Hosting: Barkeeps and Barowners

For the people who run a bar: what the tiers mean, what each mark and tool does, how to direct Harry, how to handle a bad night, and what the settings screen covers. The install guide has the full permissions table; this is the working manual.

The ladder

Six tiers, low to high: guest (in the Discord server but without the member role; can't come in unless the room says so), member (anyone in the server: talks, whispers, paints when allowed, plays), barfly and clotheshorse (roles a server hands to regulars; they change nothing on an ordinary night but keep those people talking when the floor is raised, and clotheshorses may bring new pictures in), barkeep (handles the room and directs Harry; wears a gold ✱), barowner (runs the place; ✱✱; the server owner and Administrators are barowners regardless). Which Discord role names count as each tier is set per room, on the Permissions tab or in the room file. A tier's own name always counts. A blessing raises one person by hand, whatever their roles say.

The mark is drawn in its own face and stripped from typed names, so nobody can fake one; a barkeep may take theirs off with /hidebadge on if they hold hide_badge. To see the bar as a lesser tier sees it (the controls a member gets, what the picture rules do to them, how Harry treats them), a barowner types /spoof member (or guest, barfly, clotheshorse, barkeep) and is one, to the room, to Harry and to the settings, until /spoof off or a click on the striped posing as tag in the top bar. The disguise follows you between rooms and across reloads. Nothing a poser can't undo is allowed to land: a gag, a ban, a picture ban from the house rules, or a raised floor that would show a member the door, all just take the disguise off (the punisher is told so; the audit log records the pose, the truth and why it came off). Needs status_spoof, which the pose can never hide. The "who is this" line at the top of anyone's menu shows their Discord name even when they go by an alias.

Who may do what

Nothing is tied to a tier by name. Every ability is a flag with a lowest tier that holds it, shown as a grid on the Permissions tab, and a barowner can move any row up or down. Everything on that tab is the house's: one set of roles and permissions for every room on the server (the main room's file is the baseline). The floor raises every member-default flag at once, in every room (/floor barfly): the nuisance-night switch. It wins over any row set below it (a row set higher still holds), so a room opened to guests closes with it; the tab's Floor box and the typed floor are the same switch. The house's own tools never land on a barowner: automoderation's gag, ban or picture stop on one is written to the log as spared instead (nobody could pardon them, not even themselves), and a barowner can't be banned by hand either. Rows that hand one of the house's tools to a tier below barkeep show in red on the tab. A grant gives one person one flag regardless of tier (a barkeep who may gag but not ban), from the People tab; you can only hand out what you hold. Punishments (a gag, a ban) are subtracted last, so a grant never undoes one.

The flags, by who has them out of the box:

TierFlags
memberenter, room_talk, room_dms, talk_to_ghosts, wear_custom_avs, rename_self, transport_self
clotheshorseload_new_avs
barkeepcommand_ghosts, handle_room, paint_always, ban_props, transport_people, announce, put_out, mark_bots, room_authoring, manage_moderator_settings
barownergag_people, ban_people, bless_people, set_floor, pause_preview, voice_of_god, ears_of_god, hide_badge, status_spoof, manage_admin_settings

The rank rule governs every tool: you can't use one on someone above you, nor on an equal who holds the same tool (two barkeeps trusted with the gag can't gag each other). The barowner can rein in a lieutenant because the lieutenant is below.

Handling the room

With handle_room a barkeep works the room with the mouse. Pictures on the wall and banners: click to select (a dashed frame with corner handles; clicking a picture never moves you), drag to move, drag a corner to size, Delete or the × to take it down, drag it out of the picture to bin it; /next picture and /previous picture cycle the search's other candidates. Harry, Ratbot and the test puppets can be dragged where you like; each room remembers. Loose props: /clear props clears the floor. With paint_always you paint outside a game and can wipe the board. With ban_props, Take that picture off them on a wearer's menu strips it from everyone and bans it. The full prop rules are in Avatars and Props; every command in Commands.

