ORF-R-2026-006·Preview Project

A WhatsApp assistant that runs the studio’s front desk: one number serving a lead and the founders, that briefs them the moment a booking lands

Premise

Can one markdown-conductor agent staff a studio’s front desk on WhatsApp: hold real Q&A and a booking conversation with a lead, write to the founders’ real calendar behind code rather than prompt hope, and the instant a booking lands turn around and brief the founders, all through a single business number serving two roles?

Finding

Yes, and the proof is felt rather than asserted: the moment a lead confirms, the founders’ screen fills with a booking brief, a tappable calendar link, and a ready welcome draft, while every consequential write sits behind a structural gate the model cannot talk past, not a prompt it might forget.

June 2026 · internal research preview · sealed

Orfloat’s own front desk is a WhatsApp assistant. It answers a prospect’s questions, runs the booking conversation, and writes to the founders’ real calendar, all through one business number. The recording below is one continuous take of two phones at once: a lead on the left, the studio on the right.

Lead
Studio
Transcript / recorded demo, verbatim
[two phones, recorded at once and played in step. left, the lead’s phone in light theme, the chat titled “Orfloat Applied-AI”. right, the studio’s phone in dark theme, the chat titled “Orfloat Assistant”. the studio’s screen stays idle through the whole conversation, until the booking lands.] lead Hello agent Welcome to Orfloat! I’m the studio’s assistant, built on Anthropic’s Claude. What brought you here? lead What does Orfloat do exactly? agent Orfloat is a forward-deployed applied-AI engineering lab. We embed inside a business, learn the work end to end, and ship AI systems built on Claude. Not consulting from a distance, and no agents without evals. Based in Muscat, working with founder-run and family-led businesses across Oman and the GCC. Want the longer version, or shall I map it to your business? lead Okay, I run a freight forwarding and distribution business. It’s ours here in Oman. Fleet, warehouses, customs clearance etc, a lot of moving parts. I want to understand where AI integration genuinely fits? agent A lot of that lands in what we call internal operations: demand forecasting, reorder triggers, scheduling, and daily operational briefings that pull from the systems you already run, MCP-first so the integration is a contract, not a brittle scrape. Customs paperwork intake can fit too. Where does it bite most right now: fleet utilisation, warehouse stock, or the customs clearance paperwork? lead Coordination mostly is the bottleneck, everything happens on WhatsApp and paperwork eats hours every day agent That’s the pattern we see most. Coordination living in WhatsApp is workable: an agent can sit in those threads, hold your brand voice, and turn the back-and-forth into structured actions. Paperwork that eats hours is exactly where document intake earns its place. If it helps to go deeper, I can set up a 30-minute intro with the founders. No obligation. One note: it’s currently outside their hours, Sun to Thu, 9 to 5 Muscat, so I’d book it for when they’re back. Want me to find a time? lead Can you give me a ballpark figure for how much this integration will cost? agent Honest answer: Orfloat doesn’t publish pricing, and I won’t invent a number, that wouldn’t be fair to you. Every engagement is scoped from what an on-site discovery finds. That’s exactly the founders conversation. Shall I get that intro on the books? lead Yeah okay book an intro agent Good. So we’re framing this around AI for your freight and distribution operation, mainly the WhatsApp-based coordination and the paperwork load. Anything to add before I set it up? lead This is fine proceed agent What’s your name? lead Shaikh agent Thanks Shaikh. And the company? lead Shaikh Enterprises agent What’s the best email for the calendar invite? lead niotebook@gmail.com agent How would you like to meet: phone, video, or in person? lead Video call agent Noted, video. I’ll put a Google Meet link on the invite. Checking founders’ availability now, one moment. agent Tue, 16 Jun · 11:00 Muscat Wed, 17 Jun · 14:00 Muscat Thu, 18 Jun · 10:00 Muscat Which suits? Or tell me a window and I’ll find something close. lead Tuesday 11am agent To confirm: – Meeting: Shaikh / Shaikh Enterprises with the founders – Purpose: AI for freight and distribution, WhatsApp coordination and paperwork load – When: Tuesday, 16 Jun 2026 · 11:00 Muscat · 30 min – Modality: Video (Google Meet) – Invite to: niotebook@gmail.com Shall I lock it in? lead Yes lock it pls agent Booking that in now. agent All set. The invite is on its way to niotebook@gmail.com, with the Meet link on it. Talk on Tuesday. lead Thank you got it [the signature moment. the instant the lead confirms, the studio’s phone, idle until now, fills: a calendar invitation banner reading “[ORF] Intro: Shaikh (Shaikh Enterprises) · Video”, then the agent’s post-booking brief.] ▸ studio New booking confirmed Lead: Shaikh · Shaikh Enterprises Purpose: AI for freight and distribution, WhatsApp coordination and paperwork load When: Tue, 16 Jun · 11:00 Muscat · 30 min Modality: Video (Google Meet) Contact: niotebook@gmail.com Open in Calendar: google.com/calendar/event?eid=… Welcome-email draft is in the studio Gmail Drafts.
Figure 1. the recorded demo, two phones played as one: left, the lead’s phone (light); right, the studio’s (dark). The signature moment, the instant the lead confirms and the studio’s screen fills, stays in step.

