Agent Desktop and Supervisor Dashboard
This guide covers the two day-to-day Contact Center surfaces:
- The Agent Workspace - the full-screen desktop where a contact center agent spends the shift: it presents work, connects calls, shows customer context, and captures the outcome.
- The Supervisor Dashboard - the live wallboard a contact center manager uses to monitor queue health and agent presence in real time.
Both build on the real-time SignalR layer and the Telephony soft phone. The CRM still owns the work (activities, contacts, subjects, dispositions), the Contact Center orchestrates it, and Telephony executes the media.
This page explains how the surfaces work. For a task-by-task how-to (sign in, accept a call, request a break, create a queue, load activities, monitor/whisper/barge) with screencasts, see the User Manual.
Choosing the agent experience
There are two agent tiers, so enable the one that matches how your agents work:
- Soft-phone agents - the Contact Center soft-phone projection is integration glue rather than a standalone feature: it activates automatically whenever Contact Center Voice, Contact Center Real-Time, and the shared Telephony Soft Phone Core client (
CrestApps.OrchardCore.Telephony.SoftPhone.Core) are all enabled. Soft Phone Core is enabled by dependency: turning on the Telephony Soft Phone widget or the Telephony Soft Phone Extension feature switches it on. Agents then get live Contact Center call state, presence, and work offers inside the Telephony soft phone, without the full-screen workspace. - Full-desktop agents - the CRM-integrated Agent Workspace is integration glue rather than a standalone feature. It activates automatically whenever Contact Center Agents, Contact Center Voice, Contact Center Real-Time, and Telephony Soft Phone Core are all enabled, so it also surfaces the soft-phone projection automatically. There is no separate Agent Desktop feature to enable.
Enabling the surfaces
The My workspace Agent Workspace activates on its own once Contact Center Agents, the Telephony soft phone, and a Contact Center voice capability — such as Contact Center Inbound Voice or the Outbound Dialer, which turn on Contact Center Voice and, with it, Contact Center Real-Time — are all enabled. It is gated on exactly those capabilities so the workspace cannot activate with missing services. Enable Contact Center Supervision & Live Dashboard (CrestApps.OrchardCore.ContactCenter.Supervision) for the Live dashboard; it explicitly composes Real-Time and Voice. Configure a voice provider such as Telnyx or Asterisk for voice work.
The corresponding entries appear independently under Interaction Center:
- My workspace - the Agent Workspace, available to anyone with the
ContactCenterSignIntoQueuespermission. - Live dashboard - the Supervisor Dashboard, available to anyone with the
MonitorContactCenterpermission (granted to the built-in Supervisor role).
The docked agent bar
Agents do not have to keep the Agent Workspace (or even the soft phone) focused to receive work. When the full-desktop agent experience is active — that is, whenever Contact Center Agents, Contact Center Real-Time, Contact Center Voice, and Telephony Soft Phone Core are all enabled — a persistent docked agent bar is injected into the admin chrome (the layout Footer zone) of every admin page for any signed-in user who has the ContactCenterSignIntoQueues permission. It is admin chrome, not a placeable widget, so no page can accidentally omit it. The bar is always there as a small collapsed tab showing your presence; click it to open the bar. A new phone offer opens it on its own, and it tucks itself away again when that work is finished or when you click elsewhere on the page.
The bar is the CRM-side bridge to the call router. It holds its own live Contact Center hub connection outside the soft phone, so a work assignment reaches the agent wherever they are in the CRM even when the soft phone is running in its own window or the browser extension. When work is assigned, the bar pops the matched record. It shows the ringing offer with Accept and Decline (a preview offer shows Dial and Skip), then the active call with a link to the activity. Presence on the bar is read-only: change your status from the soft phone. The bar has no disposition controls of its own; you disposition the work on the activity's Complete activity page.
The bar is deliberately not injected on:
- the standalone soft-phone page (
/softphone) — that page is the phone, and a second hub connection there would pop the matched record over the live call and navigate the phone away; and - non-admin (front-end) pages, and any non-view response (JSON, files, redirects) that has no layout to inject into.
Because it rides the soft phone's capability model, a provider without in-browser audio still gets the provider-neutral bar and workspace.
For contact center managers: preparing the environment
Agents can only receive work once the routing environment exists. Configure these in the Interaction Center before your team signs in. Each item links to its detailed reference in Agents, Queues & Dialer.
