Team collaboration
Per-mailbox ownership, role-based access, per-session revoke, audit log.
Team collaboration in Autocloz is ownership-first: a mailbox is private to the user who connected it, and only that user can send through it. An org owner or admin can read and audit that mailbox but can never impersonate it. Sessions are revocable one device at a time, and every action lands in an append-only audit log.
- ·Per-mailbox owner enforcement
- ·Role-based access (owner / admin / member)
- ·Per-session revoke (force logout one device)
- ·Append-only audit log of every action
- ·Invite via email or SCIM
The detail.
A mailbox is private. A workspace is shared.
Mailbox credentials are encrypted per-org and only the owner user can send through them. An org admin can clean up a departed teammate's mailbox but never pretend to be them.
Three roles, and the difference is what they can do to others
Owner, admin and member differ less in what they can see than in what they can change about somebody else. A member runs their own sending; an admin manages the workspace and other people's access; the owner controls billing and the org itself. Read access to a teammate's activity is an audit right, never a send right.
Revoke one device, not one person
Sessions are revocable individually, so a rep who left a laptop at a client site can be signed out of that device without being locked out of their phone mid-shift. The blunt alternative — disabling the account — is still there when someone actually leaves.
The gotcha: an audit log is only useful if it is append-only
A log an admin can edit answers no question worth asking. Autocloz writes an audit row for every state-changing action and never rewrites one, which is what lets you answer "who paused that campaign, and when" months later — and what an enterprise security review actually asks to see.
Specific to this feature.
Can an admin send from someone else's mailbox?
+
No. Mailbox credentials are encrypted per-org and sending is restricted to the user who connected the mailbox. An owner or admin can read and audit it, and can clean it up when the person leaves, but impersonation is not an available action.
How do I sign one device out without locking the person out?
+
Revoke that session. Sessions are per-device, so revoking the laptop leaves the phone signed in — useful when a device is lost rather than when a person departs.
What is written to the audit log?
+
Every state-changing action, with the actor recorded against it, appended and never rewritten. That is what makes "who changed this, and when" answerable after the fact rather than a matter of recollection.
How do people join the workspace?
+
By email invite, with SCIM-friendly flows for teams that provision through an identity provider. New members land in a role, and the role — not a per-object permission list — is what governs what they can change.
The full story.
Shared-mailbox access is the quiet failure mode of most outbound tools. Once any admin can send as any teammate, the audit trail stops meaning anything: a message that damaged a relationship cannot be attributed, and the person whose name was on it has no way to prove it was not them. Making the mailbox private to its owner is a small constraint that removes that entire class of argument.
The trade-off is real and worth stating plainly: because only the owner can send, covering for a teammate on leave means either connecting a shared mailbox deliberately or moving the sequence to a mailbox somebody present owns. That is the intended behaviour rather than a limitation to route around — the alternative is an access model where nobody can say who sent what.
Try it free.
No credit card. Every feature on this page included.