- Documentation
- 08Configure
Permissions
One permission per action, the padlock rule, the full catalogue and each rank level’s defaults.
In SuperMDT, every sensitive action has its own permission: “Licenses › Revoke”, “Calls › Transfer a call”, “Records & fines › Edit a closed file”… You give a rank exactly what you want, without handing over a whole module. Permissions are set rank by rank, in the permission matrix.
Principles
Section titled “Principles”- One permission, one action. Seeing, creating, transferring, closing, cancelling a fine, lifting a sanction: every action you might want to hand out separately has its own box.
- What is yours stays yours. A file’s author edits it until it is closed, an operation’s author and Lead run it, everyone declares their own leave and sees their own sanctions, summons and payslips. Permissions such as Edit any operation or Manage others’ leave open the same action on what belongs to others.
- Hierarchy always applies. Even with the permission, you only act on ranks strictly below yours (roster, ranks, discipline, summons, others’ leave), and you only give a rank permissions you have yourself.
- Administrators have everything. The organization’s owner and administrators have every permission of the enabled modules, in every service.
- The server checks. Hiding a button is not enough: every action is checked on the server with its precise permission.
Hidden or locked
Section titled “Hidden or locked”The interface never offers you an action you are not allowed to do. Two cases:
- Hidden: what you cannot see at all disappears. A module, page, tab or section without the read permission shows neither in the navigation nor in the page.
- Locked: on a page you can see, an action you are not allowed stays visible but greyed out, with a small padlock. Hover it (or read it with a screen reader): the help names the permission you would need, for instance Restricted: Warrants › Delete a warrant. Just ask whoever manages your service’s ranks.
permissions-lockedReading the matrix
Section titled “Reading the matrix”permissions-matrix- Domains: Operations, Records, Staff, Department. Under each, the modules enabled in the service; click a module to expand its permissions, or Expand all.
- Each permission has its label and, below it, a short help (also on hover).
- A module’s counter (for instance “3/6”) and the overall counter (“60 of 160 granted”) show where the rank stands.
- Whole group ticks or unticks a module’s permissions at once (only those you can give).
- Search finds a permission by a word of its label or help (“revoke”, “fine”, “call”).
- The filter shows All, Granted or Not granted.
- A permission you do not have yourself is locked: you can neither grant nor remove it.
- Permissions marked (game) below only show when the game integration is on.
Each box is saved as soon as you tick it.
The catalogue
Section titled “The catalogue”“Default” is the first rank level that gets the permission when you create a service from a template (recruit, member, supervisor, command); the levels above have it too. You can change everything freely afterwards.
Operations
Section titled “Operations”| Module | Permission | What it allows | Default |
|---|---|---|---|
| Duty | See the team’s hours | Everyone’s hours, weeks and shifts in the service (everyone always sees their own) | supervisors and up |
| End someone else’s duty | Clock out a colleague who forgot to | supervisors and up | |
| Set automatic cut-offs | Inactivity cut-off and reminder (the Settings tab, hidden without it) | command | |
| Dispatch | See dispatch | The console: call queue, units and live map | every rank |
| Choose call types | The list of call natures offered to dispatch | command | |
| Configure dispatch | Automatic closing of forgotten calls, last position after going off duty, panic button, call templates | command | |
| Panic button › Trigger | Send a distress alert (MDT, tablet, in-game key or command), while on duty | every rank | |
| Panic button › Acknowledge an alert | Take in charge then close a colleague’s distress alert | supervisors and up | |
| Sectors › View sectors | Patrol sectors on the map, and the sector of calls and units | every rank | |
| Sectors › Draw and edit | Draw, rename, color and delete the service’s sectors | command | |
| Game alerts › Configure (game) | The game alerts the service receives: types, priority, nature, report merging and cap | command | |
| Calls | See calls | The call queue and its history | every rank |
| Create a call | Enter a new call in the service queue | members and up | |
| Edit a call | Nature, place, priority, status, notes; attach one’s own unit | members and up | |
| Assign units | Attach or detach any unit on a call, link a report | supervisors and up | |
| Transfer a call | Send the call to another service’s queue | members and up | |
| Close a call | End a call with its outcome | members and up | |
| Reopen a call | Put a closed call back in the queue | supervisors and up | |
| Units | See units | The service’s patrols and their statuses | every rank |
| Form a unit | Create a patrol you are part of (joining a unit only requires being on duty) | members and up | |
| Manage one’s own unit | Callsign, vehicle, partners and disbanding one’s unit | members and up | |
| Manage all units | Form, edit, reshuffle or disband any unit | supervisors and up | |
| Change another unit’s status | Set a unit you are not in to “available”, “busy”… | supervisors and up | |
