Integrations
On this settings page you connect external systems to the CRM: email mailboxes, the phone system, marketing tools, and marketplaces. Once connected, data sync and import run automatically in the background.
What can I do here?
- Connect a Gmail/Google Workspace mailbox so incoming emails are automatically captured as tickets
- Set up and verify Amazon SES as an email sending provider
- Connect marketplaces and monitor their synchronization
- Connect the phone system (3CX) so calls are automatically imported and matched to contacts
- Retroactively import historical calls and emails - for the phone system either for a precisely bounded time window or across the full history
- Configure, test, or disconnect existing integrations
- Connect the Microsoft calendar via Microsoft Entra ID - sign-in, directory-administrator consent and encrypted storage of the credentials
Step by step
- Open Settings → CRM → Integrations and choose the relevant tab (CRM, HR, Marketing, Marketplaces).
- Connect a mailbox: Click "Add Mailbox", choose the sign-in type (Google OAuth, Google service account/domain-wide delegation, or generic IMAP/SMTP), and follow the steps.
- Set up the phone system: Enter the API URL, sync interval, and admin credentials under 3CX and save.
- Import historical data: Use the historical import to catch up on emails or calls. For the phone system, the Historical Import section lets you choose between the modes Time window and Full Import (see below). Already-imported entries are never created twice.
- Disconnect: Open the relevant integration and choose "Disconnect"; this stops further data synchronization.
Catch up on calls for a time window (3CX)
Use this route when calls are missing or recorded incorrectly within a manageable period - for example after an outage of the phone system.
- Open Settings → CRM → Integrations, tab CRM, and click the 3CX integration. The panel opens on the right.
- Switch to the Configuration tab and go to the Historical Import section.
- Choose the mode Time window. It is preselected.
- Enter From (date and time) and To (date and time). Both values apply in your own time zone, exactly as the clock reads for you.
- Click Start Import. While the run is working, the section shows the notice "Import running - reading the time window from the phone system …".
- When it finishes, a green box shows the result, for example: "Import finished: 12 new, 3 updated, 15 calls in the window."
- The recovered calls then appear under CRM → Calls and in the Activities of the respective contact.
- 3CX Phone System
- Call History
/settings/crm/integrationsGood to know:
- No duplicates. The run creates calls that are new and brings existing ones up to date. You can therefore safely read the same window more than once, for instance to correct wrong talk times.
- The ongoing sync is left alone. The automatic sync with the phone system keeps track of where it stopped on its own. Catching up on a time window does not move that marker and does not create a gap.
- The time window is in the address bar. Reload the page or pass the link on and your selection is still there.
- Permission. Starting the run requires the permission to manage the CRM or write access for telephony.
Start a full import (3CX)
Choose the mode Full Import in the same section if you want to read in the entire call history - typically once after the initial setup. This run is a tracked job: you see a progress bar and can pause, resume, or cancel it. For large imports spanning many months this is the right route; for a single day or a single hour, Time window is much faster.
Connect the Microsoft calendar (HR)
Take this route if your organisation runs Microsoft 365 rather than Google Workspace. The connection sits next to the Google Calendar card in the HR tab and does not replace it - both can exist side by side.
The prerequisite is an app registration in Microsoft Entra ID. You need three values from it, plus your organisation's directory id.
- Open Settings → CRM → Integrations, tab HR, and click the Microsoft Calendar card.
- Enter the Directory id (Entra ID) - your organisation's directory id or a verified domain such as
contoso.onmicrosoft.com. - Enter Client ID, Client secret and Redirect URI from the app registration. For the secret this means the secret value, not the secret id; Microsoft only shows the value immediately after you create it.
- Click Create. The secret is stored encrypted in your tenant and cannot be read back in the clear afterwards - not even by us.
- Switch the connection on with Activate and click Test connection. If the check reports an error, the directory id, application id or secret do not match.
- Click Prepare consent and then Grant consent at Microsoft. The link opens Microsoft in a new window, where an administrator of your directory grants consent once for the whole organisation. After that no employee has to consent individually.
The requested permissions are offline_access, Calendars.ReadWrite and Calendars.Read.Shared. offline_access is the permission without which Microsoft issues no refresh token at all - without it the connection would be dead after an hour.
What this stage does and does not do: sign-in, consent and the handling of access and refresh tokens are complete. An expiring token is renewed automatically. If consent is withdrawn in the directory, the connection visibly moves to the state "consent withdrawn" and has to be granted again - it does not fail silently. Not included yet: reading busy times and writing approved absences back into the Microsoft calendar. Both follow, and will then run through the same building blocks as the Google side, not through a second source.
Choose the target calendar
A Microsoft account usually holds several calendars - the default one, shared calendars, subscribed holiday calendars. Which one SCS should use is set in the Target calendar section below the consent step.
The prerequisite is that at least one employee has already connected their calendar. That happens in the employee portal, not here - only afterwards is there an account whose calendars can be listed. While nobody is connected, the section says exactly that.
- If several employees have connected, first choose under Employee whose account this is about.