Directing Harry

With command_ghosts, your requests to Harry are orders rather than questions: banners, signs, badges, the word-swap gag, pictures from the web (find a picture of…, or paste an address), clearing the floor, walking him about, and games: trivia, Pictionary, Wheel of Cheese, with a scoreboard, timer, dice and polls the bar keeps honest. And rooms: Harry, take us all to the armory takes everyone there at your word (you need transport_people, which barkeeps have; and he moves the whole room only when you say "all" or "everyone", otherwise only you), he's there too, and he knows why you came; Harry, let's all go back to the bar brings everyone home. Harry, let's play chess is a macro, a phrase mapped to a command (on the Harry tab: a row per macro, editable, × to remove, + to add; a global list every room has, and a list for this room only that adds to it and, on the same phrase, overrides it) that runs as the speaker before he hears anything: let's play chess is goto chessboard (just you), let's all play chess is take everyone to chessboard; the defaults cover chess, checkers, backgammon and the way home, and you can add your own. A macro's command may be a web address too: open https://… offers the speaker the page (a new tab if the browser allows it, else a line with the link), goto https://… sends their tab there and out of the room. The board rooms set their own pieces up when someone comes in and finds none, and clear them when the room empties. Drawing games and Wheel of Cheese don't move anyone: Harry, whiteboard puts a board up on the wall of whatever room you're in, and so does the board up button on the paint strip (whiteboard flag, barkeeps) or typed /whiteboard up. He asks a host's consent before opening the floor for a game and remembers a yes for ninety seconds (a room setting); a yes given in one room carries to the room he took you to. Harry, stop clears his balloons and stands him down; /harry reset from Discord puts the room's furniture back (nobody is moved). /harry log shows his last hour.

Test puppets. Harry, add the test puppets brings in Franny (member), Flo (barfly) and Jacky (barkeep), three people the house drives, marked with a small bot head before the name, for trying the bar on someone who isn't you: what a member sees, who can whisper to whom, what a mute or a gag looks like from outside, how a name reads with the ✱. They are people to the room (in the tally, whisperable, punishable, blessable, draggable like Harry), and nothing they say reaches Discord or the moderation model. Harry, chat as Jacky has him answer for her (lines and whispers to Jacky come back from her head, in character) until stop chatting as Jacky; move Franny to the door walks one about; send the puppets to the beach or take everyone to the armory moves them between rooms (transport_people, as for anyone), and move the puppets here or add the test puppets brings them to you from wherever they are; remove the test puppets sends them home. They don't survive a restart, and a ban on one sticks until pardoned, like anyone's. See the quick start.

Harry is the house's ghost: the character who lives in the room, hears what's said, and answers to his name. "Harry" is only his default name. The Ghost tab of the settings screen sets, for the house, his default name (a trigger word in every room, whatever a room calls him) and, per room: his name here (over the default; a trigger word in that room); his presence, full, hosts only (he hears and answers only people who may command him, which is the quiet-Harry setting for a busy night), or absent (the same switch as /harry off); his look on the room's own picture, a ghost (a voice from a spot in the painting, no head) or an avatar (a movable head); his place; his outfit, from his right-click menu in the bar; and the 8-ball, for good, which makes this room's ghost the oracle described below from boot onward, a switch a spoken 8ball off can't undo. Harry's own budget and model live with his process, not in the bar; when his tab runs out for the day he knocks off.

