Ownership transfer & step-up MFA
The Account Owner holds ultimate authority over an account. When responsibilities change, the current owner can transfer ownership to another member. This page covers that transfer and the step-up MFA that protects it and a few other sensitive actions.
What is step-up MFA?
Section titled “What is step-up MFA?”Some actions are sensitive enough that DASH asks you to prove it is really you right now, even though you are already signed in. You enter a current authenticator code, and DASH mints a short-lived authorisation that is valid for 10 minutes and can be used once.
Step-up MFA is required for:
- Starting an account-ownership transfer.
- Cancelling a pending ownership transfer.
- Promoting another user to the Admin role.
Demoting an Admin does not require step-up. Each sensitive action needs its own fresh code — one authorisation covers one action.
Transfer ownership
Section titled “Transfer ownership”- As the current owner, open Account and start an ownership transfer.
- Select the recipient from the list of active members.
- Enter your authenticator code when prompted (step-up MFA).
- DASH emails the recipient a confirmation link.
The recipient confirms
Section titled “The recipient confirms”- The recipient opens the email and selects the confirmation link. No step-up code is needed from them — clicking the emailed link is proof enough that they control that inbox.
- On confirmation, ownership passes to the recipient. You keep an Admin membership (unless it is reassigned separately), so you do not lose your access.
An expired or already-used confirmation link is rejected with a clear message; start the transfer again to issue a fresh link.
Cancel a pending transfer
Section titled “Cancel a pending transfer”Before the recipient confirms, you can cancel the transfer. Cancellation is also a sensitive action and requires a fresh authenticator code.
Initiation, cancellation and confirmation are all recorded in the Audit log.