Documentation / Teams and agencies
Working with clients
How agencies and Odoo partners run many clients from one calmo.cloud team: one server per client, shared services with roles, templates and the API.
Agencies run Odoo for many clients at once. In calmo.cloud that is one team for the agency, which hosts every client's servers and services, plus shared services for the clients who need access to their own Odoo, and provisioning templates for a repeatable onboarding.
One team, every client #
Your agency's team is the workspace for all of your clients: their servers, services, repositories, backup destinations and your staff all live there. Clients do not get teams from you; the team of a client is their own organisation's team, created by calmo.cloud when they are onboarded, and it only ever sees what you share with it.
A few habits keep a large portfolio tidy:
- One server per client. A client's Odoo, its database and its files then live on a machine that only carries that client, which keeps data cleanly separated and makes it easy for the client to own and pay for the server themselves. Several services of the same client (production, a test copy) share that server.
- Name by client. Servers and services carry the client's name, so the lists stay readable across dozens of clients.
- Backups to the client's storage. Where a client wants it, add a second backup destination in S3 storage the client owns.
Inside your team, roles decide who may manage the team itself. They do not limit what a member can do with servers and services: every member of your team can add servers, create services, deploy addons and run backups.
- Owner — the person calmo.cloud invited when the team was created. Changes roles and is the only member who cannot be removed. There is exactly one.
- Admin — additionally invites and removes members, manages API tokens and shares services with other teams. The right role for your consultants.
- Member — works with servers and services like everyone else, without touching members, tokens or sharing.
Because every member can reach every client's servers, the team is for your own staff only. Clients get access through sharing, never through membership.
Giving a client access #
Share the service with the client's own team. The client's team sees the service in its own list and works with it as far as the role you chose allows:
- Viewer sees the service, its status and its logs
- Operator additionally starts, stops, restarts and redeploys, and creates and downloads backups
- Developer additionally edits settings, creates copies, manages addons and modules, opens the terminal and runs scripts
- Manager additionally restores backups and manages hostnames
Your team stays the hosting team: the client never gets access to your server, your other clients or your team settings, and you can change or revoke the role at any time. Operator is the usual choice for a client who wants to restart their Odoo and download backups without being able to change anything.
Sharing is being rolled out team by team. If you don't see a Sharing tab on your services yet, get in touch and we switch it on. A client without a calmo.cloud team of their own gets one when they are onboarded; get in touch and we set it up.
Repeatable onboarding #
Define your standard stack once as a provisioning template: the server size at your cloud provider, Postgres and Traefik, the Odoo version, the addon repositories and the backup destinations. Running the template then sets up a new client in one go.
For a client with an existing Odoo, follow the migration guide that matches their current host: Odoo.sh, Odoo Online or another host.
Keeping the fleet healthy #
- Backups — give every service a schedule and, where the client wants it, a second destination in storage the client owns.
- Monitoring — uptime checks and server metrics per service and server, with notifications to the channels your team watches.
- Security — the security checks flag default passwords, exposed database managers and HTTPS issues on every service, so you hear about them before the client does.
- Previews — with preview deployments every pull request on a client project gets a neutralized Odoo copy the client can review before you merge.
Automating the routine #
Everything above is available through the REST API. Agencies typically script the recurring parts: creating a service from a template, attaching a repository, importing a backup, adding a hostname, or collecting the status of every client's service for their own dashboard.