Oil painting of a player town square at dusk: lit windows, a crier calling beside a wooden notice board, a travel balloon overhead

The Living Town

A deep dive into Shroud of the Avatar's player-owned towns, what Star Wars Galaxies and twenty-five years of player settlements since can teach them, and twenty-four concrete proposals.

Shroud of the Avatar sold town ownership as a product, around 440 times over, and it delivered the deed: a governor really does own a town, place its housing lots, and set its rules. What never shipped is the town game. Governance hangs off a lot sign's right-click menu and three slash commands; there is no in-game list of towns anywhere; and a town on day 1,000 plays identically to day 1. This document surveys the current machinery, walks the genre from Ultima Online's emergent villages to modern settlement systems, and proposes twenty-four improvements, most of them client-side composition over server plumbing that already exists.

0 · Executive summary 1 · The town you govern today 2 · Lessons: Ultima Online to modern 3 · The twenty-four proposals    Tier 1 · Quick wins (S1–S6)    Tier 2 · Core upgrades (S7–S16)    Tier 3 · Server-backed flagships (S17–S24)    Considered and rejected 4 · The composed surfaces 5 · Sequencing 6 · Appendix
Section 0

Executive summary

Every predecessor treats some layer beyond land as the actual town game, and each proved a different piece of it. Ultima Online shipped zero town mechanics and still grew real towns, because player vendors gave strangers a reason to walk in; its governor system, added sixteen years later, sustains per-city communities to this day on almost nothing but titles and a council seat. Star Wars Galaxies shipped the full civic apparatus, elections, specializations, citizen registries, and then watched its citizen-count rank thresholds kill cities in cascade the moment populations dipped. New World's town project board proved a passer-by will happily donate to your town if a visible bar fills. Rift proved a pure-UI directory creates tourism. And Terraria proved the civic threshold that matters can be two people, not thirty. SotA's own players predicted the ghost-town outcome on Steam in 2015 and today hand-maintain a forum directory because the game has none.

Measured against that history, SotA's gaps cluster in three places:

  1. The civic layer — a governor's powers are real (roles, spawn point, message of the day, lot policy, eviction) but scattered across a lot-sign context menu, one roles window, a separate spawn window and three chat commands. There is no console, no citizen identity, no crier, no way to give a town a voice or a face.
  2. The discovery layer — 440 towns share 23 template map plates, and the only live datum a stranger can see from outside is an overworld population sprite. Finding a live town with open lots is folklore; players literally look for chimney smoke.
  3. The progression layer — nothing in a town accumulates. No project ever completes, no contribution is recorded, no title is granted. The one progression that was sold, tier upgrades, is an out-of-game support ticket.

Twenty-four proposals follow. Fourteen are client-only or near-client-only work over ops the server already exposes. Seven need real server work, and each of those is flagged with its exact data cost. Every one of them is designed small-population-first: it must work at one governor and four residents, no citizen-count thresholds, no upkeep or decay retrofits, cosmetic and civic rewards only. Two in-flight programs are deliberately bridged to rather than duplicated: the guild and town web companion (the town's public web page, calendar, boards, web lot map) and dynamic town management (owner, size and template changes without a client build).

#ProposalTierSizeServerOne-line pitch
S1Town message window + arrival welcome1Snonean editor and an arrival panel for the message of the day; the one-day ship
S2Town census surfaces1Snoneclaimed/open lot counts where people already look
S3Lot search and wayfinding1Snonesearch the town map's lot markers by owner or house name; vendor filter
S4Foundation fixes1Schecksfour latent town defects fixed honestly
S5Lot health view1Snonegovernor list of claimed lots by tax expiry, from data clients already hold
S6District signposts1Snonenamed signposts become town-map labels; local geography for shared templates
S7The governor's console2Mnoneone tabbed window for the whole job, over ops that already exist
S8Batch lot policy tools2Mnonemulti-select restrict, reserve, and an open-town preset
S9In-game town directory2Mnonebrowse all 440 towns, sorted by who is actually home
S10The town crier2Mnonea placeable crier who speaks the town's message and points at open lots
S11Named greeters and townsfolk2Mnonename your placed NPCs, pick their greeting; delivers a 2020 promise
S12Multi-destination town teleporter2Mchecksdestination lists on the balloon, boat, wagon and hatch
S13Town identity: banner, description, tag2M3 fieldsa crest at the gate, a blurb on arrival, a tag in the directory
S14Steward work protection2Lopstewards can reclaim what they placed; transfers stop eating their work
S15The town dungeon gate2Lopa shared town dungeon under the master plot, no housing lot spent
S16Event cage spawners2Lserviceloot-free monster spawners for festivals and arena nights
S17The town ledger3Mindexthe missing per-town deed index plus a lot roster op; unlocks S18/S19
S18Cross-town vacancy board3Lfeedthe directory learns live open-lot counts and filters
S19Lot applications3Lcollectionapply at a restricted lot sign; the governor approves from the console
S20Town projects: the donation board3XLcollectionvisible donation bars that unlock cosmetic town stages; no downgrade loop
S21Citizen titles3Mfieldthe governor names a Harbormaster; the roster and nameplate agree
S22Market row: communal stalls3XLcollectionmarket lots host rentable vendor stalls instead of one claimant
S23Ship the five bespoke towns3XLmigrationfive finished, fully authored town scenes are shipping to nobody
S24The web and management bridge3Snonethe one bridge card: link out to the two in-flight epics, rebuild neither
Section 1

The town you govern today

The bones are real, and worth crediting before criticizing. A town is a scenario layered on one of 23 shared template scenes; the governor drops lot markers as placeable items, and each becomes a working claimable lot with a sign, a deed flow, taxes, and permissions. Governance is live server data: an access ladder of Owner, Steward, Resident and Banned, a selectable arrival spawn, an admin lock, per-lot claim restriction, eviction, and a message of the day. Recent work has been steady: housing lots now draw on the town map in four claimability states, terrain flattening for lots and houses shipped along with three governor levelling tools, house and lot sales with contents are built, banned players are ejected from lots, and town criers greet visitors by town name and answer questions about free lots. None of that is re-proposed here.

