ACE Permissions
ACE permissions let resources and server commands ask whether a principal has permission to perform an action.
Core ideas
- ACE — a permission rule such as allowing an object.
- Principal — the identity or group receiving permissions.
- Group — a principal you can use to organize users.
- Inheritance — principals can be added to other principals.
Example:
add_ace group.admin command allow
add_ace group.admin command.quit deny
A resource may define its own ACE object. Always use the exact object documented by that resource.
Keep permissions together
For larger servers, a dedicated permissions.cfg makes auditing easier:
# ============================================================
# ADMINISTRATION
# ============================================================
# ============================================================
# KRUIGER LABS
# ============================================================
# ============================================================
# OTHER RESOURCES
# ============================================================
Load it early:
exec permissions.cfg
Troubleshooting permission denied
Check:
- The player identifier/principal is correct.
- The principal was added to the intended group.
- The resource checks the same ACE object you configured.
- The permission file actually executed.
- There is no explicit deny that overrides the behavior you expected.
- You restarted/reloaded what the resource documentation requires.
Document status
Last reviewed: September 2026
Version note: Use the instructions that match your installed product/resource version. When behavior differs from your release, check its release notes before changing production configuration.
