Centralizing admin ownership
Designed and launched a centralized ownership model that balanced enterprise governance requirements with user trust, enabling organizations to manage account ownership at scale without sacrificing the integrity of users' personal spaces.
Role
Led product design for a centralized ownership model spanning admin policy controls, end-user takeover flows, and offboarding experiences.
Team
Cross-functional partnership across Design, Product, Engineering, and Security.
Challenge
Enterprise customers needed stronger control over employee accounts to meet security, compliance, and offboarding requirements. At the same time, users relied on Bitwarden's promise of an independently owned personal vault. When centralized ownership policies were enabled, these expectations collided. Users lost access to personal data they believed they owned, while organizations worried former employees could regain access after leaving the company.
The result was ambiguity around who owned what, what administrators controlled, and what users could expect during major account transitions.
Discovery
This was a long standing issue at Bitwarden. A user's vault was always owned by the individual, even after that user was offboarded from an organization. From an admin's perspective, this created a perception of data loss: someone could leave the company and still walk away with full control over information that was created and used within the organization. Over time, this eroded trust in the product among enterprise customers who expected stronger guarantees around account governance.
Previously, offboarding relied entirely on trust. Admins had no reliable way to see what a departing user actually had in their vault, they had to trust that the user exported their work items correctly before leaving. There was no safety net if that didn't happen.
Research
I began with a competitive analysis to understand how other companies in the identity and password management space handled ownership transitions. From there, I ran interviews with admins and with selected organization users to see whether any proposed direction would be clear and trustworthy to both sides. Talking to both groups mattered because the tension in this problem was not just technical, it was about expectations. Admins needed confidence during offboarding. Users needed to feel their personal data was still respected.
A few findings shaped the direction more than anything else:
- Automation alone was not viable. Full automated transfer of vault items raised concerns with the security team, since silently moving user owned data into an org owned space without user action introduced risk.
- Admins wanted control over timing. Many had their own internal communication processes and needed a way to inform their users before any change took effect, rather than something that happened the moment a policy was enabled.
- Transparency mattered more than convenience. Users needed to know clearly what was happening to their data rather than have it resolved quietly in the background.
Secondary research
Bitwarden stood out as an outlier in this space. Where most competitors gave organizations some default level of control over employee accounts, Bitwarden gave full account control to the individual user, even when that user was a member of an enterprise org. This made the problem unusually acute for us, since we could not simply follow existing patterns from competitors. We had to design a model that introduced organizational control without abandoning the independent ownership Bitwarden had always promised.
Synthesis
Findings from the interviews and competitive research were brought together in a formal research read out with the broader team. Out of that synthesis, one idea rose to the top: transparency, one of Bitwarden's core product pillars, needed to guide the solution. Rather than resolving the ownership conflict automatically in the background, the right approach was to inform users directly and let them take action. This reframed the problem from "how do we transfer ownership" to "how do we make ownership legible to everyone involved."
“Quote coming soon”
“Quote coming soon”
Solution
I designed the admin facing policy controls as well as the new end user experience that appeared once the policy was turned on. The core mechanism was a new personal space called My Items, which is ultimately owned by the organization rather than the individual. When the policy is enabled, users are shown a takeover screen prompting them to review and transfer relevant items into this new space. Admins also have control over when their users are prompted, so they can align the rollout with their own internal communication timelines instead of having it forced on them the moment the policy is turned on.
This also changed offboarding directly. When an admin offboarded a user, the system would automatically create a collection labeled with that user's email address, containing all items from their My Items space. Rather than depending on the user to have exported their work correctly beforehand, the admin now had a ready made, organized view of exactly what the departing user had access to. From there, the admin could reassign items that were still needed or trash the ones that weren't, with no dependency on the user's cooperation.
Iterations
The first version of this concept relied on automatic transfer combined with a simple notification to the user after the fact. This did not hold up against security review or user trust concerns, since it removed the user's ability to act before their data moved. The second version changed this significantly. Users were required to either opt in and transfer their items to My Items, or leave the organization. If a user left, the admin retained the ability to revoke and restore access if needed, giving organizations a safety net without forcing an irreversible action on users.
Another point of iteration was around how much of the policy's behavior to expose visually. Early concepts tried to depict every action the policy could take as its own screen or state. I pushed back on this, since surfacing every single mechanic would have overwhelmed both admins and users rather than clarifying anything. The final design focused on the moments that mattered most for decision making, not a full inventory of every system behavior.
Results
Established a scalable foundation for enterprise account governance without compromising user trust. The feature launched to select enterprise customers through a feature flagged rollout before expanding to general availability. This established clear boundaries between organization owned and user owned data while preserving an independent personal vault, something Bitwarden had never offered before at this level of clarity. It also gave organizations more confidence adopting centralized ownership policies for offboarding and compliance scenarios, and reduced ambiguity for both admins and users by creating a shared mental model around who owned what.
The automatic creation of a per user collection during offboarding removed the reliance on trust that had defined the old process. Admins no longer had to hope a user exported their items correctly, they had a clear, structured record they could act on immediately.
Reflection
If I were to start this over, I would reach out to admins earlier in the process. Their time is limited and scheduling those conversations took longer than expected, which slowed down validation of early concepts.
Next steps
Looking ahead, the placement of My Items in the navigation across clients needs to be revisited. Right now it does not visually read as clearly as an organization owned space, and refining that presentation will further reinforce the mental model this project was built to establish.