Security Checklist¶
Every staff member with administrative access should be able to check every box below. See Administrative Security for the full policy.
- [ ] Multi-Factor Authentication (MFA) enabled on Discord.
- [ ] MFA enabled on Steam.
- [ ] MFA enabled on any server hosting, RCON, or bot-management accounts you use.
- [ ] Strong, unique passwords on every administrative account — not reused from unrelated services.
- [ ] Passwords stored in a password manager rather than memory or plain text.
- [ ] No administrative credentials shared with anyone, for any reason.
- [ ] Administrative duties performed only from devices you trust and control.
- [ ] Operating system and security software kept up to date on those devices.
- [ ] You know how to report a suspected compromise immediately, and would do so without hesitation.
If Something Feels Wrong¶
Report a suspected compromise right away. Leadership may temporarily suspend permissions while it's investigated — this protects the community, and it is never treated as an admission of wrongdoing or a disciplinary matter.