Skip to main content
All updates

How teams should structure browser profiles

Past a hundred profiles, sloppy naming, grouping, and permissions get expensive fast. Here are the conventions that hold up over time.

  • practice
  • team
  • profiles

Early on, profiles get created ad hoc: test1, new account, Sam's. That works for a few dozen. Past a hundred, you stop knowing which profile maps to which account, and you stop being willing to delete anything.

Here are the conventions that tend to survive contact with a growing team.

Naming: put searchable information in the name

A profile name exists to be found, not to be read. Fix a field order and stick to it:

line-region-platform-index
ecom-us-amz-014

Now searching us returns every North America profile and amz returns every profile on that platform. Avoid putting a person's name in the profile name — people move around, profiles do not get renamed when they do.

Grouping: by who owns it, not by what it is

A useful split between groups and tags:

  • groups define the permission boundary, so organize them by ownership (team, project, client);
  • tags describe attributes and can stack freely (platform, region, status).

Using groups as a category tree usually means bulk-moving profiles whenever the team reshuffles. Organizing by ownership means you only change permissions.

Permissions: start with the smallest scope

Give a new member only the profile groups they need right now, not blanket access. Since 2.4 you can save a common role and profile scope as a permission template and apply it during onboarding, which is harder to get wrong than ticking items individually.

Read-only members are a good fit for people who need to see results without operating accounts, and those seats are not billed.

Proxies: routes and profiles should line up

An account whose egress IP jumps around is the start of a lot of problems. In practice:

  • keep one account identity on one route for the long run rather than switching often;
  • when you do need to rotate, use a rotation policy instead of editing config by hand, so at least the change is recorded;
  • run a batch proxy health check periodically and retire the dead routes.

When to delete

The recycle bin holds deleted profiles for 30 days, which makes "delete it and see" cheaper than it feels. A simple rule: if a profile has not launched in three months and has no concrete plan to be reused, move it to the bin. If nobody comes looking within a month, it really was not needed.

The profile management section in the help center covers the mechanics.

Looking for a specific release? The changelog lists every version.

View changelog

We use cookies

Exfing uses essential cookies to remember your language preference. With your consent, we also use analytics cookies to understand how the site is used and improve the product. View privacy policy →