Pay for twenty-four months and save 17% or moreOn every plan, pick the 24-month term when you order
Skip to main content

Staff permissions, one right at a time

Somebody else has to be able to restart the server while you are asleep. That should not also mean they can reset the world, delete every file and read your database password. Here it does not: 14 separate rights, handed out one by one, with 4 ready-made roles to start from and room for 15 people on every plan.

The staff screen of the Astroworld Minecraft server panel, showing a person's email address and a checkbox for each of the 14 rights

First, which permissions do you mean?

There are two completely different things called permissions on a Minecraft server, and almost everybody means one of them while reading about the other.

Panel permissions, this page, decide who may open your control panel and what they may press there: the console, the files, the backups, the settings. They are about the machine and everything on it.

In game permissions decide what a player may do while playing: which commands they can run, which areas they can build in, which rank they hold. That is a plugin's job, and setting up ranks and groups has its own guide. Somebody can be an admin in game with no panel access at all, and somebody can have your whole panel without being anything special in the world.

All 14 rights, and what each one really covers

These are checkboxes, not tiers. Nothing here unlocks anything else, so you can grant exactly the one thing somebody needs and nothing next to it. Each right is also a tab in their panel, so what they may do and what they can see are the same list.

The 14 staff permissions in the Astroworld Minecraft server panel
RightWhat it lets somebody do
ConsoleSee live output and send commands.
PowerThink twiceStart, stop and restart the server.
FilesThink twiceBrowse, edit and upload files.
Delete filesThink twiceDelete files and folders.
PluginsInstall and remove plugins.
ModsInstall and remove compatible server mods.
SettingsChange server settings and startup variables.
WorldThink twiceReset the world. Destructive, grant with care.
BackupsCreate, download and restore backups.
SchedulesManage automated tasks.
DatabasesThink twiceCreate databases and see their passwords.
PlayersManage operators, whitelist and bans.
ActivitySee the history of what happened.
CopilotUse the AI Copilot (spends the server's credits).

Two of them are not a tab. Delete files is split off from Files on purpose, so somebody can edit a config without being able to empty a folder. And the overview stays visible to everybody you invite, because it is read only: whether the server is up, how much memory it is using and the play address, nothing that can be pressed.

4 roles to start from

Most people think in roles rather than checkboxes, so there are 4 of them ready. They are starting points: pick one and then tick anything on or off, because a moderator on a survival server and a moderator on a creative one do not need the same things.

The 4 ready-made staff roles in the Astroworld Minecraft server panel
RoleWhat it is forWhat it contains
Co-adminAll 14Everything except managing staff.Console, Power, Files, Delete files, Plugins, Mods, Settings, World, Backups, Schedules, Databases, Players, Activity, Copilot
Moderator3 of 14Console, players and activity, day-to-day moderation.Console, Players, Activity
Builder4 of 14Console and files, plus backups so they can save their work.Console, Files, Backups, Activity
Viewer1 of 14Look, don't touch.Activity

How to invite somebody

  1. Open the Staff tab on your server

    It is one of the tabs in your own panel and only the owner sees it. A co-admin with every other right still does not, which is the whole point: nobody can widen their own access or bring in a friend.

  2. Type their email address

    They do not need an account yet. The invitation is stored against the address rather than against a person, so it waits for them and attaches itself to their account the first time they sign in. Inviting yourself is refused, because a second row for the owner would grant nothing and confuse the list.

  3. Pick a role, or tick the rights yourself

    Start from one of the 4 ready-made roles and adjust, or go straight to the 14 checkboxes. At least one right has to be ticked: an invitation that grants nothing is refused rather than quietly created, because a name in the list that can do nothing reads as access that exists.

  4. Send it

    They get an email with a link to the panel. The access is the row in your staff list rather than the email, so a mail that bounces or lands in spam does not cost them the invitation; they can sign in and it is there.

What only you can do, ever

Two things cannot be handed to anybody, no matter how much you trust them, and both are the same reasoning. Managing staff is one: an account that can grant access can grant it to itself, and then a single leaked password is not one person's access but everybody's. So even a co-admin holding all 14 rights does not see the staff screen.

Billing is the other, and it is not in the server panel at all. Your subscription, your payment method and your invoices live in your own dashboard, which nobody you invite to a server ever reaches. Somebody can run your entire server without ever being able to change what you pay for it.

Changing your mind, and being reminded to

  1. Change what somebody may do

    Tick a right on or off in their row and save. It applies immediately: a tab they no longer have disappears from their panel and the route behind it refuses them as well, so a page they left open does not keep working.

  2. Take access away entirely

    Remove them from the list. Nothing they did is removed with them, because their actions stay in the Activity timeline with their name on them, which is exactly what you want the day you are trying to work out what happened.

