Who Can Access My Company's Backups?

Backup copies can contain the same confidential emails, attachments, and files as the original accounts. Your company controls both the JitBackup console accounts and the storage used for those copies.

Does Every Employee Get a Login?

No. Backing up a Workspace user does not create a JitBackup console account for that person. A System Administrator manages console accounts under Settings > System settings > Accounts.

Console role Intended access
System Administrator System settings, console accounts, and all configured domains
Domain Administrator Backup settings and recovery operations for assigned domains
Domain Operator Backup and recovery operations for assigned domains, without administrator settings

Domain assignments are broader than an individual mailbox. Do not assume a Domain Operator is restricted to viewing only their own mail. Ask the administrator to review the role and assigned domains before giving someone recovery access.

If you only need one missing file, you can ask the authorized operator to recover it without receiving a console account yourself.

Where Is the Backup Data Stored?

JitBackup writes backup data to the storage selected by your organization: a local disk, network share, S3-compatible storage, Azure Storage, or Google Cloud Storage. Cloud storage is still an external service even when the account and bucket belong to your company.

The server also keeps a local index used to find and manage backups. People who administer the server, storage accounts, or exported files have responsibilities beyond console permissions. Your IT team should control access to all of these locations.

Self-hosting does not mean the software has no outside connections. Backups and restores use Google APIs; cloud storage uses its provider; activation and some email functions contact JitBackup services.

Why Does Google Authorization Include Write Access?

The configured service account is used for both backup and restoration. Backup reads Workspace data; restoring selected items requires permission to write them to Google. The authorization list therefore includes write-capable scopes for supported apps.

A Google Workspace super administrator should review and authorize the complete list shown by JitBackup. Removing required scopes can cause permission checks or later jobs to fail. See Service account setup and Replace a service account.

What Should I Keep Private?

Treat console passwords, service account JSON files, storage credentials, license keys, and password reset links as confidential. Do not paste them into a general support message or send them in a team chat.

Ask IT for the approved console address and a protected connection when accessing it from another computer. Report certificate warnings to IT. Keep exported data in company-approved locations and remove temporary copies according to company policy.

For a support request, share the error and enough context to diagnose it, with secrets and unrelated personal data removed. See What to include when asking for help.