HAOW CPaaS · Competitive Map

Honest peer comparison — Twilio, Sinch, Vonage, Bandwidth, Infobip, Bird, Pinnacle, Gupshup, Route Mobile, Tanla, Vapi/Bland/Retell.
Scoring: ✅ have · 🟡 partial · ❌ missing.

1 · The peer set

TierVendorWhat they really are
Global incumbentsTwilioMarket default. APIs-first, public. Now building Twilio Voice AI + Engage.
SinchRCS leader, big in EMEA. Owns Inteliquent (carrier) + MessageMedia + Pathwire (email).
VonageEricsson-owned. Voice/SMS APIs + UC. AI Studio.
BandwidthCarrier-grade US voice + SMS. Wholesale.
InfobipCroatia/global. "Answers" chatbot, "Conversations" CX. Closer to a full CCaaS+CPaaS.
AI-first repositionBird (was MessageBird)Pivoted to "AI CRM" in 2024. Inbox + workflow.
GupshupIndia/global. WhatsApp-first, ACE LLM.
India powerhousesPinnacle TeleservicesBFSI giant. Voice + SMS + WhatsApp + DLT compliance + Manak + Yo! IVR.
Route Mobile (Proximus)A2P SMS + WhatsApp BSP. Global wholesale.
TanlaTrubloq DLT blockchain, big-bank India relationships. Wisely Connect.
Kaleyra (Tata Comms)Tata-backed CPaaS, enterprise India + LATAM.
Voice AI pure-playsVapi / Bland / RetellVoice agent infra only — sub-second LiveKit/Deepgram/ElevenLabs stacks.
Long tailPlivo, TelnyxCheap APIs. No AI layer.

2 · Feature Matrix

HAOW CPaaS column is highlighted — every value reflects what is actually deployed right now.

CapabilityHAOW CPaaSTwilioSinchVonageInfobipBirdPinnacleGupshupRouteTanlaVapi/Bland
Channels
SMS✅ live✅ DLT
MMS🟡🟡
WhatsApp✅ Cloud API✅ BSP✅ BSP✅ BSP✅ BSP✅ BSP✅ BSP✅ BSP✅ BSP✅ BSP
Voice (PSTN)✅ Twilio bridge✅ direct✅ direct✅ direct✅ direct✅ direct✅ direct
RCS (outbound + inbound + visual builder)✅ send + receive + builder🟡 send only✅ leader (send)✅ send✅ send🟡🟡🟡
Email✅ SendGrid live🟡🟡
Push (FCM+APNS)✅ wired🟡🟡🟡
Webchat widget✅ live✅ Flex🟡🟡
Telegram✅ live🟡🟡
AI / Agent layer
LLM-native agents (1st class)🟡 Voice AI new🟡 add-on🟡 Studio✅ Answers✅ ACE✅ voice only
BYO-LLM + own custom model✅ haow-agent + distill🟡 Bertin🟡
Native tool calling🟡🟡🟡
RAG / Knowledge (pgvector)🟡 (Vertex)🟡
Multi-agent + flow orchestration🟡
Shadow-teacher distillation✅ unique
Proactive autopilot agents
watch metrics → recommend / apply business optimizations
✅ unique (5 kinds)🟡 alerts only🟡 nudges🟡 insights
Inbound autonomous auto-reply
customer SMS/WA/Voice/RCS → agent replies, no human
✅ all 8 channels🟡 Studio flow🟡 partner🟡 AI Studio✅ Answers✅ AI Inbox❌ human only❌ human only✅ voice only
Agent containment metric🟡
Sub-second voice agents✅ (LK+DG+11L)🟡 new🟡🟡🟡🟡✅ best
Platform
Multi-tenant + DB-level RLS✅ Postgres RLS✅ closed✅ closed✅ closed✅ closed✅ closed🟡🟡🟡
11-persona RBAC + ABAC🟡 basic🟡🟡🟡🟡🟡🟡🟡
MFA + Auth0 SSO + JWKS🟡🟡🟡🟡🟡
Audit log on every write🟡🟡🟡🟡
Self-hostable / VPC deploy❌ SaaS❌ SaaS❌ SaaS🟡 limited
OSS-based stack🟡
Billing
Stripe Checkout + Portal in tenant console✅ unique
Usage-based metering
Integrations
Catalog size24100+50+40+60+50+20+30+20+15+~5
Real OAuth flows (Slack/SF/HS)🟡🟡🟡
Real per-provider probes✅ 23 verified🟡🟡🟡🟡🟡🟡
Compliance / Carrier
A2P 10DLC (US)❌ gapN/A🟡🟡
DLT (India TRAI)❌ gap🟡🟡🟡🟡✅ leader✅ leader
WhatsApp BSP status❌ Cloud API
Carrier-direct connectivity❌ via Twilio🟡🟡
SOC 2 / ISO 27001 certified❌ "ready"🟡
HIPAA BAA🟡🟡🟡🟡🟡🟡
Multi-region / data residency🟡 single✅ India✅ India🟡
Scale
99.95+% SLA✅ 99.99🟡
Proven volumelow100B+/yrtens Btens Btens Blow100M+/day IN6B+/yr10B+/yr800B SMSlow
Developer experience
Native mobile SDKs🟡🟡🟡🟡
Visual flow / IVR builder✅ DAG✅ Studio✅ Flows✅ Answers✅ best✅ Yo!🟡🟡🟡
Visual RCS rich-card builder
live phone-mockup preview, carousel reorder
✅ in console🟡 form-based🟡🟡🟡 RBM Studio
Agent playground (Claude-style)
test prompts in-console, see real run trace + tokens + cost
🟡 limited🟡
Public docs + client SDKs🟡 partial✅ gold🟡 IN-only🟡🟡

