Skip to content

Customer permissions ​

What a customer may do is decided in three places. This page shows how they fit together, so you can answer "why can (or can't) this person do that?" in under a minute.

WhereWhat it decidesSet under
The panel switchWhich features exist at all: sign-up, creating servers, the store, billingSettings → Customers & billing
Limits and permissionsHow much, and what a customer may do: the layered numbers and the What they may do switchesLimits, Plans, Customers → Edit limits
The serverWho may touch one server: the owner, and collaborators with chosen rightsCustomers → Collaborators

Administrators are never limited by this page. Everything below is about customers.

The "What they may do" switches ​

Each switch has three states: Yes, No, or empty (use what is below). They exist on all three layers of Limits: the panel defaults, an account plan, and one customer.

SwitchLets the customer
May create serversCreate servers themselves, from the kinds you released
May delete their own serversDelete their servers (after the cooling-off period). Needs deleting to be turned on in the panel settings
May use SFTPUse an SFTP client for files
May install mods and pluginsUse the add-on browsers on a server
May schedule tasksCreate schedules (automatic backups, commands)
May share serversAdd other people to a server
May add extra portsAdd ports, within the extra-ports limit

How the layers combine:

  1. A panel default applies to everyone.
  2. An account plan a customer has (while it is trialing, active or in its payment grace period) can turn a switch on. If several plans disagree, Yes wins.
  3. A per-customer value (Customers → Edit limits) beats both, including No. Use it to give one person a right, or to take one away.

Edit limits shows what applies now and where each value comes from (default, plan or "set by you"), so nothing needs to be worked out by hand. If limits are switched off, switches that say No are ignored (see Limits).

Who may create servers ​

The panel's What customers can do setting (Settings → Customers & billing → Server access) is the master switch for creating servers. May create servers then decides who.

Panel modeEveryoneCustomers with a plan that says YesCustomers you gave YesCustomers set to No
OffNoNoNoNo
Server plans (store only)No, they buy a server planNoYes, fixed sizeNo
Account plansNoYes, fixed sizeYes, fixed sizeNo
Free choiceYes, they choose the size within limitsYesYesNo

Where creation is not allowed the New server button is hidden. A customer who has the right but no servers sees a short guide instead; customers without it are pointed to the store if you run one. The panel checks this again every time the page is shown or becomes active, so a change you make arrives without anyone signing in again.

Whatever the mode, a created server still has to pass the customer's limits, the allowed locations and templates, the hourly creation rate and the account checks (active, and a confirmed email address for people who signed up themselves).

Giving one customer the right ​

  1. Customers, open the customer, Edit limits.
  2. Under What they may do, set May create servers to Yes.
  3. Make sure you released at least one template (Customers creating servers) and that the customer has room in their limits. A customer with a servers limit of 0 sees the button and is then told which limit stops them.

To take it away again, set it to No (always wins) or clear it to return to the layers below.

Who may buy ​

Buying is separate from creating. With the store open, any signed-in customer may buy a plan, subject to the plan's own rules (stock, a per-customer maximum, terms accepted) and your sign-up settings. A purchased server is owned by the customer but belongs to the subscription: it does not count toward their server limit, cannot be deleted by them while the subscription runs (they cancel it instead), and stops if a payment fails for too long. See Billing and subscriptions.

Billing access ​

AdministratorsCustomers
Billing overview, all subscriptions, invoices, healthYesNo
Their own subscriptions, invoices, the payment portal, cancel and resumeYes (for any customer)Yes, their own only
Refunds, complimentary plans, moving a subscription by handYesNo

Customers never see another customer's data, and the payment provider's secret keys never reach a browser. Money actions by administrators are recorded in the audit log.

Per server: collaborators ​

An owner (or an administrator) can invite another customer to one server and choose the rights: view, console, files, backups, manage. A collaborator can use the owner's server within those rights but never counts toward their limits, cannot see the owner's other servers and cannot invite others unless May share servers is on for the owner.

When something seems wrong ​

SymptomLook at
No New server buttonThe panel mode (above), then Customers → Edit limits for May create servers
The button shows but creating fails with a limit messageEdit limits → "what applies now" for the named limit
"Confirm your email address"The customer signed up themselves and has not confirmed; see Sign-up
Customer cannot delete a serverA subscription server (cancel the subscription), deleting turned off, or May delete their own servers is No
A customer lost a right after a payment problemThe account plan that gave it is suspended or ended; see Billing and subscriptions

Suspended accounts ​

Account suspension overrides customer and collaborator grants. Billing, permitted account deletion, data export, security and the linked appeal remain available. Server operations, purchases and API tokens are refused. Backup download is opt-in for each suspension. See Suspension and the separate administrator catalogue.

May open support tickets and New tickets per day are available in the layered limits editor. These do not disable suspension appeals.

ActionActive customerSuspended customer
Server controls, console, files and SFTPWithin server grantsRefused
Buying and plan changesWithin store rulesRefused
Own invoices, paying, cancel and resumeYesYes
Password, authenticator, passkeys and devicesYesYes
Data exportWhen enabledAlways
Account deletionWithin account settingsPer suspension option
Backup downloadWithin server grantsPer suspension option
General tickets and articlesWhen desk enabledRefused
Linked suspension appealWhen applicableWhen appeals enabled
API tokensWithin token scopesRefused

Released under the AGPL-3.0-only license.