Skip to content

Teams and roles

The four roles and their limits, sharing profiles without sharing passwords, masked credentials, switching members and the activity log.

Last updated 2026-09-16

A workspace can hold several people. 3 members during the trial, 25 on the paid plan.

Read this first: members live in the database on the computer SoftGlaze is installed on, and invite codes are redeemed against that database. Several people can work from one installation, and each signs in with their own password. There is no hosted team server, so people on their own laptops are not sharing a workspace.

The roles

4 roles: Owner, Admin, Manager, Operator. Each has default limits on profiles, proxies and running browsers, which you can change per person.

The roles: table
RoleWhat it is forProfilesProxiesBrowsers
OwnerFull control, including members and the vaultNo limitNo limitNo limit
AdminManage profiles, proxies, groups and the managers and operators they create20020010
ManagerCreate, edit and launch profiles, and add operators50505
OperatorLaunch and use assigned profiles only10102

Each role can add members below it, up to a cap: an Owner can add up to 10 Admins, 10 Managers and 5 Operators; an Admin up to 5 Managers and 5 Operators; a Manager up to 3 Operators.

Per-member permissions

Owners and admins can adjust a member they manage:

  • Resource limits: the three numbers above.
  • Visible features: hide any of Dashboard, Profiles, Groups, Proxy pool, Extensions, Browsers, Batch import, Members, Trash or Settings from their sidebar.
  • Action permissions: every action is on by default for the role; turning one off revokes it for that member only. An override can never grant a permission the role doesn’t have.
  • Revert to role defaults puts all of it back in one step.

The full action list, and which role each one starts at, is on the team access page.

Sharing a profile

Managers and above can share selected profiles with a member, to use (launch only) or to use and edit, and revoke it later. Deleting stays with admins.

Below Manager, credentials arrive masked as ••••••••: the proxy login, the cookie export and the live 2FA code. The profile still launches for them, and they can still do the work, they just never see the password behind it.

Masking is not encryption. Until you turn on database encryption those credentials are plain text in the local database; anyone who can read the file can read them.

Switching members

The member menu at the bottom of the sidebar switches account without restarting the app. A member can have a PIN, which is asked for when you switch to them. Switching to a member of the same or a higher role asks for that member’s password.

What an Operator sees changes immediately: hidden pages leave the sidebar, credentials turn into dots, and an action their role can’t perform is refused by the app rather than hidden from the screen. The demo’s roles flow shows it in about thirty seconds.

Activity log

The Members screen has an Activity tab recording launches, stops, creations, edits, deletions, restores, imports, assignments, macro and parallel runs, member changes, permission changes and sign-ins.

Filter by member, action and date range, then export as CSV or JSON. The log is local, like everything else.

When someone leaves

Removing a member asks what happens to their data: keep it and reassign to you, keep it and reassign to another member, or delete it. Deleted profiles go to Trash and can be restored; their proxies and proxy groups are deleted outright.

Suspending a member blocks sign-in without removing anything.