The first question about an agentic CRM is whether an AI can reach the pipeline at all. We answered that one in the free agentic CRM you run from Claude, ChatGPT and Grok: crm2crm ships a native MCP server, and any assistant that speaks the protocol can read and work the CRM. Once teams actually do this, a second question shows up within a week. Who did that?
Teams rarely run one assistant. They run a research agent that scores accounts, a writing agent that drafts follow ups, a tidy-up agent that fills custom fields, sometimes on different models and different platforms. When all of them connect with one person's token, the timeline says that person did everything, revoking one bot means revoking all of them, and nobody can tell which agent changed a deal at 3am. This release fixes that.
Why "the AI is logged in as me" stops working
Connecting an assistant with your own credentials is the fastest way to start, and for one person with one chat window it is fine. It breaks in three predictable ways as soon as the setup grows.
- History lies by omission. A note written by a model and a note you typed look identical. When a deal moves backwards or a field gets overwritten, you cannot tell whether a person or a bot did it, so you cannot fix the bot.
- Access is all or nothing. If three agents share your token, cutting off the one that misbehaves cuts off the other two. Rotating means reconfiguring everything.
- Agents inherit your power. If you are an admin, every agent on your token is an admin too, with the ability to edit pipelines or change roles, which is rarely what you meant.
The fix is the same one companies use for people: give each agent an identity of its own, with its own access that can be granted, narrowed and revoked separately.
What is new, at a glance
| Capability | Where you find it | Who can use it |
|---|---|---|
| AI agent members | Settings → Users → Add AI agent | Owners and admins |
| API key that acts as an agent | Settings → Integrations → API keys → Key for | Owners and admins |
| Connect an assistant as an agent | Connector consent screen → Connect as | Owners and admins |
| Bulk notes and bulk field values | MCP tools bulk_create_notes, bulk_set_field_values | Any connection with write scope |
| Daily briefing for a chosen owner | daily_briefing and update_briefing_settings with owner | Anyone, saved per person |
| NVIDIA free tier for built-in AI | Settings → Integrations → AI providers | Anyone who connects a model key |
AI agents as members of the workspace
An AI agent in crm2crm is a member of your workspace that has a name and no way to log in. You add one from Settings → Users with the Add AI agent button, give it a name that says what it does, Scout for research or Scribe for notes, and it appears in the team list with a bot avatar and an AI agent badge where the email would be.
Under the hood an agent is a real user record, and that is the point. Notes it writes, deals it moves, fields it fills and tasks it creates are stored under its id, so the timeline on every record shows Scout or Scribe rather than the person who set the agent up. It shows up in the owner and assignee pickers too, so you can hand an agent a deal or a task like any teammate. When something looks wrong, you know which agent to look at, and you can read its trail on its own.
What an agent does not get is just as deliberate:
- No login. It has no password and a placeholder address on a reserved domain that cannot receive mail. Password login, password reset and Sign in with Google or Microsoft all refuse it, so an agent can never open a browser session.
- No promotion. Its role is fixed to member. The role menu is replaced with a plain "agent" label, and the API rejects any attempt to make it an admin.
- No seat. Agents are left out of the seat count in the team list and in usage, so adding a few of them costs nothing.
Two ways to plug an agent in
An agent on its own does nothing. You give it a way in, and there are two, depending on whether the agent runs unattended or sits inside a chat assistant you talk to.
Option 1: an API key for the agent
In Settings → Integrations → API keys, owners and admins now see a Key for menu next to the label: Me, or any AI agent in the workspace. Pick the agent, choose read or read and write, optionally pin which model provider the key uses for the CRM's AI features, and create it. The key is shown once, labelled with the agent it acts as. Every call made with it is made as that agent.
This is the route for anything that runs without you: Claude Desktop or Claude Code through mcp-remote, an IDE like Cursor, an n8n or Make workflow, or your own script calling the MCP server or the REST API. A dedicated key per agent means a dedicated off switch per agent.
{
"mcpServers": {
"crm2crm-scout": {
"command": "npx",
"args": [
"-y", "mcp-remote", "https://crm.ln2crm.com/api/mcp/",
"--header", "Authorization:Bearer crm2crm_SCOUT_KEY"
]
}
}
}
The key list shows which agent each key belongs to, and admins can revoke an agent's key from the same list. Members never see agents' keys at all, only their own.
Option 2: connect a chat assistant as the agent
When you add https://crm.ln2crm.com/api/mcp/ as a custom connector in Claude, ChatGPT, Grok or Meta AI, crm2crm shows a consent screen before handing over access. If you are an owner or admin and the workspace has agents, that screen now has a Connect as menu: your own account, or one of the agents. Pick Scribe, approve, and that connector works as Scribe from then on. Approving takes a real sign-in as yourself, so the decision is tied to a person, while the work is credited to the agent. An API key, including the agent's own, cannot approve a connection.
What an agent can and cannot do
Letting software act under its own name is only useful if the limits are enforced in code. These are checked on every call, not left to the model's good behaviour.
- Only admins hand out agent access. Creating an agent, issuing a key for it and connecting as it all require an owner or admin. A member who tries gets a permission error, not a quiet fallback to their own account.
- Only agents can be acted as. The menus never list human teammates, and the API refuses a person's id outright, so nobody can borrow a colleague's identity through this feature.
- Agents stay in their workspace. An admin cannot pick another workspace's agent, even by guessing its id.
- An agent is always a member. The 23 workspace configuration tools that need an admin, such as editing pipelines, changing roles or deactivating users, stay closed to it.