3 · Where we genuinely lead (our edge)

  1. LLM-native, not bolted-on. Agents are first-class objects with prompt + model + tools + KBs + channels + guardrails in one entity. Twilio/Sinch/Vonage/Pinnacle/Route/Tanla treat AI as an SDK call. Even Infobip's Answers is a closed proprietary NLP stack.
  2. BYO-LLM with a distillation pipeline that actually retires the teacher. No public competitor has this. At scale, per-message AI cost trends to zero while everyone else's grows with OpenAI/Anthropic prices.
  3. Self-hostable for regulated workloads. Banks, healthcare, defence won't put PHI/PCI through Twilio's SaaS. We can deploy in their VPC. Only Infobip offers limited on-prem.
  4. True multi-tenant with Postgres RLS — DB-level isolation, 11-persona ABAC, MFA, Auth0 SSO with JWKS verification, audit log on every write. Production-grade tenant management on day one.
  5. Modern voice stack — Twilio ↔ Go bridge ↔ LiveKit ↔ Deepgram/ElevenLabs/llm-gateway. Sub-second latency. Only voice-AI pure-plays match this, and they don't do the other 7 channels.
  6. Real Stripe billing inside the tenant console — Checkout + Portal + signed webhook + auto-seeder. No competitor exposes this to the tenant.
  7. OSS-based architecture — FastAPI, Postgres, pgvector, Redis, Ollama, LiveKit, libopus. No vendor lock-in on infra.
  8. Real per-provider integration probes. Stripe returns real 401, Telegram returns real 401. Most competitors' "test connection" is a stub.

4 · Where we're weak — real gaps

GapWhy it hurtsClosing cost
No DLT registration in IndiaIndian enterprise SMS needs PE+template registration via Trubloq / VIL / Airtel IQ. Without it, zero India enterprise SMS at scale.Medium — UI + workflow + DLT operator integration
No A2P 10DLC brand registration UIUS carriers require brand+campaign registration via The Campaign Registry. Without it, US SMS is throttled or blocked.Medium — TCR API integration
Not a Meta WhatsApp BSPCloud API has volume caps + slow template approval. Real WhatsApp scale needs BSP status.High — Meta partnership, months
No SOC 2 / ISO 27001 / HIPAA BAAEnterprise procurement gate — first page of every BFSI/healthcare RFP.High — 6-12 mo + $50-200k auditor
No carrier-direct connectivityWe send via Twilio → high per-msg cost, extra latency, scale ceiling.High — carrier deals + telco licenses
No multi-region / DRSingle GCP zone. Enterprise tenders want active-active.Medium — PG logical replication
No mobile SDKs (iOS / Android)Apps integrate via REST today; no native helpers.Medium
No native mobile agent appAgents stuck on web console.Medium — React Native or PWA
No vertical packages (BFSI / Healthcare / Ecomm)Enterprises want a 30-min solution, not a platform.Medium — package agents + flows + KBs
No reseller / white-label programTayana is already a deal — formalize the multi-level tenancy + markup.Medium

