Skip to content

Instances & permissions ​

Instances ​

Each Discord server is one instance. Instances are isolated from each other: their own data, settings, terms, modules, ranks and API keys. An API key always belongs to exactly one instance and only ever returns that instance's data.

Terminology ​

The UI never hard-codes patient, unit or station. It uses the instance's terms, each with a singular and plural form, which you set in the wizard and later under Einstellungen. The templates fill them like this:

TermRettungsdienstPolizeiFeuerwehrNeutral
facilityEinrichtungWacheFeuerwacheEinrichtung
buildingEinrichtungRevierWacheGebäude
areaRaumZelleStellplatzBereich
slotBettPlatzPlatzPlatz
waitingAreaWarteraumVorführraumSammelplatzWartebereich
personPatientInsasseBetroffenerPerson
operationEinsatzEinsatzEinsatzEinsatz
boardLeitstellenblattWachenblattLeitstellenblattLeitstellenblatt
unitEinheitStreifeFahrzeugEinheit
staffMitarbeiterBeamterMitarbeiterMitarbeiter
personnelSheetPersonalblattPersonalblattPersonalblattPersonalblatt
courseKursSchulungBrandschutzkursKurs
courseRegistrationAnmeldungAnmeldungAnmeldungAnmeldung
dispatcherLeitstelleLeitstelleLeitstelleLeitstelle
documentsDokumentDokumentDokumentDokument

Permissions ​

There is one permission system: capabilities, granular keys of the form <area>.<resource>.<action>, for example einsatz.sheet.close, documents.template.create or personal.notes.view. Every API route and every page checks one of them.

A person's capabilities are the union of everything that applies to them. No source takes away what another grants.

SourceHow it applies
Discord roleA rank linked to a Discord role. Every live role the member holds counts
Manual rankAssigned in the person's file in the personnel sheet
InGame rankSet by the game server through a stable inGameKey, see the ranks module
Abteilung (department)Capabilities of an organisational unit, inherited by the units nested below it
Alle Mitarbeiter (all staff)Granted to everyone holding the employee role
Leitstelle (dispatch)Granted while someone occupies a dispatcher slot
  • A rank can inherit the capabilities of the rank directly below it.
  • settings.manage is instance administration and covers every other capability. Discord administrators and the extra admins configured in the settings hold all capabilities.
  • Courses, lists, protected personnel columns, website pages and polls can be set to nur mit Einzelrecht (only with an individual right). Then the area key isn't enough and only the right on that one thing counts.
  • AI features are a capability too (ai.features.use). API keys never get it.

Suspension ​

A suspension (Suspendierung) is an in-game roleplay state of an active employee. The configured Discord suspension role is synced in both directions. While someone is suspended, the capabilities configured for suspended people replace all their normal ones.

API keys ​

API keys aren't people. An unscoped key has full access to its own instance; rank and suspension checks apply to browser sessions. Scoped keys for game servers only get the scopes they were issued with. See HTTP API.

Partner agencies ​

Instances can cooperate, for example EMS with the police. A cooperation never happens on its own:

  1. An admin proposes a cooperation with another instance. The partner's admins get a Discord DM.
  2. The partner accepts.
  3. Each side decides per module what it shares, at one of four levels:
Level (UI label)API valueMeaning
Keine Freigabe (no sharing)noneThe default
Nur anonymisiert (redacted)redactedThe partner knows an entry exists. Names and details never leave the server
Lesen (read)readThe partner can open the sheet but not change it
Lesen & Schreiben (read & write)writeShared incident, run together

Redaction and visibility are enforced on the server. Shared partner data shows in a separate read view. Handing a patient over to a partner is an explicit handover step, never a silent transfer. Cooperations can be suspended, resumed or revoked.

np_* FiveM resources