All articles
By Carlos García Updated 9 min read

Messaging guardrails for a WhatsApp sales agent: when not to quote

Messaging guardrails for a WhatsApp sales agent: when not to quote

Summary: A sales agent can sound fluent and still damage an opportunity by quoting before it understands the request or revealing a negotiated rate out of context. The rule should not be “discuss price” or “never discuss price.” It should depend on segment, available information, and authority. For SMB inbound, the agent confirms the need and the relevant paid service before sharing an approved price. For mid-market and enterprise, it qualifies the opportunity and hands the close to a person. For partners, it may automate up to contact and scheduling, while a person owns the proposal. Before production, the team turns real conversations into allowed, prohibited, and escalation messages, then tests them in a simulation with edge cases.

A WhatsApp agent can reply quickly, use the right tone, and log every interaction. That does not mean it is making sound commercial decisions. If it sends a number too early, the buyer may compare it with a different service. If it exposes the structure reserved for partners, it may weaken an agreement. If it promises a condition that depends on scope, it turns discovery into a commitment.

A vague instruction such as “do not hallucinate prices” does not solve this problem. A number may exist and be accurate while still being inappropriate for that contact, moment, or channel. The guardrail must control when, to whom, and with what context a commercial message may appear.

These are field notes for designing that boundary. The copilot or autopilot framework helps assign approval to actions. The guide to one WhatsApp number per business line covers channel separation. This note focuses on the next layer: what the agent may say once the conversation has reached the correct route.

Commercial policy comes before the prompt

A policy an agent can use must turn team judgment into observable conditions. “Large customer,” “special price,” or “interesting opportunity” are not enough when each salesperson interprets them differently.

For every sensitive message, document five elements:

  1. Population: segment, relationship type, and territory where it applies.
  2. Minimum context: facts that must be confirmed before replying.
  3. Allowed content: what the agent may state, from which source, and for how long.
  4. Stop condition: the question or exception that blocks automatic sending.
  5. Next step: who receives the case, what information they need, and what the contact may be told in the meantime.

That rule can be tested. “Use good commercial judgment” cannot.

An initial matrix by segment

The same question—“How much does it cost?”—should not trigger the same response on every route.

SegmentWhat the agent may doWhen it does not quoteExpected outcome
SMB inboundUnderstand the need, confirm the relevant paid service, and use a public or approved rateMinimum context is missing, the contact is mixing up services, asks for a nonstandard condition, or the source has expiredApproved answer or a short context question; escalation when the case falls outside policy
Mid-market / enterpriseQualify size, complexity, systems involved, stakeholders, and horizon; provide general informationPrice depends on scope, integration, security, procurement, or negotiationHuman handoff for discovery, proposal, and close, with a summary and next step
PartnersIdentify partner type, validate the relationship and need, locate the responsible contact, and scheduleThey request a negotiated rate, margin, discount, revenue split, territorial exception, or agreement termsConfirmed contact or meeting; proposal and terms issued by an authorized person

For SMB inbound, “confirm the paid service” prevents the agent from quoting implementation when the person is asking about support, or presenting a free option as if it covered the requested work. The prior question should be short and necessary, not a disguised form.

For mid-market and enterprise, the agent’s goal is not to close in chat. It reduces ambiguity and delivers a usable conversation: problem, preliminary scope, stakeholders, known constraints, and next step. A person owns the proposal because it combines variables the agent should not infer in WhatsApp.

For partners, even confirming that a special structure exists may be sensitive. The agent neither confirms nor denies terms. It verifies the relationship against an authorized source, finds the owner, and helps schedule the conversation.

Three message classes

Do not hide the entire policy inside a long prompt. Maintain a versioned catalog with three classes for each segment and intent.

Allowed

The agent may send the message after it satisfies machine-checkable conditions.

“To point you in the right direction, are you looking for a standard solution or do you need to connect it with other systems?”

“I can help identify the right option. Before discussing price, I need to confirm which service you want to cover.”

The catalog should name the allowed variables, the source that fills them, and the message’s validity period. If it includes a range, it must define the segment, currency, inclusions, exclusions, and review date.

Prohibited

The agent does not send the message, even if it finds similar wording in historical conversations.

“We offer other partners this rate.”

“We can definitely keep that price even though the scope is not defined yet.”

“This is our internal cost, and we apply the margin on top.”

The prohibited list covers acts as well as phrases: disclosing another account’s condition, inventing a discount, comparing agreements, promising validity, or exposing a reserved price structure. It must also cover paraphrases. Blocking an exact sentence does not prevent a model from expressing the same information in different words.

Escalation

The agent acknowledges the request without deciding what it is not authorized to decide.

“I understand that you need a reference to move forward. The proposal depends on scope, and I do not want to give you a number that later proves inaccurate. I will prepare the case so a person can review it with you.”

A complete escalation preserves the detected segment, confirmed facts, literal question, rule triggered, and owner. It gives the contact a concrete next step and saves sales from rereading the entire chat.