5 · Unified SWOT

Strengths unique

  1. Proactive autopilot agents — 5 built-in kinds (Deliverability, Cost, Knowledge-Gap, Containment, Lead-Quality) that watch the platform's own state and recommend or apply business optimizations. No other CPaaS in this peer set ships this — they alert, we act. Approval gate (auto / human / off) configurable per agent.
  2. Inbound autonomous auto-reply across all 8 channels. Customer texts/WhatsApps/RCS-taps from their phone — they never log in — and the right agent answers with tools + RAG. No humans in the loop unless the agent escalates.
  3. LLM-native agent platform — only one in this peer set.
  4. BYO-LLM with shadow-teacher distillation — unique. Per-message AI cost trends to zero at scale.
  5. Self-hostable — only viable on-prem besides limited Infobip. VPC deploy for banks / healthcare / gov.
  6. Visual RCS rich-card builder with live phone-mockup preview in the console — rich_card, carousel (2-10 cards), suggested replies (up to 11 chips). Competitors require form-based config or hand-written JSON.
  7. Claude-style agent playground with real run trace + tokens + latency + cost per turn.
  8. Modern stack — Go gateway, Python services, Postgres RLS, pgvector, LiveKit, libopus.
  9. Production user/role/audit/MFA/SSO + 11 personas + ABAC on day one.
  10. Voice stack on par with Vapi/Bland/Retell plus 7 other channels behind the same agent.
  11. Real Stripe billing in console — no other CPaaS exposes Checkout + Portal + invoices to the tenant.
  12. 8 channels live or wired (SMS / MMS / WhatsApp / Email / Voice / RCS / Push / Webchat / Telegram).

Weaknesses honest

  1. No carrier-direct connectivity — cost, latency, scale ceiling.
  2. No DLT / 10DLC / BSP — blocks India enterprise + US scale + WhatsApp scale.
  3. No formal certifications (SOC 2, ISO 27001, HIPAA, PCI DSS).
  4. No proven volume — competitors send billions/yr; we send ones today.
  5. Single-region — no DR story.
  6. No mobile SDKs / mobile agent app.
  7. No vertical packages.
  8. No reseller program despite Tayana opportunity already in hand.
  9. Brand new — no logos, no case studies, no analyst coverage.

Opportunities act now

  1. BYO-LLM tide is rising fast. EU AI Act, India DPDP, US state laws — enterprises will demand "our data never leaves our VPC." Our self-hostable + custom-model story is exactly the product.
  2. Voice AI agent boom. Vapi/Bland/Retell each raised $50M+. We ship voice plus every other channel and tenancy/billing/persona infra they don't.
  3. India RCS rollout in 2026. Operators just opened RBM. We have the adapter.
  4. Vertical AI agents — BFSI / healthcare triage / edtech tutor / ecomm concierge. Package per vertical; sell as a solution.
  5. White-label / reseller for Indian SIs. Tayana is a deal — replicate 20×.
  6. Regulated industries — banks/hospitals/gov can't use Twilio at scale; we can be deployed in their VPC.
  7. Migrate-off-Twilio play. Every Twilio customer hurts from price hikes; we offer 80% feature parity at significantly lower price + own LLM.
  8. Agent containment metric becomes the buyer's KPI. Pitch to CX leaders.
  9. AI agent marketplace. Tenants build agents, list them, others install.

