Skip to content
← Help

Handing the organization to somebody else

An organization has exactly one owner. Ownership can move — and it can move even when the current owner has stopped answering, which is the case this is really built for.

Approval goes to the organization’s verified address, never to the person asking. That is the whole security of it: nobody can promote themselves, because the decision belongs to whoever reads the organization’s own mailbox.

If you are the owner, handing it on

Pick an admin and transfer it. Whether anybody has to approve depends on where the organization ends up:

  • Straight away, if the person you are handing to is on the same email domain as the organization — they already embody the domain control the ceremony exists to prove. Also if your own login is the organization’s address, since asking that mailbox to approve your own request is asking twice.
  • After approval, if the organization would leave its domain by the hand of somebody who does not hold its mailbox. A single-use link goes to the verified address, and somebody there confirms.

The form tells you which of the two will happen before you press anything. Either way, every admin and the organization’s address are told once it is done.

If the owner has gone

Any admin can ask to become the owner. The request goes nowhere near the current owner for approval — the link goes to the organization’s verified address, and whoever reads that mailbox decides.

Two independent things are needed and neither is enough alone: you have to be an admin who can sign in, and somebody has to hold the organization’s mailbox. That is what makes it safe to offer at all.

The sitting owner cannot veto it

They are told, and they can argue with whoever reads the mailbox — but there is no button that refuses it. An owner who could cancel one request could cancel every request forever, which would make this work only against an owner who was not the problem.

Being honest about the remaining gap: an owner who is actively hostile can still remove the person asking, since approval re-checks that they are still an admin. That is a loud, recorded act rather than a silent one, which is the improvement available here.

Who can receive it

  • Somebody who has actually signed in at least once. An allowlisted address nobody has used may simply be a typo, and handing an organization to a typo strands it with an owner who can neither be removed nor log in.
  • Somebody with a verified recovery address. The owner is the one person nobody can remove, so an owner who loses their inbox with no way back is a stranded organization.

If your organization has no verified address

Then there is no mailbox to approve anything, and ownership transfers directly. Such an organization cannot send at all, so there is little to take — but it is worth verifying an address before you need any of this.

The link itself

It grants no sign-in and no access. It authorises one thing — this change of owner — and then it is spent. It lasts thirty minutes, works once, and an expired or already-used one says so plainly rather than failing.

It also asks you to press a button rather than acting on being opened, because it lands in a shared mailbox where scanners and link previews open things as a matter of routine.