Back to projects

WhatsApp broadcast automation · multi-tenant · client delivery

CG Sanchar - Multi-State WhatsApp Automation

One console runs WhatsApp publishing for every state team: generate a branded creative or upload your own, get a caption drafted for it, review it, and schedule it to the right channel. Each team is confined to its own state, uploads run on single-use signed URLs so no shared credentials exist anywhere in the system, and a person approves before anything reaches a public audience. Around 170 creatives have shipped through it.

Role
Lead engineer - build and client delivery
Status
Production
Year
2026
cg-sanchar---multi-state-whatsapp-automation.app
STATE CHANNELS · ONE CREATIVEBROADCASTCREATECAPTIONREVIEWBROADCAST

Metrics

Creatives shipped
~170
Scope
Multi-state
Access levels
3 · none / view / edit
Shared keys
None

Stack

ReactTypeScriptSupabaseAWS S3AWS CloudFrontAWS LambdaPresigned URLsSwiftChat APIWhatsApp ChannelsRole-based access controlLovable

Problem

Every state team produced its own WhatsApp posts by hand: build the creative, write the caption, remember which channel it belongs to, post it. It did not scale, branding drifted between states, and nothing stopped someone from publishing into a channel that was not theirs. These posts reach a public audience - a mistake is not something you can quietly undo.

Solution

We worked backwards from the two things that could not move. The client's security team would not share credentials, and each team had to stay inside its own state - so both were made structural rather than something the interface has to remember to enforce. Uploads route through a service that mints a short-lived, single-use URL per file, so no long-lived key is ever distributed and size limits live in one place. Access is modelled per state with three levels, making scope a property of the data rather than a UI check. On top of that sits the part operators actually use: choose a channel, generate a branded creative or bring your own, get a caption drafted from the image and the channel it is going to, review it, schedule it. Generation is automated; publishing stays a decision a person makes.

Architecture

Pick channel
→
Generate / upload
→
Auto-caption
→
Review
→
Signed upload
→
Private bucket + CDN
→
SwiftChat
→
WhatsApp channel

Key Engineering Decisions

  • Design for having no credentials at all

    The client's security team would not hand over keys, and they were right to refuse. Instead of negotiating, the upload path was built so credentials are never needed: one endpoint issues a time-limited URL per file. The constraint made the system safer than the original plan.

  • Separate who can deliver a file from who can store one

    The bucket blocks public access entirely and a CDN is the only public route to a creative. Storage permissions and delivery permissions stop being the same decision, so opening one never quietly opens the other.

  • Put scoping in the data, not the interface

    Every team edits only its own state, enforced at the access layer rather than by hiding buttons. With many teams publishing to public channels, a mis-scoped post costs far more than carrying a permission model.

  • Automate generation, not publishing

    An operator sees the creative and its caption before anything goes out. Keeping a person on the last step is what makes running this daily, at this reach, safe.

Build Notes

  • Each state carries its own bots, channels, and team members, so adding a state is configuration rather than a code change
  • Three access levels - none, view-only, and edit scoped to a user's own state
  • A fixed header panel is composited onto every generated creative so state branding cannot drift
  • Captions are drafted from the image plus the destination channel, appending the bot link where one is set
  • Custom uploads supported, with a toggle for whether the brand overlay is applied
  • Image storage migrated onto the client's own cloud account mid-flight, without downtime

Results

  • ~170 creatives generated and published through the pipeline
  • Per-state manual production replaced by generate, review, schedule
  • No shared cloud credentials distributed anywhere in the system
  • Each team confined to its own channels, with a review step before publish

Live channels

The automation publishes into these WhatsApp channels every day. Each state team only sees and schedules its own.

Sample posts

J&K · smart attendance reminder
J&K · smart attendance reminder
Uttarakhand · NIPUN level tracking bot
Uttarakhand · NIPUN level tracking bot
Maharashtra · daily class attendance
Maharashtra · daily class attendance
DNH&DD · morning attendance
DNH&DD · morning attendance
J&K · remedial worksheets
J&K · remedial worksheets
Maharashtra · PAT and attendance reports
Maharashtra · PAT and attendance reports
Nagaland · smart attendance
Nagaland · smart attendance
Maharashtra · daily class report
Maharashtra · daily class report

Why this matters

  • Turned a client security constraint into a better architecture instead of an exception
  • Multi-tenant role scoping across many independent teams
  • Ran the client relationship directly: weekly requirements, demos, launch
  • Migrated storage onto the client's own cloud account without downtime