What follows is what running a town actually looks like. Every governor power is real; no two of them live in the same place.

A · the lot sign, right-click
Lot Sign
Claim Lot
Change Lot Reservation
Manage Town Access
Manage Town Spawn Area
Evict Resident
Unclaim Lot
Deed List
Property Manager
B · the chat box (the only message tool)
Chat
/setpotmotd Market day is Saturday at the fountain.
/getpotmotd
/unsetpotmotd
C · the town access window
Town Access
AccessBanned
NameRole
Tamsin HaleResident
Bram CotterSteward
Wren AshbyResident
Add PlayerRaiseLower
D · everything else
Out Of Game
Change town size or map: support ticket.
Find a town to join: forum threads.
Advertise your town: word of mouth.

The machinery every proposal plugs into

A town lot is not authored into the scene. It is a decoration: the governor places a lot-marker item on the town's single master plot, the server scans the master plot's contents at town setup and registers a claimable lot (plus its basement and dungeon), and the client builds the runtime lot, sign, and house from the same item. Move the marker and the lot is destroyed and recreated under a new identity. This one fact shapes nearly every proposal below: per-lot client features must track live add/remove events rather than caching lot ids, and per-town server features must ride the existing town operations rather than writing at the database directly, because a live town room owns its own state.

flowchart LR
  G["Governor places a lot marker\n(a decoration on the master plot)"] --> M["Master plot contents"]
  M --> S["Town setup scan\nregisters lot + basement + dungeon"]
  M --> C["Client builds the runtime lot\nsign, house, permissions"]
  C --> K["Claim path\nrestriction check, deed match,\nsquare footage budget"]
  K --> D[("Lot deed record")]
  G -. "move the marker" .-> N["New lot identity minted\nall trackers must follow events"]
The one hard constraint. Nearly all town data is per-scene: a client standing in a town knows a great deal about that town (every lot's claim state, holder name, tax expiry, restriction), and almost nothing about any other town. Any feature that compares or aggregates across towns needs server-side help, and exactly one piece of cross-town data is live today: the overworld population level. The proposals are honest about which side of that line they sit on.
Section 2

Lessons: Ultima Online to modern

Ultima Online shipped in 1997 with no town system whatsoever, and grew the most storied player towns in the genre. PaxLair, founded January 1998, still holds meetings. What made UO towns real was never mechanics: it was clustered housing plus vendors. A house with player vendors was a destination; a cluster of destinations was a town. When UO finally rebuilt a city for players (New Magincia, 2011: plots by lottery, a vendor bazaar), the plots filled and the community did not follow, because a housing lottery without civic mechanics produces private houses in a city skin. And when UO finally added governors (2013), the powers that sustained real per-city communities for the next decade were nearly free: an election, a citizen title, one modest city buff, a seat at the council table. SotA should read its own history in that arc: it already ran the "sell the land and community will come" experiment 440 times.

Oil painting of a governor and two residents studying a town ledger and map by lamplight
The whole argument in one image: a town is not its land, it is its ledger, the people in the room, and the reasons to walk in. SotA shipped the land.
1997
UO emergent towns
Zero mechanics. Vendors made houses into destinations; destinations clustered into towns.
2003
SWG player cities
The full civic kit: elections, specializations, registries. Killed at low pop by citizen-count rank thresholds.
2006
Wurm deeds
Upkeep framed as preservation; opt-in highways with route finding made inter-village geography real.
2011
Rift dimensions
A pure-UI public browser with instant visits created builder tourism from nothing.
2018
Eco governments
Civics as the content. Laws, budgets and town halls generate drama without combat.
2021
New World projects
The donation board everyone praised; the upkeep-and-downgrade loop everyone hated.

What each game contributes

Star Wars Galaxies is the canonical player-city system and both halves of its lesson matter. The good half: mayoral elections, a citizen registry that put the city on the planetary map, militia roles, zoning, and above all city specializations, one chosen identity (the crafting town, the entertainer town) that gave strangers a reason to travel. The fatal half: rank tiers gated on registered citizen counts, with demotion wiping the city's invested progress. On the emulator servers that carry SWG today, cities dipping under the 30-citizen shuttleport threshold trigger cascade abandonment and multi-account citizenship fraud. Identity: steal. Headcount thresholds: never.

Wurm Online is the deepest settlement sandbox: purchased deeds with mayor and citizens, a fully custom permission matrix, and a highway network where a village opts in with a waystone and every connected waystone offers route finding to every other. Upkeep is sold as preservation (a funded deed suffers no decay), which players accept where rent would enrage them. Eco gates every civic capability behind a physical building: no town hall, no laws. The full law engine is infeasible under SotA's trust model, but the shape, civic features that live in a physical place, and civic decisions as scheduled communal events, transfers cheaply. New World's town project board is the single most stealable artifact in the modern genre: any passer-by grabs "deliver 50 iron for the town", a visible bar fills, and a named station tier unlocks. Its downgrade twin (failed invasions and unpaid upkeep degrade everyone's stations) was so hated the developers spent years softening it. Ship the board; amputate the punishment.