- Skills (Interaction Center → Management → Skills) - define the competencies routing can require, for example
Spanish,Billing, orTier2. - Queues (Interaction Center → Management → Queues) - create a queue per line of business. Choose the routing strategy (longest-idle, round-robin, or least-busy), optional sticky-agent preference, the SLA threshold, the reservation timeout, required skills, and - for inbound voice - the dialed number (DID) that feeds the queue. See Queues, reservations, and assignment.
- Business hours (Interaction Center → Management → Business hours) - attach a calendar to a queue so it pauses routing (or overflows) when closed.
- Inbound entry points (Interaction Center → Inbound entry points, Entry Points feature) - map an inbound DID to a queue with a priority, business-hours gating, and a closed-hours action (hold, voicemail, overflow, or reject).
- Agent state reason codes (Interaction Center → Management → Agent states) - define the not-ready presence reasons agents can choose (for example
Lunch,Coaching,Admin). These appear in the agent presence menu. - Agent entitlements (Interaction Center → Management → Agent entitlements, optional Agent Entitlements feature; without it any agent may sign in to any queue or campaign) - select an Orchard user and grant the queues and campaigns that user may join. The soft phone lists only these choices, sign-in rejects requests with no authorized membership, routing ignores stale or imported live memberships that are not also entitled, and removing an entitlement immediately prunes the corresponding live session membership, removes connected clients from revoked queue groups, and refreshes their membership snapshot.
- Campaigns and dispositions - campaigns and dispositions live in the Omnichannel Interaction Center. Every activity carries a Subject whose Subject Flow is the single decision controller: it defines the dispositions an agent can choose and the follow-up actions each disposition triggers. See Subject Flow is the single decision controller.
- Dialer profiles (Interaction Center → Management → Dialer Profiles, Dialer feature) - for outbound work, define a reusable dialing mode (preview, power, or progressive), pacing, and compliance rules. The campaign is picked when activities are loaded, not on the profile. See Dialer.
- Callbacks - use the callback service or workflow bridge to schedule callback requests against a contact, destination, due window, and optional queue. Due callbacks are promoted into outbound callback activities and, when a queue is set, enter the same routing path as other work.
Grant agents the ContactCenterSignIntoQueues permission (or a role that includes it), and grant supervisors the built-in Supervisor role (or the MonitorContactCenter permission).
For contact center managers: the Live Dashboard
Open Interaction Center → Live dashboard. The dashboard connects to the real-time hub and refreshes automatically as work and presence change (with a periodic safety refresh), so it can be left open on a wallboard.
It shows three sections:
- Summary metrics - total items waiting across all queues, the number of available agents, the total agent count, and the queue count.
- Queue tiles - one tile per enabled queue showing the waiting count, signed-in agents, available agents, busy/reserved/wrap-up agents, other not-ready agents, the longest current wait, and the number of items that have breached the queue's SLA threshold. Tiles turn amber as waits approach the SLA and red once items breach it, so managers can compare demand and staffing at a glance.
- Agent board - every agent with a live presence dot (available, busy, wrap-up, break, and so on), their current reason, and how many interactions they are handling.
Use it to spot a backing-up queue, an SLA breach, or too few available agents, and then rebalance staffing, adjust queue priorities, or open a campaign.
When an agent has a live interaction, the agent card shows only the Monitor, Whisper, or Barge actions for which the active provider both advertises the matching capability and implements the executable monitoring contract. Each action invokes the provider first; the audited Contact Center event is published only after the provider confirms success. Missing contracts, provider failures, and unknown outcomes stay hidden or return failure without recording a successful engagement. While an agent has paused recording for a sensitive-data capture, all three actions fail closed on the server, so a supervisor can never listen in on the secured segment.
While engaged, the card shows the active mode pressed and a Stop; the other modes switch on the same leg (a provider that cannot, like Asterisk, stops and engages again). Take over hands the call to the supervisor, and More ▾ holds End call, Transfer, Record on or off, the agent's state and Message, each shown only when the provider and the supervisor's permissions allow it. The supervisor hears the call on their own soft phone, which shows a Monitoring banner with the same switcher and Stop instead of a call row. See the user manual and, for how Telnyx does it, Telnyx supervisor monitoring.
For contact center managers: inbound routing runbook
Use this checklist before publishing a new inbound line:
- Create or confirm the Omnichannel channel endpoint for the dialed number.
