Web dashboard
Security & privacy
Discord login, live role checks, the audit log and your data.
Logging in#
The dashboard uses Sign in with Discord. It only asks Discord for your identity, not your servers, messages or email. There is no separate password to leak.
Live role checks#
The website doesn’t decide what you may see. Every request goes to the bot, which looks up your current roles in the server and checks your tier before answering. Remove someone’s staff role in Discord and they lose dashboard access on their next click. Tickets of one server are never shown in another.
Everything on record#
- Every dashboard request lands in the audit log with who, what, the target, the outcome and the time. Secrets in inputs are hidden.
- Publishing setup changes and imports from Discord are logged too.
- Every integration call and approval is recorded with who approved it and the result.
- Every ticket keeps a history of what happened: opened, sorted, claimed, moved, closed, rated.
Player privacy#
- Tickets are private: only the player, your team and the bot can see them.
- Staff notes are never shown to the player, not even in their transcript.
- The assistant never asks for passwords or full payment details, and is told to ignore any instructions hidden in messages or web pages.
The AI and your data#
- Each server has its own knowledge base. Nothing learned in your server is used in another.
- Tikkora doesn’t retrain an AI model on your data. The assistant looks things up in your knowledge base each time instead (how that works).
- Learned solutions are summarised with usernames, in-game names, emails, IPs and order IDs removed, and staff approve them before they are used (unless you auto-approve an import).
- The AI never bans, refunds or runs anything risky by itself. Dangerous tools always need a person.
Your data#
Tickets and their transcripts are kept, so your team can always look back at a case and export your history whenever you need it. Management can download everything at any time from the Data page.