By Sagar Shankaran, Founder of CallSphere
Least privilege for AI agents at a regional carrier: scoped logins, no rights in the porting queue or 911 records, and a human on every irreversible action.
Key takeaways
Here is the question to sit with before you let any AI agent touch your operation: which button on your screens, if a machine pressed it at two in the morning, could you not un-press by breakfast?
At a regional carrier the list is short and it is always the same four. Releasing a customer's number on a port-out. Changing an address record that feeds the 911 database. Handing subscriber information to somebody who says they are law enforcement. And pushing a config change to the OLT or the edge router. Everything else — a credit, a ticket, an appointment, a password reset, a bill explanation — can be walked back before the coffee is cold. Those four cannot.
An ISP support address is a hole in the wall that any stranger on earth can type into. On a normal Tuesday it takes abuse complaints, copyright notices, 811 correspondence, reseller paperwork, a dozen "my internet is slow," and — a few times a year — something written specifically to fool whoever reads it first.
The convincing ones do not say "ignore your previous instructions." They read like this: an email on what looks like agency letterhead, marked as an emergency request, asking for the subscriber name and service address behind an IP address at a given timestamp, with a line at the bottom telling you not to notify the customer. Or a Local Service Request from a carrier you have actually done business with, attached to a letter of authorization with the account holder's signature on it, asking you to issue the firm order commitment on a number that happens to belong to the bookkeeper at the largest employer in your county. Or a chat message that says the account holder passed away and the family needs the number moved today.
Every one of those is designed for a tired human. Point an agent with real permissions at that inbox and you have built a tired human who never sleeps, never gets a bad feeling, and can act in four systems at once.
Zero trust for an AI agent means what it means for a new hire on day one: it gets its own login, it gets the fewest rights that let it do the job at all, and anything it cannot undo needs a named person to press the button.
Hear it before you finish reading
Talk to a live CallSphere AI voice agent for IT support in your browser — 60 seconds, no signup.
Until this year the agents most carriers had touched could only talk. They summarized a ticket, drafted a reply, explained a bill. Read-only tools have a small blast radius: the worst outcome is a wrong sentence a person catches.
In 2026 the agents can act. They send, they pay, they book, they file. Claude Cowork landed in January and ChatGPT Work in July, both built so that a non-technical person hands over a goal and gets finished work back, with the tools connected to real accounts. The moment that happened, two old software problems became operating problems for a phone company: text arriving from outside that the agent treats as an instruction, and permissions that are broader than the job. The accepted answer settled this year and it is not exotic — least privilege, credentials scoped to one job, and a human on anything irreversible.
flowchart TD
A["Request lands in the support inbox"] --> B["Agent reads it with no rights to act"]
B --> C{"Does it touch a number, a 911 record, or subscriber data?"}
C -->|No| D["Agent drafts the reply and updates the ticket"]
C -->|Yes| E["Agent stops and opens a hold ticket"]
E --> F["Named person calls back on a published main number"]
F --> G{"Verified against the account?"}
G -->|Yes| H["Human presses the button in the port desk"]
G -->|No| I["Logged as an attempt, account holder notified"]
You already know how to do this. When you hire a rep in March, you do not hand her the porting queue, the router passwords and the records-request folder on day one. You give her Sonar or Powercode or iVUE with read on billing and write on tickets, and she earns the rest. Do exactly that, and write it down.
Give the agent its own named account in the billing system, not a shared one and never the owner's. Read on account status, balance and plan. Write on tickets and appointments only. No rights at all in the number-porting queue. No rights in the tool that updates the address record that feeds the 911 database. No console, no read-write on the OLT, no RADIUS write, no ability to change a service address. Cap what it can do with money: let it apply a one-month credit up to whatever number your rep already has authority for, and require a person above that. Have it use one login per job, so that when something goes wrong you can turn off the support agent without turning off the 811 screening job.
Then close the two doors nobody thinks about. First: the agent must not treat anything a customer typed as an order. Text in a ticket is evidence, not instruction. Second: whatever the agent does gets logged where your general manager can read it in plain English — who, what, when, on which account — because six months from now during your annual CPNI certification you will be asked how you control access to customer information, and "the AI handled it" is not an answer.
Scoping is nearly free. It is permission settings in software you already pay for. Assume six hours of your network engineer and two hours of your general manager, at a loaded $85 an hour: $680, once. Now price the other side, using your own numbers and an honest guess at odds.
| Event | Cost if it happens | Assumed odds in a year | Expected cost |
| Fraudulent port-out completed | $2,700 lost lifetime value, plus 6 hours unwinding at $85 | 1 in 8 | $401 |
| Subscriber data released on a fake emergency request | 14 hours of GM and outside counsel review at a blended $260 | 1 in 10 | $364 |
| Wrong 911 address pushed to the database | Not priceable | — | — |
| Config change to the edge router outside a window | 90-minute outage, 1,800 subscribers, callout crew, credits | 1 in 6 | ~$1,100 |
Assumptions: 1,800 affected subscribers, $79 average revenue per subscriber per month, a 34-month expected life on a rural fiber account, and odds that are illustrative, not measured. Even at those cautious guesses the expected annual cost of not scoping runs several times the one-time cost of scoping — and the row with no price on it is the one that should decide it for you.