- Configure the Subject Flow for that endpoint so inbound activities get the right subject, campaign, disposition list, required-disposition policy, and follow-up subject actions.
- Create the target queue, set its SLA, reservation timeout, routing strategy, required skills, and overflow queue.
- Attach a business-hours calendar when the queue should pause or overflow outside staffed hours.
- Create an Inbound entry point for the DID. Set the target queue (or a specific agent), priority, the default voicemail greeting (spoken to callers who reach voicemail on this line when the agent has no greeting of their own), and the closed action: hold, voicemail, overflow, or reject. To let callers choose where they go, build an IVR menu on the same screen. The Welcome message is spoken to callers while the entry point is open, before the IVR menu or, without one, before they are put through to the target; the Closed message is spoken while it is closed, before the closed action. Both are optional; see Voice Routing → Welcome and closed messages. The queue's own Welcome message is separate and is spoken when the caller starts waiting in the queue.
- Sign at least one skilled agent in to the queue, then place a test call. The expected path is provider webhook → entry point → queue → reservation → Agent Workspace offer → soft-phone media.
- Watch Live dashboard while testing. The queue waiting count should increase before assignment, then the selected agent should move from available to reserved/busy/wrap-up as the call progresses.
Building an IVR menu
An entry point can play a phone menu ("press 1 for sales, 2 for support") before the caller is routed. The IVR menu field on the entry point editor (Interaction Center → Inbound entry points → Edit) is a visual editor:
-
With no menu, the field says No IVR menu and callers are routed straight to the entry point's target. Click Build an IVR menu to start one; Remove the IVR menu goes back to no menu.
-
Each menu has a name (renaming it updates every key that opens it), What callers hear (the spoken prompt), and an optional Recorded prompt: the identifier of a voice media item played instead of the text. A menu needs one or the other.
-
Each key row picks a key (
0-9,*,#; a key already used on the menu is not offered again), an action, and a target that changes with the action:Action Stored kind Target Send to a queue RouteToQueueA queue, picked from the tenant's queues. Send to an agent RouteToAgentAn agent, picked from the tenant's agents. Open a submenu SubMenuOne of the menus defined here, or + New menu to create one. A key that jumps to a menu drawn under another key (for example back to the main menu) shows as Go to another menu. Send to voicemail VoicemailNone. Transfer to an approved external number ExternalTransferAn approved destination from the External transfer destinations section of Settings → Contact Center. Repeat this menu RepeatNone. -
First menu is the menu callers hear first. Tries is how many wrong or missing keys a caller gets before When the tries run out takes over; that fallback uses the same actions, or Route to the entry point target to route the call the way the entry point would with no menu.
Problems are shown beside the field that has them, with a count at the top: a missing or unknown first menu, a menu with no name or a duplicate name, a silent menu, a menu with no keys, a repeated or invalid key, a key with no action, an action with no target, and a key that opens a menu that does not exist. Two warnings do not block saving: a menu no key or fallback leads to (callers never hear it), and a queue, agent or destination that is no longer in the lists. The server checks the menu again on save and refuses one that cannot run.
Switch on Advanced: edit JSON to see or type the menu as JSON. The two views stay in step; JSON that cannot be read keeps the editor in JSON mode, with the reason, until it is fixed or cleared. The JSON is the same shape a deployment plan carries:
{
"RootNodeId": "main",
"MaxRetries": 3,
"FallbackAction": { "Kind": "RouteToQueue", "TargetId": "QUEUE-ID" },
"Nodes": [
{
"NodeId": "main",
"Prompt": "Press 1 for sales or 2 for support.",
"PromptMediaId": null,
"Options": [
{ "Digit": "1", "Action": { "Kind": "RouteToQueue", "TargetId": "QUEUE-ID" } },
{ "Digit": "2", "Action": { "Kind": "SubMenu", "TargetId": "support" } }
]
}
]
}
An empty field means no menu. TargetId is null for Voicemail and Repeat.
The menu plays only while the entry point is open; a closed entry point applies its closed action instead. What each action does to the caller at run time, how retries and the fallback work, and what the call's history records are described in Voice Routing → Entry-point phone menus.
For contact center managers: outbound and callback runbook
Use CRM campaigns and activities as the source of outbound work; the dialer profile only controls execution.
- Create the campaign and Subject Flow in Omnichannel. Configure dispositions and subject actions first so every outcome has a business result.
