So as for question 3... one password? So anyone who has access could log in as anyone else who has access using their email and the same password, right? Also, do they need the password when clicking from an email or is there a special link there that lets them bypass password entry? If the latter, how long do those links last?
I don't mean to pry too much into implementation details, but I am very selective about what I share, so it's important to me.