Access check (Validation)
Overview
An access check stands in front of something and decides who is allowed to reach it. It can ask for a PIN code, or recognize the caller by their phone number, by your contact list, or by the labels on their contact card. Callers who pass go on to whatever you put behind the check; callers who are turned away go somewhere else, or hear a message and stop.
Use it to protect a private menu, a members-only audio player, a message box, or the whole hotline.
In the sidebar this lives under Advanced → Validations. Everywhere a destination is picked, and on My Hotline, it is called Access check.
How It Works
- The caller reaches the access check.
- The check decides whether it recognizes them:
- PIN Code asks them to type a PIN.
- The other four types look at the number they are calling from.
- If they are recognized and you asked for extra proof, they confirm their name or type their Personal PIN.
- If they are not recognized and you allow it, they can identify themselves by typing their registered phone number or their Personal ID.
- Callers who pass follow the If the caller passes route. Everyone else follows If the caller is turned away.
Who gets through
Pick one Validation Type. On My Hotline the same field is called Who gets through?, with friendlier wording in brackets below.
- PIN Code (Caller must enter a PIN code) — Every caller types the same PIN. Nobody is recognized by their phone number.
- Contacts (Only chosen contacts) — You pick the contacts by hand in Select Contacts.
- All Contacts (Anyone saved in my contacts) — Anybody whose number is saved on any contact in your address book. Nothing to pick.
- Phone Numbers (Specific phone numbers) — A plain list of numbers you type in, with no contact cards behind them.
- Labels (Contacts with certain labels) — Anybody whose contact card carries one of the labels you pick in Select Labels. See Labels.
Settings per type
-
PIN Code (required, PIN type only) — The digits callers must enter. Any length works; the caller can also press
#to finish early. -
Phone Numbers (Phone Numbers type only) — Click Add Phone Number for each number. Each row uses an international phone box, so pick the country and type the number.
-
Select Contacts (Contacts type only) — Searchable, pick as many as you like.
-
Select Labels (Labels type only) — Searchable, pick as many as you like. A caller passes if their contact carries any one of them.
-
Validation Mode — Shown for Contacts, All Contacts and Phone Numbers:
- Allow Listed Numbers — only the listed callers continue.
- Block Listed Numbers — the listed callers are turned away and everybody else continues.
For All Contacts the app spells it out: "Allow: only callers saved as a contact continue. Block: every saved contact is turned away."
A Labels check and a PIN check have no mode. Labels always work as an allow list.
Asking for proof
A recognized caller ID is convenient, but it is not proof — phones get shared, and numbers can be spoofed. These two settings sit in the Validation Configuration section (on My Hotline they are in If we don't recognize them).
Verify every matched caller by
Shown for Contacts, All Contacts and Labels checks that are set to allow. It applies to everyone the check lets in: a recognized caller ID and a caller who typed their own number both go through it.
- Nothing — a match is enough (default) — A matched contact passes straight through, and the whole rest of the call runs as that person: exam results, list joins and later access checks all count for them. Anyone calling from a member's phone gets in as that member. Fine for convenience, not for security.
- Confirm their name (press 1 for yes, 2 for no) — The system reads the matched name out loud: "Are you Chaim Levy? Press 1 for yes, 2 for no." This catches a shared family number, but an impostor can simply press
1. - Their Personal PIN from the contact card — The caller must type the Personal PIN saved on their contact, even when their caller ID is already recognized. Real proof. A contact with no PIN set yet is turned away, so set PINs before you choose this.
- Confirm their name, then enter their PIN — Both, in that order. A contact with no PIN set yet passes on the name alone.
If several contacts share the number the caller typed, answering "no" to the name question offers the next one, and after the last one the check starts over with "okay, let us try again".
With PIN verification, several contacts can share one number too: the PIN the caller types is checked against every contact on that number, and the caller is treated as whichever one it belongs to. Two brothers on the house line can each use their own Personal PIN.
Let unrecognized callers identify themselves
A toggle, hidden on PIN checks and on block lists.
When the caller ID is not recognized, the caller is asked to enter the phone number they are registered with, or the Personal ID from their contact card, followed by #.