A bad night

In roughly the order to reach for them:

TroubleTool
One loud person/gag Ada: they keep typing and seeing their own balloons, nobody else does, they aren't told. Often enough on its own; /ungag Ada later. With ears_of_god you still see what they say, in a typewriter face with a dashed rim.
Someone who needs to leave/ban Ada: an hour, a day, a week, or for good, with a reason kept in the log; they're shown out at once and refused at the door. Also from Discord, /harry ban, on someone who isn't in the room.
A picture that shouldn't be hereTake that picture off them on the wearer's menu (ban_props): off everyone, banned from the bar. A picture on the wall: select and Delete. Or Rate… it (the same flag): PG, R or MA; people who see up to R never see an MA one, and anything over the house's ceiling goes.
Strangers pouring in/floor barfly: only people with that role or better can come in and talk; everyone else can watch. Your regulars carry on if you gave them the role ahead of time. /floor member when it's over.
The channel's picture is embarrassing/preview off puts a black PAUSED card in Discord until /preview on.
Harry is making it worseHarry, stop; presence hosts only on the Harry tab; /harry off to drop him entirely.
Something everyone should know^^ Trivia at 8 pins a sign at the top of this room; ^^^ Big event at 7pm in every room; ^^ / ^^^ alone takes it down. It stays through games and restarts and shows in Discord.
Words you don't want to hearBlocked words on the Moderation tab come out as asterisks for everyone and are refused in names. Everyone may keep a list of their own besides (Words I'd rather not see… in the side panel), applied on their own screen alone.
A parlor trick, and a testHarry, 8ball on / off: he wears a crystal ball and answers yes/no questions from a decision model (Jev, the Keys tab's TypeSafe key) with a stock line for how sure it is; his usual mind is off meanwhile. For the evening only: a restart puts the ball away, unless the room's Ghost tab has the 8-ball, for good on, which keeps it in and makes the spoken toggle defer.
More than you can watchAutomoderation: a small model judges what's said after the fact and rates pictures before anyone sees them, and the policy table says what follows: a note, a warning, the line taken back, a strike, a gag, a ban. Two strikes in a week is a day away, by default.

Everything above is logged with who did it, to whom, and why, and punishments, blessings, grants and strikes are kept by Discord id for the whole house, so a new name doesn't shed them and a door into another room doesn't either: a ban given in the pub holds in the armory, and strikes count up wherever they're earned. /harry punished lists who's gagged or banned; the People tab shows the same and lifts them.

The settings screen

The ⚙ button in the bar, Settings… on your own menu, or /settings, opens /<room>/settings in its own browser tab, one for the whole bar: opening it again from any room brings that tab forward, on that room. The tabs come in two groups: This room (The room, Ghost, Doors) is this room's own, and The World (Rooms, People, Pictures, Permissions, Moderation, Keys) holds in every room. Three keys open them, and each includes the one before: room_authoring (the room's tabs and Rooms; barkeep by default, and a clotheshorse who builds rooms can be given it alone), manage_moderator_settings (adds People; barkeep) and manage_admin_settings (everything; barowner). What you set there is kept in the database and laid over the room file, so the file stays the install's baseline. The screen keeps its explanations behind the small ? after a label (hover, or tap; Esc closes), and each tab's first ? links back here; a number box shows its default when empty, and a ↺ beside it puts the default back. A bar at the foot of a tab says Unsaved changes until you save.

