Owners and Admins administer the workspace. They see every project and every ticket, configure clients, pricing, workflow, mail, and authentication, and are the only people who close periods and run billing. An Owner additionally holds the organization: the subscription, the audit log, export, and deletion. Both roles require two-factor authentication.
Before you start
You need the Owner or Admin role, and two-factor authentication on your account. Many of the tasks below also ask you to confirm your identity again (a recent full login) before they run: inviting and changing members, minting tokens, authentication and mailbox settings, period close, billing runs and voids, redaction and deletion, export, and Stripe Checkout.
What you configure
| Area | Where | Page |
|---|---|---|
| Workspace users, roles, invitations | Settings → Members | Manage members |
| Name, ticket prefix, time zone, language, currency, period length | Settings → General | Workspace settings |
| Kinds, states, priorities, rules (inbound kind, customer-resolve state, default priority, reopen window) | Settings → Workflow and kinds | Configure the workflow |
| Labels | Settings → Labels | Labels |
| Clients, client users, contacts, billing recipients | Clients | Create a client, Manage client users, Contacts and billing recipients |
| Projects: key, billing client, billing mode, collaborating clients, members, archive | Projects | Create a project, Manage project members |
| Mailbox (Microsoft 365 or IMAP/SMTP), delivery reconciliation | Settings → Mailbox | Connect a mailbox |
| Domains, single sign-on, SCIM | Settings → Authentication | Authentication, Single sign-on, SCIM provisioning |
| API token registry, agent accounts, MCP setup | Settings → API tokens, Members, MCP setup | API tokens and agents |
| Consultant categories, default policies, default category per person | Settings → Consultant categories | Consultant categories and rate cards |
| Rate cards, policies, time banks per client | Clients → client → Rate card, Policies, Time banks | Billing policies, Time banks |
| Period length, first period start, reopen window | Settings → Period and run settings | Close a period |
| Close periods | Billing → Periods | Close a period |
| Corrections, edits to others' time, re-attribution | Time, ticket pages | Correct closed time |
| Billing runs and voids | Billing → Billing runs | Run billing |
| Client-wide document access grants for workspace users | Clients → client → Documents | Client timesheets |
| Delete and redact tickets | Ticket page | Archive and delete a ticket |
| Audit log (Owner) | Settings → Audit log | Audit log |
| Plan, subscription, invoice billing (Owner) | Settings → Organization | Plan and subscription |
| Export and delete the workspace (Owner) | Settings → Organization | Export and delete workspace |
Client management, pricing, settings, period close, and billing runs are browser-only: no API token can perform them.
Owner versus Admin
| Capability | Owner | Admin |
|---|---|---|
| Everything in the table above except the rows marked Owner | Yes | Yes |
| Assign roles | Any role, including Owner | Admin or Member; can never change or remove an Owner ("Only an owner can do this.") |
| Settings → Organization: plan, Checkout, billing portal, invoice billing request | Yes | No |
| Settings → Audit log (the 200 most recent recorded actions) | Yes | No |
| Export the workspace | Yes | No |
| Schedule workspace deletion (30-day read-only grace, then purge) | Yes | No |
| Map a SCIM group or the default role to Owner | Yes | No |
| Be the last Owner | A workspace always needs one; the last Owner cannot be demoted or removed | Not applicable |
Two-factor authentication
Owners and Admins must have two-factor authentication, either an authenticator app (TOTP) or a passkey, before they can enter the workspace. A new Admin without it is sent to Account → Security on first entry. Promoting a Member to Owner or Admin also revokes that person's personal API tokens, because tokens are minted under the two-factor rule. A workspace with single sign-on can accept the identity provider's MFA through an assurance rule on the connection. See First login.