Skip to main content
Help Centre · Getting started

Account security, MFA, recovery and ownership transfer

Owner and staff · 72-hour activation links · Passwords and MFA · Last updated 29 August 2026

The Workspace Owner account controls student data, billing and permissions. This page explains exactly how it is protected, what happens if you wait before turning on multi-factor authentication, and how ownership moves when somebody changes role or leaves. It matches what you see on screen, step for step.

#01Passwords

Academyship shows you every rule before you type, so nothing hidden can fail you at submit. The same rule applies everywhere a password is set: owner activation, staff invitations and password resets.

  • At least 12 characters. Length matters more than anything else, so length is the rule — not a mixture of symbols.
  • Up to 128 characters. Long passphrases are welcome, not truncated.
  • Spaces are allowed. A passphrase of ordinary words with spaces between them is a good choice. The requirements update live under the field as you type.
  • Pasting and password managers are fully supported. Blocking paste makes people choose weaker passwords.
  • No required mixture of capitals, numbers or symbols. That rule mostly teaches people to add “1!” to the end, which helps nobody.
  • No runs of three or more identical or sequential characters. Sequences such as aaa, 123 or abc are refused wherever they appear, because they add length without adding strength.
  • Nothing taken from your own details. A password containing a recognisable fragment of your name, your email address or your institution’s name is refused, because those are the first things an attacker tries.
  • Checked against known-compromised and very common passwords. This is the check that catches a password which satisfies every rule and is still guessable.
  • No periodic rotation. Forcing regular changes makes passwords worse, not better.

What Academyship stores. Your password is sent securely over an encrypted connection to create your account. It is never written to your browser’s storage, to a web address, to the console or to analytics. How the password itself is stored is described in your institution’s security documentation.

#02Shared devices

Before you create a sign-in, Academyship asks one question: is this your own computer, or one other people use? It changes what we recommend, and it never changes what you are allowed to do.

On a shared reception, classroom, library or lab computer. Use a password plus an authenticator app on your own phone, and do not let the browser save the password. Anyone who uses that computer afterwards would otherwise reach the account.

Passkeys are not part of this release. A passkey signs you in with your fingerprint, face or device PIN and cannot be phished — but it lives on the device it was created on, so losing that device means falling back to another method. Password plus an authenticator app is the supported combination today.

#03Multi-factor authentication by plan

The policy is risk-based rather than one rule for everyone.

Who must turn on multi-factor authentication, and when.
WhoRequirement
Paid, trial, Institutional Annual and Enterprise Workspace OwnersMandatory before the workspace can be used. Password plus an authenticator app is the baseline. Where the institution federates identity, single sign-on carries the requirement instead and Academyship never enrols a second factor of its own.
Community Workspace OwnersOffered during activation. You may wait up to 72 hours, and the nine actions listed below stay locked until it is on.
Invited staffSet by the policy of the institution that invited you, not by any plan you use elsewhere. On every paid plan it is required, so you set it up during acceptance. On Community it is optional with no deadline: it is offered and strongly recommended, and the owner can require it for the whole workspace from the Setup Centre security task.

Academyship records the method you chose and when you turned it on. It never stores the shared secret, the codes you type, or your recovery codes in readable form.

#04The Community 72-hour deferral

If you are a Community owner and choose to wait, you are shown exactly what that costs before you confirm, and you must acknowledge it explicitly. A banner then stays visible for as long as the window is running, showing how many hours are left.

Locked until you turn it on

The line is drawn around anything that puts real people into the workspace, sends information out of it, or hands out lasting power. Exploring the product, using clearly labelled sample data and confirming your own settings are all unaffected.

The nine actions locked during the deferral window.
ActionWhy it waits
Inviting any staff memberAn unprotected account must not be able to hand out access to student records.
Importing real institution or people dataA real import puts identifiable people into the workspace. Sample data is unaffected.
Exports and external communicationsThis is the path data actually leaves by, including bulk email and SMS to families.
Certificates, signatures and formal submissionsThese are valid outside Academyship and are very hard to withdraw once issued.
API keys and integrationsKeys keep working after a password change, so they are how an intruder stays in.
Granting privileged rolesCreating a second administrator is how an intruder keeps access.
Opening employee filesEmployment records hold home addresses, emergency contacts and payroll detail. They are the most sensitive personal data in the workspace and the least noticed if read.
Ownership and security changesOwnership is the strongest permission Academyship grants, and switching this protection off is the first thing an intruder tries.
Destructive bulk actionsMass deletion is the hardest action of all to undo.