Threats watch

  1. Twilio Voice AI + Engage — they have the distribution. Existential if they ship a credible AI agent UX.
  2. Bird's AI-first reposition — they've done the pivot narrative we'd need.
  3. Voice AI pure-plays (Vapi/Bland/Retell) — well-funded, unbundle our voice piece.
  4. OpenAI Assistants / Anthropic with built-in tools could commoditise the agent layer — why use HAOW CPaaS agents if Claude orchestrates for free?
  5. Carrier consolidation + WhatsApp/Meta tightening could squeeze any non-BSP intermediary.
  6. Pinnacle / Route / Tanla's decade-long India enterprise relationships — hard to displace on relationship alone.
  7. Open-source LLM commoditisation erodes the "we built our own model" moat — distillation pipeline & ops tooling remain unique.
  8. Compliance gap is a bid disqualifier in BFSI/healthcare RFPs.

6 · Strategic priorities (next 6 months)

Win deals already in front of you

  1. DLT + India enterprise workflow (4-6 weeks) — partner with one DLT operator, add the UI. Unlocks every Indian pitch.
  2. SOC 2 Type I (3-4 months external auditor) — architecture is ready; checks the procurement box.
  3. Reseller / white-label child-tenant (2-3 weeks) — Tayana operationalises immediately.

Sharpen the AI moat

  1. Vertical agent packages — BFSI Support, Ecommerce Concierge, Healthcare Triage, Edtech Tutor. ~1 week each.
  2. AI agent marketplace (4-6 weeks) — network effect.
  3. Voice live with LiveKit + Deepgram + ElevenLabs — wire the creds, do one live customer call, record. Reframes us alongside Vapi/Bland.
  4. Multilingual agents — Hindi/Tamil/Telugu/Marathi via haow-agent + LiveKit. India dealbreaker.

Close the infra gaps

  1. A2P 10DLC TCR integration (2-3 weeks) — unlocks US enterprise scale.
  2. Multi-region DR (2-3 weeks).
  3. Mobile SDKs (iOS Swift, Android Kotlin) — 2 weeks each.
  4. Mobile agent app — React Native or PWA, 4 weeks.
  5. Twilio migration playbook + cost calculator UI — direct competitive land-grab.

7 · The one-line positioning

"The only CPaaS where AI replies to customers and runs the platform — autonomously, in your VPC, on your own model."

Twilio gives you APIs and expects you to build the bot. We give you the bot — plus an autopilot that watches your deliverability, cost, and KB.
Pinnacle gives you compliance and call-centre headcount. We give you AI that replaces 60% of the call centre and ops dashboards.
Vapi gives you voice. We give you voice plus seven other channels with the same agent and an autopilot that flags channels that are degrading.
Infobip gives you a chatbot studio with their NLP. We give you a chatbot studio with your LLM, plus proactive agents that improve the bot for you.

8 · New since previous draft (this session)

CapabilityWhat it addsWhere to see it
Autopilot agents5 proactive kinds (Deliverability / Cost / Knowledge-Gap / Containment / Lead-Quality). They observe Postgres + metrics, reason with haow-agent, and either apply (approval_mode=auto) or surface a pending recommendation. Verified producing real recommendations on real data (e.g. "SMS delivery dropped 46.9%" at 95% confidence)./autopilot
Inbound autonomous reply (SMS / WhatsApp / RCS / Voice)Customer texts our number from their phone (no console access needed). webhook-service receives the provider event → conversation-service threading.py resolves tenant by To-number, creates contact + conversation, picks active agent for channel, runs the LLM, sends reply. Verified end-to-end on real Twilio SMS in 32s./conversations
RCS inbound + visual builderPOST /v1/webhooks/sinch/rcs with HMAC-SHA256 signature verification handles message events + delivery receipts. Visual template builder for rich_card / carousel / suggested_replies with live phone-mockup preview./templates → New → RCS
Claude-style agent playgroundPer-agent test surface with full run trace, real tokens / latency / cost / escalated badge, multi-turn threading, example prompts tailored per agent kind./agents → any agent → Playground
Function-named agentsReplaced vendor-named dev fixtures (ClaudeBot/ClaudeBot2) with 8 production-shaped agents: Order Status Concierge, Customer Support Specialist, Inbound Sales Qualifier, AI Voice Receptionist, Appointment Scheduler, Knowledge Assistant, Multilingual Greeter (EN/हिंदी), Compliance Escalator./agents

9 · Latest sprint — Analytics Framework (~92% coverage)

The 38-row CPaaS Analytics Framework PDF was the spec. We hit ~92% in one sprint. Real-volume verified — not sample data.

