Skip to content

Manage Members and Roles

The Members page displays roles on the left and members on the right. Roles define page and action permissions. A member's settings also determine the browser profile groups and proxies they can access.

Before defining roles, review the actions that require authorization under Browser Profiles, Proxies, and Extensions.

Create a Role

  1. Click New Role in the role panel.
  2. Enter a role name.
  3. Select the required permissions by module and save.

When an action permission is selected, the client also selects its required list permission so the role can see the page where the action is performed. Deleting a role cannot be undone. Confirm that no member still depends on it.

Create a team role
Create a team role

Edit Member Permissions

Find the member and click Edit. You can configure:

SettingDescription
RolesSelect one or more existing roles
Authorized groupsAllow all groups or only selected browser profile groups
Proxy authorizationNo access, all proxies, or selected proxies; with no access, the member can see only proxies they created
NotesRecord responsibilities or handover information

Search members by username, nickname, or phone number. Point to Notes to edit them directly. Administrators and team owners cannot be selected for batch actions or deletion.

Enable, Disable, or Remove a Member

Use the status switch to disable a member. A disabled member cannot switch to the active team. Removing a member requires confirmation and affects only the current team; it does not delete the user's account.

If edit, delete, or status controls are unavailable, the current account lacks the corresponding member or role permission, or the record belongs to the team owner.

Log Out a Member

The Online Status column shows whether each member is currently online. To end a member's active sessions in the current team immediately:

  1. Find the online member.
  2. Click Log Out in the Operation column.
  3. Verify the username in the confirmation message, then confirm.
Member logout action
Member logout action

After confirmation, all of that member's online devices receive a logout notification. Once the notification is sent, ZYBrowser refreshes the member list for the administrator and displays a Forced Logout dialog to the member, who must choose one of the following actions.

Forced logout dialog
Forced logout dialog
ButtonDescription
Switch to Initial TeamSwitches ZYBrowser back to the account's initial team
Exit LoginLogs out of the current account and returns to the login page

Important

Both actions close all currently running browser profiles. Proceed with caution.

The administrator's Log Out action does not disable the member, remove them from the team, or delete the account. The action is available only for an online non-owner member, and the current operator must have permission to log out members. A team owner cannot be logged out.

Configure the Login IP Allowlist

The Login IP Allowlist is a security setting for the active team. It restricts the IP addresses that regular members can use when accessing the team. The Security Settings button above the member list is visible only to team administrators. To configure the allowlist:

  1. Click Security Settings above the member list.
  2. Enable Login IP Allowlist.
  3. Enter one IP address, CIDR range, or trailing-wildcard IPv4 address per line.
  4. Click Save Settings.
Login IP allowlist settings
Login IP allowlist settings

The allowlist accepts these formats:

FormatExampleDescription
Exact IPv4192.168.2.1Allows only the specified IPv4 address
Trailing-wildcard IPv4192.168.5.*Supports * only as the final IPv4 segment
  • An enabled allowlist requires at least one entry. Blank lines are ignored, and ZYBrowser reports the line number of an invalid entry.
  • The allowlist applies only to subsequent sign-in attempts. Users who are already signed in from an IP address outside the allowlist are unaffected: ZYBrowser does not log them out or switch teams automatically. When a member signs in from an IP address outside the allowlist, ZYBrowser defaults to the member's initial team.
  • Team owners are exempt from the allowlist.
  • After disabling the allowlist, click Save Settings to submit the change.