Who inside the company should be able to listen to recorded customer calls?
Fewer people than currently can. A workable default: reps hear their own calls, managers hear their team's, ops and marketing work from redacted transcripts and structured outputs instead of raw audio, and unrestricted access is a short named list. Log every playback. Most companies discover during their first access review that a former employee's account still opens the entire archive.
Four tiers, not two
Most systems ship with roughly two settings: can hear calls, cannot hear calls. That forces you to over-grant, because marketing genuinely needs call data and the only way to give it to them is full access.
Four tiers solves it. Own calls. Team's calls. Redacted transcripts and structured outputs, no audio. Full archive, named individuals only. Marketing sits in the third tier and loses nothing they actually needed.
If your phone platform cannot express four tiers, the tiering can live in the layer built on top of it. That is one of the quieter arguments for keeping analysis and reporting in a system you control rather than accepting whatever permission model the recorder happened to ship with.
Make the redacted transcript the default work surface
Ask what each role does with a recording. Analysts want themes and outcomes. Marketing wants source quality and objection patterns. Ops wants dispatch accuracy. Almost none of that requires hearing a customer's voice.
Once the redacted transcript is the normal tool, raw audio becomes an exception request — which is both a smaller attack surface and a much easier thing to log. It also makes customer intelligence work shareable without shipping voice recordings around the company.
Access logging is the control that actually works
You cannot prevent curiosity with permissions alone, because the people with legitimate access are the people who would misuse it. What you can do is make access visible: who played which recording, when.
Nobody browses an archive casually when playback is logged and the log is reviewed. Ask any vendor whether playback is logged and whether you can read the log yourself — a surprising number cannot answer yes to the second part.
The offboarding gap is the real vulnerability
The recurring finding in access reviews is not a hacker. It is a former dispatcher whose account was never disabled, a shared login on a sticky note, or a service account created for an integration that still has full permissions under someone's name.
Tie account removal to the same checklist as the badge and the truck keys, use single sign-on so there is one place to revoke, and give integrations their own scoped credentials instead of borrowing an employee's.
Topics: access control · permissions · recordings · offboarding
Have a version of this question about your own business?
The useful answer usually depends on which systems you run and how they're connected. That's a conversation, not a blog post.