Team collaboration workflow

Decide who owns the work before enabling actions.

Control account visibility separately from account, proxy, and AI permissions. Hand off independent copies through one-time sharing and remove access when responsibility changes.

MaskPilot
MaskPilot team account list showing account ownership, proxies, and runtime status
Real client interface · team account scope and runtime status

Three access layers

Seeing, acting, and handing off are separate decisions.

Team collaboration limits account scope first and enables actions by responsibility. One-time sharing creates an independent copy instead of transferring the original.

Account visibility

Teammates see accounts explicitly assigned by the owner rather than every resource in the team.

Action permissions

Account create and edit, proxy create and edit, and AI capabilities are enabled separately by responsibility.

Independent handoff

One-time sharing creates a new account copy for the recipient while the original ownership remains unchanged.

Collaboration workflow

Confirm responsibility, account scope, and handoff result in layers.

Team management requires an active Team plan. Current capacity, pricing, and available actions follow what the client displays.

Map roles to real work before assigning access.

Decide who can create or edit accounts, create or edit proxies, and use AI. One-time sharing remains a separate handoff flow.

  • Grant access by responsibility rather than convenience
  • Review sensitive actions separately
  • Do not replace member accounts with shared passwords
  • Remove access that is no longer needed
See current plans and capacity

Show teammates only the accounts they own.

The owner sets account visibility before enabling actions inside that scope. A teammate cannot use AI or sharing to bypass the assignment.

  • Separate account scope from feature permissions
  • New accounts are not visible to everyone automatically
  • AI uses the teammate’s existing permissions
  • Insufficient access fails closed
See member permission steps

Use one-time sharing when an independent copy is needed.

A sharing Token can succeed once. The recipient gets a new account and stable identity without taking ownership of the original or receiving later changes.

  • A one-time Token reduces duplicate receive risk
  • The recipient gets an independent account copy
  • The copy receives a new stable identity
  • Necessary recipient audit fields remain available
See sharing and copying

Remove access when roles change and verify every recovery.

When a Team plan expires, member authentication and resource access stay closed. The owner manages the recycle bin and rechecks assignments after recovery.

  • Expired plans do not leave team resources open
  • Old Tokens do not revive after plan restoration
  • Only the owner uses the recycle bin
  • Recheck proxies, extensions, and members after recovery
See the recovery workflow

Collaboration boundaries

Team tools reduce credential sharing but do not replace governance.

Owners still maintain the member list, responsibilities, plan, and independent backups, while every teammate operates only authorized business resources.

01

Active Team plan required

Member management follows the active Team plan, capacity, and live pricing shown in the client.

02

Do not share credentials

Collaboration does not require sending passwords, verification codes, device codes, or complete Tokens.

03

Access fails closed

Expired plans and insufficient permissions do not continue using old authentication or resource state.

04

The owner handles recovery

The owner manages the recycle bin and assigns resources again after recovery.

FAQ

Questions before you start

Can every teammate see every account?

No. The owner explicitly assigns account visibility before enabling action permissions by responsibility.

Does account sharing transfer ownership?

No. The recipient receives an independent copy with a new stable identity while the original remains with its owner.

Can members continue after the Team plan expires?

No. Member authentication and resource access stay closed, and old Tokens do not revive after plan restoration.

Who can restore an account from the recycle bin?

Only the owner can use the recycle bin. Recheck proxy, extensions, capacity, and teammate assignments after recovery.

Start with least privilege

Verify account scope and permissions with one teammate.

Download MaskPilot and complete one assignment, action, and removal flow within the current plan before adding more teammates.