3CX

3CX

Connect 3CX to Corma to remove extensions, direct numbers and admin roles when people leave, and keep your phone system in step with HR records.

The Corma integration for 3CX connects your phone system to the same joiner, mover and leaver workflows as the rest of your SaaS stack, so extensions, direct numbers and admin roles follow the HR record instead of a ticket queue. It is built for IT teams that run 3CX in the cloud or self-hosted and want one view of who can call, answer and listen to recordings.

Key takeaways

  • 3CX is licensed by simultaneous calls rather than per user, so a leftover extension adds nothing to the invoice while keeping its direct number and call rights.
  • With Microsoft 365 user sync, a user disabled or deleted in Microsoft 365 stays in 3CX and has to be removed manually.
  • The 3CX System Owner role can view call recordings and reports, which makes it the first role to review when someone changes job or leaves.

How are users and roles managed in 3CX?

In 3CX, a user is an extension. Each one is created with an extension number, an email address, a department, a role and often one or more DIDs (direct inward dialing numbers). System-wide rights sit with two roles, System Owner and System Administrator, while department roles range from User and Receptionist up to Manager and Owner.

3CX can import users from Microsoft 365 or Google Workspace, but the sync is one-way and runs nightly. No SCIM endpoint is documented, and the configuration API (XAPI) is only included in the AI edition from 8 simultaneous calls.

Why do 3CX extensions outlive the people who used them?

Because licensing is not per user, nobody chases unused seats, and extensions quietly pile up. The sync rules add to it: an account disabled in Microsoft 365 stays active in 3CX, and an extension deleted only in 3CX comes back after the next nightly sync while its source account still exists. On Google Workspace, a suspended user leaves a disabled extension behind rather than a deleted one.

The result is a stock of orphaned accounts that still hold DIDs and call permissions, exactly what an ISO 27001 or NIS2 auditor will ask you to explain.

What Corma automates for 3CX

  • Leaver sequence in the right order: the departure date in your HR tool starts an offboarding workflow that closes the source account first, then the 3CX extension, so the nightly sync cannot restore it.
  • Number handover: moving a DID to a colleague, a queue or a ring group becomes a step with an owner and a timestamp.
  • Role reviews: System Owner, System Administrator and department Owner roles go into scheduled access reviews, where managers confirm or revoke each one.
  • Drift detection: Corma compares the 3CX user list with your HR roster and flags extensions that match no current employee.

3CX integration FAQ

Does 3CX support SCIM provisioning?

3CX documents no SCIM support. Users come from the Microsoft 365 or Google Workspace sync, the admin console or the XAPI. For the general method, see our guide to offboarding apps that don't support SCIM, SAML or SSO.

Can Corma manage 3CX without the AI edition's API?

Yes. Where the XAPI is not available, Corma's AI agents carry out admin console steps in an isolated browser session, using credentials from your own vault, with a video replay and a step log for every run.

Where does Corma store 3CX access data?

Corma runs on AWS data centres inside the European Union, encrypts data in transit and at rest, and is ISO/IEC 27001:2022 certified.

Running 3CX next to Microsoft 365 or Google Workspace? Book a demo and we will map your leaver process on your own stack.

Related Integrations

Check out other integrations that could help you on managing your software licences and accesses!