FFXIV demonstrates why adjacency matters: its housing wards are 60 physically adjacent plots, and the entire player venue culture (nightclubs, cafes, libraries) exists because strangers walk past doors. Its Island Sanctuary is the control group, rich solo content with zero neighbors, and zero community formed. SotA towns already have adjacency; they lack the address, the placard, the reason to walk the street. Albion Online is the structural warning: instanced private islands siphoned its population out of shared space for years, and the developers' answer was a lever, not a lecture: resource returns are 0% on islands versus 10 to 25% in shared and dangerous zones, so public space is simply better. 440 quiet POTs are structurally Albion islands; the fix is pull. ArcheAge contributes the residents board (a per-region list of local property for sale) and land churn: abandoned property automatically recycles. Minecraft's Towny ecosystem is the folk baseline an entire generation grew up on: join a town, get a town spawn teleport, see your town's name and borders on the shared map, pay a tiny tax. And Rift's dimension browser remains the single most SotA-shaped precedent in the genre: purely a list window with search, instant visiting and a recommend button, and it created a builder-tourism culture overnight.

The small games matter most for a small game. Terraria's pylon network activates fast travel when just two NPCs are housed nearby: the proof that civic thresholds can fit SotA's population. Starbound spawns an NPC tenant from a room's furnishings: decoration literally becomes population. Stardew Valley's community center restores a town through donation bundles at population one. Trove's club fixtures include one that spawns quest-giving NPCs, the cleanest "town as content" loop shipped. EQ2's guild-hall amenities (hireling bankers, brokers, gathering NPCs bought a la carte) kept guilds engaged for years. BitCraft deliberately made its whole empire ladder cosmetic prestige, crowns, banners and titles, so that conflict stays low-stakes: exactly the trust-model-compatible shape SotA needs.

Capability matrix

CapabilityUOSWGWurmEcoNWFFXIVTownySotA todaySotA proposed
Town discovery / directory● S9/S18
Map presence of towns and lots◐ shipped● +S3/S6
Citizen identity (registry, titles)◐ roles● S21
Unified governance UI● S7
Announcements / town voice◐ hidden● S1/S10
Placeable town services / NPCs● +S10/S11
Town progression (no treadmill)● S20
Communal projects / donations● S20
Town identity / specialization◐ S13 cosmetic
Economy pull (vendors, markets)◐ +S22
Inter-town travel network◐ pairwise● S12
Vacancy visibility / recycling◐ in-scene● S18/S19
Visitor UX (welcome, wayfinding)● S1/S3/S6
Governor workload tools● S7/S8/S5
Events and calendar◐ web bridge
Small-population viability

● full system · ◐ partial or emergent · ○ absent. "SotA today" includes work already shipped on the migration branch, 2026-08. The pattern to notice: SotA's empty cells are UI-and-data problems, cheap under its trust model, while the genre's famous failures (SWG's citizen treadmill, New World's downgrade loop, Eco's bureaucracy load) live in rows this page deliberately keeps at ◐.

Section 3

The twenty-four proposals

Tier 1 is small client work over data and operations that already exist. Tier 2 is the substantial client work plus the first modest server touches. Tier 3 carries the flagships, and every card that changes stored data says so plainly. Throughout, "the console" refers to the governor's console proposed in S7 and drawn in full in section 4.

Tier 1 · Quick wins

S1 · Town message window and arrival welcome

Tier 1Size SServer: none

The message of the day is the town's only voice, and it is trapped behind a slash command. Give governors a small window showing the current message with a character counter and Set and Clear buttons. Then give the message an audience: every arriving player sees a dismissible welcome panel naming the town, the governor, and the message. The op, the permission gate, and the delivered data all exist today; this is a window and a panel over them. It is the one-day ship of this catalog.

Seen in: UO governor proclamations; every Towny server's town join broadcast.

Governor side
Town Message
Welcome to Duskmoor. Market day is Saturday. Open lots by the north bridge.
76 of 200 characters
Set MessageClear
Visitor side, on arrival
Duskmoor
Governor: Elowen  ·  City
Welcome to Duskmoor. Market day is Saturday. Open lots by the north bridge.
Show Town MapClose
Implementation notes

Pure client. The window calls the existing set-message town op and gates its buttons on the same capability check the chat command uses (PlotManager.CanSetTownMessageOfTheDay). The arrival panel reads the message and governor name from the town room properties the client already parses on scene entry (PlotManager.OnReceiveSceneProperties), triggered off the existing TownPropertiesChanged event. Respect the 200-character cap and the server's rate limit, and surface both kindly ("You can change the message again in a few minutes"). One per-town "do not show again" preference.

client Sserver noneperf neutraltests new TownMessageModelTests

S2 · Town census surfaces

Tier 1Size SServer: none

Make a town's liveliness legible in five seconds. Show claimed and open lot counts where people already look: the town map header ("Duskmoor. 34 of 61 lots claimed."), the entrance sign hover, and the governor's own view. Everything needed is already in the scene: every lot's claim state and holder name arrive as room properties on the lot itself.

Seen in: SWG's citizen registry legibility; Towny's town list stats.

Implementation notes

A client-side aggregate over the live lot registry, recomputed on the lot add/remove and init-complete events rather than per frame. Two correctness traps the implementation must honor: the registry yields the same lot under multiple ids (a lot with a basement and dungeon registers three times), so counting de-duplicates by object; and the whole-town master plot is itself a lot-shaped object that must be excluded, as the existing lots list already does. Distant lots initialize late, so the count displays "counting" until the scan settles rather than a silently low number. Resident count is governor-only in v1, from the paged roles op fetched once per visit.

client Sserver noneperf event-driven, O(lots)tests new TownCensusModelTests

S3 · Lot search and wayfinding on the town map

Tier 1Size SServer: none

The town map just learned to draw every lot in four claimability states. Add a search box that filters those markers by holder or house name, and a vendors filter that highlights lots hosting player vendors. That answers the two questions every visitor has: where is my friend, and where do I shop.

