SafeGuard

Permissions

SafeGuard has two independent permissions on the FiveM server and separate roles in the dashboard. Configure both: access to the menu must not automatically make someone exempt from detections.

FiveM permissions

PermissionAllowsDoes not automatically allow
safeguard.adminF10 menu and in-game sg commandsIgnoring detections or punishments
safeguard.bypassStaff exemption from scoring and punishmentsOpening the menu, banning or using commands

Minimal ACE configuration in server.cfg:

add_ace group.admin safeguard.admin allow
add_ace group.admin safeguard.bypass allow

# Example: add a real identifier to the admin group.
add_principal identifier.license:xxxxxxxxxxxxxxxx group.admin

Restart the resource (restart safeguard) and join with that account. The server console can always use sg; players can only use staff actions when they have safeguard.admin or a framework permission configured in Config.AdminPermissions.

Never grant these permissions to builtin.everyone. Give them only to staff groups or specific identifiers. Every action is checked again by the server, but a broad permission still gives access to moderation tools.

Framework permissions

If your framework already has roles, recognise them in config.lua without ACE:

Config.AdminPermissions = { 'admin', 'admin.permissao' }
Config.Staff = {
    Exempt = true,
    Ace = 'safeguard.bypass',
    FrameworkPermissions = { 'admin', 'admin.permissao' },
}
  • Config.AdminPermissions decides who opens F10 and uses sg.
  • Config.Staff.FrameworkPermissions decides who is exempt when Exempt = true.
  • ACE and framework permissions can be used together; either path can authorise a person.

Use sg staff to confirm who is exempt and why, and sg framework to confirm the active adapter. See Frameworks for ESX, QBCore, Qbox, vRP and standalone.

Staff menu and commands

With safeguard.admin, press F10 in game or use sg. The menu lets staff find players, inspect detections and use spectate, screenshots, warnings, quarantine, kicks and bans. Destructive actions ask for confirmation and the server checks permission for every request.

With safeguard.bypass, staff do not accumulate risk while using noclip, teleports, invisibility or godmode. Limit bypass to the people who need it and remove it when someone leaves staff.

The complete action, command and limit reference is in Staff tools.

Dashboard roles

Organization roles control the dashboard and are separate from FiveM ACE:

RoleTypical useCan do
OwnerCommunity ownerEverything, including billing and deleting the organization
AdministratorTeam and server managementMembers, licenses, configuration and everything a security manager can do
Security ManagerAnticheat leadRules, bypasses, servers, audit, scanner and moderation actions
ModeratorDaily moderationPlayers, notes, detection feedback, bans and live actions
ViewerRead-only accessView servers, players, detections, bans, rules and scanner

In Team, you can only assign roles below your own: an administrator can create moderators and security managers, but not another owner. Give every person their own account; never share sessions or passwords.

Secure first-day checklist

  1. Give safeguard.admin and safeguard.bypass only to one test staff account.
  2. Check sg staff, open F10 and confirm that a normal player gets a no-permission notice.
  3. Enable learning mode before allowing automatic bans.
  4. Invite dashboard moderators with the minimum role they need.
  5. Review the Audit log after the first actions to confirm who made each change.

See also: Installation, Dashboard, Configuration and Staff tools.