Inviting the client's owner
Why a sponsored client workspace cannot publish until somebody at the client is an owner, the two ways to invite one, and how key sharing and revocation work.
On this page
A client workspace cannot publish a survey until somebody at the client is an owner. This is the one rule the practitioner setup adds, and it exists to protect the client rather than to police you.
Why publishing waits
The key that decrypts a workspace's results is held by its people, not by us. If you are the only person holding a client's key, then when the engagement ends the client has a workspace full of ciphertext and no way in. They paid for those results and they would lose them.
So: draft, author, import questions, invite recipients, set everything up. All of that works with only you present. Publish is where an owner from the client becomes a requirement, because publish is the moment after which real answers exist.
If you try before then, the wizard says so and links you straight to the invite.
Inviting one
Go to Admin → Users in the client's workspace. The Engagement access card at the top has the form.
- Enter their emailthe person who will own this at the client. Someone in HR, People or Legal, usually; the person who would still be there after you leave.
- Invite ownerwhat happens next depends on whether they already have an InviziPoll account.
- They acceptif they were sent an invitation, they set a password and become an owner. If they already had an account, they are an owner immediately.
- Share the keyonce they are in, your browser wraps the workspace key to them. Until that happens their row says they are waiting for a key.
An owner who already has their own InviziPoll workspace keeps it. Inviting a client's Head of People does not move them out of their own company's workspace; they gain this one alongside it, and switch between them.
What the client's owner can do
Everything an owner can do in any workspace: run surveys, read aggregate results, manage people, take over billing, and end your access. That last one is the point. Their control over the engagement should not depend on your goodwill.
Ending access
Either side can end your access from Admin → Users. Doing so revokes the membership and deletes your stored copy of the workspace key, so the next request is refused and the next key fetch finds nothing.
It cannot reach into a browser that has already unwrapped the key. That is the same honest limit removing any collaborator has always had, in this product and in every other one that does client-side encryption. What it does guarantee is that nothing new is decryptable and no new session gets in.
Who is who on the roster
The Engagement access card labels each person by where their access came from:
- Consultant - you and anyone at your firm, added under the engagement. A client's directory sync will never add or remove these.
- Client - their own people, whether they signed up here or were invited.
- Client directory - provisioned by the client's identity provider.
That last distinction matters to a client's IT team: a consultant's access is deliberately outside their automated provisioning, so it is visible on this page rather than invisible in a sync.