Addresses are easy to mistype and forward
A share invitation can be sent to the wrong address, forwarded to somebody else or copied from an old engagement. If possession of the invite alone is enough, the product cannot distinguish the intended recipient from whoever received the message.
Mailbox proof adds a step that connects access to control of the invited address.
Proof should remain scoped
Recipient proof does not need to create a full employee account. The external principal can remain limited to the share relationship and its permissions, lifetime and content context.
That keeps external collaboration lightweight without pretending an outsider belongs to the organisation’s internal identity domain.
Assurance should match the risk
Mailbox control may be sufficient for some workflows and insufficient for others. A mature product should be clear about what the proof establishes rather than marketing it as universal identity assurance.
The important architectural point is that recipient identity is explicit and can be strengthened where the use case requires it.
Prove before bytes
A good external-share demo should show who the share is for, which version it exposes, when it ends and what remains in the record afterwards. Recipient proof belongs in that sequence.