An AI agent you can
trust across every channel.
Mesh CRM answers grounded in your own documents, is honest when it isn't sure, and hands a teammate the mic before it ever guesses on something sensitive. Every tool it calls is gated by policy, every action is metered and audited, and no two businesses ever share a memory. Here is exactly what that gets you.
It answers from your documents — and shows its work.
Not a chatbot that improvises. A retrieval-first agent that pulls from your own material, prefers a citation to a guess, and stays honest about the edges of what it knows.
Retrieval before it answers
When a knowledge base is connected, the agent retrieves your source material first and answers from it — source-backed text is preferred over anything the model merely remembers.
Every answer cites its source
Replies carry the document and location they came from, so your team can trust an answer at a glance — and correct the source, not the prompt, when it's wrong.
Clarifies instead of guessing
When intent is ambiguous, the agent asks a clarifying question rather than assuming. A confident wrong answer is the one failure mode it's built to avoid.
A safe tool call over a hallucination
Given the choice between inventing an answer and looking one up through an allowed tool, it looks it up. Retrieved and user text stays untrusted until validated.
Do you deliver to Sylhet, and what's the return window?
Yes — we deliver to Sylhet in 2–3 business days. Returns are accepted within 14 days of delivery, unopened.
No matching source? It says so and asks — it does not fill the gap with a guess.
Your bot. Your rules. All of them.
The agent behaves exactly how you decide it should. Every control below is yours on every plan — there is no locked “advanced” tier holding your own prompt hostage.
System prompt
The real prompt, not a personality dropdown. Describe your business, fix its voice, and tell it what it must never say.
Model
Choose the model the agent runs on. Your business, your trade-off between speed and depth.
Temperature
Decide how adventurous it's allowed to be. Turn it down for policy questions, up for chat.
Escalation floor
The retrieval-confidence score below which it stops answering and fetches a human instead of guessing.
Sensitive keywords
Phrases that always mean a person: refunds, complaints, anything legal. Matched before the agent replies.
Tool budget
A hard cap on how many steps it may take in one run. It answers or hands off — it never loops forever.
Language
The language it replies in, set per business rather than guessed per message.
Handoff team
Which of your teams catches an escalation. Leave it on auto, or route it deliberately.
“Can you refund my last order to bKash instead of the card I used?”
Rafiq
Support · your team
It knows when to step back and pass the mic.
The safest thing an agent can do is recognize its own limits. When confidence drops or a request is sensitive, Mesh CRM escalates to your team — with everything they need to pick up mid-thread.
Escalates on low confidence or sensitivity
Uncertain, or a request that touches billing, refunds, or anything sensitive? The agent stops automating and raises a human instead of pressing on.
Full context carried across
Handoff lands in your team's shared inbox with the whole thread intact — no copy-paste, no lost history, no re-asking the customer.
Your people stay in control
The inbox is infrastructure for assignment; the conversation, its state, and the reply are always your team's to own.
Suspended or over quota, humans still reply
If automation is paused for billing or a plan limit, the human path stays open. Support-safe flows continue and history is preserved.
Your documents, made answerable.
Point the agent at what your business already knows. Ingestion is tenant-scoped and idempotent, every chunk keeps its source, and content is indexed so the right passage surfaces for the right conversation.
Tenant-scoped, never merged
Every chunk belongs to exactly one business. Content is never blended across tenants — isolation is enforced, not promised.
Idempotent ingestion
Re-ingest the same document and you get one clean copy, not duplicates. Uploads, URLs, and re-crawls stay safe to repeat.
Source metadata per chunk
Each chunk stores where it came from, so retrieval can cite it and you can trace any answer back to its origin.
Replaceable adapters
Ingestion and retrieval sit behind interfaces, so the storage and vector layers can change without touching the agent.
Indexed on the dimensions that matter
Documents are organized so retrieval stays precise — the right locale, the right channel, the right kind of content.
“Do you have this one?”
Customers rarely know the product name. They describe the thing, or they send a picture of it. The agent searches the product photos you uploaded and works from the closest matches — as a suggestion of what they might be holding, never as a confirmed identification.
Your photos, not a stock library
You upload your product images with a title, tags, and — when you want the answer tied to a document — the catalogue entry they belong to. A search only ever reaches your own images.
Describing it is enough
“The navy sneakers with the white sole” searches your product images on the customer's words alone. This half needs no photo and no switch — it runs on every plan.
Or they send the picture
The agent reads the photo first, then searches on the photo and the message together — so “do you have this in red?” is matched on the colour they asked for, not only on the shape they sent. Photo understanding is granted by every plan and switched on per workspace; the words-only half above needs nothing switched on at all.
A near-miss is not a match
A candidate reaches the agent only if it scores highly, or agrees with your own title and tags about what the thing actually is. Similar-looking-and-nothing-more is dropped before the agent ever sees it.
