Where: Settings → Configuration → WhatsApp, WhatsApp rooms and Staff numbers
Sokisoko can send notifications and answer questions over WhatsApp — for buyers, for supplier and staff groups, and for your own team. The assistant that answers is the same one behind Ask AI: it only ever sees what the person (or the room) is allowed to see, and it never performs an outward-facing action without a confirmation.
Before you begin
- Decide whether you need group chats. Meta's Cloud API cannot see groups; the Sozuri gateway can.
- A number registered in the WhatsApp app cannot also be on the Cloud API, so decide before linking.
- Set an Assistant name — the wake word people use in groups.
Pick the transport
| Meta Cloud API (default) | Sozuri gateway | |
|---|---|---|
| Who runs it | Meta | Sozuri, on your own WhatsApp number |
| 1:1 chats | yes | yes |
| Group chats | no — Meta has no group support | yes |
| Tappable buttons | yes | no (short codes instead) |
| Templates | required for business-initiated messages | none |
Use Cloud unless you need groups.
Connect — Cloud API
- In the WhatsApp panel, tick Send WhatsApp notifications and set Transport to Meta Cloud API.
- Fill in the Phone number ID and Access token (From Meta → WhatsApp → API setup).
- Set an App secret — Required to accept replies — unsigned callbacks are rejected.
- Under Receiving replies, set a Verify token (Any phrase; paste the same one into Meta), press Save WhatsApp settings, then copy the generated Callback URL into Meta → Webhooks and subscribe to
messages. - Under Message template, enter the Template name and Template language of a template with three body variables in order: store name, what happened, the link back.
Connect — Sozuri gateway
- Set Transport to Sozuri gateway.
- Enter the Sozuri project name, the API key and the Webhook signing secret. Secrets are write-only; the panel only reports that they are stored.
- Save, then copy the Inbound webhook URL the panel shows into Sozuri → Project → WhatsApp.
- Link the number from the Sozuri dashboard (Project → WhatsApp → scan the QR).
No template is needed on this wire, and group chats work. Inbound events are signed; unsigned or stale events are rejected.
Let the AI answer
Under AI assistant, tick Let the AI answer WhatsApp messages and set the Assistant name (e.g. GalaxyAI). In a 1:1 chat with a buyer whose number matches a storefront login, the assistant answers as that buyer — orders, quotes, invoices — with the same confirmation cards as in the storefront. In a 1:1 chat with an unknown number it answers as the public agent: catalog and how-to only.
Groups and rooms
A group is a shared room, so it is treated as one.
- Add the number to the group from the phone.
- It appears in WhatsApp rooms, marked silent. Every message is stored from that moment; nothing is answered.
- Set its Scope — the only thing that lets the assistant speak there. Nothing is inferred from the group's name or contents.
| Scope | What the assistant may know |
|---|---|
| (unclassified) | nothing — it stays silent |
| Customer | that one account's orders, quotes and invoices (also pick the Account) |
| Supplier | catalog and how-to only |
| Internal | catalog and how-to only — plus staff authority for linked numbers |
| Personal | catalog and how-to only |
In a group the assistant answers only when called by name — @GalaxyAI what is the delivery status of order 1024? — and ambient chatter is stored and ignored. A participant whose number matches a login on the bound account speaks as themselves; anyone else gets the account's read-only authority. Scope changes are written to the Audit log with who made them and what the room could see before and after.
Decline personal groups. The bot reads every message in any group it joins, so a personal group means logging staff private chat for no upside.
Confirmations
The assistant never performs an outward-facing action on its own. It prepares one and asks:
Ready to send quote 76dc3e08 to Thorn — 250000.00 KES.
Reply CONFIRM K7QD to go ahead. It expires in 10 minutes,
and only the person who asked can confirm it.
On the Cloud API the card also renders as tappable buttons; Sozuri relays plain messages, so the code in the body is the whole interface. Only the person who asked can answer; it works once and dies after ten minutes; a new card retires the previous one.
