# Forum owners don't understand discobot

**URL:** https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154
**Category:** Feature
**Created:** [July 13, 2017, 9:12pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154 "2017-07-13T21:12:36Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![michaeld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/michaeld/32/1594_2.png) [@michaeld](https://meta.discourse.org/u/michaeld)
#### Post date: [July 13, 2017, 9:12pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/1 "2017-07-13T21:12:36Z")

</div>

Today was the fourth time in a month or so that we got a support ticket from one of our customers, who was convinced that they were hacked or in some way compromised. It turned out that the culprit was Discobot, which is apparently not recognized as a system thing.

So we’re getting support tickets like

> We have noticed that a user Discobot has been setup with Admin privileges? Can you let me know urgently if this is something we should be concerned about?

and

> This seems to be a spam bot to me - and it has granted admin level clearance

The amount of people freaking out about this is just getting too high to blame the user 😉

I was wondering if there is anything that could be done to make this user (even more) identifiable as a ‘harmless’ system user. Maybe have a separate category for it in the user list, or not having it show up there at all (except when a checkbox ‘show system users’ is checked, for example), or having a special icon instead of, or next to, the shield ?

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [July 13, 2017, 9:25pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/2 "2017-07-13T21:25:26Z")

</div>

If you actually visit the discobot profile, it’s pretty clear what it is. I also have to say we haven’t had this reaction from our customers.

> [@michaeld](#):
>
> Maybe have a separate category for it in the user list, or not having it show up there at all (except when a checkbox ‘show system users’ is checked, for example), or having a special icon instead of, or next to, the shield ?

Where exactly are they seeing it and freaking out, and why aren’t they visiting the profile page for that user, are my two questions.

---

<div class="post-metadata">

### Author: ![michaeld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/michaeld/32/1594_2.png) [@michaeld](https://meta.discourse.org/u/michaeld)
#### Post date: [July 13, 2017, 9:29pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/3 "2017-07-13T21:29:50Z")

</div>

> [@codinghorror](#):
>
> If you actually visit the discobot profile, it’s pretty clear what it is.

I know and I agree. But if four distinct customers are mailing us separately, something must be not clear enough, somehow.

> [@codinghorror](#):
>
> Where exactly are they seeing it and freaking out, and why aren’t they visiting the profile page for that user, are my two questions.

They’re seeing it in Admin - Users - Staff,  
and they freak out before visiting the profile? 😉

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [July 13, 2017, 9:32pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/4 "2017-07-13T21:32:04Z")

</div>

Maybe advise them to freak out _after_ visiting the profile?

---

<div class="post-metadata">

### Author: ![michaeld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/michaeld/32/1594_2.png) [@michaeld](https://meta.discourse.org/u/michaeld)
#### Post date: [July 13, 2017, 9:36pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/5 "2017-07-13T21:36:07Z")

</div>

🙂 At the moment we come into play there, they’ve already freaked out.

But in a way, that was what I was suggesting. If there would be some kind of indication that this was a system user, they would indeed visit the profile first.

I think it would be good to have a ‘nobody’ type of user, next to admin and moderator, to designate that this is not an actual person.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [July 13, 2017, 9:37pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/6 "2017-07-13T21:37:25Z")

</div>

Sorry, our plate is rather full at the moment. You may want to work on a plugin if it is an ongoing concern for your audience.

---

<div class="post-metadata">

### Author: ![michaeld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/michaeld/32/1594_2.png) [@michaeld](https://meta.discourse.org/u/michaeld)
#### Post date: [July 13, 2017, 9:40pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/7 "2017-07-13T21:40:18Z")

</div>

Not making any demands here… just sharing something we noticed and making a suggestion.

If a PR or a plugin is welcome, we can spend some time on this.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [July 13, 2017, 9:40pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/8 "2017-07-13T21:40:51Z")

</div>

If we get a lot of complaints I can re-evaluate, but we just haven’t had many at all.

---

<div class="post-metadata">

### Author: ![tophee](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tophee/32/73406_2.png) [@tophee](https://meta.discourse.org/u/tophee)
#### Post date: [July 14, 2017, 12:20am UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/9 "2017-07-14T00:20:30Z")

</div>

Maybe a simple way of dealing with this could be to add a few words about the bot to the “READ ME FIRST: Admin Quick Start Guide”? In fact, I think that would be a good idea regardless of those scared admins.

---

<div class="post-metadata">

### Author: ![zogstrip](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/zogstrip/32/512781_2.png) [@zogstrip](https://meta.discourse.org/u/zogstrip)
#### Post date: [July 15, 2017, 9:41pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/10 "2017-07-15T21:41:20Z")

</div>

Won’t help those who have already read it tough.

