Owner and Admin

Everything an Owner or Admin configures in SAQ, with links to each task, the differences between the two roles, and the two-factor requirement.

Written for
admin
Roles
owner, admin
Requires
Owner or Admin role; Two-factor authentication (TOTP or passkey)
Feature
members

Owners and Admins administer the workspace. They see every project and every ticket, configure clients, pricing, workflow, mail, and authentication, and are the only people who close periods and run billing. An Owner additionally holds the organization: the subscription, the audit log, export, and deletion. Both roles require two-factor authentication.

Before you start

You need the Owner or Admin role, and two-factor authentication on your account. Many of the tasks below also ask you to confirm your identity again (a recent full login) before they run: inviting and changing members, minting tokens, authentication and mailbox settings, period close, billing runs and voids, redaction and deletion, export, and Stripe Checkout.

What you configure

Area Where Page
Workspace users, roles, invitations Settings → Members Manage members
Name, ticket prefix, time zone, language, currency, period length Settings → General Workspace settings
Kinds, states, priorities, rules (inbound kind, customer-resolve state, default priority, reopen window) Settings → Workflow and kinds Configure the workflow
Labels Settings → Labels Labels
Clients, client users, contacts, billing recipients Clients Create a client, Manage client users, Contacts and billing recipients
Projects: key, billing client, billing mode, collaborating clients, members, archive Projects Create a project, Manage project members
Mailbox (Microsoft 365 or IMAP/SMTP), delivery reconciliation Settings → Mailbox Connect a mailbox
Domains, single sign-on, SCIM Settings → Authentication Authentication, Single sign-on, SCIM provisioning
API token registry, agent accounts, MCP setup Settings → API tokens, Members, MCP setup API tokens and agents
Consultant categories, default policies, default category per person Settings → Consultant categories Consultant categories and rate cards
Rate cards, policies, time banks per client Clients → client → Rate card, Policies, Time banks Billing policies, Time banks
Period length, first period start, reopen window Settings → Period and run settings Close a period
Close periods Billing → Periods Close a period
Corrections, edits to others' time, re-attribution Time, ticket pages Correct closed time
Billing runs and voids Billing → Billing runs Run billing
Client-wide document access grants for workspace users Clients → client → Documents Client timesheets
Delete and redact tickets Ticket page Archive and delete a ticket
Audit log (Owner) Settings → Audit log Audit log
Plan, subscription, invoice billing (Owner) Settings → Organization Plan and subscription
Export and delete the workspace (Owner) Settings → Organization Export and delete workspace

Client management, pricing, settings, period close, and billing runs are browser-only: no API token can perform them.

Owner versus Admin

Capability Owner Admin
Everything in the table above except the rows marked Owner Yes Yes
Assign roles Any role, including Owner Admin or Member; can never change or remove an Owner ("Only an owner can do this.")
Settings → Organization: plan, Checkout, billing portal, invoice billing request Yes No
Settings → Audit log (the 200 most recent recorded actions) Yes No
Export the workspace Yes No
Schedule workspace deletion (30-day read-only grace, then purge) Yes No
Map a SCIM group or the default role to Owner Yes No
Be the last Owner A workspace always needs one; the last Owner cannot be demoted or removed Not applicable

Two-factor authentication

Owners and Admins must have two-factor authentication, either an authenticator app (TOTP) or a passkey, before they can enter the workspace. A new Admin without it is sent to Account → Security on first entry. Promoting a Member to Owner or Admin also revokes that person's personal API tokens, because tokens are minted under the two-factor rule. A workspace with single sign-on can accept the identity provider's MFA through an assurance rule on the connection. See First login.