Manager handbook
Operate the mail environment safely
A task-oriented map of the Management centre, with checks for identity, shared mailboxes, mail flow, privacy, and offboarding.
This guide is readable by everyone, but the Management centre and its actions are enforced on the server for accounts with the Manager role.
Use the Management centre as the control plane
The Overview page surfaces required configuration, optional capabilities, recent activity, and directory visibility. Treat red or action-needed checks as deployment blockers. Configuration files and Cloudflare secrets remain the infrastructure control plane; the in-app Settings page explains their current effective state without revealing secret values.
Onboard a person
- Create the person with the exact Google or Microsoft sign-in email.
- Use Standard unless management access is required, and provision the required personal mailbox on the organisation domain.
- Select Send invitation now, or use Send invitation afterward. This creates a hashed, single-use enrolment token that expires after 72 hours.
- Grant shared mailbox access separately, using the least capable level that meets the role.
- Ask the person to use the newest invitation with the matching Google or Microsoft UserInfo address, accept any published policy, and verify their mailbox and From addresses.
A newly created account is pending and has no sign-in identity until its invitation succeeds; email alone never authorises first sign-in. Resending rotates the token immediately, so only the newest link works. An identity already enrolled to another account is rejected instead of being reassigned. Paused blocks sign-in and revokes active sessions while retaining data. Offboarded is the durable end state.
Create and delegate a shared mailbox
- Open Mailboxes and create a Shared mailbox using a functional local part such as support or accounts.
- Confirm the resulting address and display name before routing external mail to it.
- Open Mailbox delegation and grant Read, Send as, or Full access.
- Have each delegate verify the mailbox appears and that unavailable actions match their access level.
- Send a controlled inbound, internal, reply, and external test before announcing the address.
Read is observation only. Send as includes reading and sending from the shared identity. Full access adds shared folder, star, archive, trash, and restore control. These are bundled cmail access levels.
Disabling a mailbox removes it from user navigation and stops sending and new inbound delivery. Existing stored data is retained. Remove obsolete delegate access before repurposing an address.
Diagnose mail without exposing content
Use Mail trace to follow direction, sender/recipient envelope metadata, status, provider response, and authentication results. Use Audit log to identify administrative changes. Keep ticket notes free of message bodies, OAuth data, push endpoints, and credentials.
- Confirm the mailbox is active and the person has the expected assignment.
- Check inbound routing and recipient status for missing received mail.
- Check the selected outbound provider, verified sender domain, and trace status for failed sends.
- Use the operations and security checklists in the source repository for backups, rotation, and incident handling.
Run support and escalation through a safe boundary
Designated, internally trained people provide first-level support (L1): receive the report, check approved runbooks, Mail trace and Audit log, communicate with the user, and follow the organisation's incident and privacy processes. Keep case notes free of message bodies, attachments, credentials, OAuth or session values, and raw exports.
Escalate a real, reproducible cmail product defect to RME Solutions Technology through the organisation's agreed ticket or email channel. Include the deployed version, safe steps, expected and observed result, impact, UTC time window, and redacted trace or error identifiers. Operational help expressly included in a separate support agreement follows that agreement; detailed design, configuration, provider or DNS work, bespoke changes, and non-reproducible troubleshooting outside it are separately scoped or quoted work.
For suspected compromise, unauthorised access, or data exposure, contain the issue and follow the organisation's incident process immediately. Suspected cmail vulnerabilities use the private security process, not ordinary support. Read the full support process.
Prepare evidence for review
Standards & assurance describes product capabilities, operator-configured controls, provider responsibilities, and known gaps. It is a shareable operational summary, not a certification or assurance of this deployment.
- Record the deployed version, providers, DNS checks, identity-provider MFA and conditional-access settings, and the approved Cloudflare Email Preview setting.
- Keep protected exports or snapshots of Audit log and Mail trace with the backup and retention evidence required by your organisation.
- Record retention periods, whether retention jobs are enabled, legal-hold decisions, backup owners, and the date of the latest restore exercise.
- Have an accountable owner review the evidence after material access, routing, provider, or retention changes.
cmail does not provide a protected audit export, legal hold, or tamper-evident audit store. Preserve and protect required evidence through the deployment's own backup, access, and retention controls.
Publish directory data by exception
The public organisation directory has two gates: the global directory switch and the position's Public visibility setting. A public position can expose only occupant name, position title, and work email. All other account, reporting, role, permission, and personal data stays internal.
- Build layers, units, and roles without enabling public output.
- Create positions as Internal and review their work email and title.
- Mark only approved positions Public.
- Enable the global directory switch only after reviewing the public preview.
Change access or offboard safely
- Pause the account immediately when access must stop; this blocks sign-in and revokes sessions.
- Transfer operational ownership and review every shared mailbox assignment.
- Offboarding automatically makes their public positions internal; replace published occupant details only after appointing a successor.
- Preserve mail according to policy and legal requirements; do not delete storage ad hoc.
- Offboard the account when the transition is complete, then review Audit log.
- Expect later mail to receive the same generic SMTP rejection as any unavailable address. The sender's mail system may show a cmail-labelled delivery failure; cmail sends no auto-reply, which protects outbound quota and prevents backscatter.
Review unavailable-recipient patterns in Cloudflare Email Routing and Worker metrics. cmail deliberately creates no durable per-attempt trace for this attacker-controlled path.