---

<div class="post-metadata">

### Author: ![Stephen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/stephen/32/95011_2.png) [@Stephen](https://meta.discourse.org/u/Stephen)
#### Post date: [July 16, 2017, 11:14pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/11 "2017-07-16T23:14:08Z")

</div>

This seems more like a communication thing. Discourse is going to keep evolving and developing, the marketing information for your service needs to remain abreast of that.

If the first time they hear of Discobot is when they receive that message, the problem is one of customer messaging, not how the bot is categorized.

---

<div class="post-metadata">

### Author: ![michaeld](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/michaeld/32/1594_2.png) [@michaeld](https://meta.discourse.org/u/michaeld)
#### Post date: [July 17, 2017, 9:07pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/12 "2017-07-17T21:07:29Z")

</div>

I don’t completely agree with that. Software should be intuitive enough to be comprehensible without extensive communication.  
Second, the fact that the bot is categorized as “admin” _is_ confusing (and, imho, sort of wrong, because it cannot and will not perform regular admin actions).

---

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [July 18, 2017, 3:15am UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/13 "2017-07-18T03:15:51Z")

</div>

> [@michaeld](#):
>
> because it cannot and will not perform regular admin actions

To be fair, discobot “reads” all PMs, and you can call discobot in any post (including PMs). Without admin rights this wouldn’t be possible.

---

<div class="post-metadata">

### Author: ![ricardojr](https://avatars.discourse-cdn.com/v4/letter/r/919ad9/32.png) [@ricardojr](https://meta.discourse.org/u/ricardojr)
#### Post date: [July 18, 2017, 6:14pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/17 "2017-07-18T18:14:08Z")

</div>

I agree. I will say that at best, its confusing the way it is right now. It was kind of weird to me as well (first time hosting Discourse). I think the fix is to simply rename the bot to something more friendly. Should be a low hanging fruit, but I also think this is a low priority item. Still valid however. “SystemNotifier”, “AutoResponder”, “SystemAssistant” would make it more clear that the user is harmless, intended to be there, and automated (IMO).

---

<div class="post-metadata">

### Author: ![featheredtoast](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/featheredtoast/32/116994_2.png) [@featheredtoast](https://meta.discourse.org/u/featheredtoast)
#### Post date: [July 18, 2017, 6:42pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/18 "2017-07-18T18:42:49Z")

</div>

While we’re bikeshedding solutions, an alternative to renaming the bot itself would be to have a default group for built-in default accounts (It could include the system account as well.) You could then include flair or titles that indicate it as a built in account, so it’s more immediately obvious.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [July 18, 2017, 10:07pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/19 "2017-07-18T22:07:39Z")

</div>

That is what @michaeld was trying to say 🙂

> [@michaeld](#):
>
> (…) some kind of indication that this was a system user (…)  
> I think it would be good to have a ‘nobody’ type of user, next to admin and moderator, to designate that this is not an actual person.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [July 18, 2017, 10:09pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/20 "2017-07-18T22:09:19Z")

</div>

Ok but @michaeld can you screenshot where users are seeing this? There are literally _dozens_ of places you can view users, so maybe mock up with actual screenshots what you are proposing, exactly? Because I’m not following, and none of our customers are having an issue with this currently.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [July 18, 2017, 10:22pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/21 "2017-07-18T22:22:22Z")

</div>

All users saw it in Users - Staff

 ![](https://global.discourse-cdn.com/meta/original/3X/9/f/9f0e9fff796892d92a99519a45cd35cefd0ec7f9.png)

Suggestions:

1. move Discobot and System users to a ‘System’ tab instead of ‘Staff’ to distinguish them

2. Replace the little shield icon on the right with something different (fa-rocket or something)

3. Remove ‘trust level: leader’ and the Leader badge on the profile and replace it with something different. Badges make it look like it’s an actual person

4. For forums that require approval, the empty space after ‘approved by’ is scary and could read something like ‘system user’

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [July 18, 2017, 10:25pm UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/22 "2017-07-18T22:25:43Z")

</div>

That’s a lot of engineering work that wouldn’t move things forward that I need moved forward to satisfy our actual customer requests..

Pull requests accepted, of course!

---

<div class="post-metadata">

### Author: ![neil](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/neil/32/102150_2.png) [@neil](https://meta.discourse.org/u/neil)
#### Post date: [July 19, 2017, 2:05am UTC](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154/23 "2017-07-19T02:05:35Z")

</div>

Don’t the site admins themselves get greeted by discobot immediately after their site is provisioned? They shouldn’t be surprised to see it in the users list. Discobot explains itself to them right away: “I’m only a robot, but our friendly staff are also here to help if you need to reach a person.” Or does [Communiteq](https://www.communiteq.com) (formerly DiscourseHosting) somehow modify discobot’s messages or timing?

I’m pretty sure that 0 of our customers have reported being hacked by discobot. 😕

[Next page](https://meta.discourse.org/t/forum-owners-dont-understand-discobot/66154.md?page=2)
