Why Can’t a Team Member Edit a Profile?
Check profile assignment, profile editing, and proxy permissions when a team member can see a profile but cannot save changes.
Updated Sep 6, 2026Seeing a profile only confirms that it is within the member’s visible scope. Editing it requires a separate feature permission. Do not assign more profiles to solve an edit denial, and do not enable every permission merely to troubleshoot one action.
Match the symptom to the permission
| Symptom | Check first |
|---|---|
| The target profile is missing from the list | Member status and profile assignment |
| The profile is visible, but saving profile settings is denied | “Edit assigned accounts” |
| A new profile cannot be created | “Create account” |
| A new proxy or group cannot be added | “Add proxy” |
| A proxy currently used by an assigned profile cannot be edited | “Change proxies used by accounts” and whether that profile actually uses the proxy |
| An AI tool action is denied | “Use AI automation” |
These permissions are independent. For example, permission to create profiles does not grant permission to modify every assigned profile. Permission to modify a proxy also does not expand which profiles the member can see.
Let the profile owner check in order
- Confirm in the team member list that the member is still enabled.
- Open profile assignment and confirm that the target profile is assigned to that member.
- For changes to the profile name, fingerprint, or other profile settings, enable “Edit assigned accounts.”
- For proxy work, distinguish between adding a new proxy and modifying the proxy currently used by an assigned profile. Enable only the required capability.
- Save the change, then ask the member to reopen the affected page and repeat the same action. If the page still shows old permissions, ask the member to sign out and back in. Refreshing the owner’s team page only confirms that the permission was saved.
If the member cannot see the profile at all, use the missing profile checklist. For the complete setup flow, see add team members and set permissions.
Separate local running state from edit access
A session on another device or under another member no longer denies a local launch through a lease and does not replace edit-permission checks. Duplicate local launches, permission to save settings, and upload-version conflicts are separate issues. Preserve the original message and check assignments and capabilities instead of broadly expanding member permissions.
Verify with least privilege
Add only the capability required for the member’s current responsibility, then repeat the same operation. After it succeeds, verify that unrelated profile creation, proxy management, or AI automation permissions were not enabled accidentally. The OWASP Authorization Cheat Sheet recommends least privilege, deny by default, and permission validation on every request. A denied action should therefore be resolved by granting the specific justified capability, not by granting every permission.
If editing is still denied
Record the member email, target profile name, failed action, time, and complete page message so the owner can review the current assignment, member permissions, and recent activity. Remove initial passwords, website credentials, proxy credentials, and other sensitive details from screenshots or logs.