Record the reference and its constraints
Keep the provider message ID, attachment reference and relevant timestamps together. Read the provider’s rules for access, expiration, size and supported types. Do not assume that a URL visible in a webhook will remain usable indefinitely or without authentication.
Decide which files your application accepts and where authorized staff can see them. Validate retrieved content according to your application’s file-handling rules before presenting it as a trusted document or image.
Make retrieval failure visible
Track whether the application has merely received the reference, downloaded the content or completed its approved storage process. Give failures a retry or operator path that does not lose the original message association.
If media is unsupported on a plan or channel, let the operator understand that limitation. A missing preview should not be indistinguishable from a customer sending an empty message.
Test access after the conversation moves
Check the attachment with a second authorized operator and after reassignment. Verify the intended retention and deletion behavior in your own application and clarify what remains with the provider.
Use harmless synthetic files in the pilot, including an unsupported type and a reference that cannot be retrieved. Keep the results beside the provider’s media documentation so future changes can be evaluated against the same cases.