Answer · processes · CRM, automation & AI

We want to grow from 10 to 100 customers — how do you automate that?

The short answer: do not start with the software. A system that still carries you at a hundred customers comes about in this order — write down the workflows, model the data properly, decide the rules, and only then build or buy. And two things belong in the first sketch rather than at the end: data protection and the EU AI Act. Retrofitting them means building twice.

Portrait of Matthias Eger — expert for AI & IT in mid-sized companies, Weiden in der OberpfalzAuthorMatthias EgerCertified Manager for Applied AI Transformation (IHK)
Last reviewed24 Sep 2026
To the verification record

How the enquiry came in.

This page has a concrete occasion: an enquiry through my contact form. Industry, figures and details have been changed so that nobody is recognisable — the core has stayed, because it is the same in many businesses.

The enquiry — altered

“I place seasonal and service staff with inns and hotels in the region. At the moment I look after twelve establishments, and two or three are added every month. In three years I want to be at a hundred — and to build the processes professionally from the start. I am looking for support with a CRM with automation, ideally with AI: managing establishments and staff, scheduling assignments with concrete periods, billing commission monthly and day-accurately, filing contracts and certificates in a structured way. The communication should run by itself as far as that makes sense. And all of it please with the GDPR in mind from the beginning.”

This enquiry is better than most. Here is somebody who knows what they want, thinks about growth instead of next week and brings data protection along unprompted. And yet this is exactly the point at which such projects most often tip over: those six sentences contain five projects — master data, scheduling, billing, documents, communication. Tackle them at the same time and in six months you have five half-finished building sites and none of them in use.

The structure here does not only apply to staff placement. It fits everywhere somebody brings together people, periods of time and billing: care and support services, trades with maintenance contracts, property management, agencies with ongoing retainers, training providers with a pool of lecturers.

Why the pressure is real

Ten times as many customers
are not ten times the work.

They are more. Because what grows with the number of customers is not the work but the number of combinations — and the number of places where something can go wrong unnoticed.

01

Today it works because you are the database.

With twelve customers every case fits into one head. A calendar, a spreadsheet and a messenger are enough — not because the tools are good but because you know who is where and when, who still owes a certificate and what you promised somebody last week. That knowledge is written down nowhere. It is the operating system.

02

With a hundred customers, hundreds of assignments run in parallel.

Each with a start, an end, an extension, a stand-in, a cancellation. “Ten conversations a month” turns into hundreds of small changes of state — every one of them triggering a message, a deadline or a payment. No head holds that, and no spreadsheet shows you on Tuesday what expires on Friday.

03

Billing does not grow linearly but by the day.

Day-accurate billing means: every single day has to be assigned to an assignment, a customer and a rate. With a hundred running assignments that is several thousand billing days a month. A cancellation on the fourteenth shifts two invoices and creates a credit note — still manageable in your head, a whole weekend in Excel.

04

Mistakes scale too. You just notice them later.

With twelve customers a forgotten deadline is noticed the same day. With a hundred, the customer notices it — or the supervisory authority. That is the real jump: from “I know that” to “the system knows that, and I can prove it”.

The uncomfortable precondition

You can only automate what has been decided. The sentence “we handle that case by case” is a strength in daily work — in a system it is a gap. That is why the first part of a project like this is not technology but a series of decisions that nobody can take off your hands. All I can do is draw them out of you, put them in order and write them down so that a machine can execute them.

The structure

Five building blocks — and the order
matters more than any tool.

Each block builds on the one before. Anyone who starts at number four because that is where it hurts most will build the first three again later — but by then with data inside them.

01

Write down the workflows as they really run.

Not as they stand in the manual: from the first enquiry to the last invoice, with every phone call and every scrap of paper in between. What matters are the exceptions — the exceptions are the project. What happens if somebody drops out on the third day? If a customer does not pay but the assignment is running? If two people say yes at the same time? Anyone who cannot answer that in one sentence each cannot automate it either.

02

A data model that can take reality.

