# What an agent is allowed to do

> Four switches decide whether an agent may email, post to Slack, spend enrichment credits, or write to your CRM instead of staging changes for review. A test run lets you watch one work before it writes anything.

- Source: https://spiich.ai/help/background-agents/agent-permissions
- Section: Background agents
- Who can do this: Everyone
- Time: 5 minutes
- Last updated: 2026-08-24

## Before you start

- You can set up background agents, or you are reviewing changes an agent already staged.

An agent starts with the minimum. It can read your CRM, your mail, your calendar and the web, because that is what makes it useful. Everything that leaves Spiich or spends money is off until you turn it on, per agent, in the form.

## The four switches

| Switch | What it unlocks |
| --- | --- |
| **Allow email sending** | The agent may email reports and summaries. A recipient list opens underneath. |
| **Allow Slack messaging** | The agent may post reports to Slack, as a DM to its owner or into channels you choose. |
| **Allow phone & email enrichment** | The agent may look up phone numbers and email addresses for contacts. Each enrichment uses additional credits. |
| **Proposal mode** | The agent stages every CRM change for review instead of writing it. |

The agent dashboard has a **Capabilities** panel that lists which of Email, Slack and Enrichment are on, so you can audit an agent without opening its configuration. An agent with none reads "No optional capabilities".

### Email recipients

Switching on **Allow email sending** opens a list of teammates. The agent's own member is always mailed, shown as `(always)`, plus anyone you switch on. Some agents deliver per record and treat the list as the exact recipient set instead; for those, the owner can be switched off too.

### Slack channels

The Slack section only appears when the workspace is connected to Slack. You choose whether the agent DMs its owner and which specific channels it may post to. A channel only shows up after the Spiich app has been invited to it in Slack. If one is missing, invite the app in Slack and click the refresh icon next to "Don't see a channel? Invite the Spiich app to it in Slack first, then refresh." See [Connect Slack](/help/connect-your-tools/connect-slack).

### Enrichment

Off by default. When it is off, the enrichment tools are not handed to the agent at all, so it cannot spend that budget by accident. When it is on, each phone or email lookup consumes credits on top of the run cost. See [Credits and usage](/help/workspace/credits-and-usage).

## Proposal mode and the approval queue

Proposal mode is what you reach for when you are not yet ready to let an agent touch the CRM unsupervised. With it on, every CRM change the agent wants to make is staged instead of written. Nothing reaches your CRM until a person approves it.

Staged changes show up in three places: as a "pending writes" button in the Background Agents header, on the agent's own row, and as a badge on the sidebar nav item.

1. **Open the queue**
   Click the pending writes button, or open the agent and go to **Proposals > Review all**.

2. **Read the proposed changes**
   Each row is one proposed record change, with its **Action**, what is **Proposed**, and its **Status**. Filter by **Pending**, **Added**, **Dismissed** or **All**.

3. **Approve or discard**
   Select the rows you want and click **Add to CRM**, or **Dismiss** to discard them. Both work in bulk.

Approving and dismissing staged changes is open to every member, not just the people who can build agents.

> **Note:** The toggle is only offered for agents whose writes really do all stage. Spiich withholds it rather than making a promise it cannot keep for a workflow that writes through a path it cannot intercept.

## Try an agent before it writes anything

The **Test agent** button, the flask icon on an agent row, runs the agent exactly as a real run would, except every CRM change is staged for review instead of written. It does not change the agent's own Proposal mode setting, so you can test an agent that normally writes directly.

1. **Start the test**
   Hover the agent's row, or open the agent, and click the flask icon.

2. **Pick a record, for an event-based agent**
   Search for and select the record you want it to run against.

3. **Confirm**
   The dialog states the credit cost and that changes will be staged. Click **Yes, test now**.

4. **Read what it did**
   Open the run and read the **Run plan** and **Entities modified**. See [Read and manage agent runs](/help/background-agents/monitor-agent-runs).

5. **Deal with the staged changes**
   Open **Proposals** and either add the changes you agree with to the CRM, or dismiss them.

6. **Make it permanent, if you want to**
   If you want every future run to work this way, open **Configure** and switch on **Proposal mode**.

> **Careful:** A test run costs the same as a real run. Agents metered per unit of work are charged as they stage each item, so dismissing a staged change refunds nothing.

## Who can change permissions

Editing an agent's permissions is editing the agent, so it needs the same grant. Admins have it by default and can extend it per member or per team.

An agent that runs as an admin can only be changed by an admin. If the pause, edit and delete buttons are greyed out on a colleague's agent, that is why. Copy it to yourself instead: the copy runs as you.

## Limits

- Slack options are hidden entirely when the workspace has no Slack connection.
- A test run is refused for agents whose writes cannot be staged. Spiich withholds the button rather than letting a test change data for real.
- Enrichment credits are consumed per lookup and are separate from the agent's run price.
- Permissions are per agent. Copying an agent does not copy its Slack channel, and the copy emails you rather than the original owner.

## If something goes wrong

**Proposal mode is on but nothing is waiting for review.** Either the agent has not run yet, or it made no CRM changes. "No writes waiting for review" next to a completed run means it found nothing to change. Open the run's **Run plan** to see what it did.

**The flask button is not shown.** That agent cannot stage its writes. Test it on a single safe record with **Run agent now** instead, or rebuild the same idea as a Custom agent.

**A Slack channel is missing from the list.** The Spiich app has not been invited to it, or the list is stale. Invite the app in Slack, then click refresh.

**"Could not add these changes to the CRM."** A transient failure on the CRM side. The proposals are still queued, so try again shortly. If it keeps failing, see [CRM sync problems](/help/troubleshooting/crm-sync-problems).

## Frequently asked questions

### Is Proposal mode the same as a test run?

They stage changes the same way, but Proposal mode is a permanent setting on the agent while a test run is a one-off. A test stages writes without changing the agent’s setting, which is why you can safely test an agent that normally writes directly to the CRM.

### If I dismiss a staged change, does the agent try again next run?

It can, unless you have set **Run once per record**. Dismissing tells you the change was wrong; it does not teach the agent. If an agent keeps proposing something you do not want, fix the Process field in its instructions rather than dismissing repeatedly.

### Can an agent read email I have not connected?

No. An agent works through the mailbox and calendar of the member it runs as, using the same read-only connection that member set up themselves. If that person has no mail provider connected, the agent has no inbox to read.

### Does turning off enrichment stop the agent finding contacts?

It stops the agent looking up phone numbers and email addresses through enrichment providers. It can still find people through web research and read whatever is already in your CRM. The enrichment tools are simply not given to the agent when the switch is off.

## Related

- [What background agents are](https://spiich.ai/help/background-agents/background-agents-overview)
- [Read and manage agent runs](https://spiich.ai/help/background-agents/monitor-agent-runs)
- [Triggers and schedules](https://spiich.ai/help/background-agents/agent-triggers)
- [Connect Slack](https://spiich.ai/help/connect-your-tools/connect-slack)
- [Trust and security](https://spiich.ai/trust)
- [Background Agents](https://spiich.ai/product/background-agents)