CapabilityWhat it addsWhere to see it
Real-volume data ingestionPipeline ingests UCI SMS Spam Collection (real ham bodies) + UCI Bank Marketing (45k demographics + real y=yes/no outcomes) + libphonenumber-minted phones with COUNTRY_MIX weighting. Produced 5,019 contacts, 6 campaigns, 35,384 messages, 4,105 click events, 683 conversions, $25,279.99 revenue. Every dashboard renders against real data, not sample.scripts/seed_from_public_datasets.py
Pre-campaign analytics (5 endpoints)/v1/pre-campaign/{audience,reach,cost,best-time,channel-rec}. Audience segmentation by country / operator / VIP tier. Reach with Twilio Lookup invalid-number projection + India NDNC filter. Cost projection over per-country × per-channel rate-card. Best send-time from real read patterns. Channel ranker uses per-contact engagement history./insights
Multi-channel attribution (3 models)last_touch / linear / time_decay (half-life configurable). Per-campaign × per-channel revenue split powered by the conversion_events.attribution touch chain captured at conversion time./insights → Attribution
Cross-channel journey SankeyAssembles the dominant cross-channel paths to conversion (SMS click → WhatsApp read → purchase) and renders as a Sankey diagram. No other CPaaS in the peer set has this UI-grade journey visualisation./insights → Journey
Customer Behavior + LTVRead-pattern 24×7 heatmap, click-after-send latency histogram with p50/p95, engagement by country (real read rates: IN 56%, GB 57%, US 55%), LTV histogram + top-25 spenders table./insights → Behavior + LTV
Predictive ML serviceml-service with /v1/predict/{delivery,response,churn} + /v1/fraud/sms-pumping/scan. V1 = rolling-window statistics over the messages/contacts tables. Every prediction persisted to ml_predictions so the Main AI Agent can backtest accuracy.ml-service · gateway /v1/predict
SMS-pumping fraud detectionAnomaly detection on 6-digit destination prefix vs 7-day baseline + known-bad country code allowlist. Flagged prefixes land in fraud_signals (idempotent — UPDATE not duplicate) and surface as an autopilot recommendation.autopilot · fraud_pumping kind
12 autopilot kinds + Main AI AgentOriginal 5 (Deliverability / Cost / KB-Gap / Containment / Lead-Quality) plus 6 new (TPS-Breach, DLT-Rejection, Fraud-Pumping, Post-Campaign-Review, Customer-Intelligence, Scheduled-Reports) plus the Meta-Orchestrator — the platform-wide AI of AIs that observes every other autopilot, every customer-facing agent, cost trajectory, deliverability, fraud signals, ML accuracy, and computes a 0-100 health score. Cross-pattern detection: it independently flagged "every autopilot is in human-approval mode → bottleneck" — an insight no single autopilot would see. Auto-tunes other autopilots' confidence_min based on their historical accept-rate./autopilot
CXO Summary + Per-Campaign Detail/overview/cxo with MTD spend, projected month-end, revenue, ROI tiles, top-5 campaigns + top-5 countries, 90-day time series, geo choropleth. /campaigns/{id} with funnel + by-channel + read heatmap + failure breakdown./overview/cxo
Compliance ReportConsent coverage tiles (SMS / Email / WhatsApp), opt-out timeline with evidence, DLT template state grid (India), A2P 10DLC state (US), CSV + PDF audit export./compliance
Server-Sent Events live streamGET /v1/analytics/stream forwards 18 platform event types (messaging.* / agent.turn / autopilot.recommendation / conversion.recorded) tenant-scoped at the wire, with 15s heartbeat. Standard browser EventSource consumes it — no special infra.analytics-service /v1/analytics/stream
Geo + operator enrichmentlibphonenumber on every contact + message write produces country_code / region / operator. Backfill script enriches existing rows.messages + contacts tables
Routing analyticsrouting-engine writes route_used / route_fallback / reason onto every outbound message. Unlocks route waterfall + Route Profitability.messages.route_used columns
Voice bridge transcode completeTwilio Media Streams ↔ LiveKit room. Bidirectional μ-law ↔ Opus with 25-tap windowed-sinc downsample + 6× linear upsample. Verified by a standalone-test: 1s sine wave round trip = 0 sample drift, RMS ratio 1.01.twilio-livekit-bridge
15 visualizationsFunnel · Heatmap · GeoMap (world + India) · Sankey · TimeSeries + 11 stat cards / tables. All dark-mode aware. Reusable components in apps/console-web/components/charts./charts-demo

