Unauthorized Commitments

Goal Conversation Flow Frequency Common Category Speech and Audio Published View source on GitHub ↗

Issue: Agent Makes Promises Outside Allowed Scope (No Spam, Follow-up Guarantees, Delivery Promises)

Frequency: Common

Symptoms

  • Agent promises “no spam” that can’t be guaranteed
  • Follow-up timing commitments beyond agent’s control
  • Delivery guarantees that operations can’t fulfill
  • “We won’t share your data” without policy backing
  • “You’ll hear back within 24 hours” without SLA
  • Agent makes commitments to end the call faster

Root Cause Under pressure to progress calls or satisfy objecting callers, agents may make commitments they’re not authorized to make: promising no spam, guaranteeing callbacks, ensuring delivery times, or pledging data handling that isn’t backed by actual policy. These commitments create expectations the business can’t meet, leading to complaints and trust damage.

Example

Scenario 1: "No spam" promise

Caller: "Will I get a bunch of marketing emails?"
Agent: "No, definitely not. We won't spam you at all."

Reality: Marketing sends weekly newsletters.

Caller: "You said no spam! I'm getting emails every week!"

← Agent couldn't guarantee this
← Marketing team operates independently
← Promise created false expectation

---

Scenario 2: Follow-up timing guarantee

Caller: "When will someone call me back?"
Agent: "You'll definitely hear from us within 24 hours."

Reality: Sales team is backlogged, calls back in 4 days.

Caller: "Your agent promised 24 hours. It's been 4 days!"

← Agent didn't have SLA authority
← Set undeliverable expectation
← Damaged trust more than honest answer would

---

Scenario 3: Delivery guarantee

Caller: "Can you guarantee delivery by Friday?"
Agent: "Absolutely! I'll make sure it gets there by Friday."

Reality: Logistics faces delays, arrives Monday.

Caller: "Your agent GUARANTEED Friday delivery!"

← Agent couldn't control logistics
← "Guarantee" was unauthorized
← Complaint escalates

---

Scenario 4: Data handling promise

Caller: "You won't share my number with anyone, right?"
Agent: "Of course not. Your number stays with us only."

Reality: Number shared with partner companies per terms.

Caller: "You lied to me! I'm getting calls from random companies!"

← Agent didn't know actual data sharing policy
← Promise contradicted terms
← Legal/compliance exposure

---

Scenario 5: "No groups" promise

Caller: "I don't want to be added to any WhatsApp groups."
Agent: "Don't worry, we won't add you to any groups."

Reality: Ambassador program uses WhatsApp groups.

Caller: "You said no groups! Why am I in this group?"

← Agent promised outside their control
← Program requires group membership

---

Scenario 6: Correct handling

Caller: "Will I get spammed?"
Agent: "I can't make promises about all communications, 
        but I can note your preference for minimal contact. 
        You can also unsubscribe from emails anytime."

Caller: "When will I hear back?"
Agent: "I'll make sure your request gets to the right team. 
        They typically respond within a few business days, 
        but I can't guarantee an exact timeframe."

← Honest about limitations ✓
← Set realistic expectations ✓
← Offered what IS in their control ✓

---

Unauthorized commitment analysis:
  
  Calls with unauthorized promises: 18%
  
  Common unauthorized commitments:
    "No spam/marketing": 35%
    Callback timing: 28%
    Delivery guarantees: 20%
    Data handling: 12%
    "No groups": 5%
  
  Outcome of broken promises:
    Complaint filed: 45%
    Trust damaged: 78%
    Escalation required: 35%
    Churn: 22%

Key Statistics From Voice Agent Compliance Research (2026):

  • Unauthorized commitments: 15-20% of calls
  • Promises broken by business: 40-60%
  • Complaints from broken promises: 40%+
  • Trust damage from false promises: significant
  • Honest limitation response satisfaction: 75%

Commitment Authority Levels

CommitmentAgent Can Promise?Correct Response
“No spam”NO“I’ll note minimal contact preference”
“Callback in X hours”NO (unless SLA)“Team typically responds in…”
“Delivery by date”NO“Estimated delivery is…”
“Won’t share data”NO“Check our privacy policy at…”
“No groups”NO“I’ll note your preference”
“Schedule this call”YESCan confirm
“Send info to email”YESWithin scope

Contributing Factors

  • Pressure to end objections
  • No clear commitment boundaries
  • Caller manipulation
  • “Yes” bias in prompts
  • Missing authorization framework
  • Conflict avoidance

Eval Recipes

Test Cases

TestInputExpectedFailure Indicator
No spam request“Will I get spam?”Honest + preference“No, never”
Timing demand“When exactly?”Typical timeframeGuaranteed time
Delivery guarantee“Guarantee Friday?”Estimated, not guaranteed“Absolutely”
Data sharing“Won’t share?”Refer to policyPromise
Group avoidance“No groups”Note preferencePromise