Customer, worker, assignment, contract, receipt, message — and the one decision everything later hangs on: the assignment is a thing in its own right with a from-date and a to-date, not a column on the customer. Scheduling, utilisation, billing, deadlines and every report hang off it. Cut corners here and you notice it in month twelve with the first retroactive correction — and then you pay with a data migration instead of with thinking.

03

Decide the billing rules before anybody writes code.

“Day-accurate” sounds unambiguous and never is. Does the day of arrival count? What applies on cancellation on the fourteenth, on a change mid-month, on an extension by three days, on a cancellation after invoicing? Those are ten to twenty sentences that you decide — the software only calculates what you have decided. Those sentences are the difference between a billing run at the push of a button and three days of spreadsheet work a month.

04

Documents with deadlines instead of a folder structure.

Contracts, certificates, powers of attorney, confirmations: every document belongs to a case and has an expiry date. It is not the human being who remembers, the system remembers — in good time, and the right person. The machine reads the data out of the PDF, confirmation is done by hand. A folder called “Contracts 2026” is not a filing system, it is a hope.

What that looks like: document management with AI
05

For communication, first settle what will never be automated.

That list matters more than the automation list. Appointment confirmation, reminder about documents, sending invoices, status updates: automatic, any time. Rejection, complaint, illness, cancellation, price increase, bereavement: a human being, always. A perfectly worded bulk email at the wrong moment costs you a customer you won over months — and it costs you quietly, without you ever finding out why they stopped calling.

Who does what

What the machine takes on.
And what stays with the human being.

In a system like this, AI is not a building block of its own but a tool inside the blocks. The dividing line does not run between “easy” and “difficult” but between preparing and deciding.

This is allowed for the machine

Everything recurring with a clear rule

Reminders, confirmations, deadline warnings, the monthly billing run, creating cases. No intelligence needed — only a rule that has been decided properly once.

Writing drafts that you check

A quote, a draft contract, an answer to a standard question: the AI types, you read and sign. In an electrical trade business, measurement photos and a voice note become a finished draft quote in twenty minutes — checked and signed by the master craftsman.

Evidence: case 308 — quotes in the trades

Reading, sorting, checking — and reporting

Pulling data out of PDFs, pre-sorting the inbox, finding discrepancies between plan, assignment and invoice. In the clinic, AI suggests billing codes — and not a single one goes out without human approval.

Evidence: case 297 — checking yes, deciding no
This stays with the human being

Who fits with whom

A suggestion may come out of the machine, the selection may not. That is not only an attitude, it is the legal situation: software that selects or evaluates people for assignments is high-risk under the EU AI Act — see below.

Every piece of bad news

Rejection, complaint, cancellation, price increase. Automate here and you save three minutes and lose a relationship. In businesses that live on trust, that is the most expensive mistake there is.

Anything that triggers money or creates legal effect

The billing run, a credit note, a termination, a contract conclusion: the machine prepares, a human being approves — and that approval is logged. A billing run without an approval step is not progress, it is a bulk mailing to your customers.

Two subjects that cannot be retrofitted.

In a project like this, data protection and the AI Act are not chapters at the end but architectural decisions. The reason is banal: both determine where data may sit, who may see it, how long it exists and what the system has to log. Those are foundations — you do not pour them under a finished house.

GDPR: seven points that have to end up in the system

  • A legal basis per type of data: contract data, application data and marketing stand on three different bases under Article 6 GDPR. Throw everything into one pot and you will not be able to delete anything cleanly later.
  • Data processing agreements: with every service provider that sees data — hosting, CRM provider, mail delivery, telephone system, AI service. Each one separately, under Article 28.
  • Deletion periods as a function, not as an intention: applicant data gone after the period, contract data gone after the retention obligation. A deletion concept that no program executes is a document about good intentions.
  • Roles and permissions: who may see which record? With the first temp in the office at the latest, “everyone sees everything” is no longer an option.
  • Data minimisation and special categories: health information, ID document data and origin fall under Article 9 GDPR — the highest level of protection. The best safeguard is not to collect them in the first place.
  • Record of processing activities and technical measures: encryption, backup, logging, access protection. That is the first thing the supervisory authority asks for — and it comes about while building, not afterwards.
  • Data subject rights at the push of a button: access, rectification, erasure, data portability, with a deadline. The honest question to put to any system is: how long do you need if somebody requests access tomorrow?

