Trust model
A phone call is input, not authority.
Concierge checks identity, authority, policy, capability, commercial state, and effect state before a phone action can reach the outside world.
1. Who Concierge trusts
Native Codex remains the semantic work authority. Verified account and call-time provenance establish owner context.
A phone number, caller ID, model statement, or external voice claim cannot create owner authority.
2. External callers stay isolated
An admitted external caller can provide task input for the current interaction.
The caller does not inherit owner authority, unrelated Codex context, current owner context, or private owner notes.
3. Caller ID is not enough
Caller ID can identify an owner candidate. Owner-only phone context needs durable enrollment and exact call-time authentication after trusted carrier ingress.
4. Purpose can only narrow
A permitted personal or transactional purpose lets evaluation continue. Purpose cannot create identity, contact permission, commercial capacity, or effect authority.
5. Final effect checks remain authoritative
- Account and entitlement
- Owner or contact authority
- Communication policy and quiet hours
- Current native root and paired-computer readiness
- Occupancy and phone allowance
- Destination and provider readiness
- Stable effect identity and replay protection
6. Uncertain outcomes stay uncertain
Concierge does not convert a timeout into an assumed failure. It reconciles provider-authoritative state before another consequential attempt.
7. Native context and operational data are different
Codex owns the authoritative native conversation and work context.
Concierge keeps bounded operational state for account, phone, routing, contacts, policy, allowance, usage, readiness, and continuity coordination.
8. Scheduled rechecks use fresh state
A scheduled recheck can revisit the same supported native Codex work later.
The wake grants no phone authority and reserves no phone allowance. A later phone action must pass current checks again.
9. Commercial boundaries
Allowance admission is separate from native reasoning. Low phone allowance does not give the model permission to invent another carrier channel.
10. Provider capability is not product capability
Telnyx is the canonical production carrier. Twilio remains fallback and reference.
A carrier feature exists only as a Concierge capability when the current product exposes it through the authorized phone path.
11. Current beta availability
Some phone and Windows paths are still being validated for the current beta. See Current availability and limits for the latest supported boundaries.
12. What these controls do not mean
These controls reduce risk. They do not make software or telecom systems immune from compromise.
Trust diagrams
Who can authorize an owner action
Verified owner / native context
↓
Authority checks
↓
Allowed owner action
External caller
↓
Task input / isolation
└── NO owner-authority pathVerified owner and native context still pass authority checks before an owner action. An external caller remains isolated as task input and has no owner-authority path.
The diagram omits credentials, sensitive identifiers, and database details.
Phone event flow
Phone event ↓ authenticate + route ↓ owner or external ↓ bound native context ↓ policy + effect checks ↓ provider action ↕ outcome reconciliation
Concierge authenticates and routes a phone event before it binds native context. Policy and effect checks occur before provider action, and uncertain outcomes reconcile afterward.
The diagram omits credentials, sensitive identifiers, and database details.
Scheduled recheck
native Codex work ↓ scheduled recheck ↓ later wake ↓ read CURRENT work + authority + limits ↓ no phone action OR newly authorized guarded action
A scheduled recheck returns to current native work. The recheck reads current authority and limits before deciding whether any newly authorized phone action is appropriate.
The diagram omits credentials, sensitive identifiers, and database details.