Every agent starts read-only. It can look at your CRM, but it cannot create, change or delete anything until you let it — and you are asked each time before that changes.
This article covers:
- The default: read-only
- What "proposes" means in practice
- Where permissions are shown
- Capabilities
The default: read-only
A new agent — including your own assistant — can read your CRM and nothing else. The Permissions tab spells it out:
This agent can view your CRM data but can't create, modify or delete anything.
This is not a setting someone forgot to turn on. It is the intended starting point, and plenty of teams never move off it.
What "proposes" means in practice
When you ask a read-only agent to do something that changes data, it does the thinking and then hands you the result to approve instead of writing it. A proposal card appears in the conversation with three buttons: Approve, Reject and Request changes. Your Inbox tells you the conversation needs attention; the card itself is where you decide.
Nothing is written until you click Approve. If a request produced several cards, each is decided separately — approve some, reject others.
This applies to work that runs unattended too. A routine that runs overnight and wants to update fifty records leaves fifty proposals waiting for you, rather than making the changes while you sleep.
Where permissions are shown
Open Agents, click an agent, and its permission summary appears on the right — Read only for most. Open agent page → Permissions shows the detail:
-
Monthly budget (credits) — a spend cap for this agent.
0means no agent-specific cap; the user and organisation caps still apply. - Entity access — which record types it may create, modify or delete. Each action is held separately: being allowed to update a deal says nothing about creating a contact.
Capabilities
Below entity access, Capabilities covers actions that are not about a record type — sending email, managing other agents, delegating work. These are separate from entity access and are granted separately.
Important: if you are expecting an agent to email customers unattended, check this section first. Without the capability it will keep drafting for approval, which is usually the right outcome but surprising if you expected it to send.