Team Roles and What Each One Can Reach

This guide explains Client, Webmail only, Domain Administrator, Mailbox Operator, Read-only and Custom — what each role opens and what it keeps shut. so you can complete the TrekMail task with confidence.

Article details

Type, difficulty, plans, and last updated info.

Type
Guide
Difficulty
Beginner
Plans
Nano · Starter · Pro · Agency
Last updated
Aug 4, 2026

Every person you invite gets one role. The role decides what they can do; the domains you assign decide where they can do it. The two work together — a Domain Administrator assigned one domain can do a lot, but only on that domain.

You can change somebody's role at any time from the Team page. The change takes effect on their next click.

The short version

Role Best for Domains Mailboxes Dashboard
Client The customer whose domain it is Yes Yes Yes
Domain Administrator Whoever handles DNS Yes No Yes
Mailbox Operator Whoever creates and fixes mailboxes Sees them only Yes Yes
Read-only An auditor, a stakeholder, a second pair of eyes Look only Look only Yes
Webmail only Somebody who just needs their inbox No No No
Custom Anything the five above do not cover You choose You choose Yes

Client

Full access to the domains and mailboxes they are given.

This is the role for the person the domain actually belongs to. On their domains they can do nearly everything you can: add and remove domains, edit DNS, create and delete mailboxes, set mailbox passwords, manage forwarding and rules, set up shared mailboxes, move mail in from another provider, and check an address list with the Email Verifier.

What they cannot touch: your billing, your branding, and your list of people. They also cannot see any domain you did not assign to them.

Give this role when you want a client to run their own email and stop asking you for every change.

Domain Administrator

Full access to the domains they are given. No mailboxes.

Domains, DNS records, Cloudflare connection and SMTP settings — all of it, on the domains you assign. Mailboxes are invisible to them, and so is the mail inside.

This is the role for a technical contact who sets up domains but has no business reading anybody's email. It also has no access to migrations, deliberately: a migration writes mail into a mailbox, and this role has no mailbox rights at all.

Mailbox Operator

Full access to the mailboxes they are given. No domains.

Creating mailboxes, deleting them, setting passwords, forwarding, rules, auto-replies, shared mailboxes, importing mail from an old provider, and the Email Verifier.

They can see the list of domains, because you cannot create a mailbox without choosing which domain it belongs to — but they cannot change a domain or its DNS.

This is the role for whoever handles the day-to-day: new starters, leavers, someone locked out of their mailbox.

Read-only

Can look at everything. Changes nothing.

Every page opens; nothing saves. They see domains, mailboxes, DNS status and settings, and can look at migrations and verification results — but every attempt to change something is refused.

Because the pages look the same as they do for everybody else, a read-only person sees a note at the top of the dashboard telling them their access is read-only, so they do not fill in a form and lose it.

They cannot see billing, your list of people, or the activity log. Watching what colleagues did is a supervisory power, and this role is not supervisory.

Webmail only

Webmail only. No dashboard.

They sign in to their mailbox and that is all. If they open your dashboard address, they are taken to their own settings page — where they can change their password, their language and their two-factor — and told plainly that this account is set up for webmail.

Use it when somebody needs an inbox and nothing else. It is the safest role you can hand out.

Custom

Pick permissions one by one.

When none of the five fit, build your own. You choose from a list grouped by area: billing, branding, people and access, mailbox credentials, shared mailboxes, and migration and verification.

Two rules hold:

  • You cannot grant what you do not have. Nobody can create a role more powerful than their own.
  • The dangerous ones are named. Permissions that hand out something irreversible — deleting an account, setting a mailbox password, resetting somebody's two-factor, minting API keys — are called out individually in the activity log when they are granted, rather than being counted as "3 more permissions".

Roles and the domains you assign

The role and the domain list are separate choices, and both apply.

Assign a person one domain and they see one domain — in the sidebar, in the mailbox list, in search, everywhere. It is not a filter they can turn off; the other domains are not reachable at all, including through the API.

Choose "all domains" and they see whatever the account has, including domains you add later.

What no role can do

Some things stay with you no matter what you hand out:

  • Change the plan, the payment card, or see an invoice
  • Buy or cancel White Label Lite
  • Close the account or transfer ownership

Common questions

Can I have two people with the same role? Yes. There is no limit on how many people hold any role.

What happens to their work if I remove them? Nothing they created goes away. Mailboxes, domains and settings belong to the account, not to the person.

Can somebody hold two roles? No — one role per person per account. If they need a mix, use Custom.

They already have their own TrekMail account. Is that a problem? No. See Working in more than one account.

Related articles

Jump to nearby guides that continue the workflow.

We use cookies for essential functionality. No ads, no ad tracking.

Sign in to TrekMail

Access your dashboard, mailboxes and DNS.

or
or

Reset email sent

If an account exists for this email, we've sent password reset instructions.

By continuing, you agree to TrekMail's Terms and Privacy Policy.