WhatsApp broadcast automation · multi-tenant · client delivery
CG Sanchar - Multi-State WhatsApp Automation
One console runs WhatsApp publishing for every state team: generate a branded creative or upload your own, get a caption drafted for it, review it, and schedule it to the right channel. Each team is confined to its own state, uploads run on single-use signed URLs so no shared credentials exist anywhere in the system, and a person approves before anything reaches a public audience. Around 170 creatives have shipped through it.
- Role
- Lead engineer - build and client delivery
- Status
- Production
- Year
- 2026
Metrics
- Creatives shipped
- ~170
- Scope
- Multi-state
- Access levels
- 3 · none / view / edit
- Shared keys
- None
Stack
Problem
Every state team produced its own WhatsApp posts by hand: build the creative, write the caption, remember which channel it belongs to, post it. It did not scale, branding drifted between states, and nothing stopped someone from publishing into a channel that was not theirs. These posts reach a public audience - a mistake is not something you can quietly undo.
Solution
We worked backwards from the two things that could not move. The client's security team would not share credentials, and each team had to stay inside its own state - so both were made structural rather than something the interface has to remember to enforce. Uploads route through a service that mints a short-lived, single-use URL per file, so no long-lived key is ever distributed and size limits live in one place. Access is modelled per state with three levels, making scope a property of the data rather than a UI check. On top of that sits the part operators actually use: choose a channel, generate a branded creative or bring your own, get a caption drafted from the image and the channel it is going to, review it, schedule it. Generation is automated; publishing stays a decision a person makes.
Architecture
Key Engineering Decisions
Design for having no credentials at all
The client's security team would not hand over keys, and they were right to refuse. Instead of negotiating, the upload path was built so credentials are never needed: one endpoint issues a time-limited URL per file. The constraint made the system safer than the original plan.
Separate who can deliver a file from who can store one
The bucket blocks public access entirely and a CDN is the only public route to a creative. Storage permissions and delivery permissions stop being the same decision, so opening one never quietly opens the other.
Put scoping in the data, not the interface
Every team edits only its own state, enforced at the access layer rather than by hiding buttons. With many teams publishing to public channels, a mis-scoped post costs far more than carrying a permission model.
Automate generation, not publishing
An operator sees the creative and its caption before anything goes out. Keeping a person on the last step is what makes running this daily, at this reach, safe.
Build Notes
- Each state carries its own bots, channels, and team members, so adding a state is configuration rather than a code change
- Three access levels - none, view-only, and edit scoped to a user's own state
- A fixed header panel is composited onto every generated creative so state branding cannot drift
- Captions are drafted from the image plus the destination channel, appending the bot link where one is set
- Custom uploads supported, with a toggle for whether the brand overlay is applied
- Image storage migrated onto the client's own cloud account mid-flight, without downtime
Results
- ~170 creatives generated and published through the pipeline
- Per-state manual production replaced by generate, review, schedule
- No shared cloud credentials distributed anywhere in the system
- Each team confined to its own channels, with a review step before publish
Live channels
The automation publishes into these WhatsApp channels every day. Each state team only sees and schedules its own.

SwiftChat Jammu & Kashmir
View on WhatsApp
SwiftChat Himachal Pradesh
View on WhatsApp
SwiftChat Uttarakhand
View on WhatsApp
SwiftChat Madhya Pradesh
View on WhatsApp
SwiftChat Gujarat
View on WhatsApp
SwiftChat Tripura
View on WhatsApp
VSK | DNH&DD
View on WhatsApp
विद्या समीक्षा केंद्र (VSK), महाराष्ट्र
View on WhatsApp
Goa- VSK - SwiftChat
View on WhatsApp
Why this matters
- Turned a client security constraint into a better architecture instead of an exception
- Multi-tenant role scoping across many independent teams
- Ran the client relationship directly: weekly requirements, demos, launch
- Migrated storage onto the client's own cloud account without downtime







