September 2026 update: bot memory rebuilt, Wordle in French, Invite Guard, team roles, webhooks and more

September 2026 update: bot memory rebuilt, Wordle in French, Invite Guard, team roles, webhooks and more

Here's everything that shipped since the August wave. The Discord post in #updates has the short version; this is the full one.

Bot memory & assistant

Six ways for the bot to remember, all built now. A server picks a memory type on the AI Responses page: Classic, the plain list it always used; Journal, where a fact the bot decides is no longer true is retired rather than deleted — it stays visible, struck through, with the date and the fact that replaced it, and a one-click Restore; Searchable archive, where the bot can ask "search memory: Paul's birthday" and get an answer even for facts that were never in its default context; Ranked, which scores every candidate fact on age, importance and relevance to the current conversation instead of always picking the most recent; Consolidated, an automatic pass that runs while your server is quiet and proposes merges for duplicate or contradictory facts — nothing is written until you approve each one, and contradictions are always left for a person to settle; and Semantic, which matches facts by meaning instead of shared words, so "the server language is French" and "it speaks French" are recognised as the same thing. Switching between the first five types costs nothing and needs no migration; moving to Semantic runs a one-time embedding pass over your existing facts first. Each type's page shows a dry run on your own data before you switch.

Deleting a fact also works properly now: the bot can only erase a fact it was actually shown by its number in that exchange, and a made-up number touches nothing. And a security fix closed a gap along the way — adding, editing or deleting a memory used to need only permission to view the server; all four write actions now require permission to configure it.

The graph assistant edits your setup instead of replacing it. It used to answer with a full replacement graph, and on a long one that meant it could quietly drop branches it forgot about. It now sends only the changes — add this card, change that field, connect these two — so anything an operation doesn't name is carried through untouched. A review window lists every addition, every changed field with its old and new value, and every removal before anything is applied; a proposal that would change nothing says so. You can keep several separate conversations instead of one shared thread per team, and Ask again puts your last question back in the box instead of making you retype it. When the model still answers with a full graph on the rare occasions that happens, that path stays honoured — but it's now labelled clearly in the thread and in the review window, so you know to read it.

A second assistant reads your feature configuration. On the settings page for any feature, it can explain what a setting does, what it currently holds, and what to change to get the behaviour you want — including telling you plainly when a feature isn't switched on at all. It names your channels and roles rather than raw Discord IDs, and any key or secret reaches it already masked. It reads, explains and proposes; applying a change is still a click a person makes. A Review changes button shows the before and after for every setting it suggests, a setting already at the suggested value is marked as such rather than shown as a change, and a proposal is recalculated against whatever the setting holds right now — so it can never silently overwrite something a teammate changed in the meantime. Applying goes through the same checks and the same activity-log entry as the settings form itself, under your name.

Both assistants can now point at your own model. Team settings accept any OpenAI-compatible endpoint published on a public address, and the model itself is picked from a list fetched from that endpoint rather than typed by hand. The same rule now applies everywhere a feature asks you to pick a model, including AudioToText transcription, which used to be locked to a single fixed model. To be clear about something said before: the team settings page used to say you could point the assistant at a model running on your own machine. That was wrong — the panel runs elsewhere and can never reach an address on your own network — and the wording has been corrected everywhere it appeared.

A handful of smaller assistant fixes landed alongside all this: it retries automatically when a proposal is rejected, with up to two more attempts you can watch happen; a finished conversation can be deleted; a rejected batch of edits now shows the reason and the retry button instead of nothing; and it stopped replying to its own messages for good, in both AI chat features — a setting you can still switch back on if you want that behaviour.

Each assistant conversation also carries two switches now, under the gear icon in the chat window and set per person rather than per team: one includes your server's feature inventory in what the assistant sees (on by default), and the other includes the memory notes the bot has built up about whichever server you're currently viewing (off by default, and limited to facts about the server itself).

