Team VMs

VM limits

On Work, each pool has its own VM limit based on its size: 25 VMs per vCPU, up to 1,000 per pool. See VM pools. Enterprise limits are set by contract.

On the legacy Team plan, all members' VMs count toward one team-wide quota. Run team to see it:

VMs: 12 / 100

Creating VMs

Team members create VMs the same way as individual users. The VM is owned by whoever creates it.

Pools

On Work and Enterprise, the team's VMs run in pools that reserve CPU and memory. Pick one with new --pool=<name>; without it, the team's default placement decides. Admins choose who can create standalone VMs, and admins and billing owners see usage with team usage.

Admin visibility

Team admins (and the billing owner) see all team members' VMs by running team vm ls. These appear under a "Team VMs" section, separate from your own. The listing can be grouped with --group=user or --group=access (as well as tag and region). Admins can also visit exe.dev/team/vms to see all VMs on their team.

Admin SSH access

Admins can SSH directly into any team member's VM, both by name and by IP shard routing. This works the same as SSHing into your own box:

ssh mybox@exe.dev

Admins can also delete, rename, and copy member VMs. Other team members can copy after the VM owner grants the team Root access with share add mybox team --root. A web-only team share does not allow copying.

Sharing with the team

There are two kinds of team sharing.

Web access

Share a VM's private web proxy with the whole team:

share add mybox team

Team shares are dynamic — when a new member joins, they automatically get access to all team-shared VMs. Remove it with:

share remove mybox team

SSH, Shelley, and web access

Web sharing (share add mybox team) grants web-proxy access only. To let any team member (not just admins) SSH into the VM, use the browser Terminal, or use Shelley:

share add mybox team --root

Because Root access is strictly more powerful than Web access — a teammate with SSH can port-forward to any port anyway — it also grants access to the VM's private web routes. You don't need to run both commands.

Revoke whole-team Root access with:

share remove mybox team --root

You can also grant one existing account Root access without sharing with the whole team:

share add mybox teammate@example.com --root

Named Root shares persist independently of whole-team access. Grants to people outside the team are subject to the team's external-sharing policy.

See team sharing controls for more on how teams can share VMs, and the individual sharing docs for more on how sharing works.