Вашою мовою цієї сторінки поки немає. Ви читаєте англійський текст.
Blog
How to hand accounts to a contractor without the passwords
Команда ARMANOS7 min
What a password really hands over
An account password is not one key but three. It opens the account, for many people it opens the recovery mailbox too, and it keeps working after the work is over.
The platform sees you rather than your contractor, and there is nothing to explain the picture with. Two logins to one account from two cities in a day are exactly the picture that sends an account for review.
- 1
The key to the account
A password opens the whole account, not the part the work needs.
- 2
The key to recovery
The same password often sits on the recovery mailbox, and then getting the account back leaves your hands.
- 3
A key with no expiry
A password you sent lives in the chat until you change it, and the change throws everyone out.
Your contractor signs in as themselves
Instead of a password you give the person a seat in your workspace. They make their own account, arrive on an invite code, and sign in with their own email and password.
The owner always holds one seat, so count colleagues from yourself. A plan hands out seats as a bundle, and extra ones are counted one by one. A seat beyond the plan costs $3 a month, an invite code lives 7 days, and you can revoke it before the person joins.
| Plan | Seats in the team |
|---|---|
| Free | 1 |
| Professional | 1 |
| Business | 3 |
| Enterprise | 20 |
An invitation works once
An invite code lives for seven days, and that period comes from one line on the server rather than being typed into the letter by hand. An expired code is refused the same way as an invented one, with one and the same answer.
An accepted code does not work a second time: an invitation carries an acceptance mark, and with it the invitation counts as used. Only an unaccepted invitation can be revoked; an accepted one is undone by removing the person from the team.
One person can belong to several teams and keeps their own workspace. Someone already on your team cannot join it a second time with a code, and the server says so outright.
Five roles and where each stops
A role is a rank, not a checklist, and an unknown role word has rank zero, so it passes no door. A higher one opens everything a lower one opens, and a role word the server does not recognise opens nothing.
For three accounts your contractor needs the lowest rank. It works the profiles they were given and stops at billing, the roster and the History screen.
| Role | What it opens | Where it stops |
|---|---|---|
| Owner | The whole workspace: billing, team, history | Cannot be removed or limited to groups |
| Admin | Billing and plan, invites, roles, group access, history | Cannot touch the owner |
| Manager | Groups, the proxy library, flows, schedules, address rotation | No billing, no team, no history |
| Operator | Their own profiles and ones shared with them | No proxy library, groups or schedules |
| Member | The same as operator | The same place as operator |
What each step adds
The two lowest roles, operator and member, are equal in rank: both work with the profiles they were given and change nothing shared. A manager on top of that creates, edits and deletes the shared working things, groups and the proxy library, and does not touch money or the team.
An admin adds billing, the team roster, history, other people's profiles and devices. The owner opens everything and is the only one who cannot be removed.
| Step | What it adds to the one below |
|---|---|
| Operator and member | work with the profiles given |
| Manager | groups and the proxy library |
| Admin | billing, team, history, other people's profiles and devices |
| Owner | everything, and cannot be removed |
Groups pin a person to one client
A role covers the whole workspace at once, so by itself it cannot say «this person runs client A only». Groups do that: you tick the ones they may see, and their list shrinks to those.
The limit holds in two places at once, and there is no way around it through a request address. A profile outside their groups is invisible in the list and by its id, and a profile with no group is hidden too.
The profile travels, the password stays
You share the profile itself, and the machine goes with it: fingerprint, pinned browser version, proxy and settings. The platform sees the same computer whichever side the account is opened from.
The account password is not among it, and a request carrying such fields is refused whole rather than trimmed quietly. A profile on the server has no column for cookies, for a login pair or for a one-time key, and a body carrying such fields is refused whole.
- 1
The machine travels
Fingerprint, browser version, proxy and settings reach whoever you shared the profile with.
- 2
The login does not
There is no login pair and no one-time key on the server at all.
- 3
Access comes back
Revoke the share and the profile leaves their app at the next sync.
One window per account
Two people opening one profile at once give the platform two live sessions of one account from two places. Your machines cannot see each other, so a profile carries one lock for everyone. The lock lives on the server: until the app is signed in it never asks for it and opens the profile.
Time holds that lock rather than a promise: while the window is open the app renews it every minute, and no admin has to be called. Pull the plug and 3 minutes later the profile opens again.
What is left after a parting
Every action worth arguing about leaves one row: who, what, when, and in whose workspace. There are 58 kinds of action, 6 of them about the team: invite, withdrawal, joining, role change, group access, departure. The admin and the owner read these rows on the History screen.
A departure cuts access both ways at once. The lock they held is lifted, the seat is freed by the same move, a second invite to the same address stops working, and the work profiles and your proxies stay with you.
Four roads and what each costs
There are four roads, and choosing between them is choosing what you risk, and none of the four is free. The table below names the price of each in one line.
For three accounts and one person take rows two and three together: a seat, the lowest role, one group and the profiles they need. Keep the file for when someone needs an account already open.
| Road | What leaves your hands |
|---|---|
| A password in a chat | The whole account, for good |
| A seat, a role and a group | Exactly what you ticked |
| A shared profile | The machine and the settings, no login pair |
| A profile file with its session | A live session and the saved login pair |
What this does not claim
- It does not claim a contractor will never see a password. A session with an account already open travels as an encrypted file, and the saved login pair and one-time key travel inside it.
- Revoking access does not erase what has already landed on their disk. The profile leaves their app, and the cookies written while they worked stay with them.
- A role covers the whole workspace. You cannot make someone senior over one group and junior over another: groups narrow what is visible, not what a role does.
- No browser fixes behaviour. Identical posts, one payment card and one daily rhythm link accounts regardless of roles and groups.
Where you can see this yourself
Every number above comes out of code you can open and run.
- The five roles and their ranking
- apps/server/src/common/roles/workspace-roles.ts
- Groups narrow what a person sees, checked on a live server
- apps/server/test/group-access.js
- Cookies and a login pair are refused whole
- apps/server/test/куки-и-входы-сервер-не-примет.js
- Leaving the team cuts access both ways
- apps/server/test/team-money-seats.js
- One window per profile, takeover only from the holder
- apps/desktop/test/profile-busy.js
- The login pair stays off the server, checked in a real browser
- apps/desktop/test/login-stays-local.js
- One-time codes match the published vectors
- apps/desktop/src/lib/totp.js · apps/desktop/test/totp.js
Questions
- Can I give access without making them an account?
- No. An invite goes to an address that already has an account, and that is the only barrier against a stranger holding the code.
- Will my contractor see my other accounts?
- They will, unless you tick their groups. An empty list means «no limit» rather than «nothing visible». The window says so outright: with nothing ticked it shows «Nothing picked: this person sees every group».
- How will they pass two-factor?
- The 2FA key from the One-time code window never reaches the server, so a shared profile does not carry it. The code is produced where the key sits: read it out yourself, or hand the profile over as a file.
- What happens to the accounts when we part?
- Access goes both ways in the same moment, the lock is lifted, a second invite to the same address stops working. Cookies already written to their disk stay with them.
- What does seating three contractors cost?
- Count from yourself: one seat always belongs to the owner. On a plan with three seats two colleagues join at no extra charge, and each one after costs $3 a month.
Next to this
See what your own browser answers
The check reads 12 values right in your browser and sends nothing anywhere.