Why Delegation Beats Sharing Your Password
Google Workspace email delegation gives your VA access to your inbox under their own login credentials, with no password sharing required. You grant it, you revoke it, and every action your VA takes is traceable back to their account.
The alternative, handing over your Google account password, breaks two-factor authentication, creates an untracked access trail, and leaves you in a bad position if you need to revoke access quickly. Delegation is how Google designed team inbox management to work. Use it.
Delegates can read your email, reply on your behalf, archive, delete, label, and manage filters. They cannot change your password, access your Google Chat, or modify account settings. Those boundaries are enforced by Google, not just by trust.
Three Ways to Share Your Google Workspace Inbox With a VA
Before setting anything up, it helps to know which access method fits your situation. There are three practical options:
| Method | How it works | Best for | Limitations |
|---|---|---|---|
| Gmail inbox delegation | Your VA accesses your actual inbox under their own login | Founders delegating a primary business email to one VA | Recipients see "on behalf of" in the From line |
| Shared inbox | Create a dedicated address (ops@yourco.com), delegate it to your VA | Client-facing, team, or support inboxes with multiple senders | Requires a Workspace seat or alias to set up |
| Email forwarding | Copies of incoming mail go to your VA's address automatically | Read-only review and flagging | VA cannot reply as your address; creates duplicate inboxes |
For most founders handing an inbox to one VA, built-in Gmail delegation is the right choice. It is simpler, keeps a clear chain of custody, and lets your VA work directly from your address without an extra account.
A shared inbox makes more sense when multiple people (you, a VA, a backup assistant) all need consistent send-as access from one address, for example a support@ or operations@ inbox.
Email forwarding is the weakest option for an active assistant. It creates a read-only copy, which means your VA cannot reply without switching accounts. Reserve it for monitoring, not managing.
Step 1: Enable Email Delegation in the Google Workspace Admin Console
Your VA cannot be added as a delegate until an admin enables the setting at the domain level. If you are the Google Workspace admin for your organization (common in companies under 20 people), this is a one-time setup.
- Sign in to the Google Admin Console at admin.google.com.
- Go to Apps > Google Workspace > Gmail.
- Click User settings.
- Scroll down to the Mail delegation section.
- Check Let users delegate access to their mailbox.
- Click Save.
The change propagates to all users in the organization within a few minutes. If you only want to enable delegation for a specific team or group, apply the setting to an organizational unit rather than the entire domain before saving.
One optional setting in this section: you can choose whether to let delegates see the account owner's name in the From header. Leaving this on means recipients know an assistant sent the email on someone's behalf, which is the more transparent default.
If you are not the admin and your admin has not enabled this setting, you will not see the delegation option in your Gmail account settings. Ask your IT contact or Workspace admin to flip it before you proceed.
Step 2: Add Your VA as a Gmail Delegate
Once delegation is enabled at the admin level, you set up your VA from within your own Gmail account. No Admin Console access required for this step.
- Open Gmail and click the gear icon in the top right, then See all settings.
- Click the Accounts and Import tab (sometimes labeled just Accounts depending on your Workspace version).
- Find the Grant access to your account section and click Add another account.
- Enter your VA's full email address (their Google Workspace or Gmail address).
- Click Next Step.
- Click Send email to grant access.
Your VA will receive an invitation email at the address you entered. They need to click the Accept link in that email before they can access your inbox. The invitation expires after seven days. If your VA misses it, send another invitation from the same settings page.
Once your VA accepts, they sign into their own Gmail account and switch to your inbox by clicking their profile avatar in the top right corner. Any Workspace or Gmail account they use can have multiple inboxes open at once through this switcher.
Google Workspace business accounts support up to 1,000 unique delegates per inbox (Google expanded the limit from 25 in January 2021), with up to 40 able to access the account concurrently. For most founder or executive inboxes, one or two active delegates is the practical limit before managing who sent what becomes its own overhead.
