Central Email + Access Setup

pillarbooth.com · decisions on this page: what each address is, who has access, and admin levels

1The four ways to share an email address

Every address below uses exactly one of these. The goal: no company activity tied to a personal mailbox — anyone can be slotted in or covered during PTO in minutes.

Real account

Cost: ~$14/mo each · has its own login + inbox
  • Best for: a mailbox someone works in all day.
  • Only option when systems connect to it (Zapier, Salesforce).
  • Watch out: a password + 2FA to keep secured in the company vault.

Delegate

Cost: free · access granted to a real account, no password shared
  • Best for: backup coverage and oversight on an account.
  • Instantly revocable — every action logged to the person.
  • Watch out: web Gmail only — no phone app, no notifications.

Group

Cost: free · an address with a member list — no login exists
  • Every member gets a copy in their own inbox — phone included.
  • Members reply as the address; all replies visible to everyone.
  • Permanent shared archive — history survives any departure.
  • Watch out: no shared drafts — convention is reply-all so others see it's handled.

Alias

Cost: free · an extra name on an existing mailbox
  • Best for: sender identities and near-zero-volume addresses.
  • Watch out: not separate — same inbox, same access as its parent.
Rule of thumb: accounts for daily work · groups for intake · aliases for names · delegates for coverage.

2The addresses — approve each one

Today: 10 paid accounts + 3 aliases. Proposed: 3 paid accounts, 4 free groups, 5 free aliases, 1 retired — saves ~$1,176/yr and makes every address person-independent. Check who belongs where; approve or flag each card.

admin@
Use: Google Workspace super-admin + owner of company subscriptions (Dropbox, Cloudflare, Claude, ClickUp…).
Rules: never a daily mailbox · credentials + 2FA in the company vault · two super-admins minimum so no one person is a lockout risk.
PersonSigns inDelegateNo access
Jordan
Ryan — second super-admin (break-glass)
Brian
purchasing@
Use: all POs to vendors + the automation hub — Zapier and Salesforce already send from it (PO Health digest, Daily Shipping Report).
Carries the aliases orders@ · inventory@ · production@ (set up 8/26 — automation sender names, replies all land here).
PersonSigns inDelegateNo access
Alana
Chris
Brian
Eddie
shipping@
Use: all customer shipping communication + BOL handling. Eddie's daily working mailbox — his shipping threads stop living in eddie@.
One-time fix: shipping@ currently exists as an alias on purchasing@ — the alias is removed, the account created, Salesforce re-pointed (~15 min).
PersonSigns inDelegateNo access
Eddie
Alana
Chris
Brian
support@Convert — group
Use: customer support intake. Members get every email in their own inbox; the Salesforce intake address joins as a member so real support mail becomes a numbered case automatically (Section 3).
PersonMember
Eddie — works the cases
Alana
Brian
Chris
Salesforce intake — auto-creates cases
sales@Convert — group
Use: sales opportunity intake. Same mechanics as support@; a CRM intake address can join later without changing anything public.
PersonMember
Mike
Blake
Brian
Jordan
info@Convert — group
Use: the website's general-inquiry address. Whoever's checked triages; most of it forwards on to sales or support.
PersonMember
Brian
Mike
ap@Convert — group
Use: vendor invoices in. A bookkeeping tool's intake address can join later for automatic bill capture.
PersonMember
Ryan
Alana
Brian
noreply@Downgrade — alias on admin@
Use: sender name for automated system emails. Apps send through domain authorization, not a mailbox — a paid account here does nothing.
privacy@Downgrade — alias on admin@
Use: the contact address on the website privacy policy. Near-zero volume; lands in admin@.
ops@Retire
Why it existed: a workaround so shared company files weren't owned by one person's account.
The proper fix: Google Shared Drives — the company owns the files, not any account — plus a scoped admin role for Brian (Section 4). Files move over, account closes.

3Support helpdesk — Salesforce cleanup + proper setup

Salesforce's built-in helpdesk (Email-to-Case) is already on: emails become numbered cases with an owner and status. It was turned on but never set up properly — checked directly in the org 8/30:

47,179 cases exist · 46,876 still marked "New" · only 303 ever closed.
Cause: Eddie's entire personal mailbox forwards in — every newsletter, QuickBooks notice, and his own sent mail becomes a "support case."
Keep it: already paid for, and cases link to our Orders + Accounts — a separate helpdesk tool can't do that without months of integration.
  1. Ask Alana first: was the eddie@ forward meant to create support cases, or to log his order emails? Gates everything below.
  2. Cut the eddie@ forward (replace with proper email logging if that was the intent).
  3. Mass-close the ~46.9k junk backlog — status "Closed — Archived"; reporting restarts at zero.
  4. Wire support@ (the group above) as the only intake — Gmail spam-screens everything before Salesforce sees it.
  5. Configure the basics, then train Eddie: new cases assigned to Eddie with a backup queue · auto-acknowledgment to the customer from support@ · working statuses · junk-sender block rules.

4Admin access cleanup

Principle: admin = who fixes the system, not seniority. Admin rights mean the power to delete data, change security, and reset anyone's password — every extra admin is risk with no benefit. Today six of eight Salesforce users are full System Administrators.

Salesforce (current levels verified in the org 8/30)

PersonTodayProposedWhy
JordanSystem AdminOwner
RyanSystem AdminOwner
AlanaSystem AdminThe working Salesforce admin
BrianSystem AdminGM — call to make together
MikeSystem AdminSales — no admin need
EddieSystem AdminWorks cases + shipments, shouldn't hold delete-everything rights
ChrisStandardAlready right
BlakeStandardAlready right

Google Workspace (current levels to be confirmed in Google Admin)

PersonProposedWhy
JordanOwner
RyanSecond super-admin — lockout protection
BrianCan manage people + groups, can't touch security or billing
Everyone elseRegular users
ASK: approve or flag every card above, then copy the decisions back to Jordan.
WHY: one sign-off here lets the whole setup — email, helpdesk, admin levels — be built in a single pass before Eddie trains.
Choices save in this browser as you click.