Awaiting review — Jordan · Brian · Ryan — 2026-08-30
Central Email + Access Setup
pillarbooth.com · decisions on this page: what each address is, who has access, and admin levels
1The four ways to share an email address
Every address below uses exactly one of these. The goal: no company activity tied to a personal mailbox — anyone can be slotted in or covered during PTO in minutes.
Real account
Cost: ~$14/mo each · has its own login + inbox
Best for: a mailbox someone works in all day.
Only option when systems connect to it (Zapier, Salesforce).
Watch out: a password + 2FA to keep secured in the company vault.
Delegate
Cost: free · access granted to a real account, no password shared
Best for: backup coverage and oversight on an account.
Instantly revocable — every action logged to the person.
Watch out: web Gmail only — no phone app, no notifications.
Group
Cost: free · an address with a member list — no login exists
Every member gets a copy in their own inbox — phone included.
Members reply as the address; all replies visible to everyone.
Permanent shared archive — history survives any departure.
Watch out: no shared drafts — convention is reply-all so others see it's handled.
Alias
Cost: free · an extra name on an existing mailbox
Best for: sender identities and near-zero-volume addresses.
Watch out: not separate — same inbox, same access as its parent.
Rule of thumb: accounts for daily work · groups for intake · aliases for names · delegates for coverage.
2The addresses — approve each one
Today: 10 paid accounts + 3 aliases. Proposed: 3 paid accounts, 4 free groups, 5 free aliases, 1 retired — saves ~$1,176/yr and makes every address person-independent. Check who belongs where; approve or flag each card.
admin@Keep — real account
Use: Google Workspace super-admin + owner of company subscriptions (Dropbox, Cloudflare, Claude, ClickUp…).
Rules: never a daily mailbox · credentials + 2FA in the company vault · two super-admins minimum so no one person is a lockout risk.
Person
Signs in
Delegate
No access
Jordan
Ryan — second super-admin (break-glass)
Brian
purchasing@Keep — real account
Use: all POs to vendors + the automation hub — Zapier and Salesforce already send from it (PO Health digest, Daily Shipping Report).
Carries the aliases orders@ · inventory@ · production@ (set up 8/26 — automation sender names, replies all land here).
Person
Signs in
Delegate
No access
Alana
Chris
Brian
Eddie
shipping@Keep — real account
Use: all customer shipping communication + BOL handling. Eddie's daily working mailbox — his shipping threads stop living in eddie@.
One-time fix: shipping@ currently exists as an alias on purchasing@ — the alias is removed, the account created, Salesforce re-pointed (~15 min).
Person
Signs in
Delegate
No access
Eddie
Alana
Chris
Brian
support@Convert — group
Use: customer support intake. Members get every email in their own inbox; the Salesforce intake address joins as a member so real support mail becomes a numbered case automatically (Section 3).
Person
Member
Eddie — works the cases
Alana
Brian
Chris
Salesforce intake — auto-creates cases
sales@Convert — group
Use: sales opportunity intake. Same mechanics as support@; a CRM intake address can join later without changing anything public.
Person
Member
Mike
Blake
Brian
Jordan
info@Convert — group
Use: the website's general-inquiry address. Whoever's checked triages; most of it forwards on to sales or support.
Person
Member
Brian
Mike
ap@Convert — group
Use: vendor invoices in. A bookkeeping tool's intake address can join later for automatic bill capture.
Person
Member
Ryan
Alana
Brian
noreply@Downgrade — alias on admin@
Use: sender name for automated system emails. Apps send through domain authorization, not a mailbox — a paid account here does nothing.
privacy@Downgrade — alias on admin@
Use: the contact address on the website privacy policy. Near-zero volume; lands in admin@.
ops@Retire
Why it existed: a workaround so shared company files weren't owned by one person's account.
The proper fix: Google Shared Drives — the company owns the files, not any account — plus a scoped admin role for Brian (Section 4). Files move over, account closes.
Salesforce's built-in helpdesk (Email-to-Case) is already on: emails become numbered cases with an owner and status. It was turned on but never set up properly — checked directly in the org 8/30:
47,179 cases exist · 46,876 still marked "New" · only 303 ever closed.
Cause: Eddie's entire personal mailbox forwards in — every newsletter, QuickBooks notice, and his own sent mail becomes a "support case."
Keep it: already paid for, and cases link to our Orders + Accounts — a separate helpdesk tool can't do that without months of integration.
Ask Alana first: was the eddie@ forward meant to create support cases, or to log his order emails? Gates everything below.
Cut the eddie@ forward (replace with proper email logging if that was the intent).
Mass-close the ~46.9k junk backlog — status "Closed — Archived"; reporting restarts at zero.
Wire support@ (the group above) as the only intake — Gmail spam-screens everything before Salesforce sees it.
Configure the basics, then train Eddie: new cases assigned to Eddie with a backup queue · auto-acknowledgment to the customer from support@ · working statuses · junk-sender block rules.
4Admin access cleanup
Principle: admin = who fixes the system, not seniority. Admin rights mean the power to delete data, change security, and reset anyone's password — every extra admin is risk with no benefit. Today six of eight Salesforce users are full System Administrators.
Salesforce (current levels verified in the org 8/30)
Person
Today
Proposed
Why
Jordan
System Admin
Owner
Ryan
System Admin
Owner
Alana
System Admin
The working Salesforce admin
Brian
System Admin
GM — call to make together
Mike
System Admin
Sales — no admin need
Eddie
System Admin
Works cases + shipments, shouldn't hold delete-everything rights
Chris
Standard
Already right
Blake
Standard
Already right
Google Workspace (current levels to be confirmed in Google Admin)
Person
Proposed
Why
Jordan
Owner
Ryan
Second super-admin — lockout protection
Brian
Can manage people + groups, can't touch security or billing
Everyone else
Regular users
ASK: approve or flag every card above, then copy the decisions back to Jordan. WHY: one sign-off here lets the whole setup — email, helpdesk, admin levels — be built in a single pass before Eddie trains.