- Load activities through Load Activities. Choose the Dialer source so activities are loaded unassigned and available for reservation.
- Create a dialer profile with the voice provider, dialing mode, pacing, and compliance settings, and pick it together with the campaign on the dialer activity load.
- Confirm do-not-call, retry delay, calling window, and national registry settings before enabling an automated mode.
- For callbacks, schedule a callback request with the destination, due time, queue, and notes. The callback dispatcher promotes due callbacks into outbound callback activities and enqueues them when a queue is set.
- Agents receive preview work, or automated power/progressive work, from the campaigns they are signed in to, then complete it with the same disposition flow used for inbound work.
For contact center managers: workflow automation
The Subject Flow is the primary business workflow for work completion. Use it for required dispositions and disposition-driven actions such as finish, retry, new activity, or communication-preference updates. Enable OrchardCore.Workflows alongside Contact Center only when you need Orchard workflow automation from Contact Center domain events such as routing decisions, offer acceptance, call connected/ended, callback scheduled/promoted, or SLA/analytics events; the Contact Center workflow activities then become available automatically. Workflow automation should enrich or react to activity state; it should not bypass queues, reservations, or the source-neutral disposition service.
For contact center agents: the Agent Workspace
Open Interaction Center → My workspace. This is the screen an agent keeps open for the whole shift. Keep the Telephony soft phone available too - it is where the call audio and device controls live.
Shift checklist
- Open My workspace and the Telephony soft phone.
- Sign in to the queues and campaigns you are staffed for.
- Set presence to Available when ready, or choose a reason code when not ready.
- Accept or decline inbound offers from the ringing card; dialer assignments open their Complete activity screen automatically so the assigned record is ready without another navigation step.
- End the conversation, review/update the CRM context, choose the disposition, add notes when needed, and submit.
- Use Recent activity to verify your last outcomes before taking the next offer.
1. Sign in and set your presence
- Sign in to queues and campaigns from the soft phone's Work tab. You can only choose queues and campaigns you are allowed to handle.
- Empty queue and campaign selectors show Select queue(s) and Select campaign(s). No membership is selected until you explicitly choose it.
- Select at least one queue or campaign before signing in. The Work tab shows an inline error when nothing is selected.
- After sign-in, the Work tab lists every queue and campaign you are signed in to. Use the individual Sign out action to leave one membership while remaining signed in to the others, or Sign out of all to leave every membership.
- If inbound voice work is already waiting in one of those queues, signing in or switching back to Available immediately asks routing to offer the next queued call instead of waiting for another inbound event.
- The Work tab signs you in and out over the live Contact Center connection without reloading the page, so your queue membership updates in place and your browser joins or leaves the live queue groups at once. Your live session membership follows too, so signing out removes this browser session from the queue and campaign state immediately.
- Signing in stays responsive even when the Voice feature is enabled, because the re-offer of waiting calls runs separately from the sign-in request.
- If the browser refreshes or the soft phone reconnects while you are signed in and available, your queues are re-checked as soon as the soft phone reconnects, so calls already waiting are offered to you rather than parked until the next inbound call.
- If a ringing offer was already assigned to you when the page refreshed, the soft phone restores that same offer and keeps the ringing modal visible until you accept it, decline it, or the reservation timeout sends it back to routing.
- A new inbound offer opens the soft-phone ringing modal as soon as routing assigns it; you do not need to refresh.
- Sign-in, sign-out, and reconnect all run the same self-healing pass before routing resumes. Leftovers such as a half-cleared offer from a restart, a pending reservation without a live ringing call, a stale ringing offer with no active reservation, or an available agent still holding assigned voice work are reclaimed and re-queued, so they cannot block your next offer or leave you counted as busy.
- When a timed-out offer goes back to the queue, its ringing assignment is cleared first, so you are not left at capacity for the next offer.
- Once you accept a call, the soft phone ignores any repeat of that same ringing offer and never shows a new inbound modal over the active call. If the offer is revoked at the same moment your accept finishes, the accepted call stays active instead of snapping back to Ready.
- Set your presence from the presence button at the top of the workspace. Choose Available to receive work, pick a reason code (for example Lunch or Coaching) to go not-ready, or choose Break. A break is granted immediately when nothing is being routed to you. While work holds you, the same item reads Request break: you finish the work and the break starts automatically afterward. The workspace menu has no Offline item; sign out from the soft phone's Work tab, or choose Offline from the soft phone's presence menu.
