Zoho CRM: Enhanced Access Controls and Authentication for Organization Emails

Enhanced Access Controls and Smoother Authentication for Organization Emails

Organization emails in Zoho CRM are used when multiple users need to send from a common address, such as sales@company.com or support@company.com. Admins set these shared emails up and decide who can use them, and this has now been significantly improved across permissions, authentication, and custom function support.

More Flexible User Permissions

Previously, admins could only assign a shared email address to users based on Profiles, which made things complicated for large or multi-region teams. An organisation operating across multiple teams or locations, each with its own shared mailbox, would have needed a separate profile per region just to manage email access, a messy and hard-to-maintain approach.

Admins can now assign access with far more precision. Alongside Profiles, you can also choose:

  • Individual users
  • Roles
  • User groups
  • Territories

When adding a new organisation email, the Select Users section now lets you pick from all of these categories, so the permission type can match how your team is actually structured, rather than forcing everything through Profiles alone.

A Smoother, Guided Authentication Process

Setup progress used to be shown across two separate status columns. A new, unified status column combines this into one clear view, reducing information overload and showing exactly what matters at each step:

  • Verification required. The email has been added, but ownership hasn't been confirmed yet. Enter the verification code sent to that mailbox.
  • Authentication pending. Verification is done, but the mailbox still needs authenticating via the correct method, such as OAuth or SMTP.
  • Authentication required. Verification is complete, but authentication isn't finished; the email can't be used until this step is completed.
  • Authenticated. Both verification and authentication are complete. The shared email is fully active and ready for use by its assigned users.

This linear flow makes setup easier to follow and ensures nothing gets missed along the way.

Using Authenticated Organization Emails in Custom Functions

Previously, if a custom function needed to send an email, the sender address had to be manually verified and authenticated by contacting Zoho support directly.

Now, admins can simply add the sender address as an organisation email address. Once it's authenticated (with at least DKIM authentication), it can be used as the sender address for emails sent from custom functions, with no need to involve support at all.

Related change: To support this, the Accessible To field is now optional when adding an organisation email address. This lets admins authenticate an organisation email purely for custom function use, even if it was never intended to be shared with other users as a sending address.

What This Means Overall

Together, these changes give admins finer control over who can use a shared email address, a clearer, guided status flow for authentication, and the ability to use authenticated organisation email addresses directly in custom functions without a support ticket. For large teams and multi-region organisations in particular, this makes managing shared emails at scale considerably simpler.

Need help? 1 Cloud Consultants can help you set up organisation emails in Zoho CRM, including permission structures for multi-region teams and authenticated sender addresses for custom functions. Book a discovery call with 1 Cloud Consultants.