SMS & Email OTP

Let an AI Agent Verify Who It Is Talking To

Amernet SMS and email OTP lets your AI agent confirm a caller’s identity before it says anything it should not — a six-digit code to the number or address you already hold for them.

It exists so an agent can hold genuinely sensitive information. Mark a knowledge base confidential and its contents are kept out of the agent entirely until the person on the call has proved who they are.

Known callers can be recognised by their number and let straight through. Everyone else gets a code.

Phone screen showing a one-time verification code
The problem

Why an AI agent needs to check identity

Some answers should not be given to whoever happens to ring.

An agent that can quote an account balance, a delivery address or a contract detail is far more useful than one that cannot. It is also a liability, because a phone number is not proof of anything and a confident voice is not identification.

So confidential material is held apart. It is not in the agent’s working knowledge during an ordinary call — it cannot be coaxed out, because it is not there.

When a caller asks for something restricted, the agent verifies first. Only then is the confidential material made available to it, for that conversation.

That is a meaningful difference from telling a model to keep a secret. The instruction is a request; this is an absence.

How it works

Six parts of the verification flow

From a restricted question to a verified answer.

Confidential knowledge, held back

Mark a knowledge base confidential and its contents stay out of the agent until the caller has been verified on that call.

A code by SMS or email

A six-digit code goes to the number or address already on file for that contact — not to whatever the caller reads out.

Known numbers can skip the code

A contact can be set to verify by caller ID, so a recognised number is granted access without a code. Others always get one.

No caller ID? Ask for a name

On a withheld number or a web call the agent asks who is calling, looks them up, and sends the code to the details held for them.

Manage the list properly

The authorised contacts list can be imported and exported in bulk, and duplicate numbers are rejected rather than quietly added twice.

Every attempt logged

Codes sent and verifications attempted are recorded, so access to restricted information is auditable after the fact.

On the call

What the caller actually experiences

A few seconds, not an interrogation.

Someone rings and asks for something restricted. If their number is one you recognise and you have allowed it, the agent simply answers. If not, it tells them a code is on its way, reads back nothing, and waits.

The caller reads the code aloud, the agent checks it, and the conversation carries on with the restricted information available.

The agent tracks where it sent the code, so the caller only has to say the digits. They are never asked to repeat their own phone number back to a system that already has it — which is where these flows usually become infuriating.

If verification fails, the agent simply cannot answer the restricted question. There is nothing to fall back on and nothing to leak.

Questions

Common questions about OTP verification

What people ask before letting an agent hold sensitive information.

To the phone number or email address already held for that contact — never to a number the caller supplies during the call. That is the point: possession of the known number or mailbox is the proof.

Yes. A contact can be set to verify by caller ID, so a recognised number is allowed straight through. Anyone set to code verification always gets one.

The agent asks who is calling, looks that person up in the authorised list, and sends the code to the details on file for them.

No. Confidential knowledge is kept out of the agent’s working context until the caller is verified, so there is nothing to disclose by accident or under pressure. See knowledge base.

Yes — import and export the authorised contacts rather than adding them one at a time, and duplicate phone numbers are rejected on entry.

Codes sent and verification attempts are logged, so access to restricted information can be reviewed afterwards.

Let your agent handle the account questions

The calls you currently escalate because the agent cannot be trusted with them.

Most teams give their agent the easy half of the call and route the rest to a person. Book a short session and we will set up a confidential knowledge base and verify a call end to end, so you can judge the flow yourself.