Shared Mailboxes and Delegation
A team address like support@ or hello@ is usually worked by more than one person. This guide teaches you exactly who can read and send from a mailbox in Backbuild Mail today, the ways to run a team address now, how access is governed and audited, and how to give every member an address automatically. After this page you will be able to set up a team address that works, and answer an access review precisely.
Who Can Read and Send From a Mailbox
After this section you will know who has access to any mailbox. Access to a mailbox is deny-by-default. Each mailbox has exactly one owner, and only these people can open it:
- The owner. The person who owns a mailbox reads it, sends from it, organizes it, and can delete it.
- The owner of a virtual worker, for the worker's inbox. A virtual worker's inbox is owned by the worker, and whoever owns the worker holds the owner's rights on it. That is how a person supervises the mail a worker handles. See Virtual Worker Inboxes.
- A delegate. The access model also recognizes delegates: a teammate given read access (view the mail) or write access (also send as the address and organize it, but never delete it or change who has access). A mailbox delegated to you appears in your mailbox switcher under Other inboxes, tagged Read only when you can only read it.
The app does not yet have a control for an owner to delegate a mailbox to a teammate, so today a mailbox is read by its owner, and a worker's inbox by the worker's owner. Sharing a worker with a colleague does not give that colleague the worker's mail.
Can several people work one support@ inbox today? Not by delegating the mailbox in the app yet. The patterns below are how teams run a shared address now.
Ways to Run a Team Address Today
After this section you will pick the setup that fits your team.
- Give the address to a virtual worker. Assign support@ to a Backbuild Virtual Worker that reads incoming mail and drafts replies for a person to review. The worker's owner reads the inbox, from the switcher or the worker's Email tab, and stays in control of what is sent.
- Work customer requests in the help desk. When several people need to answer customers together, with assignments, internal notes, and service-level targets, run the work in the Backbuild Help Desk. Customers file tickets through your support channel, and the whole team works the queue.
- One owner, one address. For a small team, one person owns the address and hands follow-up to teammates in Backbuild Chat or as help desk tickets.
Do I pay a seat for a team address? No. A team address is a mailbox, not a separately licensed user account, so there is no per-seat charge for the address itself. Each mailbox holds up to 1 GB of mail. See the pricing page for what each plan includes.
Mailbox, Alias, or Catch-All
After this section you will know which tool fits which need. These are often confused.
- A mailbox is a real inbox with its own address, folders, and labels.
- An alias is an additional address that delivers into an existing mailbox. Backbuild Mail does not yet let you add an alias.
- A catch-all gathers mail sent to any address at your domain. Backbuild Mail does not yet let you set one up: mail to an address at your domain that has no mailbox is returned to the sender as undeliverable.
Live, on Every Device
After this section you will understand what everyone with access sees. A mailbox is one live object shared by everyone who can open it. When anyone with access reads a message, stars it, changes a label, moves it, or replies, the change appears for everyone at once, on every device they use, so a worker's owner and the worker never disagree about what has been handled.
Govern Who Can Do What
After this section you will be able to answer an access review.
- Deny by default: only the people listed above can see or act on a mailbox, and only to the extent described.
- Owner controls: only a mailbox's owner can delete it, and an inbox a virtual worker is using cannot be deleted.
- Organization-scoped: a mailbox is never exposed across organizations, and a mailbox you cannot open is reported as not found, so its existence is never revealed.
- Attributable and audited: every action on a mailbox, sending, moving, labeling, deleting, and every change of a mailbox's owner, is recorded in an append-only audit trail attributed to the person who did it, so you always know who replied or changed what.
Who exactly can access a mailbox, and is it audited? Its owner, and for a virtual worker's inbox the worker's owner, all within your organization. Every write is audit-logged with the acting person, so an access review has a complete, attributable trail.
Auto-Provision Mailboxes for Members
After this section admins will be able to hand the whole team addresses without creating each one by hand. On a verified domain, open the domain in Settings, Email Domains, and choose Manage auto-provisioning rules. A rule gives an inbox on that domain to all members, or to members by role, department, or group. Preview a rule to see who would receive a mailbox, then provision now to create the missing ones. A member who matches a rule and has no mailbox yet receives it the first time they open Email, with no manual step for an admin. Managing domains is covered in Sending Domains and DNS Verification.
Related Guides
- Mailboxes, Inbox, and Reading: the mailbox switcher, virtual worker inboxes, and how mail is stored and protected.
- Sending Domains and DNS Verification: verify the domain that mailboxes live on.
- Roles and Permissions: how organization roles and permissions work across the workspace.