Roles & permissions
heliana uses a role-based permission system. Every member has one role; the role determines which actions they can perform. Four built-in system roles are always present. You can create additional custom roles and tune their permissions through the roles matrix.
Built-in (system) roles
Section titled “Built-in (system) roles”| Role | Description |
|---|---|
| Owner | The organization creator. Holds all permissions, including deleting the organization and a level of dynamic access control that not even Admin has. Cannot be edited or deleted. |
| Admin | Full admin access by default — everything Owner has except organization deletion and that dynamic access control. Fixed in the system matrix and shown with a lock icon. |
| Viewer | Read-only access by default. Fixed and shown with a lock icon. |
| Clan leader | Read access to Player Lists only — enough to see the roster without the broader visibility Viewer gets into bans, players, and servers. Fixed and shown with a lock icon. |
System roles are displayed in the matrix with a lock icon — their checkboxes are not editable, for any permission group, including per-trigger execution rights.
Create a custom role
Section titled “Create a custom role”- In the left sidebar, click Roles.
- Click New role.
- Enter a Name (for example, “Moderator”) and click Create.
The new role appears as a column in the permissions matrix with all permissions unchecked. Grant permissions by editing the matrix (see below).
Edit permissions in the matrix
Section titled “Edit permissions in the matrix”The matrix lists every permission key in rows grouped by resource (Bans, Ban lists, Players, Triggers, etc.). Columns represent roles.
- On the Roles page, click Edit.
- Checkboxes activate for all custom role columns.
- Check or uncheck permissions for each custom role as needed.
- Click Save when done, or Cancel to discard changes.
System role columns (Owner, Admin, Viewer, Clan leader) remain locked during editing.
Delete a custom role
Section titled “Delete a custom role”In the matrix header row, click the trash icon next to the custom role’s name. Confirm in the dialog. Members who had that role keep access until they are reassigned a new role.
Permission groups in the matrix
Section titled “Permission groups in the matrix”The matrix organizes permissions into the following groups:
- Audit log — read audit events
- Bans — create, read, update, delete, and import bans
- Ban lists — read and manage imported ban sources and exceptions
- Events — read server events
- Roster — read and manage Player Lists (the Access, Ban list, and Tag groups)
- Invitations — create and cancel invitations
- Members — add, update, and remove members
- Notes — read and manage player notes
- Organization — update organization settings, or delete the organization
- Players — read player profiles and IP addresses
- Roles — create, read, update, delete roles
- Servers — create, read, update, and delete servers
- Triggers — create, read, update, delete triggers
- Trigger actions — per-trigger execution rights (one row per manual trigger)
There is no “Player flags” or “Flag types” group — player tagging lives entirely under Roster (see Tag & watch players).
The Trigger actions group is only shown when at least one manual trigger exists. See Grant per-trigger execution rights.
Assign a role to a member
Section titled “Assign a role to a member”Roles are set when you invite a member (see Invite admins) or updated inline from the Members table. The Owner role cannot be assigned through the invite or members UI.
Note: custom roles can be created and configured in the matrix, but the invite dialog and the inline member role-change only offer the built-in Admin, Viewer, and Clan leader roles, so a custom role cannot currently be assigned to a member through the UI.