Skip to main content

How to Prepare the Server for Attachments and the AI Features

Attachments and the AI features in ABM Service need things from the server and the network that the server setup and ABM Service Server Manager do not set up: permission to read the shared folders where files are kept, internet access in and out, and an https address. The system administrator, ABM user 1, switches the features on from the Administration menu in ABM Service; this page is what the site's IT person does so that they work.

What does ABM Service Server need so people can open linked attachments?​

ABM Service Server needs permission to read every shared folder where your company's linked files are kept, for the server computer's own Windows account. Some attachments are not stored in ABM: ABM keeps only a link to where the file is, such as a scan in a shared folder. In a web browser, those files are opened by the company's Windows service on the ABM Service server, not by the person's own PC.

  • A file kept on a shared folder, written with two backslashes, the computer's name and the share's name, is opened directly.
  • A file kept on a drive letter, such as S:, is opened only through the shared folder the system administrator says that letter stands for, on the Mapped drives screen under Administration in ABM Service. The server has no drive letters of its own.
  • A file kept in a folder on one computer's own disk, such as its C: drive, cannot be opened from the server at all.
  1. Ask the system administrator to open Mapped drives under Administration in ABM Service, in a browser. Its Linked files, by where they are kept list shows every shared folder and drive letter your company's linked files use, and how many files each holds.
  2. Give the server computer's own account permission to read each of those shared folders, in the share's permissions and in the folder's security.
  3. Ask the system administrator to press Test on each line. The ABM server can read followed by the folder means it works. Nothing in ABM Service needs restarting.

The same permission covers invoices and other documents customers open from the Customer portal, when ABM keeps them as links to a shared folder. Files people upload in ABM Service are kept in the company database and need no share at all.

Which Windows account does ABM Service Server read shared folders as?​

ABM Service Server reads shared folders as the server computer's own account: the server's name followed by a dollar sign, such as ABMSRV$ for a server called ABMSRV. That is the account to give read permission to on each shared folder. The Mapped drives screen in ABM Service names it under Drive letters: The ABM server opens shared folders as the server computer's own account, then the account.

Each company's Windows service runs under a Windows virtual account of its own, NT SERVICE\AbmService- followed by the company's name, which the server manager sets up when the company is added. Windows never sends a virtual account to another computer under its own name: it reaches the network as the computer's account, so that is the name the file server sees.

  • Add it as a computer. In the folder's permissions dialog in Windows, the server's account is found only after you tick Computers under Object Types.
  • Read is enough. ABM Service only reads linked files; it never writes, moves or deletes anything in a linked folder.
  • One permission covers every company on the server, because every company's service reaches the network as the same computer account.
  • The desktop app is different. The ABM Service desktop app reads linked files as the person signed in to Windows. A file that opens in the desktop app but not in a browser usually means the server's account has no permission on its folder, or its drive letter is not mapped.
  • A new server is a new account. If ABM Service Server moves to another server, give that server's account the same permissions.

Where do I see why a linked attachment would not open?​

Office staff see a sentence saying why the file cannot be opened, and the company's child log file says exactly which file and why. Open the log with Open logs under the company in ABM Service Server Manager: each time somebody tries to open a linked file that the server cannot open, the log records where the file is kept and the reason, such as AccessDenied, NotFound or NotReachable, which the screen never shows.

What office staff see, and what to check for each:

  • ABM is not allowed to open the folder this file is kept in. Your system administrator can give ABM access to that folder. The server's account has no read permission on that folder, or on a folder inside the share that has its own permissions.
  • The folder this file is kept in could not be reached. followed by a note that the computer may be switched off. The file server did not answer within about eight seconds, or could not be reached at all: check it is on, that its name resolves from the ABM Service server, and that any firewall between the two allows Windows file sharing.
  • This file is no longer where it was kept. It may have been moved or deleted. The folder answered, but the file is not in it.
  • This file is kept on drive followed by a letter, and ABM has not been told which shared folder it stands for. The system administrator maps that letter on the Mapped drives screen.
  • This file is in a folder on the computer it was attached from, so it cannot be opened from here. It was linked to a computer's own disk; only the ABM Service desktop app on that computer can open it.

Where are uploaded attachments kept, and how large can they be?​

Files people upload in ABM Service are stored in the company database, in the same place ABM keeps the attachments it stores itself, so the database, and every backup of it, grows by the size of each file attached. Each file can be up to 50 MB. A larger one is refused with This file is larger than 50 MB, the most that can be attached.

