Why Understanding Admin Roles Matters When Managing Your Team’s Workspace
You just invited your first team member to Unifiedesk. You’re excited to get them set up — but do you know exactly what they’ll be able to do? Choosing between super admin and delegated admin isn’t just about permissions. It’s about who controls your data, who can change critical settings, and who’s accountable when things go wrong.
One misstep in role assignment can mean a user accidentally deletes a domain-wide policy, or worse — inherits access to everything. The difference between super admin and delegated admin isn’t just technical. It’s a design decision about control, risk, and clarity. This guide walks through real-world scenarios from Unifiedesk’s admin system to show you exactly how the two roles differ in practice. You’ll learn not just what each can do—but also when to use which.
Key takeaways
- Super admin has full control over all domains, users, settings, and integrations—ideal for initial setup and system-level changes.
- Delegated admin can manage only specific domains or workspaces they’re assigned to, reducing risk from overprivileged accounts.
- Role selection directly impacts accountability: delegated admin actions are tied to specific scopes, making audit trails clearer and errors easier to trace.
What Is a Super Admin in Unifiedesk?
Think of a super admin as the ultimate keyholder to your Unifiedesk instance—someone with full, unrestricted access to every setting, user, domain, and system configuration. They can create or delete accounts, reset passwords, manage domains, adjust encryption settings, and even access the server filesystem on self-hosted deployments. This level of control makes them essential—but also high-risk. You should limit this role to one or two trusted individuals with strong security awareness. For a more secure and scalable setup, consider using delegated admin roles instead.
Core Super Admin Capabilities
- Creates or deletes any user account across the entire domain or instance.
- Resets any user’s password without needing their old one.
- Manages all domains tied to the instance, including adding or removing them.
- Configures and modifies encryption settings, including E2E encryption policies for hosted deployments.
- Accesses the underlying server filesystem and modifies core configuration files on self-hosted deployments.
- Modifies system-level settings that affect all users, such as global authentication policies or service limits.
- Can view all logs and audit trails for every user and action taken within the instance.
Why Limit the Super Admin Role?
While powerful, this role is a single point of failure and a prime target for attackers. According to the CISA guide on access control, overprivileged accounts are a common entry point in breaches. With only one or two individuals having this access, you reduce exposure and improve accountability. Consider using delegated admin roles for day-to-day operations—those can be restricted to specific areas like user management or domain settings. This layered approach is a best practice recommended by OWASP in their Identity and Access Management guidelines.
For organizations running self-hosted Unifiedesk, the ability to access the system’s underlying infrastructure demands high-level technical expertise and security discipline. You can manage your entire workspace—from email and calendar to meetings, drive, and documents—all under a single, secure control point.
What Is a Delegated Admin in Unifiedesk?
You’re not giving full control when you set up a delegated admin in Unifiedesk. Instead, you grant precise, role-based access to specific tools—like calendars, shared drives, or group mailboxes—without letting them touch DNS, encryption settings, or other users’ private data. Every action they take is logged and tied to their account, so accountability stays clear. It’s a secure way to scale management without exposing the entire system.
What a delegated admin can do
- Manage calendars for teams or departments (learn more)—schedule, share, and adjust availability without access to other users’ personal data.
- Control Drive file shares and permissions for specific groups, but not alter encryption or delete data across the instance.
- Create, edit, or delete group mailboxes while being restricted from viewing inbox content outside their scope.
- Apply organizational policies only within their assigned domains or departments—no system-wide changes.
What a delegated admin cannot do
- Modify DNS records (like MX, SPF, DKIM, DMARC) — those are reserved for the super admin only, typically because they affect email deliverability and domain security [RFC 7208, SPF].
- Access or decrypt another user’s mailbox, calendar, or Drive data—even if they’re in the same organization.
- Change encryption settings or access the instance’s master key infrastructure, which remains under full control of the super admin.
- View or modify other administrators’ access rights or audit logs.
Let’s be clear: delegation isn’t a compromise on security—it’s a precision tool. You’re not handing over the keys; you’re giving someone a specific tool, for a limited job, with full traceability. All actions are logged in real time and visible in the audit trail, so you can always see who did what and when. This is how real teams scale securely, especially when you’re running your own domain with custom email setup or need internal controls for compliance.
Think of it like a kitchen: a chef might have full access to the prep station and oven, but they can’t open the cash register or change the security system. That’s how delegated admin works in Unifiedesk—control is scoped, accountability is preserved, and the system stays safe.
Super Admin vs Delegated Admin: The Core Difference in Action
Think of a super admin as the only person who can open the master vault — they control everything, including encryption keys in self-hosted setups. A delegated admin acts within strict boundaries set by the super admin and can’t see or change what’s outside their scope. Their actions are logged in full, so you always know who did what, when.
