Documentation
TunnelVision is a moderation tool: it shows suspicion scores, player names and coordinates. This page explains who can use it, how to grant access to your team (moderators, admins, staff) with your permissions plugin, and exactly what that access unlocks.
A single permission controls the whole /tunnelvision command: tunnelvision.admin. Operators (op) and the console have it by default. For your moderators, add this node to their group in your permissions plugin, whichever it is: TunnelVision uses Bukkit's standard permission system.
tunnelvision.admin permissionThe plugin declares a single permission, which grants access to every /tunnelvision subcommand (score, suspects, 3D reports, menu, backfill, logs). There is no finer per-subcommand permission yet.
| Who | Default access |
|---|---|
| Server console | Yes always |
Operators (/op) | Yes unless you explicitly remove it (see below) |
| Every other player | No the command doesn't even show up in their command list or tab completion |
A player without the permission who types the command gets "Unknown or incomplete command": this is intended, a moderation tool shouldn't be visible to players.
TunnelVision relies on Bukkit's standard permission system: any permissions plugin compatible with Paper or Spigot works. The only TunnelVision-specific piece is the tunnelvision.admin node; the exact commands are your plugin's (look for the one that "adds a permission to a group").
tunnelvision.admin, set to "true", to your moderators' group or rank. If your admins inherit from that group, they get it automatically; otherwise, add it to their group as well./tunnelvision in tab completion and /tunnelvision status should answer them. Most permissions plugins also have a command to test a node on a player.No need to restart the server: permissions plugins apply the change immediately. If the command doesn't show up in the player's tab completion yet, reconnecting is enough.
Only operators and the console have access. You can grant access with /op <player>, but it's not recommended for a moderator: operator status unlocks every server command (creative mode, /give, /stop…), not just TunnelVision. A permissions plugin lets you grant only what's needed.
The permission unlocks everything: keep it for the people who actually make moderation decisions. Our recommendation:
| Role | Access | Why |
|---|---|---|
| Owner, admin | Yes | Also handles maintenance operations (backfill, logs). |
| Moderator | Yes | Investigates x-ray suspicions: score, suspects, 3D report. |
| Helper, guide, trial staff | No | Reports show real player names and coordinates. Prefer temporary access if needed. |
| Builder, event team, developer | No | No moderation need. |
| Players | No | A player who could see the suspects would know who is being watched. |
TunnelVision's score is a triage aid, never proof. Whatever the role, a sanction must follow a human check: see why the score shouldn't ban.
All of these commands are covered by tunnelvision.admin. The last column flags the ones that call for care.
| Command | Purpose | Watch out |
|---|---|---|
/tunnelvision status | Plugin and sync status, recent errors. | Nothing. |
/tunnelvision score <player> [window] | A player's suspicion score over a period. | Nothing. |
/tunnelvision suspects [window] | Most suspicious sessions, sorted. | Reveals who is suspected. |
/tunnelvision render <start> <end> | 3D HTML report for the period. | Real names and coordinates by default (report.identify-by-default); --anonymize for an anonymized version. |
/tunnelvision render … --host | Publishes the report on a shareable link. | Anyone with the link can open it until it expires or is revoked. |
/tunnelvision menu | In-game graphical interface. | Same reports as render. |
/tunnelvision backfill [--restart] | Sends missing history to the service. | Long-running; --restart starts over from the beginning. |
/tunnelvision verbose <channel> on|off | Turns on console logs for a subsystem. | Edits config.yml. |
Every setting mentioned here is detailed on the configuration page.
Remove the tunnelvision.admin node from the group or player you added it to.
Operators are a special case: removing the node isn't enough, an op falls back to the default access. To take it away, you have to explicitly deny the permission: "false" value, or the node prefixed with a dash (-tunnelvision.admin), depending on your plugin.
| Symptom | Likely cause and fix |
|---|---|
| "Unknown or incomplete command" | The player lacks the permission. Check their group and that group's permissions in your permissions plugin. |
| "Permission manquante : tunnelvision.admin" | Same cause. On a network, also check that the permission applies to this server. |
| Permission granted but still denied | A denial ("false" value or -tunnelvision.admin) inherited from another group wins. Look for it in the player's parent groups. |
| The command doesn't show up in tab completion | The player needs to reconnect after the permission is added. |
No. Any permissions plugin compatible with Paper or Spigot works: TunnelVision uses Bukkit's standard permission system. Without a permissions plugin, only operators and the console have access.
No. Permissions plugins apply the change immediately; at worst, the player reconnects to see the command in tab completion.
score without giving access to render?Not yet: a single permission covers every subcommand. If you need that split, tell us on Discord.
* permission get access?Yes, with permissions plugins that support wildcards (* or tunnelvision.*): they include tunnelvision.admin.
A question about your team's access: Discord · contact@tunnelvision.fr.