cx-call-recording-governancelisted
Install: claude install-skill rulebase-co/rulebase-skills
# Call recording governance
Recordings are the highest-risk data a support operation holds and the least governed,
because they usually live in the telephony system rather than the helpdesk — owned by a
different team, with its own retention, its own access model, and frequently outside every
review that covers "support data".
Everything in this skill is a consequence of one fact: **a recording cannot be
selectively edited the way text can.** Redaction, minimisation and partial disclosure all
work differently, and most text-derived policies do not transfer.
Requirements vary by jurisdiction — notification, consent, and whether all parties must
agree all differ. **Nothing here states a legal requirement.** This is the operational
review; the determination is legal's.
## Notification and consent
- **Before recording starts.** A notification played after the recording begins has not
notified anyone about the part already captured. Check the sequence in the system
configuration, not just the script.
- **On every path.** Inbound, outbound, callbacks, transfers, conferences, voicemail, and
calls that begin as something else. **Transfers and conferences are the routine gap** —
a customer notified once at the start may be joined later by a third party under a
different arrangement.
- **Outbound calls** need their own handling, and the notification cannot be assumed from an
inbound script.
- **Agent-side recording of their own screen or voice** is employee monitoring