A group's members can send as the group, and the message says only From: the group, so nothing recorded which person sent it. Every submission whose envelope sender belongs to another account now writes an audit record: the person as actor, an EmailSubmission target named by the address and owned by that account, and "Sent as <address>", with ", from <account>" when it went out through the sender's own account rather than the group's. A delegate's send is left to AL-9's record, and a send from the sender's own address writes nothing. No Sender: header is added: the audit log is where the real sender is named. email_submission_set now takes the access token, from its one caller. The audit suite has a group member send once as the group (one record, with the address, account and details) and once as themselves (none) (specs/multi-account.md, MA-D0a, G2).