← Patronwell
DocumentationPrivacyEULASupport

Patronwell: CRM Panel for Dynamics 365 (docs)

Published at https://greatwork.company/apps/patronwell/docs. Support: hello@greatwork.company, reply within one business day.

What agents see

On a ticket, Patronwell finds the requester's Dynamics 365 contact by every email address on their Zendesk profile (the primary email and every other email identity), matched against the contact's Email, Email Address 2 and Email Address 3. It shows:

  • Contact: name, job title, email, phone, owner, when they were added, extra columns you list.
  • Account (the contact's company): number, website, industry, size, location, relationship type, owner, annual revenue, extra columns you list.
  • Open opportunities for the contact and the account: estimated value, close date (amber within two weeks, red when past), sales stage, probability and owner, then a count of won (with the total) and lost.
  • Cases (Dynamics 365 Customer Service): active first, with status, priority, case number and owner. Hidden if your environment has no Customer Service or the setting is off.
  • Recent activity: phone calls, emails, appointments, tasks and other activities regarding the contact or the account, or where the contact was a sender, recipient or attendee, plus notes, newest first (five, then "Show all").
  • Several contacts with the same email are listed so the agent can pick one.
  • No contact: the account whose website or main email uses the requester's email domain (the website must be that domain or a subdomain of it; mailbox providers such as gmail.com are never matched).
  • Lookup box: any email, contact or account id, or a Dynamics 365 record link.

On a user profile the same panel shows for that user, read-only. On an organization profile Patronwell shows the account whose website or email uses one of the organization's domains, else the account with exactly the organization's name, read-only. Every record has an Open in Dynamics 365 link.

Actions

Available on saved tickets to the agents you allow, each one switchable:

  • Create a contact (email, first and last name, job title, phone, linked to the matched account). Patronwell searches Dynamics 365 again right before creating and asks Dynamics 365 to run your duplicate detection rules, so it never adds a second contact for an email.
  • Add a note to the contact or the account, with a title and an optional link to the ticket.
  • Log a phone call (outgoing or incoming; the contact is recorded as the other party; marked completed unless you untick it) or create a task with a due date, regarding the contact or the account.

Before anything is sent the form shows one sentence saying exactly what will happen. After Dynamics 365 accepts it, Patronwell adds an internal note to the ticket ("Patronwell (Dynamics 365): Added a note to the contact Dana Whitfield", the agent's name and a link to the record) and a tag: patronwell_contact, patronwell_note or patronwell_activity. Records are created by the application user; the text names the agent who did it.

Setup guide

You need a Microsoft Entra admin (or Application Administrator) for step 1 and a Dynamics 365 or Power Platform admin for steps 2 and 3. Patronwell works with Dynamics 365 Sales, Customer Service and other Dataverse-based apps on the commercial cloud and GCC (crm9), in every region. GCC High, China and the retired Germany cloud are not supported.

1. Register an app in Microsoft Entra ID

  1. Microsoft Entra admin center (entra.microsoft.com) > Identity > Applications > App registrations > New registration.
  2. Name: Zendesk panel. Supported account types: Accounts in this organizational directory only. Redirect URI: leave empty. Register.
  3. On Overview, copy the Application (client) ID and the Directory (tenant) ID.
  4. Certificates & secrets > Client secrets > New client secret. Description Zendesk, expiry 24 months (or your policy). Copy the Value now (it is shown once), not the Secret ID. Put a reminder in your calendar 30 days before it expires.
  5. API permissions: nothing to add. Dataverse application users do not need delegated permissions.

2. Create the "Zendesk panel" security role

Power Platform admin center (admin.powerplatform.microsoft.com) > Manage > Environments > your environment > Settings > Users + permissions > Security roles > New role. Name Zendesk panel, business unit: the top (root) business unit. Grant exactly these privileges and nothing else (depth in brackets):

Tab > TablePrivilegeDepthWhy
Core Records > ContactReadOrganizationFind the requester and show the contact
Core Records > ContactCreateUserCreate a contact
Core Records > ContactAppendUserLink a new contact to its account
Core Records > ContactAppend ToOrganizationAttach notes and activities to contacts
Core Records > AccountReadOrganizationShow the account
Core Records > AccountAppend ToOrganizationLink contacts, notes and activities to accounts
Sales > OpportunityReadOrganizationShow opportunities
Core Records > ActivityReadOrganizationShow recent activities
Core Records > ActivityCreate, Append, WriteUserLog a phone call or create a task, and mark it completed
Core Records > NoteReadOrganizationShow notes
Core Records > NoteCreate, AppendUserAdd a note
Service > CaseReadOrganizationShow cases (only if you use Customer Service)
Business Management > UserReadBusiness UnitShow owners and run the privilege check
Business Management > Security RoleReadBusiness UnitConfirm Patronwell does not run as an administrator

Leave everything else at None, in particular every Delete and Write on accounts, contacts and opportunities, Export to Excel, Bulk Delete, and anything that edits users or security roles. Read-only is fine too: leave out the Create, Append and Write rows and the panel works without actions. Save and close.

3. Add the application user

Same environment > Settings > Users + permissions > Application users > New app user > Add an app > pick Zendesk panel > Add. Business unit: the top business unit. Security roles: Zendesk panel only. Create. (Application users need no license.)

Never give it System Administrator or System Customizer. Patronwell checks the application user's roles and privileges every time it opens and refuses to run if it has either, or any privilege that can change security (assign, create or edit roles, create or edit users).

