Working with a virtual assistant on your inbox: scope and etiquette
A virtual assistant can take hours of email off your day. How to decide what they handle, give access safely and agree rules for drafts, replies and escalation.

On this page(9 sections)
For a founder or an executive, email can quietly consume two hours a day. A virtual assistant (VA) is one of the quickest ways to get that time back: they sort the inbox, handle the routine, schedule meetings and draft replies for the rest.
It also puts someone else inside your most sensitive system. Done casually, delegation leads to shared passwords, unclear permissions and a mistake that goes out under your name. Done deliberately, it is one of the best-value changes you can make. This guide covers what to hand over, how to give access safely and the habits that keep the arrangement smooth.
The technical side of limited access is covered in giving contractors limited access to team email. This post is about the working relationship around it.
Decide what the VA will actually do
Do not start with access. Start with tasks. Write down what you want taken off your plate, then sort it.
| Level | Example tasks | Who decides |
|---|---|---|
| Sort and organise | Label, archive, unsubscribe from junk, flag what matters | The VA, using your rules |
| Handle routine replies | Scheduling, receipts, "where do I send this", standard answers | The VA, from approved templates |
| Draft for approval | Anything with judgement: pricing, partnerships, complaints | You approve before sending |
| Never delegate | Legal matters, HR, money movement, security, sensitive relationships | You |
Most of the early value is in the first two levels. Move tasks upward only as trust builds.
Give access the safe way
Use delegated access, not your password. Never share your own login. Use the delegation or shared-mailbox features of your mail system so the VA signs in as themselves, and every action is attributed to them. Gmail delegation, groups and shared inboxes explains one common setup.
Start narrow.
- Give access to the mailbox or folders they need, not everything.
- Hold back mailboxes for finance, legal and HR unless the task requires them.
- Prefer read and draft permissions first. Add send permissions later.
- Turn on two-step sign-in for their account. See rolling out 2FA across team email.
Set an end date or review date. Write down when you will review access. See designing per-mailbox permissions for a way to think about it.
Plan the exit. On the day the arrangement ends, access should be removed in minutes. Offboarding a teammate from shared email lists the steps.
Write the rules once
A one-page brief saves a hundred questions. It should cover:
- Your priorities. Who always gets a fast answer: key customers, investors, family. Who can wait.
- Voice and tone. A few examples of your replies and phrases to avoid. See getting AI drafts that sound like you for how to capture a voice; the same guide helps a human.
- Templates. Replies for the common cases. See reusable reply snippets for teams.
- Scheduling rules. Which hours are available, how long meetings run, how to handle time zones and which meetings you never take.
- What to escalate immediately. Anything urgent, angry, legal, financial or from a named list of people.
- What to never do. Never agree to a price, a deadline or a refund. Never share a password or a document without approval.
Keep it short and update it whenever a question repeats.
Agree how you communicate
Email delegation breaks down when the VA has to guess.
- A daily summary. Ask for a short note: what was handled, what is waiting for you and what needs a decision.
- A single place for questions. A shared note or chat thread, not scattered messages.
- A review window. A short time each day when you approve drafts, so nothing waits for days.
- Mark drafts clearly. Use a label such as
needs-approval, so you can find them and no one sends one by mistake. Writing replies together in a shared inbox has a workflow you can adapt. - Internal notes stay internal. Keep comments to each other out of the thread the customer sees. See discussing customer email internally.
Signing and identity
Decide how mail from the VA appears.
- As you. Convenient, but the recipient may believe you wrote it. That is fine for routine messages and wrong for sensitive ones. Decide which are which.
- As the assistant. "Sam, assistant to Alex" is honest and sets expectations about who will reply and how quickly.
- A mix. Use the assistant's identity for scheduling and logistics, and your own for personal messages.
Whichever you choose, be consistent, and do not use the assistant's identity to mislead anyone about who they are speaking to on a matter that depends on it.
Protect confidential information
An assistant sees everything in the mailbox they can open.
- Use a written confidentiality agreement, appropriate to your country and your business.
- Mark categories that should not be touched, such as legal threads, payroll and personal messages, and keep them in mailboxes the VA cannot reach.
- Remind them about phishing. A VA is a target, because they act on your behalf. Display-name spoofing and BEC and invoice fraud red flags describe what to watch for.
- Require confirmation by a second channel for any payment or credential request.
Using AI alongside a VA
Many assistants use AI tools to draft or summarise. Decide the rules together: which tools, what content may be pasted into them and who checks the output. When not to use AI on an email lists the categories to keep human. An AI draft reviewed by a VA and then by you is still your responsibility.
Review and grow the arrangement
- After two weeks, review what worked. Which tasks took more time than expected? Which rules were missing?
- Monthly, look at the summary notes. Move routine tasks to the VA and keep the rest.
- Quarterly, review access. Remove anything not used.
- Give feedback quickly. A correction in the first weeks is worth far more than a complaint after six months.
Key takeaways
- Start with tasks, not access, and sort them into sort, routine, draft for approval and never delegate.
- Use delegated access with the narrowest permissions, two-step sign-in and a review date.
- Write a one-page brief covering priorities, tone, templates, scheduling and escalation.
- Agree how you will communicate, how drafts are marked and how mail is signed.
- Protect confidential material and review the arrangement regularly.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

