CloutLabs

The Clout guide

6. Teams

A team is people on one account. There are no per-person workspaces and no way to divide an account into two fleets: everyone you add works on the same profiles you do. What you decide is who they are, what they may reach, and what they may do to it.


Adding somebody

Open Team, in the portal or in the app, and press Invite. There is no link to send on and no code to pass along. You give the identifier their sign-in provider can prove:

Whoever signs in holding that identifier is offered your team. Somebody already signed in gets a notification. Nothing is sent by us, so nobody can forward an invitation to anyone else.

Your plan carries a number of seats, and the Team screen counts them. An invite that has not been accepted holds one, so five open invitations fill a five seat plan even before anybody arrives.

When the fleet is full, the app says so before you type. The Team screen shows the numbers and the two things you can do about it on that same screen, cancel an invitation or remove somebody, with a link to the plan in the portal. Send is disabled in the invite dialog. That check is only the app declining to draw a control it has been told would fail: the real refusal is on our side, in the database, and if a send is refused for any reason you read our own words for it in the dialog rather than a guess made by the app.

Where to do it. Both surfaces work and both ask the same three questions: a rank, which products, and (for Clout Browser) which profiles and what they may do to them. Invite from whichever one you have open.


Ranks

Four ranks, and the one thing to understand is that only the last one changes what a person can see.

RankSeesMay
OwnerThe whole fleetEverything, including the plan, the billing arrangement and handing the account over. Exactly one per account
AdminThe whole fleetEverything except those three. Manages people, deletes profiles, reveals stored passwords, reads the audit log
ManagerThe whole fleetWorks the fleet: create, edit, launch, use saved logins, manage groups and tags. Cannot delete profiles, reveal passwords, or manage people
EmployeeOnly the profiles assigned to themOpen what they were given and use its saved logins. No creating, no editing, no deleting

Two spellings you may see and should not worry about. Member is the retired name for Manager and carries the identical permissions; both read as Manager. Launcher is the stored name for Employee, kept because renaming a database column is not worth a migration; it reads as Employee everywhere a person looks.

An Admin can promote somebody to Admin and demote another Admin. That is deliberate rather than an oversight: the invariant worth protecting is the Owner's, and it is protected in two places.


Giving an Employee particular profiles

An Employee sees nothing until you give them something. Access is granted by folder: pick the folders their work lives in, and they get the profiles filed in them.

Three consequences worth knowing before you build a structure around it, and the first is the one that surprises people:

A profile can be in more than one folder, so one profile can be reachable by two people without either of them seeing the other's work.


Permissions, and which ones are real

The Permissions tab lists every permission the product has a word for. Read it before you build a policy on it, because the screen is honest about something most permission screens hide: not every row is a control.

Each row is one of three things, and the screen says which:

A switchThe server can take this away from one person. These are the only rows you can actually change
StateReal, checked on every request that needs it, but it comes with the rank and cannot be removed one at a time. Change the rank instead
Greyed and markedNothing on the server checks it today. It is shown so you can see the shape of what is coming, not so you can rely on it

That classification comes from the server on every load, not from a list inside the app, so a permission that becomes real starts drawing as a switch on its own.

The eleven you can take away from one person

PermissionWhat it lets them do
Open profilesStart a browser and use the account inside it
Create profilesAdd new profiles to the fleet
Edit profilesChange a profile's name, proxy, notes and fingerprint
Delete profilesPermanently remove a profile and its session
Use saved loginsLet a profile sign in with its stored credentials
Reveal passwordsRead a stored password in the clear
Reveal 2FA keysRead a stored two factor seed in the clear
Upload profile dataReplace a profile's cookies, storage and history for everybody on the fleet
Edit proxiesChange the gateways every profile behind them runs through
Manage extensionsAdd, update or attach an extension. An extension runs code inside every profile it is attached to
Empty the trashDestroy a binned profile and its data for good

Taking one away only ever narrows: nothing here can give somebody more than their rank already allows.

Four things are deliberately not on that list. Managing people, billing, entitlements and account settings are what the rank is for; a tick box that removed them from an Admin would be a second control answering one question. Device access is not narrowable either, because somebody who runs profiles has to see the machine they run on, and revoking their own lost laptop should never need anybody's permission. And seeing profiles at all is not narrowable, because a teammate who can see nothing is a seat you are paying for: that is what Remove is for, and folders are what "only these profiles" is for.

Three that nothing enforces yet

These are named in the product and are not checked by any request today. The screen greys them out and says so:

Manage billing · Manage entitlements · Open profiles

None is an oversight. Billing waits on a payment provider, which does not exist yet: a plan is granted by hand. Entitlements are changed only by us, never by a customer, so there is nothing for a rank to gate. Opening a browser happens on your own computer, inside the app, where the account server is not present, and a check there would have to keep working offline. Do not build a policy on any of the three.

Use saved logins is enforced, and it is worth knowing where: at the moment a launched profile asks the account for its password. A person narrowed away from it on the Team screen is refused there, the refusal is written to the audit trail like every other request for a secret, and the profile opens without the login. Transfer ownership is enforced on the route that hands a workspace over.


Groups

Groups are the rail down the left of the Team screen. A group is a preset: a rank plus the permissions it keeps, saved under a name and a one-line description so you can put several people on the same footing at once.

New group opens a dialog: the name, the description, the rank, and a permission tree with the sections down the left and each section's rows on the right. Everything the rank allows starts ticked; untick what this group does not need. A row the rank does not hold is drawn greyed with the reason, so you can see what a higher rank would add rather than wondering where it went. A row the server does not enforce yet says so too, rather than offering a switch that would do nothing.

Two things about membership, and both are on the account rather than in your window:

Choosing a group in the rail narrows the table to the people on it. The menu on a group edits it or deletes it; deleting one leaves its people with the rank and permissions they hold today, on no group.


Taking somebody off

Remove on a row takes the person off the account. They lose access to the fleet immediately, on every computer they were signed in on, and the seat comes back. Nothing of theirs is deleted, because nothing on a shared account is theirs: the profiles belong to the account.

A member who wants to leave can do it themselves, from their own row.


What everybody on the account can see

Read this once and decide whether you are comfortable with it, because no permission changes it: everyone on your team can open the profiles they can reach, and a profile that opens is a profile that is signed in. Sharing an account means sharing the accounts inside it. The permissions above decide who may see a password in plain text, not who may use it.

For what we can technically see, and who else can, read How your data is held.