If your environment restricts access with IP firewall rules, allow Zendesk's IP addresses (Zendesk publishes them through its public IPs API); requests come from Zendesk's proxy. If a Conditional Access policy covers workload identities, exclude this app registration or allow Zendesk's IP addresses.

4. Install Patronwell in Zendesk

Zendesk Admin Center > Apps and integrations > Marketplace > Patronwell > Install. Settings:

SettingWhat to enter
Dynamics 365 environmentThe part of your environment URL before .dynamics.com. For https://contoso.crm4.dynamics.com enter contoso.crm4; for https://contoso.crm.dynamics.com enter contoso.crm. Find the URL in Power Platform admin center > Environments > your environment.
Directory (tenant) IDFrom step 1 (a GUID, or your tenant's verified domain)
Application (client) IDFrom step 1
Client secretThe Value from step 1. Stored as a secure setting: agents never see it, and Zendesk only sends it to login.microsoftonline.com
Who may take actionsagent (everyone, default), admin, custom role ids, group:<id>, comma separated
Allow creating contacts / adding notes / logging calls and tasksSwitch any action off
Show casesOn by default; shown only when your environment has Customer Service
Match an account by email domainOn by default
Extra contact fields / Extra account fieldsUp to 10 column logical names each, with an optional label: new_supporttier = Support tier, creditlimit. Find logical names in Power Apps > Tables > the table > Columns.

5. Run the setup check

Open any ticket as a Zendesk admin. If anything is missing, Patronwell opens its setup check (admins can also open it from "Setup check" at the bottom of the panel). It runs each step live and changes nothing:

  1. App settings in Zendesk: the environment value, tenant and client ids are well formed. If you pasted the full URL, it shows the exact value to type. There is also a box to paste your environment URL into.
  2. Sign-in to Microsoft Entra ID: Microsoft issues a token for your environment. Errors name the setting: unknown tenant, no app with that client id, wrong secret (often the Secret ID instead of the Value), expired secret, no such environment in the tenant, Conditional Access.
  3. Application user in Dataverse: the app registration is an active application user in the environment.
  4. Security role (least privilege): the roles it has; refused if administrator-level; a warning if it can delete or edit more than Patronwell needs.
  5. Read customer records: contacts and accounts can be read; lists any missing privilege by tab, table, privilege and depth.
  6. Actions agents can take: each action is ready, turned off in the settings, or needs a named privilege.
  7. Opportunities and cases: shown, hidden until the role can read them, or not part of your environment.

When every step passes, choose Open the panel. Agents who are not admins see "Patronwell is not set up yet" until it does.

Security model

  • The secret stays in Zendesk. The client secret is a secure setting with the body scope only. The sign-in request to https://login.microsoftonline.com/<tenant>/oauth2/v2.0/token carries a {{setting.client_secret}} placeholder; Zendesk's proxy fills in the value outside the browser. The manifest's domain whitelist is login.microsoftonline.com and {{setting.environment}}.dynamics.com, so Zendesk will only ever send the secret to Microsoft, whatever is typed in the settings.
  • The access token is short-lived and bounded by the role. Microsoft answers with an access token for your environment that reaches the agent's browser (Zendesk's proxy cannot chain a sign-in and a data request). Patronwell keeps it in memory only, never in browser storage, notes or logs, and replaces it shortly before it expires (Microsoft sets the lifetime, usually 60 to 90 minutes). It can do exactly what the application user's security role allows and nothing more. That is why the role above reads and appends but cannot edit or delete, and why Patronwell refuses administrator roles.
  • To revoke access at once, delete the client secret in Microsoft Entra ID (no new tokens) and disable the application user in Power Platform admin center.
  • Zendesk-side limits (who may take actions, which actions exist) are enforced by the sidebar; the security role is the hard limit.

Data

Read live while the sidebar is open; never copied, stored, cached or exported; no Great Work server; no analytics; no AI. Writes only when an agent confirms one, on one ticket. Full details in the privacy policy (https://greatwork.company/apps/patronwell/privacy).

Troubleshooting

MessageFix
"Enter only the part of the environment URL before .dynamics.com"Change the Environment setting to the value shown
"Microsoft did not accept the client secret"Paste the secret's Value, not its Secret ID; or create a new secret. A secret containing a plus sign also fails: create a new one
"The client secret has expired"Create a new client secret and paste its Value
"No app with this Application (client) ID"Copy the client ID from the app registration's Overview, in the same tenant as the tenant ID
"found no Dynamics 365 environment"Check the Environment setting and that the environment is in the same tenant
"has no active application user"Add the app registration as an application user (step 3), or enable it
"has the System Administrator role" / "can change security"Give the application user only the Zendesk panel role
"is missing Core Records > ..."Add the named privilege at the named depth to the Zendesk panel role
"No Dynamics 365 contact for ..."The emails differ: use the lookup box, or add the address to the contact's Email Address 2 or 3
"already has a contact"Another contact holds that email; Refresh and use the lookup box
No actions shownYour role or group is not in "Who may take actions", the action is off, the role lacks the privilege (setup check step 6), or this is a new ticket, user or organization profile
"is not a column in Dynamics 365"Fix the logical name in Extra contact or account fields
"Dynamics 365 is limiting requests"Service protection limits; wait a few seconds and Refresh

Uninstalling

Uninstalling deletes the settings, including the stored secret. Delete the client secret (or the whole app registration) in Microsoft Entra ID and the application user in your environment. Internal notes and patronwell_* tags on tickets, and records created in Dynamics 365, stay.