Skip to content

[ 01 // phones and identity ]

Know who’s calling.
Put the call on the right ticket.

Call Taking finds the caller and turns the call into a routed HaloPSA ticket before you hang up. Afterward, the recording your phone system made is transcribed and matched to the right ticket. And before a tech resets anything, the caller can prove they control the Microsoft 365 account on file.

Inside HaloPSA No new hardware, no recording agent Recordings from Yeastar or Azure Blob Storage Caller verification

[ 02 // call taking ]

Answer three questions while the caller is still talking.

Who is this, have we seen it before, and what do we do with it. Call Taking is the screen your desk opens when the phone rings.

See what’s already open

The Call Taking screen puts the caller’s open tickets next to every open ticket at their company, with VIP and High Risk flags and any Q-Notices. The fourth caller in an outage gets linked to the ticket that already exists instead of opening a new one.

Verify before you act

When the client has Identity Verification switched on, the tech checks the caller from the same screen before touching their account.

Close the call honestly

On the Call Taking screen, every call ends in one of five outcomes: New ticket, Link existing, Resolved, Transfer or No action. One outage stays one ticket, and if nobody could be identified, the call records that rather than guessing.

Call Taking isn’t a softphone. Calls ring, get answered and get transferred on your phone system exactly as they do today. QuantumOps handles the ticket side: who it is, what’s open and where the work goes.

QuantumOps for Halo · Call

The Call tab of the QuantumOps for Halo side panel during a call: Ada Lovelace from Acme Corp with VIP, VIP client and High-risk client flags, her phone, email and site, two open tickets with Link buttons, and step 2 of the Inbound incident script with a client-specific hint. Below, the caller verification row reads Not verified.
The Call tab of the QuantumOps for Halo side panel. The panel lists the caller’s own open tickets, or their company’s when they have none.

Inside HaloPSA

Call Taking can be embedded in Halo, where your techs already work. Your phone system or Halo can open it with the caller ID filled in, and the phone search starts straight away.

In the web app

A New call button in the QuantumOps header opens the same screen in its own tab, with a call timer running from the moment it opens.

In the side panel

The Call tab of QuantumOps for Halo takes the call next to whatever Halo page is open: look up, script, verify, create or link the ticket, wrap up. A panel reload doesn’t lose the session.

Screen pop from Yeastar

When a Yeastar P-Series also supplies your recordings, QuantumOps follows its live call events. An answered call opens a session by itself (for dispatchers, by default), and the extension’s dispatch board shows each agent’s phone as off, idle, ringing or on a call.

[ 03 // call to ticket ]

Every tech asks the right questions in the right order.

Scripts guide the call, the AI drafts the ticket from the answers, and the tech decides where it goes. Nothing is dispatched until they say so.

Call scripts

Build a script once in Q-Director from nine step types: prompts, questions, decision points, input fields, information, user match, variables, ticket search and AI Assist. Answers can fill ticket fields, and the notes land on the ticket.

AI Assist steps

On the web call screen, an AI Assist step turns the answers so far into the ticket’s summary, details, impact, urgency and a triage recommendation, with your own instructions if you want them.

Dispatch now

The AI triage recommendation, with a Why? for each field. Then Halo’s own load balance, round robin or intelligent routing, or a specific agent: the top three technicians carry a skill-match score next to a live workload view, and picking one lets the call book a firm or tentative appointment.

Or queue it for triage

Send it to the triage queue with a default team and ticket type, for a dispatcher to assign. Like every ticket created from a call, it goes straight into QuantumOps’ AI ticket analysis.

The side panel’s Call tab runs the same scripts and creates or links the same Halo tickets, with team, type, impact and urgency set by hand. AI suggestions and AI Assist steps are on the web call screen.

[ 04 // recordings ]

Every recorded call, transcribed and on the right ticket.

QuantumOps doesn’t record calls. It collects the recordings your phone system already makes, transcribes them and posts them to the HaloPSA ticket they belong to.

QuantumOps · Call Recordings

The Call Recordings dashboard in the QuantumOps web app with one call open: an AI summary of Ada Lovelace's call about repeated Outlook password prompts after an MFA reset, a positive sentiment breakdown, and the full transcript with each line labeled Priya Natarajan or Ada Lovelace and timed. Behind it, the list of recordings with their match and posting status.
Summaries, sentiment and speaker names come from AssemblyAI. Azure Speech separates the speakers; Whisper gives a plain transcript.

01

Collect

From a Yeastar P-Series over its API, with extensions mapped to agents and ring and talk times from the call records. Or from any phone system that can save recordings to Azure Blob Storage, using a filename template you can test.

02

Transcribe

With AssemblyAI (our recommendation), Azure Speech or OpenAI Whisper. AssemblyAI and Azure Speech put agent and caller on separate lines; Whisper doesn’t. AssemblyAI can also be given your client and product names as key terms.

03

Summarize

With AssemblyAI, each call also gets a summary, a sentiment breakdown and its topics, so nobody has to listen back to find out what was said.

