> ## Documentation Index
>
> Fetch the complete documentation index at: https://lithi.ai/llms.txt
>
> Use this file to discover all available pages before exploring further.

Manage your organization and Macs by checking the current device, account, and local setup separately. This guide helps you review bounded evidence, handle changes through the approved path, and avoid treating a label as organization-wide access.

## Know the organization boundary

The portal is the administration surface for team metadata such as license and seat status, team membership, approved devices, billing summaries, and redacted support or receipt metadata. EmailOS is the customer product on the Mac: it handles local inbox work and connected-account setup there. The portal does not broaden what EmailOS may read, and a portal record does not prove that a local connection is ready.

Keep the boundaries visible. A team name, license, seat, or device entry can describe intended administration scope. It does not authorize inspection of another person's inbox, draft, connected account, or provider record. Local consent and the connection's own scope still apply.

## Start with this Mac's evidence

The current Team area is an honest single-Mac view. It can show the role resolved for the person using this Mac, the local plan or license state that the app can verify, and a bounded capability preview. It cannot honestly show a current people roster, other people's roles, or organization-wide assignments.

There is no live signed organization-role projection transport from the portal into EmailOS today. A blank roster is therefore not a missing value to fill in. Do not infer that someone is an Owner, Admin, IT, Security Admin, Manager, HR, Finance, Member, or Viewer because a label appears in a document, an old local row, or an example. The descriptive roles reference explains terminology; it is not live administration evidence.

Use the smallest record that supports your conclusion: the visible local role or plan state, device or account name, displayed action or status, and date checked. Keep private mail, draft text, credentials, and raw provider data out of tickets and team notes.

## Add a Mac with a bounded check

When your organization's approved administration surface presents a device-add or activation step, prepare the intended team, account, and Mac first. Record only the metadata needed for the check. Confirm the device, account, organization context, and displayed scope before continuing.

Then complete local setup: open EmailOS, sign in with the intended team email, and follow its activation or connection controls. Add one approved account or resource at a time. Read provider permissions and grant only resources needed for reply context. A successful save or device row is not proof that a connected resource is ready.

If the approved control does not show an add or activation action, stop at the visible state. Do not invent a device ID, assign a role locally, or treat an invitation or catalogue entry as a live projection. Ask the responsible owner or administrator which current process supplies the missing evidence.

## Review or remove a Mac safely

Review a device when its owner, account, purpose, scope, or local setup changes. Compare its record with the Mac's visible state and intended organization boundary. If evidence conflicts, pause the affected workflow; do not choose the more permissive interpretation.

When a Mac should stop participating, use the approved owner or administrator process to remove or deactivate its device record, then use EmailOS's local connection controls to disconnect resources that should no longer be used. Check any other Mac separately because local connection state is not automatically evidence about the rest of the organization.

Removal from a list, closing the app, or deleting a local shortcut is not by itself proof that access has been revoked everywhere. Wait for the authoritative status and scope to show the intended result before relying on a connection again. Keep a bounded record of what was changed and when, without copying private content.

## Resolve a blocked change

If only one Mac is visible, review that Mac without inferring a wider roster. If setup waits, reopen EmailOS and follow the named local step. If a person or Mac should be removed, use the approved owner path and verify the resulting status.

