Administration
Users and roles
Setup → Users & assignment lists users, their role (admin or member) and their manager. The manager chain is the role hierarchy used by sharing and approvals.
Sharing
For each object choose who sees records they do not own: public read/write, public read-only or private. Owners, their managers and admins always have full access.
Field history and audit
Changes to key fields (stage, amount, owner, status…) are recorded with who and when. The history is a hash chain: editing or deleting an entry breaks the chain, and the audit page says where.
Security
- Two-factor authentication with any authenticator app (My settings → Security).
- Single sign-on (Setup → Single sign-on): connect any OpenID Connect (Okta, Microsoft Entra ID, Google Workspace, Keycloak, Auth0…) or SAML 2.0 identity provider. People choose Sign in with SSO and enter their work email; the domain picks the connection. Options: create the account on first sign-in (with a default role) and require SSO for those domains (admins keep their password). SAML responses must be signed (RSA-SHA256); the page of each connection lists the values to give your provider (entity ID, ACS URL, metadata, redirect URI).
- Sign in with Google or Microsoft when the client IDs are configured.
- Login rate limiting and lockout, signed sessions stored in SoliDB.
- API tokens per user, stored as hashes.
Languages and currency
Users choose English, French, Spanish or Greek in their menu. The organization's currency (USD, EUR or GBP) is set in Setup → Company and applies to every amount and document.
Inviting and deactivating people
In Setup → Users, an admin invites a colleague with their name, email and role: they receive a link (valid 7 days) to choose their password. Deactivate signs someone out everywhere and frees their seat; their records stay theirs. Inviting the same address again brings them back.
Subscription
On a hosted SoliCRM, Setup → Subscription shows the plan, the trial days left and the seats used, and opens the billing page (plans, card, invoices, cancellation through Stripe). When a trial ends without a plan, the CRM turns read-only: everything stays readable and exportable.
Integrations and webhooks
Setup → Integrations connects the company's own accounts: Stripe (online payment of invoices), Yousign (advanced signature of quotes), Aircall and Ringover (calls logged on contacts). Each shows the webhook address to give the service. Below, outgoing webhooks send SoliCRM's events (account, contact, lead, opportunity and case created or updated, deal won, quote accepted, invoice created or paid) as signed JSON (X-SoliCRM-Signature), retried up to five times, with a delivery log. Zapier, Make or n8n subscribe themselves through the API (POST /api/v1/hooks).
Privacy (GDPR)
On every contact and lead, the Personal data panel records consents per purpose (marketing emails, calls, partner sharing) with their history, exports everything held about the person (JSON), and — for admins — erases them: their details and the activities logged on them are anonymised, while deals and invoices stay. Setup → Privacy sets how long unconverted leads are kept, and lists every request (exports, erasures, consents, retention) without personal data. The legal pages (privacy policy, data processing agreement, sub-processors, terms) are at /legal/….
Backups and status
bin/backup dumps every database each night (14 days kept, optional off-site copy with BACKUP_RSYNC_TARGET), and bin/backup --verify restores the latest dump into a scratch database to check it. bin/restore-backup <date> <database> restores into a new database. /status shows whether the service, the database and the last backup are fine (/status.json for monitors).