# CG Sanchar - Multi-State WhatsApp Automation

> One console runs WhatsApp publishing for every state team: generate a branded creative or upload your own, get a caption drafted for it, review it, and schedule it to the right channel. Each team is confined to its own state, uploads run on single-use signed URLs so no shared credentials exist anywhere in the system, and a person approves before anything reaches a public audience. Around 170 creatives have shipped through it.

**Category:** WhatsApp broadcast automation · multi-tenant · client delivery  
**Role:** Lead engineer - build and client delivery  
**Status:** Production  
**Year:** 2026  
**Canonical URL:** https://koratmeet.in/projects/cg-sanchar

## Summary

A national education communications programme publishes to WhatsApp channels in every state, each with its own bots, channels, and staff. The tool had to take the manual work away without ever letting one team publish into another team's channel. Operators pick a channel, generate a state-branded creative or upload their own, get a caption written for it, send it through review, and schedule it.

Delivered against a live client over weekly working sessions - requirements gathered, features demoed, and scope adjusted week to week rather than against a spec fixed up front.

## Problem

Every state team produced its own WhatsApp posts by hand: build the creative, write the caption, remember which channel it belongs to, post it. It did not scale, branding drifted between states, and nothing stopped someone from publishing into a channel that was not theirs. These posts reach a public audience - a mistake is not something you can quietly undo.

## Solution

We worked backwards from the two things that could not move. The client's security team would not share credentials, and each team had to stay inside its own state - so both were made structural rather than something the interface has to remember to enforce. Uploads route through a service that mints a short-lived, single-use URL per file, so no long-lived key is ever distributed and size limits live in one place. Access is modelled per state with three levels, making scope a property of the data rather than a UI check. On top of that sits the part operators actually use: choose a channel, generate a branded creative or bring your own, get a caption drafted from the image and the channel it is going to, review it, schedule it. Generation is automated; publishing stays a decision a person makes.

## Architecture

Pick channel → Generate / upload → Auto-caption → Review → Signed upload → Private bucket + CDN → SwiftChat → WhatsApp channel

## Stack

- React
- TypeScript
- Supabase
- AWS S3
- AWS CloudFront
- AWS Lambda
- Presigned URLs
- SwiftChat API
- WhatsApp Channels
- Role-based access control
- Lovable

## Metrics

- **Creatives shipped:** ~170
- **Scope:** Multi-state
- **Access levels:** 3 · none / view / edit
- **Shared keys:** None

## Key engineering decisions

### Design for having no credentials at all

The client's security team would not hand over keys, and they were right to refuse. Instead of negotiating, the upload path was built so credentials are never needed: one endpoint issues a time-limited URL per file. The constraint made the system safer than the original plan.

### Separate who can deliver a file from who can store one

The bucket blocks public access entirely and a CDN is the only public route to a creative. Storage permissions and delivery permissions stop being the same decision, so opening one never quietly opens the other.

### Put scoping in the data, not the interface

Every team edits only its own state, enforced at the access layer rather than by hiding buttons. With many teams publishing to public channels, a mis-scoped post costs far more than carrying a permission model.

### Automate generation, not publishing

An operator sees the creative and its caption before anything goes out. Keeping a person on the last step is what makes running this daily, at this reach, safe.

## Build notes

- Each state carries its own bots, channels, and team members, so adding a state is configuration rather than a code change
- Three access levels - none, view-only, and edit scoped to a user's own state
- A fixed header panel is composited onto every generated creative so state branding cannot drift
- Captions are drafted from the image plus the destination channel, appending the bot link where one is set
- Custom uploads supported, with a toggle for whether the brand overlay is applied
- Image storage migrated onto the client's own cloud account mid-flight, without downtime

## Results

- ~170 creatives generated and published through the pipeline
- Per-state manual production replaced by generate, review, schedule
- No shared cloud credentials distributed anywhere in the system
- Each team confined to its own channels, with a review step before publish

## What this demonstrates

- Designing a system around a client's security constraints rather than around them
- Multi-tenant access control across many independent teams
- Client-facing delivery - requirements, demos, and launch coordination
- Automation with a human review gate where mistakes are public
- Turned a client security constraint into a better architecture instead of an exception
- Multi-tenant role scoping across many independent teams
- Ran the client relationship directly: weekly requirements, demos, launch
- Migrated storage onto the client's own cloud account without downtime

## Live channels

- [SwiftChat Jammu & Kashmir](https://whatsapp.com/channel/0029VaZ5G0V05MUk8jgOwQ2s)
- [SwiftChat Himachal Pradesh](https://whatsapp.com/channel/0029Vab3tAEBA1eyMV1FjV20)
- [SwiftChat Uttarakhand](https://whatsapp.com/channel/0029VadkT6DJJhzhbJxXRI0h)
- [SwiftChat Madhya Pradesh](https://whatsapp.com/channel/0029VaZSBLXC1FuLLJFcVw2p)
- [SwiftChat Gujarat](https://whatsapp.com/channel/0029VbDhr0IAYlUNlOHvur2Q)
- [SwiftChat Tripura](https://whatsapp.com/channel/0029VaiqglDDuMRgvJMar047)
- [VSK | DNH&DD](https://whatsapp.com/channel/0029VaZZlYaFy726Hx67tO2a)
- [विद्या समीक्षा केंद्र (VSK), महाराष्ट्र](https://whatsapp.com/channel/0029VbBi4VsAe5VsS3hFeQ20)
- [Goa- VSK - SwiftChat](https://whatsapp.com/channel/0029Vadypvm5K3zL7aWOJd0v)

---

Built by Meet Korat, AI Automation Engineer. Contact: meetkorat903@gmail.com · https://koratmeet.in
