Asenda Talk
Two customer support agents wearing headsets working at their desks in a modern office setting.

Photo by MART PRODUCTION on Pexels

Two voice agents become one identity when they share a credential, because the audit trail can record the credential but cannot reliably distinguish which agent used it. Separate credentials per agent are the minimum requirement for defensible attribution, access control, and incident review.

At 8:17 on a Monday morning in Accra, Ama opened a disputed call record while her tea cooled beside the keyboard. She led a small support desk, knew every escalation path by memory, and had already listened to the same tense exchange twice. The caller said one agent had accessed an account tool after consent was withdrawn. The operations log showed the tool call, its timestamp, and a valid credential.

It did not show which agent had acted.

This scene is an invented composite, but the control failure is concrete. Two configured agents, one shared secret. One handled English support calls; the other was being evaluated for Twi and English conversations. Both appeared distinct in the dashboard. At the access boundary, they had the same identity.

A shared credential erases the distinction that matters

Ama could inspect each agent’s persona, first message, and voice. She could compare the call lifecycle events and confirm that the disputed interaction had occurred. The audit trail preserved activity, but its strongest attribution stopped at the shared credential.

That left three possibilities. The expected agent made the tool call. The other agent used the same credential through a configuration error. Or a human operator used it during testing. Each path pointed to the same principal in the access record.

The support desk needed to decide whether to suspend one agent before the afternoon queue began. Suspending the wrong one could leave callers without the intended support route. Leaving both active could allow the disputed behavior to happen again.

The logs were present. The evidence was still insufficient.

Call-truth tracking answers essential questions about the telephony lifecycle: whether a call started, connected, ended, or triggered recorded events. Consent and opt-out records establish another part of the chain. Neither can recover an identity distinction removed before the action was logged.

Agent configuration and agent identity are different controls

Giving two agents different names does not give them different security identities. Neither do separate personas, voices, prompts, or opening messages. Those settings shape how an agent behaves in a conversation. Credentials determine what an access system can attribute and permit.

A defensible setup binds each agent to its own credential or narrowly scoped service identity. The resulting record should connect the call, agent configuration, runtime, tool action, consent state, and credential used. If one agent behaves unexpectedly, an operator can disable its access without disabling every agent that depends on the same secret.

Scope matters too. An appointment agent should not inherit an account-change permission because both run through the same orchestration layer. Each agent should receive only the tools required for its assigned job. Where an action carries greater risk, the system should require a separate confirmation or human handoff. This is especially important when speech recognition could affect the interpretation of a correction, as explored in Twi Speech Recognition: Why Account Changes Need Human Confirmation.

Secret handling must support that separation. Asenda Talk includes write-only, masked, environment-aware admin secret management, so operators can manage credentials without exposing stored values in ordinary views. That control helps protect secrets. Teams still have to issue distinct credentials, scope them correctly, and rotate them when attribution is compromised.

The audit trail can only preserve distinctions created upstream

With the afternoon queue approaching, Ama made the only defensible decision available: she paused tool access for both agents. The shared credential was rotated, and each agent received a separate identity before access could return.

The change arrived just in time to prevent another unattributable tool action. It could not settle the original dispute. No later inspection could reconstruct which actor had used a credential that represented all of them.

This is the same reason consent, budget ownership, and escalation rules must be assigned before calls begin. Documentation added after an incident explains intent, but it cannot replace evidence captured at the moment of action. What Happens When Consent, Budget Ownership, and Escalation Rules Are Undocumented? examines that wider operating problem.

Asenda Talk is in active early access. It can create and configure voice agents, run Vapi-orchestrated assistant sessions, track telephony lifecycle events, record consent and opt-out activity, and meter usage behind an operator-controlled real-money gate. Native Twi speech recognition and synthesis are built and fine-tuned in-house, with more African languages in progress. Outbound calling remains gated while the live telephony-provider decision is unresolved.

Those capabilities create useful evidence, but evidence architecture still depends on deployment choices. A complete call record attached to a shared credential remains an incomplete answer to the question that matters: who acted?

Make identity separation a release gate

Before activating tool access, list every agent, runtime, human operator, and environment that can perform an action. Give each one a distinct identity. Then test whether an investigator can move from a disputed call to the exact agent, credential, tool permission, consent event, and operator decision without relying on someone’s memory.

Fail the release if two actors collapse into one audit principal. Do the same if a credential appears in logs, configuration exports, or routine admin views. For outbound calling, keep the real-money gate closed until the provider, identity boundaries, consent handling, opt-out path, and escalation owner are explicit.

By late morning, Ama’s dashboard showed two agents again. This time, the access records did too.

Asenda Talk

A self-serve platform for building and running voice AI agents, built on native African-language speech (Twi, with more languages in progress) instead of a wrapper around a third-party voice API.

Try Asenda Talk

Comments

No comments yet.