Scope Defines the Role
The difference isn’t just about what tasks they can perform — it’s about who can see what, and who’s accountable. A super admin in a self-hosted Unifiedesk deployment can reconfigure system encryption keys, reset other admins, or disable entire workspaces. That power is necessary for core system maintenance, but it also means their actions must be audited rigorously.
In contrast, a delegated admin — say, a team lead managing client calendar bookings — can only create events, assign shared mailboxes, or approve meeting invites within their team’s scope. They can’t access other teams’ data, change system-wide settings, or modify encryption. This is a safeguard, not a limitation.
Auditable, Boundary-Enforced Access
Every action a delegated admin takes is recorded in the admin log. You can check, for example, who scheduled an external meeting or modified a shared calendar’s permissions — and trace it back to that specific user. This is a best practice: organizations using a secure configuration model limit access by role, and enforce logging for accountability.
Let’s say your marketing team uses a shared mailbox for client outreach. You can give a delegated admin access to that mailbox and the team calendar — they can send emails, update appointments, and manage replies — without ever touching other departments, backups, or security settings. No risks. No surprises.
Unifiedesk supports this workflow through granular role assignments. You can assign delegates to manage specific teams, calendars, or Drive folders — all under the safety of defined boundaries. Security controls like this aren’t theoretical; they’re enforced at every layer, from access to audit trails.
You don’t need to trust an admin with the keys to everything. You need to trust that their actions are limited, transparent, and traceable. That’s how you run a private, compliant, and scalable workspace.
How to Assign Delegated Admin Roles in Unifiedesk
You can assign delegated admin roles in Unifiedesk by logging in as a super admin, navigating to Users & Roles, selecting a user, and assigning a pre-defined role like “Calendar Manager” or “Drive Coordinator.” The user will only get permissions tied to that role, and you can audit their actions at any time via the audit log. This keeps control granular and secure.
Step-by-step: Granting Delegated Access
- Log in as a super admin. Only users with super admin privileges can assign roles. This ensures that sensitive administrative actions are tracked and restricted to trusted individuals.
- Go to Users & Roles. In the admin panel, select the “Users & Roles” section from the sidebar. This centralizes user management and role assignment, following industry best practices for least-privilege access.
- Select the user to delegate. Find and click on the user’s name in the list. You’re now editing their access profile, so choose carefully — this step defines what they can do without full admin rights.
- Choose a predefined role. Under “Role,” pick a specific delegated role such as “Mailbox Administrator,” “Calendar Manager,” or “Drive Coordinator.” These roles are designed to grant only the necessary permissions, minimizing risk. For reference, the principle of least privilege is widely recommended in NIST SP 800-53, especially for access control in managed environments.
- Save your changes. Once selected, click “Save.” The user receives immediate access to only the resources and actions defined by their role — nothing more.
Review and audit activity
You can always check what a delegated admin has done through the audit log. This log records login attempts, permission changes, and file actions, giving full visibility. It’s a trusted way to spot anomalies and ensure accountability — and it’s built into every Unifiedesk deployment, whether hosted or self-hosted.
Delegated roles are ideal when you need someone to manage calendars without seeing emails, or to share files without changing account settings. You’re not giving away full control — you’re giving permission to a specific job. It’s a practical, scalable way to run a team securely, and it’s baked into Unifiedesk’s design from the start.
Can a Delegated Admin Become a Super Admin?
No, a delegated admin cannot become a super admin by themselves in Unifiedesk. Only a current super admin can reassign roles, ensuring no accidental or malicious privilege escalation. This design is intentional—it keeps access control predictable and secure.
Why Self-Promotion Is Blocked
Let’s be clear: in Unifiedesk, admins can’t promote themselves. That’s not a flaw—it’s a foundational security choice. If someone with delegated access could upgrade their own role, you’d have an open door for abuse, whether by accident or intent.
That’s why the system enforces role boundaries. A delegated admin can manage specific users, teams, or settings—but only the super admin can grant broader control. This aligns with the principle of least privilege, a common practice in secure system design.
How Access Is Actually Expanded
If a delegated admin needs higher access, they request it—typically through your internal workflow. The super admin reviews the request, verifies the need, and manually updates the role. It’s a simple but effective safeguard.
This process ensures accountability. You’re not trusting automation to make access decisions; you’re keeping control in people who understand your organization’s needs. You can track changes, audit them if needed, and revoke access at any time.
For reference, RFC 6402, the standard for role-based access control in email systems, emphasizes that permission changes should be explicit and traceable—exactly how Unifiedesk works.
Need more control over your team? Explore how Unifiedesk’s admin tools help you manage roles, custom domains, and team-wide settings securely. Learn more about security practices or get started with setting up your first domain in minutes.
