Task Management

Gmail Delegate Access: Complete Guide for VAs and EAs (2026)

Tayyab6 min read
Gmail Delegate Access: Complete Guide for VAs and EAs (2026)
The short answer
Gmail delegate access lets you grant someone the ability to read and reply to your Gmail without sharing your password. The delegate signs in with their own Google account and switches into yours from their profile menu. Set it up under Gmail Settings, Accounts and Import, Grant access to your account. Delegates cannot change your password or account settings and cannot see your chat history.
Key takeaways
  • 01Gmail delegate access replaces password sharing entirely for most VA-client relationships.
  • 02Delegates send email from your address, but every message is logged as sent by them for audit.
  • 03Delegates cannot change your password, security settings, or read your Google Chats.
  • 04Setup takes under 5 minutes but only works on personal Gmail and Google Workspace accounts.

This guide is part of our broader coverage of task management for Virtual Assistants and Executive Assistants.

Why VAs and EAs use Gmail delegate access instead of sharing a password

Sharing a Gmail password with a Virtual Assistant sounds simple until it breaks. Google flags the new sign-in as suspicious and locks the account. Two-factor codes go to the wrong phone. When the working relationship ends, changing the password means updating every other login that used the same one.

Delegate access solves all of that. Your VA gets read and reply permission on your inbox without ever knowing your password. If they leave, you remove them in two clicks. Every email they send from your address is logged in the message header so your compliance team, if you have one, can audit it.

How to set up Gmail delegate access

  1. Open Gmail in a browser (not the mobile app).
  2. Click the gear icon in the top right, then See all settings.
  3. Go to the Accounts and Import tab.
  4. Under Grant access to your account, click Add another account.
  5. Enter the Gmail address of your VA. It must be a Gmail or Google Workspace address.
  6. Choose whether the sender line reads "sent by [VA] on behalf of [you]" or just "[you]". The first option is more transparent; the second reads cleaner but hides the delegation.
  7. Your VA receives an email with a confirmation link and has to click it within 7 days.

Once confirmed, your VA opens their own Gmail, clicks their profile picture in the top right, and selects your account from the list.

What delegates can and cannot do

Delegates can:

  • Read every email in your inbox
  • Reply to email from your address
  • Send new email from your address
  • Delete email
  • Manage labels and filters

Delegates cannot:

  • Change your password
  • Change your two-factor authentication or recovery email
  • Read your Google Chats
  • Access your Drive, Calendar, or other Google services (unless separately shared)
  • Set up further delegates on your account

Common pitfalls

The mobile problem. Gmail delegate access only works in the web browser. If your VA needs mobile access for after-hours triage, delegation alone is not enough. Either grant full account access via Workspace, or accept that mobile triage will not happen.

The tone problem. Even with delegate access set up cleanly, most VAs and EAs still spend real time rereading old threads to match the client's tone before hitting send. This is the actual bottleneck once access is solved. Tools like Replyf live inside Gmail and generate replies in the client's voice from past sent mail, which cuts the per-email time from several minutes to under thirty seconds.

The "on behalf of" header. External recipients see either "your VA (va@yourva.com) on behalf of you (you@yourcompany.com)" or just "you (you@yourcompany.com)", depending on which option you picked at setup. Some clients want the visible delegation for legal reasons. Others want it hidden so clients feel they are hearing directly from the founder. Pick deliberately.

When delegate access is not enough

For accounts with more than one VA, or for VAs and EAs who need mobile access, Google Workspace with role-based inbox management works better. For very light delegation (one person, one client, occasional email), delegate access is the right tool. For anything more complex, look at shared mailbox tools like Front, Missive, or Google Workspace's own multi-send features.

If the constraint you keep hitting is not the access itself but the time cost of writing tone-matched replies, that is a different problem, and one that Gmail delegation alone does not solve. That's exactly the gap Replyf was built for.

