Skip to main content
A connector profile is either Shared or Restricted: Restricting a profile controls who can use it: link an account through it, and see it offered when linking. Managing the profile is separate. Project admins keep governance of every profile in the project, restricted or not. Restrict a profile when only specific people should connect through it, for example one that holds privileged credentials or reaches a sensitive system.
The Shared and Restricted selector on a connector profile's Access tab
Sharing and restricting connector profiles is enabled per organization. If you don’t see the Access tab on a connector profile, or the Access column in the Connector Profiles list, even as an Org Admin, contact StackOne support to turn it on for your organization.

Who can do what on a restricted profile

Access on a restricted profile comes from two places: your project role, and a grant on the profile itself. A grant carries one of two roles: Put together, on a restricted profile: Your access is the sum of both: every capability your project role grants, plus every capability your profile grant adds. Neither subsumes the other, so a Project Admin who is also granted Admin on the profile combines both sets and can do everything in the table. Viewing follows your project role and doesn’t change when a profile is restricted. An ungranted Project Admin or Org Admin keeps governance of the profile. They can still view, edit, and delete it, but they can’t link accounts through it or change who can. On a Shared profile there is nothing to grant: anyone in the project who can link accounts may use it (the profile adds no restriction), and project admins fully manage it, including its access setting.
If your organization uses explicit account access, this model will feel familiar: admins keep governance of a resource without automatically being able to use it. See How access resolves for the account version.

Restrict a profile

1

Open the profile's Access tab

Go to Connector Profiles and open the profile, then open its Access tab. The Access column in the profiles list shows each profile’s current setting.
The Access column in the connector profiles list, showing each profile as Shared or Restricted
2

Switch it to Restricted

Change the selector from Shared to Restricted. You’re added as a profile Admin automatically, so restricting a profile never locks you out of it. Restricting only gates future account links — accounts already connected through the profile stay connected and keep working.
3

Grant members and groups

Add each member or group who should keep using the profile, and pick Admin or Member on their row.
A connector profile's Access tab set to Restricted, warning that only the listed members and groups can link new accounts while already-linked accounts stay connected, above a member roster with Admin and Member roles
Granting a group grants every member of the group, and the grant tracks the group’s membership: people who join the group gain access, and people who leave lose it. Groups is enabled per organization. See Groups. To change access later, anyone granted Admin on the profile adds or removes rows on the same Access tab. A restricted profile always keeps at least one Admin: a save that would remove the last one is rejected, so hand the profile to another admin in the same save, or switch it back to Shared to clear the roster entirely.

The default for new profiles

A new profile starts with its project’s default access. In organizations where your own team links its accounts through StackOne, the default is Restricted. In organizations that embed StackOne so their customers link accounts, it is Shared. The default only sets the starting value of the selector; whoever manages a profile can change its access later (a project admin on a shared profile, or a granted admin on a restricted one). Existing profiles aren’t changed retroactively. A profile stays Shared until someone restricts it.

Hidden from the linking flow

When someone links an account, from the dashboard’s Link Account flow or through the StackOne Hub, the profile picker only offers profiles they can use. A restricted profile is invisible to anyone without a grant, which also keeps it from cluttering the linking flow for people it doesn’t concern. Re-authenticating an existing account through the profile it already uses stays possible without a grant — that use was authorized when the account was linked; only moving the account to a different restricted profile needs one. See Linking Accounts.

Next steps

Scoping Connectors

Choose which of a profile’s actions and events are exposed.

Groups

Grant many users the same access at once with reusable groups.

Linking Accounts

Connect the provider accounts your agents act on.

Team Management

Invite members and assign org and project roles.