--- name: hermios-crm description: Use when the user wants to find, view, create, or update Hermios CRM records such as people, companies, opportunities (deals), tasks, notes, or custom objects, or asks a question that is answered from CRM data. --- # When To Use - "find everyone at Acme" / "who is our contact at Globex" - "add Jane Smith from Acme as a contact" - "move the Acme deal to Negotiation, 60%, closing Nov 30" - "what tasks are due this week" - "add a note to the Globex deal: they want a pilot in Q1" - "how many open deals do we have by stage" Use `$hermios-inbox` when the work starts from an email or meeting, `$hermios-pipeline` for pipeline reviews and briefs, and `$hermios-automations` for workflows. # Steps 1. If Hermios tools are not available, switch to `$hermios-connect`. For a native workspace, call `open_hermios({})` directly. To show a known record, call `open_hermios_record({view, recordId})` directly using a UUID returned by Hermios. See the native workspace tools and completion guidance in `../../references/tool-discovery.md`. After a successful requested write from a native-panel workflow, show the refreshed record with `open_hermios_record` and report the saved result. 2. Read `../../references/tool-discovery.md`. Resolve object names with `list_object_metadata_names`, then `learn_tools` for each tool before its first use. 3. Read through `execute_read_tool` (no approval prompt): `find_many_*` with server-side filters, or `group_by_*` for counts and totals. Fetch only the fields needed. 4. Write. Act, then report: for a change the user asked for that touches up to 5 records, do it without asking again. Search for duplicates first (people by email, companies by domain). Then `create_one_*` or `update_one_*` through `execute_tool`. Link notes and tasks to records with `noteTarget` / `taskTarget` rows. 5. Follow `../../references/safety.md` for anything bulk, destructive, or structural. Vault secret values are never available to Codex; for a password, API key, 2FA setup key or 2FA code, direct the user to "Open in Hermios" on the vault item. 6. Present results following `../../references/result-formatting.md`, with record names linked to `https://.hermios.app/object//` on the user's workspace subdomain (see the workspace origin section of `../../references/setup.md`). # Output Contract - Lead with the answer or the change made, then the records. - Link every record name when the ID and workspace origin are known. - After a write, list each created or updated record with its link and the fields that changed. # Customer setup and Vault Read `../../references/vault-documents-and-signing.md` for Vault boundaries, document uploads and contract-signing limitations. - Use the Vault view in the native panel to find the permitted entry, then open it in Hermios for secret operations. Never request or extract secret values or 2FA codes through MCP. - The **New customer** action in Hermios creates the company and primary contact together. Contract sending is optional, requires configured Documenso variables and a working application runner, and uses the existing web form. The bundled runner is limited to one configured pilot organization; do not promise signing for every organization. Obtain explicit authorization before sending and never claim a contract was sent without a successful result. - For 2FA, use the Hermios web app to create a separate Vault entry with category **2FA**, link it to the company, and enter the provider setup key in Hermios. Codes expire automatically, and each reveal is logged. - The **Needs rotation** view and the **Rotate by** field identify secrets due for replacement. Rotation reminders do not change credentials automatically.