AgentAnywhere Swaraj
Platform13 min readSee the platform →

One call. Three agents, two people, one record.

An outsourcer takes a call for a client. This follows that one call through the AgentAnywhere platform, from the first word to the day the client's auditor asks what the AI did on its account: which part of the platform does what, what policy decides outside the model, where a person approves, and what is written down.

AgentAnywhere Research

Animated diagram of one service call inside one client's boundary at an outsourcer. During the call, a customer's words reach an assist agent through the client's governed door, the human agent answers, and a refund stops at a named team leader who approves. After the call, a wrap-up agent drafts the note and a quality agent flags items for a person to review. A month later, the client's auditor reads signed receipts and the Registry's history for that client. A note says the figure shows text, not audio.
FIG.72One call in three bands: during the call, an assist agent works beside the human agent and a refund stops at a team leader; after it, a wrap-up agent and a quality agent work from the masked conversation; a month later, the client's auditor reads that client's record. Illustration; no client or outsourcer is depicted, and the figure is about text, not audio.

A refund, and a limit

The scene that follows is illustrative. It describes no particular centre, client or customer.

A customer calls the support line of an online retailer. The line is answered by an outsourcer in another city, one of several clients served from the same floor. She returned an appliance three weeks ago and the refund has not arrived. She has the order number, and she is not in a mood to repeat it.

The agent who takes the call can see the order. The refund is larger than an agent is allowed to release alone. The team leader who can approve it is on another call. The client's contract says its customers' data stays in the client's region, and its audit clause says the outsourcer must be able to show what any automated system did with that data.

Four things have to go right in the next ten minutes: the answer, the approval, the note, and the record. Only the first is the agent's alone.

One call, seven steps

Each step names the part of the platform that does the work.

  • 1 · The conversation enters through the client's door

    One governed door per client: policy is enforced at the point of the call, sensitive fields are masked in line, and there is a Trust Receipt for every call. The policy and the masking rules in force are that client's.

  • 2 · An assist agent works beside the human agent

    It receives each turn of the transcript with the designated fields that were detected masked, and offers suggestions grounded in the client's approved knowledge, with citations, so the agent can see where a suggestion came from before using it. Talk to us about Seva, the service-operations family, for this work.

  • 3 · Manipulated input is checked on the same call

    A customer's words, or a message pasted into a chat, are data and not instructions. The call is inspected for prompt injection outside the model. No guardrail catches everything.

  • 4 · The refund stops at a person

    The flow reaches a checkpoint with an explicit queue, a named approver group, escalation rules and an SLA timer. The team leader approves or rejects, and the approval state lives in the run record.

  • 5 · The customer gets a person when she needs one

    A clean handoff to a human when the customer needs one is part of how the platform is used on a service floor.

  • 6 · After the call, the note is drafted and the call is reviewed

    A wrap-up agent drafts the summary and the disposition from the masked conversation. A quality agent reviews the interaction for script adherence and compliance obligations, and flags items for a person to review.

  • 7 · The record is closed, per client

    The mask, the approval and each agent's call write signed Trust Receipts into that client's audit trail.

How the agents hand over to each other

Three agents and two people touch this call. Most of what goes wrong in such a chain goes wrong at the joins. The Orchestrator is the part that owns them.

Agents are services with contracts. Each declares what it accepts and what it emits. Handoffs are typed and validated at run time; a violation goes to a typed error path, not a generic catch.

A retry does not act twice. Every step has an idempotency key, so a re-run does not double-charge, double-write or double-message.

A long call survives a restart. Workflow state survives restarts and deployments, and long-running workflows checkpoint after every consequential step.

A missed deadline goes somewhere. Every step declares its retry policy, its fallback, its escalation path and its SLA. A workflow that breaches its SLA is routed to a handler you configure, not silently abandoned.

Who owns the flow

Operations

The team that runs the floor designs the flow in Flow Studio: the steps, the branch logic and the human checkpoints.

A test panel mocks tools and models, so a failure can be rehearsed before it happens.

Every save is a draft in the Registry. Production is reached only through approval.

Engineering

Engineers build the adapters to the systems the client already runs, such as CRM and ticketing, in Agent Lab.

They work on the same artifact, with tests that run in CI, where failures block the merge.

A change shows up for both teams; neither rewrites the other's work.

A month later: the client's audit

The client's auditor asks what automated systems did with its customers' data in the quarter, and who approved what.

