Push it to the phones. Reps install nothing.
The agent is an Android app delivered through managed Google Play. Google Workspace, Intune, or any Android Enterprise MDM installs it and hands it three configuration values. This page says what is required and what to check before rollout.
Managed devices only
The phones must be company-owned and enrolled as fully managed devices. On a personal phone with a work profile the agent cannot see calls made from the personal dialler, and that is where normal calls land. A work-profile deployment will show an empty board.
iOS is not supported. iPhones do not expose the call log to apps. If part of the team is on iPhone, a network-side product from the carrier is the only route for those handsets.
Through Google Workspace
Other MDMs follow the same shape: private app, forced install, managed configuration.
- 01Create a fleet enrolment code
In your workspace, open Phones and create an enrolment code for the whole fleet.
- 02Add the app as a private app
In the Google Admin console, add the agent through managed Google Play as a private app and assign it to the organisational unit the phones sit in, as a forced install.
- 03Set the managed configuration
Open the app's settings in the Admin console and set the three keys below.
- 04First launch on each phone
Each rep opens the app once and taps Allow call access and Keep running in the background. The phone then appears on the Phones page and you assign a rep name.
Three keys
server_urlenrolment_codetracked_sim_slotsCheck these
Notice and consent rules by country
Pick the country and state or region your staff work in. The same notice appears inside the workspace once it is created.
Before you enrol phones in England, United Kingdom: Written notice to staff is required before monitoring starts (UK GDPR (Articles 5, 6, 13 and 35) and ICO employment guidance). Tell staff what is collected (call times, durations and numbers, no audio), why, and where it is stored (Australia). Record the date the notice went out on the Settings page.
- Notice to staff
- Required before monitoring starts
- Under
- UK GDPR (Articles 5, 6, 13 and 35) and ICO employment guidance
- Privacy law
- UK GDPR and Data Protection Act 2018
- Call recording (not live)
- One-party consent
- Data hosted in
- Australia
Workers must be told, before monitoring starts, what is collected, why, on what lawful basis and for how long. No fixed notice period is set in law, but the notice must come before the first data is collected and a DPIA should be done first. Check with counsel on the lawful basis you rely on.
This is a summary, not legal advice.
Callboard records call metadata (direction, time, duration and the other party's number) from company-owned phones. It does not record audio, contacts or messages. That is employer monitoring of company devices in England, United Kingdom: Written notice to staff is required before monitoring starts (UK GDPR (Articles 5, 6, 13 and 35) and ICO employment guidance). Customer numbers are personal information under the UK GDPR and Data Protection Act 2018; storing them hashed and masked (the default) reduces what is held, and your privacy notice should cover them.
Call recording (One-party consent). A party to a call may record it. Businesses may monitor or record calls on their own systems for purposes listed in the Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000 if they make all reasonable efforts to tell users; interception of others' calls falls under the Investigatory Powers Act 2016 (which replaced RIPA Part 1). UK GDPR transparency still applies to recordings.
Privacy. Workers' and callers' phone numbers are personal data. You need a lawful basis (usually legitimate interests, documented), a privacy notice to workers before monitoring starts, and, because this is systematic monitoring, a data protection impact assessment is expected. The ICO's guidance on monitoring workers sets the standard.
Hosting. Kept in Australia. Australia has no UK adequacy decision, so this is a restricted international transfer: the ICO's International Data Transfer Agreement (or the Addendum to EU SCCs) and a transfer risk assessment are expected. Check with counsel.
- UK GDPR and Data Protection Act 2018
- ICO guidance: Employment practices and data protection, monitoring workers (2023)
- Telecommunications (Lawful Business Practice) (Interception of Communications) Regulations 2000
- Investigatory Powers Act 2016
This is a summary, not legal advice.
What is collected, and what is not
- Notice to staff
Workers must be told, before monitoring starts, what is collected, why, on what lawful basis and for how long. No fixed notice period is set in law, but the notice must come before the first data is collected and a DPIA should be done first. Check with counsel on the lawful basis you rely on. Have your HR or legal team handle this before rollout.
- Numbers
Phone numbers are stored as a keyed hash (so a call back can be matched) plus the last three digits for display. A workspace can choose to store full numbers, and should only do so once the notice covers it.
- Not collected
No call audio, contacts or SMS. The phone shows a persistent notification while the agent is reporting.
- Removing a phone
Removing a phone in the workspace revokes its token. It cannot re-enrol with the fleet code until restored.
- Hosting
Each workspace has its own database, kept in Australia.
Create a workspace, then push the agent