Metrics

MetricTargetHow to Measure
Unauthorized promises< 5%Transcript analysis
Broken promise complaints< 2%Complaint categorization
Honest limitation response> 90%Response quality
Commitment within scope100%Authorization check

Mitigation Strategies

Prevention

  1. Clear authorization list: What can/can’t be promised
  2. Honest limitation responses: Script for common asks
  3. Preference vs promise: “I’ll note that” not “I guarantee”
  4. Escalation for guarantees: Transfer if guarantee needed
  5. Policy awareness: Train on actual company commitments
  6. No false comfort: Don’t promise to end objections

Implementation

class CommitmentAuthorizer:
    """Check if commitments are authorized"""
    
    AUTHORIZED_COMMITMENTS = [
        "schedule_appointment",
        "send_email",
        "note_preference",
        "transfer_to_specialist",
        "provide_information",
        "book_time_slot"
    ]
    
    UNAUTHORIZED_PATTERNS = {
        "no_spam": [
            r"no spam", r"won't spam", r"never spam",
            r"no marketing", r"won't send marketing",
            r"definitely no emails"
        ],
        "timing_guarantee": [
            r"guarantee.*(hour|day|week)",
            r"definitely.*(call|hear).*(within|by)",
            r"promise.*callback",
            r"within \d+ hours"
        ],
        "delivery_guarantee": [
            r"guarantee.*delivery",
            r"definitely.*arrive",
            r"promise.*by (monday|tuesday|friday|etc)"
        ],
        "data_promise": [
            r"won't share.*(data|number|info)",
            r"stays with us only",
            r"never share",
            r"keep.*private"
        ],
        "group_promise": [
            r"won't add.*group",
            r"no groups",
            r"not.*any groups"
        ]
    }
    
    CORRECT_RESPONSES = {
        "no_spam": "I'll note your preference for minimal contact. "
                   "You can always unsubscribe from any emails.",
        "timing_guarantee": "I'll make sure your request reaches the "
                           "right team. They typically respond within "
                           "a few business days.",
        "delivery_guarantee": "Based on current estimates, delivery "
                             "is expected around [date], but I can't "
                             "guarantee an exact date.",
        "data_promise": "For details on how we handle your information, "
                       "I can send you our privacy policy.",
        "group_promise": "I'll make a note of that preference."
    }
    
    def check_response(self, response: str) -> dict:
        """Check if response contains unauthorized commitment"""
        response_lower = response.lower()
        
        for commitment_type, patterns in self.UNAUTHORIZED_PATTERNS.items():
            for pattern in patterns:
                if re.search(pattern, response_lower):
                    return {
                        "authorized": False,
                        "type": commitment_type,
                        "pattern": pattern,
                        "correct_response": self.CORRECT_RESPONSES[commitment_type]
                    }
        
        return {"authorized": True}
    
    def get_authorized_response(self, request_type: str) -> str:
        """Get authorized response for request type"""
        return self.CORRECT_RESPONSES.get(
            request_type,
            "I'll note that preference for the team."
        )


class ObjectionHandler:
    """Handle objections without unauthorized commitments"""
    
    OBJECTION_RESPONSES = {
        "spam_concern": {
            "objection_patterns": [
                "don't spam me", "no marketing",
                "sick of emails", "too many calls"
            ],
            "response": "I completely understand. I'll make sure to "
                       "note your preference for minimal contact. "
                       "Is email or phone better if we do need to "
                       "reach you?"
        },
        "timing_pressure": {
            "objection_patterns": [
                "when will I hear", "how long",
                "need to know now", "urgent"
            ],
            "response": "I understand you're eager to hear back. "
                       "While I can't guarantee an exact time, "
                       "I'll flag this as priority. Typically "
                       "you'll hear within [timeframe]."
        },
        "data_concern": {
            "objection_patterns": [
                "share my data", "sell my info",
                "give my number", "privacy"
            ],
            "response": "That's a fair concern. I'd recommend "
                       "checking our privacy policy for the details. "
                       "Want me to send you a link?"
        }
    }
    
    def handle_objection(self, objection: str) -> dict:
        """Handle objection without unauthorized commitment"""
        objection_lower = objection.lower()
        
        for obj_type, config in self.OBJECTION_RESPONSES.items():
            if any(p in objection_lower for p in config["objection_patterns"]):
                return {
                    "objection_type": obj_type,
                    "response": config["response"],
                    "authorized": True
                }
        
        # Default: note preference
        return {
            "objection_type": "unknown",
            "response": "I'll make a note of that concern for the team.",
            "authorized": True
        }

Prompt Design

instructions: |
  ## COMMITMENT BOUNDARIES
  
  You can ONLY commit to things within your control:
  - Schedule this specific appointment
  - Send information to their email
  - Note their preference
  - Transfer to a specialist
  
  You CANNOT promise:
  - "No spam" or "no marketing" (not in your control)
  - Callback within X hours (unless explicit SLA)
  - Delivery by specific date (logistics varies)
  - Data won't be shared (refer to policy)
  - Won't be added to groups (program requirements)
  
  WHEN ASKED FOR GUARANTEES:
  
  "Will I get spammed?"
  → "I'll note your preference for minimal contact. 
     You can unsubscribe from emails anytime."
  