For that client only. The deployment for this client has its own policies, masking rules and audit trail.

What ran. The Registry shows which version of the flow, which prompt and which model were in production on a given day, and who approved each. An artifact can be retired, but it cannot be deleted from production history.

What happened on a call. Signed, chained Trust Receipts: who, what, which model, which policy, when. They export as JSON and PDF.

Where it ran. In your cloud or your client's: in-perimeter, region-pinned or air-gapped. Customer data never transits ShepHertz infrastructure.

What the record does not show. A value that was not detected leaves no masking receipt, so the record cannot prove that nothing sensitive reached a model. That is found by testing on the client's own transcripts.

Which rules apply, and where the platform helps

One row per text, as read on 7 October 2026. The second column says whom the text addresses. Where that is the client and not the centre, the rule reaches the centre as contract terms.

The ruleWho the text addressesWhat it asks forWhere the platform helpsWhat it does not cover
The rule: Digital Personal Data Protection Act, 2023, section 8(1), 8(2) and 8(5), and DPDP Rules, 2025, Rule 6 12The data fiduciary, which for most of a centre's work is the client. It reaches the centre, as data processor, through the contract. These provisions come into force in May 2027.Responsibility for processing done on its behalf, a valid contract with the processor, and reasonable security safeguards. Rule 6 lists masking and virtual tokens among its examples.Policy and masking set per client, and a record a processor can hand to its client.Notice, consent, retention, rights and breach reporting, which are the client's to decide.
The rule: Clients' sector rules in India: the Reserve Bank's outsourcing directions for commercial banks, IRDAI's regulation 51, SEBI's regulation 16C 34The regulated client: a bank, an insurer, a SEBI-regulated person. Not the centre.A provider's access to a bank's customer information is on a need-to-know basis. An insurer ensures that data parted to a provider remains confidential at all times. A SEBI-regulated person is solely responsible for investors' data in any AI tool it uses.The model receives less than the whole conversation, and the client can be shown what the system did.The agreement and the client's right to audit.
The rule: Card data: Reserve Bank circulars of 7 September 2021 and 28 July 2022 67; PCI DSS and the standards council's telephone-payments supplement of November 2018, which is guidance 5Entities in the card payment chain. Whether a centre is in that chain depends on what it does with the card.No entity in the chain other than issuers and networks stores actual card data. A verification code is not kept after authorisation, in a recording or anywhere else.A card number detected in the text is masked before the model call.The recording. A number that is not detected. PCI DSS scope.
The rule: If applicable: EU General Data Protection Regulation, Articles 3, 28, 32 and 44 to 46 8Controllers and processors within Article 3. Otherwise it reaches a centre through its client's processor contract. Which applies is for counsel.A processor contract; no further processor without the controller's prior written authorisation; security measures; and a transfer tool.The deployment can sit in the client's region, and the operator of a model holds less of each customer's data.Whether a model's operator is a further processor, and the transfer tool. Masked data that could be attributed to a person by the use of additional information is still personal data (Recital 26).
The rule: If applicable: EU Artificial Intelligence Act, Articles 50(1) and 5(1)(f) 9Article 50(1): providers of AI systems intended to interact directly with people. Article 5: anyone placing on the market, putting into service or using a prohibited system. Outside the Union, the Act applies where the system's output is used in the Union.Article 50(1): people are informed that they are interacting with an AI system, unless that is obvious; in application since 2 August 2026. Article 5(1)(f) prohibits the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the system is intended for medical or safety reasons; in application since 2 February 2025.It does not satisfy either. What a quality agent is asked to score is set in the flow, where the client can read and approve it.Both duties. Whether a given score falls under Article 5 is for counsel. Establish whether you are the provider or a deployer of each system you run.
The rule: If applicable: EU Digital Operational Resilience Act, Articles 28(1)(a) and 30(2) 10Financial entities in the Union. It reaches a centre as contract terms.The financial entity remains fully responsible, and its ICT contracts state where data is processed and how it is protected.A deployment per client, in the place the contract names.The contract.

This table states what the texts say and where one platform helps. It is not legal advice. Which rows bind your centre, and through which contract, is a question for your own counsel and your client's.

What it does not do

It does not redact audio. What is shown is text. We make no claim about recordings or live audio.

We publish no accuracy figure for code-mixed Hindi and English. Bring your own transcripts.

It does not approve the refund. A person does, and is named in the record.

