Web form lead capture
Your Leads board is the sales pipeline — prospects from first enquiry to won. Until now every lead had to be typed in by hand. The web form gives you a front door for inbound work: a public, embeddable enquiry form that you put on your own website, and every submission lands on the Leads board automatically in the New column, tagged as a web enquiry.
Each VCR gets one form with its own secret key. The form is branded with your logo and company name, you choose which fields appear, and built-in spam protection keeps the junk out.
Open the web form settings
- Go to Sales in the sidebar, then Leads in the switcher.
- Click Web form in the top-right (next to New lead). You need Sales access to see it.
- The Lead capture web form dialog opens. The first time you open it, your form is created automatically with a fresh key.
Turn the form on
At the top of the dialog is the Form is live switch:
- On — the form accepts submissions.
- Off — visitors who open the form see a short "not accepting enquiries right now" message instead of the fields. Nothing is lost; turn it back on at any time.
Just under the switch you'll see your running totals: how many submissions you've received, how many were blocked as spam, and when the last one arrived.
Share or embed the form
The Share & embed section gives you two ways to publish the form:
- Direct link — a
…/f/<your-key>URL you can email, put behind a "Get a quote" button, or share on social media. Use Copy to copy it, or Open to preview it in a new tab. - Embed snippet (iframe) — paste this HTML into your website to show the form inline on a page. Copy snippet copies it ready to paste.
<iframe
src="https://portal.clevercam.co.za/f/lf_xxxxxxxxxxxxxxxx"
title="Request a callback"
style="width:100%;max-width:480px;height:640px;border:0;"
loading="lazy"
></iframe>
Regenerate the key
Regenerate key issues a brand-new key and invalidates the old link and embed immediately. Only do this if a key has leaked or is being abused — afterwards you must replace the snippet everywhere you've embedded it.
Customise the form content
The Form content section controls what visitors see:
| Field | What it does |
|---|---|
| Title | The heading at the top of the form, e.g. "Request a callback". |
| Intro text | An optional line under the title. |
| Submit button label | The text on the button, e.g. "Send enquiry". |
| Redirect URL after submit | Optional. If set, visitors are sent to this page after a successful submit (e.g. your own thank-you page) instead of seeing the thank-you message. |
| Thank-you message | Shown after a successful submit when no redirect URL is set. |
Choose the fields
The Fields section lists the five fields the form can collect. For each one you can:
- Show — tick to include the field on the form.
- Edit the label the visitor sees.
- Required — tick to make the field mandatory before the form can be sent.
| Field | Where it lands on the lead |
|---|---|
| Your name | Lead contact name |
| Lead contact email | |
| Phone | Lead contact phone |
| Company | Lead company |
| How can we help? | Lead notes |
The company (or, if blank, the contact name) becomes the lead's name on the board. Reset to default restores the standard five-field set.
Routing & protection
The Routing & protection section decides what happens to each submission and keeps bots out:
- Lead source label — the text stamped onto the lead's
source(defaults towebsite), so you can tell web leads apart in reports. - Assign to sales rep — optionally pre-assign every web lead to one of the sales-role members on People. Leave on Assign later to leave new leads unowned.
- Max submissions / hour per visitor — a per-visitor rate limit. Submissions over the limit are refused with a "try again later" message.
- Min seconds to fill (anti-bot) — submissions completed faster than this are treated as suspicious.
Every submission also passes through a hidden honeypot field that real visitors never see.
Suspected bots get a human check, not a silent bin
When a submission trips the honeypot or the fill-time check, the enquiry is not discarded. The form shows a quick human check instead — a simple question like "Quick check — what is 4 + 6?" — and the enquiry is sent the moment the visitor answers it. This protects real people who trip the checks by accident (browser autofill can complete a form in under a second), while bots that never answer are dropped as before. Each triggered check is counted in your "blocked as spam" total.
Two more things make false positives rare:
- Signed-in staff are always trusted. If you open the form in a browser where you're signed in to CleverOps (e.g. testing your own form), the spam checks are skipped entirely.
- Every submission attempt is logged with its outcome — including which check triggered — so an administrator can always see why a specific enquiry was challenged.
Visitor IP addresses are never stored in the clear — only a salted hash is kept, purely to power the rate limit.
What happens when someone submits
- The visitor fills in the form and clicks the submit button.
- A new lead is created on your Leads board in the New column, with a Web chip so you can spot inbound enquiries at a glance.
- The Leads page header shows a "N new web enquiries waiting" note while any web leads sit in New.
- From there it's an ordinary lead — drag it through the pipeline, add an estimated value, link a quote, or convert it to a customer when you win the deal.
Open the Web form dialog any time to see your submission and spam totals.
Deploying the endpoint
The form posts to a public Supabase edge function (lead-web-form) backed by the lead_web_forms table (migrations 20260629g_lead_web_forms.sql and 20260701i_lead_web_form_challenge.sql). Before the form will accept live submissions, an administrator must apply those migrations and deploy the function with JWT verification disabled so third-party sites can post to it:
supabase functions deploy lead-web-form --no-verify-jwt
The committed supabase/config.toml already sets verify_jwt = false for this function.
Permissions
Configuring the form and reading its submission stats requires Sales access (the same permission as managing leads). The public form itself needs no sign-in — that's the point.