Workflow ideas
Building a WhatsApp → CRM workflow for a Singapore SME
A worked WhatsApp-to-CRM design for a Singapore SME: verified webhooks, contact matching, lead ownership, messaging rules and recovery tests.
By Automate HQ · Updated · 5 min read

At a glance
A useful WhatsApp-to-CRM workflow turns an inbound enquiry into an identifiable contact, a follow-up task and a named owner. Verify the webhook, store the event durably and prevent duplicate actions before adding AI. Keep customer messaging rules separate from CRM automation and test the handoff when either service is unavailable.
- 01Verify and queue
- 02Match the contact
- 03Assign follow-up
- 04Track the outcome
Start with one enquiry and one owner
This is an illustrative implementation design for a Singapore service business, not a completed client project. Imagine an enquiry asking for a maintenance appointment. The desired outcome is a contact linked to the request, an assigned employee and a follow-up deadline. Sending an instant reply alone does not establish any of those outcomes.
Use the official WhatsApp Business Platform or an appropriate provider integration, a verified webhook receiver, a durable event store and the CRM API. n8n can coordinate the steps. Confirm account access and the API features available to your business before choosing a deployment design.
Verify the event before it becomes a lead
Implement the provider's webhook verification and payload-signature checks. Meta publishes a signature-validation example for Cloud API webhook payloads. Preserve the raw request bytes for signature checking; a parsed and re-serialized JSON body may differ from the signed bytes.
After validation, durably record the event before acknowledging successful receipt. Keep the receiver fast and process CRM work asynchronously. Distinguish inbound customer messages from delivery-status events so a status update does not create a new lead. Handle every relevant item in a batched payload.
Use a stable message identity scoped to the business account for duplicate detection. A unique constraint should stop two workers from processing the same action concurrently. Keep a separate completion record for contact updates, tasks and outbound replies because one may succeed while another fails.
Map identity without inventing an email address
Maintain a mapping between the channel sender identifier and the CRM record ID. Normalize phone numbers only when you have enough information; do not assume every enquiry uses Singapore's country code. A shared business phone also does not necessarily identify one individual.
If using HubSpot, inspect the contact API requirements and your configured properties. HubSpot supports contact retrieval using record ID or email and documents custom unique identifiers for relevant batch operations. An ordinary phone property is not automatically a unique upsert identifier. Do not fabricate an email address to make the integration pass validation.
When several existing contacts match, hold the enquiry for review. Where supported, use a custom unique external identifier; otherwise use a durable mapping and serialize record creation for the same sender. Preserve known CRM values instead of overwriting them with missing message data.
| Field | Source | Purpose |
|---|---|---|
| Event identity | Verified webhook | Prevent repeated processing |
| Channel sender / CRM ID | Validated mapping | Attach enquiry to the right record |
| Request summary and source reference | Customer message | Give the owner context |
| Owner and due time | Business routing rules | Make follow-up accountable |
| Messaging permission and opt-out state | Recorded customer choice | Control permitted outbound contact |
| Processing state and external IDs | Execution ledger | Support reconciliation and recovery |
Route work using Singapore business hours
Store event timestamps consistently and calculate working deadlines using Asia/Singapore. Define what happens after hours, on holidays and when the assigned employee is unavailable. If a Thailand team handles the queue, display the deadline with its timezone rather than relying on each person's laptop settings.
Create a task associated with the contact and request. Start with deterministic routing, such as service type or territory. If AI summarizes free text, retain a reference to the original message and treat the summary as a draft. Do not let the summary invent a confirmed appointment, price or service commitment.
A CRM task does not grant permission to send messages
WhatsApp's Business Messaging Policy allows free-form replies during the 24-hour customer service window opened or reset by a user message. Outside that window, messages require approved templates. The policy also requires opt-in for subsequent contact and respect for opt-out requests. Check the current policy when implementing.
Before each outbound send, evaluate the current window, message purpose, template availability and recorded permission. A queued reply may have become ineligible while the CRM was down. Provide a clear path to a person and avoid treating an enquiry as unlimited permission for marketing.
Sources: WhatsApp: Business Messaging Policy
Test whether the handoff survives failure
Replay the same message, send two messages from one new contact at once and simulate a CRM timeout after record creation. The acceptance condition is one intended contact and one task per defined enquiry, or an explicit review item when identity is uncertain. Check the destination before retrying uncertain writes.
Test an after-hours message, an opt-out, an expired messaging window and a request with no usable contact name. Review received enquiries against completed handoffs and unresolved exceptions. Start with a limited queue and staff-reviewed replies; add AI only if it reduces the work needed to classify or summarize requests.