It does not catch everything. A value that is not detected reaches the model as written. No guardrail catches every manipulated input.

It does not decide what your quality review may score. That is set in the flow, for you and your client to read and approve, and the table above says where counsel comes in.

It does not make an agent correct. The platform makes an agent accountable, which is what lets you find out whether it was correct.

It is not a certification of your deployment. ShepHertz operates a control environment credentialed for SOC 2, ISO 27001, HIPAA and GDPR. These are advisory alignments to inform your own assessment, not certifications of your deployment or binding regulatory claims.

More from the same floor: keeping card and ID numbers out of the model, the customer your guardrail blocked, orchestrating AI agents and Hinglish is a language.

Frequently asked questions

Can a BPO run AI agents separately for each client?

Yes. Each deployment sits in your cloud or your client's, with its own policies, masking rules and audit trail. What one client permits does not leak into another client's account.

Who approves a refund or a waiver when an AI agent is assisting?

A person. The flow stops at a checkpoint with a named approver group, escalation rules and an SLA timer, and the approval is recorded. Policy outside the model blocks actions that must never happen, whatever the model suggests.

How do we show a client what the AI did on its calls?

Every call leaves a signed Trust Receipt, and the audit trail is exportable and designed for an external party to verify. The Registry shows which flow, prompt and model were in production and who approved them.

What happens when the customer asks for a person?

The flow hands over to a human agent. A clean handoff to a human when the customer needs one is part of how the platform is used on a service floor.

Does this work on voice calls?

The platform works on the text of a conversation. On a voice call something else turns speech into text first, and what that system writes decides what the platform sees. We make no claim here about audio.

Can AI review every call for quality?

A quality agent can review the text of interactions for script adherence and compliance obligations and flag items for a person to review. What it scores is set in the flow, where you and your client can read and approve it. Where the EU's Artificial Intelligence Act applies, Article 5(1)(f) prohibits the use of AI systems to infer emotions of a natural person in the workplace, except for medical or safety reasons; whether a given score falls under it is for counsel 9.

Sources

The texts as they stood on 7 October 2026.

  1. 1Parliament of India: Digital Personal Data Protection Act, 2023 (No. 22 of 2023), assented to on 11 August 2023; sections 8(1), 8(2) and 8(5).
  2. 2Ministry of Electronics and Information Technology: Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), November 2025; Rules 1 and 6.
  3. 3Reserve Bank of India: Reserve Bank of India (Commercial Banks – Managing Risks in Outsourcing) Directions, 2025, 28 November 2025; paragraphs 9, 24 and 27.
  4. 4Insurance Regulatory and Development Authority of India: IRDAI (Protection of Policyholders' Interests, Operations and Allied Matters of Insurers) Regulations, 2024, regulation 51; and Securities and Exchange Board of India: SEBI (Intermediaries) Regulations, 2008, regulation 16C.
  5. 5PCI Security Standards Council: Information Supplement: Protecting Telephone-Based Payment Card Data, version 3.0, November 2018 (guidance), and PCI DSS v4.0 Self-Assessment Questionnaire D for Merchants, April 2022, Requirements 3.3.1 and 3.4.1.
  6. 6Reserve Bank of India: Tokenisation – Card Transactions: Permitting Card-on-File Tokenisation (CoFT) Services, RBI/2021-22/96, 7 September 2021.
  7. 7Reserve Bank of India: Restriction on Storage of Actual Card Data, RBI/2022-23/95, 28 July 2022.
  8. 8European Union: Regulation (EU) 2016/679, General Data Protection Regulation, applicable from 25 May 2018; Articles 3, 28, 32, 44 to 46 and Recital 26.
  9. 9European Union: Regulation (EU) 2024/1689, Artificial Intelligence Act, Articles 2(1)(c), 5(1)(f) and 50(1), with the application dates in Article 113 as amended by Regulation (EU) 2026/1744 of 8 July 2026.
  10. 10European Union: Regulation (EU) 2022/2554, Digital Operational Resilience Act, applicable from 17 January 2025; Articles 28(1)(a) and 30(2).
Topicscontact centre AI agentsagent assist with human approvalBPO AI per clientAI quality review call centreAI audit trail BPOAI agents for customer service

Written by

AgentAnywhere Research

The team that builds the platform and the models

AgentAnywhere Research writes about the platform, the model families and the trust layer we build and run in India. Where a figure is ours, it says what it covers; where something is a demonstration, it says so.

All articles →