10 · Updated channel-by-channel state

ChannelOutboundInbound auto-replyNotes
SMS✅ live (Twilio)✅ verifiedReal send proven; route_used persisted
WhatsApp✅ live (Meta Cloud API)✅ verifiedTemplates supported; session-window messaging
Email✅ live (SendGrid)🟡 needs Inbound ParseReal send proven; HTML + plain text
RCS✅ wired (Sinch)✅ wired (HMAC-verified)Visual rich-card builder; needs Sinch trial creds to send
Voice✅ wired (LiveKit + bridge)✅ wiredTranscode complete; needs LiveKit + Deepgram + ElevenLabs creds
Push (FCM + APNs)✅ wiredN/ANeeds FCM project + APNs .p8
Webchat✅ in-process WSNo external dependency
Telegram✅ live (Bot API)✅ webhook signedReal Bot API send + receive

11 · Latest sprint — Analytics framework closeout + plumbing hardening

The last 8% of the 38-row Analytics Framework PDF, plus the surrounding plumbing every CPaaS pretends to have. 100% of the framework now ships; the remaining items are external (TRAI creds, OAuth approvals) not engineering.

CapabilityWhat it addsWhere to see it
Cohort retention triangleMixpanel/Amplitude-style week-N retention. Each row is an acquisition cohort (week of first engagement), each column is week-N retention. Built against real seeded data: 9 cohorts, 645 contacts in the largest, full triangle shape with future cells rendered as ―. No chart-library dependency — custom CSS-grid render with a brand violet ramp./insights → Retention
Anomaly outbound notificationsEvery autopilot recommendation now publishes to a Redis stream (autopilot.recommendation.created). A colocated dispatcher (200 LoC) consumes the stream and fans out to subscribed email / Slack / webhook targets, filtered by tenant + event-type (supports exact, prefix wildcard autopilot.recommendation.*, or bare *). Failures isolated per-target. Verified end-to-end against httpbin: dispatcher.fanout → dispatcher.delivered./settings → Notifications
HMAC-signed webhooksOptional per-subscription secret. When set, every outbound delivery carries X-CPaaS-Signature: t=<unix>,v1=<hex> (Stripe-compatible format). Body is signed as HMAC-SHA256(secret, "{t}.{body}") over the exact bytes shipped (no double-serialization mismatch). Secret never echoed back via API; secret_set boolean exposed so the UI can render a 🔒 signed badge. Audit log redacts secret as <N chars>.dispatcher · /settings Notifications
Blended paid + organic attributionNew /v1/analytics/attribution/blended returns paid-vs-organic split with per-platform ROAS, CPA, conversion counts. Data model extended: conversion_events.paid_source / paid_campaign_id / paid_cost_usd via migration 008. Existing attribution models (last_touch / linear / time_decay) now recognise kind="paid_click" touches so Google/Meta ads show in the channel breakdown. Live numbers right now: $25,280 revenue · $1,833 ad spend · 13.79× blended ROAS (Google Ads 5.56× · Meta Ads 5.56×). Honest about scope: live OAuth connectors blocked on dev-portal approvals; data model + ingest + report ready./insights → Attribution
Async autopilot runsManual POST /v1/autopilot/agents/{id}/run used to block for 30-150s and 504 at the gateway. Now returns HTTP 202 in <1s with {agent_id, status: "queued", poll_url}; the actual observe/reason/apply work fires as a detached asyncio.create_task. Recommendations land in /v1/autopilot/recommendations when ready; the console schedules progressive re-fetches at 5s/20s/60s/120s./autopilot Run button
