cmailHelp centre Sign in

Manager handbook

Operate the mail environment safely

A task-oriented map of the Management centre, with checks for identity, shared mailboxes, mail flow, privacy, and offboarding.

Manager access is required for changes.

This guide is readable by everyone, but the Management centre and its actions are enforced on the server for accounts with the Manager role.

Use the Management centre as the control plane

The Overview page surfaces required configuration, optional capabilities, recent activity, and directory visibility. Treat red or action-needed checks as deployment blockers. Configuration files and Cloudflare secrets remain the infrastructure control plane; the in-app Settings page explains their current effective state without revealing secret values.

PeopleAccount lifecycle, sign-in provider, role, personal mailbox.
MailboxesShared addresses, delivery status, and mailbox delegation.
OrganisationLayers, units, roles, positions, and public visibility.
Mail traceInbound and outbound delivery diagnostics.
Usage policyPublish acknowledgement text and track the active version.
Audit logReview security and administrative events.

Onboard a person

  1. Create the person with the exact Google or Microsoft sign-in email.
  2. Use Standard unless management access is required, and provision a personal mailbox when the person needs an individual organisational address.
  3. Select Send invitation now, or use Send invitation afterward. This creates a hashed, single-use enrolment token that expires after 72 hours.
  4. Grant shared mailbox access separately, using the least capable level that meets the role.
  5. Ask the person to use the newest invitation with the matching Google or Microsoft UserInfo address, accept any published policy, and verify their mailbox and From addresses.

A newly created account is pending and has no sign-in identity until its invitation succeeds; email alone never authorises first sign-in. Resending rotates the token immediately, so only the newest link works. An identity already enrolled to another account is rejected instead of being reassigned. Paused blocks sign-in and revokes active sessions while retaining data. Offboarded is the durable end state.

Create and delegate a shared mailbox

  1. Open Mailboxes and create a Shared mailbox using a functional local part such as support or accounts.
  2. Confirm the resulting address and display name before routing external mail to it.
  3. Open Mailbox delegation and grant Read, Send as, or Full access.
  4. Have each delegate verify the mailbox appears and that unavailable actions match their access level.
  5. Send a controlled inbound, internal, reply, and external test before announcing the address.
Least privilege

Read is observation only. Send as includes reading and sending from the shared identity. Full access adds shared folder, star, archive, trash, and restore control. These are bundled cmail access levels.

Disabling a mailbox removes it from user navigation and stops sending and new inbound delivery. Existing stored data is retained. Remove obsolete delegate access before repurposing an address.

Diagnose mail without exposing content

Use Mail trace to follow direction, sender/recipient envelope metadata, status, provider response, and authentication results. Use Audit log to identify administrative changes. Keep ticket notes free of message bodies, OAuth data, push endpoints, and credentials.

  • Confirm the mailbox is active and the person has the expected assignment.
  • Check inbound routing and recipient status for missing received mail.
  • Check the selected outbound provider, verified sender domain, and trace status for failed sends.
  • Use the operations and security checklists in the source repository for backups, rotation, and incident handling.

Publish directory data by exception

The public organisation directory has two gates: the global directory switch and the position's Public visibility setting. A public position can expose only occupant name, position title, and work email. All other account, reporting, role, permission, and personal data stays internal.

  1. Build layers, units, and roles without enabling public output.
  2. Create positions as Internal and review their work email and title.
  3. Mark only approved positions Public.
  4. Enable the global directory switch only after reviewing the public preview.

Change access or offboard safely

  1. Pause the account immediately when access must stop; this blocks sign-in and revokes sessions.
  2. Transfer operational ownership and review every shared mailbox assignment.
  3. Remove the person from public positions or replace the published occupant details.
  4. Preserve mail according to policy and legal requirements; do not delete storage ad hoc.
  5. Offboard the account when the transition is complete, then review Audit log.
Enterprise-grade email management, simplified for small organisations and for geographically and managerially dispersed groups. Compliant email · open source under the MIT License