12. Running it
Team, organisations, permissions, obligations, and the things you hope never to need.
12.1 Your team
Settings → Team. Invite people by email. Three roles:
| Role | Can |
|---|---|
| Owner | Everything, including billing and deleting the organisation |
| Admin | Everything operational — settings, modules, automations, team |
| Member | Day-to-day work; not settings, not destructive actions |
Roles are enforced throughout, not just in the menu. A member who guesses a settings URL gets nowhere.
12.2 More than one organisation
One login can hold several organisations. Switch between them from the selector at the bottom of the sidebar; each has its own contacts, modules, terminology, plan and team.
Three things make this practical rather than merely possible:
All organisations — a single view of contacts and reminders across every organisation you belong to. Useful first thing in the morning, when the question is "what needs me today" rather than "what needs me in this particular organisation".
My network — import contacts from one of your organisations into another. If you run a consultancy and a charity and the same person appears in both, you do not type them twice.
Isolation is real, not visual. Switching organisations is not a filter. The database itself will not return another organisation's rows, so there is no configuration mistake that can make them bleed into each other.
Deleting an organisation
Only the owner can delete an organisation. It is in two places: Settings → Organisation, at the top of the settings page, and Delete this organisation at the bottom of the organisation selector. You confirm by typing the organisation's name exactly as it is shown; the button stays off until what you typed matches. Curly quotes and apostrophes typed by a phone count as the plain ones they look like; capital letters do count, because you can see them.
Deleting is not immediate. The organisation goes into a bin for 30 days, and during that time:
- nothing is sent from it — no email, campaign, sequence step, automation, review request, invitation reminder, Telegram or WhatsApp message, webhook or daily task email;
- nobody can open it, and its API keys, forms, booking pages, invoices, quotes and certificates stop working;
- nothing in it changes, so the owner can restore it from Deleted organisations in
the selector (or
/organizations) exactly as it was.
The one exception is a person asking not to be contacted: an unsubscribe from an old email is still recorded, so a restored organisation cannot write to someone who asked it to stop. Anything that was scheduled to go out while the organisation was deleted — campaigns, sequence emails, webhook deliveries, review requests and reminders — did not go out, and goes out at the next run after the restore; the restore button says so, with the number of campaigns and sequence emails waiting.
After 30 days the organisation is deleted for good, with everything in it, as the Terms (§17) say. Export it first from Settings → Backup if you may need the data.
You are never signed out by a deletion. If you belong to another organisation you are moved into it — the one you joined first; if not, you land on a page where you can create a new one. That page also lists your other organisations, each with an Open button. The same happens to everyone else who was working in the deleted organisation, the next time they open anything.
An organisation with a paid plan that still renews cannot be deleted: cancel the plan in Settings → Billing first, because deleting the organisation would not stop the payments.
12.3 Hierarchy and field visibility
For organisations where not everyone should see everything about a person.
Define your own levels — Volunteer, Leader, Pastor; or Junior, Manager, Director — and record which groups of contact fields each level should see.
The use case is pastoral care and anything resembling it, where a small group leader needs to know a member's name and phone but has no business seeing their pastoral notes. It applies equally to a sales floor where reps should not see negotiated margins.
Today this is recorded, not enforced. Everyone still sees every field, whatever you set here — a group leader with Pastoral switched off still sees the pastoral notes. Treat the screen as a plan you are writing down, not a lock you are closing, until it says otherwise.
Settings → Hierarchy & Permissions.
12.4 Consent and the right to be forgotten
Two GDPR obligations, handled properly rather than as a checkbox.
Consent is logged append-only. When someone consents, or withdraws it, that is recorded permanently with a timestamp. You can show what was agreed and when. An editable consent record proves nothing; this one is a real audit trail.
Erasure is real deletion. Chapter 2 covered the two levels: delete is recoverable, erase is permanent. Erase is the right-to-be-forgotten implementation, which is why it makes you type a confirmation phrase including the person's name.
Also relevant: every marketing email carries a one-click unsubscribe, the suppression list is honoured by every sender in the product, and full export is always available.
12.5 Security
Two-factor authentication is available per user, using an authenticator app. Turn it on in your account. If you handle other people's personal data — and you do, that is what a CRM is — turn it on.
The audit log records sensitive operations: merges, permission changes, hierarchy
edits, key management. Append-only, browsable by admins at Settings → Audit. It exists
to answer "who changed this and when" without anyone having to remember.
Isolation is enforced by the database, not by application code. Described in chapter 2 and mentioned again here because it is the single most important security property of the product: a bug in the application cannot leak another organisation's data, because the rule is enforced one layer below the application.
