Shared mailbox retention: why sales@, support@ and ap@ are records
Shared mailbox retention means deciding how long role inboxes such as ap@ and support@ are kept, because they hold complete workflows that personal inboxes do not. MSPs and finance advisors should list them, sign off keep or discard with the owner, preserve before purging, and describe them only at a high level.
Why are shared mailboxes worth keeping as records?
Role mailboxes such as sales@, support@, ap@ and orders@ hold complete workflows, not just messages: a vendor dispute from first complaint to credit memo, an invoice query through approval, a customer escalation through apology and fix. Personal inboxes mix that with scheduling and small talk. Because many people read and reply from the same address, a shared mailbox also records how the company handles a task, not how one person does.
For an MSP or finance advisor, that makes role mailboxes the first thing to protect when a client trims licenses, offboards staff or changes tenants. A company with 50+ full-time employees at peak (contractors excluded) and years of role-mailbox history may hold material that AI developers license. SourceX assesses it; you only introduce.
What does a shared mailbox hold, and how useful is it?
| Mailbox | Typical contents | Why the history is useful |
|---|---|---|
| ap@ | Vendor invoices, payment queries, remittance threads | Approval and exception patterns in procure-to-pay |
| ar@ or billing@ | Dunning, disputes, payment promises | Collections workflows with outcomes |
| support@ | Customer problems and replies | Resolution paths, tone and escalation |
| sales@ and quotes@ | Inbound enquiries, pricing responses | Deal progression and objection handling |
| orders@ and dispatch@ | Order changes, delivery issues | Operational exceptions and fixes |
| hr@ and payroll@ | Employee matters | Usually excluded as sensitive |
The finance and operations mailboxes are the most structured. HR, legal and payroll mailboxes are normally kept out of scope because of employee privacy.
How should an MSP keep role mailboxes?
Keep them as a separate decision from license cost. Tenants may convert departed users' mailboxes to shared mailboxes, delete inactive ones, or apply a short retention rule without anyone checking what is inside.
- List every shared and converted mailbox with its owner, size and oldest item.
- Tag each as keep, review or discard, with the business owner signing off.
- Check holds first. Confirm with the company that no legal or regulatory hold applies before any deletion rule is changed.
- Preserve before you purge. Export or place an archive copy of keepers in a location the company controls.
- Document the policy so a future admin does not clean it up by accident.
- Do not read the content. Inventory counts and date ranges are enough.
For the chat equivalent, see Slack retention policy; the same decision order applies.
How do you describe a mailbox at a high level in a referral?
Say what exists, never what it says. Use facts such as the mailbox purpose, years covered, rough monthly volume and whether it has been continuously maintained.
Illustrative wording for a referral note:
Do not quote vendors, amounts, names or message text. Those are confidential records, and partners never export, upload or describe them.
What are the rights questions?
Role mailboxes hold third-party content: vendors, customers and staff. Whether a company can license its mailbox history depends on contracts, notices and redaction, which the company decides with its own counsel before any work begins. FTC staff have stated that a company's promises not to use customer data for undisclosed purposes, such as training models, are enforceable, as set out in the FTC's staff note on privacy and confidentiality commitments. This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
Mailboxes that mostly handle client data on behalf of other companies, such as an outsourcer's per-client queues, are a red flag.
What does a mailbox screen look like in practice?
Use three questions per mailbox, answered by the business owner rather than by reading mail.
- Has the address been in continuous use for at least several years?
- Do threads usually reach an outcome (paid, refunded, shipped, resolved)?
- Is the content the company's own, not a client's?
Illustrative: a fictional 180-person wholesaler converts the mailboxes of three departed finance staff to shared mailboxes during a license clean-up. The MSP lists them, the controller marks ap@ and billing@ as keepers, and the owner asks IT to export both before the tenant move. The MSP never opens a message.
When should you raise it?
| Moment | What to say |
|---|---|
| Tenant migration or consolidation | "Which shared mailboxes are we carrying over, and which will be dropped?" |
| License or cost clean-up | "Let's pause on converted mailboxes until the owner decides." |
| Finance outsourcing or CFO change | "ap@ history may move; see the accounting transition guide." |
| ERP go-live | "Before the project team leaves, confirm which mailboxes feed the old system; see after hypercare." |
| Wind-down or sale | "Preserve first; see winding down without losing records." |
What are the limits of a mailbox archive?
Email threads lose context when attachments are stripped, when threading breaks during export, or when an address was reused for different purposes over the years. Ask the business owner whether the address was ever repurposed, whether attachments are included in any archive, and whether the mailbox fed a ticketing or ERP workflow that holds the other half of the story. A mailbox with intact threads, attachments and outcomes is worth far more than a bare list of subject lines, and the difference is usually decided at the moment of export.
How do rewards work for MSPs and advisors?
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; an introduction, meeting or signed agreement alone does not trigger payment, and no reward is guaranteed.
Review your client contracts and your own professional rules before accepting any referral reward. Licensed advisors should confirm their position with their regulator or body. Read the program terms and the page for managed service providers.
When is it not worth the effort?
- The mailboxes are already deleted or were only ever personal.
- The company never reached 50+ full-time employees at peak (contractors excluded), or the mailbox history covers under a couple of years.
- Most of the mail is client-owned or regulated personal data with no basis for use.
- A court, trustee or assignee controls the tenant and has not been involved.
Next step
Pick one client with a tenant change coming and list its shared mailboxes. If it passes the who qualifies baseline, register as a partner and introduce it, or send the owner to sourcex.si/apply. The introduction email builder drafts the owner note.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
What is a shared mailbox retention policy?
It is a written rule about how long role-based mailboxes such as ap@ or support@ are kept, who can delete from them and when they are archived. It should name a business owner, a retention period per mailbox and the process for legal holds, instead of inheriting a tenant-wide default.
Are shared mailboxes more valuable than personal inboxes?
Often for workflow content, because they capture whole processes with several people involved and less personal chatter. They are not automatically licensable. Rights, third-party content and redaction decide that, and the company reviews them with its counsel and SourceX.
What happens to a mailbox when a user leaves?
It depends on tenant settings. Common outcomes are conversion to a shared mailbox, deletion after a grace period, or archiving. Check your tenant's current retention settings and vendor documentation rather than assuming a default, and ask the business owner before any removal.
Can I tell SourceX what is in the mailbox?
Only at a high level: purpose, years covered and approximate volume. Partners give basic fit information and never export, upload or describe confidential content. The company completes its own data inventory once qualified.
Should HR or legal mailboxes ever be included?
Usually not. They concentrate employee and privileged matters, and companies normally exclude them. Any scope is decided by the company with its counsel, and redaction or exclusion is agreed before any work begins.
Related pages
- Slack retention policy best practice: decide before the first purge
- Outsourcing accounting: what happens to the in-house finance records?
- What happens after ERP hypercare, and why it is the last good moment to find old records
- How to wind down a company: an orderly plan that keeps the records
- Referral opportunities for managed service providers
- Which US businesses are a fit for a SourceX data licensing introduction
Free resources
- MOIC calculator — Multiple on invested capital from realized and unrealized value.
- PDF bank statement to CSV converter — Turn Chase, Bank of America or Wells Fargo PDF statements into CSV, privately in your browser.
- Client data licensing eligibility checker — A transparent preliminary screen for one company.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment