Security boundary
Google remains authoritative for mail, access, membership, roles, replies, notifications, aliases, retention and audit history. The Chrome Web Store package contains no CRM, fictional inbox, Google API client, OAuth scope, remote code, telemetry, analytics, advertising, webhook or network service operated by Collabma developers.
Minimal access
storagekeeps consent and view preferences plus a timestamp for sign in changes that does not identify anyone; administrator policy is read only.identityandidentity.emailprovide the primary Chrome profile email for exact Workspace domain validation. No OAuth token is requested.- The content script matches only
https://groups.google.com/*.
There are no optional permissions, broad host permissions or remote network origins.
Authorization gates that close safely
Collabma removes its injected interface unless every condition below remains true:
- 01Valid organization ID and Workspace domain
- 02Exact operational Group and security exclusions
- 03No ambiguous or overlapping canonical address or alias
- 04Primary Chrome profile belongs to the approved domain
- 05Current route resolves to one approved Group identity
- 06One eligible toolbar with assignment and status controls
- 07Requested control is visible, enabled and unambiguous
- 08No blocking dialog, menu or listbox is open
- 09Trusted user gesture and no action already in progress
Unknown Groups, security Groups, missing or malformed policy, account changes, domain mismatch, navigation races, selector changes, duplicated actions and delayed policy results all fail closed.
Native action safety
Collabma never constructs a mail request or calls a Google mail API. It invokes only the native button that is already visible after rechecking the route, toolbar, overlay state, user gesture and lock that permits one action.
The interface reports that the action was handed to Google and asks the user to verify the native state. It does not claim completion on the server from a page click.
Administrative controls
- Deploy first to a controlled pilot instead of the entire organization.
- Build operational and security Group policy from a verified Admin inventory.
- Keep Group identities used for access control in the exclusion list as defence in depth.
- Use named Store roles, strong verification in two steps and tested account recovery.
- Review hashes, permissions, privacy disclosures and rollback steps before each release.
Known limits
Google Groups page structure and English native action labels may change. Collabma is designed to remove its shortcuts when the supported structure is not uniquely verified, but live testing is still required after Google changes. Automated testing cannot prove mail delivery, Group configuration, notifications, posting identity, behaviour from external providers or Google service availability.
Report a security concern
Email publisher@trulinex.com with the Collabma version, browser version, affected route type and clear reproduction steps. Do not include passwords, verification codes, payment details, live message content or customer records.