Restricting a profile controls who can use it: link an account through it, and see it offered when linking. Managing the profile is separate. Project admins keep governance of every profile in the project, restricted or not. Restrict a profile when only specific people should connect through it, for example one that holds privileged credentials or reaches a sensitive system.

Sharing and restricting connector profiles is enabled per organization. If you don’t see the Access tab on a connector profile, or the Access column in the Connector Profiles list, even as an Org Admin, contact StackOne support to turn it on for your organization.
Who can do what on a restricted profile
Access on a restricted profile comes from two places: your project role, and a grant on the profile itself. A grant carries one of two roles:
Put together, on a restricted profile:
Your access is the sum of both: every capability your project role grants, plus every capability your profile grant adds. Neither subsumes the other, so a Project Admin who is also granted Admin on the profile combines both sets and can do everything in the table. Viewing follows your project role and doesn’t change when a profile is restricted.
An ungranted Project Admin or Org Admin keeps governance of the profile. They can still view, edit, and delete it, but they can’t link accounts through it or change who can.
On a Shared profile there is nothing to grant: anyone in the project who can link accounts may use it (the profile adds no restriction), and project admins fully manage it, including its access setting.
If your organization uses explicit account access, this model will feel familiar: admins keep governance of a resource without automatically being able to use it. See How access resolves for the account version.
Restrict a profile
1
Open the profile's Access tab
Go to Connector Profiles and open the profile, then open its Access tab. The Access column in the profiles list shows each profile’s current setting.

2
Switch it to Restricted
Change the selector from Shared to Restricted. You’re added as a profile Admin automatically, so restricting a profile never locks you out of it. Restricting only gates future account links — accounts already connected through the profile stay connected and keep working.
3
Grant members and groups
Add each member or group who should keep using the profile, and pick Admin or Member on their row.

The default for new profiles
A new profile starts with its project’s default access. In organizations where your own team links its accounts through StackOne, the default is Restricted. In organizations that embed StackOne so their customers link accounts, it is Shared. The default only sets the starting value of the selector; whoever manages a profile can change its access later (a project admin on a shared profile, or a granted admin on a restricted one). Existing profiles aren’t changed retroactively. A profile stays Shared until someone restricts it.Hidden from the linking flow
When someone links an account, from the dashboard’s Link Account flow or through the StackOne Hub, the profile picker only offers profiles they can use. A restricted profile is invisible to anyone without a grant, which also keeps it from cluttering the linking flow for people it doesn’t concern. Re-authenticating an existing account through the profile it already uses stays possible without a grant — that use was authorized when the account was linked; only moving the account to a different restricted profile needs one. See Linking Accounts.Next steps
Scoping Connectors
Choose which of a profile’s actions and events are exposed.
Groups
Grant many users the same access at once with reusable groups.
Linking Accounts
Connect the provider accounts your agents act on.
Team Management
Invite members and assign org and project roles.