Persona Mailbox Auditing

Operator guide for reading the 318 persona mailboxes manually — read-only, SSO-gated, and fully audited.

1. What this is

Every AI persona has its own mailbox on mail.darkcoders.io (persona-<id>@darkcoders.io). This page explains how to read those mailboxes for manual auditing and validation without touching a single message.

2. Security model

3. Quick start — Telegram commands

From the master bot @oxfares_claw_bot (operator accounts only):

<who> can be:

  1. A team word: marketing sales legal finance security engineering soc forensics threatintel pentest detection strategy people bytelens growth compliance audit risk leadership executives
  2. A persona ID, e.g. DG-001, BL-EC-001.
  3. A title or keyword, e.g. Email Marketing Specialist, Custodian.

Examples:

  /mailbox growth            → Demand Gen team mailboxes
  /mailbox BL-EC-001         → the Evidence Custodian assistant mailbox
  /team-mail bytelens        → ByteLens Lab team mailboxes
  /mailbox "Risk Assessor"   → personas whose title matches

4. Email client access (deep inspections)

SettingValue
Server / portmail.darkcoders.io / 993 (SSL)
Usernamepersona-<id>@darkcoders.io*auditor
Passwordcurrent auditor credential from Vault (ciso/data/persona-mail-audit) — never printed anywhere
Moderead-only — never mark read, move, flag, or delete

Rules: never change flags; never send from a persona mailbox without separate authority; after a rotation, fetch the new credential from Vault.

5. Receiving copies

inbox-audit@darkcoders.io expands to all 318 persona mailboxes for broadcast audit notices. Do not use it for replies.

6. Auditing and self-healing

7. Bot custody note

@oxfares_forge_cloud_bot is fully owned (verified 2026-09-06; token in Vault ciso/data/telegram/service/forgecloud). @ciso_bitwarden_ke_bot and @ciso_vault_ke_bot are not owned by the operator account and remain out of governance scope.

8. Related controls