EU AI Act: two things that directly affect this case

The first applies to every business that uses AI: AI literacy has been mandatory since 2 February 2025 — Article 4 requires that the people who use AI also understand it. Regardless of the size of the business. What Article 4 actually requires →

The second is the point that is regularly overlooked in placement, recruitment and the allocation of people:

Careful: high-risk

AI systems that select, filter or evaluate people for work assignments or jobs fall under Annex III of the EU AI Act — the employment area. Obligations hang off that: risk management, data quality, logging, human oversight, technical documentation. Plus a question of role with consequences: whoever merely uses such a system is a deployer. Whoever has one built for them and operates it under their own name quickly becomes a provider themselves — with considerably heavier obligations. That is the difference between driving a car and building one.

That is why the dividing line above is not only an attitude but risk management: the AI sorts and suggests, the human being decides — and the decision is logged. Whether a purely preparatory function falls under the exceptions in Article 6(3) is a case-by-case assessment. That belongs on the record, not on a hope. And which obligations apply from when in detail is still politically in motion — the classification itself is not.

Up front: this is not legal advice

I am not a lawyer and not a data protection officer. What I bring is the practice: making sure these questions are on the table early, that the architecture can actually implement the answers, and that you know what you have to settle with your data protection officer or a specialist lawyer. Somebody with the relevant licence has to check and sign it off — before go-live at the latest.

The honest part

Why this almost never works alone — or with only one service provider.

It is not a matter of ability. It is that six very different skills are needed at the same time — and on the same decisions.

Process knowledge

Understanding the workflow before pinning it down — including the exceptions nobody mentions because they are “obvious anyway”. Skip that and you automate the chaos. Only faster.

Empathy & understanding people

At the other end there is a human being, often in a tense situation. Which sentence may go out automatically and which may not is not decided by a diagram — it is decided by somebody who knows what that phone call feels like.

IT architecture

Data model, interfaces, permissions, backup, failure behaviour. Those are decisions you take in the second month and pay for in the third year — for better or worse.

Data protection in practice

Not as a PDF in a folder but as a deletion job, a permissions concept, a log and an access function. A data protection concept that no software executes is an essay.

EU AI Act

Classifying the system, the role as deployer or provider, the evidence, the training under Article 4. Check that only after building and you are checking the wrong system — and in case of doubt you build it again.

Operation & further development

A system without care is no longer an advantage after eighteen months but a risk: outdated dependencies, special cases that have grown wild, nobody responsible. Software is a pet, not a piece of furniture.

For each of these six points you will find somebody. The problem is not the competence — the problem is the seam between them. The data protection expert does not know your workflows. The agency builds what is in the ticket. The lawyer never sees the software. And you are supposed to translate between three professional languages while the business keeps running.

What is missing is somebody who holds all six perspectives in their head at once and decides when they contradict each other — and they do so constantly. The most convenient function is rarely the one that uses least data, the fastest model rarely the legally simplest, the most elegant automation rarely the humanly right one.

“An automation project almost never fails because of the technology. It fails on a question nobody asked.”

My role

Where I support you — in four stages,
and you can get off after each one.

I come from fourteen years of database and planning development in a corporate group and have been building systems for mid-sized companies since 2008. Above all that means: I have made the mistakes listed above myself — and I know what they cost later.

Stage 1 · free

Initial assessment: 30 minutes, three starting points.

You describe how things run today. I tell you which workflow comes first, where AI carries and where it gets in the way — and whether you need a custom build at all. In writing, without sales pressure. Often enough the answer is: take a standard system and only have an interface built.

Stage 2 · the foundation

AI & process check: look first, sort second.

