Your AI's permissions and history
Allow, Ask and Block for every action, the three presets, approvals, the Stop button, and the history with one-click undo.
DraftThis page is a first draft and may change.
Everything here is on each server's AI page in the panel. It assumes you have connected your AI.
Presets
Three buttons set every action on the server at once. You can change single actions after.
- Careful: your AI can look at everything. Every change waits for your approval, except taking a snapshot and starting the server.
- Balanced: everyday changes run straight away. Risky ones, like plugins, ranks, operator and rollbacks, wait for your approval. New servers start here.
- Full trust: your AI does everything without asking. A snapshot is still taken before each change, and you can undo it. You confirm a warning and sign in again to turn this on.
Presets never turn on chat reading. That is its own switch, below.
Every action
| Action | Careful | Balanced (the default) | Full trust |
|---|---|---|---|
| Looking | |||
| See my servers (for your whole account) | Allow | Allow | Allow |
| See the premade setups (for your whole account) | Allow | Allow | Allow |
| Read the host docs (for your whole account) | Allow | Allow | Allow |
| See its own approval requests (for your whole account) | Allow | Allow | Allow |
| See status and performance | Allow | Allow | Allow |
| Diagnose problems | Allow | Allow | Allow |
| Read logs and crash reports (chat lines removed) | Allow | Allow | Allow |
| Read recent chat (also needs the chat switch, off by default) | Allow | Allow | Allow |
| See players, whitelist, bans and ops | Allow | Allow | Allow |
| See and search plugins | Allow | Allow | Allow |
| Read settings and config files | Allow | Allow | Allow |
| See ranks and permissions | Allow | Allow | Allow |
| See snapshots and AI history | Allow | Allow | Allow |
| See scheduled tasks | Allow | Allow | Allow |
| See worlds and schematics | Allow | Allow | Allow |
| See Panes | Allow | Allow | Allow |
| Servers | |||
| Create a new server within my plan (for your whole account) | Ask | Ask | Allow |
| Starting and stopping | |||
| Start the server | Allow | Allow | Allow |
| Stop the server | Ask | Allow | Allow |
| Restart the server | Ask | Allow | Allow |
| Plugins | |||
| Install or update plugins | Ask | Ask | Allow |
| Remove plugins | Ask | Ask | Allow |
| Settings and commands | |||
| Change config files | Ask | Allow | Allow |
| Change server settings | Ask | Allow | Allow |
| Change gamerules | Ask | Allow | Allow |
| Run allowlisted commands | Ask | Allow | Allow |
| Switch Minecraft version or software | Ask | Ask | Allow |
| Players | |||
| Kick players | Ask | Allow | Allow |
| Change the whitelist | Ask | Allow | Allow |
| Turn the whitelist off | Ask | Ask | Allow |
| Ban and unban players | Ask | Ask | Allow |
| Op and deop players | Ask | Ask | Allow |
| Ranks and permissions | |||
| Create ranks and change their permissions | Ask | Ask | Allow |
| Delete ranks | Ask | Ask | Allow |
| Put players in ranks | Ask | Ask | Allow |
| Snapshots and undo | |||
| Take snapshots | Allow | Allow | Allow |
| Roll back and undo | Ask | Ask | Allow |
| Schedules | |||
| Create and change scheduled tasks | Ask | Allow | Allow |
| Make scheduled tasks that run commands | Ask | Ask | Allow |
| Delete scheduled tasks | Ask | Ask | Allow |
| Premade setups | |||
| Apply a premade setup | Ask | Ask | Allow |
| Tune a setup's settings | Ask | Allow | Allow |
| Worlds | |||
| Reset or regenerate a world | Ask | Ask | Allow |
| Panes (not available yet) | |||
| Edit Pane drafts | Ask | Allow | Allow |
| Publish Panes to players | Ask | Ask | Allow |
The actions marked "for your whole account" are set once in Account, AI, not per server.