- Scopes still apply. Give Scout a read only key and all 52 writing MCP tools refuse. The 11 destructive tools still demand an explicit confirmation, deletes still go to a 30 day trash, and merges can still be undone.
- One switch turns it off. Deactivate the agent in Settings → Users and its keys and connectors fail on the very next call. Revoke a single key if you only want to close one door.
- Never an owner by accident. If the workspace owner deletes their account, ownership passes to a human teammate, never to an agent, and admin-only actions refuse an agent whatever its role says.
- Secrets stay out of chat. As before, no agent can mint an API key, an invite or a webhook secret through MCP. Those are created in the web UI only.
Bulk tools for agents that work in batches
Agents tend to work in batches: research 150 contacts, then write 150 results back. Doing that one tool call at a time is slow, and on a busy model it eats through rate limits. Two new tools take a list instead.
bulk_create_noteswrites up to 200 notes in one call, each with an entity type (person, organization or deal), an id and the text.bulk_set_field_valueswrites up to 200 custom field values in one call, such as an ICP score, a segment or a last researched date.
Each item is processed on its own and the response reports every one: which succeeded, which failed and why. One bad id does not sink the other 199, and the agent knows exactly which rows to retry.
bulk_set_field_values(items=[
{"entity_type": "person", "entity_id": 4182, "field_key": "icp_score", "value": 82},
{"entity_type": "person", "entity_id": 9999, "field_key": "icp_score", "value": 41}
])
→ {"total": 2, "succeeded": 1, "failed": 1,
"results": [{"index": 0, "ok": true},
{"index": 1, "ok": false, "error": "not_found"}]}
Both are writing tools, so a read only key cannot call them, and every item passes the same checks as the single item versions, create_note and set_field_value.
A briefing for whoever owns the deals
The daily briefing pulls together stale deals, deals closing soon and overdue tasks, using rules you can read and change in chat, like what counts as stale. Until now it always looked at the caller's own deals. That falls flat when the deals belong to someone else, for example an agent that works a sales rep's book, or a manager checking on a teammate.
The briefing now takes an owner, by full name or email. Ask "give me Will Carter's briefing" and the assistant calls daily_briefing with that owner and gets Will's deals plus Will's task queue. To make it your default, say "always brief me on Will's deals" and it saves the choice for you alone: teammates and other agents keep their own briefing. Say "back to my own deals" to switch back.
Free models for the CRM's own AI
There are two kinds of AI in this picture. The assistant you chat with brings its own model. The CRM's built-in AI, the reasons behind lead scores, AI Overview, research notes and inbox triage, runs on a key you connect in Settings, and your records go straight from your workspace to the provider you chose.
Besides OpenAI, Anthropic, the Groq free tier and any self hosted OpenAI compatible server such as Ollama or LM Studio, you can now pick NVIDIA (free tier). Sign in at build.nvidia.com, create a key that starts with nvapi-, and the CRM uses gpt-oss-20b by default, with Nemotron and DeepSeek models one click away. It is rate limited, but it is enough to try every AI feature at zero cost. Connect it as a workspace provider and an agent's key can be pinned to it, so Scout runs its research on the free tier while the rest of the team stays on Claude. Agent keys only offer providers shared with the workspace, because an agent cannot use anyone's personal key.
Which assistants can connect
The endpoint is one URL, with a trailing slash: https://crm.ln2crm.com/api/mcp/. Everything below reaches the same 93 tools and 5 prompts, and every one of them can connect either as you or as an agent.
- Claude and ChatGPT add it as a custom connector and discover the OAuth 2.1 sign-in on their own. No client secret is stored anywhere, because every client is public and protected with PKCE.
- Grok uses a short manual form. The connector card in Settings → Integrations gives you the exact values to paste.
- Meta AI agents complete the same OAuth flow. Its callback address is on crm2crm's approved list, so the consent screen, including Connect as, works the same way.
- Claude Desktop, Claude Code, Cursor and other developer tools use an API key, yours or an agent's, through
mcp-remoteor a bearer header. - Your own code can call the MCP server or the REST API with the same key. The CRM does not care whether the caller is a person, a chat assistant or a cron job.
What we log about agent calls, and what we never log
With 93 tools and several agents per team, we need to see which tools are slow or failing. crm2crm now writes one line per tool call: the tool name, which workspace and which user or agent called it, how long it took, whether it succeeded, the error code if it failed, and the names of the arguments passed.
It never records argument values. The note text, the email address or the field value an agent sends do not appear in that log. Lines are rotated out after seven days, and they exist to find broken or slow tools, not to read your data.
Set it up in five minutes
- Add the agent. Settings → Users → Add AI agent. Name it for its job, so the timeline reads naturally.
- Give it a way in. For a script or a desktop client, create a key in Settings → Integrations → API keys and set Key for to the agent. For a chat assistant, add the connector URL there and pick the agent under Connect as on the consent screen.
- Start read only. Let it read and report for a few days. Widen it to read and write once you trust what it does.
- Watch the trail. Its notes and changes show its name on every record, so reviewing its work is a matter of reading the timeline.
- Switch it off when you are done. Revoke its key, or deactivate the agent to close every key and connector at once.
Frequently asked questions
Can I connect an AI agent to my CRM under its own name?
Can an AI agent log in to the crm2crm web app?
Do AI agents take a seat?
What stops an AI agent from doing too much?
How many tools does the crm2crm MCP server have now?
bulk_create_notes and bulk_set_field_values, which take up to 200 items per call and report each item's result separately.