Members and roles
The owner invites participants, manages supported roles, and can disable an identity’s future access to the Circle.
A neutral explanation for every participant: which decisions the owner can make, what the role cannot do, and what an ownership change means for access to data.
A Circle has one owner identity. Its approved devices can perform administrative actions for that role.
The owner invites participants, manages supported roles, and can disable an identity’s future access to the Circle.
The owner manages regular invitations, guest links, and other supported ways to enter the Circle.
The owner changes the name and available Circle policies within the limits imposed by the server.
The owner can voluntarily transfer the role to another active full member.
Becoming the owner does not itself transfer chat keys or add that person to every existing conversation.
The new owner can read only messages whose keys are already available to their identity as a participant in that chat.
A role change does not extract data from participant devices or remotely reveal content they have stored.
The administrative role includes access to membership, roles, invites, devices, and other data needed to manage the Circle.
If the owner already belongs to a chat or receives its keys through normal membership rules, they see it as a chat participant—not because they are the owner.
These are separate powers, although one person may hold both.
Manages members, invitations, and product-level rules for one Circle.
Runs the infrastructure and Circles on the physical server, affecting availability, updates, backups, and technical logs.
The server stores encrypted content without user keys, while still seeing operational metadata needed for service operation.
A server administrator can recover ownership when the former owner has lost access. The action is explicitly recorded and shown to participants.
The method is always identified in the Circle system event.
The current owner signs a transfer to a selected active member.
A server administrator appoints an active member, creates a new profile on their current device, or issues a one-time recovery link to another person.
By default their identity becomes a regular member. If access is compromised, it can be disabled separately.
Every active owner and member, but not guests, receives an event naming the former and new owner, method, and time.
Practical tasks—creating a Circle, invitations, guest links, devices, and maintenance—live in a separate guide.