Still available — everything you need to set up

  • Explore every section included in your plan
  • Use clearly labelled sample data, and remove it in one action
  • Confirm your institution essentials, calendar and academic structure
  • Choose the sections your team sees first
  • Add records yourself, one at a time

What happens at 72 hours. You are asked to turn it on before using the areas above. Nothing you have set up is undone by waiting. Turning it on takes about a minute if you already have an authenticator app, or one to three minutes the first time including installing one. It unlocks everything immediately and returns you to whatever you were trying to do — you never repeat the terms or the workspace setup.

#05Recovery codes

When you turn it on, Academyship shows ten single-use recovery codes once. Store them somewhere safe and separate from the device holding your authenticator — a password manager or a locked drawer, not the same phone.

Academyship stores only a hash of each code, so they cannot be shown to you again. If you lose them, you generate a new set. Security questions are not used anywhere in Academyship: they are guessable, searchable and shared between sites.

How long activation and invitation links stay valid.
Link typeValid forReminderRules
Owner activation72 hoursOne reminder at 24 hours, leaving 48 hoursSingle use. Requesting a new link immediately invalidates the previous unused one.
Staff invitation7 daysNoneSingle use and unique to one person. Resending invalidates the previous link.

Email scanners cannot spend your link. Opening the page does not consume the link. It is only used when you take an explicit action on the page, so a corporate security scanner that follows links cannot burn your activation for you.

If a link does expire, nothing is lost: your institution details and workspace reservation stay saved under your request reference, and you never re-enter the pricing form.

#07Transferring ownership

Use this route while the current owner is still available. The successor has to act too — ownership cannot simply be handed over.

  1. The current owner opens Security & ownership from the Setup Centre or the user menu.
  2. They re-authenticate with MFA. Recent proof of identity is required before any ownership action.
  3. They choose a successor — an existing eligible administrator, or a new person they invite.
  4. The successor verifies their institutional email address.
  5. The successor accepts the current terms — the Terms of Service, the Acceptable Use Policy and the Privacy Policy — and creates their own acceptance record, in their own name, for the document versions current on that day.
  6. The successor turns on multi-factor authentication. Ownership cannot be held without it.
  7. The current owner confirms. Both people and the institution’s recovery contact are notified, the old owner’s sessions and recovery methods are revoked or downgraded, and the whole transfer is written to the audit trail.

Set up owner continuity before you need it. The Setup Centre includes an Owner continuity task that asks you to nominate and verify an institutional recovery contact or backup administrator. It takes about five minutes and is the single most effective way to avoid a slow recovery later.

#08When the owner has left

If nobody can sign in as the owner, the institutional recovery route applies. It verifies the institution, not just the person asking.

Why this is deliberately slower. Access to a departed colleague’s mailbox is not proof of authority. If support could transfer ownership on that basis alone, anyone who inherited that inbox could take an institution’s entire student record system. Academyship will not transfer ownership because somebody can read the old owner’s email.

  1. Select “The previous owner has left” from the sign-in support screen, the expired-link screen or Security & ownership.
  2. Academyship verifies the institutional domain and collects an authorised recovery request.
  3. You provide appropriate evidence — a written request from an authorised executive, board member or IT contact; confirmation the previous owner has left; control of the verified email domain; and a contract or ABN match. Never security questions.
  4. Academyship notifies the previous owner and every existing privileged administrator on all safe channels.
  5. A person reviews the case and the workspace on record is contacted before anything moves, unless an urgent security incident requires faster revocation.
  6. A trained Academyship reviewer approves or rejects, recording the reason and the evidence relied on.
  7. You verify your email, create secure authentication and turn it on in MFA, then separately accept the current terms.
  8. The departed owner’s sessions, tokens and recovery methods are revoked, and the immutable audit trail is preserved unchanged.

Recovery needs no account and no sign-in — that is the point of it. Voluntary transfer is faster, and needs the current owner to be able to sign in.

There is one set of documents — the Terms of Service, the Acceptable Use Policy and the Privacy Policy — and the Terms bind both the institution and every individual user under its account. What differs is whose name an acceptance is recorded in, and on whose authority. These three records are deliberately kept apart, and confusing them is a common and consequential mistake.

The three legal records and what happens to each on an ownership transfer.
RecordBelongs toWhat happens on transfer
Historical individual acceptanceThe person who accepted itKept unchanged as evidence of what that person accepted at that time. Never reassigned to the successor.
Current successor acceptanceThe new ownerA brand-new record of the same Terms, created by the successor in their own name, for the document versions current on their day.
Order Form or service agreementThe institutionUnaffected. The commercial contract belongs to the institution, not to whoever holds the owner role.

What this means for invited staff. Staff accept the same Terms of Service and Acceptable Use Policy, and acknowledge the same Privacy Policy, as individual users — there is no separate set of user terms. Each acceptance is recorded in the person’s own name. They are never asked to accept the institution’s commercial agreement, because it is not theirs to accept.

#10Keep reading

These four guides cover the whole onboarding journey.