Skip to content
All posts

August 30, 2026 / 6 min read

Sending WhatsApp templates from a CRM: the approval flow, end to end

Every WhatsApp integration we ship, from Pipedrive deal updates to full campaign engines, runs into the same three constraints. They are not hard, but they are unforgiving, and they surprise developers coming from email or SMS.

Templates are pre-approved, not sent ad hoc

Outside a narrow customer service window, every business message on WhatsApp must use a template that Meta has approved in advance. A template is a rigid structure: fixed text with numbered placeholders, plus optional headers, footers, and buttons.

{
  "name": "appointment_reminder",
  "language": { "code": "en" },
  "category": "UTILITY",
  "components": [
    {
      "type": "BODY",
      "text": "Hi {{1}}, this is a reminder for your {{2}} on {{3}}. Reply CONFIRM to keep the slot or RESCHEDULE to move it."
    }
  ]
}

The approval review checks category fit (utility, authentication, or marketing), variable count, and content policy. Marketing templates face the strictest review. Plan for rejections on the first submission of anything promotional, and design your workflow so the template name is a configuration value, not a string baked into a cron job.

The 24-hour customer service window

When a user messages your business number, a 24-hour window opens. Inside it, you can send free-form messages without templates. Outside it, only approved templates go through. This is why two-way CRM conversations need both paths: free-form replies when the customer is active, and a template fallback when a rep answers late.

The failure mode is predictable: a sales rep opens a chat from last week, types a reply, and the API rejects it. A good integration surfaces the window state on the conversation, so the rep knows before typing whether the reply must go through a template.

Consent and opt-out live on your side

WhatsApp's policy expects the business to hold proof of opt-in before messaging a customer, and every marketing template needs a working opt-out. The platform enforces consequences (quality rating, messaging limits), but the consent record is your system's job. When we build the CRM side, we store the opt-in source and timestamp on the contact, and treat the absence of that record as a hard block on campaign sends.

That is the whole game, really: template discipline, window awareness, and a real consent record. Get those three right and the rest of a WhatsApp integration is ordinary engineering.