Who this is for. Super Admins, who can add, change and remove these settings. AP Helpdesk Managers, Specialists and Analysts cannot open AP Intelligence. Requires AP Intelligence to be enabled for your tenant. See the Roles and Access.
This decides who counts as one of your own people. A sender treated as internal is trusted more than an outside one: different rules apply, different categories are available, and the agent will act on requests it would refuse from a vendor.
This is an authorization setting wearing the costume of a contact list. Internal is the widest scope the agent has, so an entry here grants more than it appears to.
Figure 1. Internal Contact Management.
Two lists, two matching rules
The panel explains the difference: “Emails and domains listed here are treated as internal contacts. Emails are matched exactly; domains enable domain-level matching so any sender from an approved domain is processed as an internal contact.”
Table 1. The two lists
List |
Matches |
|---|---|
Internal Contact Emails |
Exactly, address by address |
Relaxed Domain Match Entries |
Any sender at a listed domain |
Add entries
Both lists take values almost the same way: “Type an email or regex pattern and press Enter, Tab, or comma to add” for contacts, and “Type a domain or regex pattern and press Enter, Tab, or comma to add” for domains. The one difference is that Relaxed Domain Match Entries rejects public mail domains such as gmail.com and outlook.com with the error “Public domains cannot be added.”
Entries appear as chips, each removable with ×. Changes are committed with Save.
Both fields accept a regex pattern as well as a literal value. A regex matches more broadly than a literal value and is easier to get wrong. A pattern broader than intended silently grants internal access, which is the widest scope the agent has.
A domain entry grants internal treatment to every sender at that domain, including addresses that do not exist yet. Prefer exact contacts where the list is short and stable; use a domain only where the alternative is maintaining dozens of addresses.
Choose between the two lists
Table 2. Which list to use
Situation |
Use |
|---|---|
A handful of named colleagues |
Internal Contact Emails |
A whole department at your own domain |
Relaxed Domain Match Entries |
A shared services provider on their own domain |
Relaxed Domain Match Entries, after confirming the domain is theirs alone |
Anyone at a public mail provider |
Neither. Public domains are rejected |
Audit the lists
Review both lists when people leave and when a supplier relationship ends. Nothing in the product prompts this, and an entry outlives the person or contract it was added for. A regex entry deserves particular attention, because its scope is not obvious from reading it.
Relaxed Domain Match is the widest setting on this page. It classifies senders as Internal by email domain rather than by individual address, and Internal is the broadest access scope in the product. Anyone mailing from a listed domain is treated as a colleague. Public and consumer domains are rejected for exactly this reason. Add a domain only where every possible sender at it should be trusted.