What Your VA Can and Cannot Do as a Delegate
Delegation gives your VA full read and write access to your Gmail inbox, but nothing beyond it. They can read, reply, send, archive, and label emails on your behalf. They cannot touch your account settings, change your password, access Google Chat, or reach Drive and Calendar without separate permissions.
| Your VA can do | Your VA cannot do |
|---|---|
| Read all emails, including older threads | Change your Gmail password |
| Reply, forward, or compose emails as you | Modify Gmail account settings or filters you set |
| Archive, delete, and label messages | Access your Google Chat conversations |
| Create filters and manage labels | Change account recovery info |
| Mark messages as read or unread | Access Google Drive, Calendar, or other Workspace apps (separate permissions) |
| Access your Sent, Drafts, and Trash folders | Send emails without "on behalf of" appearing to recipients |
The "on behalf of" notation appears in the recipient's email client when your VA sends a reply. In your own Sent folder, the message looks like you sent it. Most professional recipients recognize that assistants send on behalf of executives, so this is rarely an issue.
Calendar and Drive access are entirely separate from email delegation. If your VA needs those too, set them up independently: Calendar via Settings > Share with specific people, and Drive via folder-level sharing or Shared Drives.
Security Setup Before Your VA Touches the First Email
Giving inbox access is a significant trust step. Four things to have in place before your VA starts:
Enable 2-Step Verification on both accounts. Your account needs 2SV active regardless of whether you use delegation. Your VA's account should have it too. This is the baseline. If 2SV is not on, resolve that first.
Sign a confidentiality agreement. Your inbox contains client names, financial data, legal correspondence, unreleased product information, and personal messages. A signed NDA or data handling agreement is not a legal formality, it is what makes the relationship professionally structured. Include a clause covering email access specifically.
Define a written list of what your VA cannot send independently. Before day one, write down the categories of reply your VA must route to you rather than send: contracts and pricing, anything to a new prospect who has not yet signed, legal correspondence, anything involving conflict or complaint escalation. Keep this list in your shared workspace so it is not something your VA has to guess at.
Schedule a monthly access review. In Gmail settings under Accounts and Import, your current delegates are listed. Build a 10-minute monthly check into your calendar to confirm the list is current, especially after any contractor changes. When a VA's engagement ends, remove them from the list that day.
The Briefing Your VA Actually Needs (Most Setup Guides Skip This)
The technical setup takes about 10 minutes. What makes inbox delegation actually work over weeks and months is the briefing conversation you have before the first email gets touched. This is the part most guides skip.
Your labeling and folder system. Walk your VA through every label you currently use. If you do not have a labeling system, build one now, ideally together. A working baseline: Action Needed, Waiting on Reply, Finance, Clients, Read Later. Your VA should apply labels before acting on any email. This creates a shared visual system you can both navigate.
Priority senders. Name the 10 to 15 contacts who always get a response within a few hours. Board members, investors, top clients, key vendors, your accountant. Give your VA a written list. Everything else falls into a daily review batch that they can process on a schedule.
Draft versus send authority. Be explicit about which categories of reply your VA can send directly, and which must come back to you as a draft first. A practical rule that works for many founders: your VA sends directly to known internal contacts and low-stakes recurring emails (scheduling, admin confirmations, known vendors). They draft everything to new contacts, clients, and anyone with financial or legal authority.
Handling sensitive emails. Client complaints, legal correspondence, financial requests, anything from media or press. Your VA should surface these to you with a one-paragraph summary and a suggested next action, not attempt a reply. Make this the default until you have enough shared history to trust their judgement on specific categories.
Response templates for recurring emails. If you send the same type of reply more than twice a week (meeting confirmations, referral responses, vendor follow-ups, sponsorship declines), build a template with your VA in the first week. Templates reduce decision fatigue, keep your voice consistent, and let your VA move faster without asking you each time.
This briefing takes 30 to 45 minutes. Write the rules down in a shared document and link to it inside your VA's onboarding checklist. For a broader onboarding structure, see how to onboard and manage a remote virtual assistant for maximum productivity.
