Integrations
What we need from your IT team
The access, decisions and contacts your IT team provides for a Telonic deployment, and what Telonic provides in return.
On this page
Your IT team's part in a Telonic deployment is to grant access and make decisions. Telonic builds, tests and maintains the connections, the agent and everything around them. Your team creates accounts, opens the network paths, connects your sign-in system and tells us what your security review requires. If any part of the plan asks your team to write code or build an interface, the scope is wrong, and we change it.
The checklist
Only the items that apply to your deployment are needed. A first deployment on one channel usually needs a handful of them.
| What we need | What it is for | Who usually owns it | When it applies |
|---|---|---|---|
| An integration account for each system the agent connects to, with the permissions agreed in the map | Lets the agent read and act in that system, and nothing more | The owner of each system, with IT | Every deployment |
| Network allow-listing for the fixed IP addresses, port ranges and domain name Telonic provides | Lets your deployment reach your systems, and your phone system reach your deployment, through your firewall | Network or security team | Every deployment |
| Single sign-on (one work login for several systems) setup, using SAML 2.0 or OpenID Connect (the two standard ways of passing sign-in details between systems), with multi-factor authentication (a second check beyond a password) | Lets your staff sign in to the Telonic console with their usual work login | Identity team | Every deployment |
| SIP trunk details (SIP is the standard protocol business phone systems use to connect calls): the route from your session border controller (the device at the edge of your phone network that manages call traffic), phone system or contact centre platform, the numbers to route and the number of simultaneous calls | Connects your phone lines to the agent | Telephony team | Voice |
| Mailbox access for the shared mailboxes the agent will answer | Lets the agent read and reply in your mailboxes | Email administrators, for example of Microsoft 365 or Google Workspace | |
| Access to your WhatsApp Business account, or the details of your existing business solution provider | Lets Telonic connect your WhatsApp numbers, submit templates and run business verification | Marketing or digital team, with IT | |
| Test environments for the systems being connected | Lets the connection be built and tested before any customer reaches it | The owner of each system | Every system the agent writes to |
| A named technical contact | One person who can answer questions, make decisions and unblock access | IT | Every deployment |
| Your security review requirements: your questionnaire, policies and any standards you assess vendors against | Lets Telonic complete your review in the form you use | Information security | Every deployment |
| Your hosting decisions: the region, and for your own cloud account or premises, the account or infrastructure | Decides where your deployment runs | IT and security, with legal | Every deployment |
The technical detail
Network. Telonic provides fixed IP addresses, port ranges and a domain name for your deployment, so your network team can allow-list (permit through your firewall) only that traffic. Every connection between your systems and your deployment uses TLS (Transport Layer Security, the standard encryption for data in transit), version 1.2 or higher. Call audio is encrypted with SRTP (Secure Real-time Transport Protocol, the encrypted form of the protocol that carries voice) by default.
Single sign-on. Single sign-on (SSO: signing in to several systems with one work login) connects through your identity provider (the system that manages your staff's logins). Telonic supports SAML 2.0 (Security Assertion Markup Language, a widely used standard for passing sign-in details between systems) and OpenID Connect (OIDC, a newer standard built on OAuth, which lets one system grant another limited access). Multi-factor authentication (a second check beyond a password) is applied through your identity provider. Your team decides which groups of staff get which roles in the console.
Telephony. A SIP trunk (a virtual phone line that connects two phone systems over a network, using SIP, the standard protocol business phone systems use to connect calls) is authenticated with IP allow-listing and SIP digest credentials (a username and password exchanged in a protected form), and mutual TLS (where each side proves its identity with a certificate) is supported. Supported audio codecs (the formats used to encode voice) are G.711 A-law and µ-law, G.722 and Opus. See Voice: connecting your telephony over SIP.
Where a system has no interface
Most systems already have an API (application programming interface: the documented way other software exchanges data with it). Where one does not, we agree with your team the simplest way to make the data available, such as a read-only database view or a scheduled file export. These are tasks your team already knows how to do, not development work. See Custom actions.
What Telonic provides
| What Telonic provides | Detail |
|---|---|
| The connection work | Mapping, building, testing and maintaining every connection |
| Connection details | Fixed IP addresses, port ranges, a domain name and SIP endpoint details for your deployment |
| Configuration guidance | Step-by-step settings for your phone system, identity provider and mailboxes |
| An engineer | Who works with your technical contact through connection and testing |
| Security documentation | Completed security questionnaires, and an architecture description shared under a non-disclosure agreement |
| A plan with dates | Listing each system, each stage and what is needed from your team, before you commit |
Your hosting decisions
Your deployment can run in a UAE region, in a Saudi Arabian region, in your own cloud account, or on your own premises. For the two regional options, Telonic operates the infrastructure and your IT team provides no hosting resources. For your own cloud account, your team provides the account and the permissions for Telonic to deploy into it; Microsoft Azure, AWS, Google Cloud and Core42 are supported.
For your own premises, computing capacity is sized with your team during implementation. See Hosting and data residency and Cloud hosting.
In practice
Sahel Crest Properties, a Dubai developer, prepares for a deployment on its enquiry line and WhatsApp.
- The IT manager, Hamad, is named as technical contact.
- The administrator of the CRM (the system that holds the developer's customer records) creates a test integration account and a live one, each with the permissions in the agreed map. The network team allow-lists Telonic's fixed IP addresses.
- The identity team adds Telonic as an application in the developer's identity provider, using SAML 2.0, and assigns two staff groups to console roles.
- The telephony team sets up a SIP route from its session border controller for the enquiry number, and the marketing team gives Telonic access to the WhatsApp Business account.
- Information security sends its vendor questionnaire. Telonic returns it completed, with the architecture description under a non-disclosure agreement.
- No one on Hamad's team writes code.
What your team controls
- Every account and every network path, which your team can suspend or close at any time.
- Who in your organisation can sign in, and with which role.
- Where your deployment runs.
Related
- How a system gets connectedIntegrations
- PermissionsIntegrations
- Voice: connecting your telephony over SIPChannels
- Access control and single sign-onSecurity and data protection
- Hosting and data residencySecurity and data protection
Product names and logos are trademarks of their owners. Their mention shows systems Telonic connects to and does not imply partnership or endorsement.