- Under Calendar you see the calendars of that account by name. The default calendar comes first, the rest alphabetically. You never have to type an id.
- Save calendar applies the choice.
If a calendar is already linked it is pre-selected, so you always see what the connection points at.
Good to know:
- If the access token has expired, it is renewed silently while the list loads. You will not notice.
- If consent was withdrawn in the directory, the section says so explicitly instead of showing an empty list. The affected employee then reconnects their calendar.
- Only a calendar the connected account actually holds can be chosen. A link to somebody else's calendar is therefore impossible.
Fields explained
| Field | Meaning | Notes/Effect |
|---|---|---|
| Mailbox Email Address | The mailbox to be connected | |
| Sign-in Type | Google OAuth (browser consent), Google service account (domain-wide delegation, no browser), or IMAP/SMTP | The service account suits automated setup without a user login |
| Host / Port / TLS / Username / Password | Credentials for generic IMAP/SMTP mailboxes | Passwords are stored encrypted |
| Status | Active/Inactive for a connected integration | |
| API URL / Sync Interval (3CX) | Address of the phone system and how often it syncs | |
| Admin Credentials (3CX) | Needed to retrieve call history (CDR) | |
| Historical Import: Mode (3CX) | Time window catches up on exactly the given period, Full Import on the entire history | Time window is preselected |
| From (date and time) | Start of the period to catch up on, to the minute | Only in mode Time window; applies in your time zone |
| To (date and time) | End of the period to catch up on, to the minute | Only in mode Time window; applies in your time zone |
| Backfill (email) | From-date or full import of historical messages | Already-imported entries are skipped |
| Region/Marketplace, Account Name, Credentials | Details for connecting a marketplace | |
| Sync Interval (marketplace) | How often the marketplace synchronizes |
Values & statuses
Connections typically have the states Active, Inactive, Verified/Unverified (for email sending), and Sync Active/Paused (for marketplaces). A "Shadow Mode" toggle lets you run an integration on a trial basis without it taking effect in production yet.
A historical import in mode Time window reports back in four states:
- Import running - reading the time window from the phone system … - the run is working; the button stays disabled meanwhile.
- Import finished: X new, Y updated, Z calls in the window. - green box with the result. New are calls you did not have yet, updated are those whose details were corrected, in the window is the total number of calls read from the phone system.
- Warning inside the result - if the phone system reports only 0 or 1 call for a window longer than 24 hours, an amber warning box appears in addition to the result. The result may be correct (a weekend, for instance), but it is implausibly small: check the sync user's permissions in the phone system or retry the import; if you expect more calls, report the incident.
- Error message - the run could not be carried out, stating the reason (see Frequently asked questions).
An import in mode Full Import runs as a tracked job and additionally knows the states running, paused, cancelled, and completed.
Frequently asked questions
Which sign-in type should I choose for Gmail?
For a single, quickly set-up mailbox, Google OAuth (browser consent) is the right choice. For a permanent, headless connection of entire mailboxes, the Google service account with domain-wide delegation is intended - a Workspace administrator needs to grant that delegation.
What happens when I disconnect a connection?
The mailbox or marketplace is disconnected; already-imported data stays, but no new data is synchronized going forward.
Can I run a full historical import more than once?
Yes, already-imported threads or calls are automatically skipped, so re-running it doesn't create duplicates.
I start the import and seemingly nothing happens. Why?
The section now gives you feedback in every case: first the notice that the import is running, then either the result in a green box or an error message in plain words. The most common messages are:
- "You lack the permission to import calls." - have the permission to manage the CRM or write access for telephony granted to you.
- "No 3CX connection has been set up." - enter the API URL and credentials first and save.
- "The admin credentials of the phone system are missing for retrieving the call list." - add the admin credentials on the same tab.
- "The phone system rejected the request or is unreachable." - check the API URL and credentials and start the run again.
- "The phone system's call list contains rows without a usable call identifier … (error code: TELEPHONY_CDR_KEY_MISSING)" - the phone system's response had an unexpected shape; the run was aborted and nothing was written. Pass the error code on to your administrator.
- "The phone system's call list could not be plausibly separated into individual calls … (error code: TELEPHONY_CDR_GROUPING_COLLAPSED)" - also an unexpected response shape; the run was aborted and nothing was written. Pass the error code on to your administrator.
Why can't I start the import?
Both times are mandatory, and the end must be after the start. If a value is missing or the order is reversed, the form tells you right away, before anything is read at all.
Does a backfill disturb the automatic sync?
No. The backfill only reads the window you chose in addition. Where the automatic sync last stood remains unchanged - so neither a gap nor a duplicate run occurs.
Why can I now also enter a time?
Because outages rarely affect whole days. With a date and a time you catch up on exactly the affected hour instead of reading the entire day again.
Time window or Full - which one do I pick?
Time window for everyday work: closing a gap, correcting wrong talk times, checking a single day. Full for the initial load, when the entire call history of the phone system is to be taken over.
Can I send the chosen time window to someone?
Yes. The selection is in the address bar. Whoever opens the link sees the same period in the form; the import itself does not start on its own.