The top bar also shows a live chip per signed-in queue with its current waiting count, so you can see where the pressure is.
2. Receive and answer an offer
When routing selects you for a piece of work, a ringing offer card appears with the customer name (or number), the queue, and a countdown showing how long you have to respond. You have two choices:
- Accept - accepts the reservation, connects the media, and moves the work into your active panel. For providers that ring your own device, your device rings and you answer there. The workspace and the incoming-call modal re-check the provider's current call state before accepting, and the interaction is marked connected only when the provider reports it connected, so you never get stuck on a call the server already ended while the offer was in flight. For server-side queue delivery (for example Asterisk), Contact Center answers the live provider call during the accept, so the connected call stays visible and controllable.
- Decline - releases the offer so it is immediately re-offered to the next available agent. The incoming modal does not send a separate telephony reject for the same call.
If you do not respond before the countdown ends, the offer is revoked and routed elsewhere.
Dialer work is distinguished from inbound queue offers by its activity source. When a Preview, Power, Progressive, or generic dialer activity is assigned to you, the browser opens the assigned activity's shared Complete activity page automatically. Inbound work continues to show the ringing offer instead, so it is never redirected before you choose Accept or Decline.
3. Handle the active interaction
While you have nothing to handle, the panel says No active interactions right now: calls and messages you accept appear there. Recent activity likewise says No recent interactions until you finish your first one.
Once you accept, the active interaction panel shows:
- The customer, with a link to open the full CRM contact record (customer 360).
- The direction (inbound or outbound), the current call status, and a live talk timer.
- The queue the work came from.
- A Complete activity link that opens the same Omnichannel CRM completion page used by manual activities.
Use the soft phone for hold, mute, transfer, and hang-up. Controls are shown from the provider's advertised Telephony capabilities, and the server repeats the same capability check before invoking the provider. To place a second call, use Add call, which puts the current call on hold and opens the keypad; Hold on its own only holds the call. The soft phone lists every active interaction by phone number and state, lets the agent select the current call, conferences two selected calls without requiring a provider call id, and can disconnect all active calls. The workspace reflects call state in real time.
A Contact Center call is transferred through the Contact Center: the soft phone's transfer panel lists the other agents with their presence, the queues with who is waiting, and the approved outside numbers, and a warm transfer runs as a consult the agent completes or cancels from the panel (see How to transfer a call). Consultative transfer depends on the provider: Telnyx supports it; Asterisk supports blind transfer and two-call conference but rejects warm transfer. In a conference where the others stay on the call, the soft phone's hang-up button reads Leave: it takes you out of the conference and the others stay connected. End for all ends the conference for everyone.
The soft phone also keeps the active remote number visible while you are on the call, and the Recent tab lists inbound as well as outbound calls.
When Contact Center owns the assigned voice interaction, server-side call-session changes flow back into the Telephony soft phone in real time, so provider-side disconnects, failed calls, transfers, hold/resume, mute/unmute, and other normalized call-state changes update the live call card and the persisted Recent history at once.
For an answered queue or campaign call, a terminal provider event moves the agent from Busy to Wrap-up immediately. (A direct call, such as an extension call, skips wrap-up and returns the agent to work.) Wrap-up is not a timed auto-return: the agent reviews the CRM context, selects the disposition, records notes or scheduling changes, and completes the activity. Completion records the wrap-up end time and returns the agent to a previously requested break when one is pending; otherwise it returns the signed-in agent to Available and routing can offer the next call. This avoids sending another call while after-call work is unfinished. The platform caps wrap-up at 15 minutes (MaximumWrapUpDuration): after that the agent is released automatically, while the activity stays open and no disposition is recorded for it.
Presence changes and queued-call recovery run as separate operations, so a presence change never waits on voice routing and the presence control cannot be left spinning.
Contact Center also runs a provider-truth reconciliation pass when the tenant activates and on a periodic safety cadence. If Orchard Core restarts during busy hours, persisted ringing or active interactions are revalidated against the telephony server before routing resumes, and a pre-connect offer that already ended on the provider side is removed from the queue instead of being re-offered as a ghost call.
If a prior terminal provider event was already recorded in the call session but another recovery path left the interaction nonterminal, reconciliation repairs the interaction from the terminal call session before capacity is evaluated, then clears stale queue, reservation, and agent state. This prevents an ended call from consuming the agent's MaxConcurrentInteractions slot indefinitely.
