Skip to content

Roles & permissions

heliana uses a role-based permission system. Every member has one role; the role determines which actions they can perform. Four built-in system roles are always present. You can create additional custom roles and tune their permissions through the roles matrix.

Role Description
Owner The organization creator. Holds all permissions, including deleting the organization and a level of dynamic access control that not even Admin has. Cannot be edited or deleted.
Admin Full admin access by default — everything Owner has except organization deletion and that dynamic access control. Fixed in the system matrix and shown with a lock icon.
Viewer Read-only access by default. Fixed and shown with a lock icon.
Clan leader Read access to Player Lists only — enough to see the roster without the broader visibility Viewer gets into bans, players, and servers. Fixed and shown with a lock icon.

System roles are displayed in the matrix with a lock icon — their checkboxes are not editable, for any permission group, including per-trigger execution rights.

  1. In the left sidebar, click Roles.
  2. Click New role.
  3. Enter a Name (for example, “Moderator”) and click Create.

The new role appears as a column in the permissions matrix with all permissions unchecked. Grant permissions by editing the matrix (see below).

The matrix lists every permission key in rows grouped by resource (Bans, Ban lists, Players, Triggers, etc.). Columns represent roles.

  1. On the Roles page, click Edit.
  2. Checkboxes activate for all custom role columns.
  3. Check or uncheck permissions for each custom role as needed.
  4. Click Save when done, or Cancel to discard changes.

System role columns (Owner, Admin, Viewer, Clan leader) remain locked during editing.

In the matrix header row, click the trash icon next to the custom role’s name. Confirm in the dialog. Members who had that role keep access until they are reassigned a new role.

The matrix organizes permissions into the following groups:

  • Audit log — read audit events
  • Bans — create, read, update, delete, and import bans
  • Ban lists — read and manage imported ban sources and exceptions
  • Events — read server events
  • Roster — read and manage Player Lists (the Access, Ban list, and Tag groups)
  • Invitations — create and cancel invitations
  • Members — add, update, and remove members
  • Notes — read and manage player notes
  • Organization — update organization settings, or delete the organization
  • Players — read player profiles and IP addresses
  • Roles — create, read, update, delete roles
  • Servers — create, read, update, and delete servers
  • Triggers — create, read, update, delete triggers
  • Trigger actions — per-trigger execution rights (one row per manual trigger)

There is no “Player flags” or “Flag types” group — player tagging lives entirely under Roster (see Tag & watch players).

The Trigger actions group is only shown when at least one manual trigger exists. See Grant per-trigger execution rights.

Roles are set when you invite a member (see Invite admins) or updated inline from the Members table. The Owner role cannot be assigned through the invite or members UI.

Note: custom roles can be created and configured in the matrix, but the invite dialog and the inline member role-change only offer the built-in Admin, Viewer, and Clan leader roles, so a custom role cannot currently be assigned to a member through the UI.