Improvement begins with proving what actually happened.
One identity from conversation to receipt
Each new call now carries the carrier’s call identity through the conversation record, latency evidence, connection events and review receipt. A quick redial is therefore a new call even when it happens seconds later, rather than two conversations being inferred from a gap in timestamps.
Reception, calls SA‑NT places and hold rescue use the same envelope. Their outcomes are recorded in a bounded vocabulary: resolved, waiting, needs the person, failed or unclear. Unclear remains a valid result; the system does not manufacture resolution to improve its own record.
Checked against what happened
The review joins what SA‑NT said to the tool calls, ledger rows, confirmations, delivery state and connection events that could make it true. A supported completion can be marked clean. An unsupported claim, duplicate action, failed tool, long silence, repeated request, cut-off turn or connection error becomes evidence for review.
A confirmed defect can become a regression scenario or a proposed lesson about an existing tool. Neither route changes authority. Code, deployment, confirmation rules and fleet lessons remain subject to review.
No second transcript
The per-call receipt stores the call identity, type, bounded outcome, review state, evidence counts and timestamps. It does not copy the transcript, request, summary, caller number, tool inputs or tool outputs.
The receipt expires on the same ninety-day clock as the conversation and is removed with the account. This is private-pilot operational infrastructure, not a claim that every human quality of a call can be scored automatically. Warmth, speech accuracy and whether the person felt the matter was genuinely resolved still require consented human testing.
