← Docs

Team inbox

Turn a shared mailbox into a workflow: members, roles, assignment, chat.

The team inbox turns a shared inbox into a real workflow: clear ownership, internal coordination on the case, and no duplicate work. The team features are Astreo's commercial module.

Open mail in a team inbox with state, assignment and the chat line in the header
Above the mail: the state and "Assigned to", below them the chat line with "Tasks" and "History".

Team & members

A team brings together people in your company who work on mailboxes together – each still with their own login. Teams are created and managed under Team in the top bar.

You no longer add members by address; you pick a person from the company. Everyone who has a seat is available. Anyone without one gets it under Settings → Billing & plan, which is also where the invitation goes out – see seats. A newly added seat doesn't join any team at first; you make that assignment here.

If someone signs up with an address on your company domain without being invited, a join request appears in the team. You accept or decline it. Having the same domain is not proof of authorization – check who is asking.

Roles

Action rights

In addition to the role, every member has six action rights that admins switch on and off individually:

The defaults follow a simple rule: members may work, but not clear things away. Assign and Complete are on; Move, Spam and Delete are for admins only. A wrong reply can be corrected, but a case in the trash of a shared mailbox is gone for everyone. Two limits no switch can lift: viewers stay read-only, and only admins may delete permanently.

The interface only shows what someone is allowed to do: without the right, the button is missing – in the action row, in the bar for several selected mails and under Decide. If an action is rejected anyway, the message names the missing right and says that an admin can grant it under "Team".

Sharing a mailbox with the team

A connected mailbox can stay personal or be shared with a team. You can only share your own mailboxes; the credentials stay with you. Once the mailbox is shared, members see its cases and work on them together. That's how support@ becomes a true shared mailbox.

For each share, admins decide which folders the team sees:

The restriction applies to the members of this team; whoever owns the mailbox still sees everything. The same mailbox can be fully open in one team and limited to the inbox in another. Only the team's admins can revoke a share.

If a private key for encrypted mail is attached to a shared mailbox, it decrypts for everyone who can see the mailbox. Astreo therefore asks before binding it, shows who added each key, and the mailbox owner can also remove other people's keys – see encryption.

Assignment

Assign every case to a responsible person. In the mail header, choose a name from the list under "Assigned to" – you appear in it marked "(you)". With the "Assigned to me" view, each person sees their open list. More on states and views in Cases & views.

If you don't work in Astreo all the time, you can have assignments sent to you by email. Each person sets this for themselves under Settings → Notifications ("When someone assigns a case to you"). You are only notified about what someone else assigns to you.

Internal chat

Coordinate right on the case: chat messages are visible to the team only and never go to the sender. The chat line sits in the mail header, below the state and the assignment:

The chat line appears in mailboxes that several people work on. In a purely personal mailbox there is nobody to write to.

With Astreo Clear the header looks different: the case box with Decide takes the place of state and assignment.

Collision detection

Astreo shows in real time who has the same case open and who is writing a reply. That prevents duplicate answers, and nobody steps on anyone's toes.

Send-as & thread sharing

Log: who did what and when

Every action on a team mailbox is logged: assigning, changing the state, writing a chat message, moving, marking as spam, deleting, replying, escalation. This always runs and cannot be switched off – it is the input control we commit to in the data processing agreement.

The log contains no content of your emails. It records that something happened, by whom and when – plus header fields like subject and sender, but never the text of a message.

An entry, once written, can no longer be changed or deleted. The database itself enforces this, not the application: update and delete commands on the log are rejected. In addition, each entry is mathematically chained to the previous one – if one is altered afterwards, the chain no longer fits together from that point on.

You can read the log under Settings → Log & seal, filtered by period and type – see Settings & security.

Log seal

The chain notices when individual entries are changed. It does not notice if someone with enough privileges recalculates it completely – the result would be consistent in itself. That is what the seal is for.

Every day Astreo calculates a check value over your team's log, signs it and sends it to you by email. As soon as that mail is with you, the check value is out of our reach. If anyone – including us – later changed an entry, it would no longer match your mail. You can prove this without having to ask us.

Keep these mails, ideally somewhere we cannot reach. They are your evidence.

Setting it up

In the application under Settings → Log & seal (Security group). Anyone who administers a team can set it up:

"Only on demand" means only sent on demand. Sealing still happens every day. Otherwise the period up to the button press could be changed afterwards – the button would give you proof that records nothing.

The page also shows how many entries are not yet sealed. If you rarely press the button, you can see how large the unprotected period currently is. You're not prevented from doing so – it's your decision, but you should be able to see it.

What the seal does – and what it doesn't

The seal proves that the log has been unchanged since the time of the mail. What it does not do: we hold the signing key ourselves. A third party can use it to check that the signature belongs to our key – the public part is always available at https://app.astreo.de/api/audit/schluessel. The proof against us does not come from the signature but from the fact that your mail records the check value.

That's why we call it a complete, verifiable log and not "audit-proof" in the sense of the German term "revisionssicher": that term is reserved for the legally regulated archiving of business records and would promise something other than what is meant here.

With Astreo Clear

If your company has Astreo Clear, the team gets three additional settings: the fallback person for cases Clear cannot assign, cover during absence and the rules. They are described in Commitments, ownership & cover and Rules & traceability.