No confident match? It says so and asks, or fetches a person — it does not name a product to fill the silence. Price, stock, and policy still come from your documents, never from a lookalike.
It can act — but only where you allow it.
Three tools, and only three: it searches your knowledge base, it hands the conversation to a human, and it reaches your own systems over MCP. It never calls one unless the policy engine and your plan permit it — and it never decides billing, permissions, or platform state on its own.
Every tool call is checked against the policy engine, the tenant's entitlements, and the active plan before it runs. Requests the model has no business making simply never fire.
- Allowed by policy + plan, or it doesn't run
- The model never decides billing or permissions
- Model output is validated, never trusted as-is
Knowledge-base search
Retrieve from your own documents, scoped to your business and nothing else — the tool behind every grounded answer, with the source attached.
Handoff to a human
The agent can end its own turn and pass the conversation to your team, with the full thread intact. It calls this the moment confidence drops.
External data sources
Reach vendor systems over MCP — inventory, CRM, order status, and more — behind the same policy gate. You bring the server; the agent calls only what your plan and policy allow.
Metered per tenant. Nothing overstated.
Usage is measured in the backend, per business — the same numbers that enforce your plan limits are the ones you see. No inflated dashboards, no second set of figures.
Metered
Messages
Metered
Model tokens
Metered
Retrieval calls
Metered
Tool calls
Latency, end to end
Webhook, agent, tool, and handoff timings — so you can see where a conversation spends its seconds.
Routing confidence
How sure the agent was, and how often it fell back or escalated instead of answering.
Handoff rate
How much your team is pulled in — a direct read on where automation is and isn't carrying its weight.
Distinct channels. One grounded agent.
WhatsApp, Messenger, and Instagram are not interchangeable — each has its own message format, rate limits, and delivery rules. Mesh CRM treats every channel as its own thing, while the same grounded, audited agent answers across all of them.
Template messages, session windows, and delivery receipts — respected on their own terms, with rate limits honored.
Messenger
Rich replies inside the 24-hour window, with clean fallbacks when it closes. Its format, its constraints.
DMs and story replies treated as first-class conversations, held to Instagram's own limits — not an afterthought.
And the rest of the shop floor.
Meta is where most businesses start. It isn't where they stop — so your workspace runs the other channels your customers use, and gives your team the tools to work them.
What your team gets
- Shared inbox with assignment
- Private notes and mentions
- Saved replies and macros
- Labels and custom attributes
- Contact records
- Automation rules
- Satisfaction surveys
- Campaigns
- Help centre
- Reports
- Auto-resolve stale conversations
- API and webhooks
What we're building next.
Listed here so you can plan around them — not sold to you today. None of these is billed on any plan, and none will quietly appear in your invoice when it ships.
An agent that picks up the phone.
A separate voice service, built on the same grounded, auditable core: it answers from your knowledge base, and hands the call to a human the moment it's out of its depth.
Where is my order, answered from your store.
A direct read of order status and history from the store you actually run, so the agent answers from your system instead of your FAQ. The connector isn't built, so the agent says plainly that it can't see the order and passes it to your team.
The agent knows who it's talking to.
Pull a customer's record from your CRM mid-conversation, so an answer can account for their plan, their history, and what they bought last. Not connected to anything yet — today the agent knows only what's in the conversation and your knowledge base.
Book the slot, not just describe it.
Check a live calendar and hold, move, or cancel an appointment through the booking system your business already uses. Until it ships, a booking agent answers availability, hours, services, and policy from your knowledge base and hands the actual booking to a person.
Nothing raised in a chat gets lost.
Open and update a ticket in your tracker straight from the conversation. Not built — today the agent escalates to your team inside the shared inbox instead, with the full thread attached.
One agent that earns
a place on your inbox.
Grounded answers, clean handoff, policy-gated tools, and usage you can audit — connect a channel and see it work. Free for 14 days.
The comments under your posts are conversations too.
“Price?” “Delivery ki ache?” “Is this available?” — the same three questions, forever, under every post. The agent answers them publicly from your own documents, and stops to ask you whenever it isn't certain enough to speak for you.
Early access: Meta grants an app public Page access only after Advanced Access review, which this one does not hold yet. Until it does we connect Pages by hand — ask us and we'll add yours.
Received
A comment lands on one of your Facebook posts and is captured with its post, author, and text.
Decided
The agent reads it against your knowledge base and your rules, and decides whether it can answer it at all.
Held for approval
Anything low-confidence or sensitive stops here and waits in a queue for a person to approve, edit, or drop.
Actioned
The reply is posted publicly — or deliberately ignored. Either way the outcome is recorded against the comment.
Nothing is posted in your name that your rules didn't allow.