Prepare your ConnectWise before onboarding: the setup checklist
Current's ConnectWise connection is deep — it reads companies, contacts, agreements, opportunities, projects, tickets, members, and time, and writes back to most of them. That depth means the quality of your first sync is decided in ConnectWise, not in Current. This is the article to read before you paste a single credential: what to create, what to check, and what to clean up, so the first pull and the first push both land.
Work through it in order, and use the "You're ready when…" checklist at the bottom as your sign-off. For the connection walkthrough itself, see "Connect ConnectWise PSA and choose what syncs". For the field-level detail on what maps where, see "ConnectWise sync: the complete field-mapping reference".
Step 1 — Build a least-privilege security role
A ConnectWise API Member carries a security role, and that role is exactly what the API keys can do — no more, no less. Create a dedicated role for Current before you create the member (System → Security Roles → the + button, name it something like Current API), and grant it only what the sync needs. The table below is the whole list, module by module, in the order ConnectWise shows them.
| ConnectWise module → permission | Grant | What Current uses it for |
|---|---|---|
| Companies → Company Maintenance | Inquire: All. Add + Edit: All if you turn on CRM write mode | Reads companies, company types, and statuses; with CRM write mode on, creates and updates companies |
| Companies → Contacts | Inquire: All. Add + Edit: All if you turn on CRM write mode | Reads contacts; with CRM write mode on, creates and updates them |
| Companies → Documents (and Sales → Documents) | Inquire: All. Add: All if you use the Win Quote wizard | The Files chip on a company record, and filing a signed quote PDF onto the company when a quote converts |
| Sales → Opportunity | Inquire: All. Add + Edit: All | Reads opportunities and their stages and statuses; pushes deals, won/lost status, and opportunity notes |
| Project → Project Headers | Inquire: All. Add: All | Reads projects, boards, statuses, and phases; creates a project (and its phases) from a won quote |
| Project → Project Tickets | Inquire: All. Add + Edit: All | Reads project tickets as tasks; pushes dates, status, assignments, new tasks, and task notes |
| Service Desk → Service Tickets | Inquire: All. Add + Edit: All | Reads service boards, priorities, and ticket history for account insight; creates a post-sale ticket from a won quote; pushes ticket dates, status, and notes |
| Service Desk → Service Survey | Inquire: All, only if you use ConnectWise's own surveys for CSAT | Reads service surveys, their questions and their results, so ConnectWise CSAT feeds the company record, the dashboards, the SBR pack, the alerts and the churn flag. Older versions of ConnectWise list the same access as Companies → Surveys — grant whichever your role list shows. Never written |
| Time & Expense → Time Entry | Inquire: All. Add: All | Reads time for profitability; logs time entered in Current. It must be All, not My: the API Member logs time on behalf of your members |
| Finance → Agreements | Inquire: All | Agreements and additions for MRR, coverage, and the renewal dossier. Never written |
| Finance → Invoicing | Inquire: All | Invoiced amounts for the profitability split. Never written |
| Procurement → Product Catalog | Inquire: All. Add: All if you use the Win Quote wizard | Reads products on quotes; creates a catalog product when a won quote line has none |
| Schedule → Schedule | Inquire: All | Members' time off and company holidays, so timelines skip days nobody is working |
| System → Member Maintenance | Inquire: All | The staff roster, matched to Current users by email. The connection test reads this first, so a role without it fails the test |
| System → Table Setup | Inquire: All | Work roles, work types, board statuses, priorities, and communication types (the lookups the time-entry guard validates against) |
| System → My Account | Inquire: All | Lets Current recognize its own writes coming back in a poll so it skips them instead of re-importing them |
- +Every level above is All, not My. An API Member is never the owner of the records it reads, so a My-scoped permission returns nothing.
- +If you leave two-way sync and CRM write mode off, the Add and Edit levels on Companies, Contacts, and Opportunity can stay off too; Current only pushes where you have switched pushing on.
- +Skip everything else — unless you switch on PSA surveys, which needs the Service Survey line above. Expense, HR, Marketing, Procurement beyond the product catalog, and every System permission not listed are not needed. The survey line is only read once a Tenant Admin turns on "Satisfaction surveys" in the ConnectWise drawer; see "Use your PSA's built-in surveys for CSAT".
