Keep emails and calendar events private
Control visibility of emails and events in your workspace.
Once you’ve synced your email and calendar to Attio, you can choose what other workspace members can see in your synced emails. You can also use blocklists to hide emails and calendar events involving specific email addresses or domains. Attio also automatically protects communications involving internal email addresses and domains associated with your workspace.
For guidance on setting a privacy baseline for a whole team, see Manage email and calendar privacy across your workspace.
Keep emails private by default
Each workspace member can choose a default email sharing setting for each of their synced mailboxes. This setting determines which parts of synced emails other workspace members can view.
By default, teammates can see an email’s metadata and subject line, including its participants and timestamp. They cannot see the email body unless you change your default sharing setting or share the email manually.
Learn how to configure your default email sharing settings.
Note: This setting does not apply to calendar events. To prevent a single calendar event from showing in Attio, make it private in Outlook or Google Calendar. To hide all calendar events and emails with specific contacts, add them to your blocklist.
Configure blocklists
A blocklist hides emails and calendar events in Attio for the email addresses and domains you choose.
Attio automatically adds internal email addresses and domains on all plans. On Pro and Enterprise plans, admins can also add other email addresses and domains. Mailbox-only blocklists are available to all members on all plans. The two types differ by scope:
Workspace protected and blocked contacts list: Managed by admins and applied across your entire workspace. Each entry uses one of two enforcement levels:
Protected: Communications are hidden when all participants are Protected.
Blocked: Communications are hidden whenever a Blocked participant is included.
Mailbox-only blocklist: Managed by each member for their own synced mailboxes, and applied only to communications synced from that mailbox.
The type of entry determines which communications are affected:
An email address matches communications involving that exact address.
A domain matches communications involving any address on that domain, including its subdomains.
Note: To change when Attio automatically creates records from email and calendar sync or to disable automatic record creation without hiding communications, manage record creation settings.
Manage the workspace protected and blocked contacts list
Note: Only admins can view and manage the workspace protected and blocked contacts list.
On all plans, workspace members' email addresses and domains are protected. Adding other email addresses and domains is available on Pro and Enterprise plans.
The workspace protected and blocked contacts list applies to communications synced by every member of your workspace.
Admins add email addresses or domains:
Click your workspace name, then Workspace settings.
Open the Email and calendar page, then the Email visibility tab.
Click Add contacts.
Enter one or more email addresses or domains, separated by a comma or space.
Click Confirm.
Note: Changes made to blocklists can take a few minutes to be fully implemented across the workspace.
Choose an enforcement level
Each workspace protected and blocked contacts list entry has an enforcement level that determines how strictly Attio hides its communications. New entries use Protected by default. Click Protected to find the option to select Blocked instead.
Note: For help deciding which level to use for vendors, investors, and other external collaborators, see Manage email and calendar privacy across your workspace.
Use Protected for people or domains whose communications should generally stay private, but can still appear when an unprotected external participant is involved. For example, an investor who introduces you to prospects.
Use Blocked for people or domains whose communications should never appear in Attio, regardless of who else is included. For example, an external legal advisory firm.
Protected
When every participant on an email or calendar event is Protected:
The email or calendar event is hidden in Attio.
It does not contribute to communication intelligence data.
Meetings for that calendar event are not recorded.
If a communication includes a participant who is not Protected, it can remain visible in Attio.
For example, suppose jordan@loopstack.io is Protected:
An email between Jordan and another Protected workspace member is hidden.
An email between Jordan and an external contact who is not Protected can remain visible.
Communication intelligence data follows the same visibility rules.
Attio adds an extra privacy measure to the Emails tab on records for Protected addresses and domains:
On records for workspace members' email addresses and protected internal domains, the Emails tab always shows "Nothing to show here," even for emails that include participants who are not Protected.
On records for other Protected email addresses and domains, the Emails tab shows emails that include a participant who is not Protected. Emails where every participant is Protected are hidden.
Communications that remain visible because they include a participant who is not Protected can still be found elsewhere in Attio, including through features such as Ask Attio.
Note: Attio automatically uses the Protected level for your workspace's internal email addresses and domains, unless you choose otherwise. Learn more about how Attio protects internal email and calendar privacy.
