ai-screeninghr-techrecruiting

Owner, Admin or Member: Choosing Access Levels for Your Hiring Team

HireQwik September 18, 2026 10 min read

For about two months this year, our own Team Management screen gave customers an instruction they could not follow. Under the invite form it said, more or less, “promote them to Admin from the row above after they sign up.” There was no such control in the row above. The person who created the workspace was admin forever, and every person they invited was a member forever. One HR team put it to us without any softening: there was “no option to give an admin role.”

That was fixed on July 13, 2026. But the more useful thing to come out of it was a conversation we kept having with TA leads afterwards, which was not “how do I promote someone” but “who should I promote at all?” This post is the answer we ended up giving, along with exactly what each level can and cannot do.

The three levels in one paragraph each

Owner. The account holder the workspace belongs to. The Owner sees every role, every candidate and every setting, and carries an Owner badge on the team list. Nobody, including another admin, can demote or remove them. There is exactly one.

Admin. Sees every role in the organisation by default and runs the workspace: invites people, changes their level, removes them, decides which recruiter owns which job description, and controls workspace-wide settings such as Slack or Microsoft Teams notifications and any ATS connection. An admin who is also hiring can narrow their own interview list to just their roles with a My roles toggle.

Member. The day-to-day recruiter level. A member works the roles they own, plus any role nobody has claimed yet. Their inbox, interview list, shortlist and Excel exports are all filtered to that set, so their screen shows their hiring and not their colleagues’. Members can see workspace settings such as notifications but cannot edit them.

Screen by screen: what each level can reach

Descriptions of access levels tend to stay abstract, so here is the same information laid out against the actual screens a recruiter uses in a week.

Screen or actionOwnerAdminMember
Inbox of new applicantsAll rolesAll rolesOwn roles plus unassigned
Interview listAll rolesAll roles, or My rolesOwn roles plus unassigned
Shortlist runsAll rolesAll rolesOwn roles plus unassigned
Excel exportEverything visibleFollows the current viewOwn roles plus unassigned
Invite, remove, change levelsYesYesNo
Assign role ownersYesYesNo
Slack or Teams alert settingsEditEditView only
ATS connectionEditEditNo

The pattern is worth noticing. Members are limited in what they see, while admins are distinguished by what they can change. That split is why promotion is a bigger decision than it first appears: it widens both at once.

What changes when you promote someone

Promotion is not cosmetic. The moment a member becomes an admin, the filter on their work comes off. Their interview list goes from “my three roles” to “all fourteen roles in the company.” Their export includes every candidate. They can move roles between colleagues and change other people’s levels.

That is exactly what you want for someone accountable for the whole drive, and exactly what you do not want for someone who simply wants to see one extra role. For the second case, the right move is to make them the owner of that role, not an admin of the workspace.

A small implementation detail worth knowing: level changes apply on our servers instantly, because every request re-checks the person’s level rather than trusting what their browser remembers. What lags is the menu. The newly promoted admin sees admin screens after their next reload or login, the same way most workplace tools behave.

How many admins does a hiring team need?

After watching a number of teams set this up, our honest recommendation is two, and here is the reasoning rather than just the number.

  • One admin is fragile. If the only admin is on leave in the middle of May, nobody can reassign a role, invite the contract recruiter who starts Monday, or fix a notification channel. Campus season does not wait for someone to come back.
  • Five admins is no filter at all. Every admin sees everything. A team where everyone is an admin has quietly switched off the per-role views that make a shared workspace usable, and is back to scrolling past other people’s candidates.
  • Two gives cover without noise. Typically that is the TA lead plus one senior recruiter or HR operations person. The account owner is often one of the two.

There are sensible exceptions. A three-person team where everyone genuinely covers every role can reasonably make everyone an admin. A large team split across business units might want one admin per unit. The test is simple: does this person need to change the workspace, or just work in it?

A decision table for common team shapes

Team shapeSuggested setup
Solo recruiter plus a founder who reviewsFounder as Owner, recruiter as Admin
TA lead with 3 to 6 recruitersTA lead and one senior recruiter as Admins, rest as Members
Campus drive with temporary coordinatorsPermanent team as Admins or Members, coordinators as Members owning only the campus roles
Hiring manager who only reviews shortlistsOften no seat needed; share the scorecard instead

That last row surprises people. A hiring manager who only needs to read a shortlist does not need an account at all. A shared scorecard gives them the verdict, scores and transcript for a specific candidate without adding another person to the workspace.

A worked example: a seven-person campus team

Consider a fairly typical setup for a company running campus hiring across three regions, plus lateral hiring for a few technical roles.

  • Head of TA. Accountable for every number the leadership team sees. Set as the Owner, since the workspace was created on their account.
  • HR operations manager. Handles the team list, onboarding of temporary staff and the Slack channel. Set as Admin, which gives the team its second admin.
  • Three regional campus recruiters. Each runs the trainee roles for one region. Set as Members, each owning only their region’s job descriptions.
  • One lateral tech recruiter. Owns the four experienced engineering roles. Set as a Member.
  • One temporary coordinator for the April to June peak. Helps the northern region with interview follow-ups. Set as a Member owning only the northern campus role, and removed in July.