04

Match

If a Call Taking session already put the call on a ticket, the recording goes there. Otherwise QuantumOps finds the Halo users with the caller’s number, looks at their tickets from around the time of the call, and scores each on phone, agent and timing. It attaches the recording when one ticket clearly wins, and suggests when none does.

05

Post

The Halo ticket gets a call log, with caller, client, site, agent, direction, duration and the AI summary, plus a collapsible transcript note that end users never see. A call matched through a Call Taking session, or by the AI at 90% confidence or more, posts automatically by default; other matches wait for you to post them.

06

Play back

Managers see the whole pipeline on the Call Recordings dashboard, with playback. Techs clear their own calls on My Call Recordings, and the side panel’s Ticket tab plays the audio. Audio streams through links that expire.

[ 05 // unmatched calls ]

When the match isn’t certain, it asks.

Shared lines, callbacks and transfers make some calls ambiguous. When no ticket clearly wins, QuantumOps hands the call to the agent who took it, with its best suggestion.

  • Attached automatically when the top ticket scores 80 or more and no other reaches 70; being the only candidate isn’t enough on its own
  • A second AI pass every two hours for calls from the last seven days still unmatched after 12 hours: it attaches at 90% confidence or more and suggests from 50% to 89%
  • A shared phone number asks the agent to pick the caller first
  • Recordings from the same number within ten minutes of each other (by default), such as a transfer, can be posted as one transcript
  • A Slack or Teams DM of each agent’s unmatched calls, immediately, hourly, daily or weekly
  • My Call Recordings in the web app, and suggested recordings on the side panel’s Ticket tab

[ 06 // identity verification ]

Prove who’s calling before anyone resets anything.

Password resets and MFA changes are what help-desk attackers call for. Identity Verification has the caller prove, on their own phone, that they control the Microsoft 365 account the ticket names. It works on any Microsoft 365 plan once the client’s admin has consented.

1. The expected account is fixed first

Before anything is sent, QuantumOps ties the Halo contact to their permanent Microsoft Entra account ID in the client’s own tenant.

2. The link goes to the address on file

A sign-in link is emailed to the address on file for that person, from the client’s Microsoft directory or their Halo contact record, never an address the tech types. The tech sees a masked address and a “Send it again” button, and has no way to change where it goes.

3. The caller signs in on their own phone

A fresh sign-in to their own Microsoft 365 account, approved in Microsoft Authenticator with number matching. A sign-in more than five minutes old doesn’t count.

4. The result arrives live

Verified, a different account answered, declined or expired: the panel updates as it happens, the verification log records it, and the Halo ticket can get a private note naming who was proven.

QuantumOps for Halo · Call

Further down the Call tab of the side panel: the caller verification card for Ada Lovelace, not yet verified and never verified before, with a Verify caller button. Below it, the new-ticket form with summary and details, dispatch set to Queue for triage, team Service Desk, type Incident, impact and urgency Medium, the caller's number, an option to include the script notes, and the wrap-up notes box.
The Call tab of the QuantumOps for Halo side panel.

Started from wherever the call is.

The Verify button sits on the Call Taking screen, on the side panel’s Ticket, User and Call tabs, and on the Ticket Analysis, Ticket Triage and User tabs inside Halo.

  • The method is already chosen from the client’s policy, and the tech can only switch to a stronger one
  • Every step in the side panel asks for confirmation first
  • A badge names who verified the caller and when, and counts down the reuse window
  • A caller who can’t be verified goes to the supervised override form in the web app, never a quiet pass

[ 07 // social engineering ]

Built for the caller who isn’t who they say.

Someone calls as Acme Corp’s CFO, sounds rushed, and needs an MFA reset before a board meeting. Here is what each version of that call runs into.

Pass the check as yourself.

The trick: sign in with a real account of your own while claiming to be the CFO.

What it runs into: the account that signed in is compared with the one fixed from the Halo contact, by permanent ID and tenant, never by name or email. A different account is logged as a subject mismatch, never as a pass.

Get the tech to coach you.

The trick: “Which number am I meant to pick?”

What it runs into: the prompt appears only on the caller’s phone, and the panel tells the tech never to read a number to the caller or tell them what to approve.

Swap the SIM.

The trick: port the CFO’s number and wait for a text code.

What it runs into: links go by email, not text. Each client has a minimum assurance level, Substantial by default, which rules out SIM-swappable text and voice factors, and a tech can only pick a stronger method.

Enroll your own Authenticator first.

The trick: after a phishing hit, register your own Authenticator on the CFO’s account, then call.

What it runs into: when the caller’s Authenticator was registered in the last seven days, the panel warns the tech to confirm another way before acting.

Ride on an old verification.

The trick: call back later, or on another ticket, and lean on the earlier check.

What it runs into: a verification carries over for five minutes at most, only on that ticket and for that tech. Cancel is enforced on the server, so a late approval can’t flip the result.

What the tech sees when it catches one.

The panel goes red and says a different account answered. It tells the tech to treat the call as unverified, not to carry out the request, and to report it like any suspected social-engineering attempt.

