What members can see and do
Can run, Can edit and Full access explained, how folder scoping works, and the things every member can see whatever folders you give them.
On this page
Every member gets a level and a scope. The level is how much they can do; the scope is which profiles it applies to.
ποΈ The three levels#
| Level | What it allows |
|---|---|
| Can run | Open the profile and use it. Read-only otherwise β no renaming, no changing the proxy, no deleting. |
| Can edit | Everything Can run allows, plus changing the profile: rename it, repoint its proxy, save it. |
| Full access | Everything Can edit allows, plus deleting it and moving it out of its folder. |
The invite form puts it in one line: "Can run opens profiles. Can edit also changes them. Full access also deletes them."
"Can run" is not enforced in their app
A Can run member can open the profile editor on their own computer, change something and press save. It looks like it worked. The server then refuses the change, and it stays on their computer only β nothing reaches your workspace, and nothing tells them so. Their copy has silently drifted from yours.
If someone needs to make changes, give them Can edit. If they must not, tell them so β the app won't.
ποΈ The two scopes#
Selected folders#
One level per folder. Tick Can run, Can edit or Full access on each folder you want them in, and leave the rest blank. There's a No folder row for profiles you haven't filed, so "everything in Pending" can't quietly mean "and the 400 unfiled ones too".
You can mix levels: Full access on Warming, Can run on Live, nothing anywhere else.
Whole workspace#
One level for Everything, including folders made later. Pick this when you don't want to revisit permissions every time you add a folder.
π What every member sees, whatever you give them#
Folder access controls profiles. Some things are structural and are shared with every member, because an app without them is an app with empty sidebars and profiles that point at proxies it doesn't have:
- Your whole proxy library, including proxy passwords. Anyone who can run a profile receives its proxy password β their browser needs it to connect.
- Every folder name and every tag name. Not the profiles inside them.
- Every Flow.
So a member scoped to one folder can see that you have folders called Client B and Banking, and can read your proxy credentials, while never seeing a single profile in those folders.
Sessions follow their profile
A profile's cookies and logins are scoped the same way the profile is. A member who can't see a profile can't be handed its logged-in session.
βοΈ Writing the shared things#
Reading the proxy library, tags, folders and Flows is open to every member. Changing them is not, because one proxy record is the proxy that every profile in the workspace points at.
| To do this | A member needs |
|---|---|
| Change a saved proxy, a tag, a folder or a Flow | Whole workspace at Can edit |
| Delete a saved proxy, a tag, a folder or a Flow | Whole workspace at Full access |
| Use LoginDeck AI inside your workspace | Whole workspace at Can edit β otherwise "AI actions in this workspace need an edit grant across the whole workspace β ask the owner" |
A member with folder grants, or with Can run, can read all of it and can't rewrite any of it.
βοΈ Moving a profile between folders#
A move needs the right level on both folders β the one it's leaving and the one it's going to. Without that, someone with Full access to Pending could pull a profile out of a folder they have no access to by moving it into Pending.
π Reading the Access column#
The Teams table summarises each person's grant in the Access column:
whole workspace β editClient A β run, no folder β editEverything β the whole workspace(your own row)
Change any of it with the Edit access pencil on their row. See Invite people to your team.
βΉοΈ Good to know#
- Permissions are enforced by the server, not by encryption. Access changes apply from the member's next request onward β they don't reach back onto a computer.
- Removing someone stops anything new reaching them. What already synced to their machine stays on their machine.
- Members can't manage the team, buy or change the plan, or see your computers or invoices.
- LoginDeck AI comes out of the owner's allowance, whoever runs it.
- One computer at a time per profile, across the whole team. See When someone else has a profile open.
β Common questions#
Can I make a member truly read-only?
Can run is as close as it gets: they can open profiles and can't change anything in your workspace. But their app doesn't stop them editing locally β the server just refuses it, quietly. See the warning above.
Can I hide my proxy passwords from a member?
No. Any member who can run a profile receives the credentials of the proxy it uses, because the browser on their computer makes the connection. Give them profiles on proxies you're willing to share.
Can a member see profiles in folders I didn't give them?
No. They'll see the folder's name in the sidebar, and nothing inside it.
Can a member delete one of my profiles?
Only with Full access on the folder that profile is in. Anything less is refused by the server.
A member says they renamed a profile but I don't see it.
Check their level on that folder. If it's Can run, the rename is sitting on their computer and was refused. Raise them to Can edit and the change goes up on the next sync.
Do permissions apply to Flows too?
Every member can see and run every Flow. Changing or deleting one needs Whole workspace at Can edit or Full access.