For inbound server-side calls, a provider may report the caller leg as connected before an agent accepts the Contact Center offer. Ended-offer cleanup therefore uses the accepted reservation or assigned queue item—not the provider leg's answered timestamp—to decide whether the work reached an agent. A terminal call that was only waiting or reserved is removed and releases the agent so routing can continue to the next live call.
Secure pause for sensitive-data capture
When a customer must read out a card number, a national identity number, or another piece of sensitive data, the agent can suppress recording for that segment so the value never enters the recording, and resume it as soon as the customer finishes. This mirrors the "pause and resume" descoping control used by state-of-the-art contact center platforms to keep sensitive input out of recorded media.
The Pause recording control appears on the active interaction only when every one of these is true:
- The Recording feature is enabled and the tenant has turned on Allow agents to pause recording on the Recording governance tab of Settings → Contact Center.
- The agent holds the
ContactCenterSecurePauseRecordingpermission (granted to the built-in Agent stereotype). - The active voice provider advertises the RecordingPause capability and implements the executable recording contract for the live call (for example, the Asterisk provider).
When the agent pauses, the server re-checks the setting, the reason policy, the provider capability, and—most importantly—that the agent owns the live interaction before it asks the provider to pause. If the tenant requires a reason, the agent must supply one; the reason is stored on the interaction for the audit trail but never appears in the recording. A paused recording shows a clear Recording paused badge to the agent, and the control switches to Resume recording.
Two safeguards protect the customer even if the agent forgets to resume:
- Supervisor monitoring is blocked while recording is paused. A supervisor cannot start Monitor, Whisper, or Barge on an interaction whose recording is paused, so a coach can never listen in on the secured segment. The block is enforced on the server before the provider is ever contacted. If a supervisor was already engaged when the agent starts the pause, that live engagement is force-stopped as part of the pause, so an in-progress coach is evicted along with the recording rather than only being kept out afterward.
- Automatic resume returns recording to the active state after the tenant's configured maximum pause window elapses, so a pause can never silently outlive its purpose. The automatic resume is published as a distinct audit event so a safety-net resume is always distinguishable from an agent-driven resume. Setting the maximum window to
0disables the automatic guard and lets a pause persist until it is explicitly resumed.
The agent desktop and the Supervisor Dashboard both reflect the pause and resume in real time through the hub, so every audience sees the same recording state without refreshing.
Hosted secure data capture
Pausing recording keeps a spoken value out of the recorded media, but the agent still hears the customer read it out. Hosted secure data capture removes the agent from the exchange entirely: the customer enters the sensitive value on a dedicated secure page, the value is tokenized the moment it is submitted, and only a masked representation (such as the last four digits of a card) and a durable token reference are ever stored. Values that must never be retained in any form, such as a card security code, are validated and then discarded - no token and no mask are kept for them. The agent, the supervisor, and the recording never see the raw value. This mirrors the hosted-page tokenization pattern that state-of-the-art contact center platforms use to keep cardholder data out of agent scope and out of the recorded media path.
The Collect data securely control appears on the active interaction only when every one of these is true:
- The Secure Data Capture feature is enabled and the tenant has turned on Enable agent-assisted secure data capture in Interaction Center → Settings → Secure Data Capture.
- The agent holds the
ContactCenterInitiateSecureCapturepermission (granted to the built-in Agent stereotype).
When the agent starts a capture, the server re-checks the setting and confirms the agent owns the live interaction before it mints a one-time access token. Only one secure capture may be in progress for an interaction at a time, so a second request is refused while one is still collecting. The token is returned to the agent exactly once as a short-lived secure link to share with the customer over the existing channel; only its SHA-256 hash is stored, so a leaked datastore can never reconstruct a usable link. The secure page is served with Cache-Control: no-store and Referrer-Policy: no-referrer so the token in the link is never cached or leaked through a referrer header. Starting a capture also pauses recording as defense in depth when the tenant leaves Pause recording during capture enabled, so a provider that records the whole media path cannot retain the segment either. If the capture cannot be persisted after recording was paused, recording is resumed immediately so a failed start never leaves recording suppressed.
