The Workspace Owner account controls student data, billing and permissions. This page explains exactly how it is protected, what happens if you wait before turning on multi-factor authentication, and how ownership moves when somebody changes role or leaves. It matches what you see on screen, step for step.
#01Passwords
Academyship shows you every rule before you type, so nothing hidden can fail you at submit. The same rule applies everywhere a password is set: owner activation, staff invitations and password resets.
- At least 12 characters. Length matters more than anything else, so length is the rule — not a mixture of symbols.
- Up to 128 characters. Long passphrases are welcome, not truncated.
- Spaces are allowed. A passphrase of ordinary words with spaces between them is a good choice. The requirements update live under the field as you type.
- Pasting and password managers are fully supported. Blocking paste makes people choose weaker passwords.
- No required mixture of capitals, numbers or symbols. That rule mostly teaches people to add “1!” to the end, which helps nobody.
- No runs of three or more identical or sequential characters. Sequences such as
aaa,123orabcare refused wherever they appear, because they add length without adding strength. - Nothing taken from your own details. A password containing a recognisable fragment of your name, your email address or your institution’s name is refused, because those are the first things an attacker tries.
- Checked against known-compromised and very common passwords. This is the check that catches a password which satisfies every rule and is still guessable.
- No periodic rotation. Forcing regular changes makes passwords worse, not better.
What Academyship stores. Your password is sent securely over an encrypted connection to create your account. It is never written to your browser’s storage, to a web address, to the console or to analytics. How the password itself is stored is described in your institution’s security documentation.
#02Shared devices
Before you create a sign-in, Academyship asks one question: is this your own computer, or one other people use? It changes what we recommend, and it never changes what you are allowed to do.
On a shared reception, classroom, library or lab computer. Use a password plus an authenticator app on your own phone, and do not let the browser save the password. Anyone who uses that computer afterwards would otherwise reach the account.
Passkeys are not part of this release. A passkey signs you in with your fingerprint, face or device PIN and cannot be phished — but it lives on the device it was created on, so losing that device means falling back to another method. Password plus an authenticator app is the supported combination today.
#03Multi-factor authentication by plan
The policy is risk-based rather than one rule for everyone.
| Who | Requirement |
|---|---|
| Paid, trial, Institutional Annual and Enterprise Workspace Owners | Mandatory before the workspace can be used. Password plus an authenticator app is the baseline. Where the institution federates identity, single sign-on carries the requirement instead and Academyship never enrols a second factor of its own. |
| Community Workspace Owners | Offered during activation. You may wait up to 72 hours, and the nine actions listed below stay locked until it is on. |
| Invited staff | Set by the policy of the institution that invited you, not by any plan you use elsewhere. On every paid plan it is required, so you set it up during acceptance. On Community it is optional with no deadline: it is offered and strongly recommended, and the owner can require it for the whole workspace from the Setup Centre security task. |
Academyship records the method you chose and when you turned it on. It never stores the shared secret, the codes you type, or your recovery codes in readable form.
#04The Community 72-hour deferral
If you are a Community owner and choose to wait, you are shown exactly what that costs before you confirm, and you must acknowledge it explicitly. A banner then stays visible for as long as the window is running, showing how many hours are left.
Locked until you turn it on
The line is drawn around anything that puts real people into the workspace, sends information out of it, or hands out lasting power. Exploring the product, using clearly labelled sample data and confirming your own settings are all unaffected.
| Action | Why it waits |
|---|---|
| Inviting any staff member | An unprotected account must not be able to hand out access to student records. |
| Importing real institution or people data | A real import puts identifiable people into the workspace. Sample data is unaffected. |
| Exports and external communications | This is the path data actually leaves by, including bulk email and SMS to families. |
| Certificates, signatures and formal submissions | These are valid outside Academyship and are very hard to withdraw once issued. |
| API keys and integrations | Keys keep working after a password change, so they are how an intruder stays in. |
| Granting privileged roles | Creating a second administrator is how an intruder keeps access. |
| Opening employee files | Employment records hold home addresses, emergency contacts and payroll detail. They are the most sensitive personal data in the workspace and the least noticed if read. |
| Ownership and security changes | Ownership is the strongest permission Academyship grants, and switching this protection off is the first thing an intruder tries. |
| Destructive bulk actions | Mass deletion is the hardest action of all to undo. |
Still available — everything you need to set up
- Explore every section included in your plan
- Use clearly labelled sample data, and remove it in one action
- Confirm your institution essentials, calendar and academic structure
- Choose the sections your team sees first
- Add records yourself, one at a time
What happens at 72 hours. You are asked to turn it on before using the areas above. Nothing you have set up is undone by waiting. Turning it on takes about a minute if you already have an authenticator app, or one to three minutes the first time including installing one. It unlocks everything immediately and returns you to whatever you were trying to do — you never repeat the terms or the workspace setup.
