Sharing and family

Team admin, policies and ownership

Delegating who can invite and remove people, organisation policies and four-eyes approval on Business and Enterprise, which apps each member can use, who can export data, handing over ownership, and member deletion requests.

Updated 2026-09-29

Who can do what

  • Family: only the owner invites and removes people, manages seats and billing, and reviews what removed members left behind.
  • Business and Enterprise: the owner can let admins, or a custom role, invite and remove members. Custom roles and groups are managed in Settings → Organisation admin. Reviewing a removed member's content stays with the owner.

Organisation policies (Business and Enterprise)

Policies apply to every member of the organisation. You can:

  • require two-step sign-in (an authenticator app or a passkey);
  • set a minimum master-password strength for new or changed passwords;
  • cap how long a browser can stay unlocked, how long sign-in sessions last, how long they can sit idle, and how many each member can have;
  • keep vault sharing inside the organisation;
  • turn off connecting outside calendar accounts;
  • limit the organisation admin console to your own IP address ranges.

Most policies are enforced by our servers. The minimum password strength is enforced by the apps themselves, so a modified app could get around it; the policies page marks how each one is enforced.

Which apps each member can use

The account owner chooses which apps each member can use, on every team plan. When you invite someone, the invitation has a list of apps with every app your plan includes ticked; untick any they shouldn't have. Later, open a member's menu on the members page and choose Apps… to turn apps on or off. Admins and custom roles can invite people, but only the owner chooses apps, and the owner always has every app. A member never gets an app your plan doesn't include.

A turned-off app is hidden from the member's app list and blocked: our servers refuse its requests, including shared calendars, lists, contact books and budgets, calendar apps on their phone, and the browser extension for the vault. This hides and blocks the app; the member's data in it is kept. Nothing is deleted and no keys are taken away, so turning the app back on gives them everything again. If you need to take someone out of a shared item for good, remove them from it instead.

The member is told by email and in the app when you change their apps. If they open a turned-off app, they can request access, with an optional reason. You're emailed and see the request on the members page, then turn the app on or decline. After a decline, they can ask for that app again after 7 days.

Who can export data

Data export is set per member, on every team plan, by the account owner only. On the members page, open a member's menu and choose Turn off data export (or Allow data export). New members can export by default, and the owner always can. The member is told by email and in the app when the owner changes it.

When export is off for a member, the apps hide every export tool: vault, notes, calendar, lists, budgets, contacts, and form, event and poll responses, as well as Export everything in Settings → Data and the export on a suspended account's screen. Our servers also refuse the parts of export they handle. Your data is end-to-end encrypted, so exports are made on the member's own device from what they can already open. Turning export off hides the export tools, but members can still view everything they have access to.

A member whose export is off can request export access, with an optional reason. The owner is emailed and sees the request on the members page, then allows or declines it. After a decline, the member can ask again after 7 days. The member can withdraw a request while it's pending.

Four-eyes approval

Turn on four-eyes and sensitive admin actions, such as changing policies, wait until a second, different admin approves them. Requests that aren't approved expire after 72 hours. Every request and decision goes into the audit log.

Audit log and export

The audit log records unlocks, shares, schedule changes, membership changes and admin actions, as metadata only. Business keeps it for 2 years and Enterprise for 5, and both can download a signed export.

Handing over ownership

The owner can offer ownership to another member, confirming with their master password and an email code; the new owner has to accept. Billing and the subscription carry on unchanged, but the new owner re-enters the billing details and adds their own payment method. The previous owner stays on as an admin (on Family, as a member). Every member's sealed key copy is re-made for the new owner the next time they unlock. If a removed member's content is still being moved over to you, that has to finish before ownership can move.

Asking to have your account deleted

Members can't leave a team or delete their own account directly. Instead, a member can request deletion in Settings → Data, confirming with their master password (or an email code). The owner and anyone allowed to remove members are emailed and see the request on the members page. If nobody removes the member first, it happens automatically after 30 days. As with any removal, the member's account is deleted and what they stored in the team passes to the owner. The member can withdraw the request while it's pending.

See also Shared vaults, members and seats and Break-glass requests.