TabFlagHolds
The roomroom_authoringThe name, and the other names it answers to (Also called: the pub, the bar, home, for Harry, take us to the pub, goto pub and doors; an alias beats the built-in bar/home, which otherwise mean the first room); the room's picture, from the library (a room is one picture; changing it changes the room for everyone in it, and the picture's floor and spots come with it); the limits: capacity, paint mode, mirror to Discord, loose props on the floor and how long they stay, seconds between Harry's pictures and pictures a session, Harry's room-action budget, the consent window.
Ghostroom_authoringName, presence, look, place, and his macros. His outfit is set from his menu in the bar. With manage_admin_settings: Model and budgets, server-wide (his model, dollars a day, idle replies a day, the image model and its cap, the picture check), applied within a minute; anything left empty is what harryd's own .env says.
Doorsroom_authoringHotspots on the room's own picture, after the original's: shapes that, clicked, take people to another room (or issue any command). See Doors.
Roomsroom_authoringThe rooms on this server, and a form to open a new one.
Peoplemanage_moderator_settingsEveryone who has been in, one to a line: a dot for where they are (green in the bar, amber dozing, a ring for eyes closed in the window, none when away), their name and room, tier (with Discord's mark when their Discord roles give it, or an ↑ when a blessing here raised them above what Discord gives; Edit spells it out, and a blessing never changes anything on Discord), record (gags, bans, strikes, notes, blessings, grants) and when they were last in. It opens on everyone on now, in any room; the filter shows everyone, those with a gag, ban or strike, the blessed or granted, those who came by invitation, or the house's own (Harry, Ratbot and the test puppets, listed for knowing; a test puppet has Send home on its row for whoever holds handle_room, the same chore as Harry, remove the test puppets), narrowed by a name or a tier. Tick people to act on several at once: gag, ungag, Put out (out of the bar now and kept out for an hour, the original's kill), ban a week, unban, bless, clear the ledger. To wipe every strike in the house, show With a gag, ban or strike, tick the box at the top of the list and Clear the ledger. A moderator (a barkeep, by default) sees only the buttons for tools they hold: Put out (put_out, barkeep) but not a ban, say; grants and password links are the admin's, and a moderator can clear the ledger or invite only for tiers below their own. An admin's own row opens too, for its ledger only. A visitor that is a program gets Mark as a bot in its row (mark_bots, barkeep): an amber bot head on its name for everyone, and a bot pill here; a bot can say it of itself from its own menu. Edit opens one person's tools: the same, plus grants, the ledger and its clear button, and an invited person's password link. The server checks each person on its own: nothing works on someone above you. Invite someone makes a link for a person to come in with a name and password of their own; see Invitations.
Permissionsmanage_admin_settingsThe Discord role names for each tier (only when the integration has roles; on an install without Discord, tiers come from blessings on the People tab); the grid, one row per flag; the floor.
Picturesmanage_admin_settingsWhere pictures may come from: pasting, addresses, emoji, an allowlist of sites, the search providers in order.
Moderationmanage_admin_settingsAutomoderation for chat and for pictures, the ceiling, the blocked words, the policy table, the strike rules, the day's budget. See Moderation.
Keysmanage_admin_settingsThe Openverse key; Harry's OpenRouter key (harryd picks it up within a minute; the one in its .env is then a fallback); automoderation's own OpenRouter key, with the day's spend beside it; a TypeSafe key if Jev judges chat. Two OpenRouter keys on purpose: each can carry its own credit limit. All kept on the server and never shown again.

Invitations

For someone with no Discord account, or anyone you would rather let in by hand. On the People tab, under Invite someone, write who it is for (only you see the note), pick a tier, and press Make a link. Send the link privately: it lets one person in, once, within a week, and whoever opens it first gets in. It is shown once; the bar keeps only a fingerprint of it, so it can't be looked up again. The person chooses a name and a password (eight characters or more), comes straight into the room the link was made in, and afterwards signs in with the name and password from any browser, through Sign in with your name under the login button. A name somebody already goes by here, or one of the house's (Harry, barkeep and the like), is refused.

A tier on the link is a blessing like any other: it shows on the People tab and is changed or cleared there. You can't put a tier on a link above your own. The list under the button shows the links still waiting, with a Take back for each, and the last month's used ones with the name each became. Making one and using one both go in the audit log.

A forgotten password: find the person on the People tab (people who came by invitation carry an invited mark) and press Password link. The link sets a new password on the same name, so their tier, look and history stay; it works once, within a day, and ends every session the account had, in case someone else knew the old one. A newer link replaces an older one. You can't make one for someone above your own tier. An install with no Discord at all (INTEGRATION=local) lets people in only this way; see Without Discord.

