Virtual Assistant Provider guide
Build an Inbox Authority Matrix Before Delegating Executive Email

Turn vague inbox access into explicit rules for reading, drafting, sending, escalating, and retaining executive correspondence.
Key takeaways
- Separate permission to view a message from authority to answer or commit.
- Define rules by message class, sender, sensitivity, and requested action.
- Keep decisions and exceptions visible without copying sensitive content into a second system.
- Test the matrix with realistic edge cases before granting live access.
Inbox delegation fails when access is mistaken for authority
Giving a virtual assistant access to an executive mailbox solves a technical problem, not an operating one. The assistant can see a request, but may not know whether to acknowledge it, draft for review, send from an approved template, change the calendar, disclose a document, or decline. When those distinctions remain in the founder's head, ordinary messages become interruptions and risky messages may receive confident but unauthorized answers. Begin by naming the outcome. An inbox assistant might keep important requests visible, prepare accurate drafts, route sensitive matters, and maintain response commitments. That is different from representing the executive in negotiations. Write down the decisions the assistant may make and the commitments they may not make. A useful boundary is specific: the assistant may offer open calendar slots within approved hours, but may not accept commercial terms, legal notices, media statements, personnel decisions, or payments. The matrix should complement technical controls, not replace them. Use the smallest mailbox scope and system permissions that support the agreed work. If delegated access can avoid sharing a password, use it. Keep multifactor authentication, recovery methods, and account ownership with the authorized business owner.
Classify messages by consequence, not just by folder
Traditional folders such as clients, vendors, and newsletters do not reveal what an assistant can safely do. A familiar client can send a legal notice; an unknown sender can submit an ordinary scheduling request. Classify messages using sender relationship, sensitivity, requested action, deadline, and consequence of error. A practical matrix can use four action levels. Observe means the assistant may label and surface the message without changing its content or status. Prepare means the assistant may collect sources and draft a response for review. Act means the assistant may send or update a system using an approved rule. Escalate means the assistant stops, preserves the original, and routes it to a named owner. Add examples and counterexamples for every level. Consider a customer asking for the status of an already approved deliverable. The assistant may be allowed to cite the project record and send a factual update. If the same customer alleges breach of contract, requests a refund outside policy, or threatens legal action, the subject belongs with the accountable owner. The sender did not change, but the requested decision did.
Design an evidence trail that respects confidentiality
The executive should be able to review what happened without forcing the assistant to paste private email into a general task board. Record a message identifier or secure link, received time, classification, assigned owner, promised response time, action level, and current status. Note the reason for escalation in neutral terms. Keep confidential details in the authorized mailbox or case system. For sent messages, identify whether the assistant used an approved template, sent a reviewed draft, or acted under a standing rule. This distinction helps a reviewer find policy gaps. It also prevents a polished response from appearing authorized merely because it already left the mailbox. If an instruction changes, update the matrix version and effective date so older decisions can be understood in context. Define retention and deletion with the system owner. A personal spreadsheet of copied messages creates a second, weaker archive. The better record points back to the controlled source and contains only what coordination requires. When the assistant leaves the role, remove delegated access, forwarding rules, active sessions, and connected applications through a documented offboarding step.
Test edge cases before the mailbox goes live
Run a tabletop exercise with fictional messages. Include a routine reschedule, an urgent request from an unrecognized address, an invoice attachment, a password-reset email, a reporter inquiry, a complaint mentioning litigation, and a personal note. Ask the assistant to state the classification, allowed action, source used, next owner, and response deadline. The purpose is not to trick anyone; it is to expose ambiguous rules while no real sender is affected. Review disagreements. If the founder expects an immediate acknowledgment but the assistant believes no response is allowed, decide whether a neutral receipt is safe and supply the exact rule. If an apparent vendor changes bank details, make independent verification mandatory rather than allowing email alone to authorize the change. If an urgent message arrives outside coverage hours, document the backup route instead of implying continuous monitoring. Start with a narrow set of repeatable messages. Sample sent work daily, then reduce review only when evidence supports it. Add authority gradually and revoke it when the role or risk changes. The matrix is a living control, not a one-time onboarding checklist.
Use a weekly review to improve the rules
A short weekly review should examine aged messages, escalations, returned drafts, mistaken classifications, and commitments awaiting the executive. Look for patterns rather than blaming individual judgment. Five repeated questions about scheduling may need a clearer calendar rule. Repeated uncertainty about customer credits may show that the assistant should only prepare evidence, not decide the outcome. Include a small permissions check in that review. Compare what the assistant actually needs for current message classes with mailbox delegation, shared-drive access, contact exports, and any sending aliases. Remove access that belongs to an earlier responsibility, and confirm that the executive can revoke delegated access without depending on the assistant.s device or password. When a role changes, update the authority matrix and the technical permissions together; changing only one leaves either unnecessary access or an impossible assignment. Measure what the design is meant to improve: important messages found on time, authorized responses completed, avoidable executive interruptions, unresolved commitments, and boundary incidents. Raw inbox-zero counts can reward premature archiving and say little about whether the right work happened. A healthy inbox can contain visible waiting items with named owners. The US Cybersecurity and Infrastructure Security Agency recommends strong account protections such as multifactor authentication in its [account security guidance](https://www.cisa.gov/secure-our-world/use-strong-passwords). The US National Archives also provides [email management guidance](https://www.archives.gov/records-mgmt/email-management) that is useful when defining official records and retention. Apply the rules appropriate to your contracts, location, and industry. If you need an operating design before handing over a founder mailbox, review our [executive assistant services](/services/executive-assistant-staffing) or [contact us](/contact) to map a bounded delegation workflow.
Provider questions to copy
"Can you show how this role is screened, trained, checked each week, and replaced if fit is poor?"
"Can we start with a small task list before we expand the role?"
FAQ
Should a virtual assistant answer every routine email?
Only when the message class, facts, and requested action fall within a documented authority rule. Otherwise the assistant should prepare or escalate it.
Can an authority matrix replace mailbox permissions?
No. The matrix explains operational authority; technical access should still use least privilege, delegated access, account controls, and documented offboarding.
What belongs in an inbox activity record?
Use a secure source reference, classification, owner, action level, deadline, status, and minimal exception note rather than copying sensitive message bodies.
Sources and notes
These sources are included as planning references. They do not replace legal, tax, security, or HR advice.
- CISA Secure Our World: Use Strong Passwords: Official account-security guidance, including multifactor authentication.
- US National Archives Email Management: Official resources for managing email records.