Inspiration

A phone confirmation establishes what someone asked for, not whether an automated system is authorized to do it. Support teams need that distinction when voice agents propose consequential actions.

What it does

CALL-E makes an outbound confirmation call and returns a structured result. The adapter proposes a SafeOps action with the caller's words attached as an UNTRUSTED voice transcript. SafeOps checks permission, policy, contextual risk, and human approval before execution.

The demo reviews historical local records: a proposed $750 seeded refund required approval; human approval preceded execution; the refund action and step completed. A separate deterministic malicious-transcript fixture attempted an external-email action and was BLOCKED with a critical risk assessment and security incident. Without customer confirmation, the adapter returns NO_ACTION before submitting an action.

How we built it

The Python CALL-E SDK adapter uses create_and_wait and routes the outcome through SafeOpsClient.submit_action and the generic integration API. The historical real-call verification used the official CALL-E CLI; the repository also contains the Python SDK implementation. SafeOps uses Python, FastAPI, PostgreSQL, and a Next.js/TypeScript operator dashboard. The adapter does not directly execute the refund tool.

What was added during the hackathon

SafeOps core, authorization engines, dashboard, audit trail, generic API, and MCP adapter are pre-existing independent work. The submission-specific contribution is integrations/calle/: the CALL-E adapter, explicit payment/customer/amount scenario handling, no-confirmation handling, regression tests, and integration documentation. The integration was committed on September 9, 2026 (beb41de), followed by the payment-ID correction and regression tests on September 12 (ae429cb).

Challenges

An early hardcoded payment identifier could map a call to the wrong payment. The mismatch was found before approval, the request was rejected, and explicit scenario binding replaced the hardcoded identifier. Seven existing isolated adapter regression tests passed during this submission review, without calls, credentials, or a database.

The current historical record also shows a later outer-workflow failure: its objective did not match a deterministic workflow. The refund action is EXECUTED and its step COMPLETED, while the outer workflow is FAILED. Both states are preserved in the video; the submission does not claim the whole workflow completed cleanly.

Accomplishments and evidence boundaries

The integration demonstrates a phone-result-to-authorization boundary with an inspectable approval and audit trail. Evidence is author-reported one-call testing of a seeded/local refund, not a real payment or a universal exactly-once guarantee. The malicious case uses a synthetic transcript, not a real malicious call. No new real phone calls or product/security changes were made to produce this video. Community repository acceptance is not external application certification or hackathon judging approval.

Contribution PR: https://github.com/CALLE-AI/awesome-phone-call-agents/pull/519 Source repository: https://github.com/saikumar040060/safeops

What we learned

Voice content should remain untrusted even after confirmation. Scenario binding and backend authorization both matter. A voicemail or missing confirmation must not silently become permission for a refund.

What's next

Future work could improve outer-workflow lifecycle handling, add richer multi-action outcomes, and validate concurrent deployments. These are future directions; the current adapter uses a single-action polling flow.

Testing and access

The public Apache-2.0 source repository is the local test build. Follow README.md for the Docker-based backend/dashboard setup and seed a fresh local demo database. Keep the generated local credentials private. Follow docs/calle.md for adapter configuration. Run integrations/calle/test_agent.py with pytest for seven isolated tests; these require no CALL-E calls or live database. With a configured local SafeOps environment, integrations/calle/demo_malicious.py exercises the synthetic voice-transcript block without dialing. Inspect the dashboard execution and audit views to see the result. Running integrations/calle/agent.py places a real outbound call and requires the tester's own authorized CALL-E access and consenting recipient; it is optional for the isolated test path. A hosted public demo is not provided. Refunds affect seeded local records, not a production payment processor.

Video

The public demo is an edited walkthrough of existing app records and source excerpts, with an original synthetic Indian-English narrator. It is not a continuous live-call recording or a recording of the presenter's voice.

Built With

Share this project:

Updates

Submission history