Account roles: personal, managed, receive-only
Every mail account stores a role and a control scope. Core
enforces those values on send. The same checks apply to the macOS
app, the primail CLI, and the primail-mcp stdio server. There is
no local mail REST listener.
The three roles
Section titled “The three roles”New accounts default to personal and all unless you pass another value at add time.
personal
Section titled “personal”The default. Read, compose, and send are allowed, subject to control scope.
managed
Section titled “managed”A stored role you can set and list. Core does not currently
stage a confirmation queue or block send for managed. Treat it as
a label until a later product change adds extra checks. Do not
assume an agent send from a managed account waits for a tap in the
app.
receive-only
Section titled “receive-only”Send is blocked on every interface. The error code is
send_blocked_receive_only. Typical uses: a no-reply monitoring
inbox, or an archive you never want to send from.
The GUI shows a short notice on the account page when the role is receive-only. It does not offer a role picker.
Control scopes
Section titled “Control scopes”Each account also stores a control scope:
| Scope | UI send | CLI / MCP send |
|---|---|---|
all (default) | Allowed | Allowed |
ui_only | Allowed | Blocked (send_blocked_scope) |
mcp_only | Blocked | Allowed |
Scope is checked on send (and on sender-identity resolve used
for send). It does not hide the account from account_list,
mailbox_list, or email_get. A ui_only inbox is still readable
from MCP.
The GUI shows a notice when scope is not all. It does not offer a
scope picker.
Changing a role or scope
Section titled “Changing a role or scope”Use CLI or MCP. Examples (ids are opaque; substitute your own):
primail account settings-update ACCOUNT_ID --role receive-onlyprimail account settings-update ACCOUNT_ID --control-scope ui-onlyMCP tool: account_settings_update with account_id plus role
(personal / managed / receive_only) and/or control_scope
(all / mcp_only / ui_only).
Role and scope are local to this device. They do not roam through a Primail cloud account.
See Add more email accounts and Control scopes & safety rails.