Blocked
Blocked hides communications everywhere they appear in your workspace. Unlike Protected, communications remain hidden even when non-blocklisted participants are included.
If you blocklist an email address, Attio hides emails and calendar events where that exact address is a participant.
If you blocklist a domain, Attio hides emails and calendar events where any participant uses an address on that domain.
Blocklisted communications no longer factor into communication intelligence attributes, such as Last interaction.
Since matching calendar events do not appear in Attio, those meetings are not able to be recorded.
Attio does not automatically create new records from communications involving blocked addresses or domains. Existing records remain in your workspace, but their matching emails and calendar events are hidden.
Update or remove the workspace protected and blocked contacts list
How you manage an entry depends on its type.
Workspace members' email addresses: This entry is always Protected and cannot be changed.
Internal domains: These entries are Protected by default. Admins on any plan can toggle protection on or off.
Entries you've added: On Pro and Enterprise plans, select the current level in the Enforcement level column to switch between Protected and Blocked. To remove the entry, click the ⋮ icon beside it, then click Remove.
Removing an entry or turning off protection restores visibility of the associated emails and calendar events, subject to each member's sharing and mailbox-only blocklist settings.
Manage a mailbox-only blocklist
Available on all plans.
All members can use the mailbox-only blocklist.
A mailbox-only blocklist hides matching communications synced from your mailbox. It does not affect communications synced from another member’s mailbox.
For example, suppose you and a teammate both receive the same email. If you have blocklisted one of its participants but your teammate has not, the copy synced from your mailbox is hidden, but the copy synced from your teammate’s mailbox can still appear in Attio.
Note: Teammates must add the same address or domain to their own mailbox-only blocklists to hide communications from their mailboxes. Admins can use the workspace protected and blocked contacts list when an address or domain should be hidden for everyone.
A mailbox-only blocklist applies the same strictness as the Blocked workspace level, but only to communications synced from your mailbox:
Matching emails are hidden regardless of who else is on the thread.
Matching calendar events are hidden. Unless another member's mailbox syncs the event, the meeting does not appear in Attio and is not recorded.
Blocklisted communications no longer factor into communication intelligence attributes.
Attio does not automatically create records based on those communications. Existing records remain in your workspace, but their matching emails and calendar events are hidden.
Add to your mailbox-only blocklist
Click your workspace name, then Account settings.
Open Email and calendar accounts.
Select the relevant mailbox.
Open the Mailbox-only blocklist tab.
Click + Add to blocklist.
Enter one or more email addresses or domains.
Click Confirm.
To remove a blocklisted email or domain, click the ⋮ icon beside it, then click Remove. Removing an entry restores visibility of the associated emails and calendar events synced from your mailbox, subject to the workspace protected and blocked contacts list and your sharing settings.
Note: Changes made to blocklists can take a few minutes to be fully implemented across the workspace.
How Attio protects internal email and calendar privacy
On all plans, Attio automatically protects internal emails and calendar events by adding your workspace members' email addresses and your internal domains to the workspace protected and blocked contacts list with the Protected enforcement level.
Internal entries include:
Workspace members' email addresses: The email addresses of active and suspended workspace members and pending invitees, whether or not they have connected a mailbox, along with the addresses of connected mailboxes. This entry is always Protected and cannot be changed.
Internal domains: Each domain from those member addresses, pending invite addresses, and connected mailboxes, excluding public email domains such as gmail.com. Admins can turn protection off for any domain.
Protection for an internal domain covers every email address on that domain, including colleagues who don't have Attio accounts. If protection is turned off for a domain, only workspace members' own email addresses remain protected.
As a result, emails and calendar events involving only internal or otherwise Protected participants are hidden, along with their communication intelligence data. If an email or calendar event also includes a participant who is not Protected, it remains visible in Attio.
Related resources
Manage email and calendar privacy across your workspace: decide what to protect, block, and share before members connect their mailboxes.
Sync your email and calendar: connect your inbox and control automatic record creation.
Share emails with your team: configure your default sharing setting and share emails manually.
Frequently asked questions
Protected recipients are now the Protected enforcement level on the workspace protected and blocked contacts list. Existing protected recipients have carried over automatically. If you'd rather hide a contact's communications in every case, you can change their enforcement level to Blocked.