Discord Manager

Discord Manager is a Strands-powered private control plane for operating one Discord community without turning every message into an instruction.

It is built for volunteer moderators, community managers, creators, and small teams who need help turning noisy community activity into safe, reviewable actions. The core problem is authority: a public AI bot that treats member content as commands is unsafe, while a passive assistant that cannot verify or control effects is not much of an operator.

How it works

Discord Manager separates community observation from operator authority.

An authenticated operator MCP client or CLI enters the control plane. A real Strands runtime can reason about community state through bounded tools, while deterministic code owns Discord REST calls, guild scoping, proposal signing, expiry, approval, claim-before-effect, and audit recording.

The internal agent surface can inspect and propose, but it cannot approve its own proposal or rewrite the machine-owned trust policy.

The current runnable release demonstrates a narrow but real control loop:

  • inspect the configured Discord guild and channels through typed Discord REST operations;
  • create signed, expiring PROPOSE records;
  • approve the supported typed send_message action from the authenticated operator surface;
  • claim approval durably before the external effect so concurrent approvals execute at most once;
  • record proposal transitions in a private append-only audit file;
  • run Strands reasoning through the shared runtime bridge;
  • expose separate internal-agent and operator MCP surfaces;
  • provide an installer, token-safe doctor, and loopback-only HTTP dashboard.

Why it matters

Community operations are full of repetitive, judgment-heavy work: reading activity, identifying what needs attention, deciding whether an action is appropriate, and then carrying it out safely. Discord Manager lets an agent help with that work while preserving a hard boundary between what the community says and what the operator authorizes.

It is intentionally not a public AI chatbot with moderator powers.

Bounded by design

  • Ordinary Discord messages are untrusted observations by default.
  • One running configuration operates exactly one configured guild.
  • Reads and mutations are checked against that guild before reaching Discord.
  • OBSERVE, PROPOSE, and OPERATE are deterministic policy outcomes.
  • Proposal tokens are signed, expiring, and claimed before an effect.
  • The internal agent MCP cannot approve proposals.
  • Discord ingress cannot rewrite trusted-controller configuration.
  • Audit actors are derived by the control surface rather than supplied by callers.
  • The daemon remains loopback-bound; remote access belongs behind authenticated HTTPS infrastructure.

Strands

Strands is the reasoning and orchestration layer. The product deliberately keeps the model away from raw Discord mutation. The model sees bounded typed capabilities; deterministic product policy decides what may be observed, proposed, approved, or executed.

Hackathon fit

Discord Manager targets the Professional Agents track. It makes community operators dramatically better at repetitive, judgment-heavy work they already do while keeping consequential authority explicit and reviewable.

The public repository includes source code, setup instructions, an MIT license, styled architecture and safety diagrams, a demo runbook, validation instructions, and the hackathon evidence boundary.

Visual architecture

System architecture

Community Agent system architecture

Safety and authority boundary

Community Agent safety boundary

Detailed Discord Manager architecture

Community Agent detailed architecture

Built With

Share this project:

Updates

Submission history