| Set the status list | Create, rename, reorder or archive unit statuses | command | |
| Live map | See the live map | Positions of on-duty units | every rank |
| BOLOs | See BOLOs | Wanted people and vehicles | every rank |
| Issue a BOLO | Publish a be-on-the-lookout | members and up | |
| Resolve a BOLO | Mark a BOLO as resolved | members and up | |
| Delete a BOLO | Archive a BOLO (restorable) | supervisors and up |
Records
Section titled “Records”| Module | Permission | What it allows | Default |
|---|---|---|---|
| Citizens | See citizens | List, search and citizen records | every rank |
| Create a citizen | Add a citizen record | members and up | |
| Edit a citizen | Identity, custom fields and photo | members and up | |
| Change status | Declare a citizen deceased or alive again | members and up | |
| Delete a citizen | Archive a record (restorable) | supervisors and up | |
| Detach from the game | Cut the link between a record and the in-game character | command | |
| Licenses › See licenses (game) | The “Licenses” tab of in-game records | every rank | |
| Licenses › Revoke (game) | Revokes the license in game, with a reason | supervisors and up | |
| Licenses › Restore (game) | Gives back a revoked license in game, with a reason | supervisors and up | |
| Players › See game accounts (game) | “Player” tab, player pages and search; identifiers masked | command | |
| Players › See full identifiers (game) | Unmasked license, Discord and FiveM IDs | command | |
| Players › Link a character (game) | Attach or detach a character from its game account | command | |
| Properties › View properties (game) | The “Properties” tab of in-game records: homes, role, co-residents (Properties) | every rank, police and justice only | |
| Vehicles | See vehicles | List, search and vehicle records | every rank |
| Register a vehicle | Add a vehicle record | members and up | |
| Edit a vehicle | Plate, model, owner, fields and photo | members and up | |
| Change status | Stolen, seized, impounded… | members and up | |
| Delete a vehicle | Archive a record (restorable) | supervisors and up | |
| Detach from the game | Cut the link between the record and the in-game vehicle | command | |
| Plate reader › Use in game (game) | Receive the plate reader alerts in game, on duty | every rank | |
| Plate reader › Configure the reader (game) | Turn the service’s reader on, choose what triggers an alert, the sound and the trace | command | |
| Weapons | See weapons | Registry and weapon records | every rank |
| Register a weapon | Add a weapon to the registry | members and up | |
| Edit a weapon | Serial number, model, owner, fields and photo | members and up | |
| Change status | Stolen, seized, destroyed… | members and up | |
| Delete a weapon | Archive a record (restorable) | supervisors and up | |
| Detach from the game | Cut the link between the record and the in-game weapon | command | |
| Operation reports | See all operations | Read the service’s operations, not only those you took part in | every rank |
| Open an operation | Create an operation report you become the author of | every rank | |
| Join an operation | Add yourself to the officers of an ongoing operation | every rank | |
| Edit any operation | Fix the content of an operation you neither wrote nor lead, even once approved | supervisors and up | |
| Manage officers and roles | Add, remove officers and change their role on any operation | supervisors and up | |
| Close or reopen the facts | On any operation, even when not its author | supervisors and up | |
| Submit for review | Send any operation for review, even when not its author | supervisors and up | |
| Add photos, notes and hostages | Contribute to any operation, even without being on scene | supervisors and up | |
| Approve or reject | Decide on submitted operations | command | |
| Delete an operation | Archive an operation (restorable) | supervisors and up | |
| Records & fines | See records and files | Criminal records, offense files and fines | every rank |
| Create an offense file | Enter a file; its author can edit it until it is closed | members and up | |
| Edit someone else’s file | Before closing, on a file you did not write | supervisors and up | |
| Edit a closed file | Fix a file already on the record | command | |
| Change the legal status | For types without review: close, put on hold… someone else’s file | supervisors and up | |
| Delete a file | Archive a file and remove its offenses from the record (restorable) | supervisors and up | |
| Mark a fine paid | Set a fine to paid or unpaid | members and up | |
| Cancel a fine | Cancel a fine (no longer owed) | supervisors and up | |
| Retry a collection (game) | Send a failed in-game fine collection again | members and up | |
| Prosecutor and lawyer › Assign or request | Assign a file’s prosecutor or lawyer, or request one (MDT and Discord); cancel a request | members and up | |
| Prosecutor › Act as a file’s prosecutor | Be assigned, accept a prosecutor request, see the files one prosecutes | members and up, justice only | |
| Lawyer › Defend (lawyer) | Be assigned as lawyer, accept a public defender request; see only the files and cases one defends | never by default (the Justice template’s Lawyer rank) | |
| Record › See expunged convictions | They stay visible, marked “expunged”; hidden from everyone else | every rank, justice only | |
| Record › Expunge and restore | Expunge a conviction or a whole record (hidden, never deleted), then restore it | command, justice only | |