  3. Let the security check look over it

    The AI security check reads your staff list as part of a full pass: who holds a right that can destroy or expose something, which invitations have been sitting open, and who has not opened the panel in 3 months. It reports; you decide.

The three things the security check watches here

Handing out access is the easy part. The part everybody skips is looking at it again six months later, so the AI security check does that pass for you as part of a full run and reports what it finds.

What the Astroworld AI security check reports about staff access
What it looks atWhat it says
Rights that can destroy or expose5 of the 14Anybody other than you holding World, Delete files, Databases, Power, Files is worth a second look. Not because it is wrong, but because it is the set you hand a co-owner and not a moderator, and people tend to grant it once and forget.
Invitations nobody acceptedAfter 2 weeksAn open invitation is access waiting to be claimed by whoever controls that email address. If the address changed hands, or you typed one letter wrong, the access is still sitting on the table.
Staff who stopped showing up3 months quietAccess nobody is using is access nobody is watching. It is not a hole today. It is one on the day that account is lost, and by then nobody remembers it was there.

It reports and it does not act. Removing a person or taking a right away is yours, on the Staff tab, because an assistant that can quietly revoke somebody's access is a different and much worse product. The full security check covers a lot more than the panel side.

Questions about staff access to your server

How do I give someone access to my Minecraft server?

Open the Staff tab in your panel, type their email address and tick what they may do. There are 14 separate rights and 4 ready-made roles to start from, and you can invite up to 15 people per server. They do not need an account first: the invitation waits for the address and attaches itself to their account when they sign in.

What are the ready-made roles?

Co-admin is everything except managing staff; Moderator is console, players and activity, day-to-day moderation; Builder is console and files, plus backups so they can save their work; Viewer is look, don't touch. They are starting points rather than fixed roles: pick one and then tick anything on or off, because what a moderator on your server needs is not what one needs on somebody else's.

Can a co-admin invite other people?

No. Managing staff is the owner's, always, and the check refuses even somebody who holds every other right. That is deliberate: an account that can grant access can grant it to itself, and then a single leaked password is not one person's access but everybody's. Billing works the same way and lives in your dashboard rather than in the server panel at all.

Which rights should I be careful with?

5 of the 14: World, Delete files, Databases, Power, Files. World resets the world, Delete files removes anything, Databases shows database passwords in readable text, Power stops the server and Files can rewrite any file on it. None of them are wrong to grant, they are simply the set you give a co-owner. The security check flags them when somebody else holds one, so you are reminded rather than expected to remember.

How many people can I add?

15 per server, on every plan, at no extra cost. There is no tier here that unlocks more seats and no per-user price. If you genuinely need more than 15 on one server, that is worth a message rather than a workaround, because it usually means a network of servers rather than one crowded one.

Is this the same as ranks and permissions in the game?

No, and this is the confusion worth clearing up. These rights decide who may open your control panel and what they may press there: the console, the files, the backups. Ranks in the game decide what a player may do while playing: which commands they can run, which areas they can build in. Somebody can be a server admin in game with no panel access at all, and the other way round.

Can I see what my staff did?

Yes, and it is the same timeline you see for yourself: every start, stop and restart, every file change, every backup, and every change the AI applied, each line with a timestamp and a name on it. Removing somebody from your staff list does not remove their history, which is the point of having one.

What happens when I take a right away?

It stops immediately. The tab disappears from their panel and the route behind that tab refuses them too, so somebody who left the page open does not keep working from a screen that no longer reflects what they may do. Nothing on the server itself changes, so nobody is disconnected and nothing restarts.

Can staff restore a backup?

Only with the Backups right, and it is worth knowing what that one covers: creating, downloading and restoring. A restore replaces the whole server folder with an older version of itself, so it is the heaviest button anybody can press. The AI Copilot never applies a restore on its own in any mode, and it needs that same right on that server before it will even prepare one.

Does giving somebody the Copilot cost me anything?

It spends the server's credits rather than theirs, so yes, in the sense that the budget is shared. That is why it is its own right instead of coming along with Console: somebody who should be able to read the console and kick a player does not automatically get to spend the server's credits on an AI conversation. The right also opens the player experience tab, because somebody working with the Copilot should be able to see what the players are complaining about.

Where to find it

The Staff tab is in your own server panel, on every plan, with nothing to order and no per-user price. You can also open a sandbox server without an account and look at the screen before you invite anybody real.

Try the panel without an account Everything the panel does The AI security check on your server Ranks and groups inside the game Your play address, and adding more How the nightly backups work View plans and prices Ask us a question first

The 14 rights, the 4 roles, the 15 seats and the 5 rights the security check flags are read when this page is built from the same file the panel draws its checkboxes from. Written 31 August 2026.