- Seven digits or more is treated as a phone number; fewer digits is treated as a Personal ID.
- Three attempts. Whoever fails follows the "turned away" route — point that route at the next step if you would rather let them continue anonymously.
- Whoever succeeds then goes through the verification you chose above.
- On a Phone Numbers check there are no contact cards, so the number they type must itself be on your list.
Once a caller identifies themselves, the rest of the call runs as that contact — the exam they take is filed under their name, and a later access check on their label lets them through.
Prompt recordings
A collapsed section called Prompt recordings (on My Hotline: What callers hear). Every one is optional: leave it blank and the caller hears the spoken default. Each can be uploaded, recorded in your browser, taken from a library, or generated as speech — see Recordings.
| Recording | When it plays | Shown for |
|---|---|---|
| "Enter your PIN" | Asking for the PIN | PIN checks |
| "Wrong PIN, try again" | After a wrong PIN, with attempts left | PIN checks |
| "Too many wrong attempts" | After the last failed PIN attempt, before the turned-away route | PIN checks |
| "We don't recognize your number" | Asking an unknown caller for their number or ID | When self-identify is on |
| "Enter your personal PIN" | Asking a matched contact for their Personal PIN | Verification set to PIN or name + PIN |
| "We couldn't verify you" | When a matched contact has no PIN to check against, before the turned-away route | Verification set to PIN or name + PIN |
PIN attempts
A PIN check gives the caller three tries. After a wrong PIN the system says how many are left ("you have 2 attempts remaining"), or plays your own "Wrong PIN, try again" recording instead. After the third failure it plays the "Too many wrong attempts" audio and follows the turned away route.
Wrong PINs are written to the call trace, so you can see what was tried on the call trace.
Routing
Set both in the Routing Configuration section.
| Route | When it fires |
|---|---|
| When Success (My Hotline: If the caller passes) | The caller passed the check |
| When Validation Fails (My Hotline: If the caller is turned away) | Wrong PIN three times, not on the list, blocked, or self-identify failed |
Leave the turned-away route empty and the call simply ends after the message. Point it at your main menu to let rejected callers carry on as ordinary callers.
The access check modal on My Hotline
Access checks have their own panel on My Hotline, separate from the ⚙ settings every other extension shares. Everything an access check needs is in it.
To protect the whole hotline, click Add access check under the main menu title. You choose an existing check or make a new one, pick who gets through, and type a PIN if that is the type. Callers now pass the check before they ever hear your main menu, and everything behind it stays exactly as it was. The new check is named "Hotline access check".
To protect one key, use Protect key N on that key. The key now opens the check, and callers who pass reach whatever the key used to do. The new check is named "Access check — key N".
Click the amber padlock on a key (or the amber chip under the main menu title) to open the check itself. The panel slides in from the side with four sections:
- Who gets through — the type, the PIN or list, allow or block, and This access check is on. Turn that off and callers pass through without being checked at all.
- If we don't recognize them — the two verification settings above.
- What callers hear — the same six prompt recordings.
- Where they go next — the pass and turned-away destinations. Open its settings jumps straight into whatever sits behind the check, and that panel has a link back.
Open its full page at the top of the panel opens the full Validations page in a new tab.
The small x next to a check removes it from that key without deleting it. The key goes straight back to what it used to do, and you can add the same check back any time.
Tips
- Set Personal PINs first. If you choose "Their Personal PIN from the contact card", every contact without a PIN is turned away. Fill them in on the contact cards before you switch it on.
- Give the turned-away route somewhere to go. A check with nothing on the failure route simply hangs up, which sounds like a fault to the caller. A short "sorry, this is for members only" recording, then your main menu, is friendlier.
- Combine with labels. Put your members in a label, point the check at that label, and add or remove people from the label instead of editing the check. A Join a list step can even let callers add themselves.
- A block list is for keeping people out. It has no self-identify and no verification: the listed numbers are turned away, everybody else walks in.
- Extension ID appears in a collapsed "Phone System Reference" section only when your account has that setting turned on. See Settings.