Find production-ready solutions for your business

10 EspoCRM Customizations to Ask Your Vibe-Code Agent For

October 4, 2026 ·

EspoCRM is more configurable than it looks. There is an Entity Manager for data modeling, formula fields, a layout editor, a label manager, roles with field-level permissions, a customer portal, and plain config files on the server. All of it is reachable by the agent, which can work through the admin screens or edit configuration directly and then verify the result. Here are ten customizations worth asking for.

1. A custom entity for the thing EspoCRM doesn’t model

Every business has an object that generic CRMs skip: loaner equipment, installed software, subscription boxes. EspoCRM’s Entity Manager can define a whole new entity with its own fields, relationships, menus, and list views. The agent can create an Asset entity with a serial number, purchase date, and status, link it one-to-many to Accounts, and place it as a panel on the account detail page. Say “Create an Asset entity with serial number, purchase date, and status, linked to Accounts, and show it on the account page.” Your team records it like any native record, and it shows up in search and lists.

2. A formula field that does the math for you

EspoCRM has a built-in formula language for calculated fields. The classic CRM example: weighted pipeline value — amount times probability — so your forecast reflects reality instead of optimism. Say “Add a formula field to Opportunities that multiplies Amount by Probability and shows it as Expected Revenue.” The same mechanism handles commission-style calculations or days-open counters. Formulas live in the admin UI, so your team can see and adjust them later without a developer.

3. Layouts that put the right fields first

Default detail views bury the fields your team uses most. The layout editor controls field order, panels, and the columns on list views, and the agent can rearrange all of them: Amount and Expected Close Date side by side, probability visible in the list, a separate panel for shipping details. Say “Move Expected Close Date next to Amount on the opportunity detail view, and add Probability to the opportunity list.” It is a small change that saves minutes for every record, every day.

4. Rename the vocabulary to match your business

Not every company says “Opportunity” or “Case.” EspoCRM’s label manager can rename any term in the interface, and dropdown values like Lead Source are just as easy to reshape into your real channels. Say “Rename Opportunities to Deals everywhere, and set the Lead Source options to LinkedIn, Referral, Webinar, Expo 2026, and Partner.” New hires stop mentally translating the software into your language, and reports read the way the business talks.

5. Brand the interface with custom CSS

The default theme is clean but generic. EspoCRM accepts custom CSS in its settings, so the agent can set your brand colors on the navbar, buttons, and links, and tune the login page to match. Say “Add custom CSS so the top navbar is our navy #0B2545 and the primary buttons are our orange #F4A259.” It sounds cosmetic, and it is — but it makes the CRM feel like yours rather than a tool you rented, and the agent reloads the page to check contrast before calling it done.

6. Tighten roles and field-level permissions

Out of the box, people can often see more than they should. EspoCRM roles control which records a user can see — none, own, team, or all — and field-level rules can hide sensitive data such as margins from everyone except managers. The agent can audit the current roles against how you say the company works and tighten them. Say “Audit our roles so sales reps only see their own leads and opportunities, support sees all cases but no deals, and margin fields are manager-only.” This is the customization most owners skip and later regret.

7. Turn on 2FA and a real password policy

Your CRM holds your customer list, and the admin accounts are the crown jewels. EspoCRM supports time-based one-time codes for two-factor authentication and password rules you can actually set — minimum length, strength, forced changes. The agent can enable 2FA for every administrator, set a 12-character minimum, and verify that normal login still works cleanly. Say “Enable two-factor authentication for all admin users and set the password policy to at least 12 characters.” It takes minutes and removes the cheapest attack path into your business.

8. A least-privilege API user for integrations

Every integration that reuses someone’s personal login widens your blast radius. EspoCRM supports dedicated API access, so the agent can create an integration-only user, grant it read access to exactly the entities it needs — say, contacts and leads — and record where the key is used so rotation later is a one-line change. Say “Create an API user called integration-bot that can only read contacts and leads, and show me the credentials once.” If the integration leaks, you revoke one key instead of a human’s account.

9. The customer portal, scoped and branded

EspoCRM includes a customer portal: customers log in, read knowledge base articles, and open cases — without emailing you first. The real work is the portal role, which must see only that customer’s own cases and a curated set of KB categories. The agent can enable the portal, build the Customer portal role, publish your first KB articles, and test the whole thing with a dummy customer account. Say “Enable the customer portal so customers can open cases and read our knowledge base, scoped so they only ever see their own cases.” Ticket volume drops surprisingly fast once answers are self-serve.

10. Backups you can actually restore

A backup that has never been restored is a hypothesis. The agent can set up a nightly job that dumps the EspoCRM database and syncs the uploaded-files directory to an S3 or Backblaze bucket off the server, confirm Espo’s cron jobs are running on schedule, and then prove the pipeline by restoring into a scratch database and counting rows. Say “Set up a nightly backup of the database and the uploads folder to our S3 bucket, and prove it by restoring into a test database.” That restore test is the difference between insurance and hope.

See it in action

Official walkthroughs from the EspoCRM team:

Worth a watch next:

Do these roughly in order of regret: roles, 2FA, and backups first, because those are the ones that hurt when they are missing. The cosmetic items are satisfying, but the hardening items are why you run the server yourself. Want the agent already installed beside EspoCRM? Get EspoCRM on OpenSysLab.

More articles