Shared mailboxes

Team inboxes that several people work in, how much each member may do, read state, and people sharing one of their own folders.

A shared mailbox is a team’s address, such as support@example.com or invoices@example.com, that several people work in together. Each member sees it in their own mail app, beside their own mailbox, and sees what the others do in it: a message filed by one is filed for everybody.

The examples use the vsx shell function from the Quick start.

Making one

On the console, open People and choose Add a shared mailbox. Give its address, its name and the people who work in it. From the command line:

vsx admin shared add support@example.com --name Support --member bob@example.com --member cy@example.com --access organise

A shared mailbox is an account nobody signs in to:

  • It has no password and cannot be given one, an app password, a second step or an invitation. Every way of signing in refuses it.
  • It takes no seat in the licence.
  • Its mail, its quota and any legal hold are its own. What members delete from it under a legal hold is kept, as a person’s would be.

Members

Each member works in it at one of three levels, and may also send from it:

ConsoleCommandA member may
ReadreadRead everything, and change nothing, not even what is read.
Read and organiseorganiseAlso flag, file, mark read and delete messages.
Full: folders toofullAlso make, rename and remove folders.
Send as it--send-asSend from its address as if it had sent the message.
Send on its behalf--send-on-behalfSend from its address, with the member named as the sender.

On the console, open the shared mailbox from People and choose Change… under Members. From the command line:

vsx admin shared show support@example.com
vsx admin shared member support@example.com dan@example.com organise --send-as
vsx admin shared unmember support@example.com dan@example.com

A member is a person in the same organisation: not a group, an alias, a room or another shared mailbox. A member taken off, or given less, stops at their next command.

Where members find it

  • Over IMAP, its folders are under Other Users/support@example.com/.
  • Over JMAP, it is another account in the member’s session.

A member’s change is made in the shared mailbox itself, so every other member’s app picks it up at its next sync. Each change is recorded in the audit log under the member who made it.

Read state

Whether a message is read is the team’s by default: what one member reads is read for everybody, which is what a team inbox usually wants. An administrator can make it each member’s own instead, so what one member reads stays unread for the rest:

vsx admin shared read-state support@example.com personal
vsx admin shared read-state support@example.com shared

On the console this is Read state on the shared mailbox’s page. Every other flag stays the team’s either way.

Sharing one folder

A person can share one of their own folders with a colleague, rather than their whole mailbox, from their mail app:

  • An IMAP app with a sharing or permissions dialog sets who may read the folder (SETACL), and takes it away again (DELETEACL).
  • A JMAP app shares a folder with a colleague (shareWith).

The colleague may read the folder, or read and organise it. They see that folder, under the person’s name, and nothing else of the mailbox: not other folders, not other messages by guessing their ids, not a search across the rest.

A folder is shared only with a person in the same organisation. Only its owner changes who it is shared with.

Being told

When a folder, calendar or address book is shared with somebody, changed or taken back, a JMAP app is told: the server keeps a share notification in that person’s account (RFC 9670), saying what was shared, whose it is and what they may now do. The app reads them with ShareNotification/get and ShareNotification/query, and the person dismisses one with ShareNotification/set. Nobody is told of a change they made themselves, and members of a group are not told of changes to what is shared with the group. The newest 500 are kept.

The organisation decides whether people may share folders at all with the runtime setting sharing.personal:

ValueWhat it means
allowedPeople may share their folders with anybody in the organisation.
off (the default)Nobody may. Every folder already shared stops being reachable at the colleague’s next command, and is kept for when sharing is allowed again.

Shared mailboxes are an administrator’s, and sharing.personal does not touch them.

IMAP rights

For apps that show IMAP’s access rights (RFC 4314), each level is these rights:

LevelRights
Readl r
Read and organisel r s w i t e
Fulll r s w i t e k x

The owner of a mailbox, or of a shared folder, holds every right, including a, which changes who it is shared with. No member holds a.

Over the API

RouteWhat it does
POST /api/v1/tenants/{tenant}/accounts with kind: sharedMake a shared mailbox, with its members.
GET /api/v1/tenants/{tenant}/accounts/{id}/membersIts members, each with access, sendAs and sendOnBehalf, its readState, and the version to save against.
PUT /api/v1/tenants/{tenant}/accounts/{id}/membersSave its members whole, against the version read, and optionally its readState.

Something unclear or out of date on this page? Tell us.