The same wall holds for the direct links between records. When one record points at another (a deal at its contact and company, a task at the contact it is about, a tag on a contact, an invoice at its customer), both must belong to the same organisation: the database refuses a link to another organisation's record, whatever the application asks. References kept inside settings or flexible fields, such as the steps of an automation or the record a custom field value is attached to, are not links the database can see, so the application checks those instead. The people on your team are the one exception to the database rule, because the same person can belong to several of your organisations.
12.6 Backup and leaving
Settings → Backup. Download everything you have put in: your customer base, your work, your
configuration. Live credentials (your Telegram bot token, your WhatsApp app secret) stay out
of the file and stay yours — regenerate them in Settings. The same
export is available over the API, and any conversation can be exported as a transcript
on its own.
The file carries each table twice: as spreadsheet-ready CSV and as raw data. In the CSV,
a text value that starts with =, +, - or @ gets an apostrophe in front, so a
spreadsheet shows it as text instead of running it as a formula; a plain number like
-12.5 is left alone. The raw data keeps every value exactly as it is stored.
The phrase on that page is deliberate — leave whenever you want, with everything you own. Full export is a design principle rather than a feature request that got built.
It is also, honestly, a sales argument. Moving into a CRM is frightening because moving out of one usually is. Knowing the exit exists is what makes the entrance safe.
12.7 Your plan
Settings → Billing. Your current plan, what each plan includes, and the upgrade path.
Payment goes through Stripe; card details never touch this product.
Plans are per organisation, and so are the invoices. Each organisation in your account has its own plan, its own limits, its own subscription and its own invoice — buying Starter for one does not upgrade the others. That is deliberate: each organisation is its own entity, with its own accounting and its own money, and a separate invoice is what lets you put the expense through the right books.
The upgrade buttons appear only on the free plan. Once an organisation has a subscription, every change — up, down, or cancelling — goes through «Manage subscription» (the Stripe customer portal), which prorates fairly and closes the old subscription properly. Cancelling does not delete anything — you drop to the free plan and your data stays. The portal is also where you update your card and see invoices.
Plans limit users, contacts, automations and sequences. Hitting a limit stops you creating new things; it never breaks what exists.
Your price: it stays yours for as long as you stay on that plan — if we raise a plan's price for new subscribers, yours does not move to it. The one thing that can move it is an inflation adjustment, applied in proportion to your own rate, with at least 30 days' notice. Changing plan yourself, in either direction, moves you to that plan's current price.
12.8 The danger zone
At the bottom of Settings, in red, is the ability to reset the organisation's
configuration: every module off and the Telegram connection removed, with your data
left as it is. It asks for confirmation.
Deleting the whole organisation is not here any more. It is under Settings → Organisation, and it waits 30 days in a bin before anything is removed (12.2).
12.9 What runs on its own
What runs on a schedule, so you know what is happening while nobody is logged in. Times are UTC.
| When | What |
|---|---|
| Every 5 minutes | Sends scheduled campaigns — held, untouched, while your workspace has no email account of its own connected |
| Every 5 minutes | Retries failed webhook deliveries |
| Every 10 minutes | Advances drip sequences — held on their step, untouched, for the same reason |
| Every hour | The daily task email: what is due today and what is overdue. Paused: it will come from your own mailbox, once you can connect it, and until then nothing is sent. The same list is on your dashboard, under "Tasks — today and overdue" |
| Daily, 03:40 | Permanently deletes organisations whose 30 days in the bin are over (12.2) |
| Daily, 06:00 | Health check |
| Daily, 07:00 | Creates birthday tasks and fires birthday events; counts meetings and calls you logged ahead of time as contact, once they have happened (a cancelled booking never counts) |
| Daily, 08:00 | Tells a contact whose pause has ended that your messages will resume — held for the same reason |
| Daily, 09:00 | Sends one reminder for an invitation still not accepted three days after it went out — one per invitation, never a second; held for the same reason |
| Daily, 09:00 | Asks a customer for a review after their order is delivered — held for the same reason |
| Daily, 10:00 | Sends one reminder for a review request that got no answer — held for the same reason |
A few more run for us alone and never touch a contact: reporting to our own dashboard, the morning summary for our team, and clean-ups. Some of them do nothing until the feature they serve is switched on.
If something you scheduled has not happened, the delay is at most one cycle from this table.
12.10 The one thing to get right
Everything in this chapter is administration. None of it is why you bought the product.
If you do only one thing consistently, make it the thing in chapter 3: look at the dashboard each morning, deal with the longest silence, log what happened offline, and stop when someone turns red.
That habit is worth more than every setting on this page.