Build the lists from real conversations

Historical conversations provide evidence of situations. They are not a repository for copying replies or permission to reuse personal data. Work with an authorized, minimized, and de-identified sample.

  1. Select contrasting outcomes. Include conversations that moved forward clearly and others that caused corrections, false expectations, or a late escalation. Do not choose only the best chats.
  2. Mark the decision point. Record what the team knew when the question appeared, what was missing, and which message changed the direction. The goal is not to score the salesperson’s style.
  3. Extract the pattern, not the wording. Turn “this sentence worked” into a reusable condition: ask for the variable that separates two services before showing a rate.
  4. Assign a class. Allowed, prohibited, or escalation. Add segment, intent, source, owner, and review date.
  5. Look for contradictions. If two experienced people resolve the same case differently, there is no automation rule yet. The commercial owner must decide it.
  6. Write variants. Test direct, ambiguous, persistent, and colloquial versions of the same question. The control should survive a paraphrase.

The evaluation system does not need raw chat dumps. Keep synthetic or de-identified cases with the minimum facts needed to trigger a decision. Access to the original material, its retention, and its use in evaluation must follow the applicable internal policy.

Run a simulation before go-live

A spreadsheet review finds inconsistencies. A simulation shows what happens when someone insists, changes the subject, or provides information in an unexpected order.

Who participates

  • the commercial owner who can decide policy
  • an SMB or inbound salesperson
  • someone who manages complex accounts or partners
  • operations, which knows routing, scheduling, and response expectations
  • the person implementing the agent and its validations
  • someone responsible for recording decisions, failures, and version changes

If privacy, security, or compliance constrains the use of data or the channel, include the relevant owner for those cases. The session does not need to become a standing committee, but someone able to resolve an ambiguous rule must be present.

Which cases to role-play

Prepare cards with segment, known state, incoming message, and authorized outcome. Include at least:

  • an SMB lead asking for price without explaining the need
  • an SMB lead who confirms an eligible service and then asks for an exception
  • a complex account pushing for a number “just for budgeting”
  • a known partner requesting terms from an unverified number
  • a supposed partner with no recorded relationship
  • a contact that changes segment during the conversation
  • a request in another currency or against an expired rate
  • a message combining commercial interest with a complaint
  • a handoff with no available owner or a broken calendar
  • prompt injection or pasted content that tries to override policy

One person plays the contact and may insist or rephrase. Another observes the state the agent receives. The team compares the sent message, triggered rule, exposed data, created record, and next step.

The ready-to-implement criterion

“It replied reasonably” is not an exit criterion. The set is ready for a controlled pilot when:

  • every case ends as allowed, prohibited, or escalated without an implicit fourth category
  • no prohibited case reveals a price, margin, discount, or reserved term, including through a paraphrase
  • every allowed price comes from an approved, current source that applies to the segment
  • every escalation creates an owner, reason, minimum context, and visible next step
  • the team reaches the same decision when equivalent cases are repeated with different wording
  • disagreements are resolved in policy instead of being marked “the agent will decide”
  • the team has rehearsed pausing sends, correcting the rule, and rerunning the tests

The session does not authorize general autonomy. It authorizes one version of the catalog for a defined population and set of intents. A change in segment, price source, model, tool, or scope requires rerunning the affected cases.

Operate the rules after launch

Assign a commercial owner to the catalog and an operational owner to its execution. Record the version, approver, effective date, cases covered, and reason for every change. Human corrections and new escalations inform the next review, but they do not change policy by themselves.

Before each release or expansion, verify changing channel conditions that same day against applicable official and provider sources: consent, templates, messaging windows, regional availability, and data handling. Record the date and outcome. A practice observed in one account or an unconfirmed report is not a production rule.

Early success does not mean the agent quotes more often. It means the conversation stays useful without exposing an improper condition, the agent knows when to stop, and the person who receives the case can continue without reconstructing it from scratch.

Kiia can turn a real commercial route into rules, simulation cases, and a bounded pilot. The starting point is not the prompt. It is the set of decisions the team wants to be able to defend when the conversation gets difficult.

Frequently asked questions

Can the agent provide price ranges?

Only when the range is approved for that segment, has a defined validity period and currency, and the minimum context makes it safe to use. If price depends on scope, volume, integration, or an existing agreement, the agent should explain that the case needs review and escalate it.

What if the lead keeps insisting on a price?

Insistence does not change the rule. The agent acknowledges the question, asks only for the missing context, and offers a concrete next step. When the case requires a commercial decision, it hands the conversation to a person with the summary and open question.

Who approves changes to the messaging rules?

A designated commercial owner approves content and exceptions, while operations confirms that the rule can be executed and recorded. Every change needs a version, date, reason, and a new test before it reaches production.

From insight to action

Want to turn this into an agent that works for your team?

Tell us which process you want to improve. In a free call, we will identify the first workflow worth building.

Book a free call