> For the complete documentation index, see [llms.txt](https://kinematicsoup.gitbook.io/reactor/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kinematicsoup.gitbook.io/reactor/architecture/ownership-and-authority.md).

# Ownership and Authority

## Summary

How Reactor grants a player limited authority over an entity through ownership, permissions, and controllers, and how the server validates what an owner sends. It is part of the [Reactor Technical Overview](/reactor/architecture.md).

## The Default: Server Authority

By default the server owns all state. A client renders entities and sends input, but it cannot move or change an entity on its own. Ownership is how you hand a specific player controlled, bounded authority over a specific entity while the server keeps the final say.

## Owner and Permissions

An entity has at most one **owner**, a player granted rights over it. What the owner may do comes from **`ksOwnerPermissions`**:

* `NONE`: owned, but the owner changes nothing.
* `TRANSFORM`: the owner moves the entity.
* `PROPERTIES`: the owner sets the entity's properties.
* `DESTROY`: the owner destroys the entity.
* `ALL`: the three above.

Set ownership with `entity.SetOwner(player, permissions)`. Assigning `null` clears the owner and forces permissions back to `NONE`. You can also set an owner at spawn time through the spawn parameters. When an owner disconnects, the entity is destroyed if `DestroyOnOwnerDisconnect` is set, which it is by default.

## Controllers

A **controller** is a separate role. A `ksPlayerController` reads a player's input and drives an entity's movement, running on the client for prediction and on the server for authority. Ownership decides who *may* change an entity; a controller decides *how* the entity moves from input.

Assign both together with `entity.SetOwner(player, controller, permissions)`. An entity can have an owner without a controller (the owner changes transform or properties directly) or a controller without transform permission (the controller runs, but the server stays authoritative over the result). The common case is an owner with a controller for a player's own character. `entity.RemoveController` detaches the controller and can clear ownership with it.

> *A controller instance can belong to only one entity. To reuse a controller across entities, pass a clone, for example `entity.SetOwner(player, controller.Clone())`.*

## Validating Owner Updates

Granting `TRANSFORM` or `PROPERTIES` does not mean the server trusts the owner blindly. Each entity exposes validators that run before an owner's update applies:

* `OnValidateOwnerTransform`: inspect an incoming transform update. Accept it, change it, or reject it.
* `OnValidateOwnerProperty`: inspect an incoming property update the same way.

Each returns a result of `PASS`, `FAIL`, or `ABORT`. Use these to keep client-authoritative movement honest: clamp speed, keep a position in bounds, or reject an illegal change. This is what makes granting ownership safe rather than a hole in server authority.

## How the Server Applies an Owner's Update

1. Only the entity's owner may send transform, property, or destroy updates for it. Updates from anyone else are ignored.
2. Each frame the server checks that the sender still owns the entity and holds the matching permission.
3. The validators run. A rejected update does not apply.
4. Accepted updates apply to the entity and sync to the owner and to other observers.

> *The client raises `Entity.OnOwnershipChange` when an entity's owner or permissions change. The server has no equivalent event.*

## Where to Go Next

* [Server Object Model](/reactor/architecture/server-object-model.md): the entity, player, and room these rights attach to.
* [Automatic Client Data Syncing](/reactor/architecture/data-syncing.md): how owned changes reach other clients, and client prediction.
* [Client Authority and State Relay](/reactor/tutorials/authoritative_client.md): build a client-authoritative entity step by step.