The customer opens the link on their own device and enters each requested value on the secure page. On submission every requested field is tokenized before anything is persisted, so a single invalid value cannot leave a half-completed capture; recording resumes automatically, and a secure capture completed audit event records only the masked values. Resuming recording is self-healing: if the provider cannot resume at the moment a capture settles, a background recovery pass retries it, so a transient provider failure never leaves recording paused permanently. If the customer never finishes, the one-time link expires after the tenant's configured window (30 seconds to one hour, five minutes by default), a background safety net settles the abandoned capture, and recording is resumed. The agent can also cancel an in-progress capture.
The default tokenization sink validates and masks the value locally and returns an opaque surrogate token. It is registered only in the Development environment and is intended for development and evaluation only: it is not a PCI-DSS-compliant sink, because the surrogate is not backed by a compliant vault. Outside Development, no sink is registered by default, so secure capture fails closed until an operator wires one up - a misconfigured production deployment can never silently fall back to the non-compliant developer sink. A production deployment that captures cardholder data must replace the ISecureCaptureTokenSink implementation with one that forwards the raw value to a PCI-DSS-compliant tokenization provider and returns that provider's token. The sink receives a stable per-capture, per-field idempotency key and a production implementation must honor it as an idempotency contract: the same key with the same value returns the original token without minting a second vault token, and the same key with a different value fails safely instead of tokenizing the new value. This makes a retried or replayed submission exactly-once at the vault even though the capture service runs inside an ambient unit of work whose commit is evaluated after the call returns.
PCI-DSS scope. In this model the raw value is submitted to the application, which hands it straight to the sink and never persists or logs it. That keeps the value out of agent, supervisor, and recording scope, but because the application receives and transmits the cardholder data it is in scope for PCI-DSS (part of the cardholder data environment). Do not treat the server-side model as SAQ A / SAQ A-EP eligible; determine the applicable assessment with your QSA. A deployment that wants the raw value to never reach the application - the prerequisite for the reduced SAQ A / SAQ A-EP scopes - should host the entry fields directly from the tokenization provider (for example provider-hosted iframe fields or direct-to-provider submission). The pluggable ISecureCaptureTokenSink seam and the browser-side secure page are the substitution points that make that hosted-field variant possible without changing the orchestration.
4. Complete the activity in the CRM
When the conversation ends, click Complete activity in the active panel. This opens the shared Omnichannel completion page for the assigned activity, so contact-center work follows the same CRM experience as manual activities:
- Review the customer/contact context and open the customer record when details need correction.
- Review activity details such as campaign, channel, urgency, schedule, instructions, and assignee.
- Update the subject details captured by the activity's subject content type.
- Choose a disposition from the list defined by the activity's subject flow.
- Add notes when needed and submit the completion form.
Completing routes through the shared disposition path, which applies the disposition, marks the activity completed, and runs the subject flow's follow-up actions - the same path used everywhere in the CRM, so inbound, outbound, and manual work all behave consistently. If the subject flow requires a disposition, completion is blocked until you pick one and the completion page shows why.
An activity that is already finished cannot be completed a second time, and the completion page says so instead of opening a form it will not accept. This is ordinary traffic rather than a stale link: an automated call that hands off to a live agent, or a caller who reaches voicemail on the queue's maximum wait, can close its own activity while the agent still has the wrap-up open. The agent is returned where they came from with an explanation, and the outcome already on record is kept rather than overwritten.
The workflow preview renders subject- and action-derived titles with DOM text nodes rather than HTML injection. Stored CRM text is displayed literally and cannot create markup or execute script in the agent's browser.
Completion links opened from Contact Center include a local return location. After dialer work is completed or cancelled, the agent returns to My workspace; manual activity completion keeps the default Activities destination. Return locations are accepted only when they are local application URLs.
5. Review recent activity
The workspace's Recent activity panel lists the interactions you finished most recently: the direction, the customer's number, the outcome, when it ended, and the talk time. It says No recent interactions until you finish your first one.
The soft phone keeps your history on two tabs, both of which update in real time as calls end (no page refresh needed):
- Recent lists your most recent calls with their direction, outcome, and time, and a Call button to dial the number back.
- Voicemail lists the voicemails left for you. A badge on the tab shows the unread count. Each entry shows the caller's number and time with a play/pause control; the compact player keeps the caller's number and time visible while it plays. Opening the tab marks the voicemails read and clears the badge.
6. Manage your voicemails
- Play a voicemail with the ▶ control on its row. Playback is governed and audited like any other recording, and the audit names you, as an agent, as the person who listened.