Seen in: Towny's shared-map search; UO solved it socially with rune libraries for twenty years.

Implementation notes

Extends the just-shipped lot map marker model rather than rebuilding it. Holder name and house name per lot are already client-side for every claimed lot. Vendor presence comes from a one-shot cached scan of loaded scene decorations for vendor interactives, refreshed on deco events; lots outside decoration range degrade to "no vendor data" rather than lying. No per-frame work.

client Sserver noneperf cached scan, event refreshtests extends LotMapMarkerModelTests

S4 · Foundation fixes

Tier 1Size Sserver: checks

Four latent defects in the town machinery, fixed honestly: a deed-placement rule that today is checked only by the client becomes a server check as well; the dungeon decoration limit stops borrowing the wrong tuning value through an old copy-paste; a permissions guard that compares a whole flags value where it means to test one bit gets the one-line correction; and the town teleporter's destination validation gains its missing server-side twin. None of these is glamorous. All of them make the next sixteen proposals stand on firm ground.

Seen in: no precedent needed; this is housekeeping.

Implementation notes

The deed-rule server check ships with a report-only grandfather sweep first, so any long-standing placements surface before enforcement flips on. The teleporter validation folds into S12 if both land together. Each fix is a few lines with a test; the value is integrity, not features.

client Sserver Sperf neutraltests one per fix

S5 · Lot health view for governors

Tier 1Size SServer: none

A governor tab listing every claimed lot with holder, tax state, and time to expiry, sorted soonest first, plus the unclaimed lots below. No new policy anywhere: taxes, expiry and reclamation already work exactly as they work. The change is that a governor sees decay coming instead of discovering a ghost row of expired houses a month later.

Seen in: ArcheAge's residents board; FFXIV's demolition-timer transparency, minus the anxiety: this view is read-only and governor-only.

Town Console · Lots
LotHolderTaxExpires
Row, north gateTamsin HaleDue2 days
Village, fountainBram CotterPaid19 days
Town, hillsideWren AshbyPaid26 days
City, harborTax free deedNoneNo expiry
27 claimed · 14 openShow On Map
Implementation notes

Client-only: per-lot expiry is already computed server-side and delivered to every client as a lot room property, alongside holder name and taxable state. Same de-duplication and master-plot exclusion rules as S2. Tax-free deeds have no expiry value and render "No expiry" plainly. Lives as a tab of the S7 console.

client Sserver noneperf event-driventests new LotHealthModelTests

S6 · District signposts

Tier 1Size SServer: none

A placeable signpost whose governor-set name ("Craft Quarter", "Harborside") appears as a label on the town map. All 440 towns share 23 template map plates; named districts give each town its own geography without touching a single scene file, and directions become possible: the vendor row is in Harborside.

Seen in: FFXIV's ward addresses; Towny's named plot types.

Implementation notes

A new decoration archetype in the existing signpost family; the custom name rides the item's own stored properties exactly as house name overrides do, so no database shape changes. The map label renders through the location layer that already reacts to decoration add and remove. Cap labeled signposts per town with a tuning value and cull labels by zoom to prevent clutter.

client Sserver noneperf capped label counttests extends map marker tests

Tier 2 · Core upgrades

S7 · The governor's console

Tier 2Size MServer: none

One window for the whole job. Roles, spawn point, message of the day, the census, lot health, per-lot claim policy, the town's tier and square-footage budget: today these hang off a lot sign menu, two orphan windows and three chat commands. The console absorbs all of it behind tabs, opens from the lot sign, the escape menu, and the town board, and adds not one new server operation, because the complete write surface already exists. Section 4 draws it in full.

Seen in: SWG's city hall terminal; Wurm's settlement token; Eco's town hall as the place civic UI lives.

Implementation notes

A client-only composition over the existing town request family (set permissions for plot, evict, set role, retrieve roles paged, set spawn, set message). Capability gates already exist client-side and steward rules are already modeled (ban cap, steward minting is owner-only). The square-footage readout sums claimed lots client-side under the S2 counting rules. Ship tabs incrementally, roles and message first; keep the old entry points as openers to the matching tab. The one honest gap: "lot space used" as the server sees it is not delivered today, so v1 computes it client-side and labels it as an estimate, or a later revision adds it to the town properties.

client Mserver noneperf UI onlytests new TownConsoleModelTests

S8 · Batch lot policy tools

Tier 2Size MServer: none

Town lots default to restricted claiming, and the only control is one lot at a time at its sign. The console's lots tab gains multi-select: restrict or unrestrict a set of lots, reserve a lot for a named player, and an "open town" preset that unrestricts everything unclaimed. A new governor opening a 60-lot town today performs 60 sign interactions; this makes it one.

Seen in: SWG zoning; Towny's bulk plot commands.

Implementation notes

A client loop over the existing per-lot permission op, throttled politely with a progress bar and resume-on-fail. The critical trap: never persist a selection by lot id across sessions, because moving a lot mints a new identity; selections operate only on the live lot set tracked through add/remove events. A restriction row keyed to a moved lot simply orphans server-side and the recreated lot falls back to restricted, which the UI explains rather than hides.

client Mserver noneperf throttled op looptests new BatchLotPolicyTests

S9 · In-game town directory, v1

Tier 2Size MServer: none

A browsable list of every player-owned town: name, biome, size tier, overworld location, and the one live datum the client already receives for every town, its current population level. Filter, sort, and a Show On World Map jump. Default sort is who is actually home, so the list leads with life. This is the feature the community has been hand-maintaining as a forum thread for years, and v1 needs no server work at all, because the town registry ships inside the client.

Seen in: Rift's public dimension browser, which built a tourism culture out of a list window; the community's own forum town directory as the demand proof.

