Moderator at a desk reviewing a queue of flagged posts on a laptop beside a printed ladder of community roles

Discourse does not moderate like a classic forum. XenForo gives you a report queue, warnings, and a group ladder you designed. Discourse gives you a trust-level machine, a review queue fed by flags, watched words, and groups for walls. If you treat trust levels as “ranks with extra CSS” you will turn the sandbox off, over-specify category security, and spend a month asking why regulars lost tools after a quiet stretch.

This is the moderation model. It is not the first-week admin tour (wizard, five categories, SMTP). It is not the XenForo large-forum queue. It is not the stay-or-migrate decision. You already have a Discourse. You need to know what TL0 cannot do, what TL3 can lose, what the review queue will auto-silence, and how to set a category so staff can see it and new users cannot break it.

Official and Meta sources for the behaviour below: Understanding Trust Levels, the Trust Level Permissions Reference, and the 2023–2025 shift of many “minimum trust level” settings into allowed groups. Exact visit / read / like counts for promoting TL1–TL3 are admin-configurable and they move. This article will not invent those numbers. Open the two Meta references on your site’s version and read the current thresholds there. What is stable enough to operate on is the shape: sandbox, flags, rolling Regulars, staff-only Leaders.

The model in one paragraph

New accounts are TL0 (sandbox). A scheduled job promotes people who read and hang around to TL1 (Basic). Further participation promotes to TL2 (Member). TL3 (Regular) is re-checked on a 100-day rolling window and can be taken away. TL4 (Leader; Meta also says “Inner Circle”) is staff or SSO, not an activity grind. Members with TL1+ can flag. Diverse TL3 flags on a TL0 post can auto-silence the new user and hide the post. Staff work the review queue. Watched words catch the boring stuff before a human. Groups open or close categories. Trust levels are the ladder. Groups are the walls. Mixing those two jobs is the usual disaster.

If you need a one-line staff briefing: the software sandboxes strangers, promotes readers, demotes quiet Regulars, and never automatically makes someone a Leader.

The ladder you must be able to explain

Use these names with staff. Do not invent a sixth rung.

Level Common name How it is granted (defaults) What “default” means for ops
TL0 New Everyone new, except invited users, who typically start at TL1 Sandbox. Limits on media, links, mentions, likes, edits, chat. Cannot flag, mute, or ignore.
TL1 Basic Automatic, ~15-minute job, once reading requirements are met Can flag and mute. Chat rate loosens. Still not a moderator.
TL2 Member Automatic, daily job, participation requirements Longer own-post edit window. Default allowed to invite-to-topic. Like budget grows.
TL3 Regular Automatic, daily job, 100-day rolling window Extra tools (tags, topic-level edits). Flags weigh more. Can demote. Grace period exists so badge spam is harder.
TL4 Leader / Inner Circle Staff promote, or SSO maps it Junior-moderation grant: pin, timers, split/merge, edit others’ posts (via default groups). Not a grind.

Invited people skipping TL0 is the documented on-ramp for people you actually know. Public signups should stay in the sandbox. Setting “everyone starts at TL2” on a public site is how you donate the queue to spam. Meta staff have warned about that class of mistake for years; the beginner guide already said not to do it in week one. This article says not to do it in month six either.

Admins can set a level by hand and lock it. Groups can grant a minimum trust level. That is why a user sometimes looks “too trusted” for their stats: they are in a group that floors them, or a human locked TL3 so a quiet month would not strip tools. Use locks for roles (the contractor who only posts quarterly release notes). Do not lock the entire census because you dislike demotion.

SSO can map staff to TL3/TL4 on day one. That is an identity-provider job, not a promotion job. If you need every employee to land as a Regular, do it in the SSO payload, then still keep TL4 for people you would hand a split/merge button.

