The Grove
Mini CRM & Member Communications System
“One member. Multiple groups. Clear communication rules and history.”
Governing Architectural DirectiveCommunications Control & Verification Layer
Dual-dispatch routing topology separating permissive personal group workflows from API-driven broadcast pipelines.
Member Records
Normalized entity modeling with cross-cutting profile identities.
Ministry Groups & Categories
Many-to-many group assignments with independent scope.
Audience Segment Preview
Dynamic query execution calculating precise target sets prior to draft lock.
Message Planning & Admin Approval Queue
No outbound operation can occur without structured message body clearance, audience audit, and dual authorization for broadcast classes.
Manual Export Send
Filtered, de-duplicated recipient list exported with one-click click-to-chat links for team leads. Eliminates platform broadcast flags completely.
Gated WhatsApp Cloud API
Strictly gated programmatic delivery reserved for institutional emergencies. Pre-authenticated Meta templates with real-time monthly cost ceilings.
Activity & Audit Log / Delivery Trace
Immutable event log tracking dispatch channel, authorizing user, recipient hash, and status codes.
The Challenge
A church organization was confronted with severe operational disruption after its primary official WhatsApp communication number was flagged, reported, and permanently restricted by platform anti-spam algorithms.
The underlying failure was structural, not technical. Without an authoritative central member registry, multiple pastoral teams were running uncoordinated broadcast lists from personal and shared phones. Staff had no systematic way to verify:
Which physical member corresponded to which mobile record across fragmented volunteer address books.
What specific ministries, cohorts, or services an individual member actually belonged to.
Whether express permission had been granted for recurring broadcast announcements.
Who authorized specific messages, when they went out, and through which exact dispatch channel.
Treating bulk messaging as an automation problem without addressing data discipline and communication governance had created catastrophic operational risk.
The Thinking
The intervention rejected the premise of a “bulk blast tool.” The Grove was architected specifically as a mini CRM and communications-control layer.
“Send the right message, to the right group, through the appropriate channel, with clear records and controls.”
Normalized Multi-Group Membership
A single member belongs naturally to multiple ministries (e.g. Choir, Youth Leader, Facilities Volunteer). Grouping must never duplicate records.
Decoupled Consent Hierarchy
Being a member of a ministry does not imply blanket consent for organizational broadcasts. Opt-in preferences sit independently alongside record entities.
Pre-Send Audience Verification
Staff must always visually inspect the exact list of recipients generated by a query filter before a message draft can transition to the approval queue.
Manual vs. API Structural Delineation
Distinguishing strictly between routine coordinator communications (handled by manual deep link/export) and formal institutional notifications (handled via Meta Cloud API).
The Solution
The Grove was implemented as a unified administrative platform, balancing intuitive record management for non-technical ministry leads with rigid backend governance rules.
Central Directory & Tagging
Canonical record store supporting cross-category tagging, household grouping, and active status tracking.
Granular Consent Log
Timestamped audit record of member communication preferences, opt-in origins, and channel-level restrictions.
Approval Routing Engine
Drafting interface requiring multi-tier admin review before dispatch authorization can be issued.
Cost Preview & Spend Ceilings
Real-time expenditure calculation per recipient cohort with automated hard stops preventing API budget overruns.
De-duplicated Export Flow
One-click formatted CSV and URL link generation for manual outreach, preventing spam-filter triggering.
Role-Based Access (JWT)
Strict segregation between view-only coordinators, group editors, and full financial/API super-administrators.
System & Tech Stack
React · Vite · TypeScript · Tailwind CSS
Component-driven operational views with responsive tabular data displays and query builder interfaces.
Node.js · Express · TypeScript
RESTful service core enforcing business rules, dispatch rate limiting, and audience exclusion logic.
PostgreSQL via Supabase
Relational schema enforcing foreign key integrity across member categories, consent histories, and audit records.
Admin / Super-Admin Workflow · JWT · bcrypt
Cryptographic credential handling with scoped permissions preventing unauthorized API triggers.
Meta WhatsApp Cloud API (Optional, Gated)
Isolated provider adapter with cost projection checks and delivery webhook listener.
Vercel (Client) · Fly.io (Backend Service)
Containerized deployment ensuring high availability and predictable request isolation.
Outcome & Significance
A Purpose-Built Internal System
The Grove successfully replaced chaotic, distributed personal phone lists with a disciplined, centralized member records system. By uniting multi-group categorization, explicit consent tracking, draft approval routing, and delivery traces into a single platform, the organization eliminated its risk of platform bans while significantly improving staff coordination clarity.
Identifying that a communication failure was fundamentally an entity-modeling and permissions deficit, and engineering a lightweight CRM rather than a brute-force messaging tool.
Structuring flexible relational data models that reflect real-world community dynamics without causing data fragmentation or duplicated records.
Embedding policy safeguards, financial spend ceilings, and multi-tier approval gates directly into the UI state transitions so governance cannot be bypassed.
Exercising strategic architectural restraint: recognizing where manual, human-mediated communication paths are safer and more effective than programmatic API broadcasts.