Responsible administration

Devil-Guard permissions must be used only for authorised protection, server operations, evidence review and accountable enforcement.

Role separation

Administrators

Manage platform configuration, users, protected servers, releases, evidence and system-level controls through the Admin Control Center.

Server Hosts

Operate only the protected servers and credentials assigned to them. Server Host access must not be used as general administrative authority.

Server Council

Review eligible appeals and redacted evidence through the Council portal. Council voting remains separate from Admin-only controls.

Players and Clients

Players manage their own identity, aliases, personal tokens, sessions, restrictions and appeals through the Client Portal.

Protection decisions

Verify before action

Review the linked account, game identity, server session, detection evidence and current enforcement state before applying or extending a restriction.

Record the reason

Use specific, factual reasons. Avoid vague labels, personal attacks or unsupported claims that prevent later review.

Respect appeal rules

Do not bypass the Server Council process for eligible overturns. Direct Admin or Server Host access must not be used to create an unrecorded Council decision.

Preserve audit history

Do not delete or alter records merely to hide a mistake. Correct inaccurate information through the supported workflow and retain the audit trail.

Security and privacy

Least privilege

Assign only the minimum role required. Remove access promptly when responsibilities change or an account is no longer authorised.

Secret handling

Never expose APP_KEY values, server API tokens, personal client tokens, passwords, database credentials or private evidence-storage paths.

Private data

Do not publish player IP addresses, machine identifiers, filesystem paths or unredacted evidence outside authorised review areas.

Secure changes

Back up the website and database before upgrades, use the release-specific migration order and verify the deployment before reopening access.

Operational standard

Every privileged action should withstand review

Use Devil-Guard controls consistently, document important decisions and escalate uncertainty rather than making irreversible changes without evidence or authority.