#05Recovery codes
When you turn it on, Academyship shows ten single-use recovery codes once. Store them somewhere safe and separate from the device holding your authenticator — a password manager or a locked drawer, not the same phone.
Academyship stores only a hash of each code, so they cannot be shown to you again. If you lose them, you generate a new set. Security questions are not used anywhere in Academyship: they are guessable, searchable and shared between sites.
#06Activation and invitation links
| Link type | Valid for | Reminder | Rules |
|---|---|---|---|
| Owner activation | 72 hours | One reminder at 24 hours, leaving 48 hours | Single use. Requesting a new link immediately invalidates the previous unused one. |
| Staff invitation | 7 days | None | Single use and unique to one person. Resending invalidates the previous link. |
Email scanners cannot spend your link. Opening the page does not consume the link. It is only used when you take an explicit action on the page, so a corporate security scanner that follows links cannot burn your activation for you.
If a link does expire, nothing is lost: your institution details and workspace reservation stay saved under your request reference, and you never re-enter the pricing form.
#07Transferring ownership
Use this route while the current owner is still available. The successor has to act too — ownership cannot simply be handed over.
- The current owner opens Security & ownership from the Setup Centre or the user menu.
- They re-authenticate with MFA. Recent proof of identity is required before any ownership action.
- They choose a successor — an existing eligible administrator, or a new person they invite.
- The successor verifies their institutional email address.
- The successor accepts the current terms — the Terms of Service, the Acceptable Use Policy and the Privacy Policy — and creates their own acceptance record, in their own name, for the document versions current on that day.
- The successor turns on multi-factor authentication. Ownership cannot be held without it.
- The current owner confirms. Both people and the institution’s recovery contact are notified, the old owner’s sessions and recovery methods are revoked or downgraded, and the whole transfer is written to the audit trail.
Set up owner continuity before you need it. The Setup Centre includes an Owner continuity task that asks you to nominate and verify an institutional recovery contact or backup administrator. It takes about five minutes and is the single most effective way to avoid a slow recovery later.
#08When the owner has left
If nobody can sign in as the owner, the institutional recovery route applies. It verifies the institution, not just the person asking.
Why this is deliberately slower. Access to a departed colleague’s mailbox is not proof of authority. If support could transfer ownership on that basis alone, anyone who inherited that inbox could take an institution’s entire student record system. Academyship will not transfer ownership because somebody can read the old owner’s email.
- Select “The previous owner has left” from the sign-in support screen, the expired-link screen or Security & ownership.
- Academyship verifies the institutional domain and collects an authorised recovery request.
- You provide appropriate evidence — a written request from an authorised executive, board member or IT contact; confirmation the previous owner has left; control of the verified email domain; and a contract or ABN match. Never security questions.
- Academyship notifies the previous owner and every existing privileged administrator on all safe channels.
- A person reviews the case and the workspace on record is contacted before anything moves, unless an urgent security incident requires faster revocation.
- A trained Academyship reviewer approves or rejects, recording the reason and the evidence relied on.
- You verify your email, create secure authentication and turn it on in MFA, then separately accept the current terms.
- The departed owner’s sessions, tokens and recovery methods are revoked, and the immutable audit trail is preserved unchanged.
Recovery needs no account and no sign-in — that is the point of it. Voluntary transfer is faster, and needs the current owner to be able to sign in.
#09Three separate legal records
There is one set of documents — the Terms of Service, the Acceptable Use Policy and the Privacy Policy — and the Terms bind both the institution and every individual user under its account. What differs is whose name an acceptance is recorded in, and on whose authority. These three records are deliberately kept apart, and confusing them is a common and consequential mistake.
| Record | Belongs to | What happens on transfer |
|---|---|---|
| Historical individual acceptance | The person who accepted it | Kept unchanged as evidence of what that person accepted at that time. Never reassigned to the successor. |
| Current successor acceptance | The new owner | A brand-new record of the same Terms, created by the successor in their own name, for the document versions current on their day. |
| Order Form or service agreement | The institution | Unaffected. The commercial contract belongs to the institution, not to whoever holds the owner role. |
What this means for invited staff. Staff accept the same Terms of Service and Acceptable Use Policy, and acknowledge the same Privacy Policy, as individual users — there is no separate set of user terms. Each acceptance is recorded in the person’s own name. They are never asked to accept the institution’s commercial agreement, because it is not theirs to accept.
#10Keep reading
These four guides cover the whole onboarding journey.