- Delete voicemails with the checkboxes: tick one or more rows (or Select all) and click Delete. Deleting removes the entry from your inbox and erases the stored recording. The voicemails are deleted one at a time. If some cannot be deleted, the tab says how many, and each one that is left stays selected with the reason on its row (for example, the recording is under legal hold, or your session has ended). A voicemail whose caller hung up before anything was recorded is removed from your inbox without an erasure entry in the audit, because there was no recording to erase.
Who owns a voicemail
One rule decides which voicemails you see, play and delete: a voicemail is yours when it is in your soft-phone inbox. You can play and delete exactly the voicemails in your list, and nobody can play or delete a voicemail that is in another user's inbox, whatever identifier they send.
The platform puts a voicemail in an inbox once, when the call reaches voicemail:
| How the call reached voicemail | Whose inbox |
|---|---|
| A direct call to an agent (their extension, or an entry point that targets them) that was not answered | The agent the call was for. |
| An agent pressed Voicemail on a ringing call | That agent. |
| A queued call that reached the queue's voicemail on its maximum wait, after an offer to an agent expired | The agent the call was last offered to. |
| A call on a queue line that reached voicemail with no agent of its own (the caller chose voicemail from the phone menu, the queue was full, or they waited too long before anybody was offered the call) | The entry point's Voicemail inbox agent. With none set, the message is recorded but is in nobody's inbox. When the entry point delivers to The queue's shared voicemail box, the message is in no agent's inbox: it is on the Shared voicemail page for the queue, including the case above where an offer had expired earlier (see The queue's shared voicemail box). |
Unless the entry point delivers to the queue's shared voicemail box, a queue voicemail is not shared among the queue's members and is not listed for supervisors. To have a supervisor hear the messages left on a queue line, set the entry point's Voicemail inbox to the supervisor's agent profile; the messages then appear in that person's Voicemail tab like their own. A supervisor who must remove a recording uses recording erasure, which is audited as the supervisor's action.
The voicemail endpoints answer a refusal with a status code and a problem body (401 signed out, 403 not in your inbox, 404 not found, 409 legal hold). They never redirect to the sign-in or access-denied page, so the soft phone can always tell a refused delete from a completed one.
7. Record your voicemail greeting
Open Interaction Center → My voicemail greeting. This is the message callers hear before leaving you a voicemail.
- Record with your microphone (the default): press Record, speak, then press Stop (the same button toggles), review the preview, and Save.
- Or switch to Upload a file and choose an audio file (mp3 or wav).
- Remove greeting falls back to the line's default greeting.
A saved greeting is uploaded to the telephony provider's own media storage (for Telnyx, Media Storage) and played back from there, so no publicly reachable URL of your own is required. When you have no recorded greeting, the caller hears the entry point's Default voicemail greeting (configured per dialed number), and if that is also empty, a built-in system greeting. See Voice routing.
How it works
- The workspace loads a state snapshot from the server and then keeps itself current from the real-time hub's presence, offer, and queue events. It re-reads the authoritative state after you act, so what you see always matches the server.
- Contact Center domain events are persisted immediately and the handler fan-out runs as deferred outbox work, so slow workflow or real-time projections do not block the soft-phone sign-in or sign-out postback.
- Accept calls a single server-side command that accepts the reservation, revalidates the provider's current call state, tells the voice provider to connect the call when needed, and advances the interaction and call session only when the provider truth supports that transition.
- Complete goes through the source-neutral
IActivityDispositionService, so dispositions, required-disposition rules, and subject-flow actions behave identically across every channel and source.
Permissions and roles
| Permission | Grants |
|---|---|
ContactCenterSignIntoQueues | Sign in to queues/campaigns, change own presence, and use the Agent Workspace (accept/decline offers, complete work). |
ContactCenterSecurePauseRecording | Pause and resume recording on the agent's own live interaction to keep sensitive customer data out of the recording. Included in the Agent stereotype. |
ContactCenterInitiateSecureCapture | Start an agent-assisted hosted secure data capture on the agent's own live interaction, so the customer enters sensitive data on a secure page instead of reading it to the agent. Included in the Agent stereotype. |
MonitorContactCenter | Open the Supervisor Dashboard and watch queues in real time. Included in the Supervisor role. |
ManageContactCenterQueues, ManageContactCenterAgents, ManageContactCenterSkills, ManageContactCenterDialer | Configure the routing environment (queues, agents, skills, dialer). See Agents, Queues & Dialer. |