> ## Documentation Index
> Fetch the complete documentation index at: https://docs.omnilinker.pl/llms.txt
> Use this file to discover all available pages before exploring further.

# ERP integration requirements

> Check the computer, network, database access and Omnilinker access you need before you set up the ERP integration.

Setting up the ERP integration involves two people: a tenant admin who works in the Omnilinker web app, and an IT
person who installs the ERP Sync agent in your network. This page lists what each of them needs.

## Computer for the agent

Install the agent on a Windows computer that stays switched on and can reach your ERP database server. The agent only
works while this computer runs, so a server is a better choice than a desktop that is shut down at night.

| Requirement                    | Details                                                                                                                                                                                                                                               |
| ------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Operating system               | 64-bit (x64) Windows                                                                                                                                                                                                                                  |
| .NET runtime                   | None to install. The agent includes everything it needs.                                                                                                                                                                                              |
| Installation rights            | A local administrator account, and PowerShell started **as Administrator**. Setup installs a Windows service.                                                                                                                                         |
| Install folder                 | A folder outside every user profile, for example `C:\Program Files\Omnilinker\ErpSync`. Setup does not register the service from inside a user profile.                                                                                               |
| Service account                | None to create. The service runs as Local System.                                                                                                                                                                                                     |
| People who configure the agent | Members of the local group **Omnilinker ERP Sync Operators**, or administrators running the tray app elevated. Setup creates the group and adds the person who installs. See [Who can change the agent](/erp/install-agent#who-can-change-the-agent). |

## Network

| Direction  | Destination               | Port                                            | Why                                                                               |
| ---------- | ------------------------- | ----------------------------------------------- | --------------------------------------------------------------------------------- |
| Outbound   | `omnilinker.pl`           | 443 (HTTPS)                                     | The agent sends changes and receives its configuration.                           |
| Outbound   | `releases.omnilinker.com` | 443 (HTTPS)                                     | The agent downloads its [automatic updates](/erp/install-agent#update-the-agent). |
| Outbound   | Your ERP's SQL Server     | 1433, or the port your SQL Server instance uses | The agent reads the ERP database.                                                 |
| Local only | `localhost`               | 5555                                            | The agent's local API, used by the tray app.                                      |

* The agent needs no inbound connection from the internet. It opens every connection itself.
* The local API listens on `localhost` only, so it needs no firewall rule. Port 5555 must be free on the agent
  computer.
* Leave the `LocalApiPort` setting at its default of `5555`. The tray app and the web app's **Local Service** tab
  always look for the agent on port 5555. See the [configuration reference](/erp/configuration-reference).
* The **Local Service** tab of a connection in the web app talks to the agent at `http://localhost:5555`, so it only
  shows the agent's status when you open Omnilinker in a browser on the agent computer.

## Disk space

The agent keeps a local outbox database, a cached copy of its configuration and its log files on the agent computer.
Log files roll over daily and the last 30 are kept.

The first sync of a large ERP queues every product, price and stock record in the outbox before it is sent, so allow
extra space for that.

## SQL Server login

The agent connects to the ERP database with a login you choose: SQL Server authentication, or Windows
authentication. With Windows authentication the service connects as the account it runs under, Local System. On
SQL Server that account appears as:

* the agent computer's domain account, `<DOMAIN>\<COMPUTER>$`, when SQL Server runs on another computer. Both
  computers must be in the same domain, or in trusting domains.
* `NT AUTHORITY\SYSTEM`, when SQL Server runs on the agent computer itself.

Give that login the SQL Server rights below. If you cannot, use SQL Server authentication.

What the login needs depends on the change-detection mode of the connection.

### Hash scan (default)

Hash scan only reads. The login needs read access to the ERP database, for example membership of the
`db_datareader` role. The agent makes no changes to your ERP database in this mode.

### WFM\_INT change tracking (Wapro)

WFM\_INT change tracking uses Wapro's built-in integration framework. When you register it from the tray app, after
giving your consent, the agent writes to Wapro's `WFM_INT_*` framework tables. It never writes to your business
tables such as articles, prices or warehouses.

