Documentation

Permissions: giving your moderators access to TunnelVision

TunnelVision is a moderation tool: it shows suspicion scores, player names and coordinates. This page explains who can use it, how to grant access to your team (moderators, admins, staff) with your permissions plugin, and exactly what that access unlocks.

In short

A single permission controls the whole /tunnelvision command: tunnelvision.admin. Operators (op) and the console have it by default. For your moderators, add this node to their group in your permissions plugin, whichever it is: TunnelVision uses Bukkit's standard permission system.

1The tunnelvision.admin permission

The plugin declares a single permission, which grants access to every /tunnelvision subcommand (score, suspects, 3D reports, menu, backfill, logs). There is no finer per-subcommand permission yet.

WhoDefault access
Server consoleYes always
Operators (/op)Yes unless you explicitly remove it (see below)
Every other playerNo the command doesn't even show up in their command list or tab completion

A player without the permission who types the command gets "Unknown or incomplete command": this is intended, a moderation tool shouldn't be visible to players.

2Granting access

TunnelVision relies on Bukkit's standard permission system: any permissions plugin compatible with Paper or Spigot works. The only TunnelVision-specific piece is the tunnelvision.admin node; the exact commands are your plugin's (look for the one that "adds a permission to a group").

  1. To your moderators' group (recommended). Add tunnelvision.admin, set to "true", to your moderators' group or rank. If your admins inherit from that group, they get it automatically; otherwise, add it to their group as well.
  2. To a single player, if you don't want to grant it to a whole group: same node, added directly to the player.
  3. For a limited time (trial moderator, temporary help): if your plugin supports temporary permissions, it's the safest way to help someone out without forgetting to remove access afterwards.
  4. On a network (BungeeCord, Velocity) whose servers share the same permissions database: if your plugin allows it, restrict the permission to the server running TunnelVision.
  5. Check: the player should see /tunnelvision in tab completion and /tunnelvision status should answer them. Most permissions plugins also have a command to test a node on a player.
i

No need to restart the server: permissions plugins apply the change immediately. If the command doesn't show up in the player's tab completion yet, reconnecting is enough.

Without a permissions plugin

Only operators and the console have access. You can grant access with /op <player>, but it's not recommended for a moderator: operator status unlocks every server command (creative mode, /give, /stop…), not just TunnelVision. A permissions plugin lets you grant only what's needed.

3Who should have access?

The permission unlocks everything: keep it for the people who actually make moderation decisions. Our recommendation:

RoleAccessWhy
Owner, adminYesAlso handles maintenance operations (backfill, logs).
ModeratorYesInvestigates x-ray suspicions: score, suspects, 3D report.
Helper, guide, trial staffNoReports show real player names and coordinates. Prefer temporary access if needed.
Builder, event team, developerNoNo moderation need.
PlayersNoA player who could see the suspects would know who is being watched.
!

TunnelVision's score is a triage aid, never proof. Whatever the role, a sanction must follow a human check: see why the score shouldn't ban.

4What the permission unlocks

All of these commands are covered by tunnelvision.admin. The last column flags the ones that call for care.

CommandPurposeWatch out
/tunnelvision statusPlugin and sync status, recent errors.Nothing.
/tunnelvision score <player> [window]A player's suspicion score over a period.Nothing.
/tunnelvision suspects [window]Most suspicious sessions, sorted.Reveals who is suspected.
/tunnelvision render <start> <end>3D HTML report for the period.Real names and coordinates by default (report.identify-by-default); --anonymize for an anonymized version.
/tunnelvision render … --hostPublishes the report on a shareable link.Anyone with the link can open it until it expires or is revoked.
/tunnelvision menuIn-game graphical interface.Same reports as render.
/tunnelvision backfill [--restart]Sends missing history to the service.Long-running; --restart starts over from the beginning.
/tunnelvision verbose <channel> on|offTurns on console logs for a subsystem.Edits config.yml.

Every setting mentioned here is detailed on the configuration page.

5Revoking access

Remove the tunnelvision.admin node from the group or player you added it to.

Operators are a special case: removing the node isn't enough, an op falls back to the default access. To take it away, you have to explicitly deny the permission: "false" value, or the node prefixed with a dash (-tunnelvision.admin), depending on your plugin.

6Troubleshooting

SymptomLikely cause and fix
"Unknown or incomplete command"The player lacks the permission. Check their group and that group's permissions in your permissions plugin.
"Permission manquante : tunnelvision.admin"Same cause. On a network, also check that the permission applies to this server.
Permission granted but still deniedA denial ("false" value or -tunnelvision.admin) inherited from another group wins. Look for it in the player's parent groups.
The command doesn't show up in tab completionThe player needs to reconnect after the permission is added.

7FAQ

Do I need a specific permissions plugin?

No. Any permissions plugin compatible with Paper or Spigot works: TunnelVision uses Bukkit's standard permission system. Without a permissions plugin, only operators and the console have access.

Do I need to restart the server after granting the permission?

No. Permissions plugins apply the change immediately; at worst, the player reconnects to see the command in tab completion.

Can I give access to score without giving access to render?

Not yet: a single permission covers every subcommand. If you need that split, tell us on Discord.

Does a player with the * permission get access?

Yes, with permissions plugins that support wildcards (* or tunnelvision.*): they include tunnelvision.admin.

Need help

A question about your team's access: Discord · contact@tunnelvision.fr.