| Record › Set prosecution and record rules | Prosecutor or lawyer request lifetime, automatic record expungement | command, justice only | |
| Warrants | See warrants | Arrest and search warrants | every rank |
| Issue a warrant | Request an arrest or search warrant | members and up | |
| Execute a warrant | Mark a warrant in force as executed | members and up | |
| Cancel a warrant | Lift an active or expired warrant | supervisors and up | |
| Delete a warrant | Archive a warrant (restorable) | supervisors and up | |
| Electronic tags | View tags (game) | Active tags, their log, their position on the live map and their alerts | every rank |
| Place a tag (game) | Reason, decision, end date and allowed or forbidden zones | supervisors and up | |
| Remove a tag (game) | End a tag before it expires, with a reason | supervisors and up | |
| Medical records | See medical records | Visits, treatments and history | every rank |
| Record a visit | Consultation, treatment, billing | members and up | |
| Edit own visits | Fix a visit you recorded; a signed visit must be signed again | members and up | |
| Edit all visits | Fix a colleague’s visit | supervisors and up | |
| Sign a visit | Attest a visit; the care bill is then sent in game | members and up | |
| Edit medical history | Blood type, allergies, medication, emergency contact | members and up | |
| Mark a bill paid | Track payment of a visit | members and up | |
| Retry a care bill (game) | Send a failed care bill again in game | members and up | |
| Write operative reports | Write an operative report and edit your own; a signed report must be signed again | supervisors and up | |
| Edit all operative reports | Fix a colleague’s operative report | command | |
| Sign an operative report | Attest an operative report (yours or a colleague’s) | supervisors and up | |
| Delete a visit | Archive a visit (restorable) | supervisors and up | |
| Court cases | See cases | Cases, hearings and rulings | every rank |
| Open a case | Create a court case | members and up | |
| Edit a case | Title, parties, fields and notes | members and up | |
| Manage hearings | Schedule or remove a hearing | members and up | |
| Change status and rule | Investigation, trial, dismissal… | command | |
| Delete a case | Archive a case (restorable) | supervisors and up | |
| Complaints | See complaints | The complaint list and details, and a citizen’s complaints on their record | every rank |
| Record a complaint | Enter a citizen’s complaint: accused, facts, date, place, attachments | members and up | |
| Handle a complaint | Change its status, add notes and attachments, correct its details | members and up | |
| Assign a complaint | Hand a complaint to a member (or take it back) | supervisors and up | |
| Delete a complaint | Archive a complaint (restorable) | supervisors and up | |
| Set the statuses | The organisation’s complaint statuses: labels, colours, open or closed | command | |
| Evidence | View evidence | The evidence register, its links and chain of custody (Evidence) | every rank |
| Record evidence | Log sealed evidence (you become its holder) | members and up | |
| Edit evidence | Description, type, quantity, photos, links and location | members and up | |
| Transfer your evidence | Hand evidence you hold to another officer, with a reason | members and up | |
| Transfer any evidence | Transfer evidence held by another officer or in storage | supervisors and up | |
| Change the status | Under analysis, stored, returned, destroyed | supervisors and up | |
| Delete evidence | Archive evidence (restorable) | supervisors and up | |
| Evidence settings | Seal prefix and list of evidence types | command | |
| Penal code | Read the code | Read other services’ penal codes | every rank |
| Write offenses | Add, edit, import or remove code lines | members and up | |
| Manage levels | Infraction, misdemeanor, felony…: create, order, archive | supervisors and up | |
| Manage penalty degrees | Degrees and the levels they apply to | supervisors and up | |
| Structure the code | Create, rename or remove a code and its columns | command | |
| Choose the mode | One shared code or one code per police service | command | |
| Offense file types | See types | Offense file types and their settings | every rank |
| Create and edit types | Fields, covered levels, statuses | command | |
| Choose reviewers | The ranks that review a type’s files | command | |
| Delete a type | Archive a file type (restorable) | command |
| Module | Permission | What it allows | Default |
|---|---|---|---|
| Roster | See the roster | Service members, ranks and callsigns | every rank |
| Assign and change rank | Add a member to the service or change their rank (below yours) | supervisors and up | |
| Remove from the service | Remove a lower-ranked member | supervisors and up | |
| Invite | Create an invite link to a lower rank | supervisors and up | |
| Revoke an invite | Disable a service invite link | supervisors and up | |
| Ranks | See ranks | The hierarchy and each rank’s permissions | every rank |
| Create a rank | Add a rank below yours | command | |
| Rename and reorder | Rename or move lower ranks | command | |
| Edit permissions | Tick lower ranks’ permissions (only those you have) | command | |
| Delete a rank | Archive a lower rank with no members | command | |
| Leave | See the service’s leave | The leave board of every member | every rank |
| Declare one’s leave | Declare, extend or cancel one’s own leave | every rank | |