Four things, permanently. Port-out approval: your rep verifies the account holder using the authentication you already owe them under the FCC's port-out and SIM-swap rules, and the notification goes out immediately. Any request for subscriber records from anyone claiming legal authority: one named custodian of records, and a hard rule that verification is a callback to the agency's published main number, never the number in the email. Any change to an address record that feeds the 911 database. And any write to the OLT, the edge router or the routing announcements — change ticket, maintenance window, second set of eyes, the way you already do it.
Still reading? Stop comparing — try CallSphere live.
See the IT support AI agent handle a real call — complete, industry-specific, and live in your browser. No signup.
Two other honest limits. An agent cannot tell a real subpoena from a forged one — neither can your rep, which is the whole point of the callback rule. And approval fatigue is real: if you route forty things a day to the general manager for approval, by Thursday he is clicking yes without reading. Keep the approval list short enough that each one still gets a look.
Do not begin with software. Begin with a sheet of paper and your operations manager, and write down every action any of your systems can take that cannot be reversed inside an hour. At a carrier that list comes to somewhere between eight and fifteen items, and half of them will surprise you — the disconnect script that also releases the IP assignment, the bulk credit tool, the tool that changes a service address.
Next to each one, write the name of the person who is allowed to do it. Not a department, a person, plus a backup. That sheet is your permission policy, and it is useful whether or not you ever turn on an agent, because it is also the answer you owe your auditor and the thing your insurer will ask for after an incident. Then, and only then, give the agent a login and take away everything not on the safe side of that sheet.
It is the opposite. At eight people everyone has every password because that is how you get through a storm night. That worked when the shared login was used by someone who knows the Hendersons. It stops working the moment a piece of software is holding that login and reading mail from strangers.
Probably not, but do not answer that from the hip. The high-risk and transparency obligations carry a 2 August 2026 compliance date and can reach US companies whose systems affect users in the EU. What definitely binds you is closer to home: Texas TRAIGA and California SB 53 both took effect 1 January 2026, and Colorado, New York, Utah, Nevada, Maine and Illinois have statutes of their own. Federal preemption is unsettled as of this month, so state law still binds.
Read, yes — summarizing alarms and writing the shift handoff is one of the better uses of it in a small NOC. Write, no. There is no version of "the agent cleared the alarm by changing the config" that ends well at 3am with one person on call.
Because you can read the log. Insist on a record that shows, in plain English, every action taken and the account it touched, retained as long as you retain call recordings. If a vendor cannot show you that screen during the demo, they do not have it.
Most of what the public sends you is not an attack; it is somebody who wants their internet fixed or an appointment booked at 9pm. CallSphere builds the voice and chat agents that handle exactly that traffic — answering the line, booking the install, capturing the lead — and the right way to run one is scoped: it books and it writes tickets, it does not touch your porting queue or your 911 records. Ask any vendor, including us, to show you the permission screen before you show them your customers.

Written by
Sagar Shankaran· Founder, CallSphere
LinkedInSagar Shankaran is the founder of CallSphere, where he builds production AI voice and chat agents deployed across healthcare, hospitality, real estate, and home services. He writes about agentic AI, LLM engineering, and shipping voice agents that handle real calls in production.
See how AI voice agents work for your industry. Live demo available -- no signup required.
Charter fraud meets AI that can act. What a Part 135 operator must keep human, how to scope Avinode and inbox access, and the arithmetic of the approval click.
The irreversible actions in a precision machining shop that must keep a human in the loop, and how to scope everything else an AI assistant touches in 2026.
Cargo release is the one irreversible action a ship agency must keep human. How to scope AI logins across CargoWise, Navis N4, gate systems and the bank.
Least privilege for CDMO agents: keep lot disposition human, scope Vault, LabWare and SAP rights, and close the supplier CoA door. With worked numbers.
Non-cancellable POs, remit-to fraud and DFARS flags: how MRO distributors scope AI agent access in Prophet 21 and SX.e, plus what a bad release actually costs.
Guest notes, vendor emails and reviews become instructions once your agent can act. The restaurant actions that must always keep a human manager in the loop.
© 2026 CallSphere Inc. All rights reserved.
Made within San Francisco
Watch how CallSphere handles real customer calls, schedules appointments, and processes payments — live.
Try Live DemoBook a DemoCalculate Your ROI