Sharing and family

Team admin, policies and ownership

Delegating who can invite and remove people, organisation policies and four-eyes approval on Business and Enterprise, handing over ownership, and member deletion requests.

Updated 2026-09-29

Who can do what

  • Family: only the owner invites and removes people, manages seats and billing, and reviews what removed members left behind.
  • Business and Enterprise: the owner can let admins, or a custom role, invite and remove members. Custom roles and groups are managed in Settings → Organisation admin. Reviewing a removed member's content stays with the owner.

Organisation policies (Business and Enterprise)

Policies apply to every member of the organisation. You can:

  • require two-step sign-in (an authenticator app or a passkey);
  • set a minimum master-password strength for new or changed passwords;
  • cap how long a browser can stay unlocked, how long sign-in sessions last, how long they can sit idle, and how many each member can have;
  • keep vault sharing inside the organisation;
  • turn off connecting outside calendar accounts;
  • hide vault and notes export in the apps;
  • limit the organisation admin console to your own IP address ranges.

Most policies are enforced by our servers. Two — the minimum password strength and hiding export — are enforced by the apps themselves, so a modified app could get around them; the policies page marks how each one is enforced.

Four-eyes approval

Turn on four-eyes and sensitive admin actions, such as changing policies, wait until a second, different admin approves them. Requests that aren't approved expire after 72 hours. Every request and decision goes into the audit log.

Audit log and export

The audit log records unlocks, shares, schedule changes, membership changes and admin actions, as metadata only. Business keeps it for 2 years and Enterprise for 5, and both can download a signed export.

Handing over ownership

The owner can offer ownership to another member, confirming with their master password and an email code; the new owner has to accept. Billing and the subscription carry on unchanged, but the new owner re-enters the billing details and adds their own payment method. The previous owner stays on as an admin (on Family, as a member). Every member's sealed key copy is re-made for the new owner the next time they unlock. If a removed member's content is still being moved over to you, that has to finish before ownership can move.

Asking to have your account deleted

Members can't leave a team or delete their own account directly. Instead, a member can request deletion in Settings → Data, confirming with their master password (or an email code). The owner and anyone allowed to remove members are emailed and see the request on the members page. If nobody removes the member first, it happens automatically after 30 days. As with any removal, the member's account is deleted and what they stored in the team passes to the owner. The member can withdraw the request while it's pending.

See also Shared vaults, members and seats and Break-glass requests.