6. Teams
A team is people on one account. There are no per-person workspaces and no way to divide an account into two fleets: everyone you add works on the same profiles you do. What you decide is who they are, what they may reach, and what they may do to it.
Adding somebody
Open Team, in the portal or in the app, and press Invite. There is no link to send on and no code to pass along. You give the identifier their sign-in provider can prove:
- a Google email address, or
- a Telegram username.
Whoever signs in holding that identifier is offered your team. Somebody already signed in gets a notification. Nothing is sent by us, so nobody can forward an invitation to anyone else.
Your plan carries a number of seats, and the Team screen counts them. An invite that has not been accepted holds one, so five open invitations fill a five seat plan even before anybody arrives.
When the fleet is full, the app says so before you type. The Team screen shows the numbers and the two things you can do about it on that same screen, cancel an invitation or remove somebody, with a link to the plan in the portal. Send is disabled in the invite dialog. That check is only the app declining to draw a control it has been told would fail: the real refusal is on our side, in the database, and if a send is refused for any reason you read our own words for it in the dialog rather than a guess made by the app.
Where to do it. Both surfaces work and both ask the same three questions: a rank, which products, and (for Clout Browser) which profiles and what they may do to them. Invite from whichever one you have open.
Ranks
Four ranks, and the one thing to understand is that only the last one changes what a person can see.
| Rank | Sees | May |
|---|---|---|
| Owner | The whole fleet | Everything, including the plan, the billing arrangement and handing the account over. Exactly one per account |
| Admin | The whole fleet | Everything except those three. Manages people, deletes profiles, reveals stored passwords, reads the audit log |
| Manager | The whole fleet | Works the fleet: create, edit, launch, use saved logins, manage groups and tags. Cannot delete profiles, reveal passwords, or manage people |
| Employee | Only the profiles assigned to them | Open what they were given and use its saved logins. No creating, no editing, no deleting |
Two spellings you may see and should not worry about. Member is the retired name for Manager and carries the identical permissions; both read as Manager. Launcher is the stored name for Employee, kept because renaming a database column is not worth a migration; it reads as Employee everywhere a person looks.
An Admin can promote somebody to Admin and demote another Admin. That is deliberate rather than an oversight: the invariant worth protecting is the Owner's, and it is protected in two places.
Giving an Employee particular profiles
An Employee sees nothing until you give them something. Access is granted by folder: pick the folders their work lives in, and they get the profiles filed in them.
Three consequences worth knowing before you build a structure around it, and the first is the one that surprises people:
- You pick folders; the server stores profiles. Somebody given the Clients folder holds the profiles that were in Clients when you pressed Save. A profile added to that folder next week is not theirs until you set their access again. The picker says so rather than leaving you to discover it.
- A folder does not include the folders inside it. Pick each one you mean.
- Only an Owner or an Admin may edit folders. A Manager who could re-file a folder could widen somebody's access, including their own, which is why that one capability sits above their rank.
A profile can be in more than one folder, so one profile can be reachable by two people without either of them seeing the other's work.
Permissions, and which ones are real
The Permissions tab lists every permission the product has a word for. Read it before you build a policy on it, because the screen is honest about something most permission screens hide: not every row is a control.
Each row is one of three things, and the screen says which:
| A switch | The server can take this away from one person. These are the only rows you can actually change |
| State | Real, checked on every request that needs it, but it comes with the rank and cannot be removed one at a time. Change the rank instead |
| Greyed and marked | Nothing on the server checks it today. It is shown so you can see the shape of what is coming, not so you can rely on it |
That classification comes from the server on every load, not from a list inside the app, so a permission that becomes real starts drawing as a switch on its own.
The eleven you can take away from one person
| Permission | What it lets them do |
|---|---|
| Open profiles | Start a browser and use the account inside it |
| Create profiles | Add new profiles to the fleet |
| Edit profiles | Change a profile's name, proxy, notes and fingerprint |
| Delete profiles | Permanently remove a profile and its session |
| Use saved logins | Let a profile sign in with its stored credentials |
| Reveal passwords | Read a stored password in the clear |
| Reveal 2FA keys | Read a stored two factor seed in the clear |
| Upload profile data | Replace a profile's cookies, storage and history for everybody on the fleet |
| Edit proxies | Change the gateways every profile behind them runs through |
| Manage extensions | Add, update or attach an extension. An extension runs code inside every profile it is attached to |
| Empty the trash | Destroy a binned profile and its data for good |
Taking one away only ever narrows: nothing here can give somebody more than their rank already allows.
Four things are deliberately not on that list. Managing people, billing, entitlements and account settings are what the rank is for; a tick box that removed them from an Admin would be a second control answering one question. Device access is not narrowable either, because somebody who runs profiles has to see the machine they run on, and revoking their own lost laptop should never need anybody's permission. And seeing profiles at all is not narrowable, because a teammate who can see nothing is a seat you are paying for: that is what Remove is for, and folders are what "only these profiles" is for.
Three that nothing enforces yet
These are named in the product and are not checked by any request today. The screen greys them out and says so:
Manage billing · Manage entitlements · Open profiles
None is an oversight. Billing waits on a payment provider, which does not exist yet: a plan is granted by hand. Entitlements are changed only by us, never by a customer, so there is nothing for a rank to gate. Opening a browser happens on your own computer, inside the app, where the account server is not present, and a check there would have to keep working offline. Do not build a policy on any of the three.
Use saved logins is enforced, and it is worth knowing where: at the moment a launched profile asks the account for its password. A person narrowed away from it on the Team screen is refused there, the refusal is written to the audit trail like every other request for a secret, and the profile opens without the login. Transfer ownership is enforced on the route that hands a workspace over.
Groups
Groups are the rail down the left of the Team screen. A group is a preset: a rank plus the permissions it keeps, saved under a name and a one-line description so you can put several people on the same footing at once.
New group opens a dialog: the name, the description, the rank, and a permission tree with the sections down the left and each section's rows on the right. Everything the rank allows starts ticked; untick what this group does not need. A row the rank does not hold is drawn greyed with the reason, so you can see what a higher rank would add rather than wondering where it went. A row the server does not enforce yet says so too, rather than offering a switch that would do nothing.
Two things about membership, and both are on the account rather than in your window:
- Membership is stored. A person is on a group because somebody put them there, from the menu on their row. Their rank and permissions follow the group, here and on every other computer, and editing the group re-applies it to everybody on it.
- The names travel. Groups live on the account, so a teammate opening the Team screen sees the same rail you do.
Choosing a group in the rail narrows the table to the people on it. The menu on a group edits it or deletes it; deleting one leaves its people with the rank and permissions they hold today, on no group.
Taking somebody off
Remove on a row takes the person off the account. They lose access to the fleet immediately, on every computer they were signed in on, and the seat comes back. Nothing of theirs is deleted, because nothing on a shared account is theirs: the profiles belong to the account.
A member who wants to leave can do it themselves, from their own row.
What everybody on the account can see
Read this once and decide whether you are comfortable with it, because no permission changes it: everyone on your team can open the profiles they can reach, and a profile that opens is a profile that is signed in. Sharing an account means sharing the accounts inside it. The permissions above decide who may see a password in plain text, not who may use it.
For what we can technically see, and who else can, read How your data is held.