Phone: 0 (552) 380 25 25  |  Weekdays 09:00–18:00 · Technical support 24/7

🇹🇷 TR

Digital Bridge Blog

Business Email & Documents

Shared Mailbox Management: Stop Sharing Passwords for info@ and accounts@

Shared mailbox management cannot rely on shared passwords. How to set up individual permissions, ownership and an audit trail for info@ and accounts@.

 · 7 min read  · Digital Bridge Engineering Team
Shared Mailbox Management: Stop Sharing Passwords for info@ and accounts@

Shared mailbox management means giving people access to team addresses such as info@ or accounts@ through their own identity rather than a shared password, giving every incoming email an owner and recording who did what. In a well-run shared mailbox, deleting is a separate permission, unanswered mail is visible and leavers lose access automatically.

This article looks at where shared mailbox problems come from, what they cost and how to fix them.

What really happens in shared mailboxes

Most shared addresses start the same way: someone creates info@, tells three colleagues the password and everyone adds it to their own mail client. Over time more people join, the password never changes and leavers are never removed. Three problems follow:

  • Ownerless email. Everyone assumes someone else has picked it up, and a customer's request for a quote sits unanswered for two days.
  • Duplicate or conflicting replies. Two people answer the same email with different prices or delivery dates.
  • Actions without a trace. A message has been deleted or filed in the wrong folder, and there is no way to find out who did it.

Password sharing is also a security gap. The shared password walks out of the door with every leaver, stays saved on personal devices, and a single colleague entering it on a phishing page hands the whole team's mailbox to an attacker. The other access points to close on leaving day are in our employee offboarding email access checklist.

The cost of an unmanaged shared mailbox

Shared mailbox problems tend to be dismissed as "communication hiccups", but there is measurable workload and risk behind them.

Volume alone is a burden. According to Microsoft's 2025 Work Trend Index special report, the average worker receives 117 emails a day, most of them skimmed in under a minute. In a shared mailbox where three people open and read the same message separately, that load multiplies.

According to the Verizon 2026 DBIR, the human element was present in 62% of breaches. (Verizon 2026 Data Breach Investigations Report)

Credentials are a separate risk. In Sophos' State of Identity Security 2026 survey, 71% of responding organisations said they had suffered at least one identity-related breach in the past year, and employees being tricked into handing over credentials was a factor in nearly 43% of incidents. A mailbox whose password several people know is the easiest target for exactly that scenario.

Payment fraud also tends to land in shared addresses. An attacker writes to accounts@ posing as a supplier; when nobody is clearly responsible for the mailbox, a "new bank details" email can be processed without anyone questioning it. We cover that scenario in our guide to bank detail change email fraud.

Six principles for shared mailbox management

  1. People, not passwords. Every employee should reach the shared mailbox with their own identity. The mailbox password should not be handed out at all, so that when someone leaves only their access is closed. Extended to every application, this principle becomes single sign-on (SSO).
  2. Split the permissions. "Has access to the mailbox" should not be a single right. Reading, replying, deleting and labelling should be granted separately, with deletion held by as few people as possible.
  3. Every email has an owner. Incoming mail should be assigned to a person, or someone should mark that they have taken it. The list of unassigned mail should be visible every day.
  4. Notes live with the message. "Called the customer, price confirmed on Wednesday" belongs on the email itself, not in a chat group.
  5. Keep an activity log. For every message you should see who opened it, who replied and who moved it.
  6. Tie access to the organisation. Grant shared mailbox access by department membership rather than person by person, and remove it automatically when someone moves to another department.

Who gets which permission?

RoleReadWrite/sendLabelDeleteQuarantine
Team memberYesYesYesNoNo
Team leadYesYesYesYesNo
Intern / temporary staffYesSubject to approvalNoNoNo
IT / security officerWhen neededNoNoNoYes

Treat the table as a starting point and adapt it to your workflow. What matters is that permissions follow roles rather than individuals, and that risky permissions are off by default for new assignments. For a version adapted to a documents@ mailbox that collects client paperwork, see accounting firm document management.

Five steps to better shared mailbox management

  1. Take an inventory. List every shared address, who uses it and how many people know its password.
  2. Name the owners. Give each shared mailbox a responsible manager who approves access requests.
  3. Write the role matrix. Fill in the table above for your own teams.
  4. Retire the password. On the day you move to individual access, change the old shared password and close all open sessions.
  5. Watch the first month. Track unassigned messages, average response time and permission requests, and simplify the matrix if needed.