TL0 — the sandbox you should not turn off

TL0 exists so a brand-new account cannot spray the site. Defaults from the permissions reference / notebook research, which you should re-read on Meta when a friend complains:

  • 1 image (newuser max embedded media)
  • 2 links
  • 2 mentions
  • 50 likes per day
  • 24-hour own-post edit window
  • Cannot flag
  • Cannot mute
  • Cannot ignore
  • Chat: 20 messages / 30 seconds (when Discourse Chat is on)

Those caps are why a migrated community’s first week is full of “I cannot attach my four screenshots.” That is the product working. The fix is almost never “set every new-user limit to zero.” The fix is:

  1. Tell people, in the welcome topic, that reading is how they leave the sandbox (TL1 is a reading promotion, not a post-count promotion).
  2. Invite people you already trust, so they start at TL1.
  3. If a specific cap blocks a legitimate intro ritual (a hardware community that must show one photo plus a link plus a mention), change that site setting after you have opened the Permissions Reference. Do not browse the whole list inventing a personality.

Turning off the TL0 sandbox — raising default trust, or zeroing the caps — is the single most common new-admin spam magnet. The review queue cannot outrun a form that lets a fresh account drop fifty links.

TL0 also cannot flag. That is uncomfortable for people who arrived from XenForo, where a registered account can usually report. On Discourse, a brand-new user who sees spam must use some other channel (a staff PM once they can, or email, or waiting until TL1). Brief staff so they do not call that a bug.

TL1 — flags come online

The ~15-minute job is the one that promotes New → Basic once the reading bar is cleared. Requirements are admin-configurable; see the current Meta pages rather than a blog from 2018.

Behaviour that matters for a shift:

  • Can flag. The review queue now has a civilian feed.
  • Can mute. They can silence a noisy category or user without you.
  • Chat 40 messages / 30 seconds, if chat is on.

TL1 is still not a moderator. They cannot split topics. They cannot see the staff category. They can waste staff time with bad flags. That is cheaper than TL0 spam, and it is why watched words exist (below).

If someone is “stuck at TL0,” look at reading, not post count. Personal messages do not count toward the usual reading / like / topics-replied-to style of requirements (Meta is explicit that PMs are a different channel). Invited users should already be TL1; if they are not, check whether they actually used an invite.

TL2 — members, invites, longer edits

Daily job. Participation, not just reading. Again: do not tattoo last year’s visit counts on the about page. Open the live reference.

Default behaviour worth staffing around:

  • Like limit × 1.5 versus the base cap.
  • 30-day own-post edit window (versus TL0’s 24 hours).
  • Invite-to-topic is allowed by default (min trust level to allow invite = TL2 in the older setting language). People will pull friends into a specific topic. That is a feature. It is also a vector if the topic is a private planning thread you forgot to lock.

TL2 is the “this person lives here” rung for a lot of small sites. They still should not have edit_all_topic_groups. They still should not be in the staff category.

TL3 — Regulars, heavier flags, and demotion

This is the rung people misunderstand, because it looks like a rank and behaves like a license that expires.

  • Daily job.
  • 100-day rolling window. The numbers inside that window (visit rate, reading, likes given and received, unique-user and unique-day rules, flag and suspension gates, all-time floors) are configurable and have been in flux. Meta has a topic on default changes for TL3 requirements. Read that, not a screenshot in Slack.
  • Can be lost when activity drops.
  • There is a grace period after first promotion so the system is harder to game with badge-chasing bursts.
  • Like limit × 2.
  • Can create tags (unless you tightened tag creation).
  • Default member of edit_all_topic_groups = trust_level_3. Regulars can edit topic metadata (titles, tags, and the other topic-level fields your version actually grants). That is why a Regular can quietly retitle a messy support thread. It is also why a Regular can quietly retitle a thread they should have left alone. Staff need a culture for that, not just a setting.
  • Flags weigh more. Diverse TL3 flags on a TL0 author are the documented path to auto-silence + hide. Treat Regular flags as junior-moderation, because the software already does.

