I am speechless.
I am speechless.
There's ways around that, but for some orgs, it would be unneeded overkill, and not protecting anything notable.
I can honenstly not think of a single venture where "support@" is not one of the most critical resources wrt privacy and security. On top of that, "support@" is typically the account that has a high churn rate. Where people move on and new people are hired. Of all the cases, I'd say that "support@" ranks amongst the top for need of proper account management.
That said, it's dead simple to grant jane@ and john@ access to an inbox in Google. Researching how to do this may take 30+ minutes. But getting it configured afterwards is really a two minute job.
The only reason I've came across why people shared Google accounts was "we have a business domain and we need to pay for every extra seat". Which is a valid excuse. I'd argue that its not a good enough excuse to lower your security for, but valid nontheless. For one, 2fa is almost impossible when sharing accounts.
Which is why having a "pay per seat" model for any SAAS is perpendicular to having proper security practices. You are not rewarding good security, but rather punishing it by letting organisations with proper separation of accounts pay more then the ones that choose to have as few as possible.
I haven't seen anything that allows a seamless view of the inbox/outbox, and a way of sending that doesn't accidentally use their normal email address if they forget to click a drop down.
Not every password identifies a user.
Ignoring the myriad security issues with shared credentials auditing alone is completely ruined with shared creds.