Why I open-sourced agent-crm

Close-up of software development tools displaying code and version control systems on a computer monitor.
Photo by Daniil Komov on Pexels

Every CRM I looked at before building my own fell into one of two camps. Either it had no real interface for an AI agent to work through — no API worth the name, or one bolted on as an afterthought — or it had a full API, and giving an agent access meant giving it the same permissions as a human admin: delete any record, send email as the business, rewrite the pipeline.

That second camp is the one that should worry you more. An agent that can delete a contact or send an email on your behalf is one bad prompt or one bug away from doing real damage to your business and how your customers see it. I didn't want to hand that over, and I didn't think my clients should have to either.

Where agent-crm came from

agent-crm started as a module inside my own consultancy's CRM — the one I built to run my own pipeline. Once agents started doing real work in it — reading contacts, working the call queue, logging what happened on calls, moving deals through stages — I pulled that part out into its own project and gave it an MIT licence.

It's deliberately small on purpose: FastAPI, SQLite and Jinja2 in one Docker container, no external services to wire up. One database file, one admin login, one docker compose up to stand it up.

What an agent can and can't do

The CRM exposes an MCP endpoint, so any MCP-speaking agent can search contacts, pull today's call queue, log a call outcome, and move a deal to a new stage. What it can't do, by design, is delete a record or send email. Those stay with the human who logs into the plain web app and can see, on the same data, everything the agent has done.

That split is the whole point. The agent gets enough access to do the busywork well. The owner keeps the two things that are genuinely dangerous to hand to software that can act on its own.

Why open source, specifically

I could have kept agent-crm closed and sold access to it. I didn't, for the same reason I don't lock clients into automations only I can touch: if you're trusting software with your pipeline, you should be able to read exactly what it does, run it yourself for free, and leave whenever you want. Managed hosting is there if you'd rather not run the container, but the source stays open source either way.

If you're thinking about letting an agent anywhere near your own CRM, a Systems Health Check is a reasonable place to start.

Share LinkedIn X Facebook Email

Recognise this in your own business?

A Systems Health Check maps what's actually costing you time — no commitment beyond that.

Book a Health Check