Rooms

A bar is several rooms, and a room is one picture. Each is a page of its own (/boardroom) with its own picture, settings, limits, Harry (his name, presence, outfit and macros there), loose props, paint and pictures on the wall. People in one don't see people in another, and the Discord picture of the bar shows the bar: when Harry takes everyone to the whiteboard, the people watching in Discord see them leave. The room's picture never changes under people's feet; that was the old "change the picture" idea, and it's gone. Every bar gets the standard rooms at first boot: the boardroom (the big screen), the armory, the chessboard, the checkers board, the backgammon board, the game room and the White House, with no Discord channel of their own; npm run setup -- --standard on the host puts back any that were removed (see Install) (a room is a file under rooms/; delete the file to drop it).

People get from room to room through doors in the picture or with /goto (transport_self, members). With transport_people (barkeeps) you can /send Ada to the armory or /take everyone to the boardroom, never someone above you; and Harry does the same at your word. With room_authoring the Rooms tab opens a new one: an address, a name, a picture, and its window in Discord. Most rooms have no channel (the default): anyone in the server may come in, nothing is posted anywhere, and /palace peek room:boardroom or /harry log room:boardroom works from any channel. A room can instead have a channel of its own, made by the bot (it needs Manage Channels) or an existing one by id; then it gets a pinned picture there, and a channel only some roles can see is how a room is made private to them. The new room starts with this room's roles and permissions and is live at once; Harry joins it within a minute.

Doors

The Doors tab draws shapes on the room's own picture, much as the original's author mode did with hotspots: New door puts a rectangle in the middle; drag its inside to move it, drag a corner to reshape it, double-click an edge for another corner (up to thirty-two), Delete to take a corner away (three stay). Give it a name and pick where it leads: a room from the list, which fills in goto poolroom; a web page, leaving the room (goto https://…, in the clicker's tab) or in a new tab (open https://…, and they stay), for another server's bar, a reference page, anything with an http(s) address; or type any other command, which the click issues as if the clicker had typed it, with their own permissions (a shape on the jukebox can be play doorbell; in time, script …). Three switches: always show its frame, always show its name (otherwise both appear only when the pointer finds it, as in the original, or while anyone holds Control or types /doors, which reveals every door for a moment), and don't move the clicker onto it first. Save doors makes them live for everyone at once.

A spot can also run by itself: a sign that cycles, a television that flickers. The mansion's are put in by npm run mansion-spots (see Install); the Doors tab shows such a spot's frames and has Keep it still to stop it. The animation runs in each viewer's own browser, so it costs the server nothing and nobody sees quite the same frame at once.

Moderation

Everything on the Moderation tab, and the Pictures tab's rules on where pictures may come from, is the house's rule: set it from any room's settings screen and it holds in every room on the server. (So are the ledger's strikes, gags, bans, blessings and grants.) Pictures carry a rating, movie-style: PG (fine for anyone), R (adult but not explicit: nudity without sexual activity, gore, drug use, crude gestures), MA (explicit: sexual activity, anything sexual involving minors, extreme violence, content that promotes hate or self-harm), or unrated. Everyone picks in the side panel how far up they see (pictures rated up to; R to begin with); a picture above that is drawn as a grey tile with the rating's letters, on a head, on the floor or on the wall, and their browser never fetches it. A head whose face-hiding picture is hidden shows the smiley. The house sets a ceiling (MA to begin with): nothing rated above it is ever stored or hung, and nobody can choose to see above it. Unrated pictures show to everyone unless Treat unrated pictures as R is on, which hides them from people who see only PG. The picture in Discord is an R viewer. Barkeeps (ban_props) rate by hand from a head's, a loose prop's or a wall picture's menu; a hand rating stands over the model's.

