Administration

User management and access control software for growing teams

CrmLeaf's administration tools put one people list, ownership-scoped permissions, and configurable menus at the center of the platform, so a 10-person team and a 300-person company run on the same core system.

  • Free trial
  • No credit card
  • Free onboarding
admin capabilities
16
admin capabilities
record-visibility scopes
5
record-visibility scopes
people list for every module
1
people list for every module

What's inside

Sixteen administration capabilities

Grouped by the job they do. Pick any one to jump to the details.

In detail

How each capability works

01 / 16

User Management

User Management treats the user account as the spine of the platform, cleanly separated from the HR/employee record and the client record. One people list shows everyone in the company, so granting login, assigning a role, or deactivating someone doesn't mean hunting across three different screens.

Built in

  • Grant or revoke login, assign roles, and activate or deactivate a person from one screen
  • Convert a contact to an employee or client without re-entering their details
  • Invite by email with a welcome message, or bulk import a team
  • A last-administrator guard stops an account from accidentally locking itself out
  • One people list
  • Email invites with welcome mail
  • Bulk import
  • Last-administrator guard
02 / 16

Roles, Permissions & RBAC Guardrails

Roles control which pages a person can open; ownership-scoped permissions control which records they see once they're there. Condition-based RBAC guardrails enforce the dependencies a permission grid should always have enforced, so a save that doesn't make sense is refused rather than silently applied.

Built in

  • Entrust roles (admin, employee, client) plus custom fine-grained permissions
  • Ownership-scoped visibility - control not just page access but which records each role sees
  • Guardrails enforce that Update/Delete needs View, Add needs View, and a sub-feature needs its parent's View - incoherent saves are refused
  • Admin / employee / client roles
  • Ownership scoping: none/owned/added/both/all
  • Guardrails on Update, Delete, Add
03 / 16

Configurable Navigation Menus

A Super Admin lays out the sidebar per product edition - grouping, order, and labels - behind its own RBAC-gated editor. A layout can place, reorder, rename, group or hide a feature, but it can never grant access: the gates that decide what a tenant may reach stay in the registry, separate from how the menu looks.

Built in

  • Menu layouts configured per product edition, with layouts clonable between editions
  • A two-layer shell (accordion rail plus one fly-out) alongside the legacy per-app sidebar style
  • Users pin favorites to a Quick Access area and move a group between the rail and the fly-out - saved per user and per company
  • Per-edition layouts, clonable
  • Two-layer shell: rail + fly-out
  • Per-user pinning / Quick Access
04 / 16

Saved Views & Per-User Start Page

A saved view names a listing screen's filters, sort order, mode (table vs. board), page length and columns, so the screen reopens exactly as it was left. Around 47 listing screens support it, and each person can also set the specific screen they land on right after login.

Built in

  • Save a view's filters, sort, mode and columns, and reopen it in one click
  • Share a useful view with your team, or keep it private to yourself
  • Per-user start page - each person picks the screen they see after signing in
  • ~47 listing screens
  • Private / team / org visibility
  • Set-as-default, pinnable
05 / 16

Custom Fields

Custom fields and custom field groups let a record carry the exact data your business tracks, instead of forcing every company into one generic schema.

Built in

  • Add fields to the records that need them, grouped for a cleaner form
  • No code or developer time required to add a field your team actually uses
  • Custom fields
  • Custom field groups
06 / 16

Multi-Currency & Localization

Multi-currency support with automatic exchange-rate refresh means an invoice, estimate or deal can carry its own currency rather than forcing every document onto your home currency. Localization and installable language packs extend that to the interface itself.

Built in

  • Multi-currency with exchange-rate refresh and per-document currency
  • Localization support, with installable language packs available as an add-on
  • Per-document currency
  • Automatic exchange-rate refresh
  • Installable language packsAdd-on
07 / 16

Sign-in & Security

Sign-in supports email/password as well as Google and Microsoft social login, with two-factor authentication (a TOTP app or email) for teams that need it. For API and AI-assistant access, personal access tokens scope exactly what an integration or assistant can do, without sharing a person's own login.

Built in

  • Email/password login plus Google and Microsoft social login and signup
  • Two-factor authentication via a TOTP app or email
  • Personal access tokens for API and MCP (AI assistant) access
  • An email-verification cutoff date that grandfathers existing users when verification is switched on
  • Google & Microsoft login
  • Two-factor authentication (TOTP + email)
  • Personal access tokens
  • Email-verification cutoff
08 / 16

GDPR, Audit Log & Backup

Consent tools and public GDPR pages keep data-collection compliant without a manual process; an audit and recent-activity log means an admin can see who changed what; and database backup with an in-app updater keeps the platform itself current without an engineering ticket.

