Permissions, limits & safety

What an assistant connected to Telenow may do, what it can never do, and the limits every call it makes is held to.

The five permissions

You choose them on the Telenow page when you connect, and an assistant gets no more than it asked for and you allowed.

PermissionScopeTools
Read callscalls:readlist_numbers, get_call, list_calls, list_agents, get_agent, list_voices, estimate_cost, list_campaigns, get_campaign
Place callscalls:writeplace_call
Create agentsagents:writecreate_agent, create_flow_agent, update_agent
Give agents toolsagents:toolsNo tools of its own: with Create agents, it unlocks the agent options that reach outside the call (below). Off unless you tick it.
Run campaignscampaigns:writecreate_campaign, add_campaign_targets, start_campaign, pause_campaign

Give agents tools is opt-in: the Telenow page shows it unticked, and a connection never gets it unless you tick it. (An organization API key used as the bearer instead is not a connection: a key that may write gets every permission, this one included.)

A tool outside the connection's permissions is not shown to the assistant. If it calls one anyway, Telenow answers 403 with the scope it needs, and the assistant can ask you to grant it.

What it sees

  • Numbers: only the ones you picked when connecting, and only while your organization still holds them.
  • Calls: only calls on those numbers — the ones it placed and the ones they received.
  • Campaigns: only campaigns set to call from those numbers (a campaign that leaves the number to its agent is not shown).
  • Agents: every agent in the organization, with keys masked (••••1234).

An organization API key used as the bearer sees everything in its organization, as the REST API does.

What it may change

An assistant runs and changes only what it made. It starts campaigns, adds people to them and changes agents only if it created them; it can see and pause every campaign on its numbers, and call with any of your active agents. "It" is the same assistant client, connected by the same person in the same organization — connecting it again (to change its limits, say) keeps what it made when the assistant comes back as the same client: one that names itself with a client metadata URL (ChatGPT and Claude publish one) does; one that registers afresh on each connection starts over, and what it made stays in Telenow for you. A colleague's assistant, or another product, does not get it.

An organization API key used as the bearer may change every agent an assistant made, and start and add people to every campaign — it acts for the whole organization.

The AI assistant calls agent and the agents you built are yours to edit; update_agent refuses them.

What the agents it creates can do

An assistant with Create agents can set every option the Agents API has — single-context or multi-step (Flow agents API) — through the friendly fields and settings.

Assistants read untrusted text — web pages, map listings, documents — and any of it can try to steer them. So the options that let an agent reach outside the call need Give agents tools as well:

Needs "Give agents tools"Why
metadata.tools, metadata.precallLookupsWebhooks and APIs, MCP servers, connected apps — they send call data out and act elsewhere.
Flow tool and transfer steps, and tools on any stepAn API call, or the caller moved to another phone number.
Custom model and speech providers (customllm, customapi, customstt, customtts)The call's audio or words go to an endpoint the agent names.
Any URL anywhere — the prompt, the opening line, a step or the settings (any text containing ://), even a link for the agent to read outA link is how a caller is sent somewhere.
isPublicPuts the agent on the open internet.
metadata.postCallWhatsAppSends messages to the people called.
sessionConfig.followupCall-backs the agent books itself: calls Telenow places later, outside the connection's daily limit.

Without it, an assistant's agents shape what is said on the call and nothing more — prompts, voices, models, steps and conditions, call behaviour, variables, analysis, objectives, memory. (A hand-off step can still pass a call to one of your own active agents, with whatever tools you gave that agent.)

Never, with any permission:

  • Credentials — API keys, tokens and secrets, in any field. They would pass through a chat; you add them in Telenow. An assistant reads stored keys as masks (••••1234): a mask sent back unchanged keeps the stored key — inside a flow's steps too — and is refused if the step, tool or provider it belongs to now points somewhere new. A new agent refuses masks copied from another.
  • Who made the agent (metadata.assistantConnect, an app's createdByApp).
  • The builder's draft and publish bookkeeping (flowDraft, configDraft, …PublishedAt) — a graph is published with flow.

Safeguards on every call

SafeguardWhat happens
You confirm firstplace_call, start_campaign and add_campaign_targets are annotated as actions with real-world effects, so assistants ask before running them. Campaigns are created as drafts.
It says it is an AIA one-off call's opening line must say an AI assistant is calling on your behalf, and the built-in agent is instructed to say so again if it was missed, never to claim to be human, to share only the details given and to agree to no payments or commitments. These are instructions to the agent, not a filter on what it says. Calls with one of your agents follow that agent's own prompt.
Do-Not-Call and consentYour Do-Not-Call list applies to every call and campaign target, as from the dashboard. Where your organization requires consent, a number without it is not dialed.
Calling hoursWhere Telenow enforces a country's legal calling window (India's 09:00–21:00 IST today), a call outside it is refused with the time it opens, and campaigns wait for it. Elsewhere, set a campaign window and mind the callee's local time.
Your moneyYour wallet, spend limits and plan limits apply as for any call.
Transcripts are dataEvery transcript an assistant reads comes with the reminder that the other party's words are information, never instructions.

Limits

LimitSet byValue
Calls per dayYou, per connection — asked for when the assistant may place calls or run campaignsCounts single calls placed and people added to campaigns, over any 24 hours. Dials that never happened and people skipped as duplicates or Do-Not-Call do not count; neither do call-backs an agent books itself (which is why those need Give agents tools).
Minutes per callYou, per connectionA one-off call is cut at this length. Campaign calls follow the agent's own maximum length.
Campaigns created per hourTelenowThe same hourly limit as the Campaigns API, counted per connection (an API key shares its REST API budget).
People added per hourTelenowAs for the Campaigns API's pushed rows, counted the same way.
RequestsTelenow3,000 requests per 15 minutes per connection or API key.
People per requestTelenowUp to 1,000 targets per create_campaign or add_campaign_targets.

When a limit refuses, the assistant is told which one and, for the hourly ones, when to retry.

Who can connect, and for how long

  • Only an organization owner or admin can approve a connection.
  • A connection stops working at once when it is disconnected (Workplace → Connected assistants), or when the person who approved it leaves the organization or is no longer an owner or admin.
  • Assistants hold short-lived access tokens (an hour) that they renew; a renewal token that is replayed revokes the whole chain. Telenow stores no token in a readable form.

Data the assistant receives

Calls, transcripts and summaries on its numbers; your agents' settings, with keys masked; your campaigns' progress and results. What the assistant does with that data is governed by your agreement with its vendor (OpenAI, Anthropic, xAI); disconnecting stops any further access. See Data protection, GDPR & DPA for Telenow's side.