perimeter Governance
Enforced
WebAuthn Step-Up Policy Trigger: Elevated role modification
Hardware Required
Direct In-App Execution Direct Discord client admin bypass
Blocked (Fail-Closed)
Session Boundary Cryptographically bound token
Active
Interactive Proof: Test step-up verification
Tamper-Evident Audit Ledger
Streaming
session.auth (FIDO2 ceremony) 12:11:04 · PASSED
tenant.verify (guild_ops_main) 12:11:05 · ISOLATED
policy.evaluate (admin.read) 12:11:18 · ALLOWED
Product Philosophy

Critical administration belongs in a dedicated control plane.

Discord is architected for real-time interaction, voice chat, and social collaboration. When destructive administrative authorities reside solely inside the messaging client, a compromised user account or leaked session token results in immediate guild takeover.

Traditional Bot Model

Discord-First Risk
  • Single Point of Failure: Discord session theft grants full bot administrative command access.
  • No Out-of-Band Verification: Sensitive deletions execute instantly without independent cryptographic hardware confirmation.
  • Transient & Ephemeral Logs: Audit entries can be purged or obscured inside Discord chat channels.

MMS Platform Model

Web-First Security
  • Strict Perimeter Isolation: Discord handles user interaction; the Web Control Plane governs policy, authorization, and destructive actions.
  • Hardware-Bound Passkeys: FIDO2 / WebAuthn step-up ceremonies block unauthorized commands even if the Discord password or token is stolen.
  • Tamper-Evident Audit Trails: Every administrative change records actor identity, verification method, exact timestamp, and outcome.
Boundary Architecture

The Four-Tier Security Boundary

MMS decomposes community management into strictly separated responsibilities: interaction, control, decision, and execution.

TIER 01 · SURFACE

Discord

The community interaction surface. Handles user presence, messages, events, and raw slash command requests.

Domain: discord.com
Responsibility: Interaction
TIER 02 · GOVERNANCE

Web Control Plane

Out-of-band administration dashboard. Passkey authentication, administrator role assignments, and step-up authorization.

Domain: console.mms.gripe
Responsibility: Control
TIER 03 · CORE

Policy Engine

Centralized authorization engine. Evaluates tenant isolation, verifies cryptographic session proofs, and logs immutable audit records.

Domain: Internal API / DB
Responsibility: Decision
TIER 04 · WORKER

Discord Agent

Headless execution worker. Receives signed dispatch jobs from the Policy Engine and applies approved actions via Discord API.

Domain: Isolated Worker Runtime
Responsibility: Execution
Threat Containment

Discord account compromised ≠ Control plane compromised

In standard environments, an attacker who steals an administrator's Discord session token immediately wields full destruction capabilities. MMS isolates the administrative root.

Traditional Bot Incident

Critical Failure
1

Discord Session Token Exfiltrated

Attacker steals Discord authentication token via malicious client extension or infostealer.

2

Attacker Impersonates Admin

Attacker sends slash commands or direct messages pretending to be the legitimate administrator.

3

Direct Bot Execution

Bot verifies only Discord user ID. Roles deleted, server purged, audit channel deleted.

MMS Contained Incident

Attack Mitigated
1

Discord Session Token Exfiltrated

Attacker compromises the administrator's Discord client session.

2

Attacker Accesses Control Plane

Attacker visits MMS Control Plane but lacks the physical hardware passkey (FIDO2 / Touch ID).

3

Step-Up Challenge Fails Closed

Without hardware signature, destructive command is rejected. Incident logged in audit ledger.

Foundation Primitives

Security Architecture by Design

MMS is built on modern web security primitives rather than legacy bot permissions. Every tier enforces explicit authorization and verifiable trust boundaries.

Passkey / WebAuthn Only

No shared passwords or SMS codes for administrator governance. Administrative accounts authenticate through hardware-bound cryptographic keys.

Primitive: FIDO2 / WebAuthn Level 3

Step-Up Re-Authentication

Destructive mutations—such as role elevation, policy revocation, or scope re-assignment—require explicit step-up hardware confirmation.

Primitive: Timed Challenge Nonce

Tenant Isolation

Every guild operates within strict multi-tenant database row-level security and isolated encryption scopes. No cross-guild leakage is possible.

Primitive: Scope & Tenant Boundaries

Tamper-Evident Ledger

Every administrative interaction produces a structured audit record containing identity, scope, client proof, and decision outcome.

Primitive: Structured Audit Evidence

Fail-Closed Authorization

If any verification signal fails—invalid nonce, expired session, or unconfirmed hardware ceremony—the system immediately defaults to denial.

Primitive: Zero-Trust Decision Engine

Server-Side Session Store

Administrative sessions are cryptographically signed and stored server-side. Immediate revocation is guaranteed on anomaly detection.

Primitive: Revocable State Tokens
Auditability

Forensic Evidence, Not Just Logs

Auditability requires structured answers to who, what, where, when, and result. MMS captures cryptographically verifiable event records for forensic analysis.

