I'm confused - permissions or not, the tokens shouldn't be throwing visible light or providing sight from the GM layer should they? I'm pretty sure you need to leave them on the main token layer and trust your players not to bugger around with them. You can put them on the DL layer, but I think you might need "all players see light" set for that, which is no good for your sneaking person. What Franky posted above works for me - a character sheet called LightTokens or whatever, the default token is transparent with a GM-only aura to mark its location, has sight, throws bright light (not visible to all players). Drag new tokens from the journal and place them where you need to provide coverage (making sure they're all properly set up and linked to the character sheet before placing too many), then open the character sheet and give permissions to required players. It sounds like this is pretty much what you did? When I add or remove permission on my LightTokens character, it will update for the player as soon as they click or move or do anything in their browser window. You could try getting someone to join and see if their experience is the same as your dummy account? Maybe it's browser related.