Customer communications can include sensitive personal, operational, financial, safety, and contractual information. A communication process must define purpose, consent, access, retention, and human review.
Scope note: This is a vendor-neutral privacy checklist. It does not claim that any product provides inboxes, chat, SMS, email, voice, transcription, AI drafting, automation, routing, customer records, status tracking, integrations, or response outcomes.
Confirm purpose and authorized channel
Before sending or using information, confirm the purpose, authorized channel, current contact detail, applicable consent or policy, sender responsibility, and stop condition. Do not infer consent from a prior message, an account, a job request, or a contact record.
Limit data and access
Use only information needed for the approved communication. Do not publish or share names, phone numbers, email addresses, addresses, appointment details, payment information, account IDs, conversation histories, recordings, transcripts, screenshots, logs, credentials, or internal links.
Apply least-privilege access and a defined retention process.
Treat drafts and summaries as unverified
A suggested reply, transcript, summary, classification, status, or activity signal may be incomplete or wrong. It is not an approved communication, evidence of consent, booked work, completed work, payment, satisfaction, or revenue.
A responsible person must review any message that affects safety, timing, price, scope, access, privacy, legal matters, complaints, disputes, or customer expectations.
Escalate sensitive or unclear matters
Use the documented human process for urgent, safety-related, financial, legal, privacy, or unclear communications. Do not promise availability, arrival, price, service capability, remedy, or outcome without current authorization and verification.
Test with synthetic messages
| Situation | Expected control |
|---|---|
| Routine low-risk draft | Human review before sending |
| Missing or conflicting information | Pause for clarification |
| Sensitive customer information | Restrict access and minimize data |
| Urgent or safety request | Documented escalation |
| Error, complaint, or opt-out | Stop, preserve evidence, and correct |
Review, do not infer results
A message, read receipt, reply, view, notification, or status is not proof of a business result. Verify meaningful outcomes against authorized records and preserve a correction path.
Discussion
Which type of customer message should never be sent without an explicit human review?