Step 2 — Create the API Member and mint the keys
- 1Create the API MemberIn ConnectWise PSA: System → Members → API Members tab → the + (new) button. Fill in the required fields, assign the security role from Step 1, and Save. API Members are API-only — they can't sign in to the interface and don't consume a ConnectWise license seat.
- 2Mint the API keysReopen the member, go to the API Keys tab, press +, enter a description like Current sync, and click Save — not Save and Close. The Public Key and Private Key appear on that screen, and the private key is shown exactly once. Copy both into a password manager before you leave the page; a lost private key means minting a new pair.
- 3Name it recognisablySomething like current-sync. Every write Current makes shows up in ConnectWise attributed to this member — which is also how Current recognizes its own edits coming back in a poll and skips them instead of re-importing them.
Step 3 — Find your company ID and site URL
The company ID isn't generated anywhere — it's the value your team types in the Company field on the ConnectWise login screen. The site URL is the host you sign in at: na.myconnectwise.net, eu.myconnectwise.net, aus.myconnectwise.net, or your own hostname if you're on-premises. That's all Current needs — it derives the API address and version path automatically from ConnectWise's own site-discovery endpoint, and re-resolves them whenever ConnectWise moves your instance during an upgrade.
Step 4 — Service-board hygiene
Current reads your service boards for company ticket history — the support record behind sentiment, SBR statistics, and AI account insight. Most ConnectWise instances have boards that hold machine noise rather than customer work: alerts and monitoring, RMM automation, backup jobs, spam and internal IT. Current's board-noise toggles flag the usual suspects as Recommended off but never mute a board for you — you decide, in the setup wizard's mapping step or later under Integrations → ConnectWise PSA → Manage.
- +Know which boards hold real customer conversations before your first sync, so the noise never distorts your stats.
- +Muting a board hides its tickets in Current immediately; nothing is deleted, and nothing changes in ConnectWise.
- +Closed-status hygiene matters too: Current maps a board status to done when ConnectWise itself flags it as a closed status, so a board whose "finished" status isn't flagged closed will show its tickets as forever open.
Step 5 — Member emails must match Current sign-ins
Everything personal in Current — logging time, My Day, an account executive's CRM book — hangs off one link: the ConnectWise member ↔ Current user match. Current makes it automatically on a lowercase email comparison between the member's email in ConnectWise and the person's Current sign-in email. That is the only automatic match; there is no name-based fallback.
- +Give every human member a real email in ConnectWise that exactly matches their Current sign-in email (case aside).
- +Inactive members are not pulled, so they can't be linked at all.
- +If an email genuinely differs, a tenant admin links the person by hand in Users & roles — deliberately admin-only, because claiming a member identity is a security decision.
- +Unlinked people are blocked from logging time and see an empty My Day, so this is the highest-value step to get right.
Step 6 — The Current-side gates
- 1CRM write mode starts at OFFEvery CRM write to ConnectWise — companies, contacts, notes, deals — is blocked until an admin opts in. Off means no CRM writes at all.
- 2Create a test company for the middle rungTest mode allows CRM writes only against companies whose live ConnectWise name starts with "ZZ-Current Test". Create one now so your team can exercise the whole flow without touching a real account, and flip to live only after test writes have landed correctly.
- 3Map your pipeline stagesPushing a deal to a ConnectWise opportunity requires a mapping from each Current pipeline stage to a ConnectWise opportunity stage. Set it in the Manage drawer before your first deal push, or you'll get "This deal's stage isn't mapped yet."
- 4Check the two-way sync switchIt controls task-field pushes. Decide its position deliberately as part of your go-live plan rather than discovering it later.
You're ready when…
- +A dedicated API Member exists with a least-privilege security role: read on everything Current pulls, add/edit only on what you'll push.
- +The public and private keys are minted and saved — you copied the private key before closing the screen.
- +You know your company ID (the login screen's Company field) and your site URL.
- +Every person who will use Current has an active ConnectWise member whose email matches their Current sign-in email, exactly (case aside).
- +You know which service boards are machine noise, so you can mute them in the mapping step.
- +Board "finished" statuses are actually flagged closed in ConnectWise, so done means done.
- +A "ZZ-Current Test" company exists in ConnectWise for the CRM write-mode test pass.
- +Pipeline stages are mapped before the first deal push.
- +If you plan to use ConnectWise's own surveys for CSAT, the security role carries Service Survey: Inquire All (or Companies → Surveys on an older instance).
