Workspace owner
What the workspace owner can do that an admin cannot, and how to hand the workspace on.
Overview
Every workspace has exactly one owner. The owner is a workspace admin with four extra powers, all of them things you only want one person able to do: deleting the workspace, reading the audit log, changing security settings, and handing the workspace to someone else.
Everything else an administrator does — managing teams, jobs, members, career sites, labels and billing — is available to any workspace admin.
The owner role is given to the first person who sets up the workspace. There is no way to have two owners at once; ownership moves rather than multiplies.
Screenshot coming: The Transfer ownership action on the workspace members list
Owner and admin at a glance
| Action | Owner | Admin |
|---|---|---|
| Start a workspace deletion | ✅ | ❌ |
| Cancel a scheduled deletion | ✅ | ✅ |
| Open the audit log, filter it and export it | ✅ | ❌ |
| Change security settings | ✅ | ❌ |
| Read security settings | ✅ | ✅ |
| Transfer ownership | ✅ | ❌ |
| Change the workspace name, logo and URL | ✅ | ✅ |
| Add and remove members, promote to admin | ✅ | ✅ |
| Create and delete teams, manage public teams | ✅ | ✅ |
| Reach a private team you are not a member of | ✅ | ❌ |
| Sign in when the IP allowlist would block you | ✅ | Only on Settings → Security |
| Billing and plan changes | ✅ | ✅ |
Two entries above are worth reading twice.
Cancelling a deletion is deliberately not owner-only. A scheduled deletion is exactly the situation where the person who scheduled it may have left, so any workspace admin can stop the clock.
Security settings are owner-only to write, but admin-visible to read. An admin can open Settings → Security and see how the workspace is configured. Every control on the page is disabled for them except the invite links, which stay governed by the New user invitations setting rather than by the owner gate.
What only the owner can do
Delete the workspace
Settings → Workspace → Danger zone → Delete workspace, confirmed by typing the workspace name. An admin who is not the owner sees the button disabled with Only the workspace owner can delete this workspace.
This starts a 30-day window during which nothing changes and any admin can cancel. The Workspaces article covers the window in full.
Read the audit log
Settings → Audit log is owner-only, on the page and on every read behind it — the event list, the actor filter, the count and the CSV export. Admins do not see the entry in settings or in the command palette, and the page returns a not-found for them if they navigate to it directly.
The audit log is the record of what administrators did to candidate data, so keeping it out of reach of the administrators it records is the point.
Change security settings
Settings → Security is readable by any admin and writable only by the owner. That covers:
- Workspace management — who may invite new members, manage workspace labels, manage workspace templates, create API keys, and modify agent guidance. Each is set to Only admins or All members. Creating a team is not on this list: it always requires a workspace admin.
- File uploads — restricting uploads and the allowed file types.
- Restricted IPs — the Restrict access to allowed IPs toggle, and adding, editing or removing approved IP addresses.
- Approved email domains and Enterprise SSO.
Invite links are the exception. They stay governed by the New user invitations setting on the same page rather than by the owner gate, because that setting is their configured policy.
Transfer ownership
Open the workspace Members list, use the row menu on the person taking over, and choose Transfer ownership…. Only the sitting owner sees the action, and it is not offered for guests or for the current owner's own row.
Confirming does two things at once: the new person becomes the owner, and you become an admin. You keep full administrative access — you only lose the four owner powers. After that, only the new owner can transfer it back.
If the identity provider cannot be reached, nothing moves and Attia tells you so. If the result cannot be confirmed either way, you are told to contact support rather than to retry, because retrying a transfer that already succeeded is the thing that puts the two systems out of step.
Owner-only access to private teams
A workspace admin who is not a member of a private team cannot see that team, its jobs or its members. This applies on every plan and is not a plan feature — it is a control over candidate personal data.
The owner keeps access to private teams on every plan. Team leads and members of the team are unaffected either way.
If your organization genuinely needs central administrators inside every private team, that is available as a per-workspace exception; contact support rather than changing anyone's role.
Getting back in when a control locks you out
If the workspace restricts access to an allowed IP list and you are outside it, the owner is still let in, everywhere. An admin is let in on Settings → Security only, so they can correct the list — nowhere else. A member is not let in at all.
This is the reason to keep the owner role with someone who can be reached. An IP allowlist with nobody able to bypass it is an outage.
When a workspace loses every administrator
If the last owner and admin are removed from the workspace at the identity provider, Attia locks administration down entirely rather than promoting someone automatically. While that state is active, no one has admin rights — including the owner — and admin-only surfaces disappear.
Recovery is done by Attia support, by restoring an administrator at the identity provider. There is no in-product way out, on purpose: any escape hatch would be a way for a non-admin to grant themselves admin, and the people who could reach it are exactly the people who just lost access.
Contact support if this happens. Attia will not show an explanation on the affected screens today — see below.
Not available yet
- A second owner. Ownership can be transferred but not shared. If you need cover while the owner is away, transfer it and transfer it back.
- Owner-only billing. Billing and plan changes are available to any workspace admin. If you need billing restricted to the owner, tell us — it is not the current behaviour.
- An explanation when administration locks down. When a workspace loses every administrator, admin surfaces vanish with no message saying why. Contact support if administration disappears unexpectedly.
- Owner-only workspace name and URL. Any workspace admin can rename the workspace and change its URL. Old URLs redirect, so links survive the change.
- Letting members create teams. Creating a team requires a workspace admin, and there is no setting that changes it.