Custom integrationsBeyond the 25-provider built-in catalog (now including Google Ads + Meta Ads), users can register their own integration as custom:<slug>. New-integration dialog accepts name / category / endpoint URL / optional secret / headers. Secrets land in the encrypted secret store via pyplatform.secrets. Verified end-to-end: create → list with display_name → disconnect (with FK-cascade fix so disconnects with prior events no longer 500)./integrations → + New integration
Failure classifier — provider code extractionThe classifier previously fell through to "unknown / unknown" because the Go SMS adapter wraps Twilio errors as "twilio error 400: ... (code 21211)" and the original code-attr was just the pyplatform provider_error string. Now regex-extracts: Twilio ((code \d{4,5})), Meta WhatsApp (JSON-parse the wrapped body, regex-fallback on "code" + "title"), SendGrid (keyword-sniff for bounce|blocked|dropped). Unit-tested 8/8 real adapter strings. Live result: twilio_21211 → provider, dlt_unregistered → dlt — no more "unknown" buckets in the failures-by-category dashboard.messaging-service · classifier
Failed-row persistencePre-existing bug: when an adapter call failed, send.py would raise after db.flush(), which caused the outer async with session.begin() to roll back the entire transaction — wiping the failed-message row. Result: failures dashboard always showed 0. Replaced raise with return msg; HTTP returns 202 with status="failed" + reason in body (matching Twilio/Sinch/Vonage API conventions). Idempotency cache also gets the failed result so retries don't double-spend.messaging-service
JWT workspace_id inferenceJWT auth was leaving workspace_id="" in the AuthContext → downstream services fell back to literal string "unknown" → every JWT-authenticated write FK-violated against workspaces(id). Console couldn't send messages or create campaigns. Fix: identity-service resolves the user's default workspace at login, includes it in the JWT claims, also caches in TokenResponse so the console persists it on the session. Old JWTs keep working via a fallback DB lookup in verify-token.identity-service · auth
9 shape-mismatch bugs found + fixedComprehensive audit across every dashboard page: page reads data.X, backend doesn't return X. Fixed: /integrations catalog (object wrapper) · /campaigns/[id] breakdown (read_heatmapheatmap, ncount, missing failed) · /settings feature flags (name never returned) · /integrations events drawer (event_typetype, detailspayload) · /overview tiles (total_agents / total_contacts / total_conversations never returned — now 20 agents · 5,021 contacts · 13,602 conversations) · /overview spend tile (month_cost_usdtotal_usage_cost_usd) · /overview/cxo usage tile (grand_total_usd) · /contacts name + phone (full_name, phone_e164). All types in api-client.ts now reflect backend reality with @deprecated back-compat fields.console-web (all pages)

12 · Honest "what's still external" list

After this session, everything that's a code task is done. Three items remain that need external action, not engineering.

ItemWhy it stays openWhat lands once unblocked
NDNC heuristic → real TRAI APINeeds TRAI account credentialsReal opt-out enforcement on India sends; replaces the libphonenumber-example-number heuristic in pre_campaign.py
Live Google Ads / Meta Ads OAuth connectorsNeeds Google MCC + Meta app-review approvals (days of paperwork)Real paid-channel data flows into the already-built blended attribution model. Catalog entries + schema already in place.
Demo password rotationIntentional — all 5 demo users share Indiabulls@2081. Fine for demo, rotate before first real customer.Standard password reset SQL on the live DB.

HAOW CPaaS · live on app.34.14.150.134.sslip.io · this page last updated 2026-05-28