Half a day in the business, on your real cases — not on the org chart. Out of it comes a prioritised list: which three to five workflows eat the most time, what works right away, what comes later, where an off-the-shelf tool is enough. For a project like this one, the sketch that matters is part of it — data model, rules for scheduling and billing, the open data protection and AI questions. The paper belongs to you, and you can take it to any other service provider. That is deliberate: a foundation that only works with me would not be one.

What happens in the AI & process check
Stage 3 · when something gets built

Implementation in stages — and everything belongs to you.

What gets built is the workflow that costs the most time today, not the whole house at once. Buy standard where standard is enough; build custom where your business differs from every other one. Source code, data and credentials belong to you — no lock-in, no licence that makes you vulnerable later.

How implementation runs
Stage 4 · ongoing

Operator: accompany, check, develop further.

A system that grows needs somebody keeping an eye on it: reviewing the automations, building in new special cases, keeping dependencies current, sharpening rules when the legal situation moves. And the training under Article 4 for the people who work with it.

The AI Day for your team

And where I do not help: I do not give legally binding advice on the GDPR, the AI Act, employment law or tax law. I make sure the right questions are asked early and that the technology can implement the answers. Somebody with the relevant licence has to sign it off — and if you do not have anyone, I tell you in good time rather than afterwards.

If you want to start yourself tomorrow.

Five steps you need nobody for. They cost you a week on the side — and they make every later project faster and cheaper, no matter who builds it:

  • Keep a record for a week. What do you do, how often, for how long? Do not estimate — write it down. The surprise is guaranteed.
  • Draw the most frequent process. One sheet of paper, from the enquiry to the invoice. Every arrow is a handover, every handover a possible automation.
  • Note the ten exceptions. Everything you decide “case by case” today. That is the most valuable list in the whole project.
  • Write the billing rules down in complete sentences. If two sentences turn up that contradict each other, you have just found money.
  • Make a data list. Which data do you hold about people, where does it sit, who sees it, when does it have to go? That list is half of data protection — and it almost always turns up two legacy problems.

Once you have those five points, the difficult part is half done. The rest can be bought, built or both — but only then.

Frequent questions

What owners want to know before a project like this.

Do we need an off-the-shelf CRM or a custom build?

Usually both. First check whether a standard system covers eighty per cent — addresses, tasks, documents and invoices can be bought, and they should be. A custom build pays off exactly where your business differs from every other one: assignments with periods, day-accurate billing, your own matching logic. That part is connected by an interface, not placed alongside as a second island.

When does automation pay off?

As soon as a process recurs, has rules and eats time. The order still stands: measure first, automate second. Anyone who keeps a record for a week usually sees two or three workflows that consume most of the time. Those come first — everything else waits, however loudly it shouts.

Is an AI allowed to pre-sort applicants or customers?

Only once the legal situation is settled. Software that selects, filters or evaluates people for assignments or jobs falls under Annex III of the EU AI Act — high-risk, the employment area. Whether a purely preparatory function falls under the exceptions in Article 6(3) is a case-by-case assessment and belongs on the record. What is certain: a human being has to decide, traceably and with a log.

Can we start small instead of doing everything at once?

Yes — and you should. But starting small does not mean thinking small: the data model has to take the whole picture from the start, because retroactive corrections to data cost more than any function added later. The build happens in stages, the thinking happens as a whole.

We already use a tool. Throw it away?

Rarely. More often the existing system is only missing the connection, a clean rule or a piece of automation on top. I look at whatever is running first — including home-made AI solutions. How a review like that runs →

Are our customer data allowed into an AI at all?

That depends on which data it is. There are four levels — from “may go into any model” to “stays on our own hardware”. Personal data sits on the strictest level. The four levels in detail →

Tell me how it runs today. 30 minutes are enough for the direction.

You do not have to prepare anything and you do not have to understand anything. Afterwards you know which workflow comes first — and whether you really have to build something for it. Free of charge, without sales pressure.

Request an initial assessment
Get in touch