Access Model
Learn how roles, server access, plan limits, and server features control what you can use.
Membership and access are separate ideas
Joining an organization does not give you access to every server or page.
EnderDash checks four things:
- your organization role
- your server access
- the features in your plan
- the features that the server supports
For members, live operations also use scoped grants. A server can be visible while a particular file, command, or player action remains unavailable. See scoped access grants.
Two people in the same organization can therefore see different pages or panels.
Organization roles
| Role | Access |
|---|---|
| Owner | Full control of the organization |
| Admin | Control of daily organization tasks |
| Member | Access through matching grants |
Owners and admins have more access than members.
Owner and admin actions
Owners and admins can manage these organization actions:
- Setup
- server creation and deletion
- agent-key rotation
- Billing
- Audit log
- Ocelot settings
- member and server access management
Member server grants do not grant these administrative permissions. Members need the team-collaboration plan feature for organization workspace operations.
OAuth administration
Organization owners and admins manage Game OAuth clients for their organization. These clients let another application verify a game account through an allowed server.
Admin > OAuth Clients manages sign-in with EnderDash dashboard accounts. This page requires the EnderDash platform-admin role. An organization owner or admin does not automatically have that role.
Signing in through either OAuth provider does not grant organization membership or server access. See Account OAuth and Game OAuth for their separate integration flows.
Why a page or panel can still be missing
Your role is only one part of access. A page or panel also depends on:
- your access to the server
- the features in the organization plan
- the features that the connected server supports
You will not see every panel unless all these requirements are met.
The most common source of confusion
The most common access complaint is:
I can see the organization, but not the server or panel I need.
Check the server target, action allowlist, scope matchers, deny grants, and expiry. Then check the plan and runtime capability. Owners and admins have elevated agent access; member grant restrictions do not reduce that elevated role.
Frozen servers
After a plan downgrade, an organization can have more servers than its plan allows. EnderDash does not remove the extra servers.
EnderDash sorts the servers by creation date. It keeps the oldest servers active until it reaches the plan limit.
EnderDash marks each newer server as Frozen.
A frozen server:
- appears with a Frozen badge instead of Online or Offline
- is blocked from dashboard access and actions
- rejects new agent connections through the signaling service
- can still be removed by an admin
To restore access, remove servers until the total meets the plan limit. You can also upgrade the plan.
When the total is within the limit, EnderDash activates all remaining servers. Frozen servers keep their configuration and agent key.
Only an admin can remove a frozen server.
Related pages
Was this page helpful?
Send a quick note if anything is missing or unclear.
Last updated on