One number, two roles

The number is one WhatsApp business line, and it answers to two people at once: the lead who messages in, and the studio (the two founders) on the other side of the same number. The agent never sees a phone number. A thin channel server resolves every inbound message to a role and a number-free alias before the model reads a word, and the real numbers never leave the server’s environment.

The two roles are not the same conversation. The studio sees its own calendar, titles and all. The lead, when a proposed time turns out to be taken, is told only that there is a conflict, never whose. The boundary is not a request in the prompt; it is where the channel sits, between the people and the model.

The moment the studio runs itself

This is the whole point, and the demo shows it in one beat. The instant the lead says yes, three things land together. The booking becomes a real calendar event, prefixed [ORF] and carrying a Google Meet link. A brief arrives on the studio’s phone: who booked, for what, when, and a calendar link the founders can tap. And a welcome email sits written and waiting in the studio’s Gmail drafts, composed but never sent.

The founders did nothing, and the studio briefed itself. That is the feeling the preview is built to produce, and it is why the demo is two screens rather than one: the left phone is the work, the right phone is the result arriving on its own. The calendar event is the source of truth, so a brief that fails to send or a draft that fails to write can never unwind a booking that already happened.

The brain is a markdown program

There is almost no application code. The brain is a local Claude Code session, and no Anthropic API is called: the session is the agent. A single CLAUDE.md conducts it, routing on the role and the intent to the files it needs and reading them only when it needs them: seven flows, five context files, and five files of voice. The program is the markdown.

The code is the channel. Two small servers run beside the session: one speaks WhatsApp’s Cloud API and resolves identity, and one holds the calendar and the inbox. Everything a visitor would call the product’s behaviour (the answers, the judgement, the booking conversation) lives in prose the founders wrote and can read, not in a codebase they would have to trust on faith.

The boring parts, enforced in code

The safety here is not asked for in the prompt, where a model can forget it. It is built into the tools, where it cannot. Every event the agent creates must start with [ORF], enforced in the server and backed by a hook; an event that is not [ORF], one of the founders’ own, the agent cannot move or delete. Before it writes a booking, it re-reads the calendar and re-checks the slot. And the Gmail tools are create-draft and delete-draft and nothing else. There is no send. Of the eight Google tools the model can reach, not one can put a message into the world.

Above all of it sits the oldest gate of all: a read-back and an explicit yes before any write. You can watch the agent hold a softer line too, in the moment the lead asks for a price: it declines to invent a number, says so plainly, and routes to the discovery conversation instead. The booking is gated by code; the restraint is gated by character. The preview leans on both.

Drawn as one picture, the whole preview is a short pipeline: a number, a channel that turns identity into a role, one shared session that does the thinking, and one server where every write is gated.

One WhatsApp number one business line · two roles Channel resolves identity → a role, never a phone number lead studio One Claude Code session a CLAUDE.md conductor routes on role + intent · the brain 7 flows 5 context 5 voice google MCP server 8 tools · 6 calendar · 2 gmail-draft · zero send [ORF] prefix re-check slot no send to the lead answers & the booking to the studio brief, link & draft
Figure 2. the preview’s shape: one number, one channel that resolves identity before the model reads a word, one shared session whose program is markdown, and one server where every consequential write is gated in code. The same single session answers both roles.