How an AI-Trained VA Gets More Out of This Setup
The Google Workspace delegation configuration is identical whether you hire a standard VA or an AI-trained virtual assistant. The difference appears in what they do with the access. A regular VA reads and acts on emails one at a time. An AI-trained VA builds triage and drafting systems that handle much higher volume without proportionally more hours.
A standard VA reads emails and acts on them individually. An AI-trained VA builds systems on top of the access: filters that auto-label by sender or keyword, AI-assisted triage workflows that surface urgent items first, and draft-assist tools that let them write responses in your voice faster and with fewer iterations.
In practice, this means a founder can hand over a backlog of several hundred unread emails to an AI-trained VA and expect a processed, labeled, and summarized inbox back within a working day. The same task given to a VA without AI tools and workflow training takes significantly longer and produces inconsistent results.
Every VA placed by Delegated AI graduates from the Delegated AI Academy, where they train on practical AI workflows before meeting any client. For inbox management specifically, that training covers building Gmail filter systems, drafting with AI assistance at scale, and maintaining a consistent inbox-zero workflow across multiple principals.
That training background is the reason clients see different output per hour compared to a generalist VA hired from a marketplace. The technical setup is the same. The execution is not.
If you are deciding what else to hand off alongside inbox management, the breakdown in what virtual assistants handle best covers the 10 tasks that move the needle for most founders. For email marketing specifically, see virtual assistant email marketing for how to extend inbox delegation into campaign management.
Revoking Access and Offboarding
When a VA's engagement ends, remove inbox access the same day. This takes less than a minute.
- Open Gmail > gear icon > See all settings > Accounts and Import.
- Under Grant access to your account, find the delegate's email address.
- Click delete next to their name.
Revocation is immediate. Your VA loses inbox access the moment you save the change.
If your VA also had access to shared drives, calendar, or other Workspace apps, those permissions need to be removed separately. Drive access is managed at the folder level or via Shared Drive settings. Calendar access is under Calendar Settings > Share with specific people.
For a full account suspension (when the VA has their own Workspace account under your domain), go to the Admin Console > Directory > Users, find the account, and choose Suspend user. This disables their access across all Google apps instantly and preserves their data for 20 days before it requires deletion. Suspension is the cleanest offboarding action for Workspace accounts you control.
Frequently Asked Questions
Does my VA need a Google Workspace account to be a delegate?
No. A personal Gmail address can be added as a delegate on a Workspace inbox. If your Admin Console restricts delegation to accounts within your domain only, your VA will need a Workspace account on your domain or one in a domain your admin has approved for external delegation.
Can my VA send emails that look like they came from me?
The From line shows your name, but recipients typically see a "sent on behalf of" notation alongside your VA's address. The exact display depends on the recipient's email client. In most professional contexts, this is expected and unremarkable. Your own Sent folder records the message as if you sent it.
How many delegates can I add to a Google Workspace inbox?
Google Workspace business accounts support up to 1,000 unique delegates (Google expanded the limit from 25 in January 2021; up to 40 can access the account concurrently). Personal Gmail accounts support up to 10. For most founder or executive inboxes, one or two active delegates is the practical limit. More than that and managing who sent what becomes its own problem.
Is Gmail delegation secure for confidential business email?
Yes, when configured correctly. Delegation avoids password sharing, uses Google's own access controls, and creates a traceable action record. Pair it with a signed confidentiality agreement, 2-Step Verification on both accounts, and a clear written list of what your VA cannot send without your approval.
Can I limit which folders my VA can see?
Built-in Gmail delegation gives access to the full inbox, including Sent, Drafts, and Trash. There is no folder-level restriction within native Gmail delegation. If you need more granular access control (for example, limiting access to one specific label or project folder only), a dedicated shared inbox for that project is the cleaner approach.
What is the difference between Gmail delegation and sharing a Google account?
Delegation gives your VA access through their own login, so your account's 2FA stays intact and access is revocable without changing your password. Sharing a Google account means giving out your password, which disables 2FA for that session, creates no audit trail, and requires a password change to revoke access. Delegation is always the right choice for a professional arrangement.

