How to give contractors limited access to team email
A runbook for giving freelancers and agencies access to team email: own accounts, only the mailboxes they need, 2FA, an end date and a clean offboarding.

On this page(11 sections)
- The principles
- Why shared passwords are the wrong answer
- Step 1: Define the scope in writing
- Step 2: Create an individual account
- Step 3: Grant only the mailboxes they need
- Step 4: Require two-factor authentication
- Step 5: Brief them on your rules
- Step 6: Review during the engagement
- Step 7: Offboard cleanly
- Agencies with several people
- Key takeaways
A freelance support agent to cover a busy season, an agency running your partnership outreach, a part-time bookkeeper who needs to see invoices: sooner or later, someone outside the company needs to work in your team email. The quick way is to share a password. The quick way is also how access lingers for years after the engagement ends.
This runbook covers how to give contractors exactly the access they need, for exactly as long as they need it, and how to take it back cleanly.
The principles
Four rules cover almost every situation:
- Their own account, never a shared password. Every person gets an individual login.
- Only the mailboxes they need. A support contractor needs the support mailbox, not billing or the founders' inboxes.
- Two-factor authentication required. No exceptions for "they're only here for a month."
- An end date from day one. Access is time-boxed and written down.
Everything below is how to put those rules into practice.
Why shared passwords are the wrong answer
Sharing the password to support@ is tempting because it takes ten seconds. The costs show up later:
- No accountability. You can't tell who sent a reply or changed a setting.
- No clean removal. Taking access away means changing the password for everyone who uses it, so people put it off.
- Weak security. Shared passwords get pasted into chat, saved in personal password managers, and rarely protected by two-factor authentication in a way that works for everyone.
- Hidden access. Passwords get passed along to the contractor's colleagues, and you never know.
Individual accounts with mailbox-level permissions solve all of these.
Step 1: Define the scope in writing
Before creating anything, write down:
Contractor access: [name / agency]
Purpose: [e.g. first-line support coverage, weekdays]
Mailboxes: [e.g. support@ only]
Level: [read only / reply / manage]
Start date: [date]
End date: [date] (review on: [date])
Internal owner: [name], responsible for access and removal
The internal owner is the most important line. Someone on your team is responsible for this access existing and for ending it.
Step 2: Create an individual account
Create an account for the contractor under your domain or as a guest, depending on your tool. A few choices to make:
- Naming. Some teams use a convention like
firstname.contractor@or a separate label in the user list, so contractors are easy to spot during reviews. - Sending identity. Decide whether they reply as themselves, as the team (for example "Support at [Company]") or both. For customer-facing work, replying under a first name with the team's sign-off is common.
- No admin rights. Contractors rarely need to change workspace settings, rules or other people's access.
Step 3: Grant only the mailboxes they need
This is where per-mailbox permissions earn their keep. Rather than giving access to the whole workspace, grant access to specific shared mailboxes.
| Contractor type | Typical mailbox access | Usually not needed |
|---|---|---|
| Support freelancer | support@ | billing@, sales@, personal inboxes |
| Outreach agency | partnerships@ or a dedicated outreach address | support@, billing@ |
| Bookkeeper | billing@ or invoices@ | support@, sales@ |
| Recruiter | jobs@ | Everything else |
If your tool supports read-only versus reply access, use the narrowest level that lets them do the job. In Koltrix, shared mailboxes have per-mailbox permissions, which makes this kind of scoping straightforward.
Step 4: Require two-factor authentication
Turn on 2FA for the contractor's account before they start working, not after. Walk them through it if needed; it takes a few minutes.
Contractors often work across many clients' systems, which makes them attractive targets for phishing. A stolen password with 2FA in place is a much smaller problem than one without.
Step 5: Brief them on your rules
Access without context leads to well-meant mistakes. Give contractors the same essentials you'd give a new hire, condensed:
- Which threads they handle and which they escalate.
- Tone, sign-off and anything they must never promise (refunds, discounts, dates).
- How to handle account-access or security requests (usually: escalate, don't act).
- Who to ask when unsure.
Step 6: Review during the engagement
For anything longer than a month, check in at the review date you set:
- Is the access still needed?
- Is the scope still right, or has the work changed?
- Are they using any connected apps or forwarding rules that weren't discussed?
Extend the end date deliberately if the engagement continues. Don't let it lapse into "permanent by default."
Step 7: Offboard cleanly
On the end date, or earlier if the engagement ends early:
- Remove their mailbox access and disable or delete their account
- Revoke any connected apps or AI assistants they authorized
- Check for and remove any forwarding rules they created
- Reassign any threads they owned, with a short handoff note
- If they replied under their own name, decide what happens to replies sent to their address (an alias to the shared mailbox for a while works well)
- Record the date access was removed
If the contractor worked under a shared password despite everything above, change that password now and tell everyone else who uses it.
Agencies with several people
When an agency works for you, it's tempting to give the agency one login. Resist it. Ask for the names of the people who will work in your mailboxes, and give each of them an account. When someone leaves the agency, you remove one account instead of wondering who still knows a shared password.
Key takeaways
- Give every contractor an individual account; never share a password.
- Grant only the mailboxes and permission level the work requires.
- Require 2FA from day one.
- Write down the scope, an internal owner and an end date before granting access.
- Offboard with a checklist that covers connected apps, forwarding rules and thread handoffs.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.