Built in

  • GDPR consent tools and public consent pages, with admin approve/reject
  • Audit and recent-activity logging across the account
  • Database backup and an in-app updater
  • GDPR / consent tools
  • Audit / recent-activity log
  • Database backup
  • In-app updater
09 / 16

Multi-Company Workspaces

Every CrmLeaf account is an isolated company (tenant), and organizations or workspaces inside a company let branches, brands or business units stay separated without separate subscriptions. One user can belong to multiple companies and switch between them from the same login.

Built in

  • Multi-tenant architecture - every account is its own isolated company
  • Organizations/workspaces inside a company for branches, brands or business units
  • One user, multiple companies, one login to switch between them
  • Multi-tenant SaaS
  • Organizations / workspaces
  • Switch between companies, one login
10 / 16

Subdomain & CyberSecurityAdd-on

Two administration capabilities are sold as add-ons rather than included in every plan: a per-tenant subdomain for white-label host routing, and a CyberSecurity module adding email/IP blacklists and login-expiry policies for accounts that need a stricter security posture.

Add-on

  • Subdomain - white-label host routing per tenant
  • CyberSecurity - email/IP blacklists and login-expiry policies
  • White-label subdomain
  • Email / IP blacklists
  • Login-expiry policies
11 / 16

Multi-organisation

An Organization is a workspace inside one Company - a branch, brand or business unit that shares the Company's subscription, settings and user base, but keeps its own working records. A default organisation is created automatically with every account, and more can be added.

Built in

  • Add one Organization per branch, brand or business unit that needs its own working area
  • Filtering applies within the Company, on the record types that carry an organisation
  • Users select the active organisation, held in session and validated on each request
  • Default organisation auto-created
  • Shares Company plan & settings
  • Workspace picker after sign-in
12 / 16

Customisation & Branding

The company profile holds the identity clients see: company details, logo and theme, plus app-level preferences and custom links. Invoices, estimates, proposals and contracts all render using it.

Built in

  • Company details, logo and theme shown on every client-facing document
  • Per-company subdomain for white-label hosting is a separate add-on
  • Company profile & logo
  • Theme & app settings
  • Custom links
13 / 16

e-Sign

Contracts and proposals carry a built-in public signable link with signature capture from both the client and your company. For teams that need a recognised third-party e-signature provider, a DocuSign connection is available as an add-on.

Built in

  • Public signable contract and proposal links, capturing signatures from both parties
  • DocuSign integration for a recognised third-party e-signature provider (add-on)
  • Public signable link (built in)
  • Dual e-signature
  • DocuSign connectionAdd-on
14 / 16

Custom SMTP

Email your account sends - invitations, invoices, payment reminders, two-factor codes - uses your own mail configuration and your own branding. A built-in test confirms delivery before you roll it out.

Built in

  • Per-company SMTP settings with your own mail provider credentials
  • A test-send action to confirm delivery before relying on it
  • Powers invitations, document sending, payment reminders and email-based 2FA codes
  • Per-account SMTP configuration
  • Built-in send test
  • Underpins invites, invoices & 2FA email codes
15 / 16

Login & Access Policies

Security settings, two-factor authentication (TOTP app or email), and Google/Microsoft social login are core to every account. The CyberSecurity add-on adds email/IP blacklists and login-expiry policies on top.

Built in

  • Account-level security settings, separate from record-level permission scopes
  • Two-factor authentication via TOTP app or email, configurable per account
  • Email and IP blacklists plus login-expiry policies via the CyberSecurity add-on
  • 2FA: TOTP or email
  • Social login (Google/Microsoft)
  • Blacklists & login-expiryAdd-on
16 / 16

Holidays & Work Calendar

Company holidays are specific dates; weekly offs are recurring non-working days of the week and are fully configurable, so an account isn't limited to a fixed Saturday/Sunday weekend. Both feed rostering, attendance and leave logic.

Built in

  • Company holiday calendar, entered per date with a name
  • Configurable weekly offs - not fixed to any particular days
  • Feeds roster, attendance and leave logic as the non-working-day reference
  • Dated company holidays
  • Configurable weekly offs
  • Calendar & table views

Runs underneath everything

Every module in CrmLeaf runs on this same administration layer

CRM, invoicing, projects, HR and support all read from the same user list, the same roles, and the same audit log - a permission set doesn't need to be rebuilt module by module.

  • CRM & SalesOwnership-scoped deal and lead visibility
  • AnalyticsPer-company dashboard widget selection
  • AI & AutomationMCP access scoped to the same permissions as the person
  • Mobile appSame roles and start page, on Android and iOS
One user list · one set of roles · one audit log

FAQ

Common questions about CrmLeaf's administration tools

Permissions, menus, multi-company access and add-ons - the questions admins ask before they roll CrmLeaf out to a team.

  • Yes. Ownership-scoped permissions decide which records each role sees - none, only their own, only what they added, both, or all - separately from whether a role can open a page at all.

Set up roles and permissions your way

Bring your team over, assign roles, and see ownership-scoped permissions working before your trial ends.