Implementation notes

Static rows come from the baked scene registry (a town is a registry scenario whose town type is set); live population piggybacks the overworld population data the client already receives per scene. Visiting shows the overworld route; it deliberately does not teleport (see rejected). Open-lot counts are explicitly out of v1: that is cross-town data no client holds, and it arrives honestly in S18. The 440-row list would be mostly quiet towns, which is exactly why population sorts first and why S13's tags give the list texture.

client Mserver noneperf static list + one live feedtests new TownDirectoryModelTests

S10 · The town crier

Tier 2Size MServer: none

A governor-placeable crier for the town grounds: an NPC building that speaks the town's message aloud to passers-by, lists open lots, and points the way to the market. The conversation seams shipped this month: criers already greet players by town name and already answer questions about free lots. What no town can do is place one, or make it speak the town's own words. The message of the day becomes a voice standing in the square.

Seen in: UO's town criers; the oldest open request in SotA's own crier lineage is a crier that lists town lots correctly.

Town Crier
Crier:Hear ye! Welcome to Duskmoor. Market day is Saturday at the fountain.
Crier:Three lots stand open by the north bridge. Ask me the way.
Where are the free lots?Goodbye
Implementation notes

A new NPC building prefab in the existing placeable-NPC family, counted against the tier's NPC building cap. The conversation reuses the shipped town-name and free-lots seams and adds one more that reads the town message the client already holds. No new server op and no schema: the announcement text is the message of the day, which S1 makes easy to set. Bridges forward to the generative NPC program for voiced or dynamic lines later; this card stays pre-scripted.

client Mserver noneperf one NPC per placementtests conversation seam tests

S11 · Named greeters and pre-scripted townsfolk

Tier 2Size MServer: none

Let governors name their placed NPCs and pick each one's greeting from a curated set, and add a handful of new pre-scripted townsfolk (a child, a dockworker, a gardener) to the placeable roster. The team said publicly in 2020 that it hoped to expand placed guards and shopkeepers with custom naming and conversations. Naming and greetings are the affordable half of that promise, and they turn a decorated town into an inhabited one.

Seen in: Starbound's colony tenants, where decoration becomes population; EQ2's hireling amenities.

Implementation notes

Name and greeting choice store on the placed item's own properties, the same mechanism house name overrides use, so nothing changes shape in the database. New townsfolk are additions to the existing placeable NPC family, counted against the same caps. Names pass the same player-text validation as house names. Patrol routes are deliberately absent here: the decorating program already owns them.

client Mserver noneperf within NPC capstests name validation reuse

S12 · Multi-destination town teleporter

Tier 2Size Mserver: checks

The town interconnection family (balloon, boat, wagon, hatch) currently points each placed teleporter at one destination. Upgrade it to hold a governor-curated destination list with named entries, shown as a small choice dialog, and give destination validation its missing server-side check. Five allied towns stop being teleporter spaghetti and become a legible travel network.

Seen in: Wurm's waystone highways with route finding; Terraria's pylons as fast-travel-as-civic-glue. Requested by players this month.

Implementation notes

The destination list rides the teleporter item's stored properties; the choice UI is a small list dialog on the existing interaction. Reachability does not widen: destinations remain towns the governor's placed teleporters already reach, with both endpoints governor-placed, so consent stays on both sides. List length is capped by a tuning value. The server-side destination check is S4's fourth fix if it has not landed already.

client Mserver Sperf neutraltests destination list model tests

S13 · Town identity: banner, description, tag

Tier 2Size Mserver: 3 fields

Three governor-set identity fields. A banner chosen from a preset heraldry set, rendered at the town entrance and on the town map header. A short town description shown in the arrival welcome and the directory. And one identity tag (Market, Roleplay, Crafting, PVP, Quiet) as directory metadata. This is the SWG specialization payoff, identity and a reason to travel, with zero balance surface: no buffs, no thresholds, nothing to lose.

Seen in: SWG city specializations (the identity half only); BitCraft's deliberately cosmetic prestige; UO's citizen flavor.

Duskmoor · Town Gate
Banner of the Gold Wheel
Governor: Elowen · City · Market town
A trade town on the river road. Traders and visitors are welcome.
Implementation notes

The first card that changes stored town data: three new fields on the town record, written through one new operation in the existing town request family, gated on the same permission the message of the day uses, with the same rate limit and text validation. The fields ride the town room properties to every client in the scene, so the entrance banner render is one quad per town. Where a guild owns the town, the banner may display the guild's crest, sharing the renderer the guilds proposal introduces. Database change lands with its migrations ledger entry in the same commit.

client Mserver M · 3 fields + ledgerperf one quad per towntests identity model + validation tests

S14 · Steward work protection

Tier 2Size Lserver: op

Stewards decorate town grounds, and when a steward is demoted, banned, or the town changes hands, the items they placed sit in limbo. Attribution shipped this summer: the game knows who placed what. Add the reclaim path: a steward can retrieve their own placed items, and eviction and transfer flows offer "return steward items to their banks" as an option. This closes a real loss case players have documented at length.

Seen in: Wurm's mutual checks between mayor and citizens; ordinary escrow hygiene.

Implementation notes

Server work, but along a paved road: the eviction machinery that ships a lot's contents to its owner's bank generalizes to a filtered subset of the town grounds' contents, matched by placer. One new operation in the town request family, callable by the placer for their own items and by the governor for anyone's. The risk is inventory edge cases (stacks, nested containers); the mitigation is mirroring the eviction code paths exactly rather than inventing parallel ones. No stored data changes shape.

client Mserver Lperf neutraltests reclaim path + permission tests

S15 · The town dungeon gate

Tier 2Size Lserver: op

A governor-placeable dungeon entrance for the town grounds, opening a shared dungeon that belongs to the town itself rather than to any resident's lot. Housing lots already have basements and dungeons; the machinery mostly exists. What this buys a town is a communal underworld, an arena, a crypt, a haunted cellar for the fall festival, without spending a housing lot to host it.

