Co-owner & administrator oversight update - 6 October 2026
1. Two owners (full co-owner model)
•A company can now have a primary owner plus an optional second co-owner, so the property can be run when the primary owner has a day off.
•The second owner is recognised as a full co-owner across the property: the Wave board, Pulse, the employer dashboard and employee invites.
•A denormalized secondary_owner_email field is stamped on every owner-gated record (WaveSession, WaveRoom, WaveTeam, WaveRoomStage, WaveReport, CporScore, RpsScore) and the row-level security on those entities grants the co-owner equal create, read, update and delete access.
•Company registration accepts an optional second owner email, and the Organisations admin screen has a "Second owner (co-owner)" card to set or change it at any time.
•Ownership transfer automatically clears the secondary slot if the new primary owner was the co-owner (a user cannot hold both roles).
2. Administrator can view any property
•The platform administrator can open any organisation's live dashboards as if they were the owner, for full interactive troubleshooting access.
•The Organisations overview has a "View this property" card with buttons to open the Employer dashboard, Wave board or Pulse for the selected organisation.
•While viewing, a cyan banner reads "Viewing as administrator - full interactive access" with a one-click Exit back to Organisations.
•Writes made during an admin view are stamped with the property's owner email (not the admin), so the data stays owned by the organisation.
•The administrator bypasses all row-level security, so every record across the app is reachable for audit and repair.
3. Administrator access model
•The sole platform administrator is rena_nz@hotmail.com. Everyone else is role "user".
•User-role accounts are locked by row-level security to their own organisation's data; they cannot reach admin screens or other organisations.
•Code editing is a builder/dashboard action separate from the admin role, so no app user (even an admin-role account) can change the app's code.
•Admin-only surfaces include Organisations (every company), per-org Overview and Configuration tabs, the data-integrity audit and repair suite, and full interactive access to each property.