A lab head can read and edit any member's records. To prevent an accidental keystroke from changing someone else's work, the first time you edit a given record the app asks for one confirmation. After you confirm, that record stays freely editable for the rest of the browser session. There is no password and no timer.
How the confirm-once gate works
When a lab head opens a record they did not create, the record opens in read-only review mode. An Edit as lab head button appears in the header (amber, with a pencil icon). Clicking it opens a small confirmation dialog that names the member whose record you are about to change and explains that the edit will be logged to the audit trail. Two buttons follow, Cancel and Edit as lab head.
Once you confirm, the confirmation is remembered for that specific record for the rest of the browser session. The dialog does not appear again if you close and reopen the same record. A page reload or a user switch clears the memory, so the next session always starts fresh.
What happens when you edit
After confirming, the record becomes editable exactly as if it were your own. Your edits are written back to the member's folder, not copied to you, so ownership does not change. Each field you change appends a row to that member's users/<member>/_pi_audit.json file so the change leaves a complete record. See Audit log.
What it replaced
Before June 2026 the lab-head edit path used a separate PI password and a shared 5-minute timed session that unlocked every soft-write affordance at once. That gate was removed. A logged-in lab head is already authenticated through the normal account sign-in, so a password prompt was a redundant step. The per-record confirm dialog keeps the friction that stops accidental edits while removing the friction that slowed down intentional ones.
Where to go next
Soft-write actions covers the purchase approval, task assignment, and flag-for-review affordances.
Audit log covers the _pi_audit.json file and how to open the trail viewer.