A building block

A little help. A clear record.

dyna.ai - Administrator guide

Build a bot. Agree its boundaries. Follow the evidence.

Your organisation. Your operating rules. Build lending and servicing workflows with reviewed policies, controlled access and a record of the decisions behind the work.

Administrator guide

Accounts and roles

Provision named Frappe users and assign the minimum business roles needed. Open Administration → Users and access → Capability grants to inspect effective capabilities. An administrator manages configuration. Policy authorship, review, publication and campaign release use their separate business roles.

Keep service accounts separate from people. Give each connector its own credential. Store API secrets in the deployment's secret configuration and rotate them when ownership changes. Never put a service key in the public website or a bot prompt.

A role change can remove access to calls, recordings and workflow actions. Test the affected account after the change. Existing browser screens may retain information already displayed, so require sign-out when retiring an account.

Tenant boundaries

Provision each organisation as a separate Frappe site with its own database, site configuration, credentials, private files and runtime state. Route its hostname to that site. Bind runtime credentials and signed conversation envelopes to that exact tenant. A user-entered tenant field does not grant cross-organisation access.

Use separate provider credentials or explicitly allocated provider subaccounts where the provider supports them. Configure caller IDs and destination permissions for the intended organisation. Test a wrong-tenant request and a revoked-account request before opening a new tenant to users.

Providers and budgets

Configure the telephony account, callback verification, speech providers and language-model credentials on the server. Expose only configured voice and model choices in the agent editor. A saved configuration is not proof of a connected provider.

Keep development spend and public traffic allocations separate. Configure approved limits and verified owned destinations for development tests. Public calling needs its own configured allocation and admission path. Do not replace unknown usage with zero. Reconcile carrier operations before attempting a replacement call.

Deployment and recovery

Build immutable application and runtime images. Keep the previous compose configuration and image references. Back up the Frappe database, private files, encrypted site configuration and durable runtime databases before a schema migration. Verify that the backup can be restored to an isolated environment.

Migrate the intended site, clear its cache, synchronise scheduled jobs and check worker health. Test login with an ordinary account. Check read denial, a representative write, queued work and a real provider response. A successful HTTP health check does not establish workflow acceptance.

Recording review

Use the call-review guide for recording retrieval, alignment configuration and private cache retention. The worker needs the same approved recording-source access as the web backend. Alignment is a separate explicit action that sends authorised audio and transcript text to the configured processor.