TIMESTAMP (UTC) TENANT ACTOR ACTION VERIFICATION DECISION
2026-10-02 03:14:22 guild_prod_core operator_admin_01 roles.update_policy WebAuthn (Touch ID) ALLOWED
2026-10-02 03:12:09 guild_prod_core operator_admin_02 auth.step_up_challenge Hardware Token UV VERIFIED
2026-10-02 02:58:45 guild_prod_core unknown_client guild.purge_channels Missing WebAuthn Nonce DENIED (Fail-Closed)
2026-10-02 02:44:11 guild_prod_core operator_admin_01 session.create Passkey Authentication INITIALIZED
Honest Engineering Roadmap

Current Capability & Platform Progression

We distinguish clearly between verified foundational software, modules in active development, and planned capabilities. No inflated statistics or fake availability claims.

Core Foundation Available
  • Web Control Plane
    Out-of-band administration dashboard isolated from Discord messaging clients.
  • Passkey / WebAuthn Authentication
    Hardware security token and biometric verification for operator access.
  • Step-Up Re-Authentication
    High-risk administrative mutations require cryptographic challenge confirmation.
  • Administrator Governance
    Centralized multi-admin assignment and granular permission scoping.
  • Structured Audit Logging
    Immutable evidence trail recording identity, action, and verification method.
Discord Integration In Development
  • Headless Discord Agent
    Isolated worker applying approved administrative decisions via Discord API.
  • Cryptographic Dispatcher
    Queue-bounded job execution verified by policy engine signatures.
  • Agent Health & Liveness
    Real-time gateway connectivity status and fail-safe worker monitoring.
Security & Recovery Planned
  • Member Verification Service
    Web-based onboarding and identity verification hosted at verify.mms.gripe.
  • Guard & Anti-Raid Policies
    Automated join-rate throttling and mass action mitigation rules.
  • Server State Snapshots
    Scheduled backup of roles, permissions, and channel structures.
  • Disaster Recovery Engine
    One-click restoration of compromised server states from signed snapshots.
Trust Principles

Engineering Principles, Not Marketing Badges

We don't manufacture vanity security scores or unverified certification logos. Trust in MMS is grounded in architectural rigor and verifiable constraints.

Least Privilege

Every subsystem and user operates with only the minimum privileges required to execute its explicit purpose. No catch-all permissions.

Fail-Closed Default

Whenever verification data is incomplete, ambiguous, or expired, execution is halted immediately and logged as denied.

Out-of-Band Control

Administrative authority never terminates within the Discord chat application. Control planes and messaging surfaces are strictly segregated.

Cryptographic Authentication

Passkeys backed by hardware authenticators prevent credential theft, phishing, and man-in-the-middle session cloning.

Tamper-Evident Evidence

Audit logs are immutable ledgers. Neither guild administrators nor external clients can delete historical operational trails.

Zero Plaintext Passwords

MMS does not store administrator passwords. Authentication is handled natively through standard public key cryptography.

Technical Questions

Frequently Asked Questions

Direct, technical answers about architecture, security boundaries, and roadmap status.

Is MMS a Discord bot?
No. MMS is a web-first identity and security platform with a dedicated headless execution agent. Unlike conventional Discord bots whose control surface lives inside Discord chat channels, MMS administration occurs strictly outside Discord via a secure web control plane.
Why is administration web-first instead of inside Discord?
Account takeover is the primary threat vector for Discord servers. When administrators manage permissions inside Discord, a stolen session token grants immediate catastrophic control. Moving administration to a dedicated web control plane backed by FIDO2 passkeys breaks this dependency: compromising a Discord account does not compromise the server's control plane.
Does MMS require server members to have the Discord "Administrator" permission?
No. In an MMS-governed community, administrators do not need to hold dangerous native Discord administrator permissions on their accounts. Administrative changes are initiated in the Web Control Plane, authorized by the Policy Engine, and executed by the MMS agent with strict step-up checks.
Does MMS use passwords?
No. MMS employs a passkey-first authentication model (WebAuthn / FIDO2). Access relies on cryptographic public key credentials bound to hardware security keys, Touch ID, Face ID, or platform authenticators. No administrator passwords exist to be leaked, phished, or brute-forced.
What happens if an administrator's Discord account is compromised?
The attacker cannot control MMS. Because administrative actions require passkey authentication and step-up verification on the web control plane, the attacker cannot delete roles, ban members, or alter policies using only the compromised Discord token.
Are Guard and Recovery features available today?
Not yet. The foundational Web Control Plane, Passkey Authentication, Step-Up Verification, and Audit Logging are complete and active. The Discord Agent execution boundary is currently in active development. Guard, anti-raid heuristics, and snapshot disaster recovery are scheduled on the roadmap.
Infrastructure Rollout

Architected for Mission-Critical Discord Communities

The MMS Web Control Plane is provisioned for select administrators. Access console status, documentation boundaries, and phased deployment updates.