Permissions FAQ
What is an ACE?
An ACE is a permission rule. Resources can check named ACE objects to decide whether a principal is allowed to perform an action.
Why does an admin command say permission denied?
Verify the exact ACE object, the user's principal/group inheritance, and that the permissions file executes before the resource needs it.
Can I put ACEs in permissions.cfg?
Yes. Load it from server.cfg with exec permissions.cfg.
Should I grant wildcards to everyone?
No. Prefer the narrowest permission needed for the role.
Document status
Last reviewed: September 2026
Version note: Use the instructions that match your installed product/resource version. When behavior differs from your release, check its release notes before changing production configuration.
