A building block

A little help. A clear record.

dyna.ai - Share a call experience

Build a bot. Agree its boundaries. Follow the evidence.

Your organisation. Your operating rules. Build lending and servicing workflows with reviewed policies, controlled access and a record of the decisions behind the work.

Sharing a completed public voice experience

A visitor can create a no-login review link after an actual carrier-bound conversation has ended. Creating the link requires the original experience session token and explicit sharing permission. Opening the preview does not publish anything.

Choose what to share

The preview contains allowlisted example settings. It excludes the visitor name, phone number, email, actual location, free instructions, account references and call permissions. Bounded numbers and predefined choices remain available, including the fictional scenario clock.

Transcript and business-summary sharing are optional and selected together. Actual speech and reported facts can contain names, contact information or information about other people. They are not automatically redacted. Review the complete preview and obtain the permission needed to share its contents. Generated speech does not establish what the recipient heard or prove a completed external action.

Recording sharing is a separate choice with a separate sharing permission. Audio is unredacted. A recording is available only when the original recording permission, signed native recording authorisation and completed provider receipt match the exact call. Selecting recording permission during the call does not automatically publish a recording.

The published snapshot is frozen. New transcript events or changed recording metadata require a new preview before a new link can be created. Current playback availability can change if source audio is removed or its permission is withdrawn.

Anyone with the review link can view its selected contents without an account. Keep the token in the URL fragment, never a query string. The website sends it only in POST bodies. Treat the link as access to the review.

Links expire after at most 30 days and sooner when a known source-retention deadline applies. Every read checks the original call binding and source availability. Sharing does not extend source retention. Private source bindings are checked in batches on each read. Erased or revised transcript events and captured facts make the frozen review unavailable. An owner can list and revoke links using the original session token, including after the call session expires. Create and preview are available until one hour after the original experience expiry.

Revocation blocks subsequent reads and audio requests and immediately erases the shared snapshot and private source bindings. An internal daily retention task also erases expired reviews and reviews whose source evidence has been removed or revised. It preserves minimal consent, hash and revocation metadata for audit, and does not delete or change the original call. It cannot recall content that someone has already viewed, downloaded, copied or recorded.

The sharing service stores token hashes, frozen snapshots, consent receipts and revocation metadata in the private Public Demonstration Share DocType. No guest resource-API permissions are granted. The DocType must be migrated before these endpoints are enabled.

Guest POST API

All methods use /api/method/dyna_control.public_demo_shares.<method> with a JSON request body. Successful JSON responses use Frappe's message envelope. Errors expose a bounded public_error message. Responses use private/no-store, no-referrer, noindex and nosniff headers.

Method Request Result
preview session_token, boolean include_transcript, boolean include_recording snapshot, preview_digest, sharing_notice, recording_notice, recording availability
create Preview choices, session_token, stable request_id, preview_digest, sharing_consent: {granted: true, version} and separate recording_sharing_consent if audio is selected share_id, share_token, Unix expires_at, frozen snapshot, replayed
read share_token Frozen snapshot, Unix expires_at, current recording availability
ownerlist session_token Owner share IDs, UTC ISO creation times, Unix expiry, revocation state and inclusion choices. No share tokens
revoke session_token, share_id revoked: true
audio share_token Audio bytes for a permitted shared recording

Use notice versions returned by the preview. Boolean choices must be JSON booleans. The service rejects a changed preview digest. Repeating the same creation request and choices returns the same link. Reusing a request identifier with different choices fails.

A version 1 snapshot has schema_version, setup, friendly voice_name and language_name when known, transcript, summary, recording and inclusions. Transcript entries contain speaker and text. No timing alignment is implied. Summary uses the existing business-summary statistics, performance, compliance and next-action fields. Summary and transcript are empty when speech sharing is not selected.

Render all strings as text, never as HTML. The snapshot contains no owner session token, provider URL, provider account identifier, audit reference or recording credential.

Audio bounds

Audio is fetched through the server using fixed, verified provider account, call and recording bindings. Provider redirects are rejected. The service does not return a direct provider URL. Each request checks consent and revocation again after download, before returning bytes.

Public playback is limited to 20 MB, a 45-second streaming deadline and one simultaneous download per call. Provider metadata and connection operations also have bounded timeouts. Audio requests are limited to 12 per IP per minute. Other review operations are limited to 60 per IP per minute, and each experience can create at most 20 links. Playback uses a POST-to-blob request, without range streaming in this version.