A hub has two roles, and most of what matters is in one sentence: members use the hub, admins manage it.
What members can do#
- See and add to the hub's shared albums
- Create their own albums in the hub, shared or private to them
- Delete photos they uploaded, unless an admin has switched that off for a particular album
- Leave the hub
Members can't invite people, remove people, or change the plan.
What admins can additionally do#
- Invite and remove members
- Invite people from outside the hub into a hub album
- Promote other members to admin
- Set what members can do in each album — downloading, sharing outside the hub, deleting their own uploads
- Move the hub between plans
One admin is also the billing admin, who handles payment. That person can't simply leave the hub — billing has to be handed to someone else first, or the hub deleted.
Inviting outsiders into a hub album is an admin decision for the same reason: photos added to a hub album use the hub's shared storage, which the billing admin pays for. Any member can create an album inside the hub, but bringing someone new into one goes through an admin. If you want to share an album with a friend outside the household, ask an admin — or make the album in your own personal storage instead, where it's entirely your call.
Every hub should have a second admin#
This is the part of the page worth acting on.
A hub with one admin depends entirely on that person: their phone, their email address, their availability. If they lose access, nobody can invite anyone, remove anyone, or manage the plan — and the family's photos sit in a space nobody can administer.
Promoting your partner takes seconds. Do it when you create the hub, not when you need it.
Keepr enforces the minimum version of this: the last admin can't leave without promoting someone first, because a hub with no admin can't be managed by anyone. But that's a floor, not a plan — it doesn't help if the single admin is unreachable rather than leaving deliberately.
What to do if that's already happened is covered in If something happens to the hub admin.
Per-album permissions#
Some controls are set per album rather than per person, so a hub can hold albums with different rules:
| Setting | What it controls |
|---|---|
| Member uploads | Whether members can add photos to that album |
| Member downloads | Whether members can download its photos |
| Member sharing | Whether members can share it outside the hub |
| Delete own uploads | Whether members can delete photos they added |
Defaults are permissive — a shared family album should behave like a shared family album. Tighten them where a particular album needs it rather than as a general posture.