The layers
Each documented as a core function, the layers within it, what it protects against and how it is fitted. Not as a feature list, because a feature list does not tell you what happens when it fails.
Connectivity
The outermost layer, and the one whose failure is total for a site and invisible everywhere else. It answers a single question: can a call happen at all.
Authorisation
Establishing that your phone system is what it claims to beTransport
Carrying signalling and audio without exposureSelection
Choosing the way out, per callContainment
Bounding what a compromise can costThe threats at this boundary are specific and well understood, which is why the defaults are restrictive rather than convenient.
- Keeps the phone system you already own
- Concurrency from measurement, not headcount
- Multiple routes, selected per call
Control
The layer that decides where a call goes. Its failure is partial rather than total — some flows work, some do not — which makes it the hardest of the four to diagnose without evidence.
Registration
Endpoints establishing and holding a sessionRouting
Deciding where an arriving call goesRetention
Holding recordings and voicemail lawfullyReplication
Ensuring no facility holds your call flows aloneThe risks here are less dramatic than at the connectivity boundary and considerably more common.
- No appliance at any site
- Configuration replicated between facilities
- One dial plan across the estate
Numbering
The layer a caller actually touches. Its failure is the most commercially expensive of the four, because it is invisible to you and immediately obvious to them.
Eligibility
Establishing whether a range can be held at allEvaluation
Deciding where a call goesAuthority
Controlling what may be presented outboundCustody
Preventing a range being takenNumbers are identity, and the risks reflect that more than they reflect telephony.
- Geographic, national and toll-free ranges
- A guaranteed terminal destination on every number
- Volume and outcome reported per range
Operation
In a mature estate, change causes more incidents than component failure. That is why operation is a layer with a boundary rather than an activity that happens to the other three.
Request
Turning an outcome into a changeReview
Deciding whether and when a change is safeApplication
Making the change without widening the blast radiusVerification
Establishing that it did what was intendedAlmost everything here is a failure of process rather than of technology, which is what makes it tractable.
- Configuration held and maintained by us
- A rollback position before every change
- Reviews that compare capacity against measured use
Which layer you need
Most organisations arrive with a symptom rather than a layer name. Each of these maps to exactly one layer, which is usually the fastest way to decide where to start.
Which boundary matters most
The layers are constant. Which boundary matters most, and how much headroom sits behind it, is not.
Small operations
Where the containment boundary matters most, because nobody is watching.
Open Application BLarge organisations
Where the change boundary carries the most risk.
Open Application CDistributed teams
Where the boundary sits outside the organisation entirely.
Open Application DContact operations
Where capacity is a plateau rather than a peak.
Open