When You Should Use Delegated Admins — Practical Use Cases
You should use delegated admins when you need to grant limited, role-specific access without exposing full system control. This keeps teams efficient while protecting your domain’s core security. Let’s look at real-world scenarios where delegated rights shine.
Project Teams That Need Calendar Control
- Let a team lead manage only project calendars and meeting invites. They can create, edit, and send invites without touching user accounts or domain settings. This aligns with the principle of least privilege.
- Use Unifiedesk’s calendar features to assign shared calendar access, keeping collaboration organized and contained.
IT Staff Managing Storage Without User Access
- Give IT staff access to shared drive folders—without access to user accounts or sensitive metadata. They can organize files, set retention rules, and manage team folders securely.
- With Unifiedesk’s Drive system, permissions are enforced at the folder level, and even file links can expire automatically.
- Storage admin access doesn't require full platform access—just the right set of controls.
Department Managers Overseeing Group Mailboxes
- A department head should be able to manage internal mailboxes like sales@ or support@—but not change MX records or user authentication settings. Delegated rights keep them in control of their workflow without risk.
- Unifiedesk allows you to assign mailbox-specific permissions while shielding the system-level configuration. It’s the right balance of autonomy and safety.
Helpdesk Agents Troubleshooting Mailflow
- Let helpdesk agents troubleshoot mail delivery issues—view logs, test forwarding rules, and verify queue status—without accessing domain DNS or user passwords.
- They can use tools like MXToolbox or RFC 5321 to diagnose delivery problems, but only within their authorized scope.
- This minimizes accidental misconfigurations and keeps the attack surface smaller.
Delegation isn’t about trust—it’s about precision. You’re not handing someone the keys to the whole system. You’re giving them the tools they need, where they need them, and nowhere else. This is how teams stay secure and agile at scale.
Why Self-Hosted Deployments Increase the Risk of Misuse
On self-hosted Unifiedesk, super admins have direct access to raw data storage and server logs — meaning they can view any user’s email, files, calendar entries, or messages if they choose to. Since your data lives on your own servers, a compromised or malicious super admin can extract information without any third-party visibility. That’s why limiting super admin roles to only those you trust deeply is not just a best practice — it’s essential for real security.
Higher Stakes with Local Data
When you self-host, your data isn’t just stored in the cloud — it’s on your physical hardware. No provider audit, no breach notification process, no third-party oversight. If a super admin account is leaked or abused, the impact is immediate and internal. Unlike cloud services where isolation and audit trails are enforced by default, your control comes with higher responsibility.
Industry guidance, like the NIST Cybersecurity Framework, emphasizes minimizing privileged access and enforcing least-privilege principles as a core defense line. You’re not just protecting emails — you’re protecting your entire infrastructure.
Delegated Admins Reduce Attack Surface
Instead of giving full super admin rights to everyone who needs to manage users, you can create delegated admins with precise permissions. A delegated admin might set up mailboxes or manage shared folders — but never view raw data or access logs.
This is where Unifiedesk’s granular role system shines. You can assign only the needed rights — like creating users or sharing files — while blocking access to sensitive areas. This reduces the attack surface dramatically. If an attacker compromises a delegated role, they can’t pivot to full system access.
And because everything is encrypted at rest with AES-256-GCM (using per-account keys), even if someone bypasses access controls, they can’t read data without the key — which only the user holds. That’s a hard boundary, not just a soft policy.
For teams that want full control but don’t need full power, self-hosting Unifiedesk gives you autonomy — but only if you treat admin access like a key to the vault. Never share it casually.
How Unifiedesk Enforces Role Limits Automatically
You can’t accidentally give a delegated admin super powers — Unifiedesk blocks every action outside their role at the API layer. No backdoors, no workarounds. Even if they try a custom script or direct API call, the system denies it. Every access attempt, successful or not, is logged with IP, timestamp, and action type, so you’re always auditable. This is how regulated industries stay compliant with GDPR, HIPAA, and similar standards.
What Happens When a Delegated Admin Tries to Go Beyond Their Role
- Every API request is evaluated against role-specific permissions before processing—no exceptions, no bypasses.
- Even with a valid token, a delegated admin cannot access super admin settings like domain-wide policies, user deletion, or backup recovery.
- Direct API calls or custom scripts that attempt to access restricted endpoints are rejected with a clear 403 Forbidden response.
- These rejections aren’t just logged—they’re timestamped and tied to the user, IP address, and request path for full traceability.
- Logging follows industry standards: RFC 5424 for structured syslog, which many compliance frameworks reference.
How This Supports Compliance in Practice
- You can prove in court or during audits that no user had access they shouldn’t have—because the system didn’t allow it.
- Role-based access control (RBAC) is enforced consistently, even when admins are granted partial privileges like managing only specific teams.
- Log data is stored securely and can be exported for review, aligning with audit requirements from EU Data Law and similar frameworks.