Talking to the proof

This assistant did not appear from nothing. It is the successor of an earlier WhatsApp demo built for a marketing principal, the same architecture with the context and the character swapped out. And it is the working proof of the appointment-agent case study: the shape that piece describes (a Claude Code session serving a principal and their leads through one number, every calendar write behind a hard gate and a read-back) is exactly this.

It is a sibling, too, of the voice agent. Different channel, a phone call rather than a chat thread, but the same conviction underneath: the consequential actions belong behind code, and the model is trusted with the conversation, not the keys.

Where this honestly stands

What this is not, yet. It serves one shared founders’ number, not a fleet of them. It answers an allowlist, not open intake, so a stranger does not reach the founders by guessing the line. WhatsApp’s 24-hour session window bounds how the agent can reach back out on its own. The deployment is private.

And the lead in the recording is a fictional persona, booked into a real calendar with a burner address: the flow is real, the prospect is not. None of this is hidden. It is the honest edge of an internal preview, shown so the working part can be believed.

The smallest unit that works

The preview is exactly that, a preview, and it is also something more precise: the smallest unit of the thing we are really building. One number, one session, two roles, every consequential write held in code. It settles the first question end to end, on real infrastructure, against a real calendar. A demo that books a real meeting outweighs a paragraph claiming one could.

But a unit is not a system, and the very shape that makes the preview legible is the shape that does not scale. One shared session is one context window and one transcript. It holds a single conversation beautifully. Ask it to hold a hundred leads at once and the seams open: the conversations crowd the same context, the transcript that is its only memory grows until it has to be compacted, two leads who arrive in the same second contend for one brain, and a single crash takes every conversation with it.

None of that is a fault in the preview. It is the definition of a unit. The preview answers “does the conviction hold?” The production question is different: what carries that conviction to many businesses and many thousands of leads without the founders touching it? That is not a longer prompt. It is a different harness.

The production shape: sessions, memory, dreaming

We argued the general case already, in the harness is the half you own: an agent is a model plus a harness, and the harness is the only half you build. A production harness needs three things the unit fakes with a single session: isolation between conversations, memory that persists outside any one of them, and a way to get sharper between conversations rather than only within them.

Memory real-time, as sessions run Dreaming between sessions lead-1 sess_a17c lead-2 sess_b04e ··· lead-N sess_f9d1 one isolated, resumable session per lead memory store shared, file-addressed read-only read-write studio.md leads/lead-1.md bookings.md optimistic concurrency, versioned & attributed session transcripts 1 to 100 past sessions dreaming verify · organise · enrich out-of-band, between sessions store + transcripts in, curated out
Figure 3. the production memory system. One isolated, resumable session per lead, each reading and writing a shared store in real time; a dreaming process runs out of band between sessions, returning a curated store so the next sessions start sharper.

The shape is the same conviction wearing different primitives. Identity still belongs to the channel. Consequential writes still sit behind code, and the platform agrees: its own guidance is to denylist destructive tools and keep a human confirmation step before any state change, the gated calendar write and the read-back restated as a platform default.

This is not a single-vendor story. The same shape is forming on the other side of the frontier: OpenAI’s Agents SDK gives agents, handoffs between specialists, guardrails, and sessions that manage history with compaction for long runs. Two labs, one direction. The model is the bought half, and the harness is the half a builder owns.

What transfers

The lesson is portable, and it is not about WhatsApp. An agent can be handed consequential writes (a real calendar, a real inbox) the moment its guardrails live in code rather than in a prompt it might forget. Identity belongs to the channel, not the model, so the agent works in roles and never holds a number. And what earns trust is not a claim of capability but a felt result: the studio briefing itself the instant a booking lands. Build that, and the demo does the arguing.

References

  1. Meta for Developers. WhatsApp Cloud API. accessed 4 Aug 2026. developers.facebook.com/docs/whatsapp/cloud-api
  2. Google for Developers. Google Calendar API and Gmail API. accessed 4 Aug 2026. developers.google.com/calendar/api
  3. Model Context Protocol. Specification and documentation. accessed 4 Aug 2026. modelcontextprotocol.io
  4. Anthropic. Claude Code and Claude Agent SDK. accessed 4 Aug 2026. anthropic.com/claude-code
  5. Anthropic. Claude managed agents: memory stores and dreaming. accessed 4 Aug 2026. platform.claude.com/docs/en/managed-agents
  6. OpenAI. OpenAI Agents SDK. accessed 4 Aug 2026. developers.openai.com/api/docs/guides/agents