Games & rewards

Wordle now has a second language. French joins English as a full daily word, not a translation of the same one — each language has its own word, its own streaks and its own leaderboard, and nothing changes for a server that does nothing. A server already known as French on Discord gets the French word automatically; you can also set the language by hand, and switching starts a separate game so nobody's streak is thrown away. Opening a French game switches the on-screen keyboard to AZERTY; typing an accented letter is treated the same as the plain letter beneath it, because that's how the word list itself is spelled. The word list itself comes from two open sources — Lexique 4.00 for which words people actually use, and the hunspell-fr dictionary for which words exist at all — with full credit shown in the game window. The list of possible answers is filtered to keep out slurs and violent or sexual words on purpose; those words are still accepted as valid guesses, because the game shouldn't tell you a real word isn't one. The bot's own messages around the game stay in English for now — only the word and the in-Discord activity window are French.

Voting for the bot can boost XP. A new per-server switch in Leveling rewards a member who has voted for YAWBDB on top.gg with a temporary XP boost while that vote is active. It's off everywhere until a server owner switches it on, and no command is ever locked behind a vote. A weekend vote on top.gg counts double, and that doubles the bonus itself rather than tripling it outright — a 1.5× boost becomes 2.0× on a weekend vote, so one weekend vote never outweighs a month of steady voting. /boosters shows a member the running boost and when it ends.

Security & moderation

Invite Guard hands back control over who can create invites to your server. You list the roles — and, if you want, specific members — allowed to create one; anything created outside that list is removed the moment it appears, with the code, the channel, the creator and the reason all written to your log. Nobody locks themselves out by turning it on: the bot, the server owner, anyone who can manage the server, and any app you've authorised keep the right by default, and you can withdraw each exemption individually. Discord's own automatic invites — the server widget and Server Discovery — are recognised and left alone rather than fought over every few minutes, and you can put entire channels out of reach as well. If several invites get removed inside the same minute, the bot stops and tells you where to look instead of looping.

Honeypot traps grew beyond channels. Alongside a trap channel, a decoy role placed next to your real self-assignable ones now catches an account that clicks everything it can find, and a decoy invite placed somewhere only a scraper or a raid list would find it catches whoever uses it before they've said a word. A staff member manually handing out the decoy role is recognised and logged separately rather than treated as a catch — when the bot has permission to view your server's audit log; without it, every assignment counts as a trigger, and the settings page says so plainly. When the bot genuinely can't tell which invite was used — two people joining at the same instant, say — it sanctions nobody and says so in your log rather than guessing. Enough trap trips inside the same window can now trigger an Anti-Raid lockdown if you have Anti-Raid switched on — the cascade itself is off by default — catching slow raids that come in just under the door's own arrival threshold but still walk into the same decoy.

Teams & activity log

Teams compose their own roles. The three fixed roles are gone as the only option: name your own, describe them, and tick exactly what each one can do — see servers, configure, enable or disable features, moderate, remove a server, delete appeals, use the assistant, or manage roles themselves. Nothing changes for anyone on an existing role, and the built-in Administrator, Editor and Moderator roles keep doing what they always did. Permissions are enforced, not just suggested: nobody can grant a permission they don't hold themselves, nobody edits the role they're currently wearing, and a role still worn by someone — including a pending invite — can't be deleted. Every role change and every move of a member between roles now lands in the activity log with a before and after.

Outgoing team webhooks let a team's activity log push itself to a server you control, signed and verified, the instant each subscribed event happens — no polling, no export, no scraping a page. What a webhook carries is exactly what the log page shows and nothing more; your IP address is never included, and secrets are always shown as redacted on both sides of a before/after. Every delivery is signed with HMAC-SHA256 over the timestamp and the exact body, the secret is shown once and never again, and a stable delivery ID stops the same event being counted twice across retries. Up to three endpoints per team, automatic shutoff after 20 consecutive failures (re-enabling resets the count), and the last 20 attempts are visible with their status, timing and a snippet of the response. Destinations inside a private or internal network are refused, both when you save the endpoint and again before every send, and redirects are never followed. Sign-ins and other account-level events are deliberately left out of what can be sent — showing them on a page you had to open is one thing, pushing them to a third-party server unattended is another.

