Manage email and calendar privacy across your workspace
Set clear defaults for private and shared email and calendar events.
Attio automatically protects email addresses and domains from members of your workspace on all plans. On Pro and Enterprise, admins can add other email addresses and domains.
Mailbox-only blocklists, and the Metadata only and Subject line and metadata sharing settings are available on all plans. The Full access with workspace setting is available on Plus, Pro, and Enterprise. The Full access with individuals setting is available on Pro and Enterprise.
Admins manage the Workspace protected and blocked contacts list. Members manage their own mailbox-only blocklist and sharing level.
Use this guide to set a workspace-wide privacy baseline before inviting members, then help each member finish their mailbox settings after syncing. You’ll decide which communications stay private, which should never appear in Attio, and how much email context teammates can see.
Overview of Attio’s visibility settings
This guide gives recommendations on how to configure three visibility features:
Workspace protected and blocked contacts: Admin-managed rules that apply across every synced mailbox. Use Protected to hide internal emails and calendar events, and Blocked when that communication must stay out of Attio entirely. Later in this guide, we’ll share more detail on how to decide what to protect or block. See Keep emails and calendar events private for more detail and setup steps.
Mailbox-only blocklist: Member-managed rules that apply only to one mailbox. Members configure these rules separately for each of their synced mailboxes. See Keep emails and calendar events private for more detail and setup steps.
Email sharing settings: Member-managed settings that control how much teammates can see of email that is not hidden by a blocklist. Most teams use Subject line and metadata by default, then grant Full access with individuals to named teammates who need it. See Share emails with your team for sharing options and setup steps.
Configure workspace settings before inviting members
Admins should set workspace settings before inviting members so the privacy baseline is in place before anyone connects a mailbox.
Choose protection for external collaborators
External collaborators are companies and people outside of your business who are not users of your Attio workspace, but whose communication could be considered private. This might include sensitive vendors, contractors, law firms or investors.
On the Workspace protected and blocked contacts list, choose a setting based on where the collaborator’s communication should remain visible.
Leave unprotected: Choose this option when you want the collaborator’s communication history on their record. For example, you might leave a video editor unprotected so their person record shows emails with your team. We recommend leaving customer communication unprotected because your CRM should be the home for all of your contact history with customers and prospects.
Protected: Use this when the collaborator’s records should remain private, but their customer-facing communication may still be useful. For example, protect a fractional legal firm’s domain so email exclusively between employees and the firm is hidden from Attio, but communication also including third parties, like a customer, is still visible on those third party’s record pages.
Blocked: Use this when no communication involving the collaborator or firm should appear anywhere. For example, blocking a payroll provider also hides its emails from other participants’ records.
Protect an individual email address when the rule applies only to that person. Protect a domain when the company record and everyone using that domain should be protected.
Block contacts that must stay out
On Pro and Enterprise, add contacts whose communication should never enter Attio to the Workspace protected and blocked contacts list and set their enforcement level to Blocked. Common examples include a payroll provider, a personal correspondent, or an external adviser handling matters that must never be visible in the workspace.
Do not block public email domains such as gmail.com. Doing so will hide all email with anyone who uses that provider, including customers and prospects.
Blocking is intentionally broad. If a Blocked accountant or law firm is copied on an email about a customer contract, Attio also hides the thread on the customer’s record. Use Protected instead when the adviser’s records should remain private but your team still needs customer-facing threads elsewhere in Attio.
Decide how to handle investors
Investor domains need a deliberate choice because the right setting depends on how your team uses Attio.
Leave unprotected: Leave investor domains unprotected when investors are part of the pipeline, such as at a venture capital firm. Control who can read the email body through sharing settings instead.
Use Protected: Set investor domains to Protected when you don’t want communications between your company and the investment firm to show in Attio, but you want to see communications involving your investor and third parties, like introductions to other people or businesses.
Use Blocked: Set investor domains to Blocked when a founder wants all fundraising correspondence hidden from the team. The tradeoff is that investor introductions and other customer communication including investors will also be hidden from Attio.
Set an email visibility policy for your team
Decide how much of each member’s synced email should be visible to the rest of the workspace. This setting is managed individually by each member for their own mailbox and cannot be set by admins, so agree on a policy for your team and ask members to apply it when they connect their mailboxes.
Keep Subject line and metadata as the default. Teammates can see participants, timestamps, and subject lines, then request access when they need to read the email body.
Use Metadata only if your team regularly puts sensitive data in the subjects of emails, or team members need to hide who they are communication with from each other.
If teammates regularly need to read each other’s email threads, consider Full access with individuals to give specific people access rather than sharing email bodies with everyone.
Use Full access with workspace when broad email visibility is useful for how your team works, such as for sales or customer success teams where shared access to customer conversations is important. Be cautious when choosing this setting because emails shared with the workspace cannot later be made private individually.
Members can still share individual emails when needed, regardless of their default visibility setting.
After this phase, parties that should never appear in Attio are blocked, you have decided how to handle investors, and your team has agreed which sharing level members should apply to their mailboxes.
Configure mailbox settings
Each member should review two mailbox settings once their mailbox has synced. Admins cannot configure these settings on their behalf.
Add mailbox-only blocklist entries
If your work mailbox may carry some correspondence that isn't company business, you can add those people to your mailbox-only blocklist to keep those emails and calendar events private, along with your own personal email address.
A mailbox-only blocklist applies only to emails and calendar events synced from that mailbox, so another member can still sync their own copy of a thread or event with the same person.
For example, if you add your personal Gmail address to your mailbox-only blocklist, emails between that address and your work mailbox won't show in Attio. Neither will a personal calendar invite you send from your Gmail to your work address to block out time. However, if you email your work address and CC a colleague's work address, that email shows in Attio if your colleague has their mailbox synced.
Configure email sharing settings
Review the sharing level for your mailbox and apply the policy your team agreed on. Subject line and metadata is selected by default for newly synced mailboxes.
On Pro and Enterprise, grant Full access with individuals to teammates who need every thread, such as Sales and Success team members collaborating on accounts. Keep your team’s agreed sharing level for everyone else.
This approach gives the operating team the context it needs without sharing every mailbox with the whole workspace.
After this phase, each member should have a mailbox-only blocklist and a sharing level they have reviewed.
Review privacy when the team changes
Assign an admin to review email privacy whenever your team or vendor set changes.
When a new workspace member joins, have them review their mailbox-only blocklist and sharing level after connecting their mailbox.
When a workspace member is removed from Attio, Plus, Pro and Enterprise plan admins can retain the email history of that member in Attio.
When you engage a new external collaborator or add a potentially sensitive vendor, decide whether to leave them unprotected or add them to the Workspace protected and blocked contacts list as Protected or Blocked.
When fundraising begins, revisit the investor policy before sensitive threads land in Attio.
When account coverage changes, remove individual full access that is no longer needed.
Related resources
Follow the detailed behavior and setup steps for workspace and mailbox-only blocklists.
Configure mailbox sharing and named access using Share emails with your team.
Review what Attio imports before members sync their email and calendar.
Control access to lists and objects separately with Sharing and permissions.
Manage retained email when someone leaves using View and manage member accounts.