The Effective scam policy card is the source of truth for what is running.
You can save network settings before a staged rollout reaches your server, but
detections may remain observe-only until the card shows the layer as effective.
Network and shadow scores can appear as telemetry without increasing an action.
Configure participation
Open Settings → Scam defense → Scam Defense Network.
You can use the network without contributing, contribute without using it, enable both, or disable both.
Turning contribution off immediately stops that server’s evidence from counting toward network quorum and public statistics. It does not delete the server’s tenant-isolated AutoMod audit history.
What leaves your server boundary
Thea extracts only supported indicator types:- Domains
- Canonical links
- Discord invite codes
- Attachment fingerprints
- Destination hosts found in QR codes
- Message text
- The raw URL, domain, invite code, or QR payload
- A server name or Discord server ID
- A member ID
- A channel ID
- A message ID
How a verdict qualifies
One server cannot create an actionable network verdict.- A signal starts as an observation.
- At least three independent, qualified servers must report recent matching evidence before it can become suspected.
- Confirmation requires independent human-upheld evidence. Most indicators need two upheld servers, or one upheld server plus separate provider corroboration. Invite codes require three upheld servers. Established domains receive a higher confirmation floor.
- When Thea looks up a signal for your server, it removes your server’s own contribution before checking quorum.
Human correction and safety brakes
Moderator review is part of the network state:- Upheld findings add human confirmation.
- Approved findings remove that local event from automated follow-up.
- Multiple independent false-positive reviews can suppress a verdict.
- Evidence that no longer qualifies is retracted.
How network intelligence affects action
The network is an evidence source, not an action policy.- A suspected match is capped at log-only.
- A confirmed match can strengthen a local decision only when network use is enabled.
- Thea still applies signal independence, action ceilings, staff observe-only rules, permissions, rollout gates, and global safety brakes.
- A human-approved finding is excluded from retroactive deletion and incident response.
Adaptive hardening
If you enable adaptive hardening, Thea temporarily tightens checks while either condition is true:- An open or investigating network incident was matched in the last 30 minutes.
- A spreading campaign touched your server in the last 30 minutes.
Step-up verification
Step-up verification is for a newly observed account’s borderline first link. Thea:- Removes the message.
- Applies a temporary 10-minute posting pause when it has permission.
- Posts a Verify button in the channel.
- Uses the same two-step challenge system as raid protection.
- Lifts the pause after a successful challenge.
Public Network Pulse
The public Network Pulse shows broad activity without offering an indicator lookup.- It includes only evidence from servers that currently allow contribution.
- Every displayed indicator has support from at least three qualified servers.
- Activity is grouped into three-hour buckets.
- Detection and indicator totals are rounded down in groups of five.
- Community and campaign totals are rounded down in groups of three.
- A time or indicator bucket supported by fewer than three servers displays zero.
- It contains no geographic map and does not collect or infer server locations.
Shadow learning
The dashboard can show shadow-model metrics. Shadow learning uses closed numeric features and explicit moderator outcomes. It does not use message text or raw indicators. Training is balanced so every contributing server has the same total influence. Entire servers are held out during evaluation to test cross-server generalization. A candidate is rejected when its false-positive or calibration checks fail, and there is no automatic path from a shadow model to enforcement.Retention
- Unreviewed shared references expire after 14 days.
- Reviewed evidence can remain for up to 90 days.
- Incidents and campaigns can remain for up to 180 days.
- Inactive model artifacts can remain for up to 180 days.
- Public pulse values are generated from eligible live records instead of being stored as another event-level copy.
Scam Defense Network versus the global blacklist
These are separate opt-in systems:- The Scam Defense Network shares keyed infrastructure indicators such as domains and invite codes.
- The global blacklist shares a permanent-ban signal about one Discord account only after independent human moderator actions.