When a person is needed
Anyone saying human or agent in a room the assistant works in mutes the assistant there, flags the room in WhatsApp rooms with what was asked, and emails the account's assigned rep (or the staff who can act). No wake word is needed. Press Hand back on the room when a person has dealt with it — that also unmutes the assistant.
A reply typed on the business phone itself does the same without anyone asking: the room shows a person is handling for twelve hours, the assistant files what was said and stays quiet, then simply listens again — it never announces itself. Calling it by name still gets an answer. Take over puts a room in that state by hand; Hand back ends it early. Thanks and small talk are never answered, and messages arriving within ten seconds of each other get one reply. A photo a customer sends is read by the assistant — the transcript shows what the picture is of, and the reply answers that item.
Attachments
A photo or document sent into a chat is stored and shown to the rep. Its caption becomes the message, so "is this the right bolt?" with a photo still reaches the assistant as a question. The assistant reads text, not images — an attachment is filed for a person to look at. Files over 25 MB are refused. Outbound, the platform can send a document by link (a quote PDF, say) into the chat that asked for it.
Staff access over WhatsApp
By default the bot only speaks as a buyer or as the public agent, so seller-side questions have no answer. Tick Let staff use their own access over WhatsApp, then in Staff numbers:
- Enter your number and press Link my number (an admin can enter a colleague's and press Link their number).
- It shows a code like
LINK K7QD. Message exactly that, from that phone, to the business number. The code works only from that number, only in a 1:1 chat, and only for 15 minutes. - The row flips to active.
A linked number gets exactly what the person's roles already give them — nothing added. A rep with invoice.view can ask "what is outstanding?" and get the seller's answer. Staff authority applies only in that person's own chat and in Internal groups; in a customer, supplier or personal group the room's scope applies instead, so seller-side answers never appear where an outsider can read them. Revoke a number in the same panel; it takes effect immediately.
When it isn't working
| Symptom | Cause |
|---|---|
| Bot silent in a group | The room is unclassified, or nobody used its name |
| Bot silent everywhere | Let the AI answer is off, or no assistant name is set |
| Bot went quiet in one chat | Someone asked for a human or an agent, or a person replied from the business phone — the room says so in WhatsApp rooms; Hand back lets the assistant in early |
| Replies never arrive (Cloud) | No app secret — unsigned callbacks are rejected |
| Replies never arrive (Sozuri) | The signing secret differs from the one in Sozuri, or the webhook URL was not pasted into the project |
| "That confirmation has expired or is not yours" | Someone else in the room answered it, or more than ten minutes passed |
Opening an account from WhatsApp
A visitor with no account can ask the assistant to open one right in the chat: it takes their name, email and company in a single question. Because they are messaging from their own phone, the number travels with the invitation, so when they click the emailed link and set a password the number is connected at the same moment. No code, no second step: from their next message they see their own prices, orders and invoices.
The number is only trusted because WhatsApp authenticates the sender. A visitor on the website cannot claim a number, so nobody can attach someone else's phone to their own new account.
How a buyer's number is trusted
A phone number sitting in a contact record proves only that someone typed it. Before a number speaks for a customer account — their prices, orders, invoices — it has to prove itself:
- The buyer sends LINK to your WhatsApp number.
- Sokisoko emails a four-character code to that account's own address, and tells them which address it went to without spelling it out in the chat.
- They reply LINK and the code from the same phone. Only then does the number carry the account.
Until that happens the assistant treats them as a guest: it can search the catalog, explain how things work and open an account, but it will not read anyone's invoices. A code is good for fifteen minutes, works only for the number it was issued to, and only in a one-to-one chat.
Who the assistant answers
In a group the assistant only speaks when it is named, and only in a room you have classified. In a one-to-one chat it answers every buyer straight away, which is usually what you want from a sales number. Switch on Only answer when the assistant is named if you would rather it waited to be called there too — quieter when strangers message the number.
Channels and newsletters are never answered or stored. A number that follows news channels receives their broadcasts as if they were chats; those are ignored entirely, so the inbox holds buyers and the assistant is never spent on a headline.