Agent connections: let an outside AI agent work in your CRM

How to connect an outside AI agent (for example one running on Paperclip or Claude Code) to your CRM with a key, choose what it may do, approve or decline what it asks for, see what it did, and remove its access.

Updated

An agent connection lets an AI agent that runs outside Interdatum work in your CRM. The agent can be one you run on Paperclip, in Claude Code, in Cursor, or in any other tool that supports MCP servers. You give the agent a key. You choose what the key may do. Unless you choose otherwise, anything the agent wants to change or send waits for you to approve it.

Agent connections are included with the Starter and Pro plans. Only owners and admins can set them up.

What can a connected agent do?

A connected agent can look things up in your business and ask to do things in it. It works with the same information and actions as the built-in AI assistant: clients, jobs and the calendar, tasks, estimates, invoices and payments, leads and campaigns, messages, voicemails, services and pricing, team invites, automations, scheduled actions, business settings, custom records and files.

The agent works as the person who created its key. It can never see or do more than that person can. If that person is deactivated or stops being an admin, the key stops working.

Everything the agent sends still follows your normal rules. Unsubscribes are respected. Your sending limits and your plan limits apply.

How do I connect an agent?

  1. Go to Settings → CRM Settings and find Agent connections.
  2. Click Connect an agent.
  3. Give it a Name you will recognise, such as the name of the agent. Requests from the agent show this name.
  4. Under What it may do, pick an access choice. Ask first is selected to begin with. The choices are explained below.
  5. Click Create key.

You then see the key once, with a Copy key button. Copy it now. Interdatum does not keep a copy and you won't see it again. If you lose the key, remove the connection and create a new one.

Under the key you get ready-made setup text for Paperclip, for Claude Code and for other MCP clients. When you have saved the key, click I've saved the key.

Treat the key like a password. Anyone who has it can do what the key allows. A business can have up to 25 active connections.

What are the access choices?

There are five. You can change the choice later with Change access. A change applies the next time the agent does something. The key stays the same.

  • Look only: The agent can look things up. It can't change or send anything.
  • Ask first: The agent can look things up. Anything it wants to change or send waits for an owner or admin to approve it.
  • Act on CRM data: Everyday changes to your own CRM data (adding or editing a client, tasks, lead statuses, scheduling a job) happen straight away. Messages to people, money, bulk changes, setup, team changes and deletes still wait for approval.
  • Full access: The agent does everything without asking. See the section on Full access below before you choose it.
  • Custom: You choose what happens for each kind of change, which parts of the business the agent can use, and rules for individual tools.

If you are not sure, start with Ask first.

What can I set with Custom?

Choosing Custom opens a permissions editor. It starts from the choice you had selected, so you only change what you need.

What needs approval. Looking things up is always allowed in the areas the agent can use. For each kind of change you pick Not allowed, Ask first or Allowed:

  • Everyday CRM changes: add or edit a client, create or finish tasks, change a lead's status, schedule a job or assign someone to it.
  • Bulk changes, setup and automations: change many records at once, change services and how the business is set up, or set up things that run later on their own.
  • Messages to people: send texts and emails to clients, leads and staff.
  • Money: estimates, invoices, payments, refunds and taxes.
  • Team and settings: invite or change team members and change business settings.
  • Deleting: delete, void, archive or deactivate things.

Not allowed means the agent can't do it and doesn't see the tools for it. Ask first means it becomes a request you approve. Allowed means it happens straight away and nobody checks first.

What the agent can use. Each part of the business has a checkbox, for example Clients, Jobs and calendar, Messages, or Estimates, invoices and payments. All are ticked to begin with. An area you untick is hidden from the agent completely. It can't look anything up there either. One area, Data queries, can read across the whole business, so untick it if you are hiding other areas.

Individual tools. Open this list to set a rule for one tool, such as sending a text or recording a payment. You can search the list. Each tool can be Default, Not allowed, Ask first or Allowed. Tools that only look things up can be Default or Not allowed. A rule for one tool wins over the rules above. Default removes the rule.

A line under the editor sums up the result in plain words: what runs without asking, what asks first and what is not allowed.

What does Full access mean?

With Full access the agent does everything without asking. It can message your customers, send estimates and invoices, record payments, change prices and settings, and delete things. Nobody checks first.

Some limits still apply. Unsubscribes are respected. Your sending limits and plan limits still apply. The agent can never do more than the person who created the key. It can't change billing, phone numbers or account security. Everything it does is listed in the connection's activity and under Done without approval.

Because of what it allows, Interdatum asks you to confirm before it saves Full access. The same confirmation appears for Custom permissions that allow messages, money, team and settings changes, bulk changes or deletes without approval. In the list, these connections carry an Acts without approval badge.

