Persona Mailbox Auditing
Operator guide for reading the 318 persona mailboxes manually — read-only, SSO-gated, and fully audited.
1. What this is
Every AI persona has its own mailbox on mail.darkcoders.io
(persona-<id>@darkcoders.io). This page explains how to read
those mailboxes for manual auditing and validation without touching a
single message.
2. Security model
- This page and the mailbox tooling require SSO login.
- Reads are read-only:
SELECT readonly+BODY.PEEKmeans read/unread state is never changed. - Every read is redacted (tokens, passwords, keys) and written to the
OpenSearch audit index
ciso-persona-mail-audit-*. - The auditor credential rotates every 90 days (warning at 60, 7-day rollback grace), fully self-healing.
3. Quick start — Telegram commands
From the master bot @oxfares_claw_bot (operator accounts only):
/mailbox <who>— last 5 messages of a persona or team./team-mail <team>— same, using a friendly team name.
<who> can be:
- A team word:
marketingsaleslegalfinancesecurityengineeringsocforensicsthreatintelpentestdetectionstrategypeoplebytelensgrowthcomplianceauditriskleadershipexecutives - A persona ID, e.g.
DG-001,BL-EC-001. - A title or keyword, e.g. Email Marketing Specialist, Custodian.
Examples:
/mailbox growth → Demand Gen team mailboxes /mailbox BL-EC-001 → the Evidence Custodian assistant mailbox /team-mail bytelens → ByteLens Lab team mailboxes /mailbox "Risk Assessor" → personas whose title matches
4. Email client access (deep inspections)
| Setting | Value |
|---|---|
| Server / port | mail.darkcoders.io / 993 (SSL) |
| Username | persona-<id>@darkcoders.io*auditor |
| Password | current auditor credential from Vault
(ciso/data/persona-mail-audit) — never printed anywhere |
| Mode | read-only — never mark read, move, flag, or delete |
Rules: never change flags; never send from a persona mailbox without separate authority; after a rotation, fetch the new credential from Vault.
5. Receiving copies
inbox-audit@darkcoders.io expands to all 318 persona mailboxes
for broadcast audit notices. Do not use it for replies.
6. Auditing and self-healing
- Every read logs actor + personas + time to OpenSearch.
- Rotation: 90-day period, 60-day warning, 7-day grace, guarded daily
cron
persona-mail-audit-rotate. - The daily self-healing loop verifies the register (318 personas, 0 drift) and rotation state.
7. Bot custody note
@oxfares_forge_cloud_bot is fully owned (verified 2026-09-06;
token in Vault ciso/data/telegram/service/forgecloud).
@ciso_bitwarden_ke_bot and @ciso_vault_ke_bot are not
owned by the operator account and remain out of governance scope.
8. Related controls
- Telegram Bot & Channel Governance suite (37_Telegram_Bot_and_Channel_Governance)
- Persona register — 318 roles, zero drift
- Contradiction register CON-012 — policy collision fix + bot custody
- ByteLens unified plan §8.5 — AI persona assistants