Seen in: Trove's club worlds as shared build space; a long-standing player request for lot-free dungeon entrances.

Implementation notes

Lots already carry dungeon storage and dungeon identities are registered per lot at town setup; the work is enabling the same for the town's master plot and adding the entrance archetype. The known minefield is that the master plot is special-cased in many places (its bounds are the whole town, it is excluded from lot lists); every consumer of "is this a normal lot" must be audited for the dungeon path, so this card starts with a spike. Dungeon decoration caps apply as on lots, inheriting S4's cap fix.

client Mserver Lperf capped like lot dungeonstests master plot dungeon audit tests

S16 · Event cage: loot-free monster spawners

Tier 2Size Lserver: service

A governor-placeable spawner that emits chosen monsters in a bounded radius on the town grounds, for festivals, arena nights, and invasion theater. No loot tables, no experience, so it cannot become a private farm; off by default, on only by governor action, auto-despawning on a timer. The town square fills with skeletons on the governor's schedule and no one's economy notices.

Seen in: Trove's club content spawners; New World's invasion theater, minus the punishment loop. A standing player request, scoped here around the team's long-standing rejection of private resource farming.

Implementation notes

A new decoration archetype plus a constrained spawn service on the scene server: whitelisted creature sets, per-tier concurrency caps from tuning values, town grounds only, owner toggles. Combat is PvE against spawns only; no player flagging of any kind. Reuses existing encounter spawn plumbing rather than new AI hosting; the budget risk is concurrent spawns in dense towns, so the cap is a hard one. Spawner configuration stores on the placed item.

client Mserver Lperf hard spawn capstests spawn cap + no-loot tests

Tier 3 · Server-backed flagships

S17 · The town ledger

Tier 3Size Mserver: index + op

The honest plumbing card. The question "who holds the lots in this town" cannot be answered efficiently by the database today; the deed records are indexed for other questions. This card adds the per-town deed index and a paged town lot roster operation returning holder, lot shape and claim date. The player payoff arrives through S18 and S19 and through authoritative numbers in the governor's console; this card is the ground they stand on. The same index is a stated prerequisite of the web companion's town pages, so it lands exactly once, credited to whichever ships first.

Seen in: nothing to see; every owner-listing feature the genre takes for granted assumes an index like this exists.

Implementation notes

One additive index on the deed collection plus one new paged read op in the town request family, honoring per-deed privacy flags for non-governor callers. The database change lands with its migrations ledger entry in the same commit. Nothing else changes shape.

client Sserver M · index + ledgerperf indexed readstests roster op paging tests

S18 · Cross-town vacancy board

Tier 3Size Lserver: feed

The directory learns the number that matters: live claimed and open lot counts per town, with a "towns with open lots" filter by biome, tier and identity tag. Today this is the recruitment channel governors run through forum threads; it becomes a list any homeless newcomer can browse from anywhere in one evening.

Seen in: ArcheAge's residents board; Towny's town list with open plot counts.

Implementation notes

Cross-town data no client holds, served the way the one existing cross-town datum already travels: a periodic server-side aggregation delivered as a compact broadcast blob, refreshed on a minutes-scale timer. Claimed counts come off the S17 index; open counts are template lot geometry minus claimed plus the town's dynamic placements, and v1 may honestly ship claimed counts only with open counts labeled approximate. Read-only: no live-room writes are involved anywhere.

client Mserver L · read aggregationperf minutes-scale feedtests aggregation + staleness tests

S19 · Lot applications

Tier 3Size Lserver: collection

A visitor standing at a restricted lot sign can Apply, with a short note. The governor's console shows pending applications; Approve executes the existing reservation for that player and notifies them, online or off. This closes the loop that today requires finding the governor out of game, and it reuses the application pattern the guilds proposal establishes for its guild finder.

Seen in: FFXIV's Free Company applications; the guild finder pattern from this page's sibling.

Lot Sign · Village, fountain
This lot is reserved by the town.
Apply for this lot
Note to the governor:
Crafter, daily player, happy to join market days.
Send ApplicationCancel
Implementation notes

A new small collection of applications (town, applicant, note, timestamps) with a 30-day expiry, capped per player and per town against spam, landing with its migrations ledger entry. Three new ops in the town request family: apply, retrieve paged, resolve; approval internally calls the existing reservation path, and notification uses the existing offline message channel evictions already use. An application references the lot loosely by shape wanted rather than by lot id, because lot ids do not survive a governor moving the lot; it resolves to a live lot at approval time.

client Mserver L · collection + ledgerperf paged readstests application lifecycle tests

S20 · Town projects: the donation board

Tier 3Size XLserver: collection

A governor places a project board and posts a goal: restore the fountain, donate 200 stone. Any visitor donates from inventory; a visible bar fills; completion flips a paired decoration to its finished stage, dry fountain to flowing, plain banner to trimmed, and writes a contributors plaque. Bars are governor-sized, with presets tuned for one to five players. There is no downgrade, no upkeep, no decay: nothing a quiet month can take away. This is New World's most-loved civic loop with its most-hated half amputated, at Stardew Valley's proven solo scale. It is the flagship, because it is the first mechanism by which a SotA town can visibly get somewhere.

Seen in: New World's town project board; Stardew's community center proving the loop at population one; Terraria proving thresholds of two.

