Customers pick their service day without touching dispatch
Customers pick a service day from a signed link on their case. Full days are hidden, submissions are queued, and the guest user never writes a service record.
- Salesforce
- Custom
The problem
Customers called to ask which day the driver was coming, and a dispatcher looked it up. The obvious fix, a public form that writes to the schedule, means a guest user with write access to field-service records. That is a bigger risk than the phone calls.
What we built
A private link on each case, signed so an altered or made-up link fails. The customer opens it and sees only days that are actually open. The slot filter hides full days, unless the new stop is a cheap add to a route already passing by. Which days are open comes from the dispatch engine.
The submission never touches a field-service record. It lands in a queue, a platform event picks it up and writes the booking with internal permissions, and an audit row records who booked what and when. The customer gets a confirmation with a reschedule link that only offers valid days, so a change goes through the same gate as the original.
No AI in this build. Here's why that was right: a day is either open or full, and a link is either signed or it isn't. Nothing here needs a model to decide.
A signed token on the link, a slot filter that hides full days unless the stop is a cheap add to a route already passing by, a queue and a platform event that write the booking with internal permissions, an audit row per submission, and a confirmation with a reschedule link limited to valid days.
Outcome
None published yet. What we can show: every booking has an audit row, and the guest user never writes to a field-service record, which is the whole point of the queue.
Who this fits
- Field-service teams whose customers call to ask which day the driver is coming
- Operations leads who want customers to pick their own day without touching dispatch
- Anyone who has been told a public form has to write straight into the CRM