SafeToOpenEmail Security Docs

SafeToOpen Browser Security

Overview: how Email Security is deployed and licensed

Add-ins, seats, how a mailbox becomes a licensed member with no activation link, workspaces, and what the console controls

Guide 1 of 7 · April 2026

SafeToOpen Email Security is an add-in inside the mail client: “SafeToOpen Email Verification” for Outlook (Microsoft 365) and “SafeToOpen Email Security” for Gmail (Google Workspace). It scores every message the user opens or asks about, checks sender authentication, links, attachments and impersonation, and reports what it finds to your Business Console. Rolling it out is two jobs, and both are silent for the user:

This guide explains the pieces that the platform guides rely on.

1. Seats and members#

Plus seatExecutive seat
ProtectionTrust score, sender authentication, link and attachment checks, phishing reportsEverything in Plus, plus Deeper Analysis on demand or enforced by policy, executive impersonation and writing-style checks, unlimited analyses
WhoEveryoneLeadership, finance, HR, anyone targeted by CEO fraud and invoice fraud
Where setPeople page: per member, CSV column, per Entra ID group, or per Google Group

A member is an email address on the People page. Members are added by hand, by CSV, by importing Entra ID groups (Microsoft 365) or by importing Google Groups (Google Workspace). Each member uses one seat of the chosen type. Seats are bought and adjusted in Settings → Plan & billing.

2. How a mailbox becomes licensed#

  1. The address is on the People page (added, imported or synced).
  2. The add-in is present in the user’s mail client (deployed by the admin, or installed by the user where you allow it).
  3. The first time the add-in opens it signs the user in silently: Outlook through Office single sign-on with their Microsoft 365 account, Gmail through their Google account. The address from that sign-in is matched to the member, the member becomes active and the seat is in use.
Note Because the match is on the signed-in address, the invitation email is optional. Switch it off in Settings when the admin deploys the add-in centrally; keep it on for people who install the add-in themselves, since the email tells them where to get it.

A member who is removed on the People page loses the add-in’s features at the next check, usually within a minute, and the seat is freed.

3. Workspaces#

Workspaces split an organisation into sites, departments or MSP client tenants. Each has its own policies and branding (guide 4), its own report inbox and alert recipients, and its own analysts who see only that workspace’s incidents. Members belong to one workspace or to the organisation default. Entra ID groups map to workspaces on import.

4. What the console controls#

PageWhat you do there
IncidentsUser reports, dangerous and suspicious verdicts, executive impersonation; triage, notes, status.
DashboardVolumes and trends per workspace.
PeopleMembers, seats, workspace, invite emails, Entra ID import, removal.
Microsoft 365Connect one or several Entra ID tenants, map groups to workspaces and seat types, choose whether imports email people.
Google WorkspaceConnect one or several Google Workspace domains through a service account, map Google Groups to workspaces and seat types, same switches as Microsoft 365.
WorkspacesCreate workspaces, report inbox, alert recipients, analysts, and policies and branding per workspace.
IntegrationsExport tokens, signed webhooks, SIEM formats and STIX for Email Security events.
Response actionsConnect Microsoft 365 and Entra ID; rules that junk a confirmed sender or lock down a compromised user, automatically or on Confirm. Gateway and EDR blocking of URLs lives in Browser Security, because email incidents carry a sender, not a link.
Activity logEvery administrative change with who and when.
SettingsOrganisation name, default report inbox, alert cadence, invite emails, plan and billing, seats, and administrator access: co-admins that follow a Microsoft 365 or Google group, and required SSO for administrators.

5. Administrator access#

Settings → Administrator access (plan owner). Choose a group in a connected Microsoft 365 or Google Workspace directory; its members become console co-admins and people who leave the group lose access at the next hourly sync, with manually added co-admins left alone (up to 25 co-admins). A second switch requires the organisation’s administrators to sign in with Microsoft or Google, refusing password sign-in; the console will not enable it until your own account has such a sign-in linked. Details and the MSP overview screen are in the Browser Security guide “MSP Operations”: https://plus.safetoopen.com/docs/browser-security/integrations/msp.html.

6. What the user sees#

A button in the Outlook ribbon or reading pane (“Verify Email”, or the name you set), and a side panel in Gmail. The panel shows your organisation’s logo and name, the trust score and reasons, and the actions your policy allows. Settings that your policy enforces are shown but cannot be changed, with a note that the organisation manages them.

7. Verifying a deployment#

  1. The add-in appears in the user’s client without them doing anything (Outlook: within 24 hours of the Integrated apps deployment, often sooner; Gmail: at the next Gmail load).
  2. Opening it shows your organisation’s branding and no sign-in prompt.
  3. The People page shows the member as active with a “joined” time.
  4. A test message reported from the add-in appears on the Incidents page within a minute.

8. Which guide next#