The activity log finally records what your staff actually decides. Accepting or rejecting an application, deleting responses, sanctioning a member, rewriting a sanction's reason, clearing someone's history, and changes to automod rules, custom commands, embed templates, giveaways, Reaction Roles messages, scheduled messages, social alerts, birthdays, suggestions, levelling settings and the reward graph — all of it now leaves a trace, where large parts of it left none before. Moderation decisions get their own category rather than sharing one with settings changes, and sanctioning a member directly from a report — previously the one sanction path with no log entry at all — is covered too. Two gaps in Server Logs were closed alongside this: channel-permission changes for a role or a member (who can and can't do what, in a specific channel) and a server changing owners, along with the content filter, the moderation 2FA requirement, and the AFK/system/rules/moderator channels. Entries name channels and roles instead of raw IDs, and only fields that actually changed are listed — saving a form untouched no longer writes a misleading entry.

The panel itself

Works on a phone. Tables that used to lose their useful columns off the edge of a small screen now fold into cards, the wiki's sidebar collapses behind a button, and moderation controls no longer sit on top of member names.

Install it like an app. On Chrome or Edge, an "Install App" entry in the account menu adds the panel to your desktop or Android home screen with its own window and its own icon — the hamster the bot already wears on Discord. It's never pushy: no banner, nothing that opens itself, just one line in a menu you can ignore, and it disappears once you've installed. There are no notifications and nothing beyond what the site already does today. The browser tab icon and the icon used when the panel is added to a home screen — both broken for months — are fixed at the same time.

A face for YAWBDB. The bot's name is now written with six hamsters, one per letter, across the navigation bar and every sign-in screen, and the browser tab carries a drawn portrait instead of a stock photo.

Sanction buttons and role badges are easier to read. The five sanction action buttons used to mix light-text-on-pale and white-on-strong styling, with one colour that looked disabled; all five are now consistent, with contrast measured rather than eyeballed, in both light and dark mode. A member's roles used to print as solid colour blocks; the colour is now a small dot next to the role name in normal text, so a member with several roles is still easy to read.

Faster, and it says so while it loads. A thin loading bar now shows while a page is on its way in, and it clears itself the moment the page appears (or a safety fallback kicks in). Separately, the icon font that every page used to wait on — even pages with no icons — is now loaded only where it's actually needed, which noticeably speeds up the first pages people land on. And the brief unstyled flash that used to show on wiki and public pages before the page's styling caught up is gone.

Dates and numbers follow your chosen language, everywhere in the panel, instead of a mix of rules that disagreed from one screen to the next. A member card that failed to open in the sanction history now opens correctly too.

Fifteen of the emails the panel sends — from address verification to ticket and report notifications — now arrive in the recipient's own language, across all 13 languages the panel supports, rather than defaulting to English. Team invites are the one exception: they still follow the language of whoever sent the invite.

Fixes

  • Scheduled messages — deleting, disabling or rescheduling one now takes effect immediately; the send is refused server-side right up to the moment it would have gone out, instead of an already-queued message slipping through.
  • Automod text fields — the "one per line" pattern, domain and anti-scam lists finally accept the Enter key to start a new line.
  • Forms — a form is now offered and listed by its title instead of a slash command that didn't exist.
  • Dashboard notice — the banner explaining that a server card doesn't show every feature is now placed where people actually read it, and says where the rest is.
  • Text-commands reference card — corrected: it no longer claims two features open a pop-up when they don't, and now lists the commands it previously left out entirely.
  • Reaction Roles list — was showing raw Discord IDs for channels and roles instead of their names.
  • Feature settings — a rejected save now shows why, instead of the page silently doing nothing; a setting saved as zero or switched off no longer reverts to blank on reload.
  • Panel error messages — a round of fixes reworked how the panel surfaces errors to you.
  • Wordle solved on the first guess now shows the live grid in the channel, instead of the rarest result being the one nobody got to see.
  • Trigger prestige is now available in custom command graphs, not just the reward graph.
  • Turning Counters off now actually stops the channel renames it was supposed to switch off.
  • Reward messages on cross-feature triggers — a giveaway win, a Wordle solve, a birthday, a form submission or a mini-game win could send a message with a broken mention and blank values; corrected.
  • Long announcements notify again — past a certain length the notification used to fail silently.
  • Opening a wiki page no longer marks it as edited, so a page you only read stops announcing itself as just updated.