Voice AI has a larger attack and error surface than a simple chatbot
A production voice agent may connect to phone networks, customer records, internal APIs, recordings, billing systems, and human queues. Security therefore needs to cover more than login. It needs to govern what users can configure, what agents can call, what secrets they can access, and how changes are traced.
Start with role boundaries
Cally includes Owner, Admin, Member, and Supervisor roles with guarded routes and actions. This helps separate configuration, oversight, and privileged account operations. The principle is simple: a supervisor who needs to listen to calls should not automatically inherit every administrative permission.
Keep credentials outside conversational context
Cally encrypts API keys, bearer tokens, and sensitive headers at rest and masks stored values in the interface. Action definitions can use those credentials without exposing them as ordinary editable prompt content. That separation reduces accidental leakage during day-to-day agent configuration.
Sensitive actions need runtime controls
Security is not only about who configured the action. It is also about what happens during the call. Caller-confirmation safeguards can require explicit approval before a sensitive operation executes, while workflow confirmation nodes make the step visible in the conversation design.
Audit both administration and execution
Cally keeps audit logs for user actions and configuration changes, and action telemetry for individual API invocations. Together, those records can help answer two different questions: “Who changed the system?” and “What did the system do during this call?” Both are essential during incident review.
Security for voice AI should follow the full path from human administrator to live caller to backend action. Any missing link becomes the weak link.