Automoderation has a mode for chat (none, filter, AI) and one for pictures (none, AI). The filter is the blocked-word list. With AI on, every line said out loud in the bar is judged after it has been shown (a line can't wait to appear); the verdict goes through the policy table, never to the display. Whispers are never sent, nor Harry's lines, Ratbot's, captions, or lines from Discord, nor anything said in a bolted room: that talk is sealed between the people inside, and the house has agreed not to read it. A barkeep can still walk in, announced, which is the recourse a house has always had against a private room. Who judges chat is the house's choice. OpenRouter: lines go in bunches of up to ten, a few seconds after they're said, to a small model with a fixed prompt that answers PG, R or MA for each; one key does everything. Jev (TypeSafe's decision model, which answers a typed question with probabilities instead of writing prose): each line goes at once, alone, and comes back in a fraction of a second as a number from 0 to 4 on a written scale (0 ordinary talk, 1 mild, 2 crude or insulting, 3 hateful, 4 dangerous) with how sure it was; the tab draws the scale as a bar from green to red with two handles, where the house's R and MA begin (1.5 and 2.5 to begin with, with the bands G, PG, R, MA marked as our estimate), and a Try a line box that judges anything you type as the bar would and shows where it landed. Jev needs its own key (the Keys tab, TypeSafe) and costs about a hundredth of the OpenRouter judge; pictures still go to OpenRouter, since Jev reads only text. With AI pictures on, every new picture (pasted, by address, or found on the web; emoji are PG by construction) is rated before it's usable, so nobody is shown it first; one over the ceiling is refused and the person who brought it goes through the table. Repeats are free: a picture already rated isn't rated again. It runs in the room server with its own OpenRouter key (the Keys tab), not Harry's, on a small model (the tab's Model box, else MODERATION_MODEL in .env; Gemini Flash Lite unless you say otherwise; a model that must think before it answers, like Gemini 3.5 Flash, answers nothing), about $0.0002 a line and $0.001 a picture. A budget a day ($1 to begin with; the spend of both judges is counted for the whole server) stops it: past it, chat runs as filter and pictures as none until tomorrow, and the log says so once. Without the chosen judge's key the AI modes run the same way, and the Moderation tab says so in red.

The policy table has a row for each thing the house can notice: a line rated R or MA, a picture rated R or MA, a picture over the ceiling, a flood of lines (nine in ten seconds) or of pictures (eleven in ten minutes), and a second flood within the hour. Each row is a set of consequences, any of: note (the ledger only); warn (a private line to the person saying what and why); take it back (the line's balloon and transcript line go for everyone, and the mirror's Discord post if it made one) or ban the picture (off everyone, off the floor, banned); strike; gag for so many minutes; ban for so many hours; no pictures for so many minutes. Out of the box: R is a note, an MA line is a strike and taken back, an MA picture is banned with a strike and a warning, a first flood is a warning and a second a five-minute gag (an hour without new pictures, for pictures). Strikes add up: two within seven days is a ban of a day, three within thirty a week, and those numbers are yours to change. Every consequence is in the audit log; the People tab lists each person's strikes and notes for the last thirty days, with a button to clear them; and a person sees their own strikes in the side panel (and hears about each as it lands), so the system is not a trap. Gags and bans it hands out are ordinary punishments, listed and lifted like any other.

The audit log

Everything Harry does, every line that woke him, every use of a tool, every picture hung, moved, swapped or removed, every setting changed, is kept in the room's log with who and why. /harry log shows his last hour from Discord; the barowner can read the rest on the host. Whispers between people are never in it. A line in the bar that mentions Claude or starts with bug: goes there as a note for the developer instead of to Harry.

Planned tools

Not built yet; in ROLES.md as the next set, in this order: kick (out now, five minutes at the door), lock the door (nobody new for a while, without touching the floor or anyone inside), retract a line (one balloon taken back everywhere, Discord included), rename people (strip or set an alias), move people (drag someone else's head), announce (a caption from the house, optionally to every room), and report for everyone (a note to the log and the barkeeps present). Ratings, automoderation and strikes are a separate plan, MODERATION.md.