The attempt lands in the verification log as a subject mismatch, with the claimed caller and the account that actually signed in side by side.

What it proves: that the caller controls the Microsoft 365 account on file for that contact. For more, the optional Verified ID mode adds Face Check, a live match against the photo on the caller’s credential.

[ 08 // the record ]

Every attempt on the record. Every exception under a name.

Every attempt leaves evidence you can check later, in QuantumOps and on the Halo ticket.

QuantumOps · Identity Verification

The Identity Verification Management page in the QuantumOps web app, on the Verification Log tab: filters for date, mode, assurance and outcome, an Export CSV button, and a table that puts each claimed caller next to the proven subject. One row is flagged Subject mismatch because a different account signed in; others read Verified, Reused, Override granted, Downgrade blocked and Expired, with the method, assurance, number match, Face Check score, source and Halo ticket for each.

A tamper-evident log

The claimed caller and the proven account side by side, mismatches flagged, filterable by date, mode, assurance and outcome, and exportable to CSV. Each row is sealed into a keyed hash chain, with the key derived from your instance’s secret in Azure Key Vault, so an edited or deleted row breaks the chain, and an admin can run the integrity check at any time.

Proof on the Halo ticket

A private note names who was proven, how and when, such as “Verified: ada.lovelace@acme.example (Substantial, Authenticator, ticket 54892)”. Up to four Halo custom fields you set up carry status, time, method and Face Check confidence for your reports.

Supervised overrides

When nothing can verify a caller, the tech opens an override, writes the reason, names a second approver who isn’t them and attests that the approver reviewed the call. Overrides are capped at three per tech per 24 hours by default, reported per technician, and never shown or counted as verified.

[ 09 // rollout ]

Switch it on one client at a time.

Setup tests the Microsoft side before any caller sees it, and every client can have its own policy.

Setup and preflight

A two-step wizard connects the app registration in your own Microsoft Entra tenant, then runs preflight checks, from the callback address and sign-in claims to client consent and Halo custom fields, each with the fix if it fails. A sandbox rehearses a verification with the real policy, log and Halo note, without contacting Microsoft or the caller.

Per-client policy

Each client’s Microsoft admin consents once, directly or through CIPP. Turn verification on client by client, set the method and minimum assurance for each, and let “Verify all” confirm with Microsoft that every consent actually works.

Verified ID and Face Check

For higher assurance, the caller scans a QR code and presents a Microsoft Entra Verified ID credential from their Authenticator wallet, optionally with Face Check. Issuance campaigns enroll a client’s users by email ahead of the first call, and any credential can be revoked.

[ 10 // faq ]

Straight answers.

Can’t find yours? Email sales@techpulsecloud.com.

Does QuantumOps record our calls?

No. It collects the recordings your phone system already makes, from a Yeastar P-Series over its API or from an Azure Blob Storage container your PBX saves to. Nothing is recorded in the browser, and there’s no recording agent to install.

Which phone systems work with it?

Call Taking works alongside any phone system: the tech looks the caller up, or your PBX or Halo can open the screen with the caller ID filled in. Recordings come from a Yeastar P-Series or any PBX that can save them to Azure Blob Storage. Live presence and screen pop are Yeastar P-Series only, and need your recordings collected through the Yeastar API.

Who pays for transcription?

Transcription runs on a speech-to-text account connected in the Call Recordings settings: an AssemblyAI or Azure Speech key, or Whisper through your OpenAI key. The provider charges for the minutes. Summaries, sentiment and speaker names need AssemblyAI, and Whisper doesn’t separate speakers.

Can our customers see the transcripts?

Not the transcript: that note always goes on the Halo ticket hidden from end users. The call log’s AI summary follows Halo’s own call-log visibility, so check that setting before you rely on automatic posting.

Is caller verification a one-tap approval?

No, on purpose. The caller completes a full sign-in to their own Microsoft 365 account on their phone, usually including their password, and approves it in Microsoft Authenticator. Microsoft Authenticator has to be registered on their account already.

Which Microsoft 365 plans does it need?

The Authenticator sign-in mode works on any Microsoft 365 plan, with no Verified ID setup. Forcing MFA on that sign-in needs Entra ID P1 in the client’s tenant; without it, QuantumOps checks what the caller actually did and fails closed when it isn’t strong enough. Verified ID mode needs its own Microsoft setup and per-user enrollment, and Microsoft bills each Face Check attempt.

What if a caller can’t be verified?

The tech can open a supervised override: a written reason, a named second approver who isn’t the tech, and an attestation, all in the log. Overrides are rate-limited per tech and never show as verified. Or use your usual out-of-band check.

What’s available today?

Call Taking and Call Recording & Transcription are generally available. Identity Verification, the side panel’s Call tab and recordings card, and the Yeastar screen pop are available too.

[ 11 // start ]

Know who’s calling before you reset anything.

We’ll walk through Call Taking, recordings and caller verification on a real HaloPSA queue.

sales@techpulsecloud.com