The record of an unsaved conversation now outlives the outage
The Sustentus assistant keeps answering even when the system it saves conversations to is unavailable. A short interruption costs you your history, never your assistant, and since August the Sustentus team has been able to see each time that happened.
That record had one blind spot, and it was the worst one. It was kept in the same place the conversations themselves are kept — so the single situation it most needed to capture, the store being completely unreachable, was also the situation in which it could not be written. Small interruptions were caught in full. A total one erased its own evidence, and afterwards looked exactly like a quiet week.
The assistant now writes each of these records twice: once where the team reads them, and once to its own service log, before it goes anywhere near the database. The second copy needs nothing that an outage can take away, so a period the first copy is missing can be reconstructed from it. The page the team reads is unchanged and is still the place to look first — it now says plainly that a gap in it is recoverable, so an empty stretch is not mistaken for a calm one.
The second copy is written carefully. It carries only what the first one carries — which conversation step was lost, what that cost, and the name of the fault — and never the text of the conversation or the internal details of the fault itself.
This buys durability and only durability. Nobody is paged, nothing is grouped or counted for you, and reading the record is still a person’s job. It also needs one piece of setup before it is worth anything: the service log has to be pointed at somewhere that keeps it. Until an operator does that, the record survives the outage but is no further away from it than it was before.
Nothing changes in how you use the assistant, and nothing about your conversations is shared outside Sustentus.