Start with the smallest check
Run crm version, crm help customer and an approved exact lookup. Inspect the result as well as the exit code. Preserve the command, environment, time and error for support; omit credentials and unnecessary personal data.
Help or version fails
Startup configuration applies even to help and version. Check MAIT_CHANNEL, optional CRM YAML settings and credential-path overrides. Restore known working settings before replacing credentials.
Sign-in succeeds but access is refused
Sign-in and customer permissions are separate. Confirm the assigned environment and permission with its operator. Older service credentials may need reissue after permission changes; repeated login alone does not grant access. A locally valid credential can still be denied when current authority cannot be confirmed.
A customer lookup appears empty
Require the expected customer ID. Not-found responses can exit zero; missing display fields and incomplete responses are not proof of absence. Use the approved exact ID when email or provider identifiers containing reserved URL characters fail.
Manual creation fails or its result is uncertain
Manual creation requires a compatible service and operator credential. A duplicate response leaves the existing record unchanged. If the response is lost or lacks a customer ID, read by the known email and reconcile before retrying; the write may already have completed.
The pending customer is not registered
Creation links no sign-in identity and does not complete service provisioning. The customer must claim the same record through a matching verified sign-in. Do not create another record or treat pending creation as a private-access invitation.
The name differs between surfaces
With service version 0.13.0, sign-in preserves nonempty stored name fields. The CLI can retain the manually supplied display name while the account page displays first and last names filled during sign-in. Confirm the same customer ID. Where the current account Profile editor is deployed, the customer can use Edit name; CRM CLI has no profile-name editor. Re-read after an uncertain save instead of deleting or duplicating the account.
Deletion does not prove complete cleanup
Deletion acts immediately without confirmation or undo. Verify absence with a read of the approved ID. Downstream cleanup may need operator reconciliation; do not repeat deletion as a check.
Health or diagnostics look successful
Health can return an unhealthy response with exit zero and does not test customer authorization. Doctor is non-strict and can skip probes; read each result. Local cached update information is not a live release check.
Login or update prompts are confusing
Login prints a portal address; open it yourself and follow the code prompt. Use crm even if a shared error names another executable. Explicit update needs an interactive terminal when offered; there is no force flag. If a remote action succeeds but saving local state fails, reconcile before retrying.
An update is staged but the version is unchanged
Staging does not replace the executable or apply it at the next launch. Use the installation owner’s replacement process, then verify the version and an authorized read. Preserve errors and staging files until an incomplete update is understood; there is no CLI rollback command.
What you getThe failed boundary identified, with a safe verification or support handoff.