Consider one more step for sensitive messages leaving shared mailboxes: routing quotes, payment confirmations and formal letters for approval before they are sent. We explain how in our article on the email approval workflow.

How we approach it at Digital Bridge

Getting shared mailboxes in order is more an organisational decision than a software setting, so we start by listening to your teams.

  • Current-state review: We list your shared addresses, how passwords are distributed and any leftover leaver accounts, then prioritise the risks. Password and access gaps are reported as part of our cyber security consultancy.
  • Role and permission design: We draw up a permission matrix that fits your departments. For mailboxes holding personal data, our data protection compliance team reviews retention and access rules against Türkiye's KVKK and, where relevant, the GDPR.
  • Process integration: If requests arriving in a shared mailbox need to flow into a CRM or service system, we plan the API integration side as well.
  • Written proposal: Scope, phases and cost are set out in writing; we do not push packaged solutions.

How shared mailboxes work in SmartMail

SmartMail, the business email product in our Smart360 family, manages shared and personal mailboxes in one web panel. Here is how it maps to the principles above:

  • No passwords handed out. Mailbox passwords are generated by the system, stored encrypted with AES-256-GCM and never distributed to staff. Everyone signs in with their own identity (SmartID).
  • Nine separate permissions. Each mailbox has individual permissions for viewing, writing/sending, deleting, labelling, quarantine, AI re-interpretation, AI chat, notes and flagging for attention. Delete and quarantine management are off by default for new assignments.
  • Assignment board and team notes. Incoming mail can be assigned to a person; team notes and attention flags let you ask a colleague to look at a message. Each message shows its activity history, and an audit log is kept.
  • Access tied to departments. When someone leaves a department their mailbox access is removed automatically, and a leaver's access to all Smart360 products is closed in one step. Sessions are listed with device details and can be ended remotely.
  • Order and speed. Distribution lists, per-mailbox signatures, conversation threading and bulk actions are built in. AI automatically classifies incoming mail as communication, invoice/payment, quote/tender, official correspondence, promotion or update, and summarises it.

A concrete example: a supplier invoice arrives in accounts@. SmartMail classifies it as invoice/payment, and attachment analysis reads the parties, due date, VAT and grand total from the PDF without anyone downloading it. The email is assigned to an accounts specialist, who adds the note "added to payment run" and saves the attachment to the accounts area in SmartFiles with one click. An intern can see the message but cannot delete it, and the message records who did what.

Next step

Do one thing this week: count how many people know the passwords of your shared addresses. If the answer is more than two, it is time to move to individual access. For the wider selection criteria, see our guide on how to choose a business email service; if you would like to try your shared mailboxes on SmartMail, write to us through our contact page.

Let us look at your case

Tell us about your process; after a needs analysis we send a written proposal with scope, phases and cost.

Request a Quote +90 552 380 25 25

Keep reading

Questions we hear most often

Frequently Asked Questions

What is the difference between a shared mailbox and a distribution list?

A distribution list copies incoming mail into each member's own mailbox; everyone works on their own copy and nobody can see who replied. A shared mailbox is a single mailbox the team works in together, with assignments and notes visible to all. For addresses where requests need tracking, a shared mailbox is the better fit.

How should a team split the email arriving in a shared mailbox?

The most reliable method is to assign every incoming email to one person, or have a team member mark it as taken. Unassigned messages should sit in a list everyone can see, with status and notes kept alongside the message. SmartMail provides an assignment board, team notes and an activity history on every message, so two people do not answer the same email and nothing is left without an owner.

Why is sharing a shared mailbox password risky?

A shared password makes it impossible to tell who did what, leaves with every departing employee, and one person falling for a phishing page exposes the whole mailbox. With individual access, only the relevant person's access is closed and the audit log actually means something.

How can I find out who deleted an email from a shared mailbox?

If your system keeps an activity history or audit log, you can see who opened, moved or deleted each message. Mailboxes used through a shared password usually have no such record, which is why deletion should be a separate permission on a system that logs activity.

How do data protection rules apply to shared mailboxes in Türkiye?

Correspondence with customers, staff and suppliers contains personal data. Türkiye's Personal Data Protection Law (KVKK), like the GDPR, expects access to be limited to what is needed, access to be traceable and leavers' access to be closed promptly. Individual permissions and an audit log make these obligations far easier to meet.

Have a different question? Ask Us

Talk to an Engineer

Tell us what you need to solve. We'll come back with a written proposal.