Boni
Boni
Browse documentation
Bow Chat·guide·Version 1

Customer access and recovery

How a customer opens their room, installs it as an app, and gets back in later — and how to treat access links safely.

How a customer gets in

Create an access link from the room, then send it to the customer through whichever channel you already use — WhatsApp, email, or SMS.

When the customer opens the link they see a confirmation page and tap to open their room. Only that tap signs them in. This matters: chat apps and mail scanners fetch links in the background to build previews, and a link that signed you in on the fetch alone would be spent before the customer ever tapped it.

After that, the device holds a room session and goes straight into the room on later visits.

Installing the room

Supported browsers offer to install the room as an app on a phone or desktop. Once installed, the customer opens it like any other app and lands back in their authenticated room.

Two things worth telling customers:

  • On Android the phone decides where the installed app is placed. If it is not on the home screen, it is in the app drawer or app search under the room's name.
  • Installing is not the same as turning on notifications. Notifications need a separate, explicit permission — see Notifications and escalation.

Getting back in later

In order of least friction:

  1. Open the installed app. It restores the room from the saved session.
  2. Tap the original link again. It stays valid for a year and can be used more than once, including on a new device.
  3. Ask your team for a fresh link. Staff can generate one against the email or phone already on the customer's contact record.

This is what makes "send the link once" workable in practice. A customer who lost the message six weeks ago is not locked out.

The trade-off of a durable, reusable link is that whoever holds it can open that room as that customer. So:

  • Send it to the specific person, on a channel you already use with them.
  • Do not post it in a group, a shared mailbox, or a public thread.
  • If a link reaches the wrong person, tell your Boni contact so access can be dealt with.
  • Never put a link in a document, invoice, or QR code that circulates beyond the customer.

Planned change: a permanent room address

Today's link is durable enough for a controlled rollout but it is not the final design. The planned contract is a stable, non-guessable room address that carries no credential in it: a returning device with a valid session opens directly, and a new or expired device verifies an approved phone or email before anything about the room is shown. Revoking a device or replacing a phone will not change the customer-facing address.

Until that ships, use the guidance above. This page will be updated when the permanent address is live.

What to tell customers

Keep the invitation short and concrete. A message that works:

Here is your private room with our team. Everything about your job — updates, documents, and what happens next — will be there. Open it once and install it, and you can come back to the same place any time.

Do not promise permanent storage of messages or files. Retention is set by your agreement, and a room address outliving a subscription is not the same as unlimited history.