Control
The layer that decides where a call goes. Its failure is partial rather than total — some flows work, some do not — which makes it the hardest of the four to diagnose without evidence.
- No appliance at any site
- Configuration replicated between facilities
- One dial plan across the estate
What this layer does
Extensions, hunt groups, menus, queues, voicemail, recording and presence. Everything between a call arriving and a person answering it, expressed as configuration rather than as an appliance.
Removing the appliance removes a lifecycle: no licence bound to a chassis, no maintenance contract, no end-of-support date arriving at an inconvenient moment. For a multi-site estate it removes something larger — the divergence that occurs when each site configures its own system over a decade.
The failure mode is worth stating plainly. This layer fails partially. A menu misroutes, a group stops ringing, an out-of-hours rule fires at the wrong time. The symptom is confusion rather than silence, which is why per-flow evidence matters more here than anywhere else.
The layers within
Four sub-boundaries, each holding a different kind of change.
Registration
Endpoints establishing and holding a sessionEncrypted, auto-provisioned so a replacement handset configures on first boot. Failover between facilities requires no user or operator action.
Routing
Deciding where an arriving call goesTime of day, opening hours, menu selection, group and hunt pattern. All configuration; the whole layer is data rather than code.
Retention
Holding recordings and voicemail lawfullyRecording configured per user or group, retained to your policy and no longer, with access restricted by role and each access itself recorded.
Replication
Ensuring no facility holds your call flows aloneConfiguration replicated between facilities, so losing a location costs headroom rather than losing the routing logic.
- A call flow nobody documented disappearing at cutover and being noticed by a customer
- Recording enabled or retained inconsistently, producing a policy that cannot be defended
- Administrative access accumulating until nobody knows who can change what
- An endpoint too old to support current encryption being accommodated by weakening the configuration
- A site losing connectivity and its calls having nowhere defined to go
What this layer protects against
The risks here are less dramatic than at the connectivity boundary and considerably more common.
How it is fitted
Months rather than weeks for a multi-site estate, most of it discovery.
-
Measure
Every route, menu, group, out-of-hours rule, integration and analogue endpoint documented. Ends on completeness, not on a date.
-
Specify
The target configuration built and walked through with each call flow owner before any user moves.
-
Prove
A pilot group chosen for coverage rather than convenience, deliberately including the awkward cases.
-
Fit
Users and sites in waves, incumbent system available until each wave is verified.
-
Hold
Role-specific guidance, then a review of queue and answer statistics once representative usage exists.
What this layer produces
Estate-wide reporting
Answer rates, abandonment, queue duration and outcome across every site with one definition of answered.
Recording access log
Who listened to what and when, alongside the retention configuration.
Configuration history
Every change to a call flow, with before and after state and the identity that made it.
Endpoint inventory
Which models are deployed, their firmware, and any recorded encryption exception.
Often, where the models run current firmware and support modern encryption. We check the specific models. Where one cannot be operated securely we say so rather than weakening the layer to accommodate it.
Connected through analogue adapters and sought out explicitly during measurement. They are the most frequently missed item in a control-layer fitting and the most consequential to miss.
The layer observes those endpoints stop registering and applies the forwarding you configured. Other sites are unaffected — that boundary is the point of building it this way.
Configured per user or group to your policy, with access restricted by role and each access recorded. Retention is your decision; we implement and review it.
It requires connectivity, but not necessarily ours. It can sit above a trunk you already have, though the failure boundary is then partly outside our control and the design says so.