Lydia Ng
01 · Case Study / Systems & Governance

The Grove

Mini CRM & Member Communications System

System Type Community organisation CRM & control layer
Core Capabilities CRM-lite · Multi-group data · Segmentation · Gated workflows · Auditability
Repository Reference zephyr-scripts/the-grove-chat

“One member. Multiple groups. Clear communication rules and history.”

Governing Architectural Directive
System Topography

Communications Control & Verification Layer

Dual-dispatch routing topology separating permissive personal group workflows from API-driven broadcast pipelines.

STAGE 01 badge

Member Records

Normalized entity modeling with cross-cutting profile identities.

Primary Key Verified Phone
STAGE 02 category

Ministry Groups & Categories

Many-to-many group assignments with independent scope.

Role Tags Ministry ID
STAGE 03 filter_alt

Audience Segment Preview

Dynamic query execution calculating precise target sets prior to draft lock.

Deduped Query Exclusion Mask
verified_user Cross-Cutting Consent & Policy Interceptor
Checks opt-in flags, inactive states, and ministry-specific exclusions before passing to queue
lock_clock Stage 04: Control Gate

Message Planning & Admin Approval Queue

No outbound operation can occur without structured message body clearance, audience audit, and dual authorization for broadcast classes.

Queue Safety Enforcements • JWT Signed Admin Session • Cost Estimate Generated • Pre-send Recipient Snapshot
PATHWAY A Standard / Routine

Manual Export Send

Filtered, de-duplicated recipient list exported with one-click click-to-chat links for team leads. Eliminates platform broadcast flags completely.

Risk Profile: Zero Spam Risk CSV / Deep Link
PATHWAY B Hard Budget Capped

Gated WhatsApp Cloud API

Strictly gated programmatic delivery reserved for institutional emergencies. Pre-authenticated Meta templates with real-time monthly cost ceilings.

Hard Spend Ceiling Enforced Meta Official API
history_edu

Activity & Audit Log / Delivery Trace

Immutable event log tracking dispatch channel, authorizing user, recipient hash, and status codes.

Full Auditability
01 · Diagnosis

The Challenge

A church organization was confronted with severe operational disruption after its primary official WhatsApp communication number was flagged, reported, and permanently restricted by platform anti-spam algorithms.

The underlying failure was structural, not technical. Without an authoritative central member registry, multiple pastoral teams were running uncoordinated broadcast lists from personal and shared phones. Staff had no systematic way to verify:

Identity Deficit

Which physical member corresponded to which mobile record across fragmented volunteer address books.

Ministry Scoping

What specific ministries, cohorts, or services an individual member actually belonged to.

Consent Ambiguity

Whether express permission had been granted for recurring broadcast announcements.

Dispatch Obscurity

Who authorized specific messages, when they went out, and through which exact dispatch channel.

Treating bulk messaging as an automation problem without addressing data discipline and communication governance had created catastrophic operational risk.

02 · Strategy

The Thinking

The intervention rejected the premise of a “bulk blast tool.” The Grove was architected specifically as a mini CRM and communications-control layer.

Guiding Principle

“Send the right message, to the right group, through the appropriate channel, with clear records and controls.”

01

Normalized Multi-Group Membership

A single member belongs naturally to multiple ministries (e.g. Choir, Youth Leader, Facilities Volunteer). Grouping must never duplicate records.

02

Decoupled Consent Hierarchy

Being a member of a ministry does not imply blanket consent for organizational broadcasts. Opt-in preferences sit independently alongside record entities.

03

Pre-Send Audience Verification

Staff must always visually inspect the exact list of recipients generated by a query filter before a message draft can transition to the approval queue.

04

Manual vs. API Structural Delineation

Distinguishing strictly between routine coordinator communications (handled by manual deep link/export) and formal institutional notifications (handled via Meta Cloud API).

03 · Capabilities

The Solution

The Grove was implemented as a unified administrative platform, balancing intuitive record management for non-technical ministry leads with rigid backend governance rules.

contacts

Central Directory & Tagging

Canonical record store supporting cross-category tagging, household grouping, and active status tracking.

rule

Granular Consent Log

Timestamped audit record of member communication preferences, opt-in origins, and channel-level restrictions.

assignment_turned_in

Approval Routing Engine

Drafting interface requiring multi-tier admin review before dispatch authorization can be issued.

price_check

Cost Preview & Spend Ceilings

Real-time expenditure calculation per recipient cohort with automated hard stops preventing API budget overruns.

output

De-duplicated Export Flow

One-click formatted CSV and URL link generation for manual outreach, preventing spam-filter triggering.

security

Role-Based Access (JWT)

Strict segregation between view-only coordinators, group editors, and full financial/API super-administrators.

04 · Architecture

System & Tech Stack

Client Application

React · Vite · TypeScript · Tailwind CSS

Component-driven operational views with responsive tabular data displays and query builder interfaces.

Service Engine

Node.js · Express · TypeScript

RESTful service core enforcing business rules, dispatch rate limiting, and audience exclusion logic.

Data Layer

PostgreSQL via Supabase

Relational schema enforcing foreign key integrity across member categories, consent histories, and audit records.

Security & Auth

Admin / Super-Admin Workflow · JWT · bcrypt

Cryptographic credential handling with scoped permissions preventing unauthorized API triggers.

External API Gate

Meta WhatsApp Cloud API (Optional, Gated)

Isolated provider adapter with cost projection checks and delivery webhook listener.

Production Infrastructure

Vercel (Client) · Fly.io (Backend Service)

Containerized deployment ensuring high availability and predictable request isolation.

05 · Evaluation

Outcome & Significance

Operational Reality

A Purpose-Built Internal System

The Grove successfully replaced chaotic, distributed personal phone lists with a disciplined, centralized member records system. By uniting multi-group categorization, explicit consent tracking, draft approval routing, and delivery traces into a single platform, the organization eliminated its risk of platform bans while significantly improving staff coordination clarity.

What This Demonstrates
check_circle
Translating Human Coordination into Software

Identifying that a communication failure was fundamentally an entity-modeling and permissions deficit, and engineering a lightweight CRM rather than a brute-force messaging tool.

check_circle
Complex Many-to-Many Person Modeling

Structuring flexible relational data models that reflect real-world community dynamics without causing data fragmentation or duplicated records.

check_circle
Governance Designed Into Workflow

Embedding policy safeguards, financial spend ceilings, and multi-tier approval gates directly into the UI state transitions so governance cannot be bypassed.

check_circle
Knowing What NOT to Automate

Exercising strategic architectural restraint: recognizing where manual, human-mediated communication paths are safer and more effective than programmatic API broadcasts.