Owner assignment uses
organisation.owners.manage, separate from member management. An owner must be transferred or removed through the organisation operation before ordinary membership removal.
Invitations expose no workspace data until the one-time token is accepted by the invited email address.