Never share passwords
Shared passwords are a security failure and an audit failure. Use delegated access, shared mailboxes, or workspace admin tools that grant scoped permissions.
Your operations partner should access mail through official delegation — with permissions limited to what the workflow requires.
Scope permissions minimally
Inbox management typically requires read, send-as-delegate, and label or folder management — not account recovery, billing access, or admin privileges.
Review permission scopes during onboarding and revoke anything not required for documented workflows.
Document who can see what
Maintain a simple access register: who has access, to which systems, for what purpose, and when access was granted. Update it when scope changes.
Define offboarding before onboarding
Every access grant should have a documented revocation path. When engagement ends, permissions remove within an agreed SLA — not whenever someone remembers.
Confidentiality and escalation
NDAs and confidentiality terms should match the sensitivity of mail handled. Escalation rules define what never leaves your review — regardless of who has access.
Doxcta documents access and offboarding practices on our security page.