  • Plan for the growth. A company that attaches many photos and documents adds their whole size to the company database, which matters for the database server's disk and for the size and time of its backups.
  • Let uploads through anything in front of the server. A reverse proxy, gateway or tunnel service that passes requests on to the company must allow a single request a little over 50 MB, or it stops the larger uploads before they reach ABM Service.
  • Nothing is written to a shared folder. Uploading never creates a file on a share; only a linked file lives outside the database.

What does the server need for Fill in with AI and the voice note?​

Fill in with AI and Voice note on the call screen need the company's web server to reach the AI service over the internet, with outgoing HTTPS. Nothing on the internet connects in for them, so they need no public address. The system administrator switches them on as ABM Service AI on the AI agents screen under Administration.

  • Allow outgoing HTTPS from the server to the address shown as AgentDesk API under Connection on that agent's page in AI agents. The server, not the person's PC, sends what is typed or said to the AI service and receives the answer, so people's own PCs need nothing extra in a browser.
  • The machine's proxy is used. These requests go through the proxy set for the server in Windows, the same as the web application's updates. There is no setting of its own for a proxy that asks for a user name and password.
  • Voice note needs an https address in a browser, because the browser gives the microphone only to a secure page. On a plain http address it is blocked; the ABM Service desktop app works.

In the ABM Service desktop app, the same requests are sent from each person's own PC rather than from the server.

What does the server need for Log a call by voice?​

Log by voice, on the customer screen and in the Customer portal, needs the company to be reachable from the internet over https, because while somebody is talking to a voice agent, the AI service calls the company's server back to check who is calling, look up the customer and log the call. The system administrator sets each voice agent up on the AI agents screen, and its Base Path step registers the address the AI service calls; Register with AgentDesk fails unless the AI service can reach that address there and then.

What the site provides:

  1. Publish the company at an https address that the internet can reach, passing every path under it through to the company's port, not only the sign-in page. ABM Service Server answers plain http on its own port, so the https part comes from a reverse proxy, gateway or tunnel service you put in front of it.
  2. Keep the server's clock right. Every call back from the AI service carries the time it was signed, and one more than five minutes away from the server's clock is refused.
  3. Allow outgoing HTTPS from the server to the addresses shown as AgentDesk API and Widget on the agent's page. The server uses them while the agent is set up, for its list of who may use it, and each time somebody starts a voice call.
  4. Let people's browsers reach the AI service. The voice window loads from the address shown as Widget on the agent's page, so office PCs, and customers using the Customer portal, need to reach it.
  5. Give people an https address for Talk here and Call me back, which a browser allows only on a secure page. Pair a phone works on any address.

The AI service's calls back count among the company's connected users in ABM Service Server Manager, so Update now shows somebody connected while a voice call is going on, rather than cutting it off unseen.

What does the server need so people can connect AI assistants such as ChatGPT and Claude?​

AI assistants need a public https address for the company that the internet can reach, because ChatGPT and Claude connect to ABM Service from their own companies' servers. The system administrator types that address in The address assistants use on the AI assistants screen and presses Check and switch on, and nothing is switched on until the check passes.

  • A name of its own. The address is a web address with nothing after the name, though a port is allowed, so the company cannot be published as a folder under another website's address. It must lead to this company and no other, with every path under it passed through.
  • The server checks it from the inside, directly. The check is ABM Service Server asking its own public address for an answer only it can give, so the server must be able to reach its own public address from inside your network, without a proxy. A server that reaches the internet only through a proxy cannot pass it.
  • The name must look public from the server. If your own name servers give the server an inside address for the public name, the check fails with could not be reached from this server: and a reason that says which is not a public internet address. Let the server resolve the name to its public address.
  • Outgoing HTTPS, directly. When a person connects their assistant, the server also fetches that assistant's own description from its company's address on the internet, again without a proxy.

Connected assistants stay connected when the company restarts or updates, because their connections are kept in the company database; people signed in in a browser are signed out as usual.

Why do the microphone features need an https address?​

Browsers let a web page use the microphone only when the page is secure: an https address, or the computer's own address. A company opened at http:// followed by the server's name and port is not secure, so on that address the browser offers no microphone, no permission setting can change that, and ABM Service says so rather than failing silently.

  • Voice note on the call screen is blocked with Browsers only let a secure page use the microphone, and the address is not one., followed by advice to open ABM Service at its https address or in the desktop app.
  • Talk here in Log by voice is blocked with the same first sentence. Call me back is blocked too, with AgentDesk’s call-back screen needs a secure page too, and the address is not one. Pair a phone still works.
  • The ABM Service desktop app is not affected. It opens ABM Service on the PC's own address, which browsers treat as secure.

Nothing on ABM Service Server can change this: it is each browser's own rule, and the server answers plain http only. To give people the microphone in a browser, put an https address in front of the company, as described in How the Web Address and the Databases Are Connected, and have people open ABM Service at that address.