Skip to content

Mailbox access and teammates

Being a workspace user doesn’t automatically mean you can see every mailbox — access is granted per mailbox, per person, at one of five levels.

Role Can do
Owner Everything Admin can, plus delete the mailbox and read/rotate its IMAP/SMTP credentials
Admin Edit mailbox settings, auto-reply, signature, and custom folders; grant access up to Admin
Agent Read, reply, note, assign, and tag every conversation in the mailbox
Limited Agent Same as Agent, but only for conversations assigned to them
Read-only View only — no reply, note, assign, or tag

Workspace admins always have full access to every mailbox; this table is for everyone else. Manage grants under the mailbox’s Settings → Permissions tab, in the “Who can work in this mailbox” card.

The same Permissions tab has an “Invite someone to this mailbox” card — email address plus a role. What happens next depends on who they are:

  • Already a member of your workspace? Access is granted immediately. No email, nothing to accept — they’ll just see the mailbox next time they look.
  • Not a member yet (including someone from a different workspace entirely) — an email invitation goes out, and nothing is granted until they accept it. Invitations expire after 7 days; you can resend (which refreshes the token and the clock) or revoke one from the same card.

If you’re on the receiving end of one of these invites, it shows up as a badge on your account menu and a card on your own Profile page — but only the emailed link actually accepts it (that’s what proves the address is really yours). From your Profile you can resend it to yourself or decline; there’s no in-app “Accept” button.

Separate from mailbox access — this is under Settings → Users, and needs the right to edit users (workspace admins have it by default; it can also be delegated to a non-admin). Adding someone here sets their name, email, workspace role (User or Admin — those are the only two), and lets you check off initial mailbox access in the same dialog. A user’s page also has finer permission checkboxes — things like deleting conversations, editing saved replies, or editing tags — layered on top of the User/Admin role, for delegating specific admin-ish rights without making someone a full Admin.