Administration

Users and roles

Setup → Users & assignment lists users, their role (admin or member) and their manager. The manager chain is the role hierarchy used by sharing and approvals.

Sharing

For each object choose who sees records they do not own: public read/write, public read-only or private. Owners, their managers and admins always have full access.

Field history and audit

Changes to key fields (stage, amount, owner, status…) are recorded with who and when. The history is a hash chain: editing or deleting an entry breaks the chain, and the audit page says where.

Security

  • Two-factor authentication with any authenticator app (My settings → Security).
  • Single sign-on (Setup → Single sign-on): connect any OpenID Connect (Okta, Microsoft Entra ID, Google Workspace, Keycloak, Auth0…) or SAML 2.0 identity provider. People choose Sign in with SSO and enter their work email; the domain picks the connection. Options: create the account on first sign-in (with a default role) and require SSO for those domains (admins keep their password). SAML responses must be signed (RSA-SHA256); the page of each connection lists the values to give your provider (entity ID, ACS URL, metadata, redirect URI).
  • Sign in with Google or Microsoft when the client IDs are configured.
  • Login rate limiting and lockout, signed sessions stored in SoliDB.
  • API tokens per user, stored as hashes.

Languages and currency

Users choose English, French, Spanish or Greek in their menu. The organization's currency (USD, EUR or GBP) is set in Setup → Company and applies to every amount and document.

Inviting and deactivating people

In Setup → Users, an admin invites a colleague with their name, email and role: they receive a link (valid 7 days) to choose their password. Deactivate signs someone out everywhere and frees their seat; their records stay theirs. Inviting the same address again brings them back.

Subscription

On a hosted SoliCRM, Setup → Subscription shows the plan, the trial days left and the seats used, and opens the billing page (plans, card, invoices, cancellation through Stripe). When a trial ends without a plan, the CRM turns read-only: everything stays readable and exportable.

Integrations and webhooks

Setup → Integrations connects the company's own accounts: Stripe (online payment of invoices), Yousign (advanced signature of quotes), Aircall and Ringover (calls logged on contacts). Each shows the webhook address to give the service. Below, outgoing webhooks send SoliCRM's events (account, contact, lead, opportunity and case created or updated, deal won, quote accepted, invoice created or paid) as signed JSON (X-SoliCRM-Signature), retried up to five times, with a delivery log. Zapier, Make or n8n subscribe themselves through the API (POST /api/v1/hooks).

Privacy (GDPR)

On every contact and lead, the Personal data panel records consents per purpose (marketing emails, calls, partner sharing) with their history, exports everything held about the person (JSON), and — for admins — erases them: their details and the activities logged on them are anonymised, while deals and invoices stay. Setup → Privacy sets how long unconverted leads are kept, and lists every request (exports, erasures, consents, retention) without personal data. The legal pages (privacy policy, data processing agreement, sub-processors, terms) are at /legal/….

Backups and status

bin/backup dumps every database each night (14 days kept, optional off-site copy with BACKUP_RSYNC_TARGET), and bin/backup --verify restores the latest dump into a scratch database to check it. bin/restore-backup <date> <database> restores into a new database. /status shows whether the service, the database and the last backup are fine (/status.json for monitors).