Email safety
Why Pact refuses to email people outside your workspace, and how to allow it when you mean to.
Pact will not email someone outside your workspace unless you have said it may. That is the default for every workspace, and it stays that way until an admin changes it on Admin → Safety flags.
The reason is blunt: assistants resolve names, and name resolution can be wrong. Asking Pact to "email Priya" searches your mailbox for Priya — and the newest match might be a prospect who cold-emailed you last year rather than the Priya you meant. A confident draft addressed to the wrong real person is worse than no draft, so the lock sits underneath every send path in the product.
What is allowed by default
Without changing anything, Pact can email:
- you — your own address, always;
- your teammates — anyone with a seat in your workspace;
- addresses you have allowlisted — see below.
Everything else is refused, and the refusal is recorded.
Who counts as external
Anyone who is not on the list above: prospects, customers, partners, personal addresses. Being in your CRM does not make someone internal. Having emailed you does not either.
Allowing external email
There are three ways, in increasing order of blast radius.
The allowlist (best for people you email repeatedly)
Add specific addresses on Admin → Safety flags. A design partner or a test inbox belongs here. The list is durable, visible, and reviewable — it does not expire and does not need to be remembered.
A demo override (best for a one-off)
Two scopes:
- One recipient, 5 minutes — name the address; only that address opens.
- All external, 60 minutes — the demo window, behind a typed confirmation.
Both expire on their own. There is nothing to remember to switch off, which is the point: a bypass you have to remember is a bypass that stays on. Every override records who opened it, why, and for how long, and can be revoked early.
Unlocking external sends (the workspace-wide setting)
Turning on External email sends does not mean Pact will email anyone. It moves the workspace from hard locked to consent checked: each external send still needs a basis — a consent record for that address, or the sender explicitly confirming the recipient on the compose card.
What can never be overridden
Addresses on the suppression list — hard bounces, spam complaints, unsubscribes, STOP replies. No allowlist entry and no override will send to them. A mailbox that told us to stop outranks any business reason.
Reading the compose card
When Pact drafts an email, the card leads with the recipient:
- Green — someone in your workspace.
- Amber — an external address you allowlisted, or one an override covers.
- Red — a genuine third party.
The send button always names the destination — Send to [email protected], never a bare Send — so a misread card cannot become a misdirected email. If the recipient is blocked, the button is disabled and the card says why.
The ledger
Every decision, allowed and blocked alike, is recorded with the recipient, the reason, the basis, and which part of the product asked. It is on Admin → Safety flags, and it is what answers "has this workspace ever emailed that person?".