In this shape, each regional recruiter opens the interview list in the morning and sees one region. The tech recruiter never scrolls through trainee candidates. The Head of TA sees all of it and uses My roles on the rare day they are hiring directly. And if the HR operations manager is on leave, the Head of TA can still invite, reassign and fix settings, and vice versa.

What this team deliberately did not do is make the three regional recruiters admins so they could “cover for each other.” Covering is an ownership question, not a level question: moving a role to a colleague for two weeks takes one change on the Role assignments card and does not widen anyone’s access to the rest of the company.

Demoting someone without a scene

Demotions happen for ordinary reasons. A senior recruiter moves to a different business unit, a project lead’s temporary admin rights were only ever meant for one drive, or a team simply has more admins than it needs after a reorganisation. None of it needs to be awkward if you do it in a sensible order.

  1. Make sure the remaining admin count is at least two after the change. If it would drop to one, promote the replacement first.
  2. Check the roles they own. A demoted admin keeps ownership of their job descriptions, so their day-to-day work does not change. Only the company-wide view and the management controls go away.
  3. Tell them before you click. Their interview list will shrink the next time they reload. A one-line message saves a confused support question.
  4. Let a different admin make the change. You cannot change your own level, so if you are the one stepping down, ask a colleague.

The guards that stop a workspace locking itself out

The failure we were most worried about when building level changes was not a stranger getting in. It was a team accidentally removing its own ability to manage itself. So there are four rules, and each one blocks a specific way that could happen.

  1. The Owner cannot be demoted or removed. Whatever else goes wrong, the account holder can always get back in and fix it.
  2. The last admin cannot be demoted or removed. If you are down to one admin, the system refuses. You promote someone first, then change the other person.
  3. Nobody can change their own level. The level dropdown is hidden on your own row. A change always takes a second admin, the same thinking as separation of duties in any access-controlled system.
  4. Removing an admin counts as demoting them. It goes through the same checks, so you cannot sidestep the last-admin rule by deleting instead of demoting.

During code review we also caught a subtle way around rule three: an internal ID written with different capital letters could look like a different person while pointing to the same account. It was fixed before release. It is a small thing, but it is the kind of detail that decides whether “you cannot promote yourself” is actually true.

Invites: choose the level before they arrive

The invite form has a level picker, and it is worth using deliberately rather than inviting everyone as a member and sorting it out later. Pending invites show their level on the team list, so a TA lead can see at a glance that the new senior recruiter is coming in as an admin and the four campus coordinators as members.

If you pick the wrong level on a pending invite, send it again with the right one. The level updates in place and the link already sitting in the person’s inbox keeps working. You do not have to ask anyone to ignore the first email.

When someone leaves the company

Removing a departing employee is the one level change that has a knock-on effect on roles, and it catches people out. Job descriptions they owned do not automatically pass to anyone. A role that still points at a removed account is not treated as unassigned, so it disappears from every member’s view and only admins can see it until someone new is given it.

So the safe order is: reassign their roles, have the new owners confirm they can see them, then remove the account. We walk through that sequence step by step in handing over a recruiter’s roles mid-drive. If the person leaving was also an admin, check the admin count at the same time: if they are the only admin left, the last-admin rule will refuse the removal until someone else is promoted.

Setting levels before a hiring season starts

A short checklist we give teams in the week before a big drive:

  1. Open Team Management and count admins. If it is one, promote a second. If it is more than three, ask whether each one really needs to change the workspace.
  2. Remove anyone who has left. A seat for a former employee is both clutter and a data risk.
  3. Invite temporary coordinators as members, and give them ownership of only the roles they will run.
  4. Check that every open job description has an owner. A role with no owner is visible to every member, which usually means nobody is really watching it. We cover role ownership across a team in more depth in splitting AI screening by role.
  5. Confirm who controls the workspace-wide settings, notifications in particular, since only admins can change them.

None of this is complicated, but it is much easier to do on a quiet Tuesday than on the morning 1,200 applications land. If you want to walk through the setup with your own team structure, book a demo and we will set the levels with you on the call.

Frequently asked questions

How many admins should a recruiting team have in an AI screening tool?

Usually two. One admin is a single point of failure when that person is on leave, and more than two or three tends to erase the per-role filtering that keeps each recruiter's view manageable. The account owner counts as one of them.

Can I invite someone straight in as an admin?

Yes. The invite form in HireQwik has a level picker, so a new teammate can join as an admin or a member. If the invite is still pending, sending it again with a different level updates it in place and the link already in their inbox keeps working.

What is the difference between the Owner and an Admin?

An Owner is the account holder the workspace belongs to. They have everything an admin has, but they can never be demoted or removed by anyone. Admins can be promoted, demoted and removed by other admins, as long as at least one admin always remains.

See your own candidates screened

Book a 30-minute demo. Bring a live JD and we'll screen against it, then start with a pilot on your own candidates before committing to anything.