In addition to read access, the login needs these rights:

| Table                                                                                                                                                                  | Rights                       | What the agent does                                                                                                                                                                |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `WFM_INT_SYSTEM`                                                                                                                                                       | `INSERT`, `DELETE`           | Adds one row that registers Omnilinker as a consumer, named `OMNILINKER`. Unregistering deletes it.                                                                                |
| `WFM_INT_SYSTEM_TABLICE`                                                                                                                                               | `INSERT`, `DELETE`           | Adds one subscription row per tracked table. Unregistering deletes them.                                                                                                           |
| `WFM_INT_ARTYKUL`, `WFM_INT_CENA`, `WFM_INT_CENA_ARTYKULU`, `WFM_INT_MAGAZYN`, `WFM_INT_KOD_KRESKOWY`, `WFM_INT_KATEGORIA_ARTYKULU`, `WFM_INT_KATEGORIA_ARTYKULU_TREE` | `INSERT`, `UPDATE`, `DELETE` | On registration, adds one tracking row per existing record so everything is sent once. After each batch, marks the rows it has processed. Unregistering deletes Omnilinker's rows. |

The agent only touches rows that belong to the `OMNILINKER` registration. Rows of other systems that use the same
framework are left alone.

```sql theme={null}
-- Read access (enough for Hash scan)
ALTER ROLE db_datareader ADD MEMBER [<agent-login>];

-- Extra rights for WFM_INT change tracking
GRANT INSERT, DELETE ON dbo.WFM_INT_SYSTEM TO [<agent-login>];
GRANT INSERT, DELETE ON dbo.WFM_INT_SYSTEM_TABLICE TO [<agent-login>];
GRANT INSERT, UPDATE, DELETE ON dbo.WFM_INT_ARTYKUL TO [<agent-login>];
GRANT INSERT, UPDATE, DELETE ON dbo.WFM_INT_CENA TO [<agent-login>];
GRANT INSERT, UPDATE, DELETE ON dbo.WFM_INT_CENA_ARTYKULU TO [<agent-login>];
GRANT INSERT, UPDATE, DELETE ON dbo.WFM_INT_MAGAZYN TO [<agent-login>];
GRANT INSERT, UPDATE, DELETE ON dbo.WFM_INT_KOD_KRESKOWY TO [<agent-login>];
GRANT INSERT, UPDATE, DELETE ON dbo.WFM_INT_KATEGORIA_ARTYKULU TO [<agent-login>];
GRANT INSERT, UPDATE, DELETE ON dbo.WFM_INT_KATEGORIA_ARTYKULU_TREE TO [<agent-login>];
```

The agent also runs health checks that read trigger metadata (`sys.triggers`) on the tracked tables and the server's
`nested triggers` setting (`sys.configurations`).

If your Wapro database holds more than one company, have the company ID (`ID_FIRMY`) ready. You enter it in the agent.
See [Wapro](/erp/providers/wapro).

## Omnilinker access

### ERP integration feature

The ERP integration is off by default. Omnilinker enables it for your organization on request. Until it is enabled,
the **ERP Integration** menu does not appear. See [Modules and feature availability](/administration/features).

### Permissions for the tenant admin

The person who sets up the connection needs these permissions from the **ERP Integration** group:

| Permission                    | Needed to                                                     |
| ----------------------------- | ------------------------------------------------------------- |
| **ERP Connections**           | See **ERP Integration** > **Dashboard** and **Connections**.  |
| **Create ERP Connection**     | Create the connection.                                        |
| **Generate agent API key**    | Generate the key the agent signs in with.                     |
| **Edit ERP Connection**       | Change connection settings, such as the change-tracking mode. |
| **Manage Sync Configuration** | Choose what syncs.                                            |
| **Manage Field Mappings**     | Map ERP fields to Omnilinker fields.                          |
| **Manage Entity Mappings**    | Map ERP price levels and warehouses.                          |
| **Sync Logs**                 | See **ERP Integration** > **Sync Logs**.                      |
| **Agent Status**              | See the **Agent** tab of a connection.                        |

### The agent's own access

You do not create a user or assign permissions for the agent. When you generate the agent API key, Omnilinker creates
a dedicated service account for the connection and gives it only the permissions the sync needs. See
[Create a connection](/erp/create-connection#generate-the-agent-api-key).

## Checklist

* [ ] Omnilinker has enabled the ERP integration for your organization.
* [ ] The tenant admin has the permissions listed above.
* [ ] A 64-bit Windows computer that stays on and can reach the ERP database server.
* [ ] A local administrator account on that computer for the installation.
* [ ] The Windows accounts of the people who will configure the agent, to add to **Omnilinker ERP Sync Operators**.
* [ ] Outbound HTTPS (port 443) to `omnilinker.pl` and `releases.omnilinker.com` from that computer.
* [ ] Network access from that computer to the SQL Server port of your ERP database.
* [ ] Port 5555 free on that computer.
* [ ] A SQL Server login with read access to the ERP database. For Windows authentication, a login for the agent
  computer's account.
* [ ] If you will use WFM\_INT change tracking: the extra rights on the `WFM_INT_*` tables.
* [ ] The ERP database server name, database name and, for a multi-company Wapro database, the company ID.

Next, [create a connection](/erp/create-connection).