Security hygiene when using Gmail delegation

Delegation is safer than password sharing, but it is not zero-risk. A few practices most experienced VAs and EAs adopt:

  • Turn on two-factor authentication on your VA account before requesting delegation. Some clients require it. All should.
  • Use a distinct Google account for VA work, not your personal Gmail. Keeps delegation neatly scoped and makes offboarding at end-of-engagement clean.
  • Do not delegate to a Gmail address you share with anyone else. Even a spouse. Delegation grants full send-as capability on the client's behalf.
  • Ask the client to review their Google security page monthly. They can see every account that has delegate access. Regular audits catch anything unusual early.

Onboarding a new client to delegate access

The setup takes fifteen minutes if you know the steps, sixty if you do not. Send the client a short walkthrough before your first call. Most delegate-access setup calls that go sideways go sideways because the client is trying to grant access from a Google Workspace admin account that has admin restrictions on delegation. Rule that out upfront.

The specific sequence to send the client:

  1. Confirm they are logged into the exact Gmail account they want you to manage (not a personal secondary account).
  2. Go to Settings, See all settings, Accounts and Import, Grant access to your account.
  3. Add your VA/EA email address.
  4. Choose "Mark conversation as read when opened by others" (yes) and "Show your delegate's email address in the sender line" (usually yes for transparency, sometimes no if the client wants the delegation invisible).
  5. Send the invite. You accept from your own Gmail.

Cost of getting this wrong at onboarding: two weeks of the client thinking you are unresponsive because you never actually gained access. Do a test email in both directions on day one.

Once delegate access is set up, the real day-to-day work is triaging what lands. Our guide on reaching Inbox Zero in Gmail covers the twice-a-day workflow most experienced VAs and EAs settle on. If storage becomes a problem across the accounts you delegate into, the fixes are in our guide on how to clean up Gmail storage. The deeper question of how to decide what counts as urgent across multiple client inboxes is covered on our pillar guide: task management for VAs and EAs.

Auditing delegate access as roles change

Delegate access setup is one-time work. Delegate access hygiene is ongoing. Two audits every working VA or EA should run quarterly.

The delegate access audit. In the client's Gmail: Settings → Accounts and Import → Grant access to your account. Every listed email address should be currently authorized. Remove any former VAs, EAs, or assistants who have moved on. This is the single most common oversight in executive support. Old assistants often retain live inbox access for months or years after ending the engagement because nobody revoked it.

The sent-mail audit. Delegate access adds a "sent by [assistant] on behalf of [executive]" line to every message you send from the client's account. Most executives never see this because the sender line is stripped in most inbox clients. Once a quarter, log into the client's own Sent folder and verify recent messages show the sender line correctly. If they do not, the delegation permissions may have shifted (Google occasionally updates the defaults, and enterprise Workspace admins can override individual settings).

Offboarding checklist for engagement wrap-up. When ending a client engagement, do all three: revoke your own delegate access from the client's settings panel, remove any Gmail filters you created in the client's account, and delete the Chrome profile associated with that client so no cached credentials remain locally. This 5-minute checklist is standard professional hygiene and prevents post-engagement liability.

FAQ

Frequently asked

No. Delegate access is granted from your Gmail settings and never exposes your password. The delegate signs in with their own Google account and switches into yours through the profile menu.
No. Delegates cannot change your password, two-factor settings, recovery email, or any account-level settings. They can only read, send, and delete email.
Personal @gmail.com accounts can add up to 10 delegates. Google Workspace accounts can add up to 1,000, though typically only around 40 can access the mailbox at the same time before performance degrades.
No. Delegate access only works in the Gmail web interface. If your VA needs mobile access to your inbox, use Google Workspace with a shared or full-account approach instead.
No. Delegate access is Gmail-only. Chat, Meet, Drive, and Calendar are not shared through this setting.
Go to Gmail Settings, Accounts and Import, find the delegate email under Grant access to your account, and click Delete.
Tayyab
Written by
Tayyab

Hi, I'm Tayyab. I built VAToolstack after seeing solo VAs struggle to manage multiple client inboxes efficiently. I also built Replyf.app, an AI email tool that writes replies in your client's tone.

More reading

Related guides

Stay in the loop

One email a week, practical stuff.