Security, Compliance and BrandAudit and oversight

Audit and oversight

How to evidence what a digital worker did: call recordings and transcripts, call quality assessments, knowledge base version history, approval trails, and CRM write-back.

"What did the AI actually say?" is a question you will eventually be asked - by a rep, a customer, a security review, or your own legal team. 11x produces an audit trail across five surfaces: call recordings and transcripts, call quality assessments, knowledge base version history, approval trails, and CRM write-back.

Set this up before you need it. The uncomfortable version of this question arrives after an incident, and by then the useful thing is a record that already exists rather than one you start building.

The five audit surfaces

SurfaceWhat it evidences
Call recording, transcription, summarizationEvery call, verbatim - what was said, promised, and disclosed
Assessments and Smart OutcomesCall quality evaluation and structured outcomes at scale, so quality is auditable rather than assumed
Knowledge base version historyWhat changed, when, and by whom, with rollback
Approval trailWho signed off on messaging, where an approval workflow is in use
CRM write-backThe durable record - interactions, transcripts, scores, and outcomes on the account

Why CRM write-back is the important one

The other surfaces live in 11x. CRM write-back puts the record where your reporting, your reps, and your retention policies already are - and where it survives any change to your 11x configuration.

Confirm transcripts, qualification results and outcomes land on the objects and fields your reporting expects, and fix mapping early. Backfilling misplaced CRM data later is painful and usually incomplete. See security and data handling.

Transcripts contain what a prospect actually said, verbatim - potentially commercial detail, personal circumstances, or information about third parties. Decide deliberately who can read them, and avoid piping full transcripts into systems with broad internal access.

A practical oversight cadence

Weekly: sample auto-sent replies

Especially objection-category replies, where a confident wrong answer does the most damage. See smart replies.

Monthly: read disqualified transcripts

This is where the expensive mistakes hide. A wrongly disqualified good lead disappears without anyone reporting it.

Monthly: collect flagged meetings from reps

Formally. Unflagged bad meetings mean thresholds stay wrong and trust erodes quietly.

On every change: use version history

Change one thing at a time so a shift in results can be attributed.

Quarterly: audit access

Who holds admin rights, and whether any integration is still authorized with personal credentials.

What to capture for a security review

Reviews tend to ask the same things. Have these ready:

  • Which data each worker processes - see security and data handling
  • Encryption in transit and at rest, and hosting
  • Certifications: SOC 2 Type II, CASA Tier 3, GDPR, CCPA - see the trust center
  • Whether models are trained on your data (they are not - data is used only in aggregate and anonymised form)
  • Retention and subprocessors
  • Access controls and CRM permission scoping
  • Recording disclosure configuration

Frequently Asked Questions

Next steps

Need help?

Email support@11x.ai, or book time with the team.