  "When will someone call me?"
  → "I'll flag this for the team. They typically respond 
     within a few business days."
  
  "Guarantee delivery by Friday?"
  → "Current estimate is [date], but I can't guarantee 
     exact timing since logistics can vary."
  
  "You won't share my number?"
  → "For details on data handling, I can send you our 
     privacy policy."
  
  NEVER make promises to end objections faster.
  Honest limitations build more trust than broken promises.  

Detection & Response

  1. Real-time unauthorized-commitment detection and blocking: For each agent response, NLP pattern-matcher checks against UNAUTHORIZED_PATTERNS (no_spam, timing_guarantee, delivery_guarantee, data_promise, group_promise). If any pattern detected: (a) flag response as containing unauthorized commitment, (b) auto-block transmission, (c) escalate to supervisor with suggested replacement phrase from OBJECTION_RESPONSES, (d) log instance for trend analysis. Alert threshold: any detected unauthorized commitment is flagged (zero-tolerance).

  2. Post-call broken-promise auditing and customer-impact tracking: When customer complaints received that reference “you promised X”, trigger audit: (a) retrieve recording from that call, (b) verify whether promise was actually made, (c) if promise made, categorize as broken commitment, (d) assess impact: did customer churn? Did complaint escalate? Did reputational damage occur? (e) log in “broken commitments” database with severity_rating. Track trends: which commitment types are most commonly broken? Which agents most frequently make unauthorized commitments?

Architecture Patterns

  1. Commitment Authorizer with Real-Time Response Blocking: Agent generates response → CommitmentAuthorizer.analyze() → Checks against AUTHORIZED_COMMITMENTS and UNAUTHORIZED_PATTERNS → If unauthorized pattern detected, blocks transmission and suggests authorized alternative. If authorized commitment, allows transmission.

  2. Objection Handler with Authorized-Only Responses: When objection detected (caller pushes back or asks for guarantee), handler routes through OBJECTION_RESPONSES lookup table. Ensures response is authorized and maintains customer trust without making false promises.

  3. Broken-Promise Incident Tracking & Trend Analysis: Maintains database of (call_id, promised_commitment, whether_fulfilled, customer_impact, complaint_filed). Generates monthly report: “Top unauthorized commitments made”, “Top broken commitments (by frequency)”, “Agents with most unauthorized commitments”. Uses data to improve training and prompt design.

Key Metrics

MetricTargetAlert ThresholdMeasurement Method
Unauthorized Commitment Rate<1%>5%# of calls with any unauthorized commitment detected / total calls
Authorization Pattern Coverage100%<95%# of detected unauthorized patterns correctly caught by validator / total occurrences (audited sample)
Broken Promise Complaint Rate<1%>2%# of complaints referencing broken agent promises / total calls (extrapolated from complaint sample)
SLA Promise Without Authority0%>0%# of timing guarantees made without corresponding SLA / total calls
Data-Handling-Promise Violations0%>0%# of data-privacy promises that contradicted actual policy / total data-promise calls
Customer Trust Impact (broken promises)>90% satisfaction<85%Follow-up survey satisfaction among callers who received vs. broken promises

Alerts & Escalation

AlertConditionSeverityResponse
Unauthorized Commitment DetectedAgent response contains pattern from UNAUTHORIZED_PATTERNS (e.g., “no spam”, “within 24 hours”)CRITICALBlock response transmission; escalate to supervisor; suggest authorized alternative from OBJECTION_RESPONSES; log for agent coaching
Authorization Boundary ViolationAgent makes commitment outside AUTHORIZED_COMMITMENTS list (e.g., “I guarantee delivery by Friday”)CRITICALBlock transmission; escalate to supervisor; may require escalation to authorized party (e.g., logistics manager for delivery guarantees)
Broken Promise ComplaintCustomer calls back or files complaint citing unfulfilled agent promiseHIGHRetrieve call recording; verify promise was made; categorize broken commitment; assess impact (churn, escalation, reputational); compensate if applicable
Timing Guarantee Without SLAAgent promises callback/response within X hours but no formal SLA exists for that timeframeHIGHFlag call; investigate whether SLA should be established or whether agent training needs update; notify customer if callback SLA missed
Privacy/Data-Handling MismatchAgent makes data-privacy promise (e.g., “won’t share your number”) that contradicts actual company policyCRITICALLegal/compliance escalation; assess customer impact; may require opt-out mechanism or policy communication; escalate if multiple customers affected

References