Skip to content

Ownership transfer & step-up MFA

The Account Owner holds ultimate authority over an account. When responsibilities change, the current owner can transfer ownership to another member. This page covers that transfer and the step-up MFA that protects it and a few other sensitive actions.

Some actions are sensitive enough that DASH asks you to prove it is really you right now, even though you are already signed in. You enter a current authenticator code, and DASH mints a short-lived authorisation that is valid for 10 minutes and can be used once.

Step-up MFA is required for:

  • Starting an account-ownership transfer.
  • Cancelling a pending ownership transfer.
  • Promoting another user to the Admin role.

Demoting an Admin does not require step-up. Each sensitive action needs its own fresh code — one authorisation covers one action.

Screenshot pendingThe step-up MFA prompt shown before a sensitive action
  1. As the current owner, open Account and start an ownership transfer.
  2. Select the recipient from the list of active members.
  3. Enter your authenticator code when prompted (step-up MFA).
  4. DASH emails the recipient a confirmation link.
  1. The recipient opens the email and selects the confirmation link. No step-up code is needed from them — clicking the emailed link is proof enough that they control that inbox.
  2. On confirmation, ownership passes to the recipient. You keep an Admin membership (unless it is reassigned separately), so you do not lose your access.

An expired or already-used confirmation link is rejected with a clear message; start the transfer again to issue a fresh link.

Before the recipient confirms, you can cancel the transfer. Cancellation is also a sensitive action and requires a fresh authenticator code.

Initiation, cancellation and confirmation are all recorded in the Audit log.