Some changes need a second setting on top of their own:
- Turn the whitelist off, however your AI tries it: the whitelist setting, the server settings or a command. For the server settings, your AI can only send true or false; anything else, such as "no" or "False", is refused, so it cannot turn the whitelist off by a side door.
- Make scheduled tasks that run commands, also when your AI turns an old command task back on.
- Op and deop players, when your AI turns command blocks on in the server settings, since command blocks run commands with operator power.
These stay on Ask in Careful and Balanced, so pressing a preset never lets them through on its own. They run straight away only in Full trust, or when you set that action to Allow yourself. If either of the two settings involved is on Block, the change is blocked.
The looking actions can be Allow or Block, not Ask: your AI cannot wait for an answer while it reads.
Panes are not available on this host yet. Your AI can see the Pane settings, but any Pane action it tries is refused with a plain reason, and nothing changes.
Setting an action that starts on Ask to Allow shows a warning that says what your AI will now do without asking. Text hidden in a sign, a book, a plugin or chat can try to trick an AI, so keep the risky actions on Ask unless you are comfortable.
Approvals
When your AI does something set to Ask, it waits in AI, Approvals (and on your home page). Each request shows:
- what it will do, in plain words, and on which server,
- the exact details it will run with,
- warnings, for example a plugin from a source we do not review, a wildcard permission, operator, or a name that also appeared in text players wrote and your AI read in the last hour.
Press Approve to run it exactly as shown, or Deny. For risky ones (operator, ranks, rollbacks, world resets, setups, version switches and plugins from unreviewed sources) you sign in again first. Only you, co-owners and admins can decide approvals, and only in the panel.
A request waits 24 hours. Then it expires, and your AI is told the next time it does anything. Your AI is also told when a request it made has finished, or failed. If many requests changed at once, it is told about the newest 20 and asked to check the rest. It can check its own requests at any time, but it can never approve one.
The details of a request are shown with passwords, keys and tokens hidden, the same way as in the history.
If you disconnect an AI app, or we cut its connection because its sign-in was copied, its waiting requests are cancelled. They can no longer be approved, so nothing it asked for runs after the cut.
AI is working, and Stop
While your AI works on a server, the AI page shows each step as it happens: "Read the recent logs", "Install essentialsx from Modrinth", and whether it worked.
Press Stop to pause that AI on this server. Everything it tries on this server is refused with a plain reason until you press Resume. A step that was already running finishes. Requests waiting for approval stay. You and co-owners can still approve them, and anyone who decides approvals can deny them; an admin cannot approve requests from an AI that is stopped. Stop does not affect your other servers.
Admins on your team can press Stop too, and resume an AI they stopped themselves. Only you and co-owners can resume an AI that someone else stopped.
History and undo
AI, History lists every change your AI made or tried, newest first, in plain words: "Installed essentialsx from Modrinth", "Set difficulty to hard". Each line shows when, which AI app, and whether it ran straight away, waited for your approval, or was refused.
A snapshot is taken before every change, so most lines have Undo. Undo puts the server back as it was just before that change. Before you confirm, the panel shows what will come back, and lists any later changes that the same undo also removes, because they happened after that snapshot. A snapshot of the server as it is now is taken first, so an undo can itself be undone.
Undo shows only while the snapshot from just before that change is still kept. Snapshots taken before changes are kept by your plan's backup rules (on the free plan, the last 3), so an older change has no Undo; you can still roll the server back from Backups.
Your AI can undo its own changes too, under the "Roll back and undo" setting (Ask by default).
Chat reading
By default your AI cannot see chat, not even in logs. You can turn on Let my AI read recent chat for one server, behind a warning: players can write anything in chat, including text meant to trick your AI. Chat shown to your AI is marked as untrusted, cleaned and cut short. Only owners and co-owners can change this switch, and never your AI.
Limits
There are no limits on how much you use your AI. A safety brake far above normal use stops a runaway loop, for example the same restart hundreds of times, and tells your AI to wait a moment. You will not meet it in normal use.