Telegram verification

A verification bot that keeps the reason it let someone in.

Verification is the first thing a stranger meets and the last thing anyone documents. When it goes wrong you find out from the member it went wrong for.

Why this got harder

The verify button became normal, so it became the attack.

Verification bots worked well enough that clicking a verify prompt turned into ordinary behaviour across crypto Telegram. Cloned bots followed the habit. The clone does not have to beat your security. It only has to look like the step your members were already trained to take without reading.

That is a problem about trust and proof, not about detection. It matters who did the verifying, what they checked, and whether anyone can go back afterwards and see it.

Why are cloned verification bots so effective in Telegram groups?

Because the habit is the vulnerability. Years of legitimate bots have taught members that a verification prompt is routine, and routine is the state in which people stop reading. A clone inherits all of that training for free. It does not need to be convincing on its own merits; it needs to be unremarkable, which is a much lower bar.

That is also why hardening the challenge does not fix it. A harder question asked by the wrong bot is still the wrong bot. The part a community can actually control is whether, afterwards, anybody can establish what the real system did and did not do.

What is different here

Every decision leaves a record.

A verification decision is an action like any other, so it carries what every action carries: the community, the sender, what detected it, a confidence value, the evidence, the action taken, who owned it. Appeals and undo are retained.

So when a member says they were wrongly turned away, or a moderator asks why an account got through, there is something to open. Telegram's own tooling gives you nothing to hand back to a member who asks.

What does a verification record actually contain?

The full set of fields, the same ones a removal or a mute carries, is the list above. Two of them do most of the work. The evidence is what turns a decision from an assertion into something checkable, and the owner is what stops "the bot did it" from being the end of the conversation.

Provider identities are stored as one-way pseudonyms rather than as raw platform accounts, so the record stays reviewable without the workspace keeping a copy of your members' Telegram identities. A trail that is itself a liability is not much of an improvement on no trail.

And the same rulebook runs your Discord

One workspace, both platforms.

Telegram bots are Telegram only. Discord bots are Discord only. The few products that span both do access control and nothing else. SwarmUp runs one rulebook, one policy and one record across both, so an account you turned away in one place is not a stranger in the other.

Can one verification policy run across Telegram and Discord?

Yes. Both communities are operated from one workspace and run on one Community Blueprint, while each platform and each channel keeps its own permissions. Shared policy does not mean identical behaviour in both places; it means there is one place to change your mind and one record afterwards that covers both.

The alternative is the arrangement most projects are actually running: a Telegram bot, a Discord bot, and a moderator holding the connection between them in their head. That works until the person holding it is asleep, which is reliably when the same accounts try the other door.

Before you turn it on

Somebody has to decide who belongs.

Verification is a policy question wearing a technical costume. The bot can only apply a standard for entry that somebody has already written down, and most communities have never written theirs down.

How does SwarmUp know who should be allowed in?

From your Community Blueprint, which stores the rules, tone, knowledge and goals you explicitly approve. AI can help draft it, but nothing becomes live configuration until a person reviews and saves it. So the standard the door applies is one your team wrote and can point at, not one a model inferred.

This is the least glamorous part of setting up verification and the part that determines whether any of the rest is defensible. An audit trail only proves you followed your policy. It is the blueprint that decides whether the policy was worth following.

Where the automation stops

What the AI is not allowed to do.

The reason to trust a moderation product is not how clever it is. It is what it is prevented from doing without you.

  • AI cannot ban a member on its own.
  • AI cannot apply a permanent sanction on its own.
  • AI cannot publish a change to your policy.
  • Deterministic low-risk rules act automatically. Everything above that line waits for a person.
  • Every action is reversible, and the reversal is recorded too.
  • Provider identities are stored as one-way pseudonyms, not as raw platform accounts.

Straight answers

What people ask about verification.

What is a Telegram verification bot?

A Telegram verification bot checks a member before it gives them access to a group, and grants or refuses entry based on that check. SwarmUp runs verification as part of your moderation policy, so a decision about who gets in is recorded the same way a decision to remove somebody is.

How is verification different from a captcha?

A captcha asks whether something is automated. Verification asks whether somebody should be here. The first is a filter anyone can pass by doing the work; the second is a judgement about a specific account, which is why it is the one that needs a reason kept against it.

Can a verification decision be reversed?

Yes. Every action is reversible, and the reversal is recorded too. That second half matters more than it sounds: a system that quietly undoes its mistakes leaves you unable to prove you corrected anything, which is the same position as never having corrected it.

How do I know your verification bot is not a clone?

You cannot tell from inside a chat window, and this page will not claim otherwise, because claiming it is exactly what a clone does. What SwarmUp can offer is the other half: every verification decision is recorded with its reason, so a suspicious one can be checked against the workspace rather than argued about.

Can the AI decide on its own who gets verified?

Only within limits you set. Deterministic low-risk rules act automatically, and everything above that line waits for a person. AI cannot ban a member on its own, cannot apply a permanent sanction on its own, and cannot publish a change to your policy.

Does verifying more members cost more?

No. Community growth is not metered and core protection is not a premium feature. Servers, groups and seats are unlimited on every plan including the free one, so the bill is a function of how many workspaces you run rather than how many people you let through the door.

Where we are today

SwarmUp is not open to the public yet. Moderation is the core of the product and it runs today. Engagement and rewards are still in testing. Plans and prices are final, and nothing is charged before the workspace opens.

One email, when it opens

We will not waste the one email.

We are not naming a launch date until we can hold it. What you get for an address is a single message the day the workspace opens, and the same plain account of where the product stands on that day.