- Actions like resetting another user’s password or changing mailbox permissions are recorded exactly as they happen—no gaps.
- Even if someone shares their credentials, the system enforces role constraints based on who’s making the request, not just who owns the account.
Let’s be clear: roles aren’t just permissions in a menu. They’re enforced in code, at the network layer, and verified in logs. This isn’t an optional extra—it’s how unified and secure control works. If you manage multiple teams, or run a business needing strict access limits, this is how you keep things clean.
See how it fits into the full suite: email, calendar, Meet, Drive, and Documents all follow the same principle—access is limited, never assumed.
Can You Revoke Delegated Admin Access at Any Time?
Yes — you can revoke delegated admin access instantly, any time you need to. If someone no longer needs elevated permissions, or if you suspect misuse, just log in as super admin and remove their role. No waiting. No lingering access. Permissions update immediately across the system.
Here’s how it works in practice:
- Log in as super admin — access the admin dashboard using your highest-privilege account.
- Locate the user — go to the Users or Roles section and find the delegated admin in the list.
- Remove the role — click “Remove” or “Revoke” next to their role. No confirmation delay or grace period.
- Access ends immediately — the user loses all admin privileges as soon as the change is saved. No cache, no stale session.
Why this matters during team transitions
During employee offboarding or a role change, instant revocation is a critical control. You don’t want old permissions hanging around — even for a few hours. Unifiedesk’s model is designed so that when you remove a delegated role, it’s gone. No cleanup windows. No residual access.
Security standards like OWASP’s principle of least privilege emphasize that you should grant only the minimum access needed, and revoke it when no longer required. This is how you stay compliant in practice.
Let’s say a team lead leaves your company. You can remove their delegated admin rights in under a minute. No waiting for a backup, no manual session invalidation — it’s automatic and immediate.
Whether you’re using Unifiedesk’s hosted service or self-hosted deployment, this behavior holds true. In both cases, the system enforces real-time permission updates, not scheduled refreshes or stale cache windows.
Need to control access on your own domain? Unifiedesk lets you manage users and roles securely, with full visibility into who has what access. For granular control over team settings, try the security features in your account.
Conclusion: Choose the Right Admin Role for Control and Security
Super admin access should be reserved for essential tasks and guarded closely. Too many administrators with full control increase the risk of accidental or intentional misconfiguration.
Delegated admin roles let you distribute responsibilities without exposing your entire system. They’re designed for collaboration, not overreach — keeping your team productive while limiting risk.
In Unifiedesk, the admin structure prevents privilege creep. Roles are clearly defined, permissions are explicit, and accountability is built into every action. Assigning the right role from the start ensures your team’s data stays secure and your workflows remain efficient over time.
Keep reading
- Shared Inbox & Ticketing Features (complete guide)
- How to Set Up a Shared Support@ Mailbox for Your Small Team
- How to Create a Group Email Address Like info@ or sales@ in 2026
- What Is a Catch-All Email Address and Should You Use One?
- How to Set Up a Catch-All Address on a Custom Domain in 2026
Ready to put this into practice? Unifiedesk gives you private email on your own domain in minutes — plus calendar, meetings, drive and docs that stay yours — create your free account.
Frequently asked questions
Can a delegated admin delete a user account in Unifiedesk?
No — only a super admin can delete user accounts. Delegated admins lack this permission by design to prevent accidental or malicious removals.
What happens if a delegated admin’s credentials are compromised?
Only the actions within their assigned role can be performed. The attacker cannot access other users’ data or change system settings.
How many delegated admin roles can I create in Unifiedesk?
You can create as many as needed, each assigned to a specific role with limited access. There is no hard limit.
Do delegated admins see other users’ private data?
Only if explicitly granted. By default, delegated admins cannot see personal emails, files, or calendar events outside their assigned scope.
Can a delegated admin change the DNS settings for my domain?
No — DNS configuration (MX, SPF, DKIM, DMARC) is reserved for super admins only to maintain domain integrity and prevent mail abuse.
Is there a difference in admin roles between cloud and self-hosted Unifiedesk?
Yes — in self-hosted deployments, super admins have greater access to underlying server files and logs than in hosted mode, but role permissions still apply.
How do I know which admin role someone has?
Check the 'Users & Roles' section in the Unifiedesk admin panel. Each user’s assigned role is displayed next to their name.
Can a delegated admin access the AI assistant’s content?
Only if the AI assistant is configured to store data for that user and the admin is assigned relevant access — but never without explicit permission.
Why should I avoid giving super admin to multiple people?
It removes accountability and increases risk. If you have several super admins, it’s harder to track who made a change — especially in a security incident.
Can I change a super admin to a delegated admin later?
Yes — simply log in as another super admin, go to the user’s role, and reassign them to a delegated role.