Operating TL3 demotion

Quiet months demote Regulars. That is not a punishment designed by you. It is the rolling window. Three operational responses, pick one per person:

  1. Let it happen. A Regular who vanished for a season should lose edit-all-topics and heavy flags. They can earn it back.
  2. Lock the level on the user. Use this for people whose role is Regular (a category expert who posts in bursts around releases).
  3. Floor them with a group that grants minimum TL3. Use this for a class of people (current staff-adjacent helpers, a paid members group you actually intend to keep privileged).

Do not respond by turning the TL3 requirements down to zero so nobody ever demotes. You just made TL3 a participation trophy and you still have the edit_all_topic_groups grant hanging off it.

Tell members, once, in the guidelines: Regular is a rolling status. It is not a forum rank. If your culture cannot survive that sentence, Discourse’s ladder is the wrong ladder — XenForo trophies and promotions are a different design (trophies irreversible, promotions reversible). Do not try to make TL3 into a trophy.

TL4 — Leader is a staff grant

Meta 2026 is explicit enough to put on a sticky: TL4 is not automatic. Staff promote, or SSO maps it. Calling it “Inner Circle” on some Meta pages does not change the grant.

Default behaviour:

  • Like limit × 3
  • Unlimited own-post edit
  • Default member of edit_all_post_groups = trust_level_4 — they can edit other people’s posts
  • Pin, timers, split / merge

That is junior moderation. It is not a thank-you gift for 10,000 posts. A TL4 who has never worked a review queue will split the wrong topic and pin the wrong announcement. Promote people you would hand a XenForo moderator account, then still decide whether they also need the official moderator bit (which is a separate grant, with a separate staff inbox).

A workable ladder for a mid-size site:

  • TL3 Regulars — retitle, retag, heavy flags. No split.
  • TL4 Leaders — split/merge, pin, edit posts, still not in every private category.
  • Moderators — official grant, review queue owners, silence/suspend.
  • Admins — settings, category security, plugins, impersonation. Few.

Do not skip to “everyone helpful is admin.”

Allowed groups replaced a pile of min-trust settings

Between 2023 and 2025, Discourse moved a set of “minimum trust level to …” controls to allowed groups. The names you will actually search in admin:

  • edit_all_topic_groups (default trust_level_3)
  • edit_all_post_groups (default trust_level_4)
  • anonymous posting allowed groups
  • user_api_key_allowed_groups

Plus others in the same family as versions move. The operational consequence: if you renamed trust-level groups or you emptied them, the grant may no longer mean what you think. Adding a custom group to edit_all_post_groups is how you give a documentation team edit rights without making them TL4. Removing trust_level_3 from edit_all_topic_groups is how you stop Regulars from retitling.

When a user says “I used to be able to edit titles,” do not start at the user. Start at the group list on the setting.

The review queue

Flags from TL1+ land in review. Staff (and people you have given the right groups) work that queue. This is the closest thing Discourse has to XenForo’s report queue, and it is not the same product. There is no XF-style warning ladder with points unless you add process around silences and official warnings. Discourse’s verbs are closer to agree / hide / silence / suspend / ignore the flag.

Two behaviours to brief staff on:

  1. Diverse TL3 flags on a TL0 post can auto-silence the new user and hide the post. That is not a plugin. It is the default immune system. It is why Regulars are junior mods whether you trained them or not. If three Regulars dogpile a confused newcomer, you will be explaining an auto-silence. Train Regulars: flag spam, do not flag “wrong hobby opinion.”
  2. Reviewable scoring exists. There is a score, and there are priorities. The formula is not something this article will invent. If you need the current weights, open the reviewable settings on your site and the Meta topics that document them. Do not publish a fake equation on the staff category.

Queue hygiene that actually scales:

  • First response target is human (a Regular already hid the obvious spam). Staff confirm and move on.
  • Disagree with bad flags in the UI so the system can learn who cries wolf. Do not DM the Regular a lecture and leave the review item open.
  • Watched-word hits should be faster than user flags. If they are not, your word list is empty.

Compared with the XenForo large-forum shift: you have fewer ACP report states and more automation. You still need a rota. Automation without a rota is a hidden pile.

