Browse docs

Permissions

Set up administrator commands, DOJ role mappings and the permissions required for records and signatures.

DOJ access combines the player's current job and duty state, a mapped DOJ role, action permissions and access to the particular case or workspace. A boss grant alone does not make every document visible or make a character eligible to sign every signature line.

Administrator commands

Install the shared permissions bootstrap before using /jobconfig, /jobconfigimport or /setboss. Jobs Base owns these commands and their command-permission configuration.

/setboss doj <grade> grants the shared management permissions for the chosen numeric job grade. Use the actual configured job name and grade. Assign ordinary employee permissions through your job's management tools rather than giving every employee administrator command access.

Map technical grades to DOJ roles

The default records mapping is empty and access is closed until you configure it. In /jobconfig → Department of Justice Jobs → Case-file access, set a mapping version and assign the technical grade keys.

The equivalent open configuration looks like this:

config/config.lua
-- Example only: replace these keys with your framework's real grade_name values.
Config.RecordsAuthorization = {
    mappingVersion = "doj-roles-v1",
    gradeBindings = {
        prosecution = { "prosecutor" },
        judiciary = { "judge" },
        court_administration = { "court_clerk" },
    },
}

The bindings use the technical grade_name, not the numeric grade or the visible rank label. Give each grade exactly one domain. Change the mapping version whenever you change the bindings. An unmapped grade or a grade assigned to multiple domains cannot access records.

DOJ action permissions

PermissionIDAllows
Manage legal codes19Edit the legal-code catalog
Manage offences20Edit the Fine Catalogue
Manage hearings2301Manage hearings
Manage elections2302Manage elections
Manage conditions2303Manage structured conditions
Manage courtroom2304Manage courtroom operations
Present courtroom evidence2305Present evidence in the courtroom
Manage case files2306Use record-management actions within accessible cases
Manage document templates2307Manage the shared template library
Sign documents2308Sign eligible DOJ document lines

File-based registers require their configured read/edit clearance. Writes require the court-administration role and the register's writePermission; the name-change and license providers use their dedicated authorization permissions. Legacy civil-registry workflows retain the separate View, Manage and Authorize permissions in the range 2310–2333. See Registries.

Additional actionIDAllows
Vehicle reports1401Read permitted Mechanic inspection and registration records while on duty
View Finance2340Read faction balances and DOJ financial history
Transfer funds2341Pay a configured faction from the DOJ/state treasury
Collect funds2342Move faction money into the DOJ/state treasury
Bank investigations2343Read supported citizen accounts and statements
Freeze accounts2344Freeze/unfreeze supported accounts; also requires bank-investigation access
Manage citizen licenses2345Grant/revoke licenses from Citizens

Finance mutations also require Finance access; citizen actions require File Explorer access. Mutations recheck duty and current access. Provider support remains separate from having the permission; see Finance.

Case and workspace access

Case roles distinguish Owner, Editor and Viewer. Owners and editors can edit and share documents when their job permissions allow the action. Viewers can read them.

Share workspace grants View or Edit to a current member of the same job. This is inherited access to that workspace's active content; it does not turn a shortcut into a grant to its target. Edit access does not authorize a recipient to move another person's files out of their workspace. Removing a workspace share does not erase an independent case membership.

Workspace sharing alone does not grant signature authority, signature-request authority or onward document sharing. Those actions retain their separate case and role checks.

Signature eligibility

For criminal-justice documents, a staff signer needs current case access, an owner/editor role, the Sign documents permission and a signature slot matching their prosecution or judiciary role. Court administration does not sign prosecution or judiciary lines.

For a participant's signature, an authorized staff member sends a request for a specific line to a specific online character. The invitation only permits that signature on that document version. A normal read share grants no signing rights.

One human player cannot fill multiple lines on the same sealed version by switching characters. Required lines are intended for separate signers.

Diagnose an access failure

Check in this order: configured job, duty, mapping version, technical grade binding, action permission, tablet app restriction and case/workspace access. The Troubleshooting page maps common error codes to the relevant setting.