| Manage others’ leave | Declare, edit or cancel a lower rank’s leave | supervisors and up | |
| Set up review | The ranks that approve leave | command | |
| Discipline | See the service’s sanctions | Every sanction (members always see their own if the service allows it) | supervisors and up |
| Propose a sanction | Submit a sanction for review | members and up | |
| Apply a sanction | Sanction directly, for types your rank allows | supervisors and up | |
| Approve or reject | Decide on proposals (types your rank allows, never your own) | supervisors and up | |
| Lift a sanction | Lift early a sanction of a type your rank allows | supervisors and up | |
| Lift any sanction | Lift any sanction of a lower rank | command | |
| Archive a sanction | Archive or restore a lower rank’s sanction | command | |
| Set up types | Sanction types, minimum rank, visibility | command | |
| Summons | See the service’s summons | Every summons (members always see their own) | supervisors and up |
| Summon | Summon a lower-ranked member; manage one’s own summons | supervisors and up | |
| Take attendance | Record who attended any summons | supervisors and up | |
| Manage all summons | Edit, cancel or restore others’ summons | command | |
| Payroll | See the service’s payroll | Periods, lines and scales (everyone always sees their own payslip) | supervisors and up |
| Set pay scales | Rates per rank, cap and payroll settings | command | |
| Compute periods | Compute and recompute a period not yet approved (periods open by themselves) | command | |
| Bonuses and deductions | Add or remove a bonus or a deduction | command | |
| Approve a period | Freeze a period’s payroll | command | |
| Send transfers (game) | Prepare, send, cancel or retry in-game transfers | command |
Department
Section titled “Department”| Module | Permission | What it allows | Default |
|---|---|---|---|
| Announcements | Read announcements | The service’s announcements | every rank |
| Post in the service | Post, edit or archive one’s own announcements | supervisors and up | |
| See who read | Readers and acknowledgements of any announcement | supervisors and up | |
| Pin | Pin or unpin an announcement | command | |
| Manage all announcements | Edit, archive or restore others’ announcements | command | |
| Post to the whole organization | Announcements visible to every service | command | |
| Documents | Read the library | The department’s procedures, regulations and guides, depending on the ranks allowed (Documents) | every rank |
| Write the library | Create and edit the department’s documents; each edit creates a version | supervisors and up | |
| See who has read | Readers and read confirmations of the documents | supervisors and up | |
| Archive a document | Archive or restore a library document | command | |
| Manage templates | Create, edit and archive templates of issued documents, install the starter ones | command | |
| Issue a document | Fill in a template from a record and sign it | members and up | |
| See the department’s issued documents | The whole department’s register (everyone always sees their own) | supervisors and up | |
| Cancel an issued document | Cancel, with a reason, a document issued by someone else | supervisors and up | |
| Verify a document | Check a document’s authenticity with its code, even from another department | every rank | |
| Print in game (game) | Receive a document or a record as an inventory item from the tablet (In-game printing) | every rank | |
| Document settings | The department’s in-game printing: on/off and item name | command | |
| Statistics | Staff section | Members, leave and sanctions | supervisors and up |
| Duty section | Hours and everyone’s ranking | supervisors and up | |
| Operations section | Calls and units | supervisors and up | |
| Offenses section | Files, warrants and BOLOs | supervisors and up | |
| Reports section | Operations and reviews | supervisors and up | |
| Medical section | Visits and treatments | supervisors and up | |
| Justice section | Cases and hearings | supervisors and up | |
| Payroll section | Amounts paid per period | command | |
| Delegated administration | See the audit log | Every sensitive action in the organization | never by default |
| See archives | Everything deleted in the organization | never by default | |
| Restore from archives | Bring back a deleted item (purging stays with the owner) | never by default | |
| Manage forms | Citizen, vehicle, weapon, report… fields (offense file types excluded) | never by default | |
| Manage reference lists | Value lists (penal code excluded) | never by default | |
| Set up Discord | Server, roles, channels and bot commands | never by default | |
| Set up the game (game) | Jobs, game accounts, in-game features | never by default | |
| Set up the map | Live map settings and source keys | never by default | |
| Set up notifications | Allowed Discord direct messages and their categories (Notifications) | never by default |
The officer’s profile
Section titled “The officer’s profile”Each officer’s profile (photo, phone, motto, bank account) has no permission of its own: everyone edits their own, nobody edits someone else’s. Reading it follows fixed rules, enforced by the server:
- photo, phone and motto: every member of the organization;
- duty status and unit: members of a shared service and administrators;
- hours this week: Duty › See the team’s hours;
- bank account: the officer, and whoever has Payroll › Compute periods, Approve a period or Send transfers in one of their services.
