Who in the company should be able to listen to call recordings versus just see the scores?
Far fewer people than currently can, in most companies. Recordings, transcripts and derived scores are three sensitivity classes and should carry three access levels. A rule of thumb that holds up: if someone's job can be done with the derived field, they should not have the audio. Marketing needs source and outcome. Supervisors need their own team's calls. Almost nobody needs unrestricted access to everything.
Three classes, not one permission
Most call systems ship with a single "can access calls" permission, which collapses a real distinction. The audio contains a customer's voice and whatever they said out loud, including things they should not have said out loud. The transcript contains the same content in a searchable form, which is arguably worse for bulk exposure. The derived record contains a category, an outcome and a score.
Those are not equivalent and should not be granted together by default. Once you separate them, most access questions answer themselves.
A role layout that works for a service business
- Representative. Own calls, own transcripts, own scores, own evidence citations. Seeing your own evidence is what makes coaching credible rather than mysterious.
- Supervisor or manager. Full access within their team, including audio, because verifying a disputed score requires listening. Not access to other teams.
- Marketing. Source, campaign, outcome, category, revenue linkage. No audio, no transcript. Everything marketing intelligence needs is in the derived layer.
- Ownership and multi-location leadership. Aggregates and rollups by default, with the ability to drill into a specific call when there is a reason. The reason gets logged.
- Engineering and vendors. Ideally none, with a documented break-glass path that is time-limited and logged.
The access log is half the control
Permissions decide who can. Logs decide whether anyone will. In practice, a visible record of who listened to which call changes behavior more reliably than a restrictive permission matrix that people work around by sharing exports.
Log the access, retain the log, and make it clear to the team that it exists. Quiet monitoring that nobody knows about is the version that damages trust.
Exports are the hole in every model
Careful role design is undone the moment someone downloads a spreadsheet of transcripts to their laptop. If your platform allows bulk export, that capability is effectively a permission of its own and should be granted separately and logged separately.
The same is true of anything that emails content out — a daily digest containing full transcripts routes sensitive data into inboxes and phones with no access control at all. Digests should carry derived fields and links, not payloads. That is how we build intelligence briefs and it is a deliberate choice, not an oversight.
Topics: access control · roles · least privilege · call recording
Have a version of this question about your own business?
The useful answer usually depends on which systems you run and how they're connected. That's a conversation, not a blog post.