BULLETMETA

WARDOGS admin roles: who can kick, ban and change maps

How to give WARDOGS server admins real roles instead of the RCON password: the built-in ladder, custom roles, seats, Discord role mapping and two-factor.

Updated

What the game gives you

Nothing, as far as roles go. A WARDOGS server has one RCON password and one level of access: everything. Anyone you give the password to can kick, ban, change the map, end the match and rewrite the configuration, and the server keeps no record of who did which. Admin roles have to come from the tool in front of the server.

The built-in ladder

A community on BulletMeta starts with three roles, each a fixed set of permissions on a matrix of resources and actions — servers, configuration, sanctions, whitelist, ban lists, members, events, the audit log:

Moderators ban by default on purpose: a one-server friends box should not need a second seat to moderate itself. Admin and moderator can be edited — take the ban away from moderators, say, and keep the kick — and reset to the default later. You can also add your own roles from the same matrix: a helper who may only message and kick, an event host who may publish events and change the map but not ban.

Seats and invites

Admins join by name — a Steam name, SteamID64 or profile link — or by a one-time invite link that expires after an hour, a day or a week. Only an owner can invite an owner. Every plan comes with a number of admin seats, and the free base includes enough for a small team; seats are counted server-side, and a pending invite holds one until it is used or revoked.

Discord roles as seats

If your community lives on Discord, connect the guild and map a Discord role onto one of your BulletMeta roles. From then on the bot keeps them in step: somebody who gets the Discord role gets the seat, somebody who loses it loses the seat. Seats created this way are marked, and removing the mapping removes only those.

Two-factor and step-up

Anybody can enrol a TOTP authenticator on their account, and a community can require it for everyone who opens the console. Beyond that, the places that change who has access — linking accounts, the settings that decide roles — ask the person to prove the account again with the providers it holds, right then, in that browser. A stolen cookie does not get through that door.

Enterprise communities can put their own identity provider in front of the console (OpenID Connect — Entra, Keycloak, Okta, Authentik, Google Workspace), and map its groups onto roles in the same way.

What the audit log makes of it

Every action is recorded against the person who took it, including the ones a role refused — a moderator who tries to change the configuration leaves a “denied” row, not nothing. That is what a role is for: not to hide buttons, but to make “who did this” a question with an answer.

A sensible starting point

The whitelist can follow these roles too: a grant to a role puts every holder on the reserved-slot list of every server.

Do it on BulletMeta

One server with every admin tool is free. The tool this guide is about, in full, is on the server tools page.