Four layers, four boundaries. A failure in one does not reach the next.

Skinshells Voice in layers Request access
Layer two

Control

The layer that decides where a call goes. Its failure is partial rather than total — some flows work, some do not — which makes it the hardest of the four to diagnose without evidence.

In short
  • No appliance at any site
  • Configuration replicated between facilities
  • One dial plan across the estate
Function

What this layer does

Extensions, hunt groups, menus, queues, voicemail, recording and presence. Everything between a call arriving and a person answering it, expressed as configuration rather than as an appliance.

Removing the appliance removes a lifecycle: no licence bound to a chassis, no maintenance contract, no end-of-support date arriving at an inconvenient moment. For a multi-site estate it removes something larger — the divergence that occurs when each site configures its own system over a decade.

The failure mode is worth stating plainly. This layer fails partially. A menu misroutes, a group stops ringing, an out-of-hours rule fires at the wrong time. The symptom is confusion rather than silence, which is why per-flow evidence matters more here than anywhere else.

Sub-boundaries

The layers within

Four sub-boundaries, each holding a different kind of change.

Registration

Endpoints establishing and holding a session

Encrypted, auto-provisioned so a replacement handset configures on first boot. Failover between facilities requires no user or operator action.

Routing

Deciding where an arriving call goes

Time of day, opening hours, menu selection, group and hunt pattern. All configuration; the whole layer is data rather than code.

Retention

Holding recordings and voicemail lawfully

Recording configured per user or group, retained to your policy and no longer, with access restricted by role and each access itself recorded.

Replication

Ensuring no facility holds your call flows alone

Configuration replicated between facilities, so losing a location costs headroom rather than losing the routing logic.

  • A call flow nobody documented disappearing at cutover and being noticed by a customer
  • Recording enabled or retained inconsistently, producing a policy that cannot be defended
  • Administrative access accumulating until nobody knows who can change what
  • An endpoint too old to support current encryption being accommodated by weakening the configuration
  • A site losing connectivity and its calls having nowhere defined to go
Exposure

What this layer protects against

The risks here are less dramatic than at the connectivity boundary and considerably more common.

Fitting

How it is fitted

Months rather than weeks for a multi-site estate, most of it discovery.

  1. Measure

    Every route, menu, group, out-of-hours rule, integration and analogue endpoint documented. Ends on completeness, not on a date.

  2. Specify

    The target configuration built and walked through with each call flow owner before any user moves.

  3. Prove

    A pilot group chosen for coverage rather than convenience, deliberately including the awkward cases.

  4. Fit

    Users and sites in waves, incumbent system available until each wave is verified.

  5. Hold

    Role-specific guidance, then a review of queue and answer statistics once representative usage exists.

Evidence

What this layer produces

Estate-wide reporting

Answer rates, abandonment, queue duration and outcome across every site with one definition of answered.

Recording access log

Who listened to what and when, alongside the retention configuration.

Configuration history

Every change to a call flow, with before and after state and the identity that made it.

Endpoint inventory

Which models are deployed, their firmware, and any recorded encryption exception.

Questions

Asked about this layer

All questions answered

Often, where the models run current firmware and support modern encryption. We check the specific models. Where one cannot be operated securely we say so rather than weakening the layer to accommodate it.

Connected through analogue adapters and sought out explicitly during measurement. They are the most frequently missed item in a control-layer fitting and the most consequential to miss.

The layer observes those endpoints stop registering and applies the forwarding you configured. Other sites are unaffected — that boundary is the point of building it this way.

Configured per user or group to your policy, with access restricted by role and each access recorded. Retention is your decision; we implement and review it.

It requires connectivity, but not necessarily ours. It can sit above a trunk you already have, though the failure boundary is then partly outside our control and the design says so.

Applications

Where this layer is set differently

Small operations Where the containment boundary matters most, because nobody is watching. Open
Large organisations Where the change boundary carries the most risk. Open
Distributed teams Where the boundary sits outside the organisation entirely. Open
Contact operations Where capacity is a plateau rather than a peak. Open
Next

Ask about this layer specifically.

Name the symptom and the estate. The answer will be about your case rather than about the general one.