MIT-licensed CRM options, by shape

2026-09-30 · edited by Aetha Editorial

Most well-known open-source CRMs are AGPL-family, which is fine for self-hosting your own instance and a problem the day you want to embed the thing, resell on top of it, or keep derivatives private. The MIT-licenced options exist, but they differ by shape — and the shape matters more than the licence.

The vendor facts below come from one place: docs/strategy/COMPETITOR_MAP.md, researched August 4, 2026 with a re-check pass on August 20, 2026. Per-entry dates say which pass each fact comes from. Licence descriptions are factual summaries, not legal advice. We refresh comparison content on a 90-day clock.

The AGPL landscape, as researched

  • Twenty (re-checked 2026-08-20, 55.2k stars): AGPLv3 core with a "Twenty Application Exception" for apps built on published APIs, MIT for SDK and UI packages, and commercial terms for files marked Enterprise. The review re-read the LICENSE file on that date. Native MCP confirmed for Cloud workspaces; self-host parity unverified there, so unverified here. Our full write-up is Accordo vs Twenty.
  • Relaticle (re-checked 2026-08-20): AGPL-3.0, Laravel and Filament, advertising 32 MCP tools in its repo description. Agents operate the CRM through MCP but cannot reshape it — customization is runtime configuration inside a fixed app — with solo-maintainer scale recorded alongside. See Accordo vs Relaticle.
  • Frappe CRM (2026-08-04): AGPL app on the MIT-licensed Frappe framework, DocType metadata model, managed cloud, ERPNext ecosystem. See Accordo vs Frappe CRM.
  • EspoCRM and SuiteCRM (2026-08-04, not re-verified): AGPL, legacy PHP, 3.2k and 5.6k stars that day. See Accordo vs EspoCRM and SuiteCRM.
  • Odoo CRM (2026-08-04, not re-verified): LGPL community plus proprietary Enterprise, with AI features Enterprise-only per secondary sources. See Accordo vs Odoo.

The MIT options, by shape

A fixed app: Comp AI's CRM (re-checked 2026-08-20): MIT, 8.7k stars, 211 commits, single-tenant by explicit design, Vercel-coupled, no MCP package. The August re-check is blunt that the old "thesis demo" verdict no longer holds: it ships working authentication, a durable scheduler, and live providers — things this framework does not ship, stated plainly. If you want an agentic CRM to run rather than code to own, that is the MIT app. See Accordo vs Comp AI CRM.

A template: Atomic CRM (2026-08-04): MIT, React Admin plus Supabase distributed through a component registry — copied into your repo, genuinely yours. Templates carry no workflow engine, no policy or approval, and no audit, which is precisely the machinery a CRM accumulates after the screens are done. See Accordo vs templates and starters.

A framework: Accordo. MIT since Milestone 0 (LICENSE, package.json, site/brand.json under ADR-023): a coding agent generates a bespoke CRM as reviewable, owned code. A module manifest becomes a migration, a service, a REST resource, an SDK method and Admin screens (C-01). Commercial policy is deterministic code: a renewal at or above the threshold stops and waits for a named human (C-03), the agent cannot approve on the human's behalf, asserted by a test (C-04), and every mutation leaves an audit event and a step-level trace (C-16). SQLite is Node's built-in adapter; PostgreSQL needs one pinned driver (C-17).

Shape first, licence second

Get the shape wrong and the licence will not save you: a template when you needed approvals, a fixed app when you needed your own schema, a framework when you needed something running this afternoon. Get the shape right under MIT and no vendor runtime can ever re-tier you.

The boundary travels with the recommendation: this is a framework for developers, not a hosted product (L-07), and no authentication ships, so a deployment supplies the verifier (L-01). Every claim and every limitation is on one page, and so are the questions this project refuses to answer.

What this post does not mean

These pages describe this repository at this commit. None of them implies the framework is deployable, and none of them is a roadmap: nothing that is not merged appears on this site, in any tense.

  • No authentication ships: the framework authenticates nobody. Production Spine v1 (ADR-038) gives the framework verified identity, organizations and memberships, server-authoritative authorization and one tenant per application instance — so tenancy and authorization now exist and are enforced. What does not exist is authentication: no login, password, session or OIDC implementation ships, and a deployment must supply the adapter that verifies the request. Production mode refuses to start without one. In local-development mode an actor header is accepted as an assertion and is not an identity, which is the default developer posture. This is not shared-database multi-tenancy and it is not a readiness claim.
  • Not shared-database tenancy. createAccordoAppAsync can boot one tenant onto dedicated PostgreSQL databases. Shared-database row-level tenancy is not implemented, and this is not a production-readiness claim.
  • Timers exist; a service that runs them for you does not. Durable jobs, a transactional outbox and scheduled asks exist for self-hosted applications that explicitly start a worker. Nothing autostarts; a timer opens an ask, never makes a decision, and no managed worker service or recurrence is included.
  • No email, calendar or marketing integrations. An in-memory notification provider contract exists. MK1 marketing records supplied funnel observations and human-reviewed proposals only; it has no sending, publishing or spending path.
  • The build benchmark has not been run. The protocol is designed and published; no Successful Agent Build Rate exists yet. Any number you see quoted for this project is not ours.
  • Ownership means vendored source: there is no framework dependency to bump. The published create-accordo@0.1.0 scaffolds vendored source; it is the August 19 snapshot, not the current repository feature set. Use a current source checkout for the capabilities described here; upgrades require merging source (L-08). The framework is copied into the project, not installed as a framework library dependency. The accordo npm name is an empty reservation; the @accordo scope is claimed and deliberately empty.

Every claim and every limitation is on one page, and the questions this project refuses to answer are published beside them.

The evidence this post rests on

Claims

  • C-01 Write a module manifest; the agent turns it into a migration, a service, a REST resource, an SDK method and Admin screens — with no page code.

    LimitGenerated CRUD only. The factory does not generate workflows or approvals for a custom object — that is still handwritten (JTBD-06, partially supported).

  • C-03 Commercial policy is deterministic code, not a model's judgement: a renewal at or above the threshold stops and waits for a named human.

    LimitProven for the built-in renewal object and its single value threshold. A general policy engine over arbitrary custom objects does not exist.

  • C-04 The agent cannot approve on the human's behalf. A test asserts the refusal, so the boundary is a property of the system rather than a promise in a README.

    LimitIn local-development mode the actor is asserted, not authenticated: no authentication ships, so an actor header there is not an identity. This holds a boundary against an honest agent, not against an attacker with network access.

  • C-16 Every mutation goes through a module service or a named workflow, and leaves an audit event and a step-level trace behind it.

    LimitAudit records what the process did under an asserted actor. It is not a tamper-evident or externally attestable log, and it is not a compliance control.

  • C-17 SQLite is Node's built-in node:sqlite. PostgreSQL requires one pinned runtime driver, pg@8.23.0. There is no ORM, no query builder, no build step and no framework underneath your framework.

    LimitApplications that select PostgreSQL carry pg@8.23.0. The SQLite path still needs no third-party driver. This is not a production-readiness claim and not shared-database tenancy; composition is dedicated-database, not row tenancy.

Grounded in

  • docs/strategy/COMPETITOR_MAP.md

Editor of record

  • Aetha Editorial