Documentation
ACCESS / PEOPLE

Teams and private access

Invite people, assign workspace roles, and grant private mailbox access separately.

Invite a teammate

Owners and admins can open Settings → Team, enter the person’s name and email address, and choose an admin or member role. Invitations expire and are bound to the invited email address. Pending invitations can be revoked before acceptance.

Workspace roles

RoleWorkspace configurationBilling and domainsShared mailboxes
OwnerFull controlFull controlRead and send
AdminManage configurationManageRead and send
MemberLimitedNoRead and send

Workspace role does not by itself grant private mailbox content access.

Grant private mailbox access

The owner of a private mailbox can open its member list and grant a teammate access. Each grant controls whether that person can also send from the mailbox. Revoking the grant removes access without removing the person from the workspace.

API keys and agents

Keys are also permissioned identities. Give each integration the smallest scope set it needs, and revoke a key when its workload is retired. Do not share a broad personal key across unrelated services.