Watched words

Four actions, official and enough:

Action Use when
Flag A human should see it. Grey-area slurs, scam shapes you are not ready to auto-hide.
Block The post must not land. Known spam domains, invite-link dumps.
Replace You want the content, not the token (common typo, rebranded product name).
Censor You want the post, not the word (public sites with a language standard).

Start small. A 400-row list nobody reviews becomes a support queue of “why can’t I say the name of my own town.” Put block on the obvious botnet bait. Put flag on the culture words you are still arguing about. Put censor only if you have a written standard.

Watched words do not replace TL0 caps. They catch content. Trust levels catch capability. You want both.

Groups are walls; trust levels are the ladder

If you take one structural idea from this article, take this.

  • Trust levels answer: how much of the public toolbox has this person earned?
  • Groups answer: which rooms can they enter, and which grants (edit-all-posts, API keys, anonymous posting) do they hold?

A private staff category is a group permission. A donor lounge is a group permission. “Can create tags” at TL3 is a ladder permission. “This documentation team can edit anyone’s post in Docs” is a group on edit_all_post_groups, not a fake TL4.

XenForo admins arrive wanting to rebuild Registered / Supporting / VIP / Xbox EU as trust levels. That is how you get a site where VIP is TL3, Regulars are also TL3, and demotion randomly strips a paid perk. Paid perks are groups. Regional officers are groups. Trust levels stay generic.

Worked category-security example

A small public product community. Five rooms plus staff. You are not running a game-faction ACL (if you are, read the gaming fit test and be honest about Discourse’s shallower permission language).

Rooms

Category Intent Who sees Who creates topics Who replies
Announcements Staff → everyone Everyone, including guests (if the site is public) Staff group only Everyone who can post, or nobody — pick one and do not change it monthly
General Default room Everyone TL0+ (everyone who can create) Same
Support Questions; required version tag Everyone TL0+ Same
Site feedback Meta Everyone TL1+ if you want fewer “how do I register” topics from bots TL0+ or TL1+ — match create
Staff Private staff group only staff staff

Guests: if you want Google, guests read Announcements, General, Support, Site feedback. They do not read Staff. They do not create.

What you actually tick (and what you must not)

Discourse category security is a table of groups × see / reply / create. The hierarchy already includes people in higher trust-level groups, and Staff already includes admins and moderators.

The failure mode Meta and the notebook both surface:

Adding admins + moderators + TL1 + TL2 + TL3 + TL4 as separate rows “to be safe,” on top of Staff and everyone.

That redundancy is how you get “not permitted to view” for people who should see the room. You have constructed a table the resolver cannot treat as the simple hierarchy it is. The fix is subtractive:

  • Public room: one row for everyone (or the trust-level-0 group, depending on how your version labels the everyone/TL0 grant) with see + reply + create as intended. Staff do not need their own row to see a public room.
  • Announcements: everyone see + reply (or see only). staff create.
  • Staff room: staff see + reply + create. Nobody else. Not TL4. TL4 is a junior-mod toolbox, not a secret-category key.

If a contractor needs the Staff room, add them to staff (or a dedicated contractors group you include on that category). Do not promote them to TL4 as a substitute for a group.

Tag policy on Support

Support requires one tag from a version tag group. Users cannot create tags. TL3 can create tags globally unless you tightened that — so either accept Regulars inventing v2-please or restrict tag creation. This is IA, not decoration. It replaces the child boards you did not migrate.

Notification defaults

Watch Announcements for new users. Track Support if this is a product site. Leave General on normal. A firehose default is how people mute the whole site and then miss the TOS change.

Common new-admin mistakes (Discourse-specific)

These are from SF-3 / Meta practice, not folklore.

1. Renaming trust-level groups, then wondering why the UI still says the old name. Daily jobs refresh a lot of this. You renamed trust_level_3’s display name and a setting or a badge still shows “Regular” or still shows your typo. Wait for the daily job. Do not keep renaming in a loop. Prefer not renaming the core TL groups; put pretty names on extra groups.