Town Projects · Duskmoor
Restore the fountain130 / 200 stone
Trim the market banners15 / 50 cotton
Light the harbor lanternsComplete
Contributors: Tamsin Hale, Bram Cotter, Wren Ashby, and 2 visitors
DonateShow On Map
Implementation notes

The biggest card. A new projects collection (town, goal item and count, donated count, contributors, state), landing with its migrations ledger entry; three ops in the town request family (create, donate, retrieve), with donation removing items through the existing inventory transaction paths. The board and its paired staged decorations are new archetypes; the stage swap is a prefab variant toggle, the same mechanism town scenes already use for cosmetic variations, so it costs nothing per frame. Completion writes a contributors plaque using the placeable plaque work the guilds proposal introduces. Donations destroy goods, so the eligible item list is bulk commodities chosen with the economy in mind.

client Lserver XL · collection + ledgerperf stage swap is O(1)tests donation conservation tests

S21 · Citizen titles

Tier 3Size Mserver: field

The governor grants a resident a town title: Harbormaster of Duskmoor, Keeper of the Grove. Titles show in the town roster and, optionally, under the nameplate while in town. Mechanically it costs nothing. Socially it is the single highest-retention civic feature Ultima Online ever shipped: titles and citizenship have sustained per-city communities there for thirteen years on a tiny population, which is exactly the population shape SotA towns live in.

Seen in: UO's city loyalty titles; SWG's citizen registry; BitCraft's cosmetic prestige ladder.

Implementation notes

One new dictionary on the town record beside the existing roles, written whole through a targeted store helper as roles already are, acceptable at town scale, landing with its migrations ledger entry. Grant and revoke are owner-gated ops in the town request family; titles come from a curated format plus a filtered free slot passing the same text validation as house names. Display is in-town only, delivered through the role-notification channel that already exists. Nameplate rendering is off by default with a per-player option.

client Mserver M · field + ledgerperf in-town onlytests title grant + validation tests

S22 · Market row: communal vendor stalls

Tier 3Size XLserver: collection

Market lots exist as a lot shape, and today each is a micro-lot for one claimant. Let a governor flag them communal: residents rent a stall slot hosting one commission vendor each, fee to the governor, no deed involved. Six claimed micro-lots become a bazaar. Ultima Online's entire town culture ran on exactly this engine, houses full of vendors that strangers travel to shop; this formalizes it as town infrastructure.

Seen in: UO's vendor malls, the original town traffic engine; Albion's stations-as-businesses.

Implementation notes

The heaviest design card, spiked before scheduling: vendor hosting without lot ownership is the open question. Stall state is a new small collection (town, stall, renter, vendor, term), landing with its ledger entry, anchored to a governor-placed stall decoration rather than a lot id. Because no deed exists, the tax system is untouched; rent is a flat fee, not a tax. Scope ends at in-scene stall hosting: listings and search stay with the vendor systems and the web companion. Coordinates with the built house-and-lot sales work.

client Lserver XL · collection + ledgerperf within vendor budgettests stall lifecycle tests

S23 · Ship the five bespoke towns

Tier 3Size XLserver: migration

Five fully authored, one-of-a-kind town scenes exist in the project, built for specific communities, PaxLair among them, the oldest player town in the genre, founded in Ultima Online in 1998. No town points at them; the art ships to nobody. Wire them in: registry entries, build validation, map capture, and the per-town data migration that moving a live town onto its own scene requires, one town at a time, with the governor's consent, smallest first.

Seen in: our own warehouse. This is shipping finished work.

Implementation notes

Deliberately build-time: the dynamic town management epic scopes bespoke scenes out, which leaves them proposable here. The hard part is that a town's stored data is keyed by its scene identity, so a cutover re-keys the town's records via a scripted migration run during an admin lock window, with a migrations ledger entry per town. The migration primitive is the same one that epic's template switching needs; build it once, share it. Each town's lot layout is re-placed on the new terrain, which is why consent and one-at-a-time are load-bearing.

client M per townserver XL · migration + ledgerperf content, not runtimetests migration dry-run per town

S24 · The web and management bridge

Tier 3Size SServer: none

Two programs already in planning own big pieces of the town future, and this page proposes neither. The guild and town web companion owns the town's public web presence: a page per town, calendar with sign-ups, message board, wiki, a web lot map and lot listings. Dynamic town management owns owner, size and template changes without a client build. This card is only the in-game seams: a Town Page button in the console and the directory, and later a read-only strip of upcoming events in the arrival welcome, fed by the companion's calendar once it exists. Scheduling, boards, and listings stay web-side.

Seen in: the guilds proposal's bridge card, the pattern this one copies deliberately.

Implementation notes

Link-outs first, the events strip when the companion's read phase lands. Nothing here blocks on anything else in this catalog, and nothing else in this catalog blocks on the web.

client Sserver noneperf neutraltests none needed

Considered and rejected

Section 4

The composed surfaces

Twenty-four proposals must not become twenty-four widgets. Everything client-facing above lands on exactly three surfaces: one governor console, one discovery surface, and the in-scene objects a visitor walks past. Everything else is data and server work behind them.

Surface A · The governor's console

Absorbs the Town Access window, the spawn window, the slash commands, and per-lot policy, and hosts the new tabs as their cards land: S1 message, S2 census, S5 lot health, S8 batch tools, S19 applications, S20 projects, S21 titles.

Town Console · Duskmoor
Governor: Elowen  ·  City  ·  Forest template
OverviewLotsCitizensMessageSpawnProjects
Lot space used61,250 of 91,000 sq ft
41 placed27 claimed14 openDefault for new lots: Restricted
Search holderAllOpenReserved
ShapeSq FtStatusHolderAccess
Row525ClaimedTamsin HaleRestricted
Village1,050OpenUnclaimedUnrestricted
Town2,100ReservedHeld for Bram CotterReserved
City4,200OpenUnclaimedRestricted
Show On MapReserveSet AccessEvictPage 1 of 3

Surface B · Discovery: the town directory

One list window opened from the map screen, and columns that grow with the catalog: population sorting on day one (S9), tags and blurbs when S13 lands, open lot counts and services when S17 and S18 land.

