Instances & permissions
Instances
Each Discord server is one instance. Instances are isolated from each other: their own data, settings, terms, modules, ranks and API keys. An API key always belongs to exactly one instance and only ever returns that instance's data.
Terminology
The UI never hard-codes patient, unit or station. It uses the instance's terms, each with a singular and plural form, which you set in the wizard and later under Einstellungen. The templates fill them like this:
| Term | Rettungsdienst | Polizei | Feuerwehr | Neutral |
|---|---|---|---|---|
facility | Einrichtung | Wache | Feuerwache | Einrichtung |
building | Einrichtung | Revier | Wache | Gebäude |
area | Raum | Zelle | Stellplatz | Bereich |
slot | Bett | Platz | Platz | Platz |
waitingArea | Warteraum | Vorführraum | Sammelplatz | Wartebereich |
person | Patient | Insasse | Betroffener | Person |
operation | Einsatz | Einsatz | Einsatz | Einsatz |
board | Leitstellenblatt | Wachenblatt | Leitstellenblatt | Leitstellenblatt |
unit | Einheit | Streife | Fahrzeug | Einheit |
staff | Mitarbeiter | Beamter | Mitarbeiter | Mitarbeiter |
personnelSheet | Personalblatt | Personalblatt | Personalblatt | Personalblatt |
course | Kurs | Schulung | Brandschutzkurs | Kurs |
courseRegistration | Anmeldung | Anmeldung | Anmeldung | Anmeldung |
dispatcher | Leitstelle | Leitstelle | Leitstelle | Leitstelle |
documents | Dokument | Dokument | Dokument | Dokument |
Permissions
There is one permission system: capabilities, granular keys of the form <area>.<resource>.<action>, for example einsatz.sheet.close, documents.template.create or personal.notes.view. Every API route and every page checks one of them.
A person's capabilities are the union of everything that applies to them. No source takes away what another grants.
| Source | How it applies |
|---|---|
| Discord role | A rank linked to a Discord role. Every live role the member holds counts |
| Manual rank | Assigned in the person's file in the personnel sheet |
| InGame rank | Set by the game server through a stable inGameKey, see the ranks module |
| Abteilung (department) | Capabilities of an organisational unit, inherited by the units nested below it |
| Alle Mitarbeiter (all staff) | Granted to everyone holding the employee role |
| Leitstelle (dispatch) | Granted while someone occupies a dispatcher slot |
- A rank can inherit the capabilities of the rank directly below it.
settings.manageis instance administration and covers every other capability. Discord administrators and the extra admins configured in the settings hold all capabilities.- Courses, lists, protected personnel columns, website pages and polls can be set to nur mit Einzelrecht (only with an individual right). Then the area key isn't enough and only the right on that one thing counts.
- AI features are a capability too (
ai.features.use). API keys never get it.
Suspension
A suspension (Suspendierung) is an in-game roleplay state of an active employee. The configured Discord suspension role is synced in both directions. While someone is suspended, the capabilities configured for suspended people replace all their normal ones.
API keys
API keys aren't people. An unscoped key has full access to its own instance; rank and suspension checks apply to browser sessions. Scoped keys for game servers only get the scopes they were issued with. See HTTP API.
Partner agencies
Instances can cooperate, for example EMS with the police. A cooperation never happens on its own:
- An admin proposes a cooperation with another instance. The partner's admins get a Discord DM.
- The partner accepts.
- Each side decides per module what it shares, at one of four levels:
| Level (UI label) | API value | Meaning |
|---|---|---|
| Keine Freigabe (no sharing) | none | The default |
| Nur anonymisiert (redacted) | redacted | The partner knows an entry exists. Names and details never leave the server |
| Lesen (read) | read | The partner can open the sheet but not change it |
| Lesen & Schreiben (read & write) | write | Shared incident, run together |
Redaction and visibility are enforced on the server. Shared partner data shows in a separate read view. Handing a patient over to a partner is an explicit handover step, never a silent transfer. Cooperations can be suspended, resumed or revoked.