The directory follows the same rules: no permission, it opens to every member assigned to a service that has the module enabled (and to administrators); “On duty” only shows for a shared service.
Assign me (assigning yourself to a service and rank) is reserved to administrators. So is creating missing pay periods by hand: periods open by themselves (see Payroll).
Delegated administration
Section titled “Delegated administration”The Delegated administration module hands organization settings to a rank without making it an administrator. Enable it on the service (Settings › Services), then tick in the matrix what you want to delegate: audit log, archives (view, restore), forms, reference lists, Discord, game, map, notifications. These permissions are never given by default. A rank with at least one of them sees the Settings entry, with only the matching sections.
Always reserved to administrators: services (and their modules), members’ role and status in the organization, configuration import and export, turning the game integration on or off, and configuration archives (ranks, services, forms…). Permanently purging archives stays with the owner.
Ranks created before precise permissions
Section titled “Ranks created before precise permissions”Before, one permission covered a whole module (for instance “Records & fines › Edit”). Each former permission was replaced by all the precise permissions it covered: every rank keeps exactly its rights. For instance:
| Former permission | Becomes |
|---|---|
| Records & fines › Edit | Edit someone else’s file, Edit a closed file, Change the legal status, Mark a fine paid, Cancel a fine, Retry a collection |
| Calls › Edit | Edit a call, Transfer a call, Close a call, Reopen a call |
| Dispatch › Manage | Calls › Assign units, Units › Manage all units, Units › Change another unit’s status, Dispatch › Choose call types |
| Roster › Manage | Assign and change rank, Remove from the service, Invite, Revoke an invite |
| Ranks › Manage | Create a rank, Rename and reorder, Edit permissions, Delete a rank |
| Statistics › View | every section (payroll only if the rank could also see payroll) |
Nothing to do on your side: just fine-tune, rank by rank. A configuration exported before this change is translated on import too (Import and export).
Ranks that existed before the panic button and patrol sectors received them the same way: Panic button › Trigger and Sectors › View sectors for ranks that could see calls or dispatch, Panic button › Acknowledge an alert for those that could assign units, Sectors › Draw and edit for those that could configure dispatch.
Lawyer and prosecutor
Section titled “Lawyer and prosecutor”“Justice only”: the permission is only granted by default to ranks of justice services when you create a service from a template; you can then grant it by hand to any rank of a service where the module is on.
In the Justice template, the Lawyer rank doesn’t have the prosecutor’s rights. It keeps the service’s everyday life (roster, directory, absences, sanctions, summons, pay, announcements) and reading the penal code and file types, and gets Lawyer › Defend (lawyer). It sees neither citizens, nor records, nor cases: only the files and cases where it is assigned as defence, read-only (see Records & fines and Court cases).
Organizations created before. An update handled existing ranks:
- only ranks recognised as lawyers lost rights: a rank of a justice service (or of a custom service whose name suggests the bar) named “Lawyer” (or “Avocat”), or whose name contains a lawyer word (lawyer, attorney, counsel, defence, avocat…), unless it contains a prosecutor, magistrate or clerk word (prosecutor, judge, attorney general, district attorney, clerk, chief…). They got the rights described above;
- other ranks got the new permissions according to what they already did: Assign or request for those who create files; in justice, Act as a file’s prosecutor for those who create files or edit cases, See expunged convictions for those who see records, Expunge and restore and Set prosecution and record rules for those who change a case’s status;
- the Complaints module was turned on for police and justice, with see, record and handle, assign and delete, set the statuses depending on whether the rank saw records, created files, deleted them or set permissions.
Nothing was taken from any rank other than a lawyer. Then check your ranks and fine-tune them in Ranks and permissions.