Skip to content

Security Checklist

Every staff member with administrative access should be able to check every box below. See Administrative Security for the full policy.

  • [ ] Multi-Factor Authentication (MFA) enabled on Discord.
  • [ ] MFA enabled on Steam.
  • [ ] MFA enabled on any server hosting, RCON, or bot-management accounts you use.
  • [ ] Strong, unique passwords on every administrative account — not reused from unrelated services.
  • [ ] Passwords stored in a password manager rather than memory or plain text.
  • [ ] No administrative credentials shared with anyone, for any reason.
  • [ ] Administrative duties performed only from devices you trust and control.
  • [ ] Operating system and security software kept up to date on those devices.
  • [ ] You know how to report a suspected compromise immediately, and would do so without hesitation.

If Something Feels Wrong

Report a suspected compromise right away. Leadership may temporarily suspend permissions while it's investigated — this protects the community, and it is never treated as an admission of wrongdoing or a disciplinary matter.