# Control what Spiich can see and change

> Settings > Object Types gives a workspace admin a Visible and a Writable switch on every CRM object and every field, plus a single switch controlling whether the agent may read email synced from your CRM.

- Source: https://spiich.ai/help/connect-your-tools/control-crm-access
- Section: Connect your tools
- Time: A few minutes
- Last updated: 2026-08-24

## Before you start

- A CRM is connected to your workspace.
- The first import has finished, so object types and fields exist.

Connecting a CRM gives Spiich the technical ability to read and write it. [`Settings > Object Types`](https://app.spiich.ai/settings/entity-types) is where you decide how much of that ability the assistant and your background agents actually get.

The page only appears once a CRM is connected. If it is missing, or it reads *Connect a CRM from Integrations to start syncing object types*, start at [Connect your CRM](/help/connect-your-tools/connect-your-crm).

## Two switches, everywhere

Every object and every field carries the same pair.

| Switch | What it controls | What it does not do |
| --- | --- | --- |
| **Visible** | Whether the agent can read the object or field at all | Turning it off deletes nothing; the data stays synced |
| **Writable** | Whether the agent can create or change it | It cannot override what your CRM allows |

Turning Visible off is the strong lever: an agent cannot summarize, filter on or reason about a field it cannot see. Turning Writable off is the softer one: the agent still uses the field for context but cannot touch it.

The switches save immediately. There is no Save button.

## Set access per object

1. **Open Object Types**
   Go to `Settings > Object Types`. Objects are grouped under **Standard**, described in the page as the core CRM objects every workspace syncs, and **Custom objects**, the ones your CRM defines beyond that set.

2. **Decide read and write per object**
   Set **Visible** to control whether the agent can read the object, and **Writable** to control whether it can change it.

3. **Describe what the object is**
   Click the description line under an object's name and write what it represents, for example what your team actually uses a custom object for. That context is what stops the agent guessing. Descriptions hold up to 2000 characters. Press Cmd/Ctrl+Enter to save or Escape to cancel.

**Standard objects cannot be hidden.** Their Visible switch is disabled on purpose: people, companies, deals and tasks are what the product is built on, and an agent that cannot see them cannot do anything useful. You can still make them read-only by switching Writable off.

Attio custom objects arrive switched off and are turned on individually here. Attio's internal Users and Workspaces objects are never imported at all.

## Set access per field

Click the arrow to the left of an object row to expand it. Every synced field is listed with its CRM field name, its type, and its own **Visible** and **Writable** switches.

Some Writable switches are locked, and the tooltip always says which of three reasons applies.

- *This field is read-only in your CRM.* The field is marked read-only on the CRM side, so the CRM would reject any write the agent attempted. This can never be unlocked from Spiich; change the field in your CRM.
- *This object isn't writable.* The parent object's Writable switch is off. Turn it on first.
- *Turn on visibility first.* The agent cannot write to an attribute it cannot see. Turn the field's Visible switch on.

If an expanded object says *No attributes have synced for this object type yet*, its fields are still importing. Wait a few minutes and reload.

## The CRM Emails switch

At the bottom of the page, under **Email access**, sits a single switch: **CRM Emails**, described in-product as *Let the agent read emails synced from your CRM. When off, the agent only uses emails from your connected inbox (Gmail or Outlook). No synced data is deleted.*

This is a workspace-level decision and it is worth making deliberately. Email history synced from your CRM is one of the strongest signals the assistant has when writing a follow-up, and also the most sensitive thing in the pipe. Turning it off does not delete anything; it stops the agent using it, immediately.

In practice the switch matters on HubSpot, which is the CRM Spiich syncs email from. Your own mailbox is a separate, per-person connection and is unaffected either way: see [Connect Gmail and Google Calendar](/help/connect-your-tools/connect-gmail-and-google-calendar).

> **Admin only:** Only workspace admins can change email access. Everyone else sees the switch disabled with the tooltip *Only admins can change email access.*

## Limits

- Standard objects cannot be hidden. Only their Writable switch can be turned off.
- A field that is read-only in your CRM can never be made writable in Spiich.
- Object descriptions are capped at 2000 characters.
- Switching an object or field off does not delete anything that is already synced. There is no self-serve deletion; contact Spiich if you need data removed rather than hidden.
- Connecting an optional HubSpot object under **Available to connect** is admin-only, and so is the CRM Emails switch.
- These switches govern what the agent may do. They are not a substitute for permissions in your CRM itself, which still apply to every write Spiich attempts.

## If something goes wrong

**A red `Sync failed` badge sits on an object row.** The last attempt to read that object's schema or records failed. Hover the badge for the reason your CRM returned. A missing permission is fixed by clicking **Reauthenticate** on the banner in Chat; an object your plan does not include is skipped by design.

**The agent says an object is not enabled.** For HubSpot Leads or Tickets, the object was either never connected under **Available to connect**, or its switches are off. See [Connect HubSpot](/help/connect-your-tools/connect-hubspot).

**A Writable switch will not turn on.** Read the tooltip. It is one of the three locks above, and each has a different fix.

**The agent cannot see emails you know are in the CRM.** Either **CRM Emails** is off, or the email came from Attio and you were not on the message. Attio-sourced email is deliberately visible only to the people who were actually on it.

## Frequently asked questions

### Does turning Visible off delete data from Spiich?

No. The data stays synced; the agent simply stops seeing it. That is why the switch is reversible with no import cost. To actually remove data, contact Spiich; there is no self-serve deletion.

### Why can I not hide People or Deals from the agent?

Standard objects are the core the product is built on, so their Visible switch is disabled. You can still make them read-only by switching **Writable** off, which lets the agent use them for context without changing anything.

### What is the point of the object description box?

It gives the agent context it cannot infer from a field list. Writing what an object represents, for example that a custom object holds partner referrals rather than customers, measurably improves how the agent uses it. Each description holds up to 2000 characters.

### Which of these settings are admin-only?

The CRM Emails switch and connecting an optional HubSpot object are admin-only. A member who tries sees *Only admins can change email access.* or *Connecting a HubSpot object requires an admin. Ask an admin on your workspace.* Who is an admin is managed in [Manage your team](/help/workspace/manage-your-team).

## Related

- [Connect your CRM](https://spiich.ai/help/connect-your-tools/connect-your-crm)
- [Connect HubSpot](https://spiich.ai/help/connect-your-tools/connect-hubspot)
- [Your CRM data looks wrong](https://spiich.ai/help/troubleshooting/crm-sync-problems)
- [Map your CRM fields](https://spiich.ai/help/connect-your-tools/map-crm-fields)
- [Trust and security at Spiich](https://spiich.ai/trust)
- [Privacy policy](https://spiich.ai/privacy)