Use Full access for an agent you trust with a narrow job, once you have seen how it behaves. Start with Ask first. If you only want one or two things to run on their own, use Custom and allow just those.

How do I connect from Paperclip?

  1. In Paperclip, open Apps and choose the custom connector.
  2. Pick Connect your own MCP server (a short wizard) or Paste a config. Either works.
  3. Enter the server address shown in Agent connections. It ends in /api/mcp.
  4. Paste the key on its own, without the word "Bearer". Paperclip adds that itself.
  5. Choose which agents can use the connection. The wizard has a step for this.

If you use Paste a config, paste the config from the Paperclip tab. It has a placeholder where the key goes:

{
  "mcpServers": {
    "interdatum-crm": {
      "type": "http",
      "url": "https://crm.interdatum.tech/api/mcp",
      "headers": { "Authorization": "Bearer <YOUR_KEY>" }
    }
  }
}

Paperclip asks for the key separately and stores it as a secret.

A few things to know about Paperclip:

  • One connection uses one key, shared by every agent it is installed on. To give agents different permissions, create one Interdatum key for each agent or group, and add each key as its own connection.
  • Paperclip has its own "ask first" setting for each tool. If the Interdatum key is also on Ask first, things get approved twice. Pick one place. Either keep approvals in Interdatum and set Paperclip to allow, or give the key more room here and use Paperclip's ask-first.
  • Paperclip gives each tool call about 10 seconds.
  • Paperclip hides some text on its side, such as fields that look like passwords or tokens. It may block a result that reads like an instruction to the agent. This can occasionally happen with customer emails or texts.
  • Paperclip skips an identical repeated change within the same run.
  • After you change a key's permissions in Interdatum, refresh the connection's tool list in Paperclip so it matches.

How do I connect from Claude Code?

Copy the command from the Claude Code tab and run it in your terminal. It looks like this, with your own address and key:

claude mcp add --transport http interdatum-crm https://crm.interdatum.tech/api/mcp --header "Authorization: Bearer <YOUR_KEY>"

How do I connect another MCP client?

Use the config from the Other MCP clients tab. Most tools that support MCP servers accept it. Paste it where your tool keeps its MCP servers. It is the same config as the Paperclip example above, with your key in place of <YOUR_KEY>.

How do I approve what an agent asks for?

When an agent wants to do something that needs approval, it becomes a request. Nothing happens until an owner or admin decides.

Requests appear at the top of Agent connections, under Waiting for your approval. Each one shows which agent asked, what it wants to do, what kind of change it is and when it expires. The card is the same confirmation card the AI assistant uses:

  • Click Approve to do it. Some cards offer two choices, such as Save as draft and Approve & send.
  • Click Edit to change it before you approve.
  • Click Decline to turn it down. Nothing changes.

Everything is checked again when you approve. A request expires after 7 days if nobody decides. Any owner or admin can decide, not only the person who created the key.

Owners and admins also see a line in the dashboard's Needs attention list when requests are waiting. It links to this section.

Decided in the last 7 days shows recent requests and what happened to them.

How do I see what an agent did?

Click Activity on a connection to see its recent activity: what it looked up or asked for, what happened and when. Activity is kept for 30 days.

Each connection also shows when it was last used, which tool last connected with the key and how many calls it has made.

If an agent has access that lets it act on its own, Done without approval lists what it did in the last 7 days, with the agent's name and a link to its activity.

How do I remove a key?

Click Remove on the connection, then confirm. The agent stops working immediately. Removed connections stay in a Removed list so you can see what stopped working and look at their activity.

Requests the agent already made stay in the approval list. You can still approve or decline them.

A removed key can't be turned back on. Create a new connection instead.

What can't an agent do?

  • Approve its own requests. An agent can look at a request it made and withdraw it. Only an owner or admin can approve it.
  • Change your plan or billing, buy or release phone numbers, connect payment accounts, or change passwords and account security. These stay in Settings.
  • Do more than the person who created the key, or more than the key's access allows.
  • Start work that runs Interdatum's own AI, such as background AI tasks, routines and systems.
  • Use a key from another business. A key works for one business only.

Why can't I create a key?

  • You see "Included with Starter and Pro". Agent connections need the Starter or Pro plan. Click See plans. If a business with connected agents moves to a plan without AI features, the agents no longer get any tools. You can still see and remove the connections.
  • The Connect an agent button is greyed out. The business already has 25 active connections. Remove one you no longer use.
  • You don't see Agent connections. Only owners and admins can open Settings.