Worked example: an assistant asks to change a customer's email address
Consider a fictional business account for Harbour Example Pty Ltd. Its approved contact register lists Dana as an appointment coordinator who may arrange service visits. Morgan is the account owner authorised to change account contact details. A caller introduces themselves as Dana, quotes a booking reference and asks for invoices to be sent to a new email address. The opening facts may help locate the record, but they do not establish permission for the requested billing change.
The receptionist first classifies the request as a change to an account contact destination. It follows the business's approved verification method and checks the resulting authority against that action. Even if the caller is confirmed as Dana, the action is outside the appointment-coordination permission. The appropriate response is a neutral boundary: I can take the request for the account team to review, but I cannot change that email address through this call.
Do not read the current billing address aloud to explain the refusal. Do not ask the caller to confirm the owner's private details. Do not treat the new address as a channel through which to approve its own substitution. The specific recovery route should come from the business's established process, such as review by the authorised account team using an approved contact method. This example deliberately leaves the mechanism open because businesses differ in what their systems and policies support.
The internal note could say: Caller requested a change to the invoice email destination. Appointment-coordinator authority was established; authority for the billing-contact change was not established. No account change was made. Review assigned to accounts. Keep the proposed new address only in a destination approved for that information. The note should not contain verification secrets or imply that the request is fraudulent merely because it exceeded the caller's role.
Test the same scenario with Morgan using the approved method and the correct authority. The action should still depend on the permitted implementation and a confirmed result. If the update fails, the receptionist must not say the address has changed. Then test a third caller who knows the account name but cannot complete the check. That caller should receive useful general assistance without learning whether Dana or Morgan appears in the authority register.
Finish with a human-operating check. Ask the accounts owner to find the pending request, identify what remains unapproved and explain the next step. If staff cannot distinguish a denied action from a completed change, the notification design is incomplete even if the phone script behaved correctly. A verification workflow includes the handoff and its outcome, not just the moment somebody asks a security question.