2. Over-specifying category security. Covered above. Hierarchy + Staff already cover “all the trusted people.” Redundant ticks produce “not permitted to view.”

3. Turning off the TL0 sandbox. Spam magnet. If intro posts need more than one image, raise newuser max embedded media by one, or tell people to become TL1 by reading. Do not zero the whole sandbox.

4. Being surprised by the 1-image cap on intro posts. Put the cap in the welcome topic. “Read until you are Basic, then post the album” is a complete onboarding sentence.

5. Handing out TL4 as a souvenir. TL4 edits other people’s posts and splits topics. That is a staff decision.

6. Treating TL3 like a XenForo trophy. It demotes. Say so.

7. Using trust levels as ACL. Factions, donor wings, regional officers = groups.

8. Emptying edit_all_topic_groups or edit_all_post_groups while debugging, then forgetting. Those defaults exist so Regulars and Leaders can help. If you cleared them, you silently fired your junior mods.

9. Expecting TL0 to flag. They cannot. Give them a staff contact for the first fifteen minutes of their life on the site.

10. Running the XF-to-Discourse importer and assuming veterans are TL3. They are not, until the rolling window or a lock says so.

Running a shift on this model

A weekday shift on a healthy Discourse looks like this, and it is deliberately shorter than a XenForo report-queue novel.

  1. Review queue to zero or to a written postpone. Approve hides the Regulars already forced. Reverse the auto-silence that hit a confused TL0 (and message the Regulars if they flagged culture, not spam).
  2. Watched-word hits. Promote a new scam domain from flag to block.
  3. Latest, not the tree. Discourse has no last-post column to scan. You are reading a stream. If that sentence makes you angry, you picked the wrong product — not the wrong queue setting.
  4. One category-security ticket. Usually “donor cannot see lounge” = they are not in the group, or someone added six redundant rows last night.
  5. TL3 demotion mail. Someone lost Regular and cannot retitle. Decide lock / group / let it ride. Do not change global thresholds because one person wrote in.

You do not need to invent a warning-points scheme on day one. You need silences that expire, suspends that do not, and a staff topic that records why. Culture of that log is a later article; the tools here are silence, suspend, hide, and the review UI.

What to tell members (copy you can steal)

Keep it shorter than this article.

New accounts start in a sandbox: limited images, links, and mentions, and you cannot flag yet. Read a bit — Basic arrives on its own. Members get more tools over time. Regulars can help tidy topics; that status is based on recent activity and can lapse if you step away. Leaders are appointed. If something is spam, flag it once you can; if you cannot flag yet, write to staff. Please do not treat Regular like a rank you keep forever.

That paragraph prevents half of the tickets this model generates.

Takeaways

  • Discourse moderation is TL automation + review + watched words + groups. It is not a XenForo report queue with different CSS.
  • TL0 is a sandbox (1 image, 2 links, 2 mentions, 50 likes/day, 24-hour edits, no flag/mute/ignore, chat 20/30s). Do not turn it off.
  • TL1 can flag and mute. TL2 gets a larger like budget, 30-day edits, invite-to-topic by default. TL3 is a 100-day rolling Regular who can demote, create tags, and (by default) sit in edit_all_topic_groups. TL4 is staff or SSO, with pin/timers/split/merge and edit_all_post_groups.
  • Do not publish invented visit/read/like counts. They are admin-configurable; Meta’s Understanding Trust Levels and Trust Level Permissions Reference are the source.
  • Diverse TL3 flags on TL0 can auto-silence and hide. Train Regulars. Reviewable scoring exists; the formula is undocumented here on purpose.
  • Category security: do not add Admin + Mod + every TL “to be safe.” Hierarchy + Staff already cover it. Over-ticking is a known path to “not permitted to view.”
  • Groups are walls. Trust levels are the ladder. Paid perks, staff rooms, and factions are groups.

If you can explain demotion, the sandbox, and the Staff-versus-TL4 distinction without opening admin, you can moderate this product. If you cannot, stay out of the site settings until you can. The machine is already running. Your job is to stop turning it off.