Permissions
SafeGuard has two independent permissions on the FiveM server and separate roles in the dashboard. Configure both: access to the menu must not automatically make someone exempt from detections.
FiveM permissions
| Permission | Allows | Does not automatically allow |
|---|---|---|
safeguard.admin | F10 menu and in-game sg commands | Ignoring detections or punishments |
safeguard.bypass | Staff exemption from scoring and punishments | Opening the menu, banning or using commands |
Minimal ACE configuration in server.cfg:
add_ace group.admin safeguard.admin allow add_ace group.admin safeguard.bypass allow # Example: add a real identifier to the admin group. add_principal identifier.license:xxxxxxxxxxxxxxxx group.admin
Restart the resource (restart safeguard) and join with that account. The server console can always use sg; players can only use staff actions when they have safeguard.admin or a framework permission configured in Config.AdminPermissions.
builtin.everyone. Give them only to staff groups or specific identifiers. Every action is checked again by the server, but a broad permission still gives access to moderation tools.Framework permissions
If your framework already has roles, recognise them in config.lua without ACE:
Config.AdminPermissions = { 'admin', 'admin.permissao' }
Config.Staff = {
Exempt = true,
Ace = 'safeguard.bypass',
FrameworkPermissions = { 'admin', 'admin.permissao' },
}Config.AdminPermissionsdecides who opens F10 and usessg.Config.Staff.FrameworkPermissionsdecides who is exempt whenExempt = true.- ACE and framework permissions can be used together; either path can authorise a person.
Use sg staff to confirm who is exempt and why, and sg framework to confirm the active adapter. See Frameworks for ESX, QBCore, Qbox, vRP and standalone.
Staff menu and commands
With safeguard.admin, press F10 in game or use sg. The menu lets staff find players, inspect detections and use spectate, screenshots, warnings, quarantine, kicks and bans. Destructive actions ask for confirmation and the server checks permission for every request.
With safeguard.bypass, staff do not accumulate risk while using noclip, teleports, invisibility or godmode. Limit bypass to the people who need it and remove it when someone leaves staff.
The complete action, command and limit reference is in Staff tools.
Dashboard roles
Organization roles control the dashboard and are separate from FiveM ACE:
| Role | Typical use | Can do |
|---|---|---|
| Owner | Community owner | Everything, including billing and deleting the organization |
| Administrator | Team and server management | Members, licenses, configuration and everything a security manager can do |
| Security Manager | Anticheat lead | Rules, bypasses, servers, audit, scanner and moderation actions |
| Moderator | Daily moderation | Players, notes, detection feedback, bans and live actions |
| Viewer | Read-only access | View servers, players, detections, bans, rules and scanner |
In Team, you can only assign roles below your own: an administrator can create moderators and security managers, but not another owner. Give every person their own account; never share sessions or passwords.
Secure first-day checklist
- Give
safeguard.adminandsafeguard.bypassonly to one test staff account. - Check
sg staff, open F10 and confirm that a normal player gets a no-permission notice. - Enable learning mode before allowing automatic bans.
- Invite dashboard moderators with the minimum role they need.
- Review the Audit log after the first actions to confirm who made each change.
See also: Installation, Dashboard, Configuration and Staff tools.