# Team VMs


## VM limits

On Work, each pool has its own VM limit based on its size: 25 VMs per vCPU, up
to 1,000 per pool. See [VM pools](/docs/pools). Enterprise limits are set by
contract.

On the legacy Team plan, all members' VMs count toward one team-wide quota.
Run `team` to see it:

```
VMs: 12 / 100
```

## Creating VMs

Team members create VMs the same way as individual users. The VM is owned by
whoever creates it.

## Pools

On Work and Enterprise, the team's VMs run in [pools](/docs/pools) that
reserve CPU and memory. Pick one with `new --pool=<name>`; without it, the
team's [default placement](/docs/pools#default-placement) decides. Admins
choose who can create [standalone VMs](/docs/standalone-vms), and admins and
billing owners see usage with `team usage`.

## Admin visibility

Team admins (and the billing owner) see all team members' VMs by running
`team vm ls`. These appear under a "Team VMs" section, separate from your
own. The listing can be grouped with `--group=user` or `--group=access`
(as well as `tag` and `region`). Admins can also visit
[exe.dev/team/vms](https://exe.dev/team/vms) to see all VMs on their team.

## Admin SSH access

Admins can SSH directly into any team member's VM, both by name and by IP
shard routing. This works the same as SSHing into your own box:

```
ssh mybox@exe.dev
```

Admins can also delete, rename, and copy member VMs. Other team members can
copy after the VM owner grants the team Root access with `share add mybox team
--root`. A web-only team share does not allow copying.

## Sharing with the team

There are two kinds of team sharing.

### Web access

Share a VM's private web proxy with the whole team:

```
share add mybox team
```

Team shares are dynamic — when a new member joins, they automatically get
access to all team-shared VMs. Remove it with:

```
share remove mybox team
```

### SSH, Shelley, and web access

Web sharing (`share add mybox team`) grants web-proxy access only. To let any
team member (not just admins) SSH into the VM, use the browser Terminal, or use
Shelley:

```
share add mybox team --root
```

Because Root access is strictly more powerful than Web access — a teammate
with SSH can port-forward to any port anyway — it also grants access to the
VM's private web routes. You don't need to run both commands.

Revoke whole-team Root access with:

```
share remove mybox team --root
```

You can also grant one existing account Root access without sharing with the
whole team:

```
share add mybox teammate@example.com --root
```

Named Root shares persist independently of whole-team access. Grants to people
outside the team are subject to the team's external-sharing policy.

See [team sharing controls](/docs/teams/sharing-controls) for more on
how teams can share VMs, and the individual [sharing
docs](/docs/sharing) for more on how sharing works.
