Team Roles and What Each One Can Reach
Client, Webmail only, Domain Administrator, Mailbox Operator, Read-only and Custom: what each role opens and what it keeps shut.
Article details
Type, difficulty, plans, and last updated info.
▼
Article details
Type, difficulty, plans, and last updated info.
- Type
- Guide
- Difficulty
- Beginner
- Plans
- Nano · Starter · Pro · Agency
- Last updated
- Sep 9, 2026
Every person you invite gets one role. The role decides what they can do; the domains you assign decide where they can do it. The two work together. A Domain Administrator assigned one domain can do a lot, but only on that domain.
You can change somebody's role at any time from the Team page. The change takes effect on their next click.
The short version
| Role | Best for | Domains | Mailboxes | Dashboard |
|---|---|---|---|---|
| Client | The customer whose domain it is | Assigned domains | Yes, in those domains | Yes |
| Domain Administrator | Whoever handles DNS | Assigned domains | No | Yes |
| Mailbox Operator | Whoever creates and fixes mailboxes | Can choose an assigned domain | Yes, in those domains | Yes |
| Read-only | An auditor, a stakeholder, a second pair of eyes | Look only | Look only | Yes |
| Webmail only | A person recorded in the team list | No dashboard access | No dashboard access | No |
| Custom | Anything the five above do not cover | You choose | You choose | Yes |
Client
Full access to the domains and mailboxes they are given.
This is the role for the person the domain actually belongs to. On assigned domains they can manage DNS and SMTP settings, create and delete mailboxes, set mailbox passwords, manage forwarding and rules, set up shared mailboxes, move mail from another provider, and check an address list with the Email Verifier.
What they cannot touch: your billing, your branding, and your list of people. They also cannot see any domain you did not assign to them.
Give this role when you want a client to run their own email and stop asking you for every change.
Domain Administrator
Full access to the domains they are given. No mailboxes.
Domains, DNS records, Cloudflare connection and SMTP settings are available on the domains you assign. Mailboxes are not available to this role, and neither is mail inside them.
This is the role for a technical contact who sets up domains but has no business reading anybody's email. It also has no access to migrations, deliberately: a migration writes mail into a mailbox, and this role has no mailbox rights at all.
Mailbox Operator
Full access to mailboxes in their assigned domains. No domain management.
Creating mailboxes, deleting them, setting passwords, forwarding, rules, auto-replies, shared mailboxes, importing mail from an old provider, and the Email Verifier.
They can see the eligible domains because a new mailbox needs a domain, but they cannot change a domain or its DNS.
This is the role for whoever handles the day-to-day: new starters, leavers, someone locked out of their mailbox.
Read-only
Can look at everything. Changes nothing.
Every page opens; nothing saves. They see domains, mailboxes, DNS status and settings, and can look at migrations and verification results, but every attempt to change something is refused.
Because the pages look the same as they do for everybody else, a read-only person sees a note at the top of the dashboard telling them their access is read-only, so they do not fill in a form and lose it.
They cannot see billing, your list of people, or the activity log. Watching what colleagues did is a supervisory power, and this role is not supervisory.
Webmail only
Webmail only. No dashboard.
This role does not grant dashboard access or mailbox access by itself. A person still needs a mailbox and its separate mailbox credentials to sign in to webmail. Use this role when you want the Team list to record that person without handing them dashboard permissions.
Use it when somebody needs an inbox and nothing else. It is the safest role you can hand out.
Custom
Pick permissions one by one.
When none of the five fit, build your own. You choose individual permissions grouped by area. Start with the smallest set that lets the person complete their job; a Custom role with no permissions grants nothing.
Two rules hold:
- You cannot grant what you do not have. Nobody can create a role more powerful than their own.
- The dangerous ones are named. Permissions that hand out something irreversible (deleting an account, setting a mailbox password, resetting somebody's two-factor, minting API keys) are called out individually in the activity log when they are granted, rather than being counted as "3 more permissions".
Roles and the domains you assign
The role and the domain list are separate choices, and both apply.
Assign a person one domain and they see one domain: in the sidebar, in the mailbox list, in search, everywhere. It is not a filter they can turn off; the other domains are not reachable at all, including through the API.
Choose "all domains" and they see whatever the account has, including domains you add later.
What no role can do
Some things stay with you no matter what you hand out:
- Transfer account ownership
The standard roles also omit billing, White Label administration, the Team list, and account deletion. A Custom role can include some of those permissions only when the inviter is permitted to grant them.
Common questions
Can I have two people with the same role? Yes. Give each person the same role when their responsibilities match, then check their individual domain assignment before sending each invitation.
What happens to their work if I remove them? Nothing they created goes away. Mailboxes, domains and settings belong to the account, not to the person.
Can somebody hold two roles? No. One role per person per account. If they need a mix, use Custom.
They already have their own TrekMail account. Is that a problem? No. See Working in more than one account.
Related articles
Jump to nearby guides that continue the workflow.