Town Directory
Search townsBiomeOpen lotsSort: Most active
TownBiomeTierActivityOpen LotsTag
DuskmoorForestCityHigh14Market
Harrow ReachIslandTownshipMedium0Roleplay
WindmereGrasslandHamletLow5Quiet
DuskspireDesertVillageLow2Crafting
Duskmoor
A trade town on the river road. Traders and visitors are welcome.
Governor: Elowen · Open Village and Row lots · Crier, bank, market row
Show On World MapTown Page

Surface C · In the scene: the town board and its crier

One placeable notice board, refreshed when town properties change, plus the crier of S10 as its spoken twin. The board's notice is the message of the day; the open lot count is computed in scene; the last line is the S24 bridge, shown only once the town's web page exists.

Duskmoor · Notice Board
Governor: Elowen · City
Market day is Saturday at the fountain. Traders and visitors are welcome.
Open lots: 14. Press M to see them on the map.
Events and the town page are on the web.
Oil painting of two hilltop towns joined by a lantern-lit road at dawn, a travel balloon moored above the nearer town
The destinations tier in one image: towns worth traveling between, and a way to travel. The directory finds the town, the teleporter network makes the neighborhood.
Section 5

Sequencing

PhaseShipsExit criterion
1 · LegibilityS1 first (the one-day ship), then S2, S3, S5, S4, S6, landing S7 as the consolidationA governor runs the town from one window; a visitor understands the town in one minute. Zero data changes.
2 · Voice and identityS8, S9, S10, S11, S13Towns are findable, named, and speaking. First stored-data change (S13) lands with its ledger entry.
3 · The ledgerS17, then S18, S19, S21The deed index exists exactly once, shared with the web companion; vacancy, applications and titles ride it.
4 · FlagshipsS20, S14, S15, S16The donation board proves towns can get somewhere; the dungeon gate passes its master-plot spike first.
5 · Big ironS22 after its vendor-hosting spike, S23 one town at a time, S24 completionMarket rows trade; the bespoke towns ship behind a shared migration primitive.
flowchart TD
  OPS["Existing town ops\nroles, spawn, message,\nreserve, evict"] --> S7["S7 console"]
  S1["S1 message + welcome"] --> S7
  S2["S2 census"] --> S7
  S5["S5 lot health"] --> S7
  S7 --> S8["S8 batch tools"] --> S19["S19 applications"]
  S9["S9 directory v1"] --> S18["S18 vacancy board"]
  S13["S13 identity fields"] --> S9
  S13 --> S18
  S17["S17 deed index + roster"] --> S18
  S17 --> S19
  S1 --> S10["S10 crier"]
  S7 --> S20["S20 donation board"]
  S7 --> S21["S21 titles"]
  WEB["Web companion epic"] -. bridge only .-> S24["S24 bridge"]
  DPM["Dynamic town mgmt epic"] -. shared migration .-> S23["S23 bespoke towns"]

The spine: S7 is the hub nearly everything docks into. S17 is the one hard data prerequisite, shared with the web companion so it lands once. S13 feeds the directory its texture. And S1 is the deliberate first move: one small window and one welcome panel, shippable in a day, that make every town in the game feel slightly more alive the moment they exist.

Section 6

Appendix

Where each proposal's data already lives

DataLives todayUsed by
Message of the day, governor name, town flagsTown room properties, delivered to every client in sceneS1, S7, S10, board
Per-lot claim state, holder name, house name, restriction, tax expiryLot room properties, delivered per lot in sceneS2, S3, S5, S7, S8
Town registry (which scenes are towns, tier, biome, overworld position)Baked scene registry inside the clientS9
Live population level per sceneOverworld population feed, already broadcastS9, S18's delivery pattern
Roles ladder, spawn, admin lockTown record + existing paged opsS7, S21
Placer attribution on decorationsShipped this summerS14
Lot dungeon storage and identitiesRegistered per lot at town setupS15
Per-town deed rosterNowhere efficient — the S17 index is the pointS17, S18, S19

Constraints honored

Test surface

Existing fixtures this work extends: the lot map marker model tests, town management conversion tests, lot sign and lot list conversions, lot sale conservation, tax payment models, ban ejection, and the terrain flattening suites. New pure-logic targets, one per model: town message, census (with the de-duplication rules pinned), lot health, console, directory, batch policy, identity validation, application lifecycle, donation conservation, title grants. The counting traps in S2 are exactly the kind of thing a small EditMode test pins forever.

Sources

Ultima Online: UOGuide on player towns, the New Magincia plot guidelines, and the City Loyalty governor system, with the standing forum complaints about absentee governors. Star Wars Galaxies: the SWG wiki's player city pages, Game Update 8's specialization list, and the emulator-community threads documenting citizen-threshold cascade failures. Wurm Online: Wurmpedia on settlements, permissions and highways. Eco: the official government wiki and election dev blogs. New World: the town projects wiki and the settlement retrospectives. FFXIV: the player housing wiki and lottery guides. Albion: the private island debates and return-rate design. ArcheAge: housing and tax guides. Towny: the plugin wiki and shared-map integrations. Rift: the dimension browser guide. Trove, EQ2, Terraria, Starbound, Stardew, Animal Crossing, BitCraft, Pax Dei: their respective wikis and design blogs. SotA: the 2015 Steam thread predicting the ghost-town outcome, the community's forum town directory, the 2020 development update promising expanded placed NPCs, and the player wishlist sweeps of 2025 and 2026.

Feedback

General comments

No account needed. Every proposal above also has